Introduction to Bhavpro's Privacy Policy
URL: https://bhavpro.com/privacy-policy/
Policy owner: Sentiora Consulting Ltd trading as BhavPro
Version: 1.0
Effective date: 1 September 2026
Last reviewed: 1 September 2026
1. About this Privacy Policy
This Privacy Policy explains how Sentiora Consulting Ltd trading as BhavPro (“BhavPro”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you:
visit or use bhavpro.com or another website, landing page, tool or digital property operated by us;
submit an enquiry, request a quote, complete an assessment, audit, calculator, lead form or other form;
subscribe to our newsletter or other marketing communications;
communicate with us by email, telephone, messaging service, social media or another channel;
respond to or interact with our business-to-business marketing;
interact with our advertisements on Google, Meta/Facebook/Instagram, Microsoft/Bing, LinkedIn or another advertising platform;
become a prospect, customer, supplier, partner, affiliate, contractor, candidate or business contact;
create or use a BhavPro portal account;
purchase services, products, subscriptions or other offerings from us;
make a payment or request a refund;
receive consulting, technology, marketing, support, project, recruitment or other services from us; or
otherwise interact with BhavPro.
This notice is intended to provide the privacy information required under applicable UK data protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”), and amendments made by the Data (Use and Access) Act 2025/2026 as applicable.
This Privacy Policy should be read together with our:
Cookies, Tracking & Advertising Technologies Policy;
Terms and Conditions;
Refund & Cancellation Policy; and
Disclaimer.
Where we provide a shorter privacy notice at a form, checkout, advertisement, lead-generation form, portal screen or other collection point, that shorter notice supplements this Privacy Policy.
2. Who We Are
The data controller responsible for the personal data described in this Privacy Policy is:
Sentiora Consulting Ltd trading as BhavPro
Company number: 16596409
Registered in: England and Wales
Registered office: 45 Marston Road, Leicester, United Kingdom, LE4 9FE
Website: https://bhavpro.com/
Email: hello@bhavpro.com
Contact page: https://bhavpro.com/contact/
For privacy or data-protection enquiries, please use the email address above and include “Privacy” in the subject line.
BhavPro is a trading name of Sentiora Consulting Ltd.
3. Scope of Our Role
In many situations, Sentiora Consulting Ltd is the controller of personal data, including personal data relating to:
visitors to our websites;
prospects and leads;
newsletter subscribers;
business contacts;
customers and customer contacts;
portal users;
suppliers and partners;
people who interact with our marketing or advertising; and
people who communicate directly with us.
In some client engagements, we may process personal data on behalf of a client. For example, this may occur where we provide CRM implementation, marketing operations, website development, automation, recruitment, support, integration, hosting or another service involving client-controlled personal data.
Where we act only on a client’s documented instructions, the client may be the controller and BhavPro may be a processor. In that case:
the client’s privacy notice normally governs why the client processes the relevant personal data;
our contract or data-processing terms with that client govern our processing on its behalf; and
requests concerning that client-controlled data may need to be directed to the client.
We may still act as an independent controller for our own account administration, security, billing, legal compliance and business records.
4. Personal Data We May Collect
The personal data we collect depends on how you interact with us.
4.1 Identity and contact data
This may include:
name;
business or trading name;
job title or role;
employer or organisation;
postal or billing address;
email address;
telephone or mobile number;
business website;
social-media or professional profile information;
customer, contact, account or portal references; and
other identifiers reasonably required to manage our relationship.
4.2 Enquiry, lead and form data
When you submit a form, assessment, audit, calculator, consultation request, callback request, download request, lead-generation form or similar interaction, we may collect:
the information you enter into the form;
selected services or areas of interest;
business requirements;
project information;
budget or timing information you choose to provide;
form name and version;
landing page;
date and time of submission;
source or referral information;
marketing preference information;
consent or privacy-notice evidence;
IP address and browser/user-agent data where appropriate; and
campaign or attribution information.
Please do not include unnecessary confidential, special-category or highly sensitive personal data in free-text fields.
4.3 Customer and commercial data
If you become a customer or potential customer, we may collect and create records relating to:
quotations and proposals;
contracts and amendments;
orders and subscriptions;
products and services;
service periods;
project requirements;
customer contacts;
onboarding information;
commercial approvals;
invoices, credits and receipts;
payment status;
refunds and disputes;
delivery milestones;
acceptance or sign-off;
support interactions; and
account and relationship history.
4.4 Payment and transaction data
Where you pay us using an online payment provider such as Stripe, we may receive or store:
Stripe customer, Checkout Session, PaymentIntent, charge, refund or other provider references;
transaction amount and currency;
payment status;
payment method type;
limited card metadata made available by the payment provider, such as card brand or last four digits;
billing details;
fraud or risk signals made available to us;
refund and dispute information; and
evidence relevant to payment reconciliation or dispute handling.
BhavPro does not intentionally collect or store full payment-card numbers or card security codes (CVC/CVV) in its own systems. Payment-card details entered into a Stripe-hosted or Stripe-powered payment flow are handled by Stripe under its applicable terms and privacy arrangements.
4.5 Portal, account and authentication data
If you use a BhavPro customer, partner, company or other portal, we may process:
account identifiers;
user identity and role;
login and session information;
authentication and security events;
multi-factor authentication information;
access permissions;
account recovery events;
portal activity;
service, order, invoice, project, file and support records visible to the account; and
audit records associated with important actions.
Passwords and authentication secrets are handled using appropriate security controls. We do not intend to store passwords in readable plain text.
4.6 Communications and support data
We may process:
emails;
support tickets;
inbox messages;
contact-form messages;
telephone call notes;
chat or messaging correspondence;
meeting notes;
complaint records;
files or attachments you provide;
customer-service history; and
records of our response.
Where a call is recorded, we will provide an appropriate notice where required.
4.7 Newsletter, marketing and preference data
This may include:
email address;
name and organisation;
marketing topics or interests;
communication preferences;
source of subscription;
consent wording and version;
consent date and method;
withdrawal or unsubscribe date;
suppression status;
bounce or complaint status;
campaign membership;
delivery events;
engagement information where lawfully enabled; and
records demonstrating why a person was or was not eligible to receive a marketing communication.
Membership of our CRM, being a customer, making an enquiry or providing an email address does not by itself mean that you have consented to every form of marketing.
4.8 Business-to-business prospect data
For relevant B2B marketing, we may process business contact information obtained from:
the individual directly;
the organisation they work for;
publicly accessible corporate websites;
professional networking profiles;
Companies House or other public registers;
business directories;
referrals;
events;
partners;
data suppliers or research providers where their use has been assessed; and
our existing commercial relationships.
This may include:
name;
job title;
employer;
business email;
business telephone number;
business address;
professional profile;
industry;
publicly stated responsibilities;
source of the data;
date obtained;
reason we consider the contact relevant; and
marketing objection or suppression information.
We do not treat publicly available personal data as proof of consent.
4.9 Website, device and usage data
Depending on your choices and the technologies in use, we may collect or receive:
IP address;
browser and device type;
operating system;
language;
approximate location derived from IP;
pages viewed;
referring URL;
date and time;
session information;
click and interaction data;
form or conversion events;
cookie or similar identifiers;
advertising click identifiers; and
analytics or performance data.
For more detail about cookies, pixels, tags, local storage and advertising technologies, please see our Cookies, Tracking & Advertising Technologies Policy.
4.10 Advertising and attribution data
Where advertising or measurement technology is enabled in accordance with applicable consent requirements, we may process or receive information associated with:
Google Ads;
Meta/Facebook/Instagram advertising;
Microsoft Advertising/Bing Ads;
LinkedIn Ads;
other advertising networks or measurement providers;
campaign, ad, ad group or ad-set identifiers;
UTM parameters;
referrers;
click identifiers;
conversion events;
audience membership signals;
remarketing or retargeting;
campaign attribution; and
aggregated advertising performance.
We may connect advertising-source information to a subsequent enquiry, lead, quote, order or customer relationship in order to understand campaign effectiveness, subject to applicable privacy and consent requirements.
4.11 AI, automation and generated-content data
BhavPro may use AI-assisted and automated tools to support activities such as:
summarising information;
drafting content or communications;
assisting with lead qualification;
organising project or support information;
identifying operational patterns;
producing recommendations;
assisting with knowledge management;
preparing analytical outputs; and
supporting internal business workflows.
The information sent to an AI provider is limited to what we consider reasonably necessary for the relevant purpose and subject to our technical, contractual and access controls.
We do not intend to use AI systems to make solely automated decisions that produce legal or similarly significant effects on individuals without appropriate safeguards and transparency.
4.12 Supplier, partner and affiliate data
We may process:
contact information;
organisation details;
agreements;
referral information;
lead attribution;
commission and payout information;
tax or payment details;
communications;
due-diligence records; and
portal/security information.
4.13 Recruitment and candidate data
Where BhavPro receives candidate information for our own recruitment or as part of a recruitment service, data may include:
name and contact details;
CV or employment history;
skills and qualifications;
salary or availability information;
interview or assessment information;
references;
right-to-work information where required; and
correspondence.
Where BhavPro processes candidate data solely on behalf of a recruitment client, the relevant client’s privacy information may also apply.
4.14 Security, fraud-prevention and audit data
We may collect or create:
login and authentication events;
access logs;
failed login information;
IP and device information;
security alerts;
abuse-prevention information;
fraud or payment-risk indicators;
administrative audit events;
consent evidence;
policy acceptance records;
investigation records; and
incident evidence.
5. Special Category and Sensitive Personal Data
BhavPro does not generally seek to collect special category personal data through ordinary website, marketing or sales activity.
Please avoid sending information about health, race or ethnicity, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation unless it is genuinely necessary and we have asked for it through an appropriate process.
Where special category data is genuinely required, we will identify an appropriate legal basis and Article 9 condition and apply additional safeguards where required.
We do not intentionally use special category personal data to create advertising audiences.
6. How We Collect Personal Data
We collect personal data:
Directly from you
For example, when you:
submit a website form;
create an account;
subscribe to a newsletter;
request a quote;
book a consultation;
purchase a service;
make a payment;
contact support;
send us an email;
communicate through social media;
attend a meeting;
enter into a contract; or
provide information during service delivery.
Automatically
For example, through:
server logs;
security systems;
authentication systems;
cookies and similar technologies;
analytics;
advertising tags;
conversion tracking; and
portal activity logs.
Non-essential cookies and advertising technologies are controlled in accordance with our Cookies, Tracking & Advertising Technologies Policy and applicable consent requirements.
From third parties and public sources
For example:
advertising platforms;
lead-generation platforms;
partners and referrals;
payment providers;
business directories;
professional networking websites;
Companies House and other public registers;
a business you work for;
clients;
service providers;
business-data suppliers; and
public corporate websites.
Where we obtain personal data from another source, we record source information where appropriate and provide privacy information as required by law.
7. Why We Use Personal Data and Our Lawful Bases
We use personal data only where we have an appropriate lawful basis.
The lawful basis depends on the purpose and circumstances.
| Purpose | Examples | Typical lawful basis |
|---|---|---|
| Responding to enquiries | Contact forms, consultation requests, quote requests | Legitimate interests; steps at your request before entering a contract |
| Providing services | Consulting, development, marketing, support, projects, subscriptions | Contract |
| Customer account administration | CRM, portal, onboarding, account records | Contract; legitimate interests |
| Orders and payments | Checkout, billing, invoices, payment reconciliation | Contract; legal obligation; legitimate interests |
| Refunds and disputes | Refund administration, chargeback evidence, fraud checks | Contract; legal obligation; legitimate interests |
| Legal/accounting records | Tax, accounts, invoices, statutory records | Legal obligation |
| Customer service | Support, service notices, relationship management | Contract; legitimate interests |
| Website security | Authentication, access control, fraud/abuse prevention | Legitimate interests; legal obligation where applicable |
| Website operation | Core website functionality and necessary logs | Legitimate interests; contract where relevant |
| Analytics | Website/service analysis where permitted | Consent where required; legitimate interests where lawfully available |
| Advertising tracking | Conversion measurement, retargeting, personalised advertising | Consent where required |
| Newsletter marketing | Promotional email subscription | Consent or another lawful basis where legally permitted |
| Existing-customer marketing | Similar products/services where applicable | Consent, soft opt-in or legitimate interests as applicable |
| Corporate B2B marketing | Relevant marketing to corporate subscribers | Legitimate interests where appropriate; PECR consent is not generally required for corporate subscribers |
| Sole trader/individual electronic marketing | Marketing to individual subscribers | Consent or a valid soft opt-in where applicable |
| Marketing suppression | Recording an opt-out so we do not contact you again for marketing | Legal obligation; legitimate interests |
| Business research | Identifying relevant corporate prospects | Legitimate interests, subject to balancing and safeguards |
| Improving services | Quality, analytics, product and operational improvement | Legitimate interests |
| AI-assisted work | Drafting, summarisation, operational assistance | Contract; legitimate interests; consent where specifically required |
| Claims and legal matters | Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
| Recruitment | Managing applications and placements | Steps before contract; legitimate interests; contract; legal obligation |
| Partners/suppliers | Managing commercial relationships and payments | Contract; legitimate interests; legal obligation |
We may rely on more than one lawful basis for the same information where the processing has more than one genuine purpose.
8. Our Legitimate Interests
Where we rely on legitimate interests, the interests may include:
operating and improving our business;
responding to business enquiries;
developing commercial relationships;
providing effective customer support;
maintaining accurate CRM and relationship records;
understanding how our services are used;
measuring business and marketing performance;
conducting proportionate B2B prospecting;
protecting our systems, customers and business from fraud, abuse or security threats;
maintaining audit and accountability evidence;
managing disputes;
protecting and enforcing legal rights;
improving products, services and workflows; and
communicating relevant services to business contacts where the impact on the individual is proportionate.
Where required, we assess whether our interests are overridden by the individual’s rights and freedoms.
You may object to processing based on legitimate interests. See Your Rights below.
9. Website Forms, Assessments, Audits and Lead Collection
When you complete a BhavPro form, we use the information for the purpose described at or around that form.
For example:
a contact form is used to respond to your message;
a quote form is used to assess and respond to a commercial request;
an audit or assessment is used to provide or prepare the requested analysis;
a download form is used to provide the requested resource;
a newsletter form is used to manage the subscription;
a consultation booking is used to arrange and manage the consultation; and
a lead-generation form on an advertising platform is used to respond to the request made through that platform.
Where a form includes an optional marketing choice, that marketing choice is separate from the processing needed to respond to the form itself.
We may retain evidence such as:
the form and version used;
the privacy notice shown;
the wording of any marketing choice;
date and time;
source;
landing page;
attribution data;
IP address and user agent where proportionate; and
the resulting lead or CRM record.
This helps us demonstrate what information was provided and what choices were made.
10. Newsletter and Email Subscribers
If you actively subscribe to BhavPro marketing emails, we may use your contact details to send:
newsletters;
articles and guides;
service updates;
invitations;
offers;
marketing insights;
information about BhavPro services; and
other communications covered by the subscription wording shown to you.
Where consent is the basis for marketing, you can withdraw it at any time.
We may keep an append-only record showing:
when a subscription or consent was given;
the source;
the wording or version relied upon;
when it was withdrawn;
whether an address has been suppressed, bounced or complained; and
related campaign evidence.
Withdrawing marketing consent does not necessarily require us to delete all information we hold about you. For example, we may retain limited suppression information to ensure we do not add you back to marketing.
11. Direct Marketing and B2B Campaigns
BhavPro may conduct carefully targeted B2B marketing.
11.1 Corporate subscribers
Under PECR, the specific consent rule for unsolicited electronic mail does not generally apply to corporate subscribers such as limited companies and limited liability partnerships.
Where we use an identifiable business contact’s personal data for B2B marketing, UK data protection law still applies. We will therefore:
identify an appropriate lawful basis;
use contact information in a relevant and proportionate way;
be transparent about the use;
identify BhavPro in the communication;
provide a valid means to opt out; and
respect objections and suppression records.
Where appropriate, we may rely on legitimate interests for relevant corporate B2B marketing after considering the purpose, necessity, expectations and impact of the processing.
11.2 Sole traders and other individual subscribers
Sole traders and certain unincorporated partnerships are treated as individual subscribers for the relevant PECR electronic-mail rules.
We will not knowingly send unsolicited electronic-mail marketing to an individual subscriber unless we have:
valid consent; or
another applicable permission such as a lawful soft opt-in.
11.3 Publicly available business information
The fact that an email address, professional profile or other information is publicly available does not itself amount to consent.
Where we use publicly available personal data for B2B research or marketing, we assess the lawful basis, relevance and reasonable expectations and provide transparency as required.
11.4 Purchased, licensed or supplied business data
Before using third-party data for direct marketing, we may assess:
where it came from;
when it was collected;
the type of subscriber;
the privacy information supplied;
any consent wording;
permitted uses;
suppression arrangements;
contractual controls; and
whether BhavPro is lawfully permitted to use it for the intended campaign.
We may reject or delete marketing data where sufficient provenance or authority cannot be established.
12. Marketing Opt-Out and Suppression
You have an absolute right to object to the use of your personal data for direct marketing.
You can stop BhavPro marketing emails by:
using an unsubscribe link included in a marketing email;
using a preference-management facility where available;
replying to the message with an opt-out request; or
contacting us at hello@bhavpro.com.
When you opt out, we may retain limited information in a suppression record so that your preference continues to be honoured.
Opting out of marketing will not normally stop necessary non-marketing communications such as:
security notices;
contractual communications;
invoices;
payment notices;
project communications;
support responses;
legal notices; or
service administration messages.
13. Email Delivery, Open and Click Information
Marketing and transactional email systems may generate technical delivery information such as:
queued;
sent;
accepted by an email provider;
delivered where a provider supplies reliable delivery evidence;
bounced;
complained;
unsubscribed;
clicked; and
opened where tracking is lawfully enabled.
We do not treat SMTP acceptance alone as proof that a message reached a person’s inbox.
Where open tracking, tracking pixels or similar storage/access technologies are used, we apply the relevant PECR and consent rules.
14. Advertising, Remarketing and Attribution
BhavPro may advertise through third-party platforms.
Depending on our active campaigns and your consent choices, providers may include:
Google Ads and Google services;
Meta Platforms, including Facebook and Instagram;
Microsoft Advertising, including Bing;
LinkedIn; and
other advertising, social-media, measurement or attribution providers.
These services may help us:
deliver advertisements;
limit or measure advertising frequency;
understand whether an advertisement led to a visit, enquiry or purchase;
measure conversions;
build advertising audiences;
retarget or remarket to previous visitors;
analyse campaign effectiveness;
prevent advertising fraud; and
improve advertising relevance.
Non-essential advertising storage/access technologies are governed by our Cookies, Tracking & Advertising Technologies Policy and the consent controls we make available.
14.1 Google
Where configured and permitted, Google technologies may process advertising, analytics, device, website interaction and conversion information.
Consent signals may be used to control Google advertising storage, advertising user data, advertising personalisation and analytics storage.
Google may process information under its own privacy and product terms.
14.2 Meta / Facebook / Instagram
Where configured and permitted, Meta technologies may be used for:
advertising measurement;
conversion tracking;
audience creation;
remarketing;
lead-generation activity; and
campaign optimisation.
This may involve Meta Pixel, server-side or API-based conversion tools, or information submitted through Meta lead-generation features.
Meta may process information under its own privacy and business-tool terms.
14.3 Microsoft Advertising / Bing
Where configured and permitted, Microsoft Advertising technologies such as Universal Event Tracking (“UET”) may be used to:
measure conversions;
understand advertising performance;
create remarketing audiences; and
attribute visits or actions to advertisements.
We use consent controls for UET where required.
Microsoft may process information under its own privacy and advertising terms.
14.4 LinkedIn
Where configured and permitted, LinkedIn advertising technologies may be used for:
conversion measurement;
website audience analysis;
advertising attribution;
matched audiences;
retargeting;
Lead Gen Forms; and
campaign optimisation.
The LinkedIn Insight Tag can transmit information relating to a website visit, such as URL, referrer, IP address, browser/device information and time of access. We do not intentionally install advertising tags on pages where doing so would cause prohibited or inappropriate disclosure of sensitive information.
LinkedIn may process information under its own privacy and advertising terms.
14.5 Future advertising providers
We may change or add advertising providers over time.
Before activating a materially new advertising technology, we aim to assess:
the purpose;
data involved;
privacy role;
storage/access technology;
consent requirements;
retention;
international transfers; and
necessary privacy or cookie-policy updates.
15. Advertising Click IDs, UTM Parameters and Source Attribution
If you arrive through an advertisement, campaign, referral or other marketing link, we may record attribution information such as:
utm_source;utm_medium;utm_campaign;utm_content;utm_term;campaign or advertisement identifiers;
supported advertising click identifiers;
referrer;
landing page; and
conversion source.
Where appropriate, attribution information may be linked to a lead, enquiry, order or customer record.
Advertising platform identifiers remain advertising/provider identifiers; they are not used as BhavPro customer identities.
16. Payments and Stripe
BhavPro may use Stripe to provide payment processing, Checkout, subscriptions, payment methods, fraud prevention, refunds, disputes and related payment services.
When you make a payment:
Stripe may collect payment-card or payment-account information directly;
Stripe may receive device, browser, IP, billing, fraud-prevention and transaction information;
BhavPro may receive provider references and payment status;
BhavPro may retain transaction, invoice, refund, dispute and reconciliation records required to manage the purchase and protect legal or financial interests; and
Stripe may process personal data as described in Stripe’s own privacy information and applicable services agreements.
BhavPro does not intentionally store full card numbers or CVC/CVV values in its own application database.
For fraud prevention, account security and dispute handling, we may retain evidence concerning:
purchase and checkout;
customer/order/invoice identity;
amount and currency;
policy acceptance;
service or product purchased;
communications;
delivery;
refunds;
IP/device information where proportionate; and
provider references.
We retain such evidence only for legitimate business, contractual, legal, security, accounting and dispute-management purposes.
17. Customer Portal and CRM
BhavPro operates CRM and portal systems to manage business relationships and service delivery.
We may use customer/account information to:
maintain account details;
store customer contacts;
manage quotes and contracts;
process orders and subscriptions;
provide invoices and receipts;
manage support;
manage projects and deliverables;
provide files;
manage notifications;
handle refunds;
keep audit evidence; and
maintain security and account access.
A customer account is not necessarily the same thing as an individual portal user. A business customer may have multiple authorised contacts or portal users.
We apply access controls designed to prevent one customer, partner or tenant from accessing another’s data without authorisation.
18. AI and Automation
BhavPro may use third-party or internally operated AI and automation services.
Where personal data is involved, we aim to:
use only the information reasonably necessary;
restrict access;
avoid sending unnecessary sensitive information;
apply contractual and security controls;
maintain audit information where appropriate;
require human review for appropriate customer-facing or state-changing actions; and
avoid allowing an AI system to autonomously change core identity, payment or other high-risk records outside an approved workflow.
AI output may be inaccurate. Where AI is used to assist a service, it may form part of an internal workflow rather than being the sole authority for a significant decision.
If we introduce solely automated decision-making that produces legal or similarly significant effects, we will provide the required information and safeguards before using that processing.
19. Cookies and Similar Technologies
Our website and services may use:
cookies;
local storage;
pixels;
tags;
software development kits;
session technologies;
analytics;
advertising identifiers; and
similar storage/access technologies.
Some technologies are necessary to:
provide the website;
maintain security;
manage sessions;
process a requested service; or
remember essential choices.
Other technologies may be used for analytics, advertising, attribution or personalisation and may require consent.
Please read our separate Cookies, Tracking & Advertising Technologies Policy for:
current categories;
active vendors;
cookie or technology names where applicable;
purposes;
durations; and
instructions for changing your choices.
20. Who We Share Personal Data With
We may share personal data with appropriate recipients where necessary for the purposes described in this Policy.
Categories may include:
Service providers and processors
Such as providers of:
website hosting;
cloud infrastructure;
content delivery;
secure storage;
email delivery;
communications;
CRM or support infrastructure;
analytics;
security;
fraud prevention;
backup;
document processing;
AI;
automation; and
technical support.
Payment providers
Including Stripe and related payment infrastructure where applicable.
Advertising, analytics and social-media providers
Including, where configured:
Google;
Meta;
Microsoft;
LinkedIn; and
other approved advertising or measurement providers.
Professional advisers
Including:
accountants;
auditors;
solicitors;
insurers;
consultants; and
other professional advisers.
Clients
Where BhavPro processes information as part of providing a service to a client, relevant information may be made available to that client in accordance with the service relationship and applicable privacy responsibilities.
Partners, suppliers and subcontractors
Where reasonably required to provide or support a service and subject to appropriate controls.
Authorities and legal recipients
We may disclose personal data where necessary to:
comply with law;
comply with a court order;
respond to a lawful regulatory or law-enforcement request;
establish, exercise or defend legal rights;
protect the rights, property or safety of BhavPro, our customers or others; or
investigate fraud, abuse or security incidents.
Business transfers
If all or part of our business is reorganised, sold, transferred, merged or acquired, personal data may be disclosed as part of appropriate due diligence and transferred where lawful, subject to confidentiality and data-protection controls.
21. We Do Not Sell Personal Data for Money
BhavPro does not sell personal data to data brokers for monetary payment.
However, using third-party advertising platforms can involve disclosures or processing that may be regulated differently in jurisdictions outside the United Kingdom.
Where local law gives you additional rights relating to targeted advertising, sharing or similar activity, you may contact us and we will consider the request under the applicable law.
22. International Transfers
Some service providers, technology providers, advertising platforms and business partners may process personal data outside the United Kingdom.
Where UK data-protection law requires safeguards for an international transfer, we use an appropriate transfer mechanism where applicable, such as:
UK adequacy regulations;
the UK International Data Transfer Agreement (“IDTA”);
the UK Addendum to approved standard contractual clauses;
another legally recognised transfer safeguard; or
a permitted legal derogation where appropriate.
Transfer arrangements depend on the recipient, country and processing involved.
You may contact us for more information about the safeguards relevant to a particular transfer.
23. How Long We Keep Personal Data
We do not keep personal data for longer than reasonably necessary for the purpose for which it was collected, subject to legal, accounting, security, dispute and evidential requirements.
Typical retention criteria include:
| Data category | Typical approach |
|---|---|
| General enquiries with no relationship | Usually up to 24 months after the last meaningful interaction, unless a longer period is justified |
| B2B prospect records | Periodically reviewed; normally removed or minimised where there is no continuing relevance, relationship or lawful purpose |
| Marketing subscriber data | While subscribed and for a reasonable period afterwards for audit and preference management |
| Marketing consent/withdrawal evidence | Retained as reasonably necessary to demonstrate the history of permission and withdrawal |
| Marketing suppression records | Retained in limited form for as long as reasonably necessary to continue respecting the opt-out |
| Customer and contract records | Normally for the relationship and an appropriate legal limitation/record-keeping period afterwards |
| Accounting and tax records | Retained for the period required by applicable financial and tax law |
| Invoice/payment/refund/dispute evidence | Normally retained with relevant financial/legal records and longer where a dispute, chargeback, fraud or legal hold requires it |
| Portal security and access logs | Kept for a proportionate security/audit period, subject to risk and system requirements |
| Support and project records | Retained for the service relationship and a proportionate period afterwards for support, quality, contractual and legal purposes |
| Recruitment records | Retained according to the recruitment purpose, client instructions and applicable legal requirements |
| Cookie/advertising data | Depends on the technology and provider; see the Cookies, Tracking & Advertising Technologies Policy |
We may keep information for longer where:
required by law;
a dispute or claim exists or is reasonably anticipated;
fraud or security investigation requires it;
a legal hold applies;
an authority requires preservation; or
we need limited information to establish that a right, suppression or other preference has been honoured.
Where practical, information may instead be anonymised or irreversibly de-identified.
24. Data Accuracy
We take reasonable steps to keep personal data accurate and up to date.
Please tell us if relevant information changes.
Where we obtain B2B contact information from public or third-party sources, we may verify or update it using reliable business information.
25. Security
We use technical and organisational measures designed to protect personal data against:
unauthorised access;
accidental loss;
misuse;
alteration;
unauthorised disclosure; and
destruction.
Depending on the system and risk, measures may include:
access controls;
authentication controls;
multi-factor authentication;
role and tenant restrictions;
encrypted transport;
protected credential storage;
logging and audit records;
backups;
security monitoring;
rate limiting;
secure development practices;
provider security controls; and
incident-management processes.
No method of transmitting or storing information can be guaranteed to be completely secure. We therefore do not make an absolute guarantee that a security incident can never occur.
If we become aware of a personal-data breach, we assess it and make notifications to the Information Commissioner’s Office and affected individuals where required by law.
26. Your Data-Protection Rights
Depending on the circumstances and lawful basis, you may have rights to:
be informed about how your personal data is used;
access personal data we hold about you;
rectify inaccurate or incomplete personal data;
erase personal data in certain circumstances;
restrict processing in certain circumstances;
object to processing based on legitimate interests;
object to direct marketing at any time;
data portability where the legal requirements apply;
withdraw consent at any time where processing is based on consent; and
obtain safeguards relating to certain types of automated decision-making where applicable.
These rights are not absolute. For example, we may need to retain certain information to comply with legal obligations, establish or defend legal claims, maintain financial records or preserve an effective marketing suppression record.
We will explain any lawful reason for refusing or limiting a request.
27. Exercising Your Rights
To exercise a privacy right, contact:
Sentiora Consulting Ltd trading as BhavPro
45 Marston Road
Leicester
United Kingdom
LE4 9FE
Email: hello@bhavpro.com
Subject: Privacy Request
Please describe your request clearly.
We may ask for information reasonably necessary to confirm your identity and protect personal data from unauthorised disclosure.
We will respond within the period required by applicable law.
We do not ordinarily charge a fee for a data-protection rights request. The law may permit a reasonable fee or refusal in limited circumstances, for example where a request is manifestly unfounded or excessive.
28. Your Absolute Right to Object to Direct Marketing
You can object to our use of your personal data for direct marketing at any time.
We will stop using the relevant personal data for direct-marketing purposes after processing your request, subject to retaining limited suppression information where necessary to ensure your preference continues to be respected.
You can:
click an unsubscribe link;
reply with an opt-out request;
use a preference-management function where available; or
email hello@bhavpro.com.
29. Withdrawing Consent
Where we rely on your consent, you can withdraw it at any time.
Withdrawing consent does not make processing that occurred before withdrawal unlawful.
Withdrawal may affect a feature or service where that processing cannot be provided without the consent concerned.
Marketing consent can be withdrawn using the methods described above.
Cookie and advertising consent can be changed through our cookie-preference controls where available.
30. Automated Decision-Making and Profiling
We may use segmentation, scoring, analytics and automated assistance to help prioritise or organise business activity.
Examples may include:
marketing segmentation;
lead scoring;
recommendations;
fraud/risk signals supplied by payment providers;
service prioritisation; and
AI-assisted summaries.
Unless we tell you otherwise in a specific notice, BhavPro does not intend to make a decision based solely on automated processing that has a legal or similarly significant effect on you.
If that changes, we will provide appropriate information about:
the processing;
meaningful information about the logic involved;
likely significance or consequences; and
applicable safeguards and rights.
31. Children’s Privacy
BhavPro provides business and professional services and does not target its services or marketing at children.
We do not knowingly seek to collect personal data from children for marketing or ordinary commercial purposes.
If you believe a child has provided personal data to us inappropriately, please contact us.
32. Third-Party Websites and Services
Our websites may link to external websites, platforms, videos, social networks, payment services, tools or other third-party resources.
Third parties operate under their own privacy practices.
We are not responsible for the privacy content or processing practices of a third-party website merely because we link to it.
Please review the relevant third party’s privacy information.
33. Provider Privacy Information
Depending on which services are enabled, relevant provider privacy notices may include:
Stripe Privacy Center: https://stripe.com/gb/privacy
Google Privacy Policy: https://policies.google.com/privacy
Meta Privacy Policy: https://www.facebook.com/privacy/policy/
Microsoft Privacy Statement: https://privacy.microsoft.com/en-gb/privacystatement
LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy
These links are provided for convenience. Provider services and privacy terms may change over time.
34. Complaints
We would like the opportunity to address any privacy concern directly.
Please contact:
Sentiora Consulting Ltd trading as BhavPro
Email: hello@bhavpro.com
Subject: Privacy Complaint
If you remain dissatisfied, you have the right to complain to the UK’s data-protection supervisory authority:
Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/
You can also use the ICO’s online complaint services.
35. Changes to this Privacy Policy
We review this Privacy Policy periodically and update it where necessary to reflect:
legal or regulatory changes;
new services;
changes to how we process personal data;
changes to advertising, analytics or AI technologies;
new providers;
changes to international transfers; or
improvements to our privacy practices.
The version and effective date at the top of this Policy identify the current published version.
Where a change is material and the law requires additional notice or consent, we will provide that notice or obtain that consent before the relevant new processing begins.
We may retain previous policy versions for legal, audit and evidential purposes.
36. Contact Us
For privacy questions, rights requests or concerns:
Sentiora Consulting Ltd trading as BhavPro
Company number: 16596409
Registered office: 45 Marston Road, Leicester, United Kingdom, LE4 9FE
Email: hello@bhavpro.com
Website: https://bhavpro.com/
Contact: https://bhavpro.com/contact/
End of Privacy Policy — Version 1.0 — Effective 1 September 2026
