Our Privacy Policy.

Privacy Policy

How Louisa Clow Advisory handles personal information

Last updated: 1 August 2026

1. Who we are

Louisa Clow Advisory Ltd ("LCA", "we", "us" or "our") is an independent governance, risk and compliance advisory business. For the purposes of UK data protection law, LCA is the controller of the personal information described in this notice.

Company number SC895050 | Registered office: Rosslyn, 22 Knox Wynd, Scotland. ML10 6XX. | Registered in Scotland | Privacy contact [email protected]

2. When this policy applies

This policy applies when you visit our website, contact us, book or attend an introductory meeting, receive marketing from us, engage us or interact with us in a professional capacity. Separate contractual privacy terms may apply to client assignments where LCA processes information on a client’s instructions.

3. Personal information we collect

  • Contact and professional details, including name, role, organisation, work email address, telephone number and LinkedIn or other professional profile information

  • Enquiry and relationship information, including messages, meeting notes, stated requirements, proposed budgets, desired start dates and records of our communications

  • Client and engagement information needed to prepare proposals, enter contracts, deliver services, issue invoices, manage suppliers and maintain business records

  • Website and device information, such as IP address, device and browser details, pages visited, referral source and cookie preferences

  • Marketing preferences, objections and suppression records

  • Information obtained from professional contacts, referrals, public registers, company websites, LinkedIn and other legitimate public sources

Please do not submit confidential client information, criminal offence data, health information or other special category data through the public website form unless we have specifically asked you to do so using an appropriate secure method.

4. How we use personal information and our lawful basis

Purpose Lawful Basis
Responding to enquiries and arranging meetings To take steps at your request before entering into a contract; legitimate interests in developing and operating our business.
Preparing proposals and delivering services Contract; legitimate interests; legal obligations where applicable.
Managing client, supplier and professional relationships Contract; legitimate interests in administration, service quality and relationship management.
Keeping financial, tax, insurance and corporate records Legal obligation; legitimate interests in establishing, exercising or defending legal rights.
Operating, securing and improving the website Legitimate interests for essential security and performance; consent for non-essential cookies and analytics where required.
Sending relevant professional updates and B2B marketing Legitimate interests where appropriate; consent where the Privacy and Electronic Communications Regulations (PECR) require it. Every electronic marketing message will provide a clear way to opt out.
Preventing misuse and protecting legal rights Legitimate interests; legal obligation; establishment, exercise or defence of legal claims.

5. Marketing

We may contact business contacts about services, insights or events that are relevant to their professional role where we have a lawful basis to do so. We will not disguise our identity, and we will provide a valid way to opt out. We will obtain consent where required, including before sending unsolicited electronic marketing to individual subscribers such as sole traders unless a lawful exception applies. We maintain suppression records so that we can respect opt-outs.

6. Cookies and analytics

Our website uses essential cookies needed for security and functionality. We may also use analytics or similar technologies to understand website performance. Non-essential cookies will only be used where the required consent has been obtained. You can change your choices through the cookie settings tool. More detail is provided in our Cookie Policy.

7. Who we share information with

  • Website, hosting, IT, email, cloud storage, cybersecurity, booking, accounting and document-management providers.

  • Professional advisers, insurers, banks, auditors and service providers supporting our business.

  • Clients, suppliers, associates and subcontractors where necessary for an agreed engagement and subject to appropriate confidentiality and data protection arrangements.

  • Public authorities, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law.

  • A purchaser, investor or adviser involved in a proposed business reorganisation, subject to appropriate safeguards.

We do not sell personal information.

8. International transfers

Some service providers may process information outside the United Kingdom. Where this happens, we use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by law.

9. How long we keep information

Record Indicative Retention
Unsuccessful enquiries and proposals Normally up to 24 months after the last meaningful contact, unless a longer period is justified.
Client engagement and contractual records Normally 7 years after the engagement ends, reflecting contractual, tax, insurance and legal requirements.
Financial and tax records Normally 6 years after the relevant accounting period, or longer where required by law.
Marketing records Until you opt out or the information is no longer relevant. Suppression records may be retained to ensure your marketing preferences continue to be respected.
Website analytics Retained in accordance with the configured retention period of the relevant analytics provider and your cookie preferences.

We may update this policy when our services, suppliers or legal obligations change. The latest version will be published on the website with an updated date. These are default periods, not absolute rules. We may keep information for longer where necessary for legal claims, regulatory matters, fraud prevention or another documented reason.

10. Security

We use proportionate technical and organisational measures to protect personal information, including access controls, secure cloud services, device security, multifactor authentication where available, confidentiality obligations, supplier due diligence and secure deletion practices. No online service can guarantee absolute security.

11. Your rights

  • Access your personal information and receive a copy.

  • Ask us to correct inaccurate or incomplete information.

  • Ask us to delete information in certain circumstances.

  • Ask us to restrict how information is used.

  • Object to processing based on legitimate interests and object at any time to direct marketing.

  • Request data portability where applicable.

  • Withdraw consent at any time where processing is based on consent.

  • Complain to the Information Commissioner’s Office.

To exercise a right, email [email protected]. We may need to verify your identity. You can also contact the ICO through ico.org.uk.

12. Children

Our website and services are intended for business and professional users and are not directed at children. We do not knowingly collect children’s personal information through the website.

13. Changes to this policy

We may update this policy when our services, suppliers or legal obligations change. The latest version will be published on the website with an updated date.