Privacy Policy
Last updated: March 2026
1. Introduction
Advisio Ltd (“we”, “our”, “us”), a company registered in England and Wales, is committed to protecting your privacy. This policy explains how we collect, use, store, and safeguard your personal information when you visit advisio.uk or engage with our advisory services.
We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
2.1 Information You Provide Directly
When you contact us, submit a form, or engage with our services, we may collect:
- Full name
- Email address
- Phone number
- Company name and job title
- Details of your enquiry or project requirements
- Any other information you choose to provide in correspondence
2.2 Information Collected Automatically
When you visit our website, we may automatically collect:
- Usage data such as pages visited, time on site, and referral source via Google Analytics (loaded only after you consent to cookies)
- Technical data such as browser type, device type, operating system, and screen resolution
- IP address (anonymised where possible)
2.3 Information from Third Parties
We may receive information about you from publicly available sources (such as LinkedIn or Companies House) in the normal course of business development, where we have a legitimate interest in doing so.
3. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
- Consent – where you have given clear consent for us to contact you or send marketing communications
- Legitimate interests – where processing is necessary for our legitimate business interests (such as responding to enquiries, improving our services, or business development), provided these do not override your rights. Where we rely on legitimate interests, we have conducted a balancing assessment to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting us
- Contractual necessity – where processing is necessary to perform or enter into a contract with you
- Legal obligation – where we are required to process data to comply with a legal obligation
4. How We Use Your Information
We use collected information to:
- Respond to your enquiries and provide advisory services
- Communicate with you about engagements, proposals, or projects
- Improve our website, content, and user experience
- Send relevant insights, articles, or communications (only with your consent)
- Administer and protect our business and website
- Comply with legal and regulatory obligations
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties.
We may share data with trusted service providers who assist us in operating our business, including:
- Cloudflare: website hosting and content delivery
- HubSpot: CRM, contact form processing, and email communications
- Google Analytics (GA4): anonymised website usage analytics (only with your consent)
- Notion: content management for our Insights articles
- Professional advisors (accountants, legal counsel)
All third-party service providers are required to process your data in accordance with applicable data protection law and are bound by confidentiality obligations. Where data is transferred outside the UK, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or adequacy decisions).
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specifically:
- Enquiry data: retained for up to 3 years from last contact, unless an ongoing engagement exists or you have provided consent for us to remain in contact
- Client engagement data: retained for 7 years after the end of the engagement, in line with professional and legal obligations
- Marketing consent data: retained until you withdraw consent
- Website analytics data: anonymised and aggregated, retained indefinitely
You may request deletion of your data at any time (see Section 7).
7. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectification – request correction of inaccurate or incomplete data
- Erasure – request deletion of your data (the “right to be forgotten”)
- Restriction – request that we restrict processing of your data
- Portability – request a copy of your data in a structured, machine-readable format
- Object – object to processing based on legitimate interests or direct marketing
- Withdraw consent – where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at hello@advisio.uk. We will respond within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies and Tracking
We use cookies only with your explicit consent. When you first visit our site, a cookie consent banner will ask for your permission before any non-essential cookies are set.
- Essential cookies: used for basic site functionality (e.g. remembering your cookie preference). These do not require consent under PECR
- Analytics cookies: we use Google Analytics (GA4) to understand how visitors use our site. These cookies are only set if you click “Accept” on the cookie banner. Google Analytics collects anonymised usage data such as pages visited, session duration, and referral source. We do not use Google Analytics for advertising or cross-site tracking
You can change your cookie preferences at any time by clearing your browser's cookies for this site and revisiting. The consent banner will reappear.
We do not use any third-party advertising cookies or tracking pixels.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (HTTPS), secure hosting, and access controls.
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by UK GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, providing details of the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
11. Automated Decision-Making
We do not currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals. If this changes in the future, we will update this policy and, where required, obtain your explicit consent.
12. Children's Privacy
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
14. Contact
For privacy-related enquiries, to exercise your rights, or to raise a concern, contact us at:
Advisio Ltd
Email: hello@advisio.uk
Data Controller: Chris Hodgson, Advisio Ltd