This page states what we can evidence. Where a fact is confirmed during onboarding rather than published here, it says so plainly instead of implying more than we can show. If something your process requires is missing, ask at scoping and you will get a straight answer before you invest time.

The contracting entity

Legal entity
Zaex Enterprises LLP, a Limited Liability Partnership registered in India. Huntley Cross Advisory is a trading name of that entity.
Tax identifier
GST 33AADFZ0704B1ZU.
Registered address and LLPIN
Provided in writing on request and stated in full on the engagement letter. If your KYC process needs them before signature, which is normal, ask at first contact rather than at contracting.
Contracting jurisdiction
Agreed per engagement. Cross-border supply into the UK and EU is the usual case and is priced and invoiced accordingly.

Scope of engagement

We deliver analysis, modelling, decision support and execution oversight against a scope agreed in writing before work starts.

We are not authorised by the Financial Conduct Authority. We do not provide regulated financial advice, recommend or arrange investments, act as your agent for tax returns or statutory filings, or issue audit or assurance opinions. Where work requires an authorised or licensed firm, we say so at scoping and that work sits outside our engagement. The same boundary is stated on each financial, tax, M&A and risk service page.

Billing and tax treatment

We do not publish a price list. Fees are scoped to the engagement and the organisation, quoted in GBP in writing before any work starts, and fixed for that scope. Nothing on this site can be bought without a conversation first, which is deliberate: a published number would be wrong for most of the people reading it.

The applicable tax treatment is stated on the quotation and on the invoice, so your finance function knows the amount and its treatment before committing. Invoices are itemised and addressed to the purchasing organisation. Where a purchase order, supplier reference or cost-centre code must appear on the invoice, tell us at scoping.

Data protection

Cross-border transfers
Personal data moving between the UK/EU and India is handled under UK GDPR Article 46 safeguards (Standard Contractual Clauses / International Data Transfer Agreement) and the India Digital Personal Data Protection Act 2023.
What we collect through this site
Through this site, only what a form submits. There is no account system and no login. Submissions from the contact form are additionally recorded in a client database we operate, hosted in London and described under Sub-processors below, and kept for 24 months from last contact.
What we hold beyond this site
That same database also records the organisations we deal with, our business contacts at them, and published news about those organisations. Some of it comes from enquiries; some is compiled from public sources such as company registers, organisation websites and news reporting. Every record carries where it came from and when, so we can answer that question about any single entry rather than in general. Contacts are held in a professional capacity, for the purpose of scoping and delivering advisory engagements.
Retention
Stated per data category in the privacy policy, including the retention window for enquiries and for mandate records.
Data subject requests
Routed through the contact address in the privacy policy.

Sub-processors

Every third party that can see data associated with this website, and why:

ProcessorPurposeData involved
FormspreeForm intake for contact, application and enquiry submissionsWhatever the form submits: name, email, phone if given, message body
VercelStatic hosting and edge deliveryRequest metadata, including IP address, as part of serving the page
CloudflareCDN and edge protection in front of the originRequest metadata, including IP address
Cloudflare WorkersRuns our enquiry capture endpoint, and the Turnstile bot check on the contact form. Compute executes across Cloudflare's global network rather than in a single jurisdiction; only storage is pinned to LondonContact-form submission content, and a keyed hash of the submitting IP address rather than the address itself
NeonManaged Postgres holding the enquiry store, in AWS Europe West 2 (London)Contact-form submission content, retained 24 months from last contact
OpenRouterRoutes up to three requests per contact enquiry to the inference providers below: classification, fact extraction, and service-fit assessment. Prompt logging is off, so it retains nothingThe contact-form message and email address, and at the extraction step the text of the enquirer's own public website
Microsoft Azure (United States)Runs those models, on the Azure OpenAI service. Routing is pinned to Azure alone and cannot fall outside it, so no other provider can serve the request. It operates under zero data retention, meaning the content is not stored for any period. Note this is Microsoft rather than OpenAI: OpenAI's own endpoint does not offer zero retention, so it is not usedThe contact-form message and email address, and the text of the enquirer's own public website, held only for the duration of each request
Resend (United States)Delivers the internal enquiry brief to our own inbox, and sends business-to-business outreach where a lawful basis to make contact has been established and recorded. It is a transactional email provider rather than a marketing platform, and we hold no marketing list: every send is checked against a per-person, per-channel, per-purpose permission record first, and an objection or a bounce suppresses that address before the next send rather than after itThe brief: the contact-form submission, plus any facts gathered from the organisation's own public website and the quotations they came from. For outreach: the recipient's business contact details and the same sourced facts
Google AnalyticsAggregate site analytics, loaded only after cookie consent is givenUsage events; no submission content
UnsplashServes the hero and section photography on 34 of the 39 pages, resized and format-negotiated at their edgeRequest metadata for the image files, including IP address and user agent; no submission content
jQuery CDN (code.jquery.com)Serves the jQuery library on every page, including this one. Loaded with a Subresource Integrity hash, so a modified file fails to executeRequest metadata for the script file, including IP address and user agent; no submission content

If your policy prohibits any processor above, say so at scoping. Analytics is already consent-gated and can be disabled outright for an engagement.

Application security posture

This website is a static site. There is no application backend, no authentication system and no payment processing in it, and no customer data sits at rest in the website itself to breach.

The firm's systems are a separate question, and the accurate answer is no longer "nothing". Contact-form submissions are recorded in the enquiry store named under Sub-processors above. It is not part of the website and shares no code with it. Submissions from every other form on this site, including newsletter and careers, continue to go to Formspree alone.

That store exposes four routes and no others, and answers every request outside them identically:

  • Submission. Accepts a contact-form enquiry. Rate-limited per source and per day, and gated by a bot challenge.
  • Erasure. Deletes on request. Authenticated with a single operator credential and answers identically whether or not anything matched, so that no caller can use it to ask whether a given person or company is in the database.
  • Delivery events. Receives delivery and bounce notifications from the email provider named above. Every event is signature-verified; an unsigned or wrongly signed event is refused rather than skipped.
  • An internal read surface, on a separate hostname, for the firm to read its own enquiries. There is no password and no user account: access is granted by an identity provider against a named allowlist of three firm mailboxes, and the service verifies that assertion itself and refuses the request outright if it is absent, expired or not addressed to it. Every read is written to an append-only audit record before any data is returned, so a record that was read leaves a trace even when nothing was changed.

This paragraph previously described two routes, no login and no accounts. That was true when it was written and stopped being true as the read surface and the delivery webhook shipped. Corrected 2026-08-12.

The following response headers are configured in production:

  • Strict-Transport-Security: HSTS with preload; the site is HTTPS-only.
  • Content-Security-Policy: script sources restricted to an explicit allow-list; no third-party origin is permitted without a resource that uses it.
  • X-Frame-Options and Cross-Origin-Opener-Policy: clickjacking and cross-origin window isolation.
  • X-Content-Type-Options: MIME-sniffing disabled.
  • Referrer-Policy and Permissions-Policy: referrer leakage and browser feature access restricted.
  • Cross-Origin-Resource-Policy and X-Permitted-Cross-Domain-Policies: cross-origin resource and legacy plugin policy.

External scripts are loaded with Subresource Integrity hashes, so a compromised third-party file fails to execute rather than running silently. There is one deliberate exception, named here rather than left for you to find: Cloudflare publishes no integrity hash for the Turnstile bot-check script and updates that file continuously, so pinning a hash would silently disable bot protection on the contact form at Cloudflare's next release rather than failing at deploy. The omission is documented in the markup so that it is not later "corrected" into an outage.

Every change to this site passes an automated invariant suite before it can deploy; a build that violates a disclosure, link-integrity or content rule is blocked rather than shipped. That suite includes a rule that fails the build if the enquiry capture code is present while this page still claims no enquiry store exists, so the disclosure above cannot quietly fall out of date.

Confirmed during onboarding

These are settled in writing per engagement rather than published on a marketing page, because the answer depends on the contract in front of us:

  • Professional indemnity position and any certificate your process requires.
  • Security certifications and questionnaire responses, including your own vendor questionnaire.
  • Master services agreement, data processing agreement and NDA execution.
  • Named delivery contacts, escalation path and continuity arrangements for the engagement.
  • Client references, provided under NDA at scoping.

Ask for any of these at first contact. Telling you where we stand costs one email and is cheaper for both sides than finding out at contracting.

Our evidence standard

We do not publish anonymous testimonials, invented placement statistics or client names we do not have consent to use. Published case studies are anonymised deliberately, and the production metrics on this site are labelled as the partner's prior engagements rather than presented as firm aggregates. That is a deliberate trade: it costs conversions, and it means the claims that are here can be checked.