Unified Privacy & Cookie Policy
Last updated: June 2026
This policy explains how Stone & Co ("we", "us", "our") collects, protects, and uses your information when you use stoneadvisory.co.uk, complete our online tools, or correspond with us. We've kept this in plain English. If you have any questions, email us at hello@stoneadvisory.co.uk.
1. Who we are
Stone & Co is a trading name of Enablematic Consulting Agency Ltd, registered in England and Wales (Company No: 16695138). Our registered office is First Floor Office, 3 Hornton Place, London, W8 4LZ. We operate as a data controller and are registered with the Information Commissioner's Office (ICO). For data matters, contact Byron Stone at hello@stoneadvisory.co.uk.
2. Information we collect and why we use it
Under the UK GDPR, we only process your personal data where we have a clear legal basis to do so. The following maps our data activities, processing purposes, and corresponding legal grounds:
- Direct inquiries and tools. Name, contact details, and core business metrics (sector, bed capacity, revenue, EBITDA) entered into our Valuation Calculator or Exit Readiness Audit, used to generate, review, and deliver your custom financial diagnostic report or indicative valuation. Lawful basis: performance of a contract, or taking necessary steps prior to entering into a contract.
- Insights and newsletters. Email address submitted via subscription boxes or tool forms, used to keep in touch with sector founders and send relevant care market updates, transaction insights, or regional trends. Lawful basis: legitimate interests, with a clear option to opt out or unsubscribe instantly at any time.
- Automated diagnostics. Calculation logic applied to your submitted financial data inputs, used to provide immediate, automated advisory baseline metrics. Every report is verified by a human partner before final confirmation. Lawful basis: legitimate interests, ensuring the right to request direct human intervention or contest the output.
- Legal compliance and defence. Historical engagement data, identity records, and business documentation, used to comply with statutory anti-money laundering frameworks or defend against prospective legal claims. Lawful basis: legitimate interests and legal obligation.
We do not sell your personal data under any circumstances, nor do we transfer it to third parties to facilitate external marketing activities.
3. How we use cookies
Cookies are small text files placed on your device to store data. We maintain a minimal cookie footprint to preserve site performance and visitor privacy:
- Essential cookies (always active). These are strictly necessary for basic operations, including remembering your cookie consent choices and ensuring smooth performance as you browse between pages.
- Analytics cookies. We use Cloudflare Web Analytics, which counts page views without cookies and without collecting anything that identifies you, so it runs on every visit. With your consent we also use Google Analytics, with IP anonymisation active, to understand aggregated traffic patterns such as page popularity and exit points. Google Analytics sets cookies and is not loaded at all unless you opt in. You can withdraw consent at any time through the Cookie Settings link in the footer, or clear the cookies in your browser.
4. Data sharing and international transfers
We restrict data sharing to trusted third-party service providers essential to running our business infrastructure, including our website hosting provider and the systems that process form submissions and client records. Our website is hosted by Cloudflare, enquiry and report emails are sent through Resend, and enquiry details are stored in our own database on Cloudflare. Reports are rendered by PDFShift, and site analytics are processed by Cloudflare and by Google. Because these infrastructure networks safely utilise global servers, some data processing occurs in regions outside the UK, including the United States. We safeguard these transfers using approved mechanisms, including UK-approved Standard Contractual Clauses (SCCs) and the UK Extension to the EU-US Data Privacy Framework.
5. Data security and retention
We treat proprietary business and founder data with strict security. We enforce rigid access controls and secure encryption layers for data in transit. Your records are only retained as long as commercially necessary:
- Audit and calculator inputs: retained for up to 3 years following your last active interaction before deletion or total anonymisation.
- Newsletter records: kept active until an explicit unsubscribe request is submitted.
- Formal client engagement records: retained for a post-engagement period of 6 years to satisfy commercial and UK tax compliance mandates.
6. Your rights
Under UK data protection law, you possess explicit rights regarding your personal information. You have the right to request a copy of your stored data, correct any structural inaccuracies, request complete account erasure (the "right to be forgotten"), restrict active processing, or object to direct outreach. To trigger any of these statutory rights, email Byron Stone directly at hello@stoneadvisory.co.uk. We will address your request within one calendar month. If you believe our processing infringes upon your rights, you have the right to lodge an official complaint with the Information Commissioner's Office (ico.org.uk).