Privacy Policy
Last updated: 15 September 2026
1. Who we are
ELJ Consulting is operated by Lisa Jensen, trading as ELJ Consulting. In this policy, “ELJ Consulting”, “we”, “us” and “our” refer to ELJ Consulting.
For personal information that we collect and use for our own business purposes, ELJ Consulting is the data controller.
Correspondence address: St Georges Works, 51 Colegate, Norwich NR3 1DD
Email: info@eljconsulting.co.uk
Telephone: 0800 001 6402
Website: https://www.eljconsulting.co.uk
Information Commissioner’s Office registration number: ZA445195
2. What this policy covers
This policy explains how we collect, use, store and protect personal information when you:
visit our website;
contact us or make an enquiry;
become a client, supplier or business contact; or
communicate with us in connection with our services.
ELJ Consulting also provides credit control and client records management services on behalf of other businesses. When we process personal information solely on a client’s instructions, that client will normally be the data controller and ELJ Consulting will act as its data processor. In those circumstances, the client’s privacy policy will explain how and why your information is used. We process that information only for the agreed service, in accordance with the client’s documented instructions and an appropriate data processing agreement.
3. Personal information we collect
Depending on how you interact with us, we may collect and process:
your name, job title and the name of your business;
your business or personal email address and telephone number;
postal or business addresses;
information included in an enquiry, contact form, email, telephone call or other communication;
details of the services you request or receive;
contractual, billing, invoice and payment information;
records of correspondence, agreed actions and service progress;
your communication and marketing preferences;
technical information associated with use of our website, such as your Internet Protocol address, browser type, device information, pages visited and cookie preferences; and
information needed to establish, exercise or defend legal rights, prevent fraud or comply with a legal obligation.
When we act on behalf of a client, we may also process information supplied by that client. Depending on the service, this may include names, contact details, account references, invoices, payment history, outstanding balances, correspondence, bank statements, sales and purchase invoices, receipts, payroll information, VAT records, identification documents and other records requested by the client.
We ask clients not to provide personal information that is unnecessary for the service. Where particularly sensitive information is involved, it must be handled under the client’s documented instructions and with appropriate safeguards.
4. How we obtain personal information
We may receive personal information:
directly from you;
from a business or professional practice that has appointed us to provide a service;
from suppliers and professional advisers;
through our website and its essential or consented technologies; and
from publicly available business sources where it is appropriate and lawful to use them.
5. How and why we use personal information
We use personal information only where we have a lawful reason to do so. Our purposes and usual lawful bases are:
Responding to enquiries
We use contact details and enquiry information to respond, provide requested information and discuss possible services. We do this where it is necessary to take steps at your request before entering into a contract, or because we have a legitimate interest in managing genuine business enquiries.
Providing and managing our services
We use relevant contact, service, account and communication information to enter into and perform contracts, deliver agreed services, provide progress updates and manage client relationships. Our lawful bases are performance of a contract and our legitimate interests in operating and administering our business.
Providing services on behalf of clients
When acting as a data processor, we use personal information only as necessary to provide the agreed credit control or client records management service and only on the data controller’s documented instructions.
Billing, accounting and legal compliance
We use transaction, invoice, payment and business records to administer our finances, maintain appropriate records and meet tax, accounting and other legal requirements. Our lawful bases are compliance with legal obligations and our legitimate interests in managing our business.
Protecting our business and legal rights
We may use relevant information to maintain security, prevent or investigate fraud, manage complaints, recover sums owed, obtain professional advice and establish, exercise or defend legal claims. We rely on our legitimate interests and, where applicable, compliance with legal obligations.
Business communications and marketing
We may send relevant business communications where you have asked to receive them, where consent is required, or where we have a legitimate interest and the law permits us to do so. You may ask us to stop marketing communications at any time by emailing info@eljconsulting.co.uk.
Website operation and cookies
We use strictly necessary technologies to operate and secure the website. We use non-essential cookies or similar technologies only where the law permits and, where required, after obtaining your consent. You can accept, reject or change your choices using the website’s privacy settings.
We do not use personal information for solely automated decision-making that produces legal or similarly significant effects.
6. Who we share personal information with
Where necessary and lawful, we may share personal information with:
the client that appointed us to provide a service;
website hosting, email, telephone, secure storage, customer relationship management, accounting, document transfer, information technology and security providers;
accountants, insurers, legal advisers and other professional advisers;
payment and banking service providers;
government bodies, regulators, law enforcement agencies or courts where disclosure is required or permitted by law; and
a prospective purchaser, successor or adviser if our business is sold, transferred or reorganised, subject to appropriate confidentiality arrangements.
We require service providers handling personal information for us to protect it, use it only for the agreed purpose and comply with applicable data protection requirements. We do not sell personal information.
7. International transfers
Some service providers may store or process information outside the United Kingdom. Where this occurs, we take reasonable steps to ensure that an appropriate legal safeguard is in place, such as United Kingdom adequacy regulations or approved contractual safeguards, together with any additional protections considered necessary.
You may contact us if you would like further information about the safeguards relevant to your personal information.
8. How long we keep personal information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, contractual and dispute-resolution requirements.
Our usual retention approach is:
unsuccessful or one-off enquiries are normally retained for up to 12 months after the last meaningful contact;
client, contract, invoice, payment and related business records may normally be retained for up to six years after the end of the relationship or the relevant accounting period;
information processed solely on behalf of a client is retained, returned or securely deleted in accordance with that client’s instructions, the data processing agreement and any applicable legal requirement;
marketing preferences and suppression records may be retained for as long as necessary to respect your communication choice; and
cookie and website information is retained for the period stated in the relevant cookie or privacy settings.
We may retain information for longer where required by law or where it is reasonably necessary in connection with an actual or potential legal claim.
9. How we protect personal information
We use appropriate organisational and technical safeguards designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or misuse. These include limiting access to those who need the information, using suitable security controls and transferring documents through appropriate channels.
No Internet or electronic storage system can be guaranteed to be completely secure. If you believe information has been sent to us in error or that there may be a security issue, please contact us promptly.
10. Your data protection rights
Depending on the circumstances, you may have the right to:
be informed about how your personal information is used;
request access to the personal information held about you;
ask for inaccurate or incomplete information to be corrected;
ask for personal information to be erased;
ask us to restrict the way information is used;
object to processing based on legitimate interests or for direct marketing;
receive certain information in a portable format;
withdraw consent at any time where processing relies on consent; and
complain to the Information Commissioner’s Office.
These rights are not absolute and exemptions may apply. If ELJ Consulting holds information only as a processor for one of its clients, we may refer your request to the relevant client as the data controller.
To exercise a right, email info@eljconsulting.co.uk. We may need to confirm your identity before responding. There is normally no charge, although the law allows a reasonable fee or refusal in limited circumstances.
You may also raise a concern with the Information Commissioner’s Office through https://ico.org.uk/make-a-complaint/. We would appreciate the opportunity to address your concern first.
11. Cookies and similar technologies
Our website may use cookies and similar technologies to operate correctly, remember choices, maintain security and, where enabled, understand website use.
Strictly necessary technologies may be used without consent where permitted by law. Optional analytics, advertising or similar technologies will not be used unless they are enabled through the website’s consent controls where consent is required.
You can review or change your choices at any time through the website’s privacy settings. You can also control cookies through your browser, although blocking essential technologies may affect website operation.
12. Third-party websites
Our website may contain links to websites operated by other organisations. We are not responsible for their privacy practices. Please read the privacy information provided by the relevant organisation before supplying personal information.
13. Changes to this policy
We may update this policy to reflect changes to our services, suppliers, website or legal obligations. The latest version will be published on this page and identified by the date shown at the top.
14. Contact us
For questions about this policy or the way ELJ Consulting handles personal information, contact:
Lisa Jensen
ELJ Consulting
Email: info@eljconsulting.co.uk
Telephone: 0800 001 6402
Correspondence address: St Georges Works, 51 Colegate, Norwich NR3 1DD
