sga stabilisation & growth advisory logo white

Privacy Policy

Last Updated: August 2026

Stabilisation & Growth Advisory (“SGA”, “we”, “us”, “our”) provides operational, governance, financial and advisory services to SMEs. We are committed to protecting your personal information and being transparent about how we use it.

This Privacy Policy explains:

  • what information we collect
  • how we use it
  • how we store and protect it
  • your rights
  • how to contact us

SGA is the controller of your personal information under UK GDPR and the Data Protection Act 2018.

1. The information we collect

We only collect information that is necessary for delivering our services.

a) Information you provide directly

This includes:

  • Name
  • Email address
  • Business name
  • Role
  • Contact details
  • Information shared during advisory sessions
  • Information submitted through the SGA Health Check
  • Information provided during a Business Review
  • Documents you choose to share with us (e.g., financial reports, workflows, policies)

We do not collect special category data unless you explicitly provide it (and we will immediately delete it if it is not required).

b) Information collected through the SGA Health Check

The Health Check collects:

  • your confidence levels
  • your comfort with processes
  • your perception of capability
  • your operational maturity indicators
  • your pillar‑level clarity

This is perception‑based, not behavioural tracking.

We do not use cookies, analytics, or tracking pixels inside the Health Check.

c) Information collected automatically

Our website may collect:

  • basic analytics (page views, device type)
  • essential cookies required for site functionality

third‑party profiling tools

We do not use:

  • marketing cookies
  • behavioural tracking
  • advertising pixels

2. How we use your information

We use your information to:

  • deliver advisory, operational, governance and financial services
  • run the SGA Health Check
  • provide Business Reviews
  • prepare reports, recommendations and capability assessments
  • communicate with you about your engagement
  • maintain internal records
  • improve our diagnostic tools and methodologies (using anonymised data only)

We do not:

  • use your data for advertising
  • sell your data
  • share your data with third parties for marketing
  • use your data for automated decision-making
  • use your data for profiling

3. Lawful bases for processing

We rely on the following lawful bases under UK GDPR:

Contract

To deliver advisory, operational, governance and financial services.

Consent

When you choose to complete the SGA Health Check or provide optional information.

Legal obligation

For financial records, invoicing and compliance.

Legitimate interests

To maintain internal records, improve services and ensure business continuity.

Recognised Legitimate Interests (UK GDPR 2024–2026)

For anonymised data analysis, diagnostic improvement and internal administrative processing.

We do not use legitimate interests for marketing.

4. How we store and protect your information

We use appropriate technical and organisational measures to protect your data, including:

  • encrypted storage
  • access controls
  • secure communication channels
  • restricted internal access
  • regular security reviews

We also follow the DUAA 2025 requirement for:

  • proportionate data retention
  • minimisation
  • secure deletion
  • transparency

5. How long we keep your information

We keep your information only as long as necessary:

  • Advisory engagement records: up to 6 years (legal obligation)
  • Financial records: 6 years (HMRC requirement)
  • Health Check responses: 90 days, then anonymised
  • Business Review notes: 12 months, unless part of an ongoing engagement
  • Emails: 24 months, unless legally required to retain

You may request deletion at any time.

6. Sharing your information

We only share your information when necessary:

  • with professional advisers (e.g., accountants) with your permission
  • with regulators when legally required
  • with service providers who support our operations (e.g., secure hosting)

We do not share your information with:

  • advertisers
  • marketers
  • data brokers
  • credit reference agencies
  • third parties for commercial gain

7. International transfers

If we transfer data outside the UK, we ensure the destination has not materially lower data protection standards (UK GDPR 2024–2026 update).

We use:

  • UK Addendum
  • International Data Transfer Agreement (IDTA)
  • recognised safeguards

8. Automated decision-making

SGA does not use automated decision-making or AI‑based profiling that produces legal or significant effects.

All recommendations are human-led.

9. Children’s data

Our services are not intended for children. We do not knowingly collect data relating to anyone under 18.

10. Your rights

Under UK GDPR, you have the right to:

  • access your data
  • correct inaccurate data
  • request deletion
  • restrict processing
  • object to processing
  • request data portability
  • withdraw consent
  • lodge a complaint with the ICO

Subject Access Requests (DSARs)

We follow updated UK rules:

  • we may request ID
  • we may request clarification
  • we may pause (“stop the clock”) while awaiting information
  • we will conduct a reasonable and proportionate search

11. How to complain

We hope to resolve any concerns directly.

If you wish to escalate, you may contact the ICO:

Information Commissioner’s Office www.ico.org.uk 0303 123 1113

12. Contact us

Stabilisation & Growth Advisory

Email: contact@stabilisationgrowthadvisory.co.uk

Registered Office Address: 48 Turnstone Way, Huddersfield, HD4 5FA, United Kingdom

Scroll to Top