Last updated: [DATE — set this when you publish]
This policy is issued by [legal entity name, e.g. "Ascendry Ltd"], registered at [registered business address] ("Ascendry", "we", "us"). We are the data controller for the personal data described in this policy.
If you are a UK-based controller processing personal data at any real volume, you likely need to be registered with the ICO (Information Commissioner's Office) and pay the annual data protection fee unless a specific exemption applies — worth confirming this is in place, it is a real legal requirement separate from having this policy published.
From anyone visiting this website
From people who book a call with us
From clients who engage our services
From prospective clients we identify ourselves
Separately from the above, we identify potential clients to contact by analysing publicly available profile information on platforms like Instagram and YouTube (name, bio, follower count, and similar public profile data), using a third-party data tool (Apify). We do this to find businesses that may be a genuine fit for our services — see Section 5 for the legal basis and how to opt out.
If you have never contacted us but received an outreach message from Ascendry, your contact details were most likely sourced this way. We rely on legitimate interests as our legal basis: reaching out to genuinely relevant businesses is a normal and expected part of B2B outreach, we only use information you've made publicly available on your own professional profile, and we do not use it for any purpose beyond evaluating and initiating a potential business relationship.
You have the right to object to this processing at any time, free of charge. If you'd like us to stop processing your data or delete what we hold, contact us at [privacy contact email] and we will action this promptly.
We use the following third-party processors to run our business. Each only receives the data needed to perform their function:
We do not sell personal data to anyone. Some of these providers may process data outside the UK/EEA (typically the United States); where they do, they rely on their own approved safeguards (such as Standard Contractual Clauses) — confirm this against each provider's current DPA before publishing.
This site uses cookies that are strictly necessary for it to function (e.g. keeping you logged in), plus cookies set by Calendly, Wistia, and Stripe when those embeds are used.
There is currently no cookie consent banner on this site. Under UK PECR, non-essential cookies (which likely includes at least some of what Calendly/Wistia set) generally require consent before they load, separately from GDPR itself. Worth treating as a real follow-up, not just this policy page.
We keep client and financial records for as long as required by UK tax law (currently six years after the end of the relevant accounting period), and other personal data only for as long as it's needed for the purpose it was collected for, or until you ask us to delete it (subject to Section 9). Exact retention periods per data type: [set these deliberately rather than leaving them open-ended].
Under UK GDPR, you have the right to:
To exercise any of these, contact [privacy contact email].
We may update this policy as our tools or practices change. Material changes will be reflected with a new "last updated" date at the top of this page.
Questions about this policy or how your data is handled: [privacy contact email].