— Legal
Privacy Policy
Last updated 1 September 2026
This policy explains what personal information Ayden Advisory Group collects through this website and the client portal, why, how long it is kept and what you can ask us to do with it.
1. Who we are
Ayden Advisory Group (“the firm”, “we”) is a private strategic advisory firm. For the purposes of applicable data protection law we are the controller of the personal information described in this policy. Write to info@aydenadvisors.com with any question about it, or to exercise any right set out below.
2. What we collect
When you use the public site
- The pages requested and the time of the request.
- The referring website’s domain, where your browser sends one. We record the domain only, never the full referring address.
- A daily pseudonymous identifier derived from your network address and browser description. It is a one-way digest, it is salted with a secret and the calendar date, it changes every day, and it cannot be reversed into an address or matched across days.
We do not use third-party analytics, advertising tags, social plugins or content delivery networks on this site. Nothing about your visit is sent to another company.
When you send a consultation request
- Your name, email address, organisation and chosen practice area.
- What you write in the message field.
- Your network address and browser description, recorded to prevent abuse of the form.
When you hold a portal account
- Your name, email address, company or principal entity, role and, optionally, telephone number.
- A cryptographic hash of your password. We never store the password itself and cannot recover it.
- Your acceptance of the confidentiality undertaking: the version accepted, the date and time, your network address, your browser description, and a digest and snapshot of the exact text you accepted.
- A record of your activity in the portal: sign-ins, pages viewed, documents opened and documents downloaded, with the time, network address and browser description of each.
3. Why we hold it
- To answer your enquiry
- Because you asked us to, and because it is in our legitimate interest to respond to people who approach the firm.
- To operate the client portal
- To perform, or to take steps towards, an advisory engagement.
- To keep the portal secure
- Our legitimate interest, and our clients’ clear expectation, that access to confidential material is controlled and evidenced. This is the reason the access record exists: it is a confidentiality control, and it is what allows the firm to establish who saw what.
- To understand how the site is used
- Our legitimate interest in knowing which material is read, assessed against your interests — which is why public analytics are pseudonymous and first-party.
- To meet legal and professional obligations
- Record-keeping, and responding to lawful requests.
4. Who sees it
Personal information is seen by the principals and staff of the firm who need it, and by our hosting provider, which stores the data on our instruction and has no right to use it. We do not sell personal information, we do not share it for anyone else’s marketing, and we do not transfer it to any party except where we are required to by law or by an order of a competent court or regulator.
5. Where it is held
The website, its database and its document storage are hosted on servers operated by our hosting provider. Where information is transferred outside the jurisdiction in which it was collected, we rely on the safeguards permitted by applicable law for that transfer.
6. How long we keep it
- Consultation requests
- Two years from the last contact, unless an engagement follows.
- Portal accounts
- For as long as the account is open, and then for six years, which reflects the period in which a question about an engagement may still arise.
- Confidentiality acceptance records
- For the duration of the undertaking and six years thereafter. These records are evidence of an agreement and are not deleted on request while that agreement remains relevant.
- Access and download records
- Two years, then deleted.
- Public analytics
- Twenty-six months. The pseudonymous identifier is unusable after one day in any case.
7. Your rights
Depending on where you are, you may have the right to ask for a copy of the personal information we hold about you; to have it corrected; to have it deleted; to restrict or object to how we use it; and to receive it in a portable form. You may also withdraw consent where we rely on consent, without affecting what was done before.
Write to info@aydenadvisors.com. We will respond within one month, and will tell you if we need to verify your identity first. Where we cannot do what you ask — for example, where a record is evidence of an agreement, or where professional obligations require us to keep it — we will say so and explain why. If you are not satisfied you may complain to your data protection supervisory authority.
8. Security
Passwords are stored only as a modern one-way hash. The site is served over HTTPS. Session cookies are marked HttpOnly, Secure and SameSite. Confidential documents are stored outside the public web directory under randomised names, are served only through an authenticated endpoint after an authorisation check, and are reachable only through single-purpose links that expire. Every access is recorded. No system is perfect, and we do not claim otherwise; if a breach occurs that is likely to affect you, we will tell you and the relevant authority as the law requires.
9. Children
This site is intended for business use by adults. We do not knowingly collect information from anyone under eighteen.
10. Changes
We will post any change to this policy on this page and update the date at the top. Where a change is material we will tell portal account holders directly.