Featured
Business services, tools and software — buy online or request a tailored quote.

Introduction to Bhavpro's Privacy Policy

URL: https://bhavpro.com/privacy-policy/
Policy owner: Sentiora Consulting Ltd trading as BhavPro
Version: 1.0
Effective date: 1 September 2026
Last reviewed: 1 September 2026


1. About this Privacy Policy

This Privacy Policy explains how Sentiora Consulting Ltd trading as BhavPro (“BhavPro”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you:

  • visit or use bhavpro.com or another website, landing page, tool or digital property operated by us;

  • submit an enquiry, request a quote, complete an assessment, audit, calculator, lead form or other form;

  • subscribe to our newsletter or other marketing communications;

  • communicate with us by email, telephone, messaging service, social media or another channel;

  • respond to or interact with our business-to-business marketing;

  • interact with our advertisements on Google, Meta/Facebook/Instagram, Microsoft/Bing, LinkedIn or another advertising platform;

  • become a prospect, customer, supplier, partner, affiliate, contractor, candidate or business contact;

  • create or use a BhavPro portal account;

  • purchase services, products, subscriptions or other offerings from us;

  • make a payment or request a refund;

  • receive consulting, technology, marketing, support, project, recruitment or other services from us; or

  • otherwise interact with BhavPro.

This notice is intended to provide the privacy information required under applicable UK data protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”), and amendments made by the Data (Use and Access) Act 2025/2026 as applicable.

This Privacy Policy should be read together with our:

  • Cookies, Tracking & Advertising Technologies Policy;

  • Terms and Conditions;

  • Refund & Cancellation Policy; and

  • Disclaimer.

Where we provide a shorter privacy notice at a form, checkout, advertisement, lead-generation form, portal screen or other collection point, that shorter notice supplements this Privacy Policy.


2. Who We Are

The data controller responsible for the personal data described in this Privacy Policy is:

Sentiora Consulting Ltd trading as BhavPro
Company number: 16596409
Registered in: England and Wales
Registered office: 45 Marston Road, Leicester, United Kingdom, LE4 9FE
Website: https://bhavpro.com/
Email: hello@bhavpro.com
Contact page: https://bhavpro.com/contact/

For privacy or data-protection enquiries, please use the email address above and include “Privacy” in the subject line.

BhavPro is a trading name of Sentiora Consulting Ltd.


3. Scope of Our Role

In many situations, Sentiora Consulting Ltd is the controller of personal data, including personal data relating to:

  • visitors to our websites;

  • prospects and leads;

  • newsletter subscribers;

  • business contacts;

  • customers and customer contacts;

  • portal users;

  • suppliers and partners;

  • people who interact with our marketing or advertising; and

  • people who communicate directly with us.

In some client engagements, we may process personal data on behalf of a client. For example, this may occur where we provide CRM implementation, marketing operations, website development, automation, recruitment, support, integration, hosting or another service involving client-controlled personal data.

Where we act only on a client’s documented instructions, the client may be the controller and BhavPro may be a processor. In that case:

  • the client’s privacy notice normally governs why the client processes the relevant personal data;

  • our contract or data-processing terms with that client govern our processing on its behalf; and

  • requests concerning that client-controlled data may need to be directed to the client.

We may still act as an independent controller for our own account administration, security, billing, legal compliance and business records.


4. Personal Data We May Collect

The personal data we collect depends on how you interact with us.

4.1 Identity and contact data

This may include:

  • name;

  • business or trading name;

  • job title or role;

  • employer or organisation;

  • postal or billing address;

  • email address;

  • telephone or mobile number;

  • business website;

  • social-media or professional profile information;

  • customer, contact, account or portal references; and

  • other identifiers reasonably required to manage our relationship.

4.2 Enquiry, lead and form data

When you submit a form, assessment, audit, calculator, consultation request, callback request, download request, lead-generation form or similar interaction, we may collect:

  • the information you enter into the form;

  • selected services or areas of interest;

  • business requirements;

  • project information;

  • budget or timing information you choose to provide;

  • form name and version;

  • landing page;

  • date and time of submission;

  • source or referral information;

  • marketing preference information;

  • consent or privacy-notice evidence;

  • IP address and browser/user-agent data where appropriate; and

  • campaign or attribution information.

Please do not include unnecessary confidential, special-category or highly sensitive personal data in free-text fields.

4.3 Customer and commercial data

If you become a customer or potential customer, we may collect and create records relating to:

  • quotations and proposals;

  • contracts and amendments;

  • orders and subscriptions;

  • products and services;

  • service periods;

  • project requirements;

  • customer contacts;

  • onboarding information;

  • commercial approvals;

  • invoices, credits and receipts;

  • payment status;

  • refunds and disputes;

  • delivery milestones;

  • acceptance or sign-off;

  • support interactions; and

  • account and relationship history.

4.4 Payment and transaction data

Where you pay us using an online payment provider such as Stripe, we may receive or store:

  • Stripe customer, Checkout Session, PaymentIntent, charge, refund or other provider references;

  • transaction amount and currency;

  • payment status;

  • payment method type;

  • limited card metadata made available by the payment provider, such as card brand or last four digits;

  • billing details;

  • fraud or risk signals made available to us;

  • refund and dispute information; and

  • evidence relevant to payment reconciliation or dispute handling.

BhavPro does not intentionally collect or store full payment-card numbers or card security codes (CVC/CVV) in its own systems. Payment-card details entered into a Stripe-hosted or Stripe-powered payment flow are handled by Stripe under its applicable terms and privacy arrangements.

4.5 Portal, account and authentication data

If you use a BhavPro customer, partner, company or other portal, we may process:

  • account identifiers;

  • user identity and role;

  • login and session information;

  • authentication and security events;

  • multi-factor authentication information;

  • access permissions;

  • account recovery events;

  • portal activity;

  • service, order, invoice, project, file and support records visible to the account; and

  • audit records associated with important actions.

Passwords and authentication secrets are handled using appropriate security controls. We do not intend to store passwords in readable plain text.

4.6 Communications and support data

We may process:

  • emails;

  • support tickets;

  • inbox messages;

  • contact-form messages;

  • telephone call notes;

  • chat or messaging correspondence;

  • meeting notes;

  • complaint records;

  • files or attachments you provide;

  • customer-service history; and

  • records of our response.

Where a call is recorded, we will provide an appropriate notice where required.

4.7 Newsletter, marketing and preference data

This may include:

  • email address;

  • name and organisation;

  • marketing topics or interests;

  • communication preferences;

  • source of subscription;

  • consent wording and version;

  • consent date and method;

  • withdrawal or unsubscribe date;

  • suppression status;

  • bounce or complaint status;

  • campaign membership;

  • delivery events;

  • engagement information where lawfully enabled; and

  • records demonstrating why a person was or was not eligible to receive a marketing communication.

Membership of our CRM, being a customer, making an enquiry or providing an email address does not by itself mean that you have consented to every form of marketing.

4.8 Business-to-business prospect data

For relevant B2B marketing, we may process business contact information obtained from:

  • the individual directly;

  • the organisation they work for;

  • publicly accessible corporate websites;

  • professional networking profiles;

  • Companies House or other public registers;

  • business directories;

  • referrals;

  • events;

  • partners;

  • data suppliers or research providers where their use has been assessed; and

  • our existing commercial relationships.

This may include:

  • name;

  • job title;

  • employer;

  • business email;

  • business telephone number;

  • business address;

  • professional profile;

  • industry;

  • publicly stated responsibilities;

  • source of the data;

  • date obtained;

  • reason we consider the contact relevant; and

  • marketing objection or suppression information.

We do not treat publicly available personal data as proof of consent.

4.9 Website, device and usage data

Depending on your choices and the technologies in use, we may collect or receive:

  • IP address;

  • browser and device type;

  • operating system;

  • language;

  • approximate location derived from IP;

  • pages viewed;

  • referring URL;

  • date and time;

  • session information;

  • click and interaction data;

  • form or conversion events;

  • cookie or similar identifiers;

  • advertising click identifiers; and

  • analytics or performance data.

For more detail about cookies, pixels, tags, local storage and advertising technologies, please see our Cookies, Tracking & Advertising Technologies Policy.

4.10 Advertising and attribution data

Where advertising or measurement technology is enabled in accordance with applicable consent requirements, we may process or receive information associated with:

  • Google Ads;

  • Meta/Facebook/Instagram advertising;

  • Microsoft Advertising/Bing Ads;

  • LinkedIn Ads;

  • other advertising networks or measurement providers;

  • campaign, ad, ad group or ad-set identifiers;

  • UTM parameters;

  • referrers;

  • click identifiers;

  • conversion events;

  • audience membership signals;

  • remarketing or retargeting;

  • campaign attribution; and

  • aggregated advertising performance.

We may connect advertising-source information to a subsequent enquiry, lead, quote, order or customer relationship in order to understand campaign effectiveness, subject to applicable privacy and consent requirements.

4.11 AI, automation and generated-content data

BhavPro may use AI-assisted and automated tools to support activities such as:

  • summarising information;

  • drafting content or communications;

  • assisting with lead qualification;

  • organising project or support information;

  • identifying operational patterns;

  • producing recommendations;

  • assisting with knowledge management;

  • preparing analytical outputs; and

  • supporting internal business workflows.

The information sent to an AI provider is limited to what we consider reasonably necessary for the relevant purpose and subject to our technical, contractual and access controls.

We do not intend to use AI systems to make solely automated decisions that produce legal or similarly significant effects on individuals without appropriate safeguards and transparency.

4.12 Supplier, partner and affiliate data

We may process:

  • contact information;

  • organisation details;

  • agreements;

  • referral information;

  • lead attribution;

  • commission and payout information;

  • tax or payment details;

  • communications;

  • due-diligence records; and

  • portal/security information.

4.13 Recruitment and candidate data

Where BhavPro receives candidate information for our own recruitment or as part of a recruitment service, data may include:

  • name and contact details;

  • CV or employment history;

  • skills and qualifications;

  • salary or availability information;

  • interview or assessment information;

  • references;

  • right-to-work information where required; and

  • correspondence.

Where BhavPro processes candidate data solely on behalf of a recruitment client, the relevant client’s privacy information may also apply.

4.14 Security, fraud-prevention and audit data

We may collect or create:

  • login and authentication events;

  • access logs;

  • failed login information;

  • IP and device information;

  • security alerts;

  • abuse-prevention information;

  • fraud or payment-risk indicators;

  • administrative audit events;

  • consent evidence;

  • policy acceptance records;

  • investigation records; and

  • incident evidence.


5. Special Category and Sensitive Personal Data

BhavPro does not generally seek to collect special category personal data through ordinary website, marketing or sales activity.

Please avoid sending information about health, race or ethnicity, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation unless it is genuinely necessary and we have asked for it through an appropriate process.

Where special category data is genuinely required, we will identify an appropriate legal basis and Article 9 condition and apply additional safeguards where required.

We do not intentionally use special category personal data to create advertising audiences.


6. How We Collect Personal Data

We collect personal data:

Directly from you

For example, when you:

  • submit a website form;

  • create an account;

  • subscribe to a newsletter;

  • request a quote;

  • book a consultation;

  • purchase a service;

  • make a payment;

  • contact support;

  • send us an email;

  • communicate through social media;

  • attend a meeting;

  • enter into a contract; or

  • provide information during service delivery.

Automatically

For example, through:

  • server logs;

  • security systems;

  • authentication systems;

  • cookies and similar technologies;

  • analytics;

  • advertising tags;

  • conversion tracking; and

  • portal activity logs.

Non-essential cookies and advertising technologies are controlled in accordance with our Cookies, Tracking & Advertising Technologies Policy and applicable consent requirements.

From third parties and public sources

For example:

  • advertising platforms;

  • lead-generation platforms;

  • partners and referrals;

  • payment providers;

  • business directories;

  • professional networking websites;

  • Companies House and other public registers;

  • a business you work for;

  • clients;

  • service providers;

  • business-data suppliers; and

  • public corporate websites.

Where we obtain personal data from another source, we record source information where appropriate and provide privacy information as required by law.


7. Why We Use Personal Data and Our Lawful Bases

We use personal data only where we have an appropriate lawful basis.

The lawful basis depends on the purpose and circumstances.

PurposeExamplesTypical lawful basis
Responding to enquiriesContact forms, consultation requests, quote requestsLegitimate interests; steps at your request before entering a contract
Providing servicesConsulting, development, marketing, support, projects, subscriptionsContract
Customer account administrationCRM, portal, onboarding, account recordsContract; legitimate interests
Orders and paymentsCheckout, billing, invoices, payment reconciliationContract; legal obligation; legitimate interests
Refunds and disputesRefund administration, chargeback evidence, fraud checksContract; legal obligation; legitimate interests
Legal/accounting recordsTax, accounts, invoices, statutory recordsLegal obligation
Customer serviceSupport, service notices, relationship managementContract; legitimate interests
Website securityAuthentication, access control, fraud/abuse preventionLegitimate interests; legal obligation where applicable
Website operationCore website functionality and necessary logsLegitimate interests; contract where relevant
AnalyticsWebsite/service analysis where permittedConsent where required; legitimate interests where lawfully available
Advertising trackingConversion measurement, retargeting, personalised advertisingConsent where required
Newsletter marketingPromotional email subscriptionConsent or another lawful basis where legally permitted
Existing-customer marketingSimilar products/services where applicableConsent, soft opt-in or legitimate interests as applicable
Corporate B2B marketingRelevant marketing to corporate subscribersLegitimate interests where appropriate; PECR consent is not generally required for corporate subscribers
Sole trader/individual electronic marketingMarketing to individual subscribersConsent or a valid soft opt-in where applicable
Marketing suppressionRecording an opt-out so we do not contact you again for marketingLegal obligation; legitimate interests
Business researchIdentifying relevant corporate prospectsLegitimate interests, subject to balancing and safeguards
Improving servicesQuality, analytics, product and operational improvementLegitimate interests
AI-assisted workDrafting, summarisation, operational assistanceContract; legitimate interests; consent where specifically required
Claims and legal mattersEstablishing, exercising or defending legal claimsLegitimate interests; legal obligation
RecruitmentManaging applications and placementsSteps before contract; legitimate interests; contract; legal obligation
Partners/suppliersManaging commercial relationships and paymentsContract; legitimate interests; legal obligation

We may rely on more than one lawful basis for the same information where the processing has more than one genuine purpose.


8. Our Legitimate Interests

Where we rely on legitimate interests, the interests may include:

  • operating and improving our business;

  • responding to business enquiries;

  • developing commercial relationships;

  • providing effective customer support;

  • maintaining accurate CRM and relationship records;

  • understanding how our services are used;

  • measuring business and marketing performance;

  • conducting proportionate B2B prospecting;

  • protecting our systems, customers and business from fraud, abuse or security threats;

  • maintaining audit and accountability evidence;

  • managing disputes;

  • protecting and enforcing legal rights;

  • improving products, services and workflows; and

  • communicating relevant services to business contacts where the impact on the individual is proportionate.

Where required, we assess whether our interests are overridden by the individual’s rights and freedoms.

You may object to processing based on legitimate interests. See Your Rights below.


9. Website Forms, Assessments, Audits and Lead Collection

When you complete a BhavPro form, we use the information for the purpose described at or around that form.

For example:

  • a contact form is used to respond to your message;

  • a quote form is used to assess and respond to a commercial request;

  • an audit or assessment is used to provide or prepare the requested analysis;

  • a download form is used to provide the requested resource;

  • a newsletter form is used to manage the subscription;

  • a consultation booking is used to arrange and manage the consultation; and

  • a lead-generation form on an advertising platform is used to respond to the request made through that platform.

Where a form includes an optional marketing choice, that marketing choice is separate from the processing needed to respond to the form itself.

We may retain evidence such as:

  • the form and version used;

  • the privacy notice shown;

  • the wording of any marketing choice;

  • date and time;

  • source;

  • landing page;

  • attribution data;

  • IP address and user agent where proportionate; and

  • the resulting lead or CRM record.

This helps us demonstrate what information was provided and what choices were made.


10. Newsletter and Email Subscribers

If you actively subscribe to BhavPro marketing emails, we may use your contact details to send:

  • newsletters;

  • articles and guides;

  • service updates;

  • invitations;

  • offers;

  • marketing insights;

  • information about BhavPro services; and

  • other communications covered by the subscription wording shown to you.

Where consent is the basis for marketing, you can withdraw it at any time.

We may keep an append-only record showing:

  • when a subscription or consent was given;

  • the source;

  • the wording or version relied upon;

  • when it was withdrawn;

  • whether an address has been suppressed, bounced or complained; and

  • related campaign evidence.

Withdrawing marketing consent does not necessarily require us to delete all information we hold about you. For example, we may retain limited suppression information to ensure we do not add you back to marketing.


11. Direct Marketing and B2B Campaigns

BhavPro may conduct carefully targeted B2B marketing.

11.1 Corporate subscribers

Under PECR, the specific consent rule for unsolicited electronic mail does not generally apply to corporate subscribers such as limited companies and limited liability partnerships.

Where we use an identifiable business contact’s personal data for B2B marketing, UK data protection law still applies. We will therefore:

  • identify an appropriate lawful basis;

  • use contact information in a relevant and proportionate way;

  • be transparent about the use;

  • identify BhavPro in the communication;

  • provide a valid means to opt out; and

  • respect objections and suppression records.

Where appropriate, we may rely on legitimate interests for relevant corporate B2B marketing after considering the purpose, necessity, expectations and impact of the processing.

11.2 Sole traders and other individual subscribers

Sole traders and certain unincorporated partnerships are treated as individual subscribers for the relevant PECR electronic-mail rules.

We will not knowingly send unsolicited electronic-mail marketing to an individual subscriber unless we have:

  • valid consent; or

  • another applicable permission such as a lawful soft opt-in.

11.3 Publicly available business information

The fact that an email address, professional profile or other information is publicly available does not itself amount to consent.

Where we use publicly available personal data for B2B research or marketing, we assess the lawful basis, relevance and reasonable expectations and provide transparency as required.

11.4 Purchased, licensed or supplied business data

Before using third-party data for direct marketing, we may assess:

  • where it came from;

  • when it was collected;

  • the type of subscriber;

  • the privacy information supplied;

  • any consent wording;

  • permitted uses;

  • suppression arrangements;

  • contractual controls; and

  • whether BhavPro is lawfully permitted to use it for the intended campaign.

We may reject or delete marketing data where sufficient provenance or authority cannot be established.


12. Marketing Opt-Out and Suppression

You have an absolute right to object to the use of your personal data for direct marketing.

You can stop BhavPro marketing emails by:

  • using an unsubscribe link included in a marketing email;

  • using a preference-management facility where available;

  • replying to the message with an opt-out request; or

  • contacting us at hello@bhavpro.com.

When you opt out, we may retain limited information in a suppression record so that your preference continues to be honoured.

Opting out of marketing will not normally stop necessary non-marketing communications such as:

  • security notices;

  • contractual communications;

  • invoices;

  • payment notices;

  • project communications;

  • support responses;

  • legal notices; or

  • service administration messages.


13. Email Delivery, Open and Click Information

Marketing and transactional email systems may generate technical delivery information such as:

  • queued;

  • sent;

  • accepted by an email provider;

  • delivered where a provider supplies reliable delivery evidence;

  • bounced;

  • complained;

  • unsubscribed;

  • clicked; and

  • opened where tracking is lawfully enabled.

We do not treat SMTP acceptance alone as proof that a message reached a person’s inbox.

Where open tracking, tracking pixels or similar storage/access technologies are used, we apply the relevant PECR and consent rules.


14. Advertising, Remarketing and Attribution

BhavPro may advertise through third-party platforms.

Depending on our active campaigns and your consent choices, providers may include:

  • Google Ads and Google services;

  • Meta Platforms, including Facebook and Instagram;

  • Microsoft Advertising, including Bing;

  • LinkedIn; and

  • other advertising, social-media, measurement or attribution providers.

These services may help us:

  • deliver advertisements;

  • limit or measure advertising frequency;

  • understand whether an advertisement led to a visit, enquiry or purchase;

  • measure conversions;

  • build advertising audiences;

  • retarget or remarket to previous visitors;

  • analyse campaign effectiveness;

  • prevent advertising fraud; and

  • improve advertising relevance.

Non-essential advertising storage/access technologies are governed by our Cookies, Tracking & Advertising Technologies Policy and the consent controls we make available.

14.1 Google

Where configured and permitted, Google technologies may process advertising, analytics, device, website interaction and conversion information.

Consent signals may be used to control Google advertising storage, advertising user data, advertising personalisation and analytics storage.

Google may process information under its own privacy and product terms.

14.2 Meta / Facebook / Instagram

Where configured and permitted, Meta technologies may be used for:

  • advertising measurement;

  • conversion tracking;

  • audience creation;

  • remarketing;

  • lead-generation activity; and

  • campaign optimisation.

This may involve Meta Pixel, server-side or API-based conversion tools, or information submitted through Meta lead-generation features.

Meta may process information under its own privacy and business-tool terms.

14.3 Microsoft Advertising / Bing

Where configured and permitted, Microsoft Advertising technologies such as Universal Event Tracking (“UET”) may be used to:

  • measure conversions;

  • understand advertising performance;

  • create remarketing audiences; and

  • attribute visits or actions to advertisements.

We use consent controls for UET where required.

Microsoft may process information under its own privacy and advertising terms.

14.4 LinkedIn

Where configured and permitted, LinkedIn advertising technologies may be used for:

  • conversion measurement;

  • website audience analysis;

  • advertising attribution;

  • matched audiences;

  • retargeting;

  • Lead Gen Forms; and

  • campaign optimisation.

The LinkedIn Insight Tag can transmit information relating to a website visit, such as URL, referrer, IP address, browser/device information and time of access. We do not intentionally install advertising tags on pages where doing so would cause prohibited or inappropriate disclosure of sensitive information.

LinkedIn may process information under its own privacy and advertising terms.

14.5 Future advertising providers

We may change or add advertising providers over time.

Before activating a materially new advertising technology, we aim to assess:

  • the purpose;

  • data involved;

  • privacy role;

  • storage/access technology;

  • consent requirements;

  • retention;

  • international transfers; and

  • necessary privacy or cookie-policy updates.


15. Advertising Click IDs, UTM Parameters and Source Attribution

If you arrive through an advertisement, campaign, referral or other marketing link, we may record attribution information such as:

  • utm_source;

  • utm_medium;

  • utm_campaign;

  • utm_content;

  • utm_term;

  • campaign or advertisement identifiers;

  • supported advertising click identifiers;

  • referrer;

  • landing page; and

  • conversion source.

Where appropriate, attribution information may be linked to a lead, enquiry, order or customer record.

Advertising platform identifiers remain advertising/provider identifiers; they are not used as BhavPro customer identities.


16. Payments and Stripe

BhavPro may use Stripe to provide payment processing, Checkout, subscriptions, payment methods, fraud prevention, refunds, disputes and related payment services.

When you make a payment:

  • Stripe may collect payment-card or payment-account information directly;

  • Stripe may receive device, browser, IP, billing, fraud-prevention and transaction information;

  • BhavPro may receive provider references and payment status;

  • BhavPro may retain transaction, invoice, refund, dispute and reconciliation records required to manage the purchase and protect legal or financial interests; and

  • Stripe may process personal data as described in Stripe’s own privacy information and applicable services agreements.

BhavPro does not intentionally store full card numbers or CVC/CVV values in its own application database.

For fraud prevention, account security and dispute handling, we may retain evidence concerning:

  • purchase and checkout;

  • customer/order/invoice identity;

  • amount and currency;

  • policy acceptance;

  • service or product purchased;

  • communications;

  • delivery;

  • refunds;

  • IP/device information where proportionate; and

  • provider references.

We retain such evidence only for legitimate business, contractual, legal, security, accounting and dispute-management purposes.


17. Customer Portal and CRM

BhavPro operates CRM and portal systems to manage business relationships and service delivery.

We may use customer/account information to:

  • maintain account details;

  • store customer contacts;

  • manage quotes and contracts;

  • process orders and subscriptions;

  • provide invoices and receipts;

  • manage support;

  • manage projects and deliverables;

  • provide files;

  • manage notifications;

  • handle refunds;

  • keep audit evidence; and

  • maintain security and account access.

A customer account is not necessarily the same thing as an individual portal user. A business customer may have multiple authorised contacts or portal users.

We apply access controls designed to prevent one customer, partner or tenant from accessing another’s data without authorisation.


18. AI and Automation

BhavPro may use third-party or internally operated AI and automation services.

Where personal data is involved, we aim to:

  • use only the information reasonably necessary;

  • restrict access;

  • avoid sending unnecessary sensitive information;

  • apply contractual and security controls;

  • maintain audit information where appropriate;

  • require human review for appropriate customer-facing or state-changing actions; and

  • avoid allowing an AI system to autonomously change core identity, payment or other high-risk records outside an approved workflow.

AI output may be inaccurate. Where AI is used to assist a service, it may form part of an internal workflow rather than being the sole authority for a significant decision.

If we introduce solely automated decision-making that produces legal or similarly significant effects, we will provide the required information and safeguards before using that processing.


19. Cookies and Similar Technologies

Our website and services may use:

  • cookies;

  • local storage;

  • pixels;

  • tags;

  • software development kits;

  • session technologies;

  • analytics;

  • advertising identifiers; and

  • similar storage/access technologies.

Some technologies are necessary to:

  • provide the website;

  • maintain security;

  • manage sessions;

  • process a requested service; or

  • remember essential choices.

Other technologies may be used for analytics, advertising, attribution or personalisation and may require consent.

Please read our separate Cookies, Tracking & Advertising Technologies Policy for:

  • current categories;

  • active vendors;

  • cookie or technology names where applicable;

  • purposes;

  • durations; and

  • instructions for changing your choices.


20. Who We Share Personal Data With

We may share personal data with appropriate recipients where necessary for the purposes described in this Policy.

Categories may include:

Service providers and processors

Such as providers of:

  • website hosting;

  • cloud infrastructure;

  • content delivery;

  • secure storage;

  • email delivery;

  • communications;

  • CRM or support infrastructure;

  • analytics;

  • security;

  • fraud prevention;

  • backup;

  • document processing;

  • AI;

  • automation; and

  • technical support.

Payment providers

Including Stripe and related payment infrastructure where applicable.

Advertising, analytics and social-media providers

Including, where configured:

  • Google;

  • Meta;

  • Microsoft;

  • LinkedIn; and

  • other approved advertising or measurement providers.

Professional advisers

Including:

  • accountants;

  • auditors;

  • solicitors;

  • insurers;

  • consultants; and

  • other professional advisers.

Clients

Where BhavPro processes information as part of providing a service to a client, relevant information may be made available to that client in accordance with the service relationship and applicable privacy responsibilities.

Partners, suppliers and subcontractors

Where reasonably required to provide or support a service and subject to appropriate controls.

Authorities and legal recipients

We may disclose personal data where necessary to:

  • comply with law;

  • comply with a court order;

  • respond to a lawful regulatory or law-enforcement request;

  • establish, exercise or defend legal rights;

  • protect the rights, property or safety of BhavPro, our customers or others; or

  • investigate fraud, abuse or security incidents.

Business transfers

If all or part of our business is reorganised, sold, transferred, merged or acquired, personal data may be disclosed as part of appropriate due diligence and transferred where lawful, subject to confidentiality and data-protection controls.


21. We Do Not Sell Personal Data for Money

BhavPro does not sell personal data to data brokers for monetary payment.

However, using third-party advertising platforms can involve disclosures or processing that may be regulated differently in jurisdictions outside the United Kingdom.

Where local law gives you additional rights relating to targeted advertising, sharing or similar activity, you may contact us and we will consider the request under the applicable law.


22. International Transfers

Some service providers, technology providers, advertising platforms and business partners may process personal data outside the United Kingdom.

Where UK data-protection law requires safeguards for an international transfer, we use an appropriate transfer mechanism where applicable, such as:

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement (“IDTA”);

  • the UK Addendum to approved standard contractual clauses;

  • another legally recognised transfer safeguard; or

  • a permitted legal derogation where appropriate.

Transfer arrangements depend on the recipient, country and processing involved.

You may contact us for more information about the safeguards relevant to a particular transfer.


23. How Long We Keep Personal Data

We do not keep personal data for longer than reasonably necessary for the purpose for which it was collected, subject to legal, accounting, security, dispute and evidential requirements.

Typical retention criteria include:

Data categoryTypical approach
General enquiries with no relationshipUsually up to 24 months after the last meaningful interaction, unless a longer period is justified
B2B prospect recordsPeriodically reviewed; normally removed or minimised where there is no continuing relevance, relationship or lawful purpose
Marketing subscriber dataWhile subscribed and for a reasonable period afterwards for audit and preference management
Marketing consent/withdrawal evidenceRetained as reasonably necessary to demonstrate the history of permission and withdrawal
Marketing suppression recordsRetained in limited form for as long as reasonably necessary to continue respecting the opt-out
Customer and contract recordsNormally for the relationship and an appropriate legal limitation/record-keeping period afterwards
Accounting and tax recordsRetained for the period required by applicable financial and tax law
Invoice/payment/refund/dispute evidenceNormally retained with relevant financial/legal records and longer where a dispute, chargeback, fraud or legal hold requires it
Portal security and access logsKept for a proportionate security/audit period, subject to risk and system requirements
Support and project recordsRetained for the service relationship and a proportionate period afterwards for support, quality, contractual and legal purposes
Recruitment recordsRetained according to the recruitment purpose, client instructions and applicable legal requirements
Cookie/advertising dataDepends on the technology and provider; see the Cookies, Tracking & Advertising Technologies Policy

We may keep information for longer where:

  • required by law;

  • a dispute or claim exists or is reasonably anticipated;

  • fraud or security investigation requires it;

  • a legal hold applies;

  • an authority requires preservation; or

  • we need limited information to establish that a right, suppression or other preference has been honoured.

Where practical, information may instead be anonymised or irreversibly de-identified.


24. Data Accuracy

We take reasonable steps to keep personal data accurate and up to date.

Please tell us if relevant information changes.

Where we obtain B2B contact information from public or third-party sources, we may verify or update it using reliable business information.


25. Security

We use technical and organisational measures designed to protect personal data against:

  • unauthorised access;

  • accidental loss;

  • misuse;

  • alteration;

  • unauthorised disclosure; and

  • destruction.

Depending on the system and risk, measures may include:

  • access controls;

  • authentication controls;

  • multi-factor authentication;

  • role and tenant restrictions;

  • encrypted transport;

  • protected credential storage;

  • logging and audit records;

  • backups;

  • security monitoring;

  • rate limiting;

  • secure development practices;

  • provider security controls; and

  • incident-management processes.

No method of transmitting or storing information can be guaranteed to be completely secure. We therefore do not make an absolute guarantee that a security incident can never occur.

If we become aware of a personal-data breach, we assess it and make notifications to the Information Commissioner’s Office and affected individuals where required by law.


26. Your Data-Protection Rights

Depending on the circumstances and lawful basis, you may have rights to:

  • be informed about how your personal data is used;

  • access personal data we hold about you;

  • rectify inaccurate or incomplete personal data;

  • erase personal data in certain circumstances;

  • restrict processing in certain circumstances;

  • object to processing based on legitimate interests;

  • object to direct marketing at any time;

  • data portability where the legal requirements apply;

  • withdraw consent at any time where processing is based on consent; and

  • obtain safeguards relating to certain types of automated decision-making where applicable.

These rights are not absolute. For example, we may need to retain certain information to comply with legal obligations, establish or defend legal claims, maintain financial records or preserve an effective marketing suppression record.

We will explain any lawful reason for refusing or limiting a request.


27. Exercising Your Rights

To exercise a privacy right, contact:

Sentiora Consulting Ltd trading as BhavPro
45 Marston Road
Leicester
United Kingdom
LE4 9FE

Email: hello@bhavpro.com
Subject: Privacy Request

Please describe your request clearly.

We may ask for information reasonably necessary to confirm your identity and protect personal data from unauthorised disclosure.

We will respond within the period required by applicable law.

We do not ordinarily charge a fee for a data-protection rights request. The law may permit a reasonable fee or refusal in limited circumstances, for example where a request is manifestly unfounded or excessive.


28. Your Absolute Right to Object to Direct Marketing

You can object to our use of your personal data for direct marketing at any time.

We will stop using the relevant personal data for direct-marketing purposes after processing your request, subject to retaining limited suppression information where necessary to ensure your preference continues to be respected.

You can:

  • click an unsubscribe link;

  • reply with an opt-out request;

  • use a preference-management function where available; or

  • email hello@bhavpro.com.


29. Withdrawing Consent

Where we rely on your consent, you can withdraw it at any time.

Withdrawing consent does not make processing that occurred before withdrawal unlawful.

Withdrawal may affect a feature or service where that processing cannot be provided without the consent concerned.

Marketing consent can be withdrawn using the methods described above.

Cookie and advertising consent can be changed through our cookie-preference controls where available.


30. Automated Decision-Making and Profiling

We may use segmentation, scoring, analytics and automated assistance to help prioritise or organise business activity.

Examples may include:

  • marketing segmentation;

  • lead scoring;

  • recommendations;

  • fraud/risk signals supplied by payment providers;

  • service prioritisation; and

  • AI-assisted summaries.

Unless we tell you otherwise in a specific notice, BhavPro does not intend to make a decision based solely on automated processing that has a legal or similarly significant effect on you.

If that changes, we will provide appropriate information about:

  • the processing;

  • meaningful information about the logic involved;

  • likely significance or consequences; and

  • applicable safeguards and rights.


31. Children’s Privacy

BhavPro provides business and professional services and does not target its services or marketing at children.

We do not knowingly seek to collect personal data from children for marketing or ordinary commercial purposes.

If you believe a child has provided personal data to us inappropriately, please contact us.


32. Third-Party Websites and Services

Our websites may link to external websites, platforms, videos, social networks, payment services, tools or other third-party resources.

Third parties operate under their own privacy practices.

We are not responsible for the privacy content or processing practices of a third-party website merely because we link to it.

Please review the relevant third party’s privacy information.


33. Provider Privacy Information

Depending on which services are enabled, relevant provider privacy notices may include:

These links are provided for convenience. Provider services and privacy terms may change over time.


34. Complaints

We would like the opportunity to address any privacy concern directly.

Please contact:

Sentiora Consulting Ltd trading as BhavPro
Email: hello@bhavpro.com
Subject: Privacy Complaint

If you remain dissatisfied, you have the right to complain to the UK’s data-protection supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/

You can also use the ICO’s online complaint services.


35. Changes to this Privacy Policy

We review this Privacy Policy periodically and update it where necessary to reflect:

  • legal or regulatory changes;

  • new services;

  • changes to how we process personal data;

  • changes to advertising, analytics or AI technologies;

  • new providers;

  • changes to international transfers; or

  • improvements to our privacy practices.

The version and effective date at the top of this Policy identify the current published version.

Where a change is material and the law requires additional notice or consent, we will provide that notice or obtain that consent before the relevant new processing begins.

We may retain previous policy versions for legal, audit and evidential purposes.


36. Contact Us

For privacy questions, rights requests or concerns:

Sentiora Consulting Ltd trading as BhavPro
Company number: 16596409
Registered office: 45 Marston Road, Leicester, United Kingdom, LE4 9FE
Email: hello@bhavpro.com
Website: https://bhavpro.com/
Contact: https://bhavpro.com/contact/


End of Privacy Policy — Version 1.0 — Effective 1 September 2026