Legal · Data Protection

Privacy Policy

This notice explains how RRH Advisory Limited ("RRH", "we", "us", "our") collects, uses, stores, discloses and protects personal data when you visit our website, submit an enquiry, or engage our advisory services. We handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable national data protection laws in the European Economic Area, the United Kingdom and the Nordic countries.

Last updated: 16 July 2026 · Version 2.1

1. Who we are and how to contact us

RRH Advisory Limited is a company registered in England and Wales under company number 17283513, with its registered office at 88 Miswell Lane, Tring, England, HP23 4EX. For the purposes of the UK GDPR, RRH acts as the data controller in respect of personal data processed through this website and in the course of client engagements, unless a written engagement letter specifies otherwise.

RRH Advisory Limited

88 Miswell Lane · Tring · England · HP23 4EX
Company number: 17283513
Telephone: +352 27 86 05 77
Privacy enquiries: privacy@rrh-advisory.com
General enquiries: enquiries@rrh-advisory.com

2. Scope of this notice

This notice applies to personal data processed in connection with (a) visitors to the RRH website; (b) individuals who submit an enquiry, request a consultation or otherwise correspond with us; (c) clients and prospective clients of RRH, and their representatives; (d) counterparties, witnesses, beneficial owners and other individuals whose data we process in the course of an engagement; (e) suppliers, agents and professional counterparts; and (f) recipients of our marketing communications, including audiences reached through paid social advertising in the Nordic region and elsewhere.

This notice does not apply to personal data processed by third parties whose services or websites we link to. Their processing is governed by their own privacy notices, which we encourage you to review.

3. Categories of personal data we process

Depending on the nature of your interaction with us, we may process the following categories of personal data:

  • Identification data — full name, title, date of birth (where relevant to an engagement), nationality and, where required by law, identification document numbers.
  • Contact data — postal address, email address, telephone number, and the name and address of any authorised representative.
  • Professional data — employer, job title, professional qualifications and areas of responsibility.
  • Enquiry data — the content of any enquiry, consultation form, email or telephone message you send us, including a free-text description of your matter and, where you choose to provide it, an approximate financial magnitude expressed as a range.
  • Engagement data — matter reference, correspondence, meeting notes, documents you or third parties provide to us, records of advice given, invoices and payment references.
  • Financial data — where relevant to an engagement, transaction records, account statements, contracts, correspondence with financial institutions and other documentary material.
  • Website and technical data — IP address, device and browser type, operating system, language, referring URL, pages viewed, timestamps and interactions with page elements, and diagnostic logs.
  • Marketing data — records of consents given or withdrawn, subscription preferences, and identifiers used for measurement of advertising campaigns (see sections 7 and 8).

We do not require you to provide financial account numbers, copies of identification documents or payment card details through this website. If such information is required for an engagement, it will be requested through a secure channel established with your adviser.

4. Sources of personal data

We collect personal data from the following sources:

  • Directly from you, when you complete a consultation form, correspond with us by email or telephone, meet with an adviser, or provide documents in the course of an engagement.
  • From your representatives, where you instruct legal counsel, an accountant, a family office or another intermediary to communicate with us on your behalf.
  • From counterparties and third parties, where their conduct or documentation is relevant to a matter we are asked to advise on, and where lawful.
  • From public sources, including public registers, court records, regulatory filings, news reports, and sanctions and politically-exposed-persons databases.
  • From your device and browser, through cookies, similar technologies and server logs, when you visit this website.
  • From advertising platforms, where a user interacts with an RRH advertisement and the platform reports aggregated or event-level data back to us.

5. Purposes and lawful bases of processing

We rely on the following lawful bases under Article 6(1) GDPR:

Responding to your enquiry and providing information you requestArticle 6(1)(b) — necessary to take steps at your request prior to entering into a contract; and Article 6(1)(f) — our legitimate interest in operating a professional advisory practice.
Providing advisory services under an engagement letterArticle 6(1)(b) — performance of a contract to which you are party.
Client due diligence, know-your-client and sanctions screeningArticle 6(1)(c) — compliance with legal obligations to which we are subject; and Article 6(1)(f) — legitimate interest in preventing fraud, money laundering and financial crime.
Record-keeping, accounting and taxArticle 6(1)(c) — compliance with legal obligations under English commercial and tax law.
Managing complaints, disputes and legal claimsArticle 6(1)(f) — our legitimate interest, and that of our clients, in establishing, exercising or defending legal claims.
Operating, securing and improving the websiteArticle 6(1)(f) — our legitimate interest in providing a secure, functional website; and, where required, Article 6(1)(a) — your consent for non-essential cookies.
Direct marketing to existing and prospective clients, including paid advertising on Meta platformsArticle 6(1)(a) — your consent, where required; and Article 6(1)(f) — our legitimate interest in promoting our services, subject to your right to object at any time.

6. Special-category and sensitive data

We do not seek special-category data (Article 9 GDPR — data concerning health, religion, political opinions, trade-union membership, sexual orientation, or racial or ethnic origin) or criminal-conviction data (Article 10 GDPR) through this website. If you provide such information voluntarily in the free-text field of a consultation form, or if such information is relevant and proportionate to an engagement, we will process it only where a specific condition in Article 9(2) or Article 10 GDPR is met — typically your explicit consent, or the establishment, exercise or defence of legal claims. You should not send us sensitive information through this website unless it is necessary.

7. Cookies, analytics and marketing pixels

Our website uses cookies and similar technologies. A cookie is a small text file placed on your device by your browser. We use the following categories:

  • Strictly necessary cookies — required for the operation of the site, such as maintaining session state and protecting against cross-site request forgery. These do not require consent under Article 5(3) of the ePrivacy Directive as transposed into UK law by the Privacy and Electronic Communications (EC Directive) Regulations 2003.
  • Analytics cookies — used to understand aggregate visitor behaviour and improve the site. Where these are non-essential, we set them only after you have given consent through our cookie banner.
  • Marketing and measurement cookies and pixels — including the Meta Pixel and the Meta Conversions API, used to measure the effectiveness of our advertising campaigns and to construct advertising audiences. These are set only with your consent.

You may withdraw your consent to non-essential cookies at any time by clearing cookies in your browser, adjusting your browser settings, or contacting us at privacy@rrh-advisory.com. Blocking strictly-necessary cookies may impair the functionality of the site.

8. Facebook / Meta advertising and Custom Audiences

RRH promotes its services through paid campaigns on Meta platforms, including Facebook and Instagram, targeted primarily at professional audiences in the Nordic region and other European markets. Where you have consented to marketing and measurement cookies:

  • The Meta Pixel and the server-side Meta Conversions API may transmit event data — such as page views, form submissions and button interactions — to Meta Platforms Ireland Limited, together with hashed identifiers such as your hashed email address if you have provided one.
  • We and Meta act as joint controllers in respect of the collection and transmission of that event data, as described in Meta's Controller Addendum. Meta acts as an independent controller for the subsequent use of the data for its own purposes.
  • We may create Custom Audiences and Lookalike Audiences to reach individuals with similar interests. We do not upload sensitive personal data to Meta and we do not target audiences on the basis of financial vulnerability, alleged victimisation or any other protected characteristic.

You can control how Meta uses information about you through your Facebook and Instagram advertising preferences, and you can opt out of interest-based advertising through the tools operated by the European Digital Advertising Alliance (youronlinechoices.eu).

9. Disclosure to third parties and processors

We disclose personal data only where necessary and lawful. Recipients may include:

  • Members of the RRH team, on a need-to-know basis and under professional confidentiality obligations.
  • Specialists and sub-advisers engaged for a specific matter, including lawyers, accountants, forensic professionals, translators and mediators.
  • Service providers that process personal data on our behalf under a written data-processing agreement — including hosting and cloud infrastructure providers, email and productivity providers, secure document-exchange platforms, customer-relationship-management tools, and analytics and advertising platforms as described in sections 7 and 8.
  • Financial institutions, regulators, ombudsman schemes, courts, tribunals and law-enforcement authorities, where required by law, court order or regulatory obligation, or where necessary to establish, exercise or defend legal claims.
  • Professional advisers to RRH, including our own legal counsel, auditors and insurers.
  • Acquirers or successors, in the event of a reorganisation, sale or transfer of all or part of our business, subject to appropriate confidentiality protections.

10. International transfers of personal data

Personal data is primarily processed within the European Economic Area. Where a transfer to a country outside the EEA is necessary — for example, to a sub-adviser or service provider established elsewhere — we ensure that appropriate safeguards under Chapter V of the GDPR are in place. These typically include (a) a European Commission adequacy decision, or (b) the Standard Contractual Clauses adopted by the European Commission on 4 June 2021, supplemented, where required, by additional technical, contractual and organisational measures identified through a transfer impact assessment. You may request a copy of the safeguards used for a specific transfer by contacting privacy@rrh-advisory.com.

11. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter for such additional period as is required to comply with legal, regulatory, tax and professional obligations, or to establish, exercise or defend legal claims. Indicative retention periods are:

Website analytics and diagnostic logsUp to 13 months from the date of collection.
Enquiries that do not result in an engagement24 months from the date of last contact, unless a longer period is justified.
Client-engagement files, including correspondence and advice10 years from the closure of the matter, in accordance with English professional practice.
Client due-diligence records5 years from the end of the business relationship, in accordance with anti-money-laundering legislation, or longer where required.
Accounting and tax records10 years from the end of the financial year to which they relate.
Marketing preferences and consent recordsFor the duration of the marketing relationship and for 3 years thereafter.

At the end of the applicable retention period, personal data is securely deleted or irreversibly anonymised.

12. Information security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls on a least-privilege basis, encryption of data in transit using industry-standard TLS, encryption of data at rest for engagement files, segregated environments for production and non-production systems, regular patching and vulnerability management, secure development practices, business-continuity and back-up arrangements, staff confidentiality undertakings and periodic security training. We keep our measures under review and update them in line with evolving risk and good practice.

13. Your rights as a data subject

Subject to the conditions and limitations set out in the GDPR, you have the following rights:

  • Right of access — to obtain confirmation as to whether we process personal data concerning you and, if so, a copy of that data.
  • Right to rectification — to request that inaccurate or incomplete personal data be corrected or completed.
  • Right to erasure — to request the deletion of your personal data in the circumstances specified in Article 17 GDPR.
  • Right to restriction of processing — to require us to limit our processing in the circumstances specified in Article 18 GDPR.
  • Right to data portability — to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where processing is based on consent or on a contract and is carried out by automated means.
  • Right to object — to object at any time to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes.
  • Right to withdraw consent — to withdraw any consent previously given, without affecting the lawfulness of processing carried out before the withdrawal.
  • Right not to be subject to solely automated decisions producing legal or similarly significant effects, as further described in section 14.

To exercise any of these rights, please contact privacy@rrh-advisory.com. We may request information to verify your identity before responding, and we will respond within one month of receipt of your request, subject to any extension permitted under Article 12(3) GDPR.

14. Automated decision-making and profiling

RRH does not take decisions that produce legal effects concerning you, or similarly significantly affect you, on the basis of solely automated processing. Advisory decisions are always made by, or under the responsibility of, a qualified adviser. Limited profiling may occur in the context of website analytics and advertising, as described in sections 7 and 8, but this does not affect any decision taken by RRH in the course of an engagement.

15. Confidentiality of advisory engagements

Information you share with RRH in the course of an actual or prospective engagement is treated as strictly confidential, in addition to the protection afforded by data-protection law. We do not discuss or acknowledge specific engagements outside the RRH team without the client's written authorisation, save where disclosure is required by law, court order, regulatory obligation or the rules of a professional body.

16. Children's data

Our services are directed to professional and adult clients. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, please contact privacy@rrh-advisory.com so that we can take appropriate action.

17. Changes to this notice

We may update this notice from time to time to reflect changes in our practices or applicable law. The version number and effective date at the top of this notice indicate the most recent revision. Material changes will be brought to your attention through the website or, where appropriate, by direct communication.

18. Complaints and supervisory authorities

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for RRH is:

Information Commissioner's Office (ICO)

Wycliffe House · Water Lane · Wilmslow · Cheshire · SK9 5AF · United Kingdom
Tel: 0303 123 1113 · www.ico.org.uk

You may also lodge a complaint with the supervisory authority of your country of residence, place of work, or the place of the alleged infringement — including, in the Nordic region, the Swedish Authority for Privacy Protection (IMY), the Norwegian Data Protection Authority (Datatilsynet), the Danish Data Protection Agency (Datatilsynet), and the Office of the Data Protection Ombudsman of Finland.