Privacy Policy - GDPR
Grosvenor M&A
Last updated: 30 June 2026
This website is operated by Grosvenor M&A.
The privacy of our website users, clients, prospective clients, business contacts and other individuals is important to us. This privacy policy explains how and why we collect, use, store, share and protect personal information, and explains your rights under UK data protection law.
Please read this policy carefully.
1. Who we are
Grosvenor M&A is responsible for the personal information we collect and use through this website and in connection with enquiries made through it.
For the purposes of UK data protection law, the data controller is:
Grosvenor M&A
[Insert full legal entity name]
[Insert company number, if applicable]
[Insert registered office or business address]
Email: admin@grosvenorcorporate.com
If you have any questions about this privacy policy or how we use your personal information, please contact us using the email address above.
2. Personal information we collect
We may collect and process the following types of personal information:
your name;
business name;
job title or role;
postal address;
email address;
telephone number;
information you provide when contacting us through our website;
information about your business, where relevant to an enquiry or potential engagement;
communication records, including emails, messages, meeting notes and call records;
website usage information, including cookies and analytics data;
marketing preferences;
information required for client onboarding, anti-money laundering, fraud prevention, conflict checks or regulatory compliance, where applicable.
We will only collect information that is relevant and necessary for the purpose for which it is being processed.
3. How we collect personal information
We may collect personal information in the following ways:
when you contact us through our website;
when you email, telephone or otherwise communicate with us;
when you request information about our services;
when you engage us or enquire about engaging us;
when you subscribe to marketing or updates;
when you attend meetings, calls or events with us;
when information is provided to us by you, your representatives or your business;
when we receive information from professional advisers, introducers, funders, buyers, investors, accountants, solicitors or other parties involved in a transaction or enquiry;
through cookies and similar technologies on our website.
4. How we use your personal information
We may use your personal information for the following purposes:
to respond to enquiries;
to provide information about our services;
to assess whether we can assist you or your business;
to provide mergers and acquisitions, corporate finance, business sale, acquisition, consultancy or related advisory services;
to communicate with you;
to manage client relationships;
to carry out client onboarding, identity checks, anti-money laundering checks, fraud prevention checks and conflict checks where required;
to prepare, review and manage business sale, acquisition or investment opportunities;
to share information with potential buyers, sellers, funders, investors or advisers where appropriate and subject to suitable confidentiality arrangements;
to manage contracts and engagements;
to maintain business records;
to comply with legal, regulatory, accounting, tax or professional obligations;
to protect our business, clients and third parties from fraud or unlawful activity;
to improve our website and services;
to send marketing communications where permitted by law;
to deal with complaints, disputes or legal claims.
5. Lawful bases for processing
We will only use your personal information where we have a lawful basis to do so under UK data protection law.
The lawful bases we may rely on include:
Contract
Where processing is necessary to enter into or perform a contract with you or your business.
Legal obligation
Where processing is necessary to comply with legal, regulatory, tax, accounting, anti-money laundering or other obligations.
Legitimate interests
Where processing is necessary for our legitimate business interests, provided your rights and interests do not override those interests. This may include responding to business enquiries, managing client relationships, undertaking business development, protecting our business from fraud, keeping business records, and providing professional advisory services.
Consent
Where you have given consent for a specific purpose, such as certain types of marketing or non-essential cookies.
Legal claims
Where processing is necessary to establish, exercise or defend legal claims.
6. Marketing
We may use your personal information to send you information about our services, updates, insights or other communications that may be relevant to you or your business.
Where required by law, we will ask for your consent before sending marketing communications.
In some business-to-business circumstances, we may rely on legitimate interests to contact business contacts about services that may be relevant to their role or organisation, provided this is permitted by applicable law.
You can opt out of marketing communications at any time by:
clicking the unsubscribe link in any marketing email; or
emailing us at admin@grosvenorcorporate.com.
We will not sell your personal information to third parties for marketing purposes.
7. Cookies and website analytics
Our website may use cookies and similar technologies.
Cookies are small text files placed on your device when you visit a website. They may be used to make the website work properly, improve your experience, understand how visitors use the website, or support marketing and analytics.
We may use:
strictly necessary cookies;
performance or analytics cookies;
functionality cookies;
marketing or tracking cookies, where applicable.
Non-essential cookies will only be used where you have given consent, where required by law.
You can manage or withdraw cookie consent through the cookie settings on our website, where available, or through your browser settings.
Some website functions may not work properly if cookies are disabled.
8. Sharing your personal information
We may share personal information where necessary and lawful with:
professional advisers, including solicitors, accountants, tax advisers, consultants and insurers;
potential buyers, sellers, investors, funders, lenders or acquirers;
parties involved in a merger, acquisition, disposal, investment or corporate finance transaction;
regulatory, legal, tax, law enforcement or government authorities where required;
anti-money laundering, identity verification, fraud prevention or compliance service providers;
IT, cloud hosting, website, CRM, email, document storage and software providers;
marketing, analytics and website service providers;
payment, finance or administration providers;
other third parties where necessary to provide our services, protect our business or comply with legal obligations.
Where we share personal information with third-party service providers, we require them to process it securely and only for authorised purposes.
Where confidential business or transaction information is shared with potential buyers, funders, investors or advisers, we will normally do so under suitable confidentiality arrangements, where appropriate.
9. International transfers
Some of our service providers may store or process personal information outside the United Kingdom.
Where personal information is transferred outside the UK, we will take steps to ensure that appropriate safeguards are in place, such as adequacy regulations, approved contractual clauses or other lawful transfer mechanisms.
10. Criminal offence data, fraud prevention and AML checks
In limited circumstances, we may process information relating to suspected fraud, criminal offences, sanctions, anti-money laundering checks, identity verification or regulatory compliance.
We will only process this type of information where it is lawful and necessary, for example to comply with legal obligations, protect our business or clients, prevent fraud or meet regulatory requirements.
Where required, we will rely on an appropriate lawful basis and relevant condition under UK data protection law.
11. Monitoring and recording communications
We may monitor, record or retain communications, including emails, telephone calls, messages and meeting notes, where lawful and appropriate.
This may be done for:
quality assurance;
training;
record keeping;
fraud prevention;
regulatory compliance;
resolving disputes;
protecting our business, clients and third parties.
We will only do this where it is proportionate and lawful.
12. How long we keep personal information
We will only keep personal information for as long as necessary for the purposes for which it was collected.
Retention periods may vary depending on the type of information and the reason it is held.
As a general guide:
website enquiries may be kept for up to 2 years;
marketing records may be kept until you unsubscribe or object, and for a reasonable period afterwards to maintain suppression records;
client and transaction records may be kept for up to 6 years after the end of the business relationship or transaction, unless a longer period is required;
financial, accounting and tax records may be kept for the period required by law;
anti-money laundering, identity verification and fraud prevention records may be kept for the period required or permitted by law;
records relevant to disputes, complaints or legal claims may be kept for as long as necessary to deal with those matters.
When personal information is no longer required, we will delete it, anonymise it or securely archive it.
13. Keeping your information secure
We take appropriate steps to protect personal information against loss, misuse, unauthorised access, disclosure, alteration or destruction.
Security measures may include:
password protection;
restricted access to systems and documents;
secure cloud storage;
encryption where appropriate;
secure email and document management procedures;
access controls;
staff confidentiality obligations;
data breach procedures.
If a personal data breach occurs and we are required to notify you or the Information Commissioner’s Office, we will do so in accordance with applicable law.
14. Children
Our website and services are not intended for children under the age of 18.
We do not knowingly collect personal information from children through this website.
15. Your rights
Under UK data protection law, you have rights in relation to your personal information.
These may include the right to:
be informed about how your personal information is used;
access the personal information we hold about you;
ask us to correct inaccurate or incomplete information;
ask us to delete your personal information in certain circumstances;
ask us to restrict processing in certain circumstances;
object to processing based on legitimate interests;
object to direct marketing at any time;
ask for your personal information to be transferred to you or another organisation in certain circumstances;
withdraw consent where processing is based on consent;
complain to the Information Commissioner’s Office.
These rights are not absolute and may be subject to legal limitations.
To exercise your rights, please contact us at:
We may need to verify your identity before responding to your request.
16. Complaints
If you are unhappy with how we use your personal information, please contact us first so that we can try to resolve your concern.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
17. Changes to this privacy policy
We may update this privacy policy from time to time.
Any updates will be published on this website. Where appropriate, we may also notify you of significant changes by email or other suitable means.
18. Contact us
If you have any questions about this privacy policy or how we use personal information, please contact:
Grosvenor M&A
Email: admin@grosvenorcorporate.com
Address: [Insert postal address]
