PRIVACY POLICY

SIAN GISSING 

 

Sian Gissing Global Holdings Ltd

Trading as Sian Gissing Strategic Legal Consultancy

Last updated: 27 July 2026

 

1. About this Privacy Policy

This Privacy Policy explains how Sian Gissing Global Holdings Ltd, trading as Sian Gissing Strategic Legal Consultancy, collects, uses, stores, shares and protects personal information.

It applies when you:

  • visit www.siangissing.com;
  • contact us by telephone, email, social media or online form;
  • create a customer account;
  • purchase a product or digital resource;
  • book a consultation;
  • complete a client intake questionnaire;
  • submit documents for research or review;
  • attend an online consultation;
  • subscribe to marketing communications;
  • otherwise interact with the Company or Consultancy.

We process personal information in accordance with applicable data-protection law, including the UK GDPR and the Data Protection Act 2018.

 

2. Who we are

The data controller is:

Sian Gissing Global Holdings Ltd
Trading as Sian Gissing Strategic Legal Consultancy

Registered office:

128 City Road
London
England
EC1V 2NX
United Kingdom

Company number: 17138981

ICO registration number: ZC208021

Sian Gissing Global Holdings Ltd is registered with the Information Commissioner’s Office as a data controller under registration reference ZC208021. Further information is available on our Governance & Data Protection page.


Email: legal@siangissing.com

For all privacy enquiries or requests concerning your personal information, please contact us using the email address above.

 

3. Our role and regulatory status

Sian Gissing Strategic Legal Consultancy provides non-reserved strategic consultancy, general legal information, legal and factual research, educational support and practical guidance.

It is not a solicitors’ practice and is not authorised or regulated by the Solicitors Regulation Authority.

Information submitted to the Consultancy will be treated confidentially in accordance with this Privacy Policy. However, communications with an unregulated consultancy may not attract legal professional privilege in the same way as communications with an authorised solicitor or barrister.

 

4. Personal information we may collect

Depending on your interaction with us, we may collect the following categories of personal information.

4.1 Identity and contact information

This may include:

  • full legal name;
  • preferred name;
  • postal address;
  • email address;
  • telephone number;
  • date of birth where reasonably necessary;
  • country of residence;
  • nationality where relevant;
  • time zone;
  • photographic identification where required for identity or compliance checks.

4.2 Business and professional information

This may include:

  • job title;
  • employer or business name;
  • company registration number;
  • business address;
  • professional role;
  • relationship to a company, trust, estate, yacht or other organisation;
  • authority to act on behalf of another person or organisation.

4.3 Booking and transaction information

This may include:

  • products and Services purchased;
  • appointment dates and times;
  • booking and order references;
  • payment status;
  • billing address;
  • currency;
  • invoices;
  • refunds;
  • cancellation and rescheduling history.

Payments are processed through third-party payment providers. We do not ordinarily receive or store your complete payment-card details.

4.4 Client intake and matter information

Where you enquire about or purchase a Consultancy Service, we may collect:

  • a summary of your circumstances;
  • relevant areas of law or business;
  • your objectives and desired outcome;
  • names of parties involved;
  • names of solicitors, barristers, insurers or other advisers;
  • court, tribunal, regulator or authority details;
  • claim or case reference numbers;
  • hearing dates, limitation dates and other deadlines;
  • previous professional advice;
  • relevant chronology;
  • asset, debt or financial-value ranges;
  • information about trusts, estates, companies, contracts, yachts or property;
  • information contained in correspondence and documents you submit.

4.5 Documents and correspondence

This may include:

  • contracts and agreements;
  • court papers;
  • legal correspondence;
  • judgments and orders;
  • trust deeds;
  • wills and estate documents;
  • business and company records;
  • invoices and statements;
  • yacht sale, repair or management agreements;
  • reports and surveys;
  • emails, messages and attachments;
  • consultation notes and written summaries.

4.6 Technical and Website information

This may include:

  • IP address;
  • browser and device information;
  • operating system;
  • Website pages viewed;
  • referral source;
  • interaction and purchase events;
  • cookie identifiers;
  • approximate location;
  • account login information;
  • Website security and fraud-prevention information.

4.7 Marketing and communication preferences

This may include:

  • newsletter subscription status;
  • consent records;
  • preferred communication channels;
  • responses to campaigns;
  • whether you have unsubscribed or objected to marketing.

4.8 Telephone and meeting information

This may include:

  • telephone messages;
  • caller details;
  • the date and time of calls;
  • Zoom or other online-meeting details;
  • consultation attendance information;
  • meeting notes.

Consultations will not ordinarily be recorded without prior notice and appropriate consent.

 

5. Sensitive and special-category information

Legal and personal matters may sometimes involve information concerning:

  • health;
  • race or ethnicity;
  • religious or philosophical beliefs;
  • political opinions;
  • sexual orientation or sex life;
  • trade-union membership;
  • genetic or biometric information;
  • criminal allegations, convictions or offences;
  • children or vulnerable people.

The ICO identifies these as categories requiring additional care and, where applicable, an additional legal condition for processing.

Please provide only information that is relevant and reasonably necessary for the agreed purpose.

Where we process special-category or criminal-offence information, we will do so only where an appropriate lawful basis and additional legal condition apply, which may include:

  • your explicit consent where legally appropriate;
  • establishment, exercise or defence of legal claims;
  • substantial public interest where applicable;
  • protection of vital interests;
  • another condition permitted by law.

6. How we collect personal information

We may collect information:

Directly from you

For example, when you:

  • place an order;
  • book an appointment;
  • complete a form;
  • upload documents;
  • send an email;
  • telephone the Company;
  • attend a consultation;
  • contact us through social media;
  • subscribe to communications.

From another person or organisation

For example:

  • a person authorised to act for you;
  • a company representative;
  • a referral source;
  • another professional adviser;
  • a party involved in your matter;
  • publicly available registers and records;
  • courts, tribunals, regulators or government bodies;
  • fraud-prevention and identity-verification sources.

Where information is obtained from another source, we will provide appropriate privacy information where required. The ICO generally requires this within a reasonable period and no later than one month, subject to applicable exceptions.

Automatically

Some technical information may be collected automatically through:

  • cookies;
  • analytics tools;
  • Shopify;
  • fraud and security systems;
  • Meta or Google technologies, where enabled;
  • server and Website logs.

7. Why we use personal information

We may process personal information to:

  • respond to enquiries;
  • create and manage customer accounts;
  • administer orders, bookings and payments;
  • conduct identity, conflict, jurisdiction and suitability checks;
  • assess whether a matter falls within our scope;
  • prepare for and provide Consultancy Services;
  • review documents;
  • carry out legal, factual or commercial research;
  • arrange and deliver online consultations;
  • provide digital products and educational content;
  • prepare consultation notes or written summaries;
  • communicate with you;
  • provide customer support;
  • administer cancellations, refunds and complaints;
  • maintain business, accounting and contractual records;
  • prevent fraud, misuse and cybersecurity incidents;
  • protect confidential information;
  • establish, exercise or defend legal claims;
  • comply with legal, court, tax, accounting and regulatory obligations;
  • maintain and improve our Website and Services;
  • send marketing communications where permitted;
  • measure Website use and advertising effectiveness where permitted.

 

8. Our lawful bases

We rely on one or more of the following lawful bases, depending on the purpose.

8.1 Contract

We process information where necessary to:

  • take steps at your request before entering a contract;
  • process an order;
  • administer a booking;
  • provide a Product or Service;
  • manage payment, cancellation or refund arrangements;
  • communicate about the contract.

8.2 Legal obligation

We may process information where necessary to comply with:

  • tax and accounting duties;
  • company-record requirements;
  • court orders;
  • lawful requests from competent authorities;
  • consumer-protection duties;
  • data-protection responsibilities;
  • other applicable legal obligations.

8.3 Legitimate interests

We may process information where reasonably necessary for legitimate business interests, including:

  • managing and improving the business;
  • responding to enquiries;
  • maintaining accurate records;
  • conducting proportionate conflict and suitability checks;
  • protecting the Website and systems;
  • preventing fraud and misuse;
  • managing complaints;
  • protecting intellectual property;
  • establishing, exercising or defending legal claims;
  • communicating with existing customers about related Services where permitted.

We consider whether those interests are overridden by your rights and interests before relying on this basis.

8.4 Consent

We may rely on consent for:

  • optional marketing;
  • non-essential cookies;
  • certain advertising or analytics tools;
  • recording a consultation;
  • processing particular sensitive information where explicit consent is appropriate;
  • another activity where consent is required.

You may withdraw consent at any time. Withdrawal does not make earlier processing unlawful.

8.5 Vital interests

In rare situations, we may process information where necessary to protect someone’s life or physical safety.

The ICO requires organisations to identify and explain the lawful basis used for each processing purpose.

 

9. What information you are required to provide

Some information is necessary to:

  • enter into or perform a contract;
  • process payment;
  • confirm your identity;
  • conduct a conflict or suitability check;
  • understand the matter;
  • comply with legal requirements.

Where required information is not provided, we may be unable to:

  • accept your booking;
  • review documents;
  • prepare properly;
  • provide the Service;
  • continue with the engagement.

Providing optional marketing information is not a condition of purchasing a Service.

 

10. How we store and manage client records

We may store and manage records through secure:

  • customer relationship management systems;
  • practice and matter-management systems;
  • Shopify customer and order records;
  • appointment-booking systems;
  • email systems;
  • cloud-storage platforms;
  • video-conferencing services;
  • accounting and payment platforms.

This may include use of Clio for client intake, CRM, matter administration, correspondence, notes or document management. Clio describes its service as a cloud-based legal practice-management platform and maintains its own privacy arrangements.

We take reasonable steps to:

  • limit access to people who need it;
  • use secure passwords and access controls;
  • maintain appropriate technical safeguards;
  • review app permissions;
  • minimise unnecessary information;
  • retain records only for appropriate periods;
  • securely delete or anonymise information when no longer required.

No online or electronic system can be guaranteed to be completely secure.

 

11. Confidentiality

Information and documents supplied for Consultancy Services will be used only where reasonably necessary to:

  • conduct initial checks;
  • assess and deliver the Service;
  • perform agreed research or review;
  • communicate with you;
  • maintain appropriate records;
  • comply with legal duties;
  • protect legal rights.

We do not sell confidential client files, consultation information or matter details.

We will not use identifiable client information for testimonials, publicity, case studies or educational content without separate permission.

We may use genuinely anonymised or hypothetical examples where no individual or matter can reasonably be identified.

 

12. Who we may share information with

We may disclose limited personal information to service providers where reasonably necessary to operate the Website, administer the business and provide the Services.

These may include:

Shopify

Shopify may process information relating to:

  • Website hosting;
  • ecommerce;
  • customer accounts;
  • checkout;
  • orders;
  • payments;
  • fraud prevention;
  • analytics;
  • customer privacy settings.

Shopify allows merchants to configure privacy policies, cookie banners, data-sharing opt-outs and geographic privacy settings. Shopify also makes clear that merchants remain responsible for complying with laws applicable to their business and customers.

Easy Appointment Booking or other booking providers

Booking providers may process:

  • names;
  • contact details;
  • appointment times;
  • intake answers;
  • confirmation and reminder information;
  • meeting links.

Clio

Where used, Clio may process:

  • client contacts;
  • intake details;
  • matters;
  • correspondence;
  • notes;
  • documents;
  • associated records.

Zoom or other meeting providers

Zoom or another provider may process information required to:

  • create meeting links;
  • deliver online meetings;
  • administer participants;
  • maintain service security.

Google

Google services may be used for:

  • business email;
  • calendars;
  • forms;
  • documents;
  • cloud storage;
  • analytics;
  • Website functionality.

Payment providers

Payment providers may process:

  • payment details;
  • billing information;
  • fraud and transaction information;
  • refunds and chargebacks.

Professional and operational advisers

We may share information where reasonably necessary with:

  • accountants;
  • tax advisers;
  • insurers;
  • IT and cybersecurity providers;
  • cloud-service providers;
  • professional advisers;
  • authorised lawyers instructed by us;
  • debt-recovery providers where lawful;
  • regulators, courts or public authorities.

Meta, Facebook and Instagram

Where you contact us through Facebook or Instagram, or where Meta advertising and analytics tools have been enabled, Meta may process information relating to your interaction with those services.

Depending on the Shopify settings enabled, such tools may process Website, purchase or customer-matching events.

This section should remain only if you actually use Meta Pixel, Conversions API, customer-list advertising or related Meta tools.

 

13. Data sharing and sale

We do not sell confidential client information.

We do not sell personal information for money.

We may share limited information:

  • to provide a Service you requested;
  • with contracted service providers;
  • to process payments;
  • to administer Website functionality;
  • for analytics or marketing where permitted;
  • where you have consented;
  • where legally required;
  • to establish, exercise or defend legal claims;
  • in connection with a legitimate business transfer.

Where applicable privacy law defines certain advertising or analytics disclosures as “sale” or “sharing,” we will provide any legally required notice and opt-out mechanism.

 

14. Cookies and similar technologies

The Website may use cookies and similar technologies for:

Strictly necessary purposes

These may be required for:

  • Website operation;
  • checkout;
  • security;
  • fraud prevention;
  • account login;
  • remembering privacy choices.

Analytics

These may help us understand:

  • Website visits;
  • page use;
  • traffic sources;
  • user interactions;
  • technical performance.

Advertising and marketing

Where enabled and permitted, these may support:

  • advertising measurement;
  • audience matching;
  • personalised or non-personalised campaigns;
  • Meta or Google advertising tools.

Non-essential cookies will be used only where permitted and subject to applicable consent controls.

You may manage cookie preferences through the Website banner or your browser settings.

Further details should be set out in a separate Cookie Policy.

 

15. Direct marketing

We may send marketing communications where:

  • you have consented;
  • another lawful basis permits it;
  • the communication relates to similar Products or Services and applicable rules permit it.

You may opt out at any time by:

The right to object to direct marketing is absolute. Once a valid objection is received, personal information must no longer be used for that purpose.

We may retain a minimal suppression record to ensure that your preference continues to be respected.

 

16. International clients and transfers

The Company is established in England and primarily processes information under UK data-protection law.

Our clients may be located in:

  • the United Kingdom;
  • the European Union or European Economic Area;
  • the United States;
  • Asia;
  • other international jurisdictions.

Personal information may be processed or stored outside the United Kingdom through providers including Shopify, Clio, Zoom, Google, Meta, payment providers and cloud-service providers.

Where a restricted international transfer is made and the law requires safeguards, we will seek to rely on an appropriate mechanism, which may include:

  • UK adequacy regulations;
  • approved contractual safeguards;
  • the UK International Data Transfer Agreement;
  • an applicable UK Addendum;
  • another legally recognised mechanism;
  • an applicable legal exception.

Clients in other jurisdictions may have additional rights under national, federal, state or regional privacy law. We will honour such rights where those laws legally apply to our activities.

 

17. How long we keep information

We keep personal information only for as long as reasonably necessary for the relevant purpose.

Indicative retention periods may include:

Enquiries that do not become clients

Ordinarily up to 12 months after the final meaningful contact, unless a longer period is required for a complaint, conflict record, safeguarding concern or legal claim.

Customer, contract and consultation records

Ordinarily up to six years after the Service or contractual relationship ends, where reasonably necessary for contractual records, complaints, insurance and legal claims.

Accounting and tax records

Kept for the period required by applicable tax and accounting law.

Conflict-check information

A limited record may be retained where reasonably necessary to identify and manage future conflicts.

Consultation notes and submitted documents

Ordinarily retained for the client-record period unless:

  • they are no longer required;
  • a shorter period is appropriate;
  • a longer period is required due to proceedings, a complaint, insurance or legal obligations.

Marketing information

Kept until:

  • you withdraw consent;
  • you object;
  • the information becomes inaccurate;
  • it is no longer reasonably required.

A limited suppression record may be retained after an opt-out.

Technical and cookie information

Retained in accordance with the relevant platform, cookie setting and operational need.

Retention periods may be extended where reasonably necessary for:

  • ongoing proceedings;
  • complaints;
  • fraud prevention;
  • safeguarding;
  • court orders;
  • insurance;
  • legal claims;
  • another legal duty.

When information is no longer needed, it will be deleted, anonymised or securely placed beyond ordinary use where appropriate.

 

18. Your data-protection rights

Depending on the circumstances and applicable law, you may have the right to:

  • be informed about processing;
  • access your personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion;
  • request restriction of processing;
  • object to certain processing;
  • object to direct marketing;
  • request data portability where applicable;
  • withdraw consent;
  • challenge certain automated decisions where applicable;
  • complain to a supervisory authority.

Right to deletion

You may request deletion at any time.

The right is not absolute. We may retain specified information where continued processing is reasonably necessary for:

  • legal obligations;
  • contractual and accounting records;
  • establishment, exercise or defence of legal claims;
  • fraud prevention;
  • safeguarding;
  • insurance;
  • public-interest grounds;
  • another lawful exemption.

Making a request

Please email:

legal@siangissing.com

Include enough information for us to identify you and understand the request.

We may request reasonable proof of identity before releasing or changing information.

We will respond within the legally required period. In many UK GDPR cases, this is ordinarily one month, although the period may lawfully be extended for complex or numerous requests.

 

19. Complaints to the ICO

Please contact us first so that we have an opportunity to address your concern.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office

Details of how to submit a complaint are available through the ICO’s official services.

Clients in another country may also be entitled to complain to their local competent data-protection authority.


20. Automated decision-making

We do not currently make decisions producing legal or similarly significant effects about clients solely through automated processing.

Shopify, payment providers or fraud-prevention systems may use automated indicators to identify potentially fraudulent or suspicious transactions. Where a third-party provider acts independently, its own privacy notice will apply.

If our use of automated decision-making changes materially, we will update this Policy and provide any information required by law.

 

21. Children

Our Products and Consultancy Services are intended for adults aged 18 or over.

We do not knowingly invite children to purchase Services or submit personal information directly.

Information concerning a child may sometimes be provided by a parent, guardian or authorised adult where relevant to a matter. Such information should be limited to what is necessary.

If you believe a child has submitted information to us without appropriate authority, contact legal@siangissing.com.

 

22. Business transfers

If the Company undergoes:

  • a restructuring;
  • merger;
  • acquisition;
  • sale;
  • transfer of assets;
  • insolvency process;

personal information may be disclosed to relevant professional advisers and transferred to an appropriate successor, subject to applicable law, confidentiality and data-protection safeguards.

 

23. Links and third-party websites

The Website may contain links to third-party websites or services.

We do not control their privacy practices and are not responsible for their content or handling of personal information.

You should review the relevant third party’s privacy notice before submitting information.

 

24. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes in law;
  • ICO guidance;
  • changes to the Website or Services;
  • new technology or providers;
  • changes to how information is processed.

The latest version will be published on the Website with the updated date.

Where a change materially affects how existing personal information is used, we will provide appropriate notice before beginning the new processing where required. The ICO recommends regularly reviewing privacy information and informing individuals before materially new uses begin.

 

25. Contact us

For privacy questions, rights requests or concerns:

Sian Gissing Global Holdings Ltd
Trading as Sian Gissing Strategic Legal Consultancy

128 City Road
London
England
EC1V 2NX
United Kingdom

Email: legal@siangissing.com

Company number: 17138981