Legal

Privacy Policy

How Albany Limited, trading as Zymbos Advisory, handles personal data on this website and in our advisory work. Last updated 25 August 2026.

1. Who we are

Albany Limited, trading as Zymbos Advisory (“we”, “us”), is the controller of the personal data described in this policy. Registered in England & Wales, company no. 02964693. Registered office: Vine Cottages, 215 North Street, Romford, Essex RM1 4QA. Contact: hello@zymbosadvisory.com. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018. ICO registration number: to be confirmed (registration in progress; this page will be updated once issued).

2. What this policy covers

This policy covers our website at zymbosadvisory.com and the personal data we handle in enquiries, proposals and advisory engagements. The Zymbos AI Governance Tracker is a separate service with its own privacy policy, available within that application. This website is not directed at children.

3. What we collect

Enquiry and proposal data: your name, work email, company, phone number and message when you use our contact or assessment forms. Newsletter data: your email address when you subscribe to updates. Booking data: when you book a call through Calendly, your name, email and chosen time. Engagement data: information you provide during an advisory engagement, handled under the engagement terms and kept to the minimum needed. Technical data: IP address, browser and device information and server logs generated when you visit the site, used for security and troubleshooting. We do not collect special category data through this website, and we perform no profiling or automated decision-making about you.

4. Why we process it, and our legal bases

To respond to enquiries and prepare proposals: steps prior to a contract and our legitimate interests (UK GDPR Art. 6(1)(b) and (f)). To deliver advisory engagements: performance of a contract (Art. 6(1)(b)). To send updates you have subscribed to: your consent (Art. 6(1)(a)), withdrawable at any time via the unsubscribe link or by contacting us. To secure and improve the website: our legitimate interests (Art. 6(1)(f)). To meet legal and accounting obligations: legal obligation (Art. 6(1)(c)). We do not sell personal data, and we show no advertising.

5. Service providers we share data with

Cloudflare hosts and serves this website. Web3Forms (operated by Web3Creative) relays contact-form submissions to our mailbox. Calendly handles call bookings. Microsoft 365 provides our email. oxethica provides the assessment platform used in engagements, hosted in the EU (Frankfurt). Stripe processes card payments where an engagement is paid by card; for some regulated activities, such as fraud monitoring, Stripe acts as an independent controller of payment data. Each provider acts under contractual terms limiting its use of your data. We share personal data with no one else, unless required by law.

6. International transfers

Some of our providers process data outside the UK. We use two lawful transfer routes under the UK GDPR. UK-US Data Bridge: providers certified under the UK Extension to the EU-US Data Privacy Framework, which the UK government has recognised as providing adequate protection (Stripe is certified). Approved contract clauses: for our other providers, including Web3Forms and Calendly, we rely on the UK Addendum to the EU Standard Contractual Clauses (or the UK International Data Transfer Agreement), as incorporated in each provider's data processing terms. Where a provider's Data Bridge certification lapses, its terms fall back to the approved contract clauses automatically. You can request further details of these safeguards by contacting us.

7. How long we keep it

Contact-form messages and enquiries: up to 24 months. Newsletter data: until you unsubscribe. Engagement records and deliverables: up to 6 years after the engagement ends, to meet legal, insurance and tax obligations. Billing and financial records: up to 6 years. Server logs: 90 days on a rolling basis.

8. Security

Connections to this website use TLS encryption, and access to our systems is restricted and protected. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the ICO where the law requires it.

9. Your rights

Under the UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the basis. To exercise them, contact hello@zymbosadvisory.com. You may also complain to the Information Commissioner's Office (ico.org.uk).

10. Cookies

This website sets no analytics or advertising cookies. Strictly necessary items only: our hosting provider may set a security cookie, and embedded services such as Calendly set their own cookies when you use them, under their own policies. Any non-essential cookies introduced later will be set only with your consent.

11. Changes

We may update this policy from time to time; the latest version will always appear on this page with its “last updated” date.