Henry & Saint-Martin

PRIVACY POLICY

Updated September 2026

1. Purpose of This Policy

This Privacy Policy explains how Henry & Saint-Martin ("we", "us", "our") collects, uses, stores and protects personal data, in line with the General Data Protection Regulation (GDPR), UK GDPR (for UK-based contacts) and applicable French and EU law.

"The Site" means our website. "You" means anyone who visits the Site, contacts us, or engages us for advisory work. This policy applies to all clients, prospective clients, corporate contacts and other individuals who engage with Henry & Saint-Martin through the Site, proposals, diagnostics, projects and communications.

Where we publish separate Terms of Use for the Site, this policy operates alongside them.


2. Who We Are

Henry & Saint-Martin is a commercial advisory practice serving founder-led and growth-stage consumer businesses in fashion, sportswear, retail, ecommerce and marketplace, principally across Europe, the UK and the Gulf. Services are delivered in three forms.

Diagnostic. A fixed-fee commercial assessment. Sprint. A fixed-fee project to fix and implement a defined commercial problem. Fractional / Transformation. Part-time senior leadership of a function or transformation.

Henry & Saint-Martin is operated by Andrew Henry and Gabriel Saint-Martin. At present the practice has no separate incorporated legal entity. Andrew Henry and Gabriel Saint-Martin act jointly as data controller for the personal data described in this policy. This will be updated if and when the practice incorporates.


3. What Personal Data We Collect

Contact and Identity. Name, email address, phone number, job title, company name and business address.

Engagement Information. Information shared during scoping calls, diagnostics, sprints or fractional work. Business, commercial and operational data provided by a client for the purposes of an engagement, which may incidentally include names or roles of the client's own staff. Working papers, analysis, findings, recommendations and deliverables we prepare.

Communications. Emails and call correspondence. Scheduling information via Calendly. Meeting notes. Call recordings only where both parties explicitly agree in advance.

Technical Data. IP address, device and browser information. Website usage data via analytics cookies.

Payment Information. Processed securely by Stripe. Full card details are never stored by us.

Business Development Data. Publicly available business contact information such as name, role, company and professional email, used to identify and approach prospective clients, gathered through our professional networks and public sources.

We do not knowingly collect any of the above about anyone under the age of 16. The Site and our services are directed at business professionals, not at children.


4. How We Collect Your Data

We collect data when you contact us via the Site or email, take part in a scoping call, diagnostic, sprint or fractional engagement, book a call through Calendly, send us emails or documents relating to an engagement, interact with our Site, are identified as a prospective client through our own business development activity, or process payments or invoices with us.


5. Why We Use Your Data

To deliver an engagement, under the performance of a contract. Scoping, running and reporting on a Diagnostic, Sprint or Fractional engagement. Preparing analysis, findings and recommendations. Coordinating meetings and workshops.

To communicate with you, under contract or legitimate interest. Scheduling, reminders and engagement materials. Follow-ups, proposals and summaries.

To operate the practice, under legitimate interest. Invoicing, accounting and contract management. Identifying and approaching prospective clients through business development. Meeting legal and regulatory obligations.

To improve our work, under legitimate interest. Reviewing engagement outcomes to refine our methodology. Using anonymised, non-identifiable learnings across engagements, never identifiable client data or information, and never without removing anything that could identify a client or their business.

With your consent. Newsletters and commercial insight content. Case studies and testimonials, agreed with you in advance. Any other marketing communications.

Consent can be withdrawn at any time.


6. Confidentiality of Engagement Information

All commercial, financial and operational information shared with us as part of an engagement is treated as confidential. It is used solely for the purposes of that engagement and is not disclosed to third parties without your agreement, except where required by law or as set out in Section 9.

Where an engagement requires us to process personal data that a client company itself controls, for example employee or organisational data reviewed as part of a diagnostic, that data remains the client's responsibility as data controller, and we act as a data processor on its behalf under the terms of the engagement contract. This policy governs the data we hold in our own right as described above. It does not replace any data processing terms agreed separately with a client.

Recordings of calls or meetings are only made with the explicit prior agreement of everyone involved.


7. How We Store Your Data

Data is stored in the following platforms: Google Workspace for email, documents and calendar, Zoom for calls, recorded only with consent, Calendly for scheduling, Stripe for payment processing, and password-protected folders and cloud storage.All systems are protected with strong passwords and two-factor authentication where available.


8. How Long We Keep Your Data

We keep data only as long as necessary. Engagement records, working papers and deliverables are kept for up to 6 years after an engagement ends. Contracts, invoices and financial records are retained in line with applicable tax and accounting law, typically 6 to 10 years depending on jurisdiction. General correspondence is kept for up to 3 years. Business development contact data is reviewed periodically and deleted or anonymised if there has been no engagement or response within approximately 24 months. Marketing consent records are kept until you unsubscribe.

You may request deletion of your data at any time, except where retention is required for legal, tax or accounting purposes.


9. Sharing Your Data

We do not sell your data and do not share it with third parties for commercial purposes.

Your data may only be shared with legal or regulatory authorities where required by law, service providers who process data on our behalf such as Google Workspace, Zoom, Calendly and Stripe under their own data protection terms, professional advisors such as an accountant or lawyer bound by confidentiality, and other stakeholders within your own organisation, only where explicitly agreed as part of the scope of an engagement, for example presenting findings to a board or sponsor.

You will always be informed when sharing is required or relevant.


10. International Data Transfers

Some of our service providers, including Google, Zoom and Stripe, may process data outside the European Economic Area and the UK. Where this happens, we rely on appropriate safeguards, including Standard Contractual Clauses or equivalent mechanisms, to ensure your data receives a comparable level of protection.

Because our clients and contacts are based across Europe, the UK and the Gulf, an engagement may itself involve transferring data across these regions. Where local law imposes additional requirements, we take reasonable steps to comply with them alongside this policy.


11. Your GDPR Rights

Under GDPR and UK GDPR, you have the right to access your personal data, correct inaccurate or incomplete data, request erasure of your data, object to processing, restrict processing, request a portable copy of your data in a structured, commonly used format, withdraw consent at any time, and lodge a complaint with a supervisory authority.

To exercise any of these rights, contact Andrew Henry or Gabriel Saint-Martin at hello@henryandsaintmartin.com, or directly at andrew@henryandsaintmartin.com or gab@henryandsaintmartin.com.

Website: www.henryandsaintmartin.com.

If you are based in France or the EU, you may also complain to the CNIL (Commission Nationale de l'Informatique et des Libertes) at www.cnil.fr. If you are based in the UK, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk.


12. Marketing and Newsletter Consent

If you sign up for our communications, you will only receive commercial insight content and updates on our work. You can unsubscribe at any time with one click.

Where we approach a prospective client directly as part of our own business development, we do so on the basis of legitimate interest, using publicly available business contact information. You can ask us to stop at any time.

Whatever your marketing preferences, we may still send administrative messages relevant to an active engagement or a material change to this policy.


13. Cookies and Website Tracking

Our Site may use cookies, small text files stored on your device, for analytics, performance tracking and to remember your preferences. Some are session cookies, which expire when you close your browser. Others are persistent and remain until they expire or you delete them. You can manage or disable cookies at any time through your browser settings. Disabling them may affect how parts of the Site function.

14. Links to Other Websites

The Site may contain links to third-party websites, including client, partner or press content. We are not responsible for the privacy practices or content of those sites. This policy applies only to data collected by us through the Site and our services. We encourage you to review the privacy policy of any third-party site before providing information to it.


15. Security Measures

We take data security seriously. Measures in place include encrypted systems and secure cloud services, two-factor authentication across platforms, password management and restricted access, and regular review of access and systems.No method of electronic storage or transmission is completely secure, so while we work to protect your data we cannot guarantee absolute security. In the event of a data breach, you will be notified as required under GDPR.


16. Third-Party Services

We use the following third-party platforms to operate the practice: Google Workspace, Zoom, Calendly and Stripe.Each provider operates under its own privacy policy. Where data is processed outside the European Economic Area or the UK, appropriate safeguards are in place, including Standard Contractual Clauses, to ensure GDPR-equivalent protection.


17. Business Transfers

If Henry & Saint-Martin incorporates, restructures, or is party to a merger, acquisition or sale of assets, your personal data may be transferred as part of that transaction. Any new owner would continue to be bound by this policy, or would notify you directly of any material change to how your data is handled.




18. Changes to This Policy

This policy may be updated from time to time. The current version will always be available on the Site with the latest revision date. Where changes are material, clients will be notified directly.


19. Contact

Henry & Saint-Martin 

Andrew Henry and Gabriel Saint-Martin 

Email: hello@henryandsaintmartin.com 

Website:www.henryandsaintmartin.com