Skip to main content
Huntley Cross
  • Home
  • About
  • Leadership
  • Services
    • All Services
    • AI Readiness Audit
    • AI System Implementation
    • Fractional AI Operator
    • Agentic AI
    • AI & Automation
    • Data & Analytics
    • Financial Consulting
    • Tax Advisory
    • M&A Advisory
    • Risk Management
    • Digital Transformation
    • Business Strategy
  • Portfolio
    • Case Studies
    • Portfolio Details
  • Careers
  • Blog
  • Contact
Book a Partner-Led Scoping Call

Privacy Policy

Home/Privacy Policy

Last updated: 25 April 2026

1. Who we are

Huntley Cross Advisory is the trading name of Zaex Enterprises LLP, a Limited Liability Partnership registered in India (GST 33AADFZ0704B1ZU). In this policy “we”, “our” and “us” refer to Zaex Enterprises LLP trading as Huntley Cross Advisory.

We are the data controller in respect of personal data collected through this website and through engagements we deliver under the Huntley Cross Advisory brand.

2. The personal data we collect

2.1 Information you provide

We collect personal data when you contact us, book a scoping call, subscribe to insights, or engage our services. This typically includes your name, work email address, phone number, employer or company, and the substance of any brief you share with us.

Submitting the contact form sends what you typed to two independent destinations, rather than to one destination with a copy taken afterwards. Formspree processes it on our behalf and delivers it to our inbox, and our own enquiry store records it so that enquiries can be counted, tracked and answered. Both receive the same submission directly from your browser, and the distinction matters for the deletion request described in section 9. Every other form on this site, including newsletter subscriptions and careers applications, goes to Formspree alone and is not recorded in the enquiry store.

The enquiry store also records a keyed hash of your IP address rather than the address itself. It is used to limit how many submissions one source can make and cannot be reversed back into an address by us.

2.2 Automated classification of your enquiry

Shortly after you submit the contact form, your message and email address are sent once to a language model, which classifies the enquiry: whether it is spam, what kind of organisation it appears to come from, and what you appear to be asking about. This helps us prepare before replying.

No decision about you is made automatically. The classification is read by a person and informs how we prepare; it does not decide whether you get a reply, and it produces no legal or similarly significant effect. You can ask us what was recorded about your enquiry using the address in section 9.

Routing is pinned to three named providers in the United States, all operating under zero data retention, so your message is not stored by them for any period and cannot be routed elsewhere. They are named in the table in section 7. The model is not trained on what you send.

2.3 Information we obtain from other sources

We maintain a client database covering the organisations we work with or expect to, the business contacts we deal with at them, and published news about those organisations. Not all of it comes from you. Some is compiled from public sources: company registers, organisation websites and news reporting.

Where a record concerns a person, it concerns them in a professional capacity, for the purpose of scoping and delivering advisory engagements. We do not build profiles of people in a personal capacity, and we do not seek special category data.

Every record carries its own provenance, meaning where it came from and when it was obtained. That is deliberate, and it is what lets us answer a question about one specific entry rather than describing our practice in general. If you want to know what we hold about you and where each part of it came from, ask using the address in section 9 and we will tell you.

Where we have obtained your details from a source other than you, you have the same rights set out in section 9, including the right to object to the processing and to ask us to erase what we hold.

2.4 Information collected automatically

When you visit this website we collect technical information, IP address, browser and device, pages visited and time spent, and referring URL.

Two separate mechanisms are involved, and they behave differently:

  • Google Analytics 4 loads only after you accept the consent banner. If you decline, it does not load.
  • Cloudflare Web Analytics is injected by our content delivery network at the network edge, before this website's own code runs. It is cookieless, but it is not controlled by the consent banner. If you do not wish to be measured by it, block static.cloudflareinsights.com in your browser.

If you submit a form, we also record the campaign and referral parameters present in the URL you arrived on, so we can tell which pages generate enquiries. These are stored in your browser for 30 days and sent with the form.

3. Why we process your personal data

We process personal data to:

  • respond to enquiries and operate scoping calls;
  • deliver and manage engagements under contract;
  • send periodic insight communications where you have opted in;
  • operate, secure and improve this website;
  • comply with legal, tax, accounting and audit obligations.

Our lawful bases under the UK GDPR / EU GDPR are: contract (for engagement delivery), legitimate interests (for replying to your enquiry, recording and tracking that enquiry so it is not lost or answered twice, business-to-business outreach to a named role at an organisation about services relevant to it, securing the site, and basic operational analytics), consent (for cookies that are not strictly necessary, and for marketing communications), and legal obligation (for tax and accounting record retention).

Outreach is a separate purpose from replying to you, and we treat it as one. Contacting you because you wrote to us, and contacting you because we think our work is relevant to your organisation, rest on different bases and are recorded separately: a permission record holds the person, the channel, the purpose, the basis and where that basis came from, and a send that has no matching live record does not go out. You may object to outreach at any time, and the right to object attaches specifically to legitimate interests. An objection, a bounce or a complaint suppresses your address, and that suppression is kept deliberately so a later import cannot quietly undo it.

Asking us to erase your data also suppresses your address, and this is the one thing we keep afterwards. When we erase you we retain a one-way cryptographic hash of your email address and nothing else: not your name, not your message, not the address itself, and nothing that can be turned back into it. Its only purpose is that if your details later reach us again from another source, the system recognises that you asked not to be contacted and refuses to send. Without it, erasing you would make you contactable again the moment your name reappeared, which is the opposite of what you asked for. You can ask us to remove that record too, and we will explain the consequence before doing so.

4. Confidentiality of engagement materials

Information you share when scoping or executing a mandate is treated as confidential by default. We sign a written non-disclosure agreement before any material exchange of substantive information. Engagement materials are retained only for the duration of the mandate plus the period required to meet our professional and statutory record-keeping duties, after which they are securely destroyed.

5. Cross-border transfers

Because Zaex Enterprises LLP is registered in India and we serve clients in the United Kingdom, the European Economic Area and other jurisdictions, your personal data may be transferred outside the UK and EEA. Where this applies, we rely on Article 46 GDPR safeguards: the UK International Data Transfer Agreement (IDTA) or the European Commission’s Standard Contractual Clauses, supported by appropriate technical and organisational measures.

Personal data of Indian residents is processed in accordance with the Digital Personal Data Protection Act, 2023.

One point specific to the enquiry store, because it is easy to state too comfortably: the database itself is hosted in London, but the code that writes to it runs on Cloudflare's global network and executes at whichever location your request enters that network. Pinning that execution to a single jurisdiction is not available on our current plan. Storage location and processing location are therefore two different answers, and the Article 46 safeguards above are what cover the difference. We would rather say that than claim the whole path sits in London.

6. Cookies and tracking

We use a small number of strictly necessary cookies. Google Analytics loads only after you accept the consent banner, and not at all if you decline.

Withdrawing consent. Your choice is stored in your browser. To change it, clear this site's data in your browser settings; the banner will then appear again on your next visit. We are adding a permanent “cookie preferences” control to the footer so this does not require changing browser settings.

As noted in section 2.4, Cloudflare Web Analytics is injected at the network edge and is not governed by the banner.

7. Sharing of personal data

We do not sell personal data. We share it only with: (a) the sub-processors named below; (b) regulators, tax authorities, auditors and professional advisers where law or contract requires; and (c) third parties with your written instruction.

7.1 Sub-processors

Every third party that receives personal data through this website is named here. Where a provider processes data outside the UK, the transfer relies on the safeguards described in section 5.

Sub-processors that receive personal data through this website
Provider Purpose Data received When
Cloudflare Content delivery, security and edge analytics IP address, browser and device, page requested Every request
Vercel Website hosting IP address, page requested Every request
Formspree (United States) Processing contact, application, careers and newsletter forms Everything you type into a form, including any file you attach On form submission
Cloudflare (Workers and Turnstile) Running our enquiry capture endpoint and the bot check on the contact form. Compute is global, not London-only Everything you type into the contact form, and a keyed hash of your IP address On contact form submission
Neon (London) Managed database holding the enquiry store Everything you type into the contact form On contact form submission
OpenRouter (United States) Routing up to three requests per enquiry: classifying it, reading facts out of the sources, and assessing how it fits our services Your message and email address, and for the fact-reading step the text of your organisation's own public website Up to three times, within an hour of your submission
Microsoft Azure (United States) Running those models, on the Azure OpenAI service. Routing is pinned to Azure alone and cannot fall outside it. It operates under zero data retention, so your message is not stored by it for any period. This is Microsoft rather than OpenAI: OpenAI's own endpoint does not offer zero retention, so it is not used Your message and email address, and the text of your organisation's own public website Up to three times, within an hour of your submission
Resend (United States) Delivering the internal enquiry brief to our own inbox, and sending business-to-business outreach where we have established a lawful basis to contact you. It is a transactional email provider rather than a marketing platform, and we hold no marketing list: every send is checked against a per-person, per-channel, per-purpose permission record before it leaves. Replying to your enquiry and contacting you unprompted are different purposes under different bases, and we record which applies The brief: your submission, plus any facts gathered from your organisation's own public website and the quotations they came from Once per enquiry, after the enrichment step completes
GoDaddy / Secureserver Email hosting for our inbox The content of form notifications and any email you send us On form submission or email
Google (Analytics 4) Website analytics Pseudonymous identifier, pages visited, events Only after you accept the consent banner
Google Fonts Serving the site's typefaces IP address, browser Every page load
Unsplash Serving photography used on the site IP address, browser, referring page Every page load carrying such an image
jQuery (via its content delivery network) Loading a JavaScript library the site depends on IP address, browser Every page load

If you would like this list re-checked against what the site actually loads, ask us and we will confirm in writing.

8. Retention

Enquiry data is retained for up to 24 months from last contact unless an engagement follows. Engagement records are retained for the duration of the mandate plus the period required by law or by professional standards. Tax and accounting records are retained for the periods mandated under Indian and, where applicable, UK law.

The 24 month window applies to both destinations described in section 2.1, and they are held separately rather than expiring together.

9. Your rights

Subject to applicable law, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive your data in a portable form, and to withdraw consent at any time. To exercise any of these rights, write to us at [email protected].

One boundary is worth stating plainly, because a deletion request that is only half honoured is worse than one that is refused. Your details can sit in more than one place. Within our own database, an erasure removes both the enquiry you submitted and any contact record holding the same address, in a single operation, so that half of it cannot succeed while the other half quietly fails. Formspree and the resulting email in our inbox are separate systems and are not reached by that operation. Write to the address above and we will tell you what we hold and where before anything is acted on.

If you are located in the UK or the EEA, you may also lodge a complaint with your local supervisory authority. In India you may contact the Data Protection Board once it is operational under the DPDP Act.

10. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, restricted access, and confidentiality obligations on every person who handles client material. No method of transmission or storage is fully secure; we will notify you and the relevant supervisory authority of any qualifying personal-data breach in accordance with applicable law.

11. Children

Our advisory services are directed at organisations and their professional representatives.

Huntley Cross Labs is different. Its programmes (Live Sessions, the Fellowship, Practitioner Tracks, the Foundation Internship and the Apprenticeship) are aimed at students and early-career practitioners, and applications are made through this website. Labs programmes are open to applicants aged 18 and over. We ask applicants to confirm this when they apply, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has submitted an application, contact us and we will delete it.

Where an applicant supplies proof of enrolment for a student rate, we accept a document with the date of birth redacted, and we delete it once the rate has been applied.

12. Updates to this policy

We will update this policy when our practices change or when the law requires. Material changes will be flagged on this page with a revised “last updated” date.

13. How to contact us

For privacy enquiries:

  • Email: [email protected]
  • Operations: [email protected]
  • Direct line: +91 9789863180
  • Postal: Zaex Enterprises LLP, registered office in Tamil Nadu, India. Full registered-office address is disclosed in engagement contracts and available on request.
Huntley Cross

Partner-led advisory for transactions, finance, and transformation execution.

Quick Links

  • About Us
  • Our Services
  • Case Studies
  • Leadership & Team
  • Careers
  • Contact Us

Our Services

  • Business Strategy
  • Financial Consulting
  • Tax Advisory
  • M&A Advisory
  • Digital Transformation
  • Risk Management

Newsletter

Subscribe for the latest insights.

The firm Huntley Cross Advisory is the trading name of Zaex Enterprises LLP, a Limited Liability Partnership registered in India.
Registered office Zaex Enterprises LLP
Tamil Nadu, India.
Full registered address disclosed on engagement letter.
Tax & data GST 33AADFZ0704B1ZU
Cross-border personal data handled under UK GDPR Article 46 safeguards (SCCs / IDTA) and the India DPDP Act 2023.
Regulatory status Not authorised by the Financial Conduct Authority. We do not provide regulated financial advice.

© 2026 Huntley Cross. All Rights Reserved.

Privacy PolicyTerms of ServiceProcurement & Security

We use analytics cookies only if you accept. Declining leaves only the strictly necessary cookies in place, and you can change your choice at any time. Learn more