Privacy Policy
How we handle personal data under the UK GDPR and the Data Protection Act 2018. Last updated 22 August 2026.
1. Who we are
Danneau Consulting (“we”, “us”) is a corporate finance and advisory firm based in London, United Kingdom. We are the data controller for personal data collected through this website.
Registered office and ICO registration details will be published here once confirmed. For any privacy question, contact us at privacy@danneauconsulting.co.uk.
2. Personal data we collect
- Contact form: your full name, business email address and the details of your enquiry.
- Consultation booking form: name, business email, company name, service area of interest, preferred timing and any context you provide.
- Client portal sign-up: name, business email, company name, password (stored only as a salted hash by our authentication provider), and the onboarding details you supply — industry, company website, company size, deal stage and engagement objectives.
- Portal activity: engagement records, deliverables, invoices and messages exchanged with your advisor.
- Technical data: limited server log and security data (such as IP address and timestamps) generated when you use the site.
We do not knowingly collect special category data through this website.
3. Why we use it, and our lawful basis
- Responding to enquiries and booking requests — legitimate interests (responding to a request you initiated) and, where an engagement follows, steps taken at your request prior to entering a contract.
- Operating the client portal — performance of a contract, or steps taken at your request prior to one.
- Market intelligence briefings — consent, which you may withdraw at any time.
- Security, record-keeping and legal compliance — legal obligation and legitimate interests.
4. How your data is stored
Website and portal data is stored in a managed PostgreSQL database and authentication service operated by Supabase, our hosting and infrastructure processor. Access is restricted by row-level security so that portal users can only read and write their own records. Data is encrypted in transit (TLS) and at rest by the platform.
Where a processor stores or accesses data outside the UK, transfers are made under the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses.
5. Sharing
We do not sell personal data. We share it only with service providers acting on our instructions (hosting, database and authentication, email delivery), with professional advisers where necessary, and with regulators or law enforcement where legally required.
6. Retention
Enquiry and booking records are kept for up to 24 months from your last contact with us unless an engagement begins. Client and engagement records are kept for the duration of the engagement and for six years afterwards, in line with normal professional and statutory record-keeping requirements. Portal accounts are deleted on request, subject to those retention obligations.
7. Your rights
Under the UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- request erasure where we no longer need the data;
- restrict or object to certain processing;
- data portability for data you provided to us;
- withdraw consent at any time where consent is the lawful basis.
To exercise any of these, email privacy@danneauconsulting.co.uk. We respond within one month. If you are unhappy with our response you may complain to the Information Commissioner’s Office at ico.org.uk.
8. Cookies
This site uses strictly necessary cookies only, unless you consent to more. See our Cookie Policy for detail and to change your choice.
9. Changes
We may update this notice from time to time. The date at the top of this page shows when it was last revised.