FiMa Consulting Group

Privacy policy

This policy explains what happens to personal data you give FiMa Consulting Group Ltd through this website. It describes the website only. Engagement data handled under a signed consulting contract is governed by that contract.

Last updated: August 2026

Who is responsible

FiMa Consulting Group Ltd, a company registered in England & Wales, is the controller of the personal data described here.

For any question about this policy, or to exercise any of the rights below, write to info@fimaconsulting.co.uk.

What we collect, and when

We collect personal data in one place only: the consultation request form. Nothing on this site collects personal data in the background.

The form asks for your name, your company, your email address, your country and a description of what you are trying to change. You choose what to put in that last field, so please do not include confidential or special-category information in it.

We also record which page the request came from, which language version you used, the version of this policy you agreed to, and the time you agreed to it. We do this so that we can show, later, what you actually consented to.

What we do not collect

We do not store your IP address with your enquiry. Rate limiting uses a short-lived, irreversible hash that cannot be turned back into an address and is discarded automatically.

We do not use tracking pixels, session recording, heat mapping, chat widgets or advertising cookies unless you have actively chosen to allow them in cookie settings.

We do not buy personal data, and we do not enrich what you send us with data from other sources.

Why we are allowed to use it

For the consultation request itself, our legal basis is the steps taken at your request before entering into a contract, and our legitimate interest in responding to a business enquiry.

For the optional marketing box, the basis is your consent. It is unticked by default, it is never a condition of getting a reply, and you can withdraw it at any time by replying to any message or writing to info@fimaconsulting.co.uk.

For analytics and marketing cookies, the basis is your consent, given through cookie settings and withdrawable there at any time.

Who else sees it

Our hosting and deployment provider serves this website and processes requests in transit.

Our database provider stores consultation requests. The records sit in a database dedicated to FiMa and are not shared with any other company, product or venture.

Our email provider carries the internal notification of your request to us.

Where you have consented to them, the analytics and advertising providers named in the cookie policy receive the events described there. They never receive the content of your message.

We do not sell personal data and we do not share it for anyone else’s marketing.

Where it is held

Consultation requests are stored in the European Economic Area.

Some providers may process limited data outside the EEA. Where that happens, transfers rely on the safeguards those providers publish, such as standard contractual clauses or an adequacy decision.

How long we keep it

A consultation request that does not become an engagement is deleted within 24 months.

If your request becomes an engagement, the record is retained under the terms of that engagement and the retention periods required for business records.

Marketing consent, and the record of it, is kept until you withdraw it and for a short period afterwards so we can evidence that the withdrawal was honoured.

Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to our use of it, and ask for it in a portable form.

Write to info@fimaconsulting.co.uk. We will respond within one month.

If you are not satisfied with our response, you can complain to the Information Commissioner’s Office in the United Kingdom, or to your national supervisory authority in the European Union — in Italy, the Garante per la protezione dei dati personali.

Security

The site is served over HTTPS. Consultation requests are written by a server-side endpoint; the browser never holds a database credential.

Access to stored requests is restricted at the database level: the public cannot read them under any circumstances.

We validate and bound everything submitted, and we do not write anything you send into email headers.

Changes

If this policy changes materially we will update the version recorded against new consents, so it is always possible to establish which version you agreed to.

Cookies

Nothing but strictly necessary storage is running right now. We would like to use analytics to see which pages get read, and marketing tags to measure whether the right audiences arrive. Both are off until you choose.

Read the cookie policy