Privacy policy
Version 1.0 · Effective 25 August 2026 · Last updated 25 August 2026
This policy explains what personal data ACE X collects, why we collect it, how long we keep it and what rights you have. It covers aceexpansion.co, the Practice Value Score tool, and our work with clients and prospective clients.
We do not handle patient health data. ACE X is a management consultancy, not a healthcare provider. We do not request, receive, store or process patient medical records, clinical notes or any special-category health data. Client data we work with is commercial: revenue totals, appointment counts, marketing performance and business contact details.
1. Who we are
The data controller is Ace Consulting Enterprises LTD, trading as ACE X, a company registered in England and Wales, company number 15600309, registered office 6 Allison Bank, Geoffrey Watling Way, Norwich, England, NR1 1GW.
| Data protection contact | hadi@aceexpansion.co |
|---|---|
| Phone | +44 7538 719039 |
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the UK GDPR. Data protection enquiries go to the address above.
2. What we collect and why
2.1 Website visitors
| Data | Purpose | Lawful basis |
|---|---|---|
| IP address, browser and device type, pages viewed, referring URL | Keeping the site running, security, understanding which pages are useful | Legitimate interests — operating and improving our website |
| Advertising and analytics identifiers set by cookies | Measuring marketing performance, retargeting | Consent — see clause 5 |
2.2 Practice Value Score users
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, business email, practice name, and the business answers you give | Producing your score and revenue estimate, and sending it to you | Performance of a contract, or steps taken at your request before a contract |
| The same data, used to follow up | Telling you what the score means and whether we can help | Legitimate interests — business-to-business marketing to a business that has asked us for a diagnostic. You can opt out at any time. |
The questionnaire asks about revenue, patient-list size, no-show rates and booking systems. It does not ask for, and you must not enter, information about any identifiable patient.
2.3 Prospective clients we contact
| Data | Purpose | Lawful basis |
|---|---|---|
| Business name, business email, role, publicly available business information | Business-to-business outreach about our services | Legitimate interests — direct marketing to businesses. Assessed and documented as balanced against the recipient’s interests. |
Every outreach email identifies us, states why we are writing, and offers a way to stop hearing from us. Ask us to stop and we suppress your domain permanently.
2.4 Clients
| Data | Purpose | Lawful basis |
|---|---|---|
| Contact details of your named staff, billing details, engagement records and correspondence | Delivering the engagement, invoicing, support | Performance of a contract |
| Invoices, payment records, contracts | Accounting and tax records | Legal obligation — Companies Act 2006 and HMRC requirements |
| Your customer or patient contact lists, where you provide them for a reactivation campaign | Running the campaign you engaged us for, on your instructions | We act as your processor. You are the controller and are responsible for the lawful basis. |
Where we are your processor
When you give us a contact list to run a campaign, you decide the purpose and we act only on your written instructions. You are responsible for holding a valid lawful basis, for giving the required privacy information to those individuals, and for honouring their objections. Where required, we will sign a data processing agreement before any list is transferred.
Contact lists must contain contact details only. Do not send treatment history, clinical notes or any health information.
3. Payment data
We do not store full card numbers. Card payments are processed by our payment provider, who acts as an independent controller for the payment transaction and holds the card details under its own terms. We receive confirmation of payment, the last four digits, the amount, the currency and the date.
4. Who we share data with
We share personal data only with service providers who help us operate, each under a written contract requiring appropriate safeguards:
- website and application hosting;
- email delivery and business email;
- customer relationship and outreach tooling;
- payment processing;
- accounting and bookkeeping;
- advertising and analytics platforms, where you have consented to cookies.
We also disclose data where the law requires it, or to establish or defend legal claims. We never sell personal data.
5. Cookies and tracking
Strictly necessary cookies keep the site working and do not require consent. Analytics and advertising cookies, including the Meta (Facebook) pixel used on this site, are set only where you consent, and you can withdraw consent at any time by clearing cookies in your browser or using the controls on this site.
The Meta pixel allows us to measure which ads lead to visits and to show ads to people who have visited. Meta processes that data under its own terms as an independent or joint controller depending on the activity.
Most browsers let you block cookies. Blocking non-essential cookies does not affect your ability to use this site or to contact us.
6. International transfers
Our clients are in the United States and some of our suppliers are outside the UK. Where personal data is transferred outside the UK, we rely on one of the following: an adequacy decision made by the UK Government, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required. You can ask us which mechanism applies to a specific transfer.
7. How long we keep data
| Category | Retention |
|---|---|
| Website analytics | 26 months |
| Practice Value Score submissions | 24 months from submission, unless you become a client |
| Outreach records, including suppression lists | Suppression records are kept indefinitely, because that is how we make sure we never contact you again |
| Client engagement records and correspondence | 6 years after the engagement ends |
| Invoices and accounting records | 6 years from the end of the financial year, as required by law |
| Client-supplied contact lists | Deleted or returned within 30 days of the engagement ending, or sooner on your instruction |
8. How we protect data
Access is limited to the people who need it. Accounts use multi-factor authentication. Data is encrypted in transit. Client-supplied lists are held in access-controlled storage and deleted on the schedule above. We review these measures as the business changes.
9. Your rights
Under the UK GDPR you have the right to:
- be told what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased, where the grounds apply;
- restrict or object to processing, including an absolute right to object to direct marketing;
- receive data you gave us in a portable format;
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, email hadi@aceexpansion.co. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If we are acting as a processor for a client, we will pass your request to that client, who is the controller, and tell you we have done so.
10. Complaints
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint
11. Changes to this policy
We may update this policy. The version number and effective date at the top always show the current version. Where a change materially affects how we use your data, we will tell you directly.
Questions about this policy: hadi@aceexpansion.co or +44 7538 719039.