Smiling CFO Limited (“Smiling CFO”, “we”, “us” or “our”) is committed to protecting your privacy and handling personal information responsibly.
This Privacy Policy explains how we collect, use, store, share and protect personal information when you:
By using this website, you acknowledge that your personal information may be processed as described in this Privacy Policy.
Smiling CFO Limited is the controller responsible for your personal information.
Smiling CFO Limited is registered in England and Wales under company number 14725946.
Registered office: The Counting House, 61 Charlotte Street, St Paul’s Square, Birmingham, United Kingdom, B3 1PX.
Email: hello@smilingcfo.co.uk.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at hello@smilingcfo.co.uk.
Depending on how you interact with us, we may collect and process the following categories of personal information.
| Category | Examples |
|---|---|
| Identity information | First name, last name, job title and role. |
| Contact information | Email address, telephone number, business address and communication details. |
| Business information | Company name, website address, industry, category, brand, business context and other information relevant to an enquiry or project. |
| Enquiry and communication information | Information contained within emails, website forms, messages, call notes and other communications you send to us. |
| Mental Availability Review information | Information submitted through our Mental Availability Review or similar assessments, including responses, assessment data, diagnostic outputs and related business information. |
| Client and project information | Information required to scope, manage and deliver client work, including project communications, commercial records and deliverables. |
| Technical information | IP address, browser type, device information, operating system, website usage information, referring website information, cookie identifiers, logs and security data. |
| Marketing information | Your communication preferences, marketing consent records, unsubscribe records and engagement with marketing communications. |
We only use personal information where we have a lawful basis to do so. The table below summarises the main ways we use personal information.
| Purpose | Examples of personal information used | Lawful basis |
|---|---|---|
| Responding to enquiries | Name, business contact details and message content. | Legitimate interests and/or steps prior to entering into a contract. |
| Delivering Mental Availability Review results or similar assessment outputs | Contact details, company information and review responses. | Legitimate interests and/or steps prior to entering into a contract. |
| Providing services to clients | Contact details, project communications, deliverables and commercial records. | Contract, legitimate interests and, where required, legal obligation. |
| Managing client and business relationships | Contact details, role, company and communication history. | Legitimate interests. |
| Improving our services and methods | Assessment feedback and aggregated or anonymised review information. | Legitimate interests. |
| Purpose | Examples of personal information used | Lawful basis |
|---|---|---|
| Sending insights, updates and marketing communications | Name, business email address, role, preferences and opt-out records. | Consent, legitimate interests and/or another lawful basis permitted for B2B marketing. |
| Operating website analytics | Cookie identifiers, usage information, device/browser information and approximate location. | Consent for non-essential analytics cookies. |
| Protecting website security and maintaining systems | IP addresses, logs, access times, error reports and security information. | Legitimate interests. |
| Maintaining business, accounting and tax records | Client contact details, transaction information, invoices and contracts. | Legal obligation and legitimate interests. |
| Establishing, exercising or defending legal rights | Relevant communications, contracts, records and evidence. | Legitimate interests and/or legal obligation. |
We may send occasional insights, updates and information about our services where you have opted in, where you are an existing client or business contact and the communication relates to similar services, or where we are otherwise permitted to contact corporate subscribers under applicable law.
Every marketing email will identify us clearly and include a simple way to opt out. You can unsubscribe at any time by clicking the unsubscribe link included in our emails or by contacting us at hello@smilingcfo.co.uk.
Completing an enquiry form, downloading a resource or completing the Mental Availability Review does not automatically subscribe you to marketing communications unless the relevant form clearly states this or you separately opt in.
We do not sell personal information to third parties.
When you complete the Mental Availability Review or a similar assessment, we use the information provided to generate and deliver your results, understand how organisations engage with our services, improve our assessment processes and support relevant follow-up discussions.
We may use aggregated or anonymised information from reviews and assessments to improve our methods, develop benchmarks, identify market-level patterns and improve our services. We will not publish information that identifies you or your organisation without permission.
We use Google Analytics to understand how visitors use our website and to improve website performance and user experience.
Google Analytics may collect information including pages visited, device type, browser information, approximate location, time spent on pages and website interactions.
Google Analytics cookies are only activated where you provide consent through our cookie preferences system. You can change your cookie preferences at any time through the cookie settings tool on our website.
We use cookies and similar technologies as described in our Cookie Policy. Non-essential analytics, functional or marketing cookies are only used where consent is required and has been provided.
Our website hosting providers and technical systems may automatically collect technical information including IP addresses, access times, browser information, error logs and security information. This information is processed for security, monitoring, maintenance, troubleshooting and fraud-prevention purposes.
We may share personal information with trusted service providers and advisers who help us operate our business, including:
Where service providers process personal information on our behalf, they are required to process it securely, only for authorised purposes and in accordance with applicable data protection requirements.
Some of our service providers may process personal information outside the United Kingdom. Where our providers process personal information outside the UK, we rely on recognised safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses or other lawful transfer mechanisms.
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to meet legal, accounting, tax, reporting or dispute-resolution requirements.
| Data type | Typical retention period |
|---|---|
| General enquiries that do not become client engagements | Up to 24 months from the last meaningful interaction. |
| Mental Availability Review or assessment submissions | Up to 24 months unless the information becomes part of a client engagement, is required for legal or business reasons, or has been aggregated or anonymised. |
| Marketing contacts | Until you unsubscribe, object, there is a hard bounce, or the information is no longer required. Suppression records may be retained to ensure we do not contact you again. |
| Client project records | Up to 6 years following completion of services, unless a longer period is required to establish, exercise or defend legal claims. |
| Financial and tax records | As required by applicable accounting and tax legislation. |
| Website security logs | Usually 6 to 12 months unless needed for investigation, security, legal or technical reasons. |
We maintain appropriate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, misuse, alteration or disclosure.
These measures may include access controls, password protection, multi-factor authentication where available, secure cloud services, restricted administration access, backups, software updates and supplier security controls.
Access to personal information is restricted to authorised individuals who require it for legitimate business purposes.
If we become aware of a personal data breach, we will assess the nature and impact of the breach and take appropriate steps to contain, investigate and remedy it. Where required by law, we will notify the Information Commissioner’s Office and/or affected individuals.
Under UK data protection law, you may have the right to:
Requests should be sent to hello@smilingcfo.co.uk. We may need to verify your identity before responding to a request.
If you have concerns about our use of personal information, please contact us first at hello@smilingcfo.co.uk.
You also have the right to complain to the Information Commissioner’s Office (ICO). The ICO website is www.ico.org.uk.
We may update this Privacy Policy from time to time. Any changes will be published on this page together with the revised update date.