How Cross-Border Strategists Ltd collects, uses, and protects your personal data
Last updated: 18 September 2026
Cross-Border Strategists Ltd is a specialist UK-Ireland cross-border advisory practice and is the controller of personal data processed in connection with our website, enquiries about our services and, where you become a client, our advisory relationship.
| Detail | Information |
|---|---|
| Registered name | Cross-Border Strategists Ltd |
| Company number | 17046690 |
| Registered office | 37 Lombard Street, London EC3V 9BQ |
| ICO registration number | ZC106067 |
| Data protection enquiries | info@crossborder-strategists.com |
If you have any questions about this Privacy Notice, our use of personal data or your data protection rights, please contact us using the details above.
We process personal data in accordance with applicable data protection and privacy legislation, including the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025 and, where applicable, the Privacy and Electronic Communications Regulations 2003.
This Privacy Notice explains how we collect, use, disclose, retain and protect personal data in connection with our website, enquiries, client engagements and the operation of our business.
The personal data we collect depends on your relationship with us and the circumstances in which we interact with you.
We may collect and process the following categories of personal data:
| Category | Examples |
|---|---|
| Identity information | Name, title, date of birth and other information used to identify an individual |
| Contact information | Business or personal email address, telephone number, postal address and other contact details |
| Professional and business information | Job title, employer, directorships, business interests, professional role and information about your relationship with an organisation or matter |
| Engagement information | Information provided in connection with an enquiry, prospective engagement or client matter, including correspondence, instructions, documents and information relevant to the services requested |
| Corporate and ownership information | Information relating to directors, shareholders, beneficial owners, officers, employees and other individuals connected with a business or corporate structure |
| Financial and transaction information | Payment information, billing information and financial or transactional information relevant to an engagement |
| Verification and compliance information | Identification and verification information and information obtained through due diligence, conflict or other compliance procedures where appropriate |
| Technical and website information | Internet Protocol address, browser and device information, website activity, cookie identifiers and other technical information generated when you interact with our website or systems |
| Communications | Emails, correspondence and other communications exchanged with us |
We may receive personal data from sources other than the individual to whom it relates.
These sources may include clients, prospective clients, professional advisers, counterparties, corporate entities, service providers and publicly available sources such as corporate registers and other public records.
Where we obtain personal data from another source, the information may include identity, contact, professional, corporate, ownership, financial or other information relevant to an engagement or our legitimate business and compliance requirements.
Where required by data protection law, we provide individuals with the relevant privacy information within the applicable period.
Our services do not ordinarily require us to collect special category personal data.
We may nevertheless receive such information where it is relevant to an engagement, included within documents or correspondence supplied to us or otherwise provided in circumstances connected with our work.
Where we process special category personal data, we do so only where an appropriate lawful basis and condition for processing applies.
In some circumstances, we may need certain personal data in order to respond to an enquiry, establish or perform an engagement, process a payment or comply with an applicable legal or regulatory requirement.
Where particular information is required, we will indicate this where appropriate. If the necessary information is not provided, we may be unable to accept an engagement, provide particular services or comply with a request.
We process personal data only where we have a lawful basis for doing so. The basis that applies depends on the purpose of the processing and our relationship with the individual concerned.
| Purpose | How we use personal data | Lawful basis |
|---|---|---|
| Enquiries and prospective engagements | To respond to enquiries, understand the assistance being sought, communicate with prospective clients and consider whether we are able to accept an engagement | Legitimate interests in managing business enquiries and prospective engagements. Contract where processing is necessary to take steps at an individual’s request before entering into a contract |
| Client engagements and advisory services | To establish and manage engagements, review information and documents, conduct research and analysis, communicate advice and carry out the work for which we have been engaged | Contract where the individual is a party to the engagement. Legitimate interests where we provide services to a business and process personal data relating to individuals connected with that business or matter |
| Verification and compliance | To carry out identification, verification, conflict, due diligence and other compliance procedures where appropriate | Legal obligation where processing is required by applicable law. Legitimate interests where proportionate checks are necessary for the proper administration and protection of our practice or an engagement |
| Business and financial administration | To administer engagements, issue invoices, process payments and maintain appropriate accounting, tax and business records | Contract, legal obligation or legitimate interests, depending on the purpose of the processing |
| Legal rights and records | To maintain appropriate records and to establish, exercise or defend legal rights or claims where necessary | Legitimate interests in protecting our legal rights and maintaining appropriate business records. Legal obligation where applicable |
| Website and information security | To operate, maintain and protect our website, systems and communications and to identify or address technical and security issues | Legitimate interests in maintaining the security and effective operation of our website, systems and business |
| Website analytics | To understand how our website is used and to improve its operation and content | Consent where required for analytics cookies or similar technologies |
Where we rely on legitimate interests, those interests include managing enquiries and client engagements, providing advisory services to business clients, maintaining appropriate business and professional records, protecting our legal rights and maintaining the security and effective operation of our website, systems and communications.
Before relying on legitimate interests, we consider the purpose of the processing, whether the use of personal data is necessary for that purpose and the potential effect on the rights and interests of the individuals concerned. We also consider what an individual would reasonably expect in the circumstances and any safeguards that may be appropriate.
These assessments are documented and kept under review, particularly where the purpose, nature or circumstances of the processing change.
We disclose personal data only where this is necessary for the operation of our business, the delivery of our services, compliance with legal or regulatory requirements or the protection of our legal rights.
Depending on the circumstances, personal data may be shared with:
| Recipient | Purpose |
|---|---|
| Technology and service providers | Providers of website hosting, business email, cloud infrastructure, document storage, communications, security and other systems used to operate our practice |
| Professional advisers and specialists | Lawyers, accountants, tax advisers, consultants and other specialists where their involvement is appropriate to an engagement or required for professional advice |
| Client representatives and other parties to an engagement | Directors, employees, representatives, professional advisers and other persons involved in a matter where disclosure is necessary for the work we have been asked to undertake |
| Verification and compliance providers | Providers used for identification, verification, due diligence or other compliance checks where these are appropriate or required |
| Public authorities and regulatory bodies | Courts, regulators, tax authorities, law enforcement bodies and other public authorities where disclosure is required by law or is otherwise lawful and necessary |
| Parties involved in a business transaction concerning Cross-Border Strategists Ltd | Prospective purchasers, investors and their professional advisers where disclosure is reasonably necessary in connection with a proposed investment, sale, merger, acquisition or transfer of all or part of our business |
Where a service provider processes personal data on our behalf, we require appropriate contractual and data protection safeguards to be in place. We select providers with regard to the nature of the processing, the information involved and the level of protection required.
Where information is shared with an independent professional adviser, public authority or another organisation that determines its own purposes and means of processing, that organisation may act as an independent data controller and will be responsible for its own processing of that personal data.
We do not sell personal data.
Some of the service providers and technology platforms we use may process or store personal data outside the United Kingdom. Personal data may also need to be transferred internationally where this is relevant to an engagement or to the delivery of our services.
Where a transfer of personal data is subject to the international transfer requirements of UK data protection law, we ensure that an appropriate legal mechanism is in place.
Depending on the destination and circumstances of the transfer, this may include:
Where personal data is transferred to an eligible organisation in the United States, we may rely on the UK Extension to the EU US Data Privacy Framework where the recipient holds the appropriate active certification and the transfer falls within the scope of that certification.
We take reasonable steps to ensure that international transfers are subject to protections appropriate to the personal data involved and the circumstances of the transfer.
You may contact us at info@crossborder-strategists.com for further information about the safeguards used for a particular international transfer involving your personal data.
We retain personal data only for as long as necessary for the purposes for which it was collected, including where retention is required to meet legal, regulatory, accounting or reporting obligations, maintain appropriate business and professional records or establish, exercise or defend legal rights.
The appropriate retention period depends on the nature of the information, the purpose for which it is processed and any legal or regulatory requirements that apply.
Our principal retention periods are set out below.
| Category | Retention approach |
|---|---|
| Enquiries that do not become client engagements | Normally retained for up to 12 months after our last substantive communication, unless there is a reason to retain the information for longer |
| Client and engagement records | Normally retained for six years following the end of the engagement, subject to any longer or shorter period required by law, the nature of the matter or a continuing need to establish, exercise or defend legal rights |
| Contracts, invoices and accounting records | Retained for the period required by applicable company, tax and accounting requirements, which will generally be at least six years for relevant company tax records |
| Verification and compliance records | Retained for the period required by applicable law or regulation, or for as long as necessary where the relevant checks are undertaken on another lawful basis |
| Website and security records | Retained for a period proportionate to the security, operational or technical purpose for which the information was collected |
| Analytics information | Retained in accordance with the configuration of the analytics technologies we use and only for as long as necessary for the relevant analytics purpose |
At the end of the applicable retention period, personal data is securely deleted or anonymised unless there is a lawful reason for retaining it for longer.
Retention periods may be extended where information is relevant to an actual or anticipated dispute, investigation, regulatory matter or legal obligation. In those circumstances, we retain the relevant information only for as long as the continuing purpose requires.
Depending on the circumstances and the basis on which we process your personal data, you may have the following rights under data protection law.
| Right | What it means |
|---|---|
| Right to be informed | You have the right to receive clear information about how we collect and use your personal data. This Privacy Notice is intended to provide that information |
| Right of access | You may request confirmation of whether we process your personal data and obtain a copy of that data, together with certain information about how it is processed |
| Right to rectification | You may ask us to correct personal data that is inaccurate or complete information that is incomplete |
| Right to erasure | You may ask us to delete your personal data in circumstances where the right to erasure applies |
| Right to restrict processing | You may ask us to restrict the way we use your personal data in certain circumstances, including while the accuracy of information or an objection to processing is being considered |
| Right to data portability | Where the right applies, you may request certain personal data you have provided to us in a structured, commonly used and machine readable format or ask for it to be transmitted to another controller where technically feasible |
| Right to object | You may object to processing based on legitimate interests in circumstances provided by law. You have an absolute right to object to the use of your personal data for direct marketing |
| Right to withdraw consent | Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. Where consent is managed through our website controls, you may change your choices using those controls. You may also contact us at info@crossborder-strategists.com where appropriate |
| Safeguards relating to automated decision making | Where we make a decision about you based solely on automated processing that produces legal or similarly significant effects, you are entitled to the safeguards provided by data protection law. These include rights to receive information about the decision, make representations or contest the decision and obtain human intervention. Additional restrictions apply where special category personal data is used |
These rights do not apply in every circumstance. Their availability may depend on the nature and purpose of the processing, the lawful basis relied upon and any applicable exemption or restriction under data protection law.
You may exercise your data protection rights by contacting us at info@crossborder-strategists.com.
You are not normally required to pay a fee to exercise your rights. We may request information reasonably necessary to confirm your identity where we have reasonable doubts about the identity of the person making the request.
We will respond to requests without undue delay and ordinarily within one month of receipt. Where permitted by law, this period may be extended by up to a further two months where necessary, taking into account the complexity and number of requests. If an extension is required, we will inform you within the initial response period and explain the reason for it.
When responding to a request for access to personal data, we will carry out searches that are reasonable and proportionate in the circumstances.
Where we are unable to comply with a request in whole or in part, we will explain the reason where required by law and provide information about the available complaint or legal remedies.
Our website may use cookies and similar technologies to operate securely, remember relevant preferences and understand how the website is used.
Cookies are small files stored on your device when you visit a website. Similar technologies may include pixels, scripts, tags, local storage and other technologies that store information on, or access information from, your device.
Depending on the configuration of our website, we may use the following categories:
| Category | Purpose |
|---|---|
| Strictly necessary technologies | Used where necessary for the operation, security or functionality of the website or to provide a service you have requested |
| Preference technologies | Used to remember choices or settings that affect how the website appears or functions |
| Analytics technologies | Used to understand how visitors use the website, measure its performance and identify areas for improvement |
Where consent is required by law, the relevant technology will not be used until you have provided that consent.
Where applicable law permits a technology to be used without consent, including certain technologies used solely for statistical purposes or to remember website preferences, we will use the relevant exception only where its legal requirements are satisfied. Where an exception requires us to provide a means of objecting, an appropriate option will be made available.
Where consent is used, you may accept or reject the relevant technologies through the controls provided on our website and may change your choices subsequently.
You can also control or delete cookies through your browser settings. Restricting certain technologies may affect the operation or functionality of parts of the website.
Further information about the particular cookies and similar technologies in use, their purposes, providers and duration may be provided through our cookie controls or the Cookie Policy available on the website.
We take the security of personal data seriously and maintain technical and organisational measures designed to protect the information we process against unauthorised or unlawful access, use, alteration, disclosure, loss, destruction or damage.
The measures we apply are determined by the nature of the personal data, the way it is processed and the risks associated with that processing. They may include appropriate access controls, authentication measures, secure systems and communications, data protection requirements for service providers, information security procedures and measures designed to maintain the confidentiality, integrity and availability of personal data.
Access to personal data is limited to those who require it for a legitimate business or professional purpose and is subject to appropriate controls.
We keep our security arrangements under review and assess whether they remain appropriate as our systems, processing activities and the risks affecting personal data develop.
Where a personal data breach occurs, we assess and manage the incident in accordance with applicable data protection law, including any requirement to notify the Information Commissioner’s Office or affected individuals.
We do not currently use solely automated processing, including profiling, to make decisions about individuals that produce legal or similarly significant effects.
We may use technology to support research, analysis, administration and other aspects of our work. Where professional judgement is required in relation to a client, prospective client or engagement, that judgement remains subject to meaningful human involvement.
If we introduce solely automated decision making that produces legal or similarly significant effects, we will provide the information and safeguards required by applicable data protection law. These may include information about the decision, the ability to make representations or contest the decision and the ability to obtain human intervention.
Where special category personal data is involved, we will apply the additional restrictions governing significant decisions based solely on automated processing.
Our website may contain links to websites, platforms or services operated by third parties. Following a link to a third party website may allow that organisation to collect or process personal data in accordance with its own privacy practices.
We do not control how independent third parties process personal data through their own websites or services. We encourage you to review the relevant privacy information before providing personal data to, or interacting with, a third party website or service.
This section does not apply where a third party processes personal data on our behalf. Our arrangements with service providers acting on our behalf are addressed in Section 5 of this Privacy Notice.
We keep this Privacy Notice under review and may update it where our processing activities, services, systems or legal and regulatory obligations change.
The current version will be published on our website with the date on which it was last updated.
Where a change materially affects how we use personal data, or where we intend to use personal data for a new purpose, we will take appropriate steps to bring the change to the attention of affected individuals before the relevant processing begins where required by law.
If you have concerns about how we have collected, used, disclosed or otherwise handled your personal data, or about how we have responded to a request concerning your data protection rights, you may make a data protection complaint to us.
Complaints may be submitted by email to: info@crossborder-strategists.com
Please provide sufficient information for us to understand the nature of your concern and identify the personal data or processing involved. We may contact you if further information is reasonably necessary to investigate the matter.
We will acknowledge a data protection complaint within 30 days of receiving it. We will take appropriate steps to investigate the complaint without undue delay, keep you informed of its progress where appropriate and communicate the outcome to you once our investigation is complete.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
| Information Commissioner’s Office | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom |
Further information about making a complaint is available on the Information Commissioner’s Office website.
Making a complaint to us does not affect your right to raise a concern with the Information Commissioner’s Office or pursue any other remedy available to you under applicable law.
Cross-Border Strategists Ltd is registered in England and Wales, company number 17046690. Registered office: 37 Lombard Street, London EC3V 9BQ. ICO registration number ZC106067.