top of page
GOODISON ADVISORY
GOODISON ADVISORY

Privacy Notice
Version:
1.0
Effective date: 22 August 2026

1. Who we are 

Goodison Advisory Limited provides independent ERP strategy, selection and business transformation advice. For the processing described in this notice, Goodison Advisory will usually act as a data controller. During some client engagements, we may also process personal information solely on a client’s documented instructions, in which case the client is the data controller and Goodison Advisory acts as its processor. 

Company: Goodison Advisory Limited (company number 17270005) 

Registered office: C/O ESDG Accountancy Ltd, 44 Royal Parade Mews, London SE3 0TN, United Kingdom 

Website: www.goodisonadvisory.co.uk 

Privacy contact: privacy@goodisonadvisory.co.uk 
 

2. Personal information we collect and use 
 

We seek to collect and use only the personal information reasonably required for our business and advisory services. This will ordinarily include: 

name, business email address, business telephone number and business address; 

employer or organisation, job title, professional role and organisational position; 

enquiry, proposal, contract, engagement and correspondence records; 

meeting invitations, attendance, notes, decisions, actions and Teams-generated transcripts where transcription is enabled; 

professional contributions contained in project documents, requirements, evaluations and deliverables; 

complaint, dispute or claim correspondence; and 

technical information generated when you use our website or business systems, where applicable. 

Information we do not ordinarily require. We do not ordinarily require special-category personal information, personal payment-card information, personal financial information, passwords or authentication credentials. Please do not provide these unless we have specifically agreed that they are necessary and appropriate safeguards are in place. 
 

3. Why we use personal information 
 

to respond to enquiries and discuss possible engagements; 

to prepare proposals, enter into and manage contracts, and provide advisory services; 

to communicate with client, prospect and supplier representatives; 

to organise meetings and maintain appropriate records of discussions, decisions and actions; 

to manage client relationships and engagement records in our customer relationship management system; 

to operate, secure and improve our business and technology services; 

to meet legal, tax, accounting and regulatory obligations; and 

to establish, exercise or defend legal claims and deal with complaints. 
 

4. Our lawful bases 


Depending on the activity, we rely on one or more of the following lawful bases under UK data protection law: 

Contract: where processing is necessary to take steps at your request before entering into a contract, or to perform a contract with you. 

Legitimate interests: to operate a professional advisory business, manage relationships with corporate representatives, respond to enquiries, deliver and improve services, maintain proportionate business records, protect our systems and establish or defend claims. We consider the impact on individuals before relying on this basis. 

Legal obligation: where we need to process or retain information to comply with an applicable legal, tax, accounting or regulatory requirement. 

Consent: where we specifically ask for consent. You may withdraw consent at any time, although this will not affect processing already undertaken lawfully. 


5. Where personal information comes from 
 

directly from you; 

from the organisation you represent or another authorised participant in an engagement; 

from client project documents, meeting invitations and engagement correspondence; 

from referrals and professional contacts; 

from publicly available professional sources, such as company websites and professional networking profiles; and 

from our technology systems when you communicate or interact with us.
 

6. How we use technology 
 

We use approved business technology services to operate Goodison Advisory. These include Microsoft 365 for business email, identity and access management, document storage, collaboration, online meetings and, where enabled, meeting transcription. Client documents are stored principally in SharePoint and Teams, in separate client workspaces with controlled access. 

We may use approved AI-assisted capabilities within our managed business environment to support activities such as organising, reviewing and drafting information. We consider necessity, confidentiality, contractual restrictions, client instructions and data minimisation before using client information. Outputs are reviewed by Goodison Advisory before they are relied upon or shared. Client information is not submitted to public consumer AI services. 

Meeting transcription is used only where there is a defined business purpose. Participants are informed through the relevant meeting process, and transcripts are handled as client-confidential information. 
 

7. Who we share personal information with 
 

Where necessary for the purposes described above, we may share personal information with: 

the client or organisation connected with the relevant enquiry or engagement; 

approved technology and business service providers, including providers of Microsoft 365, customer relationship management, website hosting, accounting and professional support services; 

professional advisers, insurers, auditors or legal advisers where required; and 

public authorities, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law. 

Service providers are expected to process information only for the relevant service and under appropriate contractual and data-protection requirements.
 

8. International processing 
 

Some technology or professional service providers may process personal information outside the United Kingdom. Where this occurs, we take steps to ensure that an applicable transfer mechanism and appropriate safeguards are in place. If a client requires work to be performed in its own technology environment, we follow the client’s authorised access and handling requirements. 
 

9. Security 
 

We use proportionate technical and organisational measures to protect business and client information. These include multifactor authentication, separate administrative access, device encryption using BitLocker, endpoint protection, automatic security updates, screen locking, controlled external sharing, expiring links, prohibition of anonymous sharing and removable USB storage, and the ability to secure managed devices if lost. Access to client information is limited to Goodison Advisory and authorised client users, unless otherwise agreed. 
 

10. How long we keep information 
 

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected. The period is determined by the nature of the information, the status and duration of the enquiry or engagement, client instructions, contractual commitments, and applicable legal, tax, accounting, insurance and claims requirements. Meeting transcripts and working materials are reviewed at engagement closure and deleted when they are no longer required. Information that is no longer required is securely deleted or anonymised.
 

11. Your data protection rights 
 

Depending on the circumstances and the lawful basis used, you may have rights to: 

ask for access to your personal information; 

ask us to correct inaccurate or incomplete information; 

ask us to erase personal information; 

ask us to restrict how information is used; 

object to particular processing; 

receive certain information in a portable format; and 

withdraw consent where consent is the lawful basis. 

These rights are not absolute and exemptions may apply. We will respond without undue delay and normally within one month. To make a request, email privacy@goodisonadvisory.co.uk. 
 

12. Complaints 

If you have concerns about our use of personal information, please contact privacy@goodisonadvisory.co.uk so that we can investigate and respond. 

You may also complain to the Information Commissioner’s Office (ICO): 

Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF 

Telephone: 0303 123 1113 

Website: www.ico.org.uk/make-a-complaint

​

13. Changes to this notice

We may update this notice when our services, systems, suppliers or legal obligations change. The current version will be published on our website with its effective date.

​

bottom of page