Legal
Privacy Policy
Last updated: 5 September 2026
Who we are
Exseed Advisory is the trading name of Mike Hubbard, a sole trader based in Shrewsbury, Shropshire, United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Mike Hubbard is the data controller for personal data collected through this website (exseed-advisory.uk) and in the course of providing advisory and software build services.
You can contact us about anything in this policy at [PRIVACY CONTACT EMAIL] or by phone on 07971 233535.
What this policy covers
This policy explains what personal data we collect when you visit this website, contact us, request a Sales Growth Assessment, subscribe to updates, or work with us as a client; why we collect it; how long we keep it; who we share it with; and the rights you have over it.
The data we collect
When you use the contact form or the "Bring us a problem" form we collect your name, email address, company name, the description of your business problem and, if you provide it, an indicative budget range.
When you request a Sales Growth Assessment we collect your name, email address, company name, team size and a description of your biggest sales challenge.
When you subscribe to updates we collect your email address and, optionally, your name.
When you become a client we collect the business contact details, correspondence, meeting notes and project documents needed to deliver the work, together with billing details for invoicing. Where a build involves your customers' or staff members' data, we act as a processor on your behalf under a separate written agreement and this policy does not cover that data.
When you browse the site our hosting provider records standard technical information such as your IP address, browser type, pages visited and the time of each request, in server logs used for security and performance. If you accept analytics cookies we also collect anonymised usage data (see Cookies below).
We do not knowingly collect data from anyone under 18, and we do not collect special-category data through this website.
Why we collect it and our lawful basis
We use your data to respond to your enquiry and to scope, propose and deliver the services you have asked about. Our lawful basis is that this processing is necessary to take steps at your request before entering into a contract, and to perform the contract once agreed.
We send updates and occasional marketing emails only to people who have subscribed or who are existing business contacts, on the basis of consent or, for business-to-business contacts, our legitimate interest in keeping in touch about relevant services. Every email includes an unsubscribe link and you can opt out at any time.
We keep server logs and use security tooling on the basis of our legitimate interest in keeping the site and our systems secure.
We keep invoices and accounting records because we are legally required to.
How long we keep it
Enquiries and assessment requests that do not lead to work are deleted after 12 months. Client records are kept for the duration of the engagement and for six years afterwards, in line with UK limitation periods and HMRC record-keeping requirements. Newsletter subscriptions are kept until you unsubscribe. Server logs are retained for no more than 90 days.
Who we share it with
We do not sell personal data. We share it only with the service providers we use to run the business, each under contract and only for the purpose described: our website hosting and form-handling providers; our email and calendar provider; our CRM and note-taking tools; our accounting software; and, where an engagement requires it, the contract specialists (for example security, DevOps or governance consultants) who work with us on your project, who are bound by confidentiality. We may also disclose data where the law requires it.
Some of these providers store data outside the UK. Where they do, transfers are protected by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
How we protect it
We apply the same discipline to our own systems that we apply to the ones we build for clients: access is limited to the people who need it, accounts are protected by multi-factor authentication, data is encrypted in transit and at rest by our providers, and we review the tools we use for their security posture. No system is completely secure, and we will tell you and the ICO without undue delay if a breach affecting your data occurs.
Cookies
This website uses strictly necessary cookies to remember your cookie preference. With your consent it also uses analytics cookies to understand which pages are used and how the site performs; this data is aggregated and does not identify you. You can accept or decline analytics cookies using the banner when you first visit, and change your mind at any time via the Cookies page. Declining has no effect on your ability to use the site.
Your rights
Under UK GDPR you have the right to access the personal data we hold about you; to have inaccurate data corrected; to have your data erased where there is no good reason for us to keep it; to restrict or object to our processing, including objecting to marketing at any time; to receive the data you gave us in a portable format; and to withdraw consent where consent is our basis for processing. To exercise any of these rights, email [PRIVACY CONTACT EMAIL]. We will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve any concern first.
Changes to this policy
We will post any changes on this page and update the date at the top. Significant changes will be flagged on the site.