Legal
Privacy Policy
Last updated: 6 September 2026
01
Who we are
Helmshore Consulting Limited ("Helmshore", "we", "us") provides sell-side readiness and M&A advisory services. We operate Helmshore Readiness, a web platform used by clients and their nominated team members during an engagement.
We are the data controller for the personal data described in this notice, except where section 08 says otherwise.
Contact details:
Email: adam@helmshoreconsulting.com
Address: 71–75 Shelton Street, London, WC2H 9JQ
02
This website
You can read every page of this website without giving us anything.
- We set no cookies and run no analytics, advertising or tracking scripts.
- We have no contact forms. If you email us, we hold that email.
- The site makes no requests to any third party. Typefaces, images and everything else are served from this site, so no other company learns that you visited it.
- Screenshots shown on this site use invented data. No client information appears anywhere on it.
03
The Helmshore Readiness platform
The platform is invite-only. Accounts are created only for people we, or a client lead, have explicitly invited to a specific engagement.
About you as a user
- Name and email address
- Your role on the engagement and the organisation you belong to
- Passkey credentials, or the one-time sign-in codes we send by email. We never set, receive or store passwords.
- A record of your sign-ins and of every change you make
The engagement content
- The answers your team writes to the readiness questionnaire, and the correspondence between your team and Helmshore about those answers
- Responses recorded against actions in the preparation plan
- Documents uploaded as evidence that an action is complete
- The readiness report, preparation plan and data room index we produce
Engagement content is commercial information about a business. It can also contain personal data about individuals, for example employees named in a share-award schedule, a pension analysis or an employment contract. Section 08 explains who is responsible for that.
Why we hold it, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Delivering the engagement you have appointed us for | Performance of a contract |
| Creating and managing your account, and signing you in | Performance of a contract |
| Keeping an audit trail of who changed what and when | Legitimate interests — integrity and accountability of professional work product |
| Securing the platform and investigating misuse | Legitimate interests — security |
| Meeting our own legal, regulatory and professional obligations | Legal obligation |
04
How we use AI, and what that means for your data
Helmshore Readiness uses a large language model, Claude, provided by Anthropic, to assist in the production of the readiness report and the preparation plan. To do that, the answers your team has given, and the findings drawn from them, are sent to Anthropic's API.
What this means in practice:
- Nothing is issued to you automatically. Every draft is reviewed, edited and approved by a person at Helmshore before it becomes a document you see. There is no automated decision-making that produces legal or similarly significant effects.
- Your content is not used to train models. Anthropic's Commercial Terms of Service state that Anthropic may not train its models on customer content. We retain all rights in what we send, and we own what comes back.
- It is deleted within thirty days. Anthropic automatically deletes the material we send, and the drafts it returns, within thirty days. The exception is material flagged as a possible breach of their usage policy, which they may hold for longer; nothing in a readiness engagement should fall into that category.
- Uploaded evidence documents are not sent to the model. Only structured text answers and the findings drawn from them are.
- Anthropic acts as our processor and may only handle the data on our instructions.
05
Who else processes your data
We use a small number of service providers. Each acts on our instructions under a written contract.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication and file storage for the platform | London (UK) |
| Netlify | Serves this website and the platform's pages | Global content network |
| Resend | Sends sign-in codes and notification emails | US / EU |
| Anthropic | The Claude model that drafts reports and plans (section 04) | US |
We do not sell personal data, and we do not share it for anyone else's marketing.
Transfers outside the UK
Your engagement content is stored in the United Kingdom. Some of the providers above operate outside the UK. Where personal data is transferred out, we rely on UK adequacy regulations where they apply, and otherwise on an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
06
How long we keep it
- During the engagement, for as long as the engagement is live.
- After it ends, for up to six years, to meet legal, tax and professional obligations and to answer questions about work we did.
- Uploaded evidence documents are deleted at the end of the engagement unless you ask us to keep them, or we are required to.
- Audit records are append-only and are kept for the retention period above. They cannot be edited or deleted, by us or by anyone else.
We delete or anonymise personal data when it is no longer needed.
07
How we protect it
- Sign-in is passwordless: a passkey held on your own device, or a single-use code sent to your invited email address and valid only briefly.
- Access is invite-only. The platform will not create an account for an address nobody has invited.
- Every read and every write is checked in the database itself, not merely in the interface. Advisers, client leads and contributors each see only what their role allows.
- Every change is written to an append-only audit log.
- Everything is served over HTTPS, and the site restricts what the browser is allowed to load and connect to.
- Sessions expire after fourteen days of inactivity and after thirty days regardless.
08
Where we act as a processor, not a controller
When your team enters information about other people — your employees, directors, shareholders or counterparties — into the platform, your organisation decides what goes in and why. In that respect your organisation is the controller and Helmshore is your processor: we handle that information only on your instructions and only to deliver the engagement.
Our engagement terms include the data processing provisions required by UK GDPR Article 28. If you need a standalone data processing agreement, ask and we will provide one.
For your own account details — your name, your email address, your sign-in records — we are the controller.
09
Your rights
Under UK data protection law you have the right to:
- ask what personal data we hold about you and receive a copy
- have inaccurate data corrected
- ask us to delete data, where no legal obligation requires us to keep it
- restrict or object to how we use it
- receive certain data in a portable form
- withdraw consent, where we relied on consent
To exercise any of these, email adam@helmshoreconsulting.com. We will respond within one month.
If you are unhappy with how we have handled your data, please tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.
10
Changes to this notice
We update this notice when the platform changes. The current version is always published here, with the date it took effect.