Legal
Privacy Policy
Last updated: 6 October 2026. This Privacy Policy explains how Lanterns & Ledgers collects and uses personal data and the rights you have over that data.
1. Who we are
Lanterns & Ledgers ("we", "us", "our") is a fractional finance consultancy based in Bristol, United Kingdom, providing fractional finance director and financial management services to values-led businesses, founders, charities and community interest companies (CICs). This policy applies to our website at www.lanternsledgers.co.uk (the "website").
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for personal data collected through the website. You can contact us at any time at hello@lanternsledgers.co.uk.
2. Information we collect
We collect the following categories of personal data:
- Enquiry data: when you contact us through the contact form or by email, we collect your name, email address, telephone number (if you provide one) and the content of your message.
- Correspondence data: records of communications between you and us, such as emails and meeting notes, where relevant to an enquiry or a client engagement.
- Technical data: limited technical information, such as your IP address, browser type and device, collected in server logs by our hosting provider to keep the website secure and operational.
We do not collect special category data (such as data about health, ethnicity or biometrics) through this website, and the website is not directed at children under 16.
3. How we use your information
We use personal data to:
- respond to your enquiries and provide information about our services;
- provide fractional finance and related professional services to clients under an engagement letter or written agreement;
- communicate with you about matters connected with an enquiry or engagement;
- keep accurate business records and meet our legal, regulatory, tax and accounting obligations; and
- keep the website secure and functioning.
4. Lawful bases for processing
We rely on the following lawful bases under UK GDPR:
- Performance of a contract: processing that is necessary to provide services to clients, or to take steps at your request before entering into a contract.
- Legitimate interests: responding to enquiries, maintaining business records and keeping the website secure.
- Legal obligation: complying with our legal, regulatory, tax and accounting duties.
- Consent: where you have given us specific consent. Where processing is based on consent, you may withdraw it at any time.
5. Cookies
The website uses only strictly necessary cookies required for it to function and to deliver content safely. We do not use analytics, advertising or third-party tracking cookies. You can control or delete cookies through your browser settings; doing so will not prevent you from using the website.
6. Sharing your information
We do not sell, rent or trade your personal data. We share it only with:
- Service providers: trusted processors that help us operate the website and our business, including our hosting provider (Vercel) and our content management system (Prismic).
- Professional advisers: accountants, auditors or legal advisers, where this is necessary.
- Authorities: where disclosure is required by law, regulation or valid legal process.
Where we engage processors, we do so under written contracts that require them to protect your personal data and to process it only on our instructions.
7. International transfers
Some of our service providers may process personal data outside the United Kingdom, including in the United States. Where this happens, we put in place appropriate safeguards, such as the International Data Transfer Addendum to the EU Standard Contractual Clauses (the UK Addendum), the UK-US Data Bridge, or an assessment that the transfer is necessary for the performance of a contract with you.
8. Data retention
We keep personal data only as long as we need it:
- Enquiry data is retained for up to 24 months after our last correspondence, unless a client relationship follows.
- Client records are retained for at least six years after an engagement ends, so that we can meet our legal, tax and professional obligations.
- Server logs are retained only for as long as needed for security and operational purposes.
9. Your rights
Under UK GDPR, you have the right to:
- request access to your personal data and a copy of it;
- request the correction of inaccurate or incomplete data;
- request the erasure of your data in certain circumstances;
- request that we restrict processing of your data;
- object to processing based on legitimate interests;
- request the transfer of data you provided to us to another controller; and
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email hello@lanternsledgers.co.uk. We will respond within one month.
If you are unhappy with how we have handled your personal data, you have the right to complain to the Information Commissioner's Office, the UK data protection regulator.
10. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), access controls and secure storage with our providers. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. The "Last updated" date above shows when it was last revised. Please check back occasionally for updates.
12. Contact us
If you have any questions about this policy or how we handle your data, email hello@lanternsledgers.co.uk or write to: Lanterns & Ledgers, Bristol, United Kingdom.