Privacy Policy

Who we are

Our website address is: https://hocain.co.uk/.

Hocain & Co. (“we”, “us”, “our”) provides financial advisory services, including financial modelling, valuation, due diligence, transaction advisory, and fractional CFO services. This policy explains what personal data we collect through this website, how we use it, and the rights you have over it.

If you have any questions about this policy or how we handle your data, you can contact us at kelly@kellyhocain-co-uk.

Data we collect

Contact and enquiry form

When you submit our contact or intake form, we collect the information you provide — typically your name, email address, and the contents of your message. We use this only to respond to your enquiry and, if you become a client, to begin the engagement process. We do not use this information for unrelated marketing purposes without your separate consent.

Communications via WhatsApp Business

We use WhatsApp Business to communicate with prospective and existing clients. If you contact us or we correspond with you via WhatsApp, that communication is subject to WhatsApp’s own privacy policy and data handling practices, in addition to this policy, since messages are transmitted and stored through WhatsApp’s platform. We recommend reviewing WhatsApp’s privacy policy at https://www.whatsapp.com/legal/privacy-policy for details on how they process your data.

We retain WhatsApp correspondence with clients and prospective clients for as long as is reasonably necessary for the purposes described below.

Client engagement data

If you engage us for advisory services, we will collect and process additional personal and financial information as necessary to carry out the engagement (for example, information contained in documents you share with us for financial modelling, valuation, or due diligence work). This is handled under the terms of our engagement letter or contract with you and is kept confidential in accordance with our professional obligations.

Media

If you upload images to the website (for example, as part of an enquiry), please be aware that images may contain embedded location data (EXIF GPS). We do not deliberately extract or use this data.

Cookies

Our website may use cookies for basic functionality (such as remembering your preferences). We do not currently run a blog or comments system, so comment-related cookies do not apply. If this changes, this policy will be updated accordingly.

If our site uses any analytics or tracking cookies in the future, we will disclose them here along with how to opt out.

How we use your data

We use the personal data we collect to:

  • Respond to enquiries submitted via our contact form or WhatsApp
  • Provide, manage, and deliver advisory services to clients
  • Meet our legal, regulatory, and professional obligations (including under ICAEW requirements)
  • Improve our website and services

We do not sell your personal data to third parties.

Legal basis for processing (UK GDPR)

Where UK GDPR applies, we rely on the following legal bases:

  • Consent — where you voluntarily submit information via our contact form or initiate contact via WhatsApp
  • Contract — where processing is necessary to perform a contract or engagement with you as a client
  • Legitimate interests — for example, to respond to enquiries and maintain business records
  • Legal obligation — where we are required to retain certain records for professional, tax, or regulatory purposes

Who we share your data with

We do not share your personal data with third parties except:

  • Where necessary to deliver services you have engaged us for (for example, with subcontractors bound by confidentiality obligations, if applicable to your engagement)
  • Where required by law or by professional regulatory bodies
  • WhatsApp, as the platform used to facilitate direct messaging (see above)

If you request a password reset for any account-based area of the site (if applicable), your IP address may be included in the reset email.

How long we retain your data

  • Contact form enquiries that do not result in an engagement are retained for a reasonable period to allow for follow-up, then deleted.
  • Client records, including engagement correspondence and related financial documents, are retained in line with our professional and legal obligations as a finance advisory practice (typically a minimum of six years from the end of the engagement, in line with standard UK record-keeping requirements), unless a longer period is required by law or regulation.
  • WhatsApp correspondence with clients is retained for the same period as other client records where it forms part of the engagement history.

What rights you have over your data

Under UK GDPR, you have the right to:

  • Request a copy of the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data (subject to our legal and professional obligations to retain certain records)
  • Object to or restrict certain processing
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, contact us at [insert contact email]. We will respond within the timeframes required by UK GDPR.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at https://ico.org.uk if you believe your data has not been handled appropriately.

Where your data is sent

Data submitted via our contact form is processed and stored within [insert hosting/email provider location, e.g. “the UK/EU”]. Data shared via WhatsApp is subject to WhatsApp/Meta’s own data transfer practices, as set out in their privacy policy.

Changes to this policy

We may update this privacy policy from time to time, for example as our website or service offering changes. The “last updated” date at the top of this page will reflect the most recent revision.