
Privacy Policy
Last Updated: August 2026
Stabilisation & Growth Advisory (“SGA”, “we”, “us”, “our”) provides operational, governance, financial and advisory services to SMEs. We are committed to protecting your personal information and being transparent about how we use it.
This Privacy Policy explains:
- what information we collect
- how we use it
- how we store and protect it
- your rights
- how to contact us
SGA is the controller of your personal information under UK GDPR and the Data Protection Act 2018.
1. The information we collect
We only collect information that is necessary for delivering our services.
a) Information you provide directly
This includes:
- Name
- Email address
- Business name
- Role
- Contact details
- Information shared during advisory sessions
- Information submitted through the SGA Health Check
- Information provided during a Business Review
- Documents you choose to share with us (e.g., financial reports, workflows, policies)
We do not collect special category data unless you explicitly provide it (and we will immediately delete it if it is not required).
b) Information collected through the SGA Health Check
The Health Check collects:
- your confidence levels
- your comfort with processes
- your perception of capability
- your operational maturity indicators
- your pillar‑level clarity
This is perception‑based, not behavioural tracking.
We do not use cookies, analytics, or tracking pixels inside the Health Check.
c) Information collected automatically
Our website may collect:
- basic analytics (page views, device type)
- essential cookies required for site functionality
third‑party profiling tools
We do not use:
- marketing cookies
- behavioural tracking
- advertising pixels
2. How we use your information
We use your information to:
- deliver advisory, operational, governance and financial services
- run the SGA Health Check
- provide Business Reviews
- prepare reports, recommendations and capability assessments
- communicate with you about your engagement
- maintain internal records
- improve our diagnostic tools and methodologies (using anonymised data only)
We do not:
- use your data for advertising
- sell your data
- share your data with third parties for marketing
- use your data for automated decision-making
- use your data for profiling
3. Lawful bases for processing
We rely on the following lawful bases under UK GDPR:
Contract
To deliver advisory, operational, governance and financial services.
Consent
When you choose to complete the SGA Health Check or provide optional information.
Legal obligation
For financial records, invoicing and compliance.
Legitimate interests
To maintain internal records, improve services and ensure business continuity.
Recognised Legitimate Interests (UK GDPR 2024–2026)
For anonymised data analysis, diagnostic improvement and internal administrative processing.
We do not use legitimate interests for marketing.
4. How we store and protect your information
We use appropriate technical and organisational measures to protect your data, including:
- encrypted storage
- access controls
- secure communication channels
- restricted internal access
- regular security reviews
We also follow the DUAA 2025 requirement for:
- proportionate data retention
- minimisation
- secure deletion
- transparency
5. How long we keep your information
We keep your information only as long as necessary:
- Advisory engagement records: up to 6 years (legal obligation)
- Financial records: 6 years (HMRC requirement)
- Health Check responses: 90 days, then anonymised
- Business Review notes: 12 months, unless part of an ongoing engagement
- Emails: 24 months, unless legally required to retain
You may request deletion at any time.
6. Sharing your information
We only share your information when necessary:
- with professional advisers (e.g., accountants) with your permission
- with regulators when legally required
- with service providers who support our operations (e.g., secure hosting)
We do not share your information with:
- advertisers
- marketers
- data brokers
- credit reference agencies
- third parties for commercial gain
7. International transfers
If we transfer data outside the UK, we ensure the destination has not materially lower data protection standards (UK GDPR 2024–2026 update).
We use:
- UK Addendum
- International Data Transfer Agreement (IDTA)
- recognised safeguards
8. Automated decision-making
SGA does not use automated decision-making or AI‑based profiling that produces legal or significant effects.
All recommendations are human-led.
9. Children’s data
Our services are not intended for children. We do not knowingly collect data relating to anyone under 18.
10. Your rights
Under UK GDPR, you have the right to:
- access your data
- correct inaccurate data
- request deletion
- restrict processing
- object to processing
- request data portability
- withdraw consent
- lodge a complaint with the ICO
Subject Access Requests (DSARs)
We follow updated UK rules:
- we may request ID
- we may request clarification
- we may pause (“stop the clock”) while awaiting information
- we will conduct a reasonable and proportionate search
11. How to complain
We hope to resolve any concerns directly.
If you wish to escalate, you may contact the ICO:
Information Commissioner’s Office www.ico.org.uk 0303 123 1113
12. Contact us
Stabilisation & Growth Advisory
Email: contact@stabilisationgrowthadvisory.co.uk
Registered Office Address: 48 Turnstone Way, Huddersfield, HD4 5FA, United Kingdom
