Skip to main content
privacy-notice
Carn Advisory

Policy Document

Carn Advisory Limited

Privacy Policy
Effective Date: 5 March 2026


Policy Management Record

Policy Version

Last Updated

Next Review Date

Changes Incorporated

1.0

5 March 2025

5 March 2026

Initial version

1.1

5 March 2026

5 April 2027

Revised to reflect transition to Carn Advisory Limited


 

 

Contents

1. Introduction. 

2. Data Controller 

3. What Data We Collect 

4. How We Collect Personal Data. 

5. Purpose and Legal Basis for Processing. 

6. Data Sharing and Third Parties. 

7. International Data Transfers. 

8. Data Retention. 

9. Data Subject Rights. 

10. Data Security. 

11. Updates to This Policy. 


 1. Introduction

Carn Advisory Limited ("Carn," "we," "us," or "our") is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with the Data Protection Act 2018, the Applied GDPR (Data Protection (Application of the GDPR) Order 2018), and the GDPR and LED Implementing Regulations 2018


2. Data Controller

Carn is the data controller for the personal data we process. For any questions about this policy or how we handle your data, please contact us at DPO@carnadvisory.com.

    • Established: Isle of Man
    • Sector: Consultancy & Advisory Services

3. What Data We Collect

We may collect and process the following categories of personal data:

    • Business Contact Information (name, job title, company, email address, phone number, business address)
    • Client & Service Data (correspondence, service requests, engagement records)
    • Financial data (billing information, payment details)
    • Marketing & Communication Data (preferences, responses, and interactions with our marketing materials)
    • Website & Technical Data (IP addresses, cookies, analytics data)

4. How We Collect Personal Data

We collect personal data in the following ways:

    • Directly from individuals (via our website, email, phone, or in-person consultations)
    • Through contractual agreements with clients and service providers
    • Via automated technologies such as cookies when using our website
    • From third-party sources (e.g., business directories, publicly available information)

 

5. Purpose and Legal Basis for Processing

Each processing activity is conducted based on a lawful basis, as set out below:

    • Legitimate Interests – For business communications, networking, and marketing (subject to opt-out rights).
    • Contractual Necessity – Where processing is required to fulfil a contract or service request.
    • Legal Obligation – Where data must be retained for tax, compliance, or legal purposes.
    • Consent – For marketing communications where required.

 

We use personal data to:

    • Provide our consultancy services and fulfil contracts
    • Respond to inquiries and service requests
    • Manage client relationships
    • Send marketing communications (subject to opt-out rights)
    • Improve our website and services through analytics

6. Data Sharing and Third Parties

We do not sell or rent personal data. We may share data with:

    • Service providers supporting our operations (IT, marketing, legal, etc.)
    • Regulatory authorities, if legally required
    • Business partners where necessary for service fulfilment


7. International Data Transfers

If we transfer personal data outside the Isle of Man, the UK and the EU, we ensure that appropriate safeguards (such as Standard Contractual Clauses) are in place to protect the data.


8. Data Retention

We retain personal data only for as long as necessary:

    • Business & client data – Retained for up to 6 years for tax and business record purposes.
    • Marketing data – Retained until opt-out or withdrawal of consent.
    • Website data – Retention period varies; see our Cookie Policy.

9. Data Subject Rights

You have the following rights under Applied GDPR:

    • Right to access your data
    • Right to rectify inaccurate data
    • Right to erasure “right to be forgotten” (where applicable)
    • Right to restrict processing
    • Right to data portability
    • Right to object to processing (including marketing opt-out)
    • Right to lodge a complaint with the Isle of Man Information Commissioner (www.inforights.im)

10. Data Security

We implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, or misuse.


11. Updates to This Policy

We may update this Privacy Policy periodically. The latest version will always be available on our website.

 

For any questions about this Privacy Policy, please contact DPO@carnadvisory.com.



  

 

 

Social responsibility icons created by Freepik - Flaticon