PRIVACY POLICY

PRIVACY POLICY

Business Concierge MRUKWA Ltd
Last updated: 14 June 2026

1. Who we are

The data controller is:

Business Concierge MRUKWA Ltd
A company registered in Scotland / United Kingdom
Company Number: SC632228
Registered office address: 5 South Charlotte Street, Edinburgh, Scotland, EH2 4AN
Contact e-mail: info@mybusinessplan.co.uk
Website: www.mybusinessplan.co.uk

In this Privacy Policy, “we”, “us”, “our company” or “Business Concierge” refers to Business Concierge MRUKWA Ltd.

This Privacy Policy explains what personal data we collect, why we process it, the lawful basis for processing, who we may share it with, how long we keep it for and what rights individuals have in relation to their personal data.

2. Scope of our business

We provide business advisory and documentation services for entrepreneurs and individuals planning to start, fund or grow a business in the United Kingdom. Our services may include, among others:

* Business plan preparation.
* Financial forecasts and cashflow preparation.
* Funding pathway analysis.
* Preliminary financial readiness and funding risk analysis.
* Business consultations.
* Support with preparing documentation for funding applications.
* Strategic, operational or marketing documentation.
* Sale of digital products, consultations, services and educational materials through our website.

Due to the nature of our services, we may process contact, business, financial and documentation-related data provided by clients for the purpose of delivering our services.

3. What personal data we may collect

Depending on the type of contact, form or service, we may process the following categories of personal data:

3.1 Identification data

* Name and surname.
* Business name.
* Position or role in the business.
* Date of birth, where required for a specific process.
* National Insurance Number, where provided by the client as part of documentation required for a funding process.
* Immigration status information or share code, where voluntarily provided by the client for documentation purposes.

3.2 Contact data

* E-mail address.
* Telephone number.
* Residential or correspondence address.
* Business address.
* Data used for communication via e-mail, telephone, WhatsApp, website forms or other agreed communication channels.

3.3 Business data

* Description of the business or business idea.
* Industry, location, target audience and competitors.
* Trading history.
* Business goals.
* Planned investments.
* Information about products, services, pricing, costs, suppliers, premises, employees, equipment, stock and growth strategy.
* Documents, form responses, briefs, consultation notes and other information provided for the purpose of delivering the service.

3.4 Financial data

For services related to funding, financial readiness, forecasting or preparation of funding documentation, we may process:

* Bank statements.
* Income information.
* Expense information.
* Information about financial commitments.
* Information about overdrafts, direct debits, returned payments and credit commitments.
* Information about the requested funding amount.
* Information about personal contribution or deposit.
* Information about start-up and operating costs.
* Information about the financial history of the business.
* Documents required by funding providers, where voluntarily provided by the client.

We are not a bank, lender, credit reference agency or financial institution. Our analysis is advisory, documentary and preparatory in nature. Funding decisions are made independently by funding providers.

3.5 Payment and purchase data

Where a client purchases a product or service through our website or pays for a service, we may process:

* Order details.
* Billing details.
* Information about purchased products or services.
* Payment status.
* Data required to handle complaints, refunds or accounting records.

We do not store full card payment details. Payments may be processed by third-party payment providers in accordance with their own security and privacy policies.

3.6 Technical and analytics data

When using our website, we may collect:

* IP address.
* Device type.
* Browser type.
* Information about how the website is used.
* Referral source.
* Cookies and similar technology data.
* Analytics data relating to website traffic.

The exact scope of this data depends on the tools actually used on our website.

3.7 Marketing data

We may process:

* E-mail address.
* First name.
* Communication preferences.
* Information about services the person has shown interest in.
* History of enquiries, where relevant to providing appropriate communication.

Marketing communication is carried out in accordance with applicable data protection and electronic marketing rules.

4. Where we obtain data from

We mainly obtain personal data directly from the individual, for example when they:

* Complete a form on our website.
* Contact us by e-mail, telephone, WhatsApp or social media.
* Book a consultation.
* Purchase a service or product.
* Send documents for a business plan, forecast, analysis or consultation.
* Take part in a consultation, workshop, training or advisory process.
* Subscribe to a newsletter or educational materials.
* Answer our questions during the preparation of documentation.

We may also receive personal data from a third party where the client has authorised that person to communicate with us on their behalf, for example an accountant, business partner, family member or colleague.

5. Purposes of processing personal data

We process personal data for the following purposes:

5.1 Handling enquiries

We process personal data to respond to enquiries submitted through forms, e-mail, telephone, WhatsApp or social media.

5.2 Preparing an offer or recommendation

We may analyse information provided by a client in order to recommend an appropriate service, scope of work, sequence of actions or funding preparation pathway.

5.3 Delivering services

We process personal data to deliver the purchased or agreed service, including preparing a business plan, financial forecast, cashflow, funding pathway analysis, consultation, audit, documentation or educational materials.

5.4 Funding and risk analysis

Where a client uses a service related to funding, we may analyse financial data, business data and client documents in order to prepare materials, assess application readiness, identify risks or organise documentation.

We do not guarantee that funding will be obtained. Our analysis does not constitute a credit decision or a binding assessment by a funding provider.

5.5 Contact during and after service delivery

We may contact clients in relation to organisation, documents, payments, deadlines, missing information, updates, questions and next steps.

5.6 Payments, invoices and accounting

We process data required to issue invoices, confirm payments, keep accounting records, meet tax obligations and comply with legal requirements.

5.7 Security and legal protection

We may process personal data to protect our rights, bring or defend legal claims, prevent misuse, secure documentation and maintain system security.

5.8 Marketing and education

We may send educational, business or marketing information about our services, products, consultations, events or materials where we have an appropriate lawful basis to do so.

Every person may opt out of marketing communication.

5.9 Website analytics and improvement

We may analyse website usage to improve performance, content, forms, functionality, security and communication effectiveness.

6. Lawful bases for processing personal data

We process personal data in accordance with the UK GDPR and the Data Protection Act 2018. Depending on the situation, the lawful basis may be:

6.1 Steps before entering into a contract or performance of a contract

This applies where a person contacts us to request a service, purchases a service, books a consultation or provides information required for us to perform the service.

6.2 Legal obligation

This applies, for example, to keeping accounting records, invoices, tax information and documentation required by law.

6.3 Legitimate interests

We may process personal data based on legitimate interests, for example to:

* Respond to enquiries.
* Communicate with clients.
* Organise our work and client service.
* Improve the quality of our services.
* Protect against legal claims.
* Prevent misuse.
* Conduct basic website analytics.
* Contact existing clients about similar services, where permitted by applicable rules.

6.4 Consent

In some cases, we process personal data based on consent, for example:

* Newsletter subscriptions.
* Certain marketing activities.
* Certain analytics or marketing cookies.
* Publishing client testimonials, photographs, recordings or case studies.

Consent can be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

7. Financial data and client documents

Due to the nature of our services, clients may provide documents containing financial, business or personal data. Such documents may include, among others:

* Bank statements.
* CVs.
* Company documents.
* Premises-related documents.
* Supplier quotations.
* Application documents.
* Reports, statements, forms, calculations.
* Other materials required to perform the service.

We process these documents only for the purpose of delivering the agreed service, preparing an analysis, documentation, forecast, business plan or consultation.

Clients should only provide documents and data that are necessary for the service. If a document contains third-party data, the client should ensure that they have the right to provide that data to us.

8. Automated decision-making

We do not make decisions based solely on automated processing that would produce legal effects concerning the client or similarly significantly affect them.

We may use digital tools, calculators, spreadsheets, forms, analytics systems or tools supporting our work, but final recommendations, documents and communication are based on human analysis.

9. Use of AI tools

We may use digital tools or artificial intelligence-based tools to support administrative, editorial, analytical or organisational work.

We should not input client financial data, client documents or data identifying the client into external AI tools unless this is necessary to perform the service, secure, compliant with applicable data protection principles and appropriately agreed.

Where the use of a specific tool would require transferring personal or financial client data outside our standard systems, we will assess the necessity, security and lawful basis for doing so.

10. Who we may share data with

We do not sell personal data.

We may share personal data only where necessary to provide our services, operate our business, comply with legal obligations or where the client has given consent.

Data may be shared with the following categories of recipients:

* Website hosting providers.
* E-mail service providers.
* Form system providers.
* Payment service providers.
* Accounting system providers.
* Accountants, tax advisers or legal advisers.
* CRM, file storage or document management providers.
* Analytics tool providers.
* Marketing tool providers, where used.
* Team members or subcontractors working on service delivery.
* Funding providers, brokers, partners or advisers only where this is part of the agreed process or where the client specifically requests it.
* Public authorities, regulators or courts where required by law.

Any party processing data on our behalf should do so under appropriate confidentiality, security and data protection arrangements.

11. International transfers

Some technology tools, such as e-mail, hosting, payment systems, analytics systems, CRM, marketing tools or file storage systems, may process data outside the United Kingdom.

Where personal data is transferred outside the United Kingdom, we aim to use providers that ensure an appropriate level of data protection, for example through appropriate legal mechanisms, adequacy decisions, standard contractual clauses or other safeguards required by applicable law.

12. How long we keep data

We keep personal data only for as long as necessary for the purposes for which it was collected or for as long as required by law.

Indicative retention periods:

* Enquiries that do not result in cooperation: up to 24 months from the last contact, unless further retention is justified.
* Client data and service documentation: up to 6 years from the end of cooperation, where needed for accounting, tax, evidential or legal claim purposes.
* Invoices and accounting records: in accordance with applicable accounting and tax requirements.
* Marketing data: until consent is withdrawn, the person unsubscribes or objects.
* Cookies and analytics data: according to the settings of the relevant tool and user consent.
* Financial documents provided for a specific analysis: for the period necessary to perform the service and maintain supporting records, unless otherwise agreed or legally required.

After the relevant period expires, data is deleted, anonymised or archived in a restricted manner where legally justified.

13. Data security

We use appropriate organisational and technical measures to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.

These measures may include, among others:

* Restricting access to data to people who need it to perform their work.
* Using protected accounts and passwords.
* Storing documents in selected business systems.
* Taking care when sending documents.
* Regularly organising data and documents.
* Confidentiality obligations for team members and collaborators.

Clients should also take care when sending documents and should not provide data that is not necessary for the service.

14. Electronic marketing

We may send marketing, educational or informational communication about our services, products, consultations, events or materials where:

* The recipient has given consent.
* Another lawful basis permitted by applicable rules applies.
* The communication concerns similar services for an existing client and the law permits such contact.

Every person may opt out of marketing communication at any time by clicking an unsubscribe link, replying to the message or contacting us at:

info@mybusinessplan.co.uk

After opting out, we may still contact the person about administrative, legal, accounting or service-related matters.

Under PECR, consent is generally required before sending unsolicited electronic mail marketing to individual subscribers, although specific soft opt-in rules may apply in limited situations.

15. Cookies and similar technologies

Our website may use cookies and similar technologies. Cookies are small files stored on a user’s device that help the website function properly, analyse traffic, remember preferences or support marketing activities.

We may use the following categories of cookies:

15.1 Strictly necessary cookies

These are required for the website, forms, basket, payments, security or basic website functions to work properly. These cookies do not require consent where they are necessary to provide a service requested by the user.

15.2 Analytics cookies

These help us understand how users interact with the website, which content is useful and where the website functionality should be improved.

15.3 Marketing cookies

These may be used to measure advertising effectiveness, remarketing, advertising personalisation or campaign analysis.

15.4 Functional cookies

These may remember user choices, such as language, preferences or website settings.

Users can manage cookies through browser settings or through a cookie banner, where available on the website.

Analytics and marketing cookies should be used in accordance with applicable law and, where required, only after obtaining the user’s consent.

16. Links to other websites

Our website may contain links to external websites, tools, payment portals, calendars, forms or social media platforms.

We are not responsible for the privacy policies, content or security practices of external websites. We recommend reviewing the privacy policy of every website or service used.

17. Testimonials, case studies, photographs and recordings

We may publish client testimonials, photographs, recordings, business names or cooperation stories only where we have an appropriate lawful basis, such as the client’s consent.

A client may withdraw consent for future use of their testimonial, photograph or recording by contacting us. Withdrawal of consent does not affect the lawfulness of use that took place before consent was withdrawn.

18. Children’s data

Our services are not directed at children. We do not knowingly collect children’s data for business or marketing purposes.

If we become aware that we have received children’s data without an appropriate lawful basis or consent from an authorised person, we will take steps to delete such data.

19. Individual rights

Individuals have rights under data protection law. Depending on the circumstances, these may include:

* The right of access.
* The right to rectification.
* The right to erasure.
* The right to restriction of processing.
* The right to object to processing.
* The right to data portability.
* The right to withdraw consent where processing is based on consent.
* The right to be informed about how data is processed.
* The right to lodge a complaint.

The right to object to processing based on legitimate interests may be exercised at any time by contacting us.

To exercise your rights, please contact us at:

info@mybusinessplan.co.uk

We may request additional information to verify the identity of the person making the request.

20. Data protection complaints

If you believe that we process your personal data unlawfully or incorrectly, please contact us first at:

info@mybusinessplan.co.uk

We will aim to respond to the complaint and resolve the matter in accordance with applicable requirements.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office (ICO)
Website: www.ico.org.uk

From 19 June 2026, UK organisations are required to have a process for handling data protection complaints under the Data (Use and Access) Act 2025.

21. Changes to this Privacy Policy

We may update this Privacy Policy if the law changes, our services change, the website functionality changes, the technology tools we use change or the way we process personal data changes.

The current version of this Privacy Policy will be available on our website.