Aureus Consulting Group Limited ("Aureus", "we", "us", or "our") is committed to protecting the privacy and personal data of all individuals who interact with us. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website or engage with our services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller
The data controller responsible for your personal data is Aureus Consulting Group Limited, a company registered in England and Wales, with its registered office at Flat 1, 2 Dunraven Street, Mayfair, London, W1K 7AB, United Kingdom.
For all data protection enquiries, please contact us at info@acgl.uk.com.
Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity data: your name, job title, and organisation;
- Contact data: your email address, telephone number, and correspondence address;
- Enquiry data: the content of messages submitted through our contact forms, including the nature of your business enquiry;
- Technical data: your IP address, browser type and version, time zone, browser plug-in types, operating system and platform, and other technology identifiers on the devices you use to access this website;
- Usage data: information about how you navigate and interact with our website, including pages visited, referral sources, and session duration;
- Marketing data: your preferences in receiving communications from us, including newsletter subscriptions.
We do not collect any special categories of personal data (such as data relating to race, religion, health, or criminal records) through this website.
How We Collect Your Data
We collect personal data through the following means:
- Direct interactions: when you complete a contact form, subscribe to our newsletter, or correspond with us by email or other means;
- Automated technologies: as you interact with our website, we may automatically collect technical and usage data through cookies and similar tracking technologies (please refer to our Cookie section below);
- Third parties: we may receive data about you from professional networking platforms such as LinkedIn, or from publicly available sources, in the context of our legitimate business development activities.
Lawful Basis and Purposes of Processing
We process your personal data on the following lawful bases under UK GDPR:
- Legitimate interests (Article 6(1)(f)): to respond to your business enquiries, to conduct business development activities, to improve our website, and to maintain the security of our systems;
- Consent (Article 6(1)(a)): where you have expressly opted in to receive our newsletter or marketing communications. You may withdraw your consent at any time;
- Contractual necessity (Article 6(1)(b)): where processing is necessary for the performance of a contract with you or to take steps prior to entering into a contract;
- Legal obligation (Article 6(1)(c)): where we are required to process your data to comply with applicable law, regulatory requirements, or professional obligations.
Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties. We may share your data in the following limited circumstances:
- Service providers: trusted third-party service providers who assist us in operating our website, hosting infrastructure, email delivery, and analytics. All such providers are bound by appropriate data processing agreements;
- Professional advisers: solicitors, accountants, and auditors acting in an advisory capacity, subject to professional duties of confidentiality;
- Regulatory and legal authorities: where required to do so by applicable law, court order, or the request of a competent governmental or regulatory authority;
- Business transfers: in the context of a merger, acquisition, or sale of all or part of our business, in which case personal data may be transferred as part of the transaction.
International Data Transfers
Where we transfer your personal data outside the United Kingdom, we ensure that such transfers are subject to appropriate safeguards in accordance with UK GDPR, including adequacy decisions, standard contractual clauses, or other approved transfer mechanisms. If you require further information regarding the specific safeguards in place, please contact us at info@acgl.uk.com.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulatory obligations. In practice:
- Enquiry and correspondence data is retained for a period of up to five years following our last interaction;
- Technical and usage data is typically retained for up to 26 months;
- Marketing and newsletter subscription data is retained until you withdraw your consent or unsubscribe.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.
Your Rights Under UK GDPR
Subject to applicable conditions and exceptions under UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at info@acgl.uk.com. We will respond within one calendar month of receiving your request. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
Our website uses cookies and similar tracking technologies to distinguish you from other users and to improve your experience. Cookies are small data files stored on your device. We use the following categories of cookies:
- Strictly necessary cookies: essential for the operation of our website and cannot be disabled;
- Analytical/performance cookies: allowing us to recognise and count visitors and to analyse how visitors move around the website, helping us to improve its performance;
- Functionality cookies: used to recognise you when you return to our website and to personalise our content accordingly.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include encryption of data in transit, access controls, and regular security assessments.
While we take all reasonable precautions, no method of transmission over the internet or method of electronic storage is entirely secure. We cannot guarantee absolute security of your data and you transmit data to us at your own risk.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or regulatory requirements. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Where changes are material, we will make reasonable efforts to notify you directly.