Privacy policy

Version 1.0 · Effective 25 August 2026 · Last updated 25 August 2026

This policy explains what personal data ACE X collects, why we collect it, how long we keep it and what rights you have. It covers aceexpansion.co, the Practice Value Score tool, and our work with clients and prospective clients.

We do not handle patient health data. ACE X is a management consultancy, not a healthcare provider. We do not request, receive, store or process patient medical records, clinical notes or any special-category health data. Client data we work with is commercial: revenue totals, appointment counts, marketing performance and business contact details.

1. Who we are

The data controller is Ace Consulting Enterprises LTD, trading as ACE X, a company registered in England and Wales, company number 15600309, registered office 6 Allison Bank, Geoffrey Watling Way, Norwich, England, NR1 1GW.

Data protection contacthadi@aceexpansion.co
Phone+44 7538 719039

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the UK GDPR. Data protection enquiries go to the address above.

2. What we collect and why

2.1 Website visitors

DataPurposeLawful basis
IP address, browser and device type, pages viewed, referring URLKeeping the site running, security, understanding which pages are usefulLegitimate interests — operating and improving our website
Advertising and analytics identifiers set by cookiesMeasuring marketing performance, retargetingConsent — see clause 5

2.2 Practice Value Score users

DataPurposeLawful basis
Name, business email, practice name, and the business answers you giveProducing your score and revenue estimate, and sending it to youPerformance of a contract, or steps taken at your request before a contract
The same data, used to follow upTelling you what the score means and whether we can helpLegitimate interests — business-to-business marketing to a business that has asked us for a diagnostic. You can opt out at any time.

The questionnaire asks about revenue, patient-list size, no-show rates and booking systems. It does not ask for, and you must not enter, information about any identifiable patient.

2.3 Prospective clients we contact

DataPurposeLawful basis
Business name, business email, role, publicly available business informationBusiness-to-business outreach about our servicesLegitimate interests — direct marketing to businesses. Assessed and documented as balanced against the recipient’s interests.

Every outreach email identifies us, states why we are writing, and offers a way to stop hearing from us. Ask us to stop and we suppress your domain permanently.

2.4 Clients

DataPurposeLawful basis
Contact details of your named staff, billing details, engagement records and correspondenceDelivering the engagement, invoicing, supportPerformance of a contract
Invoices, payment records, contractsAccounting and tax recordsLegal obligation — Companies Act 2006 and HMRC requirements
Your customer or patient contact lists, where you provide them for a reactivation campaignRunning the campaign you engaged us for, on your instructionsWe act as your processor. You are the controller and are responsible for the lawful basis.

Where we are your processor

When you give us a contact list to run a campaign, you decide the purpose and we act only on your written instructions. You are responsible for holding a valid lawful basis, for giving the required privacy information to those individuals, and for honouring their objections. Where required, we will sign a data processing agreement before any list is transferred.

Contact lists must contain contact details only. Do not send treatment history, clinical notes or any health information.

3. Payment data

We do not store full card numbers. Card payments are processed by our payment provider, who acts as an independent controller for the payment transaction and holds the card details under its own terms. We receive confirmation of payment, the last four digits, the amount, the currency and the date.

4. Who we share data with

We share personal data only with service providers who help us operate, each under a written contract requiring appropriate safeguards:

We also disclose data where the law requires it, or to establish or defend legal claims. We never sell personal data.

5. Cookies and tracking

Strictly necessary cookies keep the site working and do not require consent. Analytics and advertising cookies, including the Meta (Facebook) pixel used on this site, are set only where you consent, and you can withdraw consent at any time by clearing cookies in your browser or using the controls on this site.

The Meta pixel allows us to measure which ads lead to visits and to show ads to people who have visited. Meta processes that data under its own terms as an independent or joint controller depending on the activity.

Most browsers let you block cookies. Blocking non-essential cookies does not affect your ability to use this site or to contact us.

6. International transfers

Our clients are in the United States and some of our suppliers are outside the UK. Where personal data is transferred outside the UK, we rely on one of the following: an adequacy decision made by the UK Government, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required. You can ask us which mechanism applies to a specific transfer.

7. How long we keep data

CategoryRetention
Website analytics26 months
Practice Value Score submissions24 months from submission, unless you become a client
Outreach records, including suppression listsSuppression records are kept indefinitely, because that is how we make sure we never contact you again
Client engagement records and correspondence6 years after the engagement ends
Invoices and accounting records6 years from the end of the financial year, as required by law
Client-supplied contact listsDeleted or returned within 30 days of the engagement ending, or sooner on your instruction

8. How we protect data

Access is limited to the people who need it. Accounts use multi-factor authentication. Data is encrypted in transit. Client-supplied lists are held in access-controlled storage and deleted on the schedule above. We review these measures as the business changes.

9. Your rights

Under the UK GDPR you have the right to:

To exercise any of these, email hadi@aceexpansion.co. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If we are acting as a processor for a client, we will pass your request to that client, who is the controller, and tell you we have done so.

10. Complaints

If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint

11. Changes to this policy

We may update this policy. The version number and effective date at the top always show the current version. Where a change materially affects how we use your data, we will tell you directly.

Questions about this policy: hadi@aceexpansion.co or +44 7538 719039.