Privacy Notice
Last updated: 20 July 2026
Who I am
This privacy notice explains how I collect and use personal information through this website and in connection with enquiries about my services.
The data controller is:
Zoë Ann May trading as Zoë May Consulting & Creative
Sole trader
Business address: see Legal Information
Email: hello@zoemayconsulting.co.uk
Website: www.zoemayconsulting.co.uk
Personal information I collect
Depending on how you contact or work with me, I may collect:
-
your name;
-
organisation and job title;
-
business or personal email address;
-
telephone number;
-
postal address, where relevant;
-
information included in an enquiry or contact-form message;
-
correspondence and meeting notes;
-
information needed to prepare a proposal, contract or invoice;
-
payment and transaction information;
-
technical information generated when you use the website, such as IP address, browser type and cookie preferences;
-
any other information you choose to provide.
Please avoid submitting sensitive personal information through the website contact form unless it is genuinely necessary.
How I collect your information
-
when you submit the website contact form;
-
when you email, telephone or message me;
-
when you ask for a proposal or engage my services;
-
during meetings, workshops or project delivery;
-
when you connect with me through LinkedIn;
-
from publicly available professional sources, where relevant to legitimate business activity;
-
automatically through website cookies or similar technologies, subject to your cookie choices.
Why I use your information
I may use personal information to:
-
respond to enquiries;
-
arrange introductory calls or meetings;
-
prepare proposals, quotations and contracts;
-
provide consultancy or creative services;
-
communicate about ongoing work;
-
manage appointments, project records and client relationships;
-
issue invoices and maintain financial records;
-
comply with legal, tax, accounting and insurance requirements;
-
protect the security of the website, email and business systems;
-
establish, exercise or defend legal claims;
-
improve the website and understand how it is used, where analytics consent has been given;
-
send marketing communications only where permitted by law.
Lawful bases for using your information
UK data protection law requires a lawful basis for each use of personal information. The basis will depend on the circumstances.
I may rely on:
Steps before entering a contract
To respond to a request for a proposal, quotation or discussion about possible services.
Performance of a contract
To provide agreed services, communicate about the work and manage payment.
Legal obligation
To comply with tax, accounting, regulatory or other legal requirements.
Legitimate interests
Where it is reasonably necessary to operate and protect the business, respond to general enquiries, maintain professional relationships, secure systems or establish and defend legal rights, provided those interests are not overridden by your rights.
Consent
Where required, such as for non-essential website cookies or certain marketing communications. You can withdraw consent at any time.
Consent is only one possible lawful basis; businesses must identify the appropriate basis before using personal information.
Contact-form enquiries
When you submit the contact form, I use the information you provide to understand and respond to your enquiry.
Submitting the form does not automatically add you to a marketing list.
The lawful basis will normally be:
-
taking steps at your request before entering a contract, where your enquiry concerns possible services; or
-
legitimate interests, where I need to respond to another genuine business enquiry.
Marketing communications
I do not use contact-form details for unrelated marketing without an appropriate lawful basis.
Where consent is required, marketing consent will be requested separately and will not be bundled into the contact form.
You may ask me to stop sending marketing communications at any time by emailing: hello@zoemayconsulting.co.uk.
Electronic marketing rules can also apply to business contacts, particularly sole traders and individuals.
Who I may share information with
I may share personal information only where reasonably necessary with:
-
Wix, as website hosting and form-service provider;
-
Microsoft 365, for email, documents and business administration;
-
accounting, bookkeeping or tax advisers;
-
payment providers or banks;
-
professional advisers, insurers or legal representatives;
-
IT, website or cybersecurity service providers;
-
subcontractors or associates supporting an agreed project, where appropriate;
-
public authorities, regulators or law-enforcement bodies where required by law;
-
a purchaser or successor if the business is sold or transferred.
-
Microsoft, where Microsoft 365 and Microsoft Copilot are used for email, documents, administration and productivity;
-
OpenAI, where ChatGPT is used for drafting, research support or administrative assistance.
I do not sell personal information.
Where a supplier processes information on my behalf, I will take reasonable steps to ensure appropriate contractual and security arrangements are in place.
Use of artificial intelligence
I may use artificial-intelligence tools, including Microsoft Copilot and ChatGPT, to support limited business tasks such as:
-
drafting and improving written material;
-
summarising non-sensitive information;
-
developing document structures, checklists or templates;
-
administrative research and productivity support.
Where personal information is involved, I will use AI tools only where there is an appropriate lawful basis and where the use is necessary and proportionate.
I will take reasonable steps to minimise the information provided to AI tools. Wherever practical, personal details, confidential information and project identifiers will be removed or anonymised before information is submitted.
I will not intentionally use public or consumer AI tools to process:
-
special-category personal data;
-
confidential client material;
-
legally privileged information;
-
security-sensitive infrastructure information;
-
unpublished commercial information;
-
personal information that is not necessary for the task.
AI-generated material may be inaccurate or incomplete. Outputs will therefore be reviewed by me and will not be relied upon without appropriate professional judgement and verification.
Where AI services process personal information on my behalf, the provider may act as a data processor or separate controller depending on the service and circumstances. Further information about the relevant provider and safeguards can be requested by contacting me.
I do not use AI to make solely automated decisions that produce legal or similarly significant effects about individuals.
International transfers
Some service providers may store or process information outside the United Kingdom.
Where this happens, I will rely on an appropriate safeguard recognised under UK data protection law, such as:
-
UK adequacy regulations;
-
the UK International Data Transfer Agreement;
-
the UK Addendum to approved standard contractual clauses; or
-
another lawful transfer mechanism.
Further information about relevant safeguards can be requested using the contact details above.
How long I keep information
I keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, insurance and contractual requirements.
My intended retention periods are:
-
Unsuccessful or general enquiries: normally up to 12 months after the last meaningful contact;
-
Client and project records: normally seven years after the end of the engagement;
-
Contracts, invoices and accounting records: normally at least six years after the end of the relevant financial year or transaction;
-
Website contact-form submissions: normally up to 12 months, unless they become part of a client record;
-
Marketing records: until you unsubscribe or the information is no longer needed;
-
Cookie and analytics information: for the period stated in the Cookie Policy or the relevant service settings.
Information may be kept longer where necessary for an active dispute, legal claim, regulatory requirement or insurance matter.
Personal information should not be retained for longer than necessary.
How I protect your information
I use reasonable technical and organisational measures to protect personal information, including:
-
password-protected accounts;
-
multifactor authentication;
-
access controls;
-
secure Microsoft 365 storage;
-
device and software security;
-
appropriate backups;
-
limiting access to those who genuinely need the information;
-
securely deleting or disposing of information when it is no longer required.
No internet or email system can be guaranteed to be completely secure.
Cookies and website analytics
The website may use essential cookies needed for security and operation.
Non-essential analytics, functional or marketing cookies will only be used in accordance with the choices available through the cookie banner.
Further details are available in the Cookie Policy and through the Cookie Settings link in the website footer.
Your data protection rights
Depending on the circumstances and lawful basis, you may have the right to:
-
ask for access to your personal information;
-
ask for inaccurate information to be corrected;
-
ask for information to be deleted;
-
ask for use of your information to be restricted;
-
object to certain uses of your information;
-
ask to receive or transfer information in a portable format;
-
withdraw consent where consent is the lawful basis;
-
complain about how your information has been handled.
These rights are not absolute, and legal exemptions may apply. The rights available can differ depending on the lawful basis used.
To exercise a right, contact:
I may need to confirm your identity before dealing with a request.
Complaints
Please contact me first if you have concerns about how I have used your personal information so that I have an opportunity to resolve the issue.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
The ICO’s contact details and complaint process are available on its website.
Links to other websites
This website may contain links to third-party websites, including LinkedIn.
I am not responsible for the privacy practices of those websites. You should read the relevant third party’s privacy notice before providing personal information.
Children’s information
This website and its consultancy services are not directed at children and I do not knowingly collect children’s personal information through the contact form.
If you believe that a child has submitted personal information, please contact me so that it can be reviewed and, where appropriate, deleted.
Changes to this privacy notice
I may update this notice where the website, services, suppliers or legal requirements change.
The date at the top of the page will show when it was last revised.