Data protection statement

Your data, your trust, our responsibility.

Crown Veritas collects and processes personal data only when it is needed to provide consulting services, respond to enquiries, or improve this website. This privacy policy explains how our Surrey-based business consulting practice handles that information under UK GDPR.

Data minimisation
Encrypted storage
Your GDPR rights
01 / Overview

Privacy Policy Overview

This privacy policy is for clients, prospective clients, suppliers, and visitors to the Crown Veritas website.

Crown Veritas is the data controller for personal information collected through this website and during our consulting engagements. We decide what information is needed, why it is used, and how long it is kept.

This data protection statement applies to contact enquiries, client records, project communications, and anonymous website analytics. It does not cover websites operated by other organisations.

Data controller: Crown Veritas, Beech Drive, Reigate and Banstead, Surrey, KT20 6PP, United Kingdom.
02 / Personal data usage

What We Collect

We ask for information that helps us answer you or deliver agreed advisory work.

Contact details

Your name, email address, telephone number, organisation, and the details you include in an enquiry.

Website analytics

Anonymous usage information such as pages viewed, device type, and broad location data used to improve the site.

Client engagement data

Project notes, correspondence, business information, and financial or operational details you choose to share for consulting work.

Sensitive information

We do not request special category data unless there is a clear need and you have given explicit consent.

03 / Lawful processing

Why We Process Data

Each use of personal data has a lawful basis under UK GDPR.

Purpose Lawful basis What this means
Deliver consulting work Contract performance We use relevant information to prepare advice, manage communication, and complete an agreed engagement.
Reply to enquiries Pre-contract steps We process the details needed to discuss your requirements before a service agreement is made.
Send relevant updates Legitimate interests or consent Marketing is limited to relevant business information, and optional communications include a clear opt-out.
Meet legal duties Legal obligation We retain or share information where accounting, regulatory, or other UK legal requirements apply.
04 / Your control

Your Rights

You can ask what we hold, correct it, or object to a particular use.

Access and correction

Ask for a copy of your personal data or tell us when it needs updating.

Erasure and restriction

Request deletion where the law allows, or ask us to pause a specific processing activity.

Objection and portability

Object to processing based on legitimate interests and request usable electronic data where portability applies.

05 / Protection and records

Security and Retention

We protect records according to their purpose and remove them when they are no longer needed.

Encryption and access controls

Information is protected in transit and at rest where supported by the systems we use. Access is limited to people who need the information for their role.

Retention periods

Enquiry records are reviewed when communication ends. Client and financial records are kept for the period required by the engagement, professional practice, or UK law, then securely deleted or anonymised.

Processors and safeguards

We may use trusted providers for hosting, email, document management, or analytics. They process information only on our instructions and are expected to maintain suitable confidentiality and security measures.

International transfers

We do not plan transfers of personal data outside the UK or EEA. If that changes, we will use the safeguards required by UK data protection law and update this policy.

06 / Speak with us

Questions About Data

Send data protection queries to [email protected]. You can also contact the Information Commissioner's Office if you believe your concern has not been resolved.