Privacy Policy

Last updated: 27 July 2026

Mou Consulting Limited ("MouCFO", "we", "us") is the controller of personal data we collect about visitors and account holders of the MouCFO platform, and processor of personal data our customers upload into the Service. This policy explains what we collect, why, on what lawful basis, who we share it with, and your rights under the UK GDPR, the Data Protection Act 2018 ("DPA 2018") and, where applicable, the EU GDPR.

1. Who we are

Mou Consulting Limited, registered in England and Wales (company number 13092399), trading as MouCFO. Contact: cfo@mouconsulting.co.uk. We are registered with the UK Information Commissioner's Office (ICO), registration number ZC142893. Our privacy contact handles data protection queries; you can reach them at the same email.

2. What we collect

Account data: name, work email, company name, role, hashed password, MFA settings. Customer Data (financial): figures you upload or sync via integrations (revenue, costs, invoices, headcount, budgets, forecasts). This is processed on behalf of your organisation. Usage & device data: pages viewed, feature usage, IP address, browser type, timestamps, error logs. Support data: messages and attachments you send us. Payment data: billing address and card metadata; full card numbers are handled by our PCI-DSS compliant payment processor and never stored on our systems. Marketing data: email address and preferences where you have opted in.

Employee & headcount data (processed on your instruction): where you use the Headcount module, your organisation may upload information about its own staff — such as name, role, department, start and leave dates, salary, employer National Insurance and pension cost. We act solely as processor for this data; your organisation is the controller and is responsible for having a lawful basis and for informing its staff. We do not use it for any purpose other than delivering the Service to you, and we ask that you do not upload special-category data (health, ethnicity, trade-union membership) or bank details into the platform.

Security & abuse-prevention data: for public forms and endpoints (lead magnets, trial signup, demo requests, invitation links) we record a truncated request IP address, the email address submitted and a request counter, so we can rate-limit abuse of our email sending and brute-force attempts against invitation links. These throttle records contain no financial data and are held only briefly (see Retention).

3. Lawful bases for processing

We rely on the following lawful bases under UK GDPR Art. 6: Contract — to provide the Service you have signed up for; Legitimate interests — to secure the Service, prevent fraud, send transactional and security notices, and improve the product (balanced against your rights); Legal obligation — to meet tax, accounting and anti-money-laundering requirements; Consent — for optional analytics cookies and marketing emails, which you can withdraw at any time.

4. How we use your data

To create and secure your account; deliver the Service and integrations you connect; generate AI commentary, budgets and board packs on your instruction; process payments; provide support; send service, security and (where opted in) product-marketing communications; detect abuse; and comply with law.

5. AI processing

When you use AI features (narratives, chatbot, budgeting, board pack generation), the relevant slice of your data is sent to a large language model provider strictly to generate a response for you. Our contracts with AI providers prohibit use of your data to train foundation models. Prompt and response logs are retained for a short period (typically up to 30 days) for debugging and abuse prevention and are then deleted. No solely automated decision-making under Art. 22 UK GDPR is performed on you personally.

6. Categories of recipients (sub-processors)

To deliver the Service we rely on a small number of carefully selected sub-processors, all bound by written data-processing agreements and, where relevant, UK International Data Transfer Addendum / Standard Contractual Clauses. We use providers in the following categories:

Cloud hosting & edge delivery · Managed database, authentication & file storage · AI model inference · Payment processing · Transactional email delivery · Product analytics (only where you consent) · Customer support tooling.

An up-to-date list of the specific providers we use, together with their locations and roles, is available on request from cfo@mouconsulting.co.uk. We will give reasonable advance notice of material changes to our sub-processors.

7. International transfers

Our primary infrastructure is in the EU/UK. Where personal data is transferred outside the UK/EEA (for example to US AI providers), we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (SCCs), or an adequacy decision, together with additional technical and organisational safeguards (encryption in transit and at rest, access controls, minimisation).

8. Sharing

We share personal data with the sub-processors listed above, with professional advisors (lawyers, auditors, accountants) under confidentiality, with tax and regulatory authorities where legally required, and with a successor entity in the event of a merger, acquisition or sale of assets (in which case you will be notified). We do not sell your personal data and do not share it for cross-context behavioural advertising.

9. Retention

Account data is retained while your account is active. After account closure we retain account records for up to 6 years to meet UK tax and company-law obligations. Customer Data you upload — including employee and headcount records — is deleted 30 days after account cancellation (unless you export it earlier). AI prompt/response logs are deleted after 30 days. Rate-limiting and abuse-prevention records (IP/email counters) are held for no more than 30 days. Email delivery logs are held for 12 months for deliverability and dispute handling. Backups roll off within 35 days. Marketing preferences are retained until you unsubscribe.

10. Your rights

Under UK GDPR you have the right to: (a) access a copy of your personal data; (b) rectify inaccurate data; (c) erasure ("right to be forgotten") where applicable; (d) restrict processing; (e) data portability; (f) object to processing based on legitimate interests or direct marketing; (g) withdraw consent at any time; and (h) not be subject to solely automated decisions with legal or similarly significant effect. To exercise any of these rights, email cfo@mouconsulting.co.uk. We will respond within one month.

11. Complaints

If you are unhappy with how we have handled your data, please contact us first — but you also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.

12. Security & breach notification

We maintain technical and organisational measures appropriate to the risk, including TLS 1.2+ in transit, AES-256 at rest, row-level security, role-based access control, MFA on privileged accounts, audit logging, secret rotation, quarterly access reviews, automated dependency & security scanning on every release, and documented incident response. In the event of a personal data breach affecting your data, we will notify you and, where required, the ICO without undue delay and within 72 hours of becoming aware, in line with Art. 33 UK GDPR.

Tenant isolation. Every record in the platform is bound to your workspace and enforced at the database layer, so one customer's data can never be read or written by another. Unauthenticated visitors have no read access to any customer table. Sensitive fields such as accounting-integration credentials are encrypted at rest with AES-256-GCM, and subscription/billing fields can only be changed by our payment provider's verified webhook — never from a browser session. Access within your own workspace is further restricted by role (owner, admin, finance, viewer), with employee salary and pension records writable only by owners and admins.

13. Children

The Service is intended for use by businesses and is not directed to individuals under 18. We do not knowingly collect personal data from children.

14. Cookies

We use strictly necessary, preference and (with consent) analytics cookies. See our Cookie Policy.

15. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or an in-app banner at least 14 days before they take effect. The "Last updated" date shows the latest revision.

16. Contact

Mou Consulting Limited (company number 13092399), United Kingdom. ICO registration ZC142893. Email cfo@mouconsulting.co.uk.