Privacy and Cookie Policy

This policy sets out how Link Stone Advisory Limited uses and protects personal information about you. It should be read alongside our Terms of Business, clause 7 of which sets out the data protection terms that apply to client engagements.

The short version

  • We take our responsibility for your data seriously, and we keep it safe
  • You have rights over your data, and we will help you exercise them
  • We collect some personal data from you, and only what we need
  • We use it to answer your enquiries, deliver the services you ask for, and meet our legal and professional obligations
  • Where we verify identities for Companies House, we are required by law to collect identity documents and keep records of the checks
  • We never sell, trade or rent your data
  • We will tell you before we share your data, unless the law requires us not to
  • When we no longer need it, we delete it
  • Our website uses only the cookies needed to make it work. No tracking, no advertising cookies
  • You can contact our Data Protection Lead at any time at dataprivacy@linkstoneadvisory.com

Our commitment to privacy

This Privacy Policy sets out how Link Stone Advisory Limited (“Link Stone Advisory”, “we”, “us”, “our”) uses and protects the personal information about you that we collect or that you provide, in accordance with applicable UK data protection law. This includes personal information from the public domain, from our previous interactions with you, through your use of our website, and when you become a client, participate in our programmes or online applications, or sign up to receive updates from us.

Changes to this policy

Any changes we make will be posted on this page and, where appropriate, notified to you by email. Please check back periodically for updates.

Our role

Under clause 7.2 of our Terms of Business, we and our clients are each independent data controllers in relation to personal data provided to us during an engagement. This means we determine our own purposes and means for that data, and we are responsible for it under data protection law.

Where a member of our team holds a directorship or other office in a client company, information they receive in that capacity belongs to that company, and the company is the controller for it.

Information about you

We may collect and process personal information from you in various ways, for example if you:

  • Contact us by phone, email, online using a form on our website, face-to-face or otherwise in writing
  • Become a registered user of our website, or become a client
  • Request further information about a service
  • Complete an online form to access content, a report or updates
  • Register for or purchase services from us
  • Ask us to verify your identity for Companies House purposes, or are an individual whose identity we are asked to verify
  • Are an officer, shareholder or other key stakeholder of a client, whose identity we are required to confirm
  • Engage with us on a social media platform
  • Enter a competition or prize draw, or complete a survey
  • Submit a job application
  • Visit our website (see the Cookie Policy section below)
  • Report a problem with our website, an event or a service
  • Provide consent for marketing to be sent to you
  • Discuss our services with us, or are recommended to us by a prior or current client
  • Are contacted by us as a prospective client
  • Work for an organisation that is an existing, prior or prospective client

Types of personal data we collect

Identity data. First name, last name, title, username, email address or similar identifier, phone number, social media links, photograph, CV and other information about your qualifications and your right to work, if you choose to provide such details.

Identity verification data. Where we verify your identity for Companies House purposes, or confirm identity for anti-money-laundering purposes, copies of government-issued identity documents, the name, date of birth and address shown on them, and our record of the checks carried out.

Contact data. Billing address, delivery address, names, email address and telephone numbers.

Work data. Job title, company details, email address, username or similar identifier, phone number, country or location, team size, job history, social media links, development goals and account management notes.

Technical data. Internet protocol (IP) address, login data, browser type and version, time zone setting and location, operating system and platform.

Transaction data. Details about payments to and from you or your company, amounts, and other details of services you have purchased from us.

Financial data. Bank account or payment card details, billing name, billing address, billing email.

Profile data. Username and password, orders made by you, your interests, preferences, feedback and survey responses, social media links, and account management notes.

Usage data. Aggregate and anonymous information about how our website is used, and information about how you engage with communications we send you.

Marketing and communications data. Your preferences in receiving marketing from us and your communication preferences.

Special categories of personal data

As an employer, and when performing HR engagements for clients, we may collect special categories of personal data. This includes details about racial or ethnic origin, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health, and genetic and biometric data. We may also process information about criminal convictions and offences, which is subject to separate safeguards under UK data protection law.

Anti-money-laundering screening, including sanctions and politically exposed person checks, may reveal political opinions and information about criminal convictions or alleged offences.

Because of the sensitive nature of this information, we apply additional controls:

  • Purpose limitation. We process special category data only for the specific, explicit and legitimate purposes disclosed to you at the time of collection.
  • Information barriers. Colleagues not directly involved in your matter do not have access to the data.
  • Role-based access control. Access is limited on a need-to-know basis.
  • Confidentiality. All personnel permitted to access this data are bound by binding confidentiality obligations and professional codes of conduct.
  • Technical safeguards. Special category data is encrypted in storage and in transit.

We maintain an Appropriate Policy Document explaining how we comply with the data protection principles when processing special category and criminal offence data. It is available on request.

Other than in the circumstances described above, our policy is not to ask you for sensitive personal data. If you choose to provide it to us unprompted, you consent to us using that information for the reason explained at the time you provide it.

Identity verification as an Authorised Corporate Service Provider

We are registered with Companies House as an Authorised Corporate Service Provider. In that capacity we carry out identity verification for individuals including company directors, people with significant control, and members of limited liability partnerships, as required by the Economic Crime and Corporate Transparency Act 2023.

What we collect. Government-issued photographic identity documents, such as a passport, driving licence or national identity card; your name, date of birth and address as shown on those documents; and a record of the checks performed, the documents relied upon, and the outcome.

How we carry out the check. Our identity checks are carried out manually. A member of our team examines your identity document and compares it with you, either in person or by video call. We do not use facial recognition software, automated identity verification platforms or any other technology that performs biometric matching, and we do not create biometric data from your photograph.

Our lawful basis. We process this information because we are under a legal obligation to do so as an Authorised Corporate Service Provider under the Economic Crime and Corporate Transparency Act 2023 and associated regulations.

If you do not provide it. We cannot complete a verification without this information. If it is not provided, we are unable to confirm your identity to Companies House, which may prevent you from being appointed or from continuing in a role that requires verification.

Who we share it with. We provide verification statements to Companies House. We are required to keep records of the checks and the evidence relied upon, and to make them available to the Registrar of Companies, to our anti-money-laundering supervisory authority, and to law enforcement where required by law.

How long we keep it. We retain identity verification records, including copies of the photographic identity documents relied upon, for 7 years. We keep the document copy because we are required to record which documents we checked, and photographic identification is a specified requirement. A record of the check without the underlying evidence would not demonstrate that the requirement was met.

If you are not our client. We may verify the identity of individuals who are not themselves our clients, for example a director of a company that engages us. Where we do, we are the data controller for that verification and this policy applies to it.

If you do not provide personal data

Where we need to collect personal data by law, or in order to act on your instructions or perform a contract with you, and you do not provide that data when asked, we may not be able to act on your instructions or perform the contract. This applies in particular to the client identification and anti-money-laundering checks described in clause 2.1 of our Terms of Business, and to identity verification as described above. As our Terms of Business record, if we are unable to obtain satisfactory evidence of identity we cannot proceed with the engagement.

Providing your details in order to download a report or receive updates from us is always optional.

Recording and transcription of meetings

We may record and transcribe meetings and calls to produce accurate notes and summaries, using the tools listed below. Where we intend to record, we will tell you at the start of the meeting and proceed only with the agreement of those taking part. Recordings and transcripts are treated as confidential client information and are subject to the same access controls, retention periods and professional confidentiality obligations as our other engagement records.

Information we receive from other sources

We work with third parties including event organisers, webinar and podcast providers, sub-contractors in payment and delivery services and search information providers, and may receive personal data about you from them.

We may record information about you that is publicly available from sources such as LinkedIn, corporate websites, industry websites and online directories. We may then research further details by contacting your company directly or searching online. We may also make searches of appropriate databases as part of our client identification obligations.

If you apply for a job with us, we may receive information about you from your referees and former employers. If you use our pages on social media platforms, we may collect personal data you provide via those platforms in accordance with the policies of the applicable platform.

Personal data about other people

If you provide personal data to us about anyone other than yourself — colleagues, personnel, relatives, next of kin, referees, clients, advisers or suppliers — you must ensure they have given permission for you to disclose it to us and for us to use it in accordance with this policy. This reflects clause 7.3 of our Terms of Business.

Uses we make of personal data

Direct marketing. Where you have expressly consented in accordance with applicable law, where you have purchased services from us, or where we otherwise have a legitimate interest or legal right, we may contact you by telephone or electronic message with information about our services. We may also contact you by post from time to time unless you have told us you do not want to receive these communications. You can unsubscribe using the link in our emails at any time, or by emailing dataprivacy@linkstoneadvisory.com.

Transactional purposes. To provide you with information you request and to carry out our obligations under any contract between us.

Website administration and improvement. To manage access to our content and resources; to present our website effectively; to understand in aggregate how our website is used; to notify you about changes to our services or website; and to keep our website safe and secure.

Marketing analysis. To analyse how recipients engage with communications we send, with a view to improving our marketing materials and making relevant suggestions about services that may interest you.

Internal administration and analysis. To process job applications, administer our database, and carry out data analysis, research and statistical analysis.

Regulatory and professional obligations. To meet our obligations as a firm regulated by the Institute of Chartered Accountants in England and Wales and as an Authorised Corporate Service Provider, including client identification, anti-money-laundering checks, identity verification, conflict checks and record keeping.

Legal compliance. To comply with any relevant legal obligations.

Profiling

We may occasionally use personal data to conduct profiling of individuals on our database. This helps us target communications in a more focused and relevant way, and reduces the chance of individuals receiving communications that do not apply to them.

To do this we may cross-check certain personal data against public sources such as a company website, and analyse how you engage with emails we send you in order to understand your interests and preferences.

Our profiling is limited to marketing purposes. We do not make automated decisions based solely on profiling that produce legal effects concerning you or similarly significantly affect you. You have the right to object to the use of your personal data for profiling at any time. Email dataprivacy@linkstoneadvisory.com and we will stop.

Legal basis and obligations

We collect and process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR); the Data Protection Act 2018; the Privacy and Electronic Communications Regulations (PECR); the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017; the Economic Crime and Corporate Transparency Act 2023 and associated regulations; the code of ethics and regulations of the Institute of Chartered Accountants in England and Wales; and other applicable data protection and privacy laws.

Data controller

The data controller is Link Stone Advisory Limited, registered in England and Wales, company number 12327242, registered office 28 Brock Street, Bath, BA1 2LN.

We are registered with the Information Commissioner’s Office under registration reference ZA566853, which can be inspected on the ICO register at ico.org.uk. Our Data Protection Lead can be contacted at dataprivacy@linkstoneadvisory.com.

Legal bases for processing

  • Consent — where you have given clear consent for a specific purpose, such as marketing communications
  • Contract — where processing is necessary for a contract with you, or to take steps at your request before entering into one
  • Legal obligation — where we need to comply with the law or our regulatory obligations, including client identification, anti-money-laundering requirements and identity verification
  • Substantial public interest — for special category data processed in connection with anti-money-laundering and the prevention or detection of unlawful acts, relying on paragraph 10 of Schedule 1 to the Data Protection Act 2018
  • Legitimate interests — where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights

Disclosing personal data to third parties

We never sell, trade or rent personal data. We may disclose your personal data to:

  • Cloud service and productivity providers — Google Ireland Limited and Google LLC for Google Workspace, and Microsoft Ireland Operations Limited for Microsoft 365, which provide our email, document management, file storage and collaboration tools.
  • Companies House — verification statements and supporting records, as described above.
  • Subcontracted consultants — we may subcontract work on your affairs to other consultants, who are bound by our client confidentiality terms, as provided in clause 5.4 of our Terms of Business.
  • Independent quality control reviewers — our files are periodically reviewed by an independent regulatory or quality control body as part of our commitment to service quality, as provided in clause 4.3 of our Terms of Business. Reviewers are bound by the same confidentiality obligations as our own directors and staff.
  • Funding introducers — where you ask us to explore funding options, we may share your details with Swoop Finance Limited or FundSurfer Limited under the arrangements described in clauses 3.3 and 3.4 of our Terms of Business. We will always tell you before we do so.
  • Our professional indemnity insurers and advisers — where necessary in connection with a claim or potential claim.
  • Authorities, regulators and law enforcement — including the ICAEW, Companies House, HMRC and the National Crime Agency, where we are under a legal or regulatory duty to disclose, including reporting obligations under anti-money-laundering legislation.
  • Referees or employers — if you are making a job application and ask us to contact them.

We aim to ensure that personal data we pass to third parties is used only for lawful purposes in accordance with this policy and appropriate data processing agreements.

International data transfers

Data we collect from you may be transferred to, and stored at, a destination outside the United Kingdom, and may be processed by staff operating outside the UK who work for us or for one of our suppliers. Where we transfer personal data outside the UK we ensure appropriate safeguards are in place, including adequacy regulations, UK-approved Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework.

Our providers

  • Google Workspace — productivity and collaboration, including email, file storage and shared workspaces.
  • Google Fonts — our website uses typefaces served by Google Fonts. Your browser requests the font files from Google when a page loads, which makes your IP address visible to Google. No cookies are set by this.
  • Microsoft 365 — productivity suite including Teams, Outlook and SharePoint.
  • Plaud — PLAUD Inc, transcription and summarisation of meeting audio.
  • HubSpot, Inc. — customer relationship management and email marketing. We do not use HubSpot tracking code on our website.
  • Xero — accounting systems and client financial processing.
  • Syft — Syft Analytics Inc, reporting and financial analysis.
  • Fathom — Access Workspace Australia Pty Ltd, reporting and financial analysis.
  • Automattic Inc. — WordPress.com and Jetpack, which host our website and process submissions made through our website forms.

Artificial intelligence and machine learning

We use machine learning and artificial intelligence capabilities powered by Claude, a large language model provided by Anthropic, PBC, accessed through Anthropic’s commercial service tiers and application programming interfaces.

When we use these tools, text inputs, uploaded files and context metadata are transmitted to Anthropic. Under Anthropic’s commercial terms, data submitted through our deployment is segregated, is not used to train models, and operational logs are deleted within seven days. We do not use these tools to process identity verification documents.

Connected systems. Our systems may use the Model Context Protocol, an open integration standard, to connect the model securely with external tools such as file storage or customer relationship management. Where a query requires external information, a contextual request is routed to an authorised server. Data retrieved this way is held in memory to generate a response and is not persistently retained by the integration layer. Depending on the tools enabled, data may flow between Anthropic and the providers of those connected systems, whose own privacy terms apply.

Data retention

We retain your personal data only for as long as reasonably necessary, including to satisfy legal, regulatory, tax, accounting or reporting requirements. We may retain data for longer in the event of a complaint or where we reasonably believe there is a prospect of litigation.

  • Marketing contacts. Up to 3 years from the date of last engagement.
  • Client relationship and engagement data. 7 years following the end of the business relationship.
  • Identity verification records, including copies of identity documents. 7 years, as required by the regulations governing Authorised Corporate Service Providers.
  • Client due diligence and anti-money-laundering records. 5 years from the end of the business relationship or completion of the transaction, as required by the Money Laundering Regulations 2017. Where records are held longer under our client engagement or identity verification retention, the longer period applies.
  • Financial and transaction data. 7 years from the end of the financial year in which the transaction occurred.
  • Meeting recordings and transcripts. Retained as part of the engagement record and deleted in line with the client retention period.
  • Job applications. Unsuccessful applications retained for 6 months, or up to 3 years with your consent.
  • Legal claims. Until the claim is resolved and any appeal period has expired.

For further detail, contact dataprivacy@linkstoneadvisory.com

Security

We employ appropriate technical and organisational security measures to protect personal data from unauthorised access and against unlawful processing, accidental loss, destruction and damage. These include encryption of data in transit and at rest, access controls and authentication measures, staff training, incident response procedures, and due diligence on the processors we engage.

As our Terms of Business record, electronic communication is not entirely secure. There are inherent risks in sending information over public networks, and we cannot guarantee the security of data transmitted to us.

Links to third-party websites

Our website may contain links to and from other websites. Those websites have their own privacy policies and we do not accept responsibility or liability for them or for their processing of your data.

Your rights

Under UK data protection law you have the following rights:

  • Right of access — to request information about the personal data we hold about you, what we use it for and who it may be disclosed to.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to have your data erased in certain circumstances.
  • Right to restrict processing — in certain circumstances, such as where you contest the accuracy of the data.
  • Right to data portability — to have your data transferred to another organisation in a commonly used, machine-readable format where technically feasible.
  • Right to object — to processing based on legitimate interests, to direct marketing including profiling for marketing purposes, and to processing for research or statistical purposes.
  • Right to withdraw consent — at any time, where we rely on consent.
  • Right not to be subject to automated decision-making that produces legal effects or similarly significantly affects you.

You are not required to pay a charge for exercising your rights. To exercise them, email dataprivacy@linkstoneadvisory.com or write to us at our registered address. We will respond within one month, which may be extended by two further months for complex requests. We may request additional information to verify your identity.

Limitations. We are not required to rectify or erase your data where doing so would prevent you from meeting your contractual obligations to us, or where we are legally or professionally required to retain copies. In particular, we cannot erase identity verification records or anti-money-laundering records before the end of the retention periods above, because we are required by law to keep them.

Right to complain

If you are not satisfied with our response, or believe we are processing your personal data other than in accordance with applicable law, you may complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Website ico.org.uk, helpline 0303 123 1113. We would ask that you contact us first so that we have the opportunity to address your concerns.

Contact

Data Protection Lead
Link Stone Advisory Limited
28 Brock Street, Bath, BA1 2LN
dataprivacy@linkstoneadvisory.com


Cookie Policy

A cookie is a small text file stored on your computer, tablet or phone when you visit a website. Cookies allow a website to recognise your device and to function correctly as you move between pages.

We use strictly necessary cookies only. These are the cookies required for our website to work — for example to maintain your session while you browse, to keep the site secure, and to remember that you have submitted a form. Under UK law, strictly necessary cookies do not require your consent, though you can block them through your browser settings.

We do not use analytics, advertising, targeting or social media tracking cookies. We do not operate advertising pixels, we do not follow you across other websites, we do not build advertising profiles, and we do not share website data with advertising networks.

Our website statistics are collected by our hosting provider without placing cookies on your device. They tell us how many people visited a page. They are aggregated and anonymous, and are not used to identify you.

Fonts. Our website uses typefaces served by Google Fonts. Your browser requests these files from Google when a page loads, which makes your IP address visible to Google. This does not set a cookie and is not used to track you.

Controlling cookies. Most browsers automatically accept cookies unless you change your settings. You can restrict, block or delete cookies through your browser settings, usually found in the options or preferences menu. Because we use strictly necessary cookies only, blocking them may mean you cannot access all or parts of our site.

We may update this Cookie Policy from time to time. If we introduce analytics or other non-essential cookies in future, we will ask for your consent before doing so and update this policy accordingly.

Privacy and Cookie Policy — August 2026