Privacy Policy.
01Who We Are
The Crane Consultancy is a trading name of Crane Consultancy Limited, a company registered in England and Wales (Company No. 15526285), with its registered office at 45 Albemarle Street, Floor 3, Mayfair, London, W1S 4JL.
We are the data controller for personal information collected through this website and through our commercial engagements. This policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
When we manage digital advertising and marketing operations for our clients, we act as a data processor on behalf of those clients, who remain the data controllers for their own customers' and leads' personal data. In that role we process personal data only on our clients' documented instructions and under a data processing agreement. Except where this policy states we are acting as a processor for a client, we act as the data controller.
Questions? If you have any questions about this policy or how we handle your data, please contact us at [email protected] before proceeding.
02Data We Collect
We collect personal data in the following ways:
- Contact enquiries. When you submit our contact form, we collect your full name, professional email address, and the content of your message.
- Direct communications. When you contact us via WhatsApp, email, or telephone, we retain records of that correspondence.
- Analytics data. We collect anonymised usage data including pages visited, time on site, and device type via Google Analytics (configured with IP anonymisation and no cross-site tracking).
- On-site engagement measurement. On our article and research pages we keep anonymous, aggregate counts of how a page is used: for example, how far a reader scrolls, whether they reach the end, and whether they play the narrated audio. These are stored per page as running totals only, with no cookies, no identifiers, no personal data and no IP address, and are collected only where analytics consent has not been declined. We use them to understand which pieces land, and to improve what we publish.
- Technical data. Server logs may record your IP address, browser type, and referring URL for security and diagnostic purposes. These logs are not used for profiling.
- Commercial mandates. When we enter into a commercial engagement, we may collect additional business contact information as part of our client onboarding process.
- Newsletter subscription. When you subscribe to The Crane Standard, we collect your email address and an auditable record of your consent (the date, time, source and IP address of your subscription), as required under the Privacy and Electronic Communications Regulations (PECR).
- Press list subscription. When a journalist joins the Crane Index press list from our newsroom, we collect the same details in the same way, and a record of which list was asked for. The press briefing is monthly and separate from The Crane Standard: joining one does not add you to the other, and each can be unsubscribed from independently.
- Consultation bookings. When you book a consultation, we collect your name, professional email, optional company name and your chosen time, which is added to our calendar to schedule the call.
- Readiness scanners. When you use our AI readiness scanners, we process the website domain you submit; if you request a manual review, we also collect the email address you provide.
We do not knowingly collect data from individuals under the age of 18. This website and our services are directed exclusively at business professionals.
03How We Use It
We use your personal data only for the purposes for which it was collected:
- To respond to your enquiry and assess whether we can assist you
- To communicate with you regarding a potential or active commercial engagement
- To fulfil our contractual obligations as your retained consultancy
- To improve the performance and user experience of this website
- To send you The Crane Standard, our weekly newsletter, where you have subscribed (you can unsubscribe from any email)
- To send you the monthly Crane Index press briefing, where you have joined the press list (you can unsubscribe from any email)
- To comply with legal and regulatory obligations applicable to our business
- To detect, investigate, and prevent fraudulent or unlawful activity
We do not use your personal data for automated decision-making or profiling. We do not sell, rent, or trade your personal data to third parties for marketing purposes.
04Legal Basis
Under UK GDPR, we process your personal data on the following legal bases:
- Legitimate interests for responding to enquiries and improving our website, where our legitimate business interest does not override your privacy rights
- Contract performance where processing is necessary to fulfil our obligations under a commercial agreement with you or your organisation
- Legal obligation where we are required to process data to comply with applicable law, including tax and financial regulations
- Consent where you have opted in, such as subscribing to The Crane Standard or the Crane Index press list (either of which you may withdraw at any time by unsubscribing) or allowing non-essential cookies
05Data Sharing
We do not sell your data. We share personal data only in limited, necessary circumstances:
- Service providers. We use trusted third-party processors to operate our business:
- Cloudflare (United States): website hosting, our data storage, and the security layer in front of it.
- Resend (United States): transactional and newsletter email delivery.
- Google (United States): Calendar, for scheduling the consultations you book, and analytics and advertising infrastructure.
- Stape (Estonia): server-side tracking infrastructure.
- Stripe (United States and Ireland): payment processing for subscriptions and one-off purchases. Card details are entered on Stripe's own hosted checkout and never reach our systems; what we receive back is the name, email address and order details needed to fulfil and account for the purchase.
- Anthropic (United States): the reading companion on our articles. Where you type a question into an article, that question and the text of that article are sent to Anthropic to compose the answer. We log the question and the answer so we can see what readers want to know, and we ask you not to include personal details in it.
- Advertising and measurement partners (client engagements). When we manage advertising for our clients, we share limited data with the advertising platforms those clients use, Google, Microsoft (Bing) and LinkedIn, for conversion measurement and campaign optimisation. This may include advertising click identifiers (such as the Google Click ID, Microsoft Click ID and the LinkedIn first-party ad tracking identifier) and contact details that we irreversibly hash (SHA-256) before transmission, used only to match a sale or enquiry back to the advertisement that produced it. Where a client runs lead generation forms on these platforms (such as LinkedIn Lead Gen Forms), we also deliver the resulting leads into that client's own CRM. This processing is carried out on behalf of, and on the documented instructions of, the client as data controller; we do not use it for our own marketing, and we never sell it.
- Legal compliance. We may disclose data to law enforcement, regulatory authorities, or courts where legally required or where necessary to protect our rights or the rights of others.
- Business transfers. In the event of a merger, acquisition, or sale of the business, your data may be transferred to the acquiring party, subject to equivalent privacy protections.
Where we transfer data outside the United Kingdom, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions as applicable.
06Retention
We retain personal data only for as long as necessary for the purposes set out in this policy:
- Enquiry data from the contact form is retained for up to 24 months, after which it is securely deleted unless a commercial engagement has commenced
- Scanner review requests are treated as enquiries and retained for up to 24 months
- Newsletter and press list subscription data is retained until you unsubscribe; your email is then removed from the active list, though a minimal record of your prior consent may be kept as evidence of lawful processing
- Client engagement data is retained for 7 years following the end of an engagement, in accordance with UK financial record-keeping requirements
- Anonymised analytics data is retained in accordance with Google Analytics default retention settings (26 months)
- Server security logs are retained for 90 days
At the end of the applicable retention period, data is securely deleted or anonymised.
07Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Access. You may request a copy of the personal data we hold about you.
- Rectification. You may request correction of inaccurate or incomplete data.
- Erasure. You may request deletion of your personal data where there is no compelling reason for us to continue processing it.
- Restriction. You may request that we restrict processing of your data in certain circumstances.
- Portability. You may request that we provide your data in a structured, machine-readable format.
- Objection. You may object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
09Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These measures include:
- HTTPS encryption across all pages and data transmissions
- Content Security Policy headers restricting resource loading to trusted origins
- Server-side tracking to reduce client-side data exposure
- Honeypot and time-gating mechanisms on contact forms to prevent automated abuse
- Access controls limiting data access to authorised personnel only
- Credentials for the advertising and analytics accounts we work in on behalf of clients are held in our hosting platform's encrypted secret store and read only at the moment they are used, never written into the website's code
No method of transmission over the internet is 100% secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay.
10Third Parties
Our website contains links to third-party websites, including our verified infrastructure partners. This policy does not apply to those websites. We encourage you to review their respective privacy policies before providing any personal data.
Our key infrastructure providers and their privacy documentation:
11Our HMRC-Connected Software
We operate our own software that connects to HMRC's APIs to read this company's VAT record. HMRC requires a privacy policy covering any software granted production credentials, and this section is it.
It has no customers and no users but us. The software is built by Crane Consultancy Limited for Crane Consultancy Limited. It is not sold, resold, distributed or offered as a service, and no other organisation's data passes through it. Where HMRC's guidance speaks of "customer data", the customer is this company and the data is its own.
What it reads. Our VAT obligations, liabilities and payments, under an authorisation scoped to reading only. That authorisation carries no permission to submit anything, so the software is incapable of filing a return; our VAT returns are filed from FreeAgent, which is separately MTD-compatible.
Personal data. The VAT record is company data rather than personal data. Our own directors' and staff names appear in the underlying bookkeeping, for which this company is the controller and which is covered elsewhere in this policy. No client of ours, and no visitor to this site, has personal data processed by this software.
Fraud prevention data. HMRC requires software connecting to their APIs to send technical details of the machine making the call, which they record to protect against fraudulent access. We send those details for our own server, and every value is read from that machine rather than composed; where a value genuinely cannot be known, it is omitted rather than filled with a plausible substitute.
Where the data is held. Credentials and the authorisation are stored encrypted at rest on Cloudflare's global network, and calls are made from cloud servers which may be located outside the United Kingdom. Access tokens are short-lived, held in memory only, and never written to disk or to logs. As the data concerned is this company's own, no international transfer of another party's personal data arises.
Lawful basis. Legitimate interests, and where our own staff's data is involved in the underlying records, compliance with a legal obligation. Both are set out in the Legal Basis section above.
If something goes wrong. We maintain a documented incident process, under which any breach concerning data reached through HMRC's APIs is reported to HMRC within 72 hours of our becoming aware of it, and any personal data breach is reported to the Information Commissioner's Office within the same period.
12Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised.
Material changes will be communicated to active clients directly. Continued use of our website following an update constitutes acceptance of the revised policy.
13Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us through any of the following:
Crane Consultancy Limited
45 Albemarle Street, Floor 3
Mayfair, London, W1S 4JL
If you are unsatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.