Privacy Policy

Last updated: August 2025

FAI Consultancy ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller Information

Data Controller: Francesca Fay Wood
Trading as: FAI Consultancy
Business Address: Manhay Farm, Manhay, Helston, TR13 0NJ
Email: hello@faiconsultancy.com
ICO Registration: Not required to register

We act as the data controller for all personal data collected through our website and services.

2. What Personal Data We Collect

Information You Provide Directly:

  • Contact details: Name, email address, phone number, business name, job title

  • Communication data: Messages, enquiries, feedback, survey responses

  • Account information: Login credentials, preferences, subscription details

  • Payment information: Billing address, payment method details (processed by our payment providers)

  • Professional information: Business requirements, project details, industry sector

Information We Collect Automatically:

  • Technical data: IP address, browser type and version, device type, operating system

  • Usage data: Pages visited, time spent on site, click patterns, referral sources

  • Cookie data: As detailed in our Cookie Notice below

Information from Third Parties:

  • Social media: If you interact with us on social platforms

  • Professional networks: LinkedIn profile information if you connect with us

  • Referrals: Contact details shared by mutual connections (with their consent)

3. Legal Basis for Processing

We process your personal data on the following legal bases:

Contract (Article 6(1)(b)):

  • Providing consultancy services

  • Processing payments

  • Delivering digital products and training

Legitimate Interests (Article 6(1)(f)):

  • Website analytics and improvement

  • Business communications and relationship management

  • Fraud prevention and security

  • Marketing to existing clients about similar services

Consent (Article 6(1)(a)):

  • Email marketing to prospects

  • Non-essential cookies

  • Optional data collection (surveys, testimonials)

Legal Obligation (Article 6(1)(c)):

  • Tax and accounting records

  • Compliance with regulatory requirements

4. How We Use Your Personal Data

Service Delivery:

  • Provide consultancy, training, and digital products

  • Process payments and manage subscriptions

  • Provide customer support and respond to enquiries

  • Manage our contractual relationship with you

Business Operations:

  • Maintain accurate business records

  • Analyse website usage and improve user experience

  • Develop new services and offerings

  • Comply with legal and regulatory obligations

Marketing and Communications:

  • Send service updates and important notices

  • Share relevant industry insights and resources (with consent)

  • Invite you to events, webinars, or training sessions

  • Display targeted advertising on third-party platforms

You can opt out of marketing communications at any time using the unsubscribe link or by contacting us.

5. Data Sharing and Third-Party Processors

We never sell your personal data. We share data only with trusted processors who help deliver our services:

Essential Service Providers:

  • Payment processors (PayPal, Stripe): Secure payment processing

  • Email service (Mailchimp): Newsletter delivery and marketing automation

  • Analytics (Google Analytics): Website performance and usage insights

  • Automation tools (Zapier): Workflow automation between systems

  • Cloud storage (Google Workspace): Secure data storage and collaboration

  • Video conferencing (Zoom): Training and consultation delivery

Professional Services:

  • Accountants and legal advisors: As required for business compliance

  • IT support providers: For technical maintenance and security

All processors are bound by data processing agreements ensuring they:

  • Process data only on our instructions

  • Implement appropriate security measures

  • Delete or return data when requested

  • Comply with UK GDPR requirements

Legal Disclosures:

We may disclose personal data if required by law, court order, or to protect our legal rights.

6. International Data Transfers

Some of our processors may transfer data outside the UK. Where this occurs, we ensure appropriate safeguards are in place:

  • Adequacy decisions: Transfers to countries with adequate data protection

  • Standard Contractual Clauses: For transfers to other countries

  • Certification schemes: Such as Privacy Shield successors

Current international processors include:

  • Mailchimp (USA): Protected by Standard Contractual Clauses

  • Google Analytics (USA): Protected by Google's data transfer safeguards

  • Zapier (USA): Protected by Standard Contractual Clauses

7. Data Retention

We retain personal data only for as long as necessary:

Client Data:

  • Active clients: Throughout our relationship plus 6 years for tax purposes

  • Former clients: 6 years after final transaction (legal requirement)

  • Project data: 3 years after project completion

Marketing Data:

  • Newsletter subscribers: Until you unsubscribe

  • Prospects: 2 years from last meaningful contact

  • Website analytics: 26 months (Google Analytics default)

Financial Data:

  • Payment records: 6 years (legal requirement)

  • Tax records: 6 years (legal requirement)

Data is securely deleted when retention periods expire, unless we have a legal obligation to retain it longer.

8. Your Data Protection Rights

Under UK GDPR, you have the following rights:

Right of Access (Article 15):

Request a copy of personal data we hold about you

Right of Rectification (Article 16):

Correct inaccurate or incomplete data

Right of Erasure (Article 17):

Request deletion of your data (subject to legal obligations)

Right to Restrict Processing (Article 18):

Limit how we use your data in certain circumstances

Right to Data Portability (Article 20):

Receive your data in a structured format

Right to Object (Article 21):

Object to processing based on legitimate interests or for marketing

Right to Withdraw Consent (Article 7(3)):

Withdraw consent for consent-based processing

Right to Lodge a Complaint:

Contact the ICO if you're unhappy with how we handle your data

To exercise these rights, contact us at: hello@faiconsultancy.com

We'll respond within one month and provide the service free of charge (unless requests are excessive).

9. Data Security

We implement appropriate technical and organisational measures to protect your data:

Technical Measures:

  • SSL/TLS encryption for data transmission

  • Secure cloud storage with access controls

  • Regular software updates and security patches

  • Multi-factor authentication for sensitive systems

Organisational Measures:

  • Staff training on data protection

  • Access controls limiting who can view personal data

  • Regular review of data processing activities

  • Incident response procedures for data breaches

Data Breach Procedure:

In the unlikely event of a data breach, we will:

  • Assess the risk and take immediate containment action

  • Report to the ICO within 72 hours if required

  • Notify affected individuals if there's a high risk to their rights

  • Document the breach and our response

10. Cookies and Tracking Technologies

Our website uses cookies and similar technologies. See our Cookie Notice below for full details.

Cookie Categories:

Strictly Necessary: Essential for website functionality

  • Session management

  • Security and fraud prevention

  • Load balancing

Analytics: Help us understand website usage

  • Google Analytics (anonymised)

  • Hotjar (user behaviour analysis)

Marketing: Personalise advertising and measure effectiveness

  • Facebook Pixel

  • LinkedIn Insight Tag

  • Google Ads

Preferences: Remember your choices and settings

  • Language preferences

  • Cookie consent choices

You can manage cookie preferences in your browser or through our cookie consent tool.

11. Children's Privacy

Our services are not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make significant changes:

  • We'll update the "Last updated" date

  • We'll notify active clients by email

  • We'll highlight key changes on our website

  • Continued use of our services constitutes acceptance of updates

13. Contact Us

For any questions about this Privacy Policy or your data rights:

Email: hello@faiconsultancy.com
Post: Manhay Farm, Manhay, Helston, TR13 0NJ

Information Commissioner's Office (ICO):
If you're not satisfied with our response, you can contact the ICO:

  • Website: ico.org.uk

  • Phone: 0303 123 1113

  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF


Cookie Notice

What Are Cookies?

Cookies are small text files stored on your device when you visit websites. They help websites remember your preferences and improve your experience.

Cookies We Use:

Essential Cookies (Always active):

  • Session cookies: Keep you logged in during your visit

  • Security cookies: Protect against fraud and attacks

  • Functionality cookies: Remember your language and region preferences

Analytics Cookies (Can be disabled):

  • Google Analytics: Understand how visitors use our site

    • Data collected: Pages visited, time on site, bounce rate

    • Retention: 26 months

    • Opt-out: Available through Google Analytics opt-out

Marketing Cookies (Require consent):

  • Facebook Pixel: Show relevant ads on Facebook

  • LinkedIn Insight Tag: Professional advertising and analytics

  • Google Ads: Personalised advertising across Google properties

Managing Cookies:

Browser Settings: You can disable cookies in your browser settings, though this may affect website functionality.

Opt-out Tools:

  • Google Analytics: Google Analytics opt-out

  • Facebook: Ad preferences in your Facebook account

  • LinkedIn: Ad preferences in your LinkedIn account

Cookie Consent: You can update your cookie preferences using Podia's built-in consent tool or through your browser settings.


Version: 1.0 (August 2025)