Privacy Policy

Last updated: June 2026

1. Introduction

Smiling CFO Limited (“Smiling CFO”, “we”, “us” or “our”) is committed to protecting your privacy and handling personal information responsibly.

This Privacy Policy explains how we collect, use, store, share and protect personal information when you:

  • visit our website;
  • contact us by email, telephone, website form or other communication method;
  • complete our Mental Availability Review or any other assessment, diagnostic or enquiry form;
  • subscribe to receive insights, updates or marketing communications;
  • engage us to provide services;
  • interact with our content, events, downloads or business development activity.

By using this website, you acknowledge that your personal information may be processed as described in this Privacy Policy.

2. Who we are

Smiling CFO Limited is the controller responsible for your personal information.

Smiling CFO Limited is registered in England and Wales under company number 14725946.

Registered office: The Counting House, 61 Charlotte Street, St Paul’s Square, Birmingham, United Kingdom, B3 1PX.

Email: hello@smilingcfo.co.uk.

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at hello@smilingcfo.co.uk.

3. Information we collect

Depending on how you interact with us, we may collect and process the following categories of personal information.

4. How we collect information

  • directly from you;
  • through website forms, assessment forms and downloads;
  • through the Mental Availability Review or similar tools;
  • through email, telephone, video calls and other communications;
  • through website analytics technologies, where you have provided consent where required;
  • through cookies and similar technologies;
  • from publicly available business sources, professional networks or referrals, where relevant to business-to-business contact.

5. How we use information and our lawful bases

We only use personal information where we have a lawful basis to do so. The table below summarises the main ways we use personal information.

Client, enquiry and assessment activity

Website, marketing and business administration

6. Marketing communications

We may send occasional insights, updates and information about our services where you have opted in, where you are an existing client or business contact and the communication relates to similar services, or where we are otherwise permitted to contact corporate subscribers under applicable law.

Every marketing email will identify us clearly and include a simple way to opt out. You can unsubscribe at any time by clicking the unsubscribe link included in our emails or by contacting us at hello@smilingcfo.co.uk.

Completing an enquiry form, downloading a resource or completing the Mental Availability Review does not automatically subscribe you to marketing communications unless the relevant form clearly states this or you separately opt in.

We do not sell personal information to third parties.

7. Mental Availability Review and assessment information

When you complete the Mental Availability Review or a similar assessment, we use the information provided to generate and deliver your results, understand how organisations engage with our services, improve our assessment processes and support relevant follow-up discussions.

We may use aggregated or anonymised information from reviews and assessments to improve our methods, develop benchmarks, identify market-level patterns and improve our services. We will not publish information that identifies you or your organisation without permission.

8. Website analytics

We use Google Analytics to understand how visitors use our website and to improve website performance and user experience.

Google Analytics may collect information including pages visited, device type, browser information, approximate location, time spent on pages and website interactions.

Google Analytics cookies are only activated where you provide consent through our cookie preferences system. You can change your cookie preferences at any time through the cookie settings tool on our website.

9. Cookies and similar technologies

We use cookies and similar technologies as described in our Cookie Policy. Non-essential analytics, functional or marketing cookies are only used where consent is required and has been provided.

10. Website security and system logs

Our website hosting providers and technical systems may automatically collect technical information including IP addresses, access times, browser information, error logs and security information. This information is processed for security, monitoring, maintenance, troubleshooting and fraud-prevention purposes.

11. Sharing information

We may share personal information with trusted service providers and advisers who help us operate our business, including:

  • website hosting providers;
  • website developers and support providers;
  • WordPress plugins and website technology providers;
  • email and business communication providers;
  • analytics providers;
  • assessment, form or survey platform providers;
  • CRM or mailing list providers;
  • cloud storage and document management providers;
  • professional advisers, including accountants and legal advisers;
  • legal, regulatory, tax or public authorities where required.

Where service providers process personal information on our behalf, they are required to process it securely, only for authorised purposes and in accordance with applicable data protection requirements.

12. International transfers

Some of our service providers may process personal information outside the United Kingdom. Where our providers process personal information outside the UK, we rely on recognised safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses or other lawful transfer mechanisms.

13. Data retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to meet legal, accounting, tax, reporting or dispute-resolution requirements.

14. Data security

We maintain appropriate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, misuse, alteration or disclosure.

These measures may include access controls, password protection, multi-factor authentication where available, secure cloud services, restricted administration access, backups, software updates and supplier security controls.

Access to personal information is restricted to authorised individuals who require it for legitimate business purposes.

15. Personal data breaches

If we become aware of a personal data breach, we will assess the nature and impact of the breach and take appropriate steps to contain, investigate and remedy it. Where required by law, we will notify the Information Commissioner’s Office and/or affected individuals.

16. Your rights

Under UK data protection law, you may have the right to:

  • access your personal information;
  • correct inaccurate or incomplete personal information;
  • request deletion of personal information;
  • restrict processing;
  • object to processing;
  • request transfer of personal information;
  • withdraw consent where processing relies on consent.

Requests should be sent to hello@smilingcfo.co.uk. We may need to verify your identity before responding to a request.

17. Complaints

If you have concerns about our use of personal information, please contact us first at hello@smilingcfo.co.uk.

You also have the right to complain to the Information Commissioner’s Office (ICO). The ICO website is www.ico.org.uk.

18. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be published on this page together with the revised update date.