Privacy Policy

Effective date: 2 September 2026


Who we are

The data controller is Clifton House Consulting Limited, trading as PelicanCFO. Registered in England and Wales. Company number 12506901.

For all data protection queries and subject access requests, contact us at hello@pelicancfo.com.

The two kinds of data on this site

PelicanCFO does two different things, and they involve different data. This policy keeps them separate.

General enquiries and scoping calls. What you send when you contact us about a Finance Health Check, ongoing CFO support, or any other finance question. This is described in the next section.

Interview Rehearsal session data. What is collected when a candidate buys and completes a rehearsal session. This is described further down and is handled separately.

Booking a scoping call is a third route. It happens on Cal.com rather than on this website, and is covered under third-party services below.

General enquiries and scoping calls

If you use the enquiry form on our contact page, we ask for your name, your email address, and what you would like help with. You may also choose to give your company, your role, an approximate annual revenue band, a phone number, and anything else you want to tell us. Only the first three are required, and the rest are optional.

We use this information to respond to your enquiry, to arrange a scoping call or Interview Rehearsal contact where that is relevant, to understand what you are asking about, and to keep a basic record of the correspondence where that is reasonably necessary.

We do not use enquiry data for profiling, automated decision-making, advertising, remarketing or mailing lists. We do not add you to a newsletter. There is no marketing sequence to opt out of.

Where you contact us about potentially engaging PelicanCFO, we process the information you provide where necessary to take steps at your request before entering into a contract. For other general enquiries, we may rely on our legitimate interest in responding to people who contact us and maintaining appropriate business correspondence.

You can also simply email hello@pelicancfo.com instead of using the form. The same uses apply.

Please do not send confidential financial information through the enquiry form. Management accounts, bank statements, detailed financial records and similar confidential documents should only be provided once scope and handling arrangements have been agreed. The form is for making contact, not for sharing your numbers.

How the enquiry form works

The enquiry form is built with Netlify Forms. When you submit it, your answers are sent to and stored by Netlify, our hosting provider, and we retrieve them from there in order to reply. Netlify processes the submission as part of providing that service.

The form also uses a hidden field to catch automated spam submissions. It collects nothing about you.

We have not published a fixed deletion schedule for form submissions held by Netlify, so we do not claim one here. Where you ask us to delete an enquiry, we will remove it from the submission store and from our own records, subject to anything we are required to keep.

Data handling in an engagement

This section describes how we handle client information once work is actually under way, as distinct from a first enquiry.

Client data is used only for the agreed engagement. Only authorised PelicanCFO personnel see client information.

No client-identifiable data is used in marketing without written approval, and no client data is used in public demonstrations. Any anonymised learning or benchmarking use requires appropriate engagement terms.

Live bank statement upload is not a feature of this website. Where financial records are needed for a piece of work, the scope, the format and the handling arrangements are agreed with you first.

Interview Rehearsal session data

The rest of this policy describes Interview Rehearsal, PelicanCFO's separate service for finance candidates. If you have only sent us an enquiry, the sections above are the ones that apply to you.

We collect the following categories of personal data:

Account and session data. When you purchase a session, we collect your name, email address, and payment reference. This data is used to manage your account, deliver your session, and send you session output by email where applicable. The legal basis is contract performance.

Pre-session questionnaire data. Before your session begins, we ask you to provide information about your current role, target role, and company type. This data is used to calibrate your session. It is stored in Supabase and associated with your session record. The legal basis is contract performance.

Session interaction data. We collect your responses to session scenarios, either as voice recordings or written text depending on the format you choose. Voice recordings are transcribed using the OpenAI Whisper API. The transcript is used to generate your session feedback. The legal basis is contract performance.

Session metadata. We collect anonymised metadata about each session including role level, scenario type, approximate answer length, whether a retry was taken, and closing observation theme. This data is used to improve the product. It is anonymised before any aggregate analysis. The legal basis is legitimate interests. We consider this processing proportionate because the analysis is performed on anonymised or aggregated session-level patterns rather than identifiable candidate profiles.

Voice recordings and transcripts

If you choose to submit spoken answers during your session, your voice is recorded in your browser and sent to the OpenAI Whisper API for transcription. The transcript is then used by our AI feedback system to generate your session feedback.

Voice recordings are deleted as soon as transcription processing is complete. We do not store audio files beyond the transcription step.

Transcripts are normally deleted within 30 days of your session completing.

No voice recording, transcript, or session feedback output is used to train AI models without your explicit informed consent. We will always ask separately and specifically before using any session content for model training purposes.

Payment data

Payments are processed by Stripe. We do not store your full card details. Stripe processes and stores payment information in accordance with PCI DSS standards. You can read Stripe's privacy policy at stripe.com/gb/privacy.

We retain a record of your transaction reference, the amount paid, and the date of payment for our accounting and legal obligations. The legal basis is legal obligation.

How long we keep your data

Enquiry data is kept only for as long as is reasonably necessary for the purpose it was provided: answering your enquiry, any resulting conversation or engagement, and any legal or accounting obligation that applies to it. Enquiries that do not lead anywhere are not kept indefinitely.

Account and payment data is retained for seven years from the date of transaction to comply with UK financial record-keeping requirements.

Pre-session questionnaire data is retained for the duration of your account and normally deleted on request unless retention is required for legal or security reasons.

Voice recordings are deleted as soon as transcription processing is complete. Transcripts are normally deleted within 30 days of your session completing.

Anonymised session metadata is retained indefinitely for product improvement purposes. Because it is anonymised, it cannot be linked back to you as an individual.

Your rights under UK GDPR

Under UK data protection law, you have the following rights:

The right to access. You can request a copy of the personal data we hold about you.

The right to rectification. You can ask us to correct personal data that is inaccurate or incomplete.

The right to erasure. You can ask us to delete your personal data where we no longer have a lawful basis to hold it. Note that we are required to retain certain financial records for seven years regardless of erasure requests.

The right to restrict processing. You can ask us to pause processing of your personal data in certain circumstances.

The right to data portability. You can ask us to provide your personal data in a structured, commonly used, machine-readable format.

The right to object. You can object to processing based on legitimate interests.

To exercise any of these rights, contact us at hello@pelicancfo.com. We will respond within one calendar month.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.

Third-party services

PelicanCFO uses the following third-party services to operate the website and the product. Netlify handles the enquiry form, Cal.com handles scoping-call scheduling and Plausible provides website analytics; the remainder relate to Interview Rehearsal.

Plausible. Used for privacy-friendly website analytics, so we can see which pages are read and which calls to action are used. Plausible does not set analytics cookies and does not track visitors across other websites. We do not use it for advertising, and we do not send it anything you type into the enquiry form.

Cal.com. Used to schedule PelicanCFO scoping calls. When you choose to book a call you leave this website and use Cal.com's own booking service. Cal.com processes the information you enter into its booking form and the meeting details needed to arrange the booking.

OpenAI Whisper API. Used for voice transcription. Audio submitted to Whisper is processed in accordance with OpenAI's data handling terms. We have configured this service to minimise data retention consistent with OpenAI's API data policies.

Anthropic Claude API. Used to generate session feedback. Transcripts submitted to the Claude API are processed in accordance with Anthropic's API data usage policies. API data submitted by business customers is not used to train Anthropic's models by default.

Supabase. Used to store session data, account information, and session metadata. Data is stored using infrastructure configured for UK or EU data residency where available. Supabase operates under standard contractual clauses for international data transfers where applicable.

Stripe. Used for payment processing. Stripe is PCI DSS compliant. We do not pass full card details to Stripe from our servers - payment is handled directly by Stripe's secure payment interface.

Netlify. Used for website hosting and content delivery, and to receive and store submissions from the enquiry form. Netlify may process IP addresses and basic request data as part of standard hosting and delivery.

Cookies

This website does not set any cookies. We do not use advertising cookies, tracking cookies, or third-party analytics cookies, and there are no operational or session cookies on the public site. Our website analytics are provided by Plausible, which does not use cookies, so there is no analytics cookie to consent to.

If and when the Interview Rehearsal service is running, it may use strictly necessary cookies to maintain your session state while you are signed in and taking a session. Those would be operational only, and this policy will be updated to describe them before they are used.

You can control cookies through your browser settings.

Changes to this policy

We will update this policy when our data practices change in a material way. The effective date at the top of the page will be updated whenever the policy is revised. For significant changes that affect how we handle your personal data, we will notify you by email where we hold your email address.

Contact

For any questions about this privacy policy or your personal data, contact us at hello@pelicancfo.com.

Clifton House Consulting Limited. Registered in England and Wales. Company number 12506901.