Privacy Policy

Last updated: 7 August 2026

1. About this Privacy Policy

Manx Compliance Solutions Limited (“Manx Compliance Solutions”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store and share personal data when you:

  • visit www.manxcompliancesolutions.com;

  • submit an enquiry through our website;

  • contact us by email, telephone or another communication channel;

  • discuss a potential engagement with us; or

  • become a client, supplier or professional contact.

It also explains your rights under Isle of Man data-protection law.

2. Who is responsible for your personal data?

Manx Compliance Solutions Limited is the data controller responsible for the personal data covered by this Privacy Policy.

Contact address:
15 Waterloo Road
Ramsey
Isle of Man
IM8 1DR

Email: enquiries@manxcompliance.com
Website: www.manxcompliancesolutions.com

We have not appointed a separate Data Protection Officer. Questions about this Privacy Policy or our handling of personal data should be directed to the email address above.

3. When this Privacy Policy applies

This Privacy Policy applies when Manx Compliance Solutions decides why and how personal data will be processed.

During a client engagement, we may sometimes process personal data on the instructions of a client. In those circumstances, the client will normally be the data controller and Manx Compliance Solutions will act as its data processor. The client’s privacy notice and the terms of the relevant engagement will apply to that processing.

4. Personal data we collect

The personal data we collect depends on how you interact with us.

Website and enquiry information

When you submit an enquiry or contact us, we may collect:

  • your name;

  • your business or firm name;

  • your job title or professional role;

  • your email address;

  • your telephone number;

  • the nature of the support you require;

  • relevant timescales;

  • the contents of your message; and

  • subsequent communications with you.

Please do not include unnecessary personal data, special-category information or confidential information about other people in the website enquiry form.

Client and professional information

If you engage us or discuss a potential engagement, we may also collect:

  • business and professional contact details;

  • information required to prepare proposals and engagement terms;

  • contractual and billing information;

  • identity and due-diligence information where required;

  • records of advice, meetings and correspondence;

  • information about directors, officers, employees, customers or other individuals relevant to the engagement; and

  • information needed to meet legal, regulatory, insurance or professional obligations.

Technical information

When you use the website, our website hosting and technology providers may automatically process limited technical information, including:

  • your Internet Protocol address;

  • browser and device type;

  • operating system;

  • pages visited and the time of access;

  • referring website or page;

  • website performance information; and

  • security and diagnostic records.

This information is primarily used to deliver the website, maintain security, diagnose faults and understand general website usage.

5. How we obtain personal data

We may receive personal data:

  • directly from you;

  • through the website enquiry form;

  • during telephone calls, meetings and email correspondence;

  • from the business or organisation you represent;

  • from clients, professional advisers or referral partners;

  • from publicly available sources, such as company, professional or regulatory registers; and

  • from website, email, hosting and IT service providers.

Where you provide personal data about another person, you should ensure that you are entitled to provide it and, where appropriate, that the individual has received relevant information about its use.

6. How and why we use personal data

We may use personal data to:

  • receive, assess and respond to enquiries;

  • arrange confidential initial discussions;

  • understand the nature of the support required;

  • prepare proposals, engagement terms and service agreements;

  • provide compliance, governance, risk and regulatory support;

  • communicate with clients and professional contacts;

  • manage client relationships and ongoing engagements;

  • maintain appropriate business, regulatory and financial records;

  • establish, exercise or defend legal claims;

  • protect the website and our systems against misuse, fraud and security threats;

  • comply with applicable legal and regulatory obligations; and

  • improve the operation, security and effectiveness of our website and services.

We will not use personal data for a purpose that is incompatible with the purpose for which it was collected unless permitted or required by law.

7. Our lawful bases for processing

We rely on one or more of the following lawful bases:

Steps before entering into a contract and performance of a contract

We may process personal data where this is necessary to respond to a request, prepare an engagement or provide agreed services.

Where our client is a company or other organisation rather than an individual, we will generally rely on our legitimate interests in establishing and managing that business relationship.

Legitimate interests

We may process personal data where necessary for our legitimate business interests, including:

  • responding to business enquiries;

  • developing and managing professional relationships;

  • operating and protecting our website and systems;

  • administering the business;

  • maintaining appropriate records;

  • improving our services; and

  • protecting our legal rights.

We consider whether those interests are proportionate and whether they could unfairly affect your rights.

Legal obligations

We may process personal data where necessary to comply with applicable legal, regulatory, accounting, tax, reporting or record-keeping obligations.

Legal claims

We may retain or use relevant personal data where necessary to establish, exercise or defend legal claims.

Consent

We will rely on consent where the law requires it, including for certain non-essential cookies or optional communications. You may withdraw your consent at any time. Withdrawal will not affect processing that took place before consent was withdrawn.

8. Special-category and criminal-offence data

We do not ask visitors to submit special-category data or criminal-offence information through the website enquiry form.

Such information may occasionally be relevant to a client engagement. Where it is necessary for us to process this information, we will do so only where an appropriate legal basis and additional condition apply, and with suitable safeguards.

9. Who we share personal data with

We may share personal data, where reasonably necessary, with:

  • website hosting and form-delivery providers;

  • email, cloud storage, communications and IT-support providers;

  • professional advisers, including legal advisers, accountants and insurers;

  • contractors or specialist consultants supporting an authorised engagement;

  • regulators, government bodies, courts, law-enforcement agencies or other authorities where disclosure is required or permitted by law

Relevant authorities may include the Isle of Man Financial Services Authority, Gambling Supervision Commission and Financial Intelligence Unit where disclosure is legally required or appropriate.

Service providers are permitted to process personal data only for authorised purposes and are expected to protect it appropriately.

We do not sell or rent personal data.

10. International transfers

Some website, email, cloud or technology providers may process personal data outside the Isle of Man.

Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we will take reasonable steps to ensure that an appropriate transfer mechanism and safeguards are in place. These may include approved contractual protections or another mechanism permitted by Isle of Man data-protection law.

11. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, contractual, insurance and accounting requirements.

Our usual retention periods are:

  • General enquiries that do not become client engagements: up to 24 months after the last meaningful communication.

  • Prospective-client information that results in an engagement: transferred to the relevant client file.

  • Client engagement, advice and contractual records: normally six years after the engagement or client relationship ends.

  • Financial and accounting records: retained for the applicable statutory period.

  • Website security and diagnostic records: retained for the period reasonably required for security, fault investigation and service operation.

  • Records relevant to a complaint, investigation or legal claim: retained until the matter and any applicable limitation or review period have concluded.

Information may be retained for longer where required by law or where reasonably necessary for regulatory enquiries, legal proceedings or the protection of legal rights.

When personal data is no longer required, it will be securely deleted, anonymised or otherwise placed beyond use.

12. Cookies and similar technologies

The website may use cookies or similar technologies that are necessary for its operation, security and functionality.

If non-essential analytics, advertising or other optional technologies are enabled, they should be activated only after any consent required by law has been obtained. You can manage optional cookies through the website’s cookie controls, where available, or through your browser settings.

Blocking essential cookies may affect how parts of the website operate.

13. Information security

We use proportionate administrative, technical and organisational measures designed to protect personal data against:

  • unauthorised access;

  • accidental loss;

  • improper use or disclosure;

  • alteration; and

  • destruction.

Access is limited to people and service providers who have a legitimate need to use the information.

Although we take reasonable precautions, no website, email system or internet transmission can be guaranteed to be completely secure. Please avoid sending particularly sensitive or confidential information through the general website enquiry form.

14. Your data-protection rights

Depending on the circumstances and subject to applicable exceptions, you may have the right to:

  • be informed about how your personal data is used;

  • request access to the personal data we hold about you;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase personal data where there is no lawful reason to retain it;

  • ask us to restrict the use of your personal data;

  • object to processing based on legitimate interests;

  • receive certain information in a portable format;

  • withdraw consent where processing is based on consent; and

  • challenge certain decisions made solely by automated means.

These rights are not absolute and may not apply in every situation. For example, we may need to retain information to comply with a legal obligation or to establish, exercise or defend legal claims.

We do not use personal data to make decisions about individuals based solely on automated processing or profiling.

15. Exercising your rights

To exercise a data-protection right, contact:

Email: enquiries@manxcompliance.com

Please describe your request clearly. We may ask for information necessary to confirm your identity and ensure that personal data is not disclosed to an unauthorised person.

We will normally respond within one month. Where a request is particularly complex or several requests are made, the law may permit additional time. We will tell you if this applies.

There is normally no charge for exercising your rights. A reasonable fee may be charged, or a request may be refused, where permitted by law—for example, if a request is manifestly unfounded or excessive.

16. Complaints

Please contact us first if you have concerns about how your personal data has been handled. We will review the matter and attempt to resolve it promptly.

You also have the right to complain to the Isle of Man Information Commissioner:

Isle of Man Information Commissioner
P.O. Box 69
Douglas
Isle of Man
IM99 1EQ

Telephone: +44 (0)1624 693260
Email: ask@inforights.im
Website: www.inforights.im

17. Links to other websites

Our website may contain links to websites operated by other organisations. We are not responsible for their content, security or privacy practices.

You should read the privacy information provided by any external website before submitting personal data to it.

18. Children’s personal data

Our website and services are intended for businesses and professional users. They are not directed at children, and we do not knowingly collect personal data from children through the website.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our services, technology, suppliers, legal obligations or data-handling practices.

The latest version will be published on this page with its updated date. Material changes may also be communicated through another appropriate method.

20. Contact us

For questions about this Privacy Policy or the way we handle personal data, contact:

Manx Compliance Solutions Limited
15 Waterloo Road
Ramsey
Isle of Man
IM8 1DR

Email: enquiries@manxcompliance.com