FLORUI LIMITED | PRIVACY POLICY
Effective Date: 26 June 2026 | Version 1.0 | www.florui.co.uk
1. Introduction
Florui Limited ("Florui", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.
This policy applies to all personal data processed in connection with our business advisory and consulting services, our website at www.florui.co.uk, and any other interactions you may have with us. Please read this policy carefully to understand our practices regarding your personal data and how we will treat it.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other applicable data protection legislation in force from time to time.
2. Data Controller
The data controller responsible for your personal data is:
Florui Limited
Registered in England and Wales
Website: www.florui.co.uk
Founder: David Wallis
Email: dave@florui.co.uk
Correspondence Address: United Kingdom
If you have any questions about this Privacy Policy or our data protection practices, please contact us using the details provided in Section 14 of this policy.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Data Collected from Clients and Prospective Clients
· Full name and job title
· Business name and registered address
· Contact details including email address, telephone number, and postal address
· Financial information relevant to advisory engagements (e.g. business performance data, financial statements)
· Information about your business objectives, strategy, and operations shared during consultations
· Correspondence and communications records
· Invoicing and payment information
· Information provided in contracts, engagement letters, and related documentation
· Due diligence information where required for regulatory or contractual purposes
3.2 Data Collected from Website Visitors
· IP address and browser type
· Pages visited and time spent on the website
· Referring website or search terms used to find us
· Contact form submissions (name, email address, message content)
· Cookie data and similar tracking technologies (see Section 11)
· Any other information you voluntarily submit via the website
3.3 Special Categories of Data
We do not routinely collect special category personal data (such as health information, racial or ethnic origin, political opinions, or criminal record information). If such data is required in connection with a specific engagement, we will seek your explicit consent and explain how it will be used before collecting it.
4. How We Collect Personal Data
We collect personal data through the following means:
Direct interactions: You may provide data directly to us when you complete our website contact form, correspond with us by email or telephone, enter into a contract or engagement letter with us, attend meetings or calls with us, or provide information as part of an advisory engagement.
Automated technologies: When you visit our website, we may automatically collect technical data about your equipment and browsing activity using cookies and similar technologies. Please see Section 11 for more information.
Third parties and public sources: We may receive personal data about you from third parties, such as referrals from existing clients, information from companies' public filings (e.g. Companies House), or publicly available professional profiles (e.g. LinkedIn).
Contractual and legal obligations: We may collect data through the execution of contracts, non-disclosure agreements, engagement letters, and other legally binding documents.
5. Legal Basis for Processing
We process your personal data only where we have a lawful basis to do so. The legal bases we rely on are:
Performance of a contract (Article 6(1)(b) UK GDPR): Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes processing data to deliver our advisory and consulting services.
Legitimate interests (Article 6(1)(f) UK GDPR): Where processing is necessary for our legitimate business interests, such as maintaining client records, business development, improving our services, and ensuring the security of our systems — provided these interests are not overridden by your rights and interests.
Consent (Article 6(1)(a) UK GDPR): Where you have given clear consent for us to process your data for a specific purpose, such as sending you marketing communications or placing non-essential cookies on your device. You may withdraw consent at any time.
Compliance with a legal obligation (Article 6(1)(c) UK GDPR): Where processing is necessary to comply with a legal or regulatory obligation to which we are subject, such as anti-money laundering requirements or tax record-keeping obligations.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
· To provide and manage our business advisory and consulting services
· To communicate with you regarding your engagement, queries, or requests
· To draft, execute, and manage contracts, engagement letters, and related documentation
· To send invoices and process payments
· To comply with our legal, regulatory, and professional obligations
· To conduct due diligence where required
· To maintain internal records and business administration
· To improve and develop our website and services
· To send you information about our services or insights where you have consented or where we have a legitimate interest to do so
· To protect the security of our business, clients, and systems
· To handle complaints, disputes, or legal proceedings
7. Data Sharing and Third Parties
We do not sell your personal data. We may share your data with the following categories of third parties only where necessary and appropriate:
Professional advisers: Including lawyers, accountants, and insurers who provide professional services to Florui Limited, subject to duties of confidentiality.
IT and software service providers: Including cloud storage providers, email platforms, and document management tools used to run our business operations, who process data on our behalf under data processing agreements.
Sub-contractors and associates: Where we engage external consultants or specialists to support a client engagement, we will only share the minimum necessary data and will ensure appropriate confidentiality and data protection obligations are in place.
Regulatory authorities and law enforcement: Where required by law, court order, or regulatory obligation, we may disclose personal data to relevant authorities.
Prospective buyers or investors: In the event of a business transfer, merger, or acquisition, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
7.1 International Transfers
We primarily process and store data within the United Kingdom. Where we transfer personal data outside the UK, we will ensure that appropriate safeguards are in place (such as UK adequacy decisions or Standard Contractual Clauses) to protect your data in accordance with UK GDPR requirements.
8. Data Retention
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements. Our standard retention periods are as follows:
Category of Data | Retention Period | Reason
Client engagement records and contracts | 7 years from end of engagement | Legal and tax obligations; limitation periods
Correspondence and emails | 7 years from end of engagement | Business records and legal protection
Invoicing and financial records | 7 years | HMRC requirements
Website contact form enquiries | 2 years from last contact | Legitimate interest in follow-up
Website analytics and cookie data | Up to 26 months | Industry standard for analytics
Marketing preferences and consent records | Until consent is withdrawn or 3 years of inactivity | Consent management
Prospective client data (no engagement commenced) | 2 years from last contact | Legitimate business interest
At the end of the relevant retention period, we will securely delete or anonymise your personal data.
9. Security of Your Personal Data
We take appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, use, alteration, or disclosure. These measures include:
· Use of secure, encrypted communication channels for transmitting sensitive information
· Password protection and access controls on systems storing personal data
· Use of reputable, security-certified cloud service providers
· Regular review and update of our information security practices
· Restricting access to personal data to those who have a legitimate business need
· Physical security measures for any paper-based records
Whilst we take all reasonable steps to protect your data, no method of transmission over the internet or method of electronic storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately.
10. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights in relation to your personal data:
Right of access: You have the right to request a copy of the personal data we hold about you (known as a Subject Access Request).
Right to rectification: You have the right to ask us to correct inaccurate or incomplete personal data we hold about you.
Right to erasure: You have the right to request that we delete your personal data in certain circumstances (e.g. where it is no longer necessary for the purpose it was collected, or where you have withdrawn consent).
Right to restriction of processing: You have the right to ask us to restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have contested.
Right to data portability: Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to have it transferred to another controller.
Right to object: You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis, or where we process your data for direct marketing purposes.
Rights in relation to automated decision-making: You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects on you. We do not currently use automated decision-making in this way.
Right to withdraw consent: Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact us using the details in Section 14. We will respond to your request within one month. We may need to verify your identity before processing your request. There is no charge for exercising these rights in most circumstances.
11. Cookie Policy
Our website at www.florui.co.uk uses cookies and similar tracking technologies to improve your browsing experience and to understand how visitors use our site.
11.1 What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They allow the website to remember your actions and preferences over a period of time, so you do not have to keep re-entering them. Cookies can be "session cookies" (which expire when you close your browser) or "persistent cookies" (which remain on your device for a set period).
11.2 Types of Cookies We Use
Strictly necessary cookies: These are essential for the website to function and cannot be switched off. They are usually set in response to actions you take, such as setting your privacy preferences, logging in, or filling in forms. Without these cookies, the website cannot function properly.
Analytical/performance cookies: These allow us to count visits and traffic sources so we can measure and improve the performance of our website. They help us understand which pages are the most and least popular and see how visitors move around the site. All information collected is aggregated and anonymous. We may use tools such as Google Analytics for this purpose.
Functionality cookies: These enable the website to provide enhanced functionality and personalisation. They may be set by us or by third-party providers whose services we have added to our pages.
Targeting/marketing cookies: These may be set through our website by our advertising partners to build a profile of your interests and show you relevant content or adverts. If you do not allow these cookies, you will experience less targeted content.
11.3 Managing Cookies
You can control and manage cookies in several ways. When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies.
You can also set your browser to refuse some or all cookies, or to alert you when websites set or access cookies. Please note that if you disable or refuse cookies, some parts of our website may become inaccessible or not function properly.
For more information about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org or www.youronlinechoices.eu.
12. Third-Party Links and Services
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit when you leave ours.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or other factors. We will notify you of any material changes by:
· Posting the updated policy on our website at www.florui.co.uk with a new effective date
· Sending you a notification by email where we hold your contact details and the change is significant
We encourage you to review this policy periodically to stay informed about how we are protecting your personal data. Your continued engagement with us following any update constitutes your acknowledgement of the revised policy.
14. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact us:
Data Privacy Enquiries
Florui Limited
Email: dave@florui.co.uk
Website: www.florui.co.uk
Attn: David Wallis, Founder
We aim to respond to all privacy-related queries within 5 working days and will always respond within one month as required by UK GDPR.
15. Your Right to Complain to the ICO
If you are not satisfied with how we handle your personal data, or if you believe we have not complied with our obligations under UK data protection law, you have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address your concerns before you contact the ICO, so please contact us in the first instance.
Florui Limited | www.florui.co.uk | Effective Date: 26 June 2026 | Version 1.0
