Ada Corporate Advisory

Privacy Notice

Last updated: 10 September 2026

The short version

Ada Corporate Advisory builds research products that help acquirers, search funds and business brokers find UK companies matching their criteria — and help advisors find the buyers who are actively acquiring.

To do that we use information that is already public, mainly the Companies House register. That includes the names and roles of company directors and shareholders. If you are a director, owner or named manager of a UK company, we may hold some professional information about you, and we may share it with a customer who may then write to you to introduce themselves.

We only use professional information. We do not collect home addresses, personal mobile numbers, or anything about your health, family or private life — and nothing we produce claims to know whether you want to sell your business.

You can ask us to remove you or your company at any time, and we will, without asking you to justify it. Use the request form or email david@adacorporateadvisory.com.

1. Who we are

Ada Corporate Advisory Ltd is the controller of the personal data described in this notice.

  • Company number: 17253017, registered in England and Wales
  • Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
  • ICO registration number: registration applied for — this number will be added when it is issued
  • Contact: David Aleonte, Founder — david@adacorporateadvisory.com

We are a small company and are not required to appoint a Data Protection Officer, so we have not. Please send any privacy question or request to the address above, or use the request form.

2. If you are a director, owner or named manager of a company we research

This section applies if you are a director, shareholder or person with significant control of a UK company, or a person named on a public sector register — for example a CQC registered manager or nominated individual, or a firm's named contact on the Register of Statutory Auditors.

What we collect about you

  • Your name and your role at the company (director, shareholder, registered manager)
  • Your appointment dates and length of service
  • An age band (for example, 60–64), worked out from the month and year of birth published on the Companies House register. We do not store your date of birth — it is converted to a band before anything is written down, so we hold less than the public register does.
  • Your shareholding band as shown on the register of persons with significant control (for example, 25–50%)
  • Other UK companies you are an officer of, as shown on the register
  • A courtesy title (Mr, Mrs, Dr) where Companies House itself publishes one. We never guess a title from a first name.
  • Work contact details your company publishes — an email address or business telephone number on its own website, or a shared office mailbox such as info@ or enquiries@ at the company's domain
  • A work email address in a common format (for example, firstname@company.co.uk) at your company's own domain, which we check with an email verification service and keep only if it exists. We never present a checked address as one you have published.
  • A link to your public LinkedIn profile where one appears in ordinary web search results. We do not log in to LinkedIn and we do not copy anything from it.
  • A postal address for the company — its registered office, an address a regulator publishes against it, or one it publishes on its own website. We do not fetch or store a director's correspondence or service address.

What we do not collect

We do not collect or keep your home address, personal mobile or home telephone number, personal email address, date of birth, or any information about your health, ethnicity, religion, politics, family or private life. We do not collect information about criminal matters. We do not buy lists of people, and we do not scrape social media.

Where the information comes from

All of it is public. We use the following sources — these are where we read from, not companies we share your data with:

  • The Companies House public register — company details, officers, persons with significant control, filed accounts and filing history
  • The Gazette, the official public record, for corporate insolvency notices. We never query its personal insolvency notices.
  • Public sector registers published under the Open Government Licence or for public inspection: the Care Quality Commission, Ofsted, the Care Inspectorate (Scotland), RQIA (Northern Ireland), the Food Hygiene Rating Scheme, HMRC's Anti-Money Laundering Supervised Business Register, the Register of Statutory Auditors, and HM Land Registry's commercial property dataset
  • Your company's own website
  • Public web, news and map search results — including business directory and map listings, Google News and GDELT
  • Domain registration records for .uk domains (Nominet), and the Internet Archive
  • An email verification service, which tells us whether a work address can receive mail

Where a register lists an individual rather than an organisation — a childminder, a sole practitioner — we drop the record at import and never store it.

What we use it for

  1. To identify UK companies matching a customer's stated acquisition criteria — sector, size, location and ownership structure
  2. To score each company on measures drawn from its public record: how long the board has been in place, how ownership is structured, what has been filed and when
  3. To prepare a research file for that customer, listing the companies, the people who run them, published contact routes, and a draft introduction letter the customer can choose to send

Our research describes observable facts about a company's public record. It never states or implies that any owner intends to sell, and our files tell customers so explicitly.

The scoring is about companies, not about you personally. It produces no decision with legal or similarly significant effects on you. No file reaches a customer automatically: a person builds and releases every one, and our system refuses to release a file that fails its own quality checks unless that person deliberately overrides the refusal — an override we record.

Our lawful basis

We rely on legitimate interests (Article 6(1)(f) UK GDPR). Those interests are our own in running a business research service, our customers' in finding companies they may wish to invest in or acquire, and the wider interest in owners of private businesses being able to hear from potential buyers, which supports succession and business continuity.

We have balanced these against your rights. We took into account that the information is limited to your professional role, that most of it is published by law on the Companies House register, that we hold no home or personal contact details and no sensitive information, and that you can opt out at any time. You can ask us for a copy of our legitimate interests assessment.

Who we share it with

  • Our customers — search funds, business brokers, acquirers and corporate finance advisers who have asked us to research companies matching their criteria. Each customer receives only the companies researched for them. They use the information as independent controllers and are responsible for their own compliance, including for any contact they make with you.
  • Our service providers, who process data on our behalf under contract (see section 5)

We do not sell your information, we do not share it with consumer marketers, and we do not publish it.

How long we keep it

  • Contact details, draft messages and decision-maker records for a company we never took forward are deleted automatically 6 months after the company entered our research. This runs on a schedule, not on request, and the deletion is recorded.
  • Register-derived company records — the names, roles and age bands published on the public register — are kept while the company remains part of the universe we research, so that a repeat search does not re-fetch the same public record. We delete them when you ask us to.
  • A research file already delivered to a customer is a fixed snapshot: re-scoring and our own deletions do not rewrite it. We can withdraw a customer's access to it immediately, and we delete the snapshot itself if you ask us to.
  • If you ask us to remove you, we keep a minimal record — the company name and number — on a suppression list, so you are never picked up again. We keep that record for as long as we operate the service: deleting it is what would let you back in.

Opting out

You have the right to object to our use of your information. We honour every objection without asking you to justify it. Use the request form — if you give your company number, that company is excluded from future research immediately, before anyone here reads your message — or email david@adacorporateadvisory.com with your name and the company name or number.

3. If you are a customer, prospective customer or business contact

This section covers our research customers, and users of DealFlow AI, our software for advisors and brokers. We process:

  • Your name, job title, company, work email and telephone number
  • Your account and login details, and the criteria, searches, saved prospects and pipeline data you create in the product
  • Connected mailbox data — if you connect an email account to send outreach from DealFlow AI, the authorisation tokens for that mailbox and the messages you choose to send or read through the product. Tokens are encrypted. You can disconnect at any time.
  • Our correspondence with you, and notes of calls and meetings
  • Billing and payment records. Card payments are handled by our payment provider — we never see or store full card numbers.
  • Standard technical data generated when you use the product

Why, and on what basis: to provide the service and manage your account (contract); to keep the financial records the law requires (legal obligation); to contact business prospects about our services and to secure and improve the product (legitimate interests). Connecting a mailbox is always your choice, and asking us to stop contacting you is enough — we will.

How long: for as long as you are a customer, then six years after the relationship ends to meet accounting and legal requirements. Prospect records we no longer need are deleted within 24 months of our last contact.

If you use DealFlow AI to research and contact acquirers, you are the controller of that outreach and responsible for your own compliance with data protection and marketing law.

4. If you visit our website

Our website uses only cookies that are strictly necessary for it to work — keeping you signed in to your account or to the client portal. These do not require consent, and we do not use advertising or tracking cookies.

Our hosting provider keeps standard server logs (such as IP address, browser type and pages visited) for security and troubleshooting, for 30 days.

The privacy request form does not record your IP address. We deliberately do not log people who are exercising a privacy right.

5. Service providers and international transfers

These providers process data on our instructions only. Public registers and search engines are listed in section 2 as sources — we read from them, we do not send your data to them.

ProviderWhat they doWhere
SupabaseDatabase and authenticationIreland (eu-west-1)
VercelWebsite, portal and application hostingIreland (Dublin)
ZohoOur emailEU
ZeroBounceChecking whether a work email address existsUnited States
SerperWeb and map search resultsUnited States
Google (Gemini)Summarising a company's own website text, and drafting introduction messages for reviewUnited States
StripePayments (customers only)United States / Ireland
Google / MicrosoftMailbox connection, only if a customer chooses to connect oneUnited States / EU

Where a provider processes data outside the UK, we rely on UK adequacy — including, for certified US companies, the UK Extension to the EU-US Data Privacy Framework — or on the ICO's International Data Transfer Agreement or Addendum.

6. How we protect your information

We store data with reputable hosting providers in the UK and EU, encrypt data in transit, restrict access to the people who need it, and enforce per-customer isolation at the database level so each customer can reach only their own research files. Access to the research console is limited to named administrators, and views, exports and downloads are recorded in an append-only log.

7. Your rights

You have the right to:

  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data deleted
  • restrict how we use it
  • object to our use of it (see “Opting out” above)
  • data portability, where it applies

Use the request form or email david@adacorporateadvisory.com. We may need to confirm your identity first. We will respond within one month of receiving your request and any information we need to confirm who you are or to understand what you are asking for. If a request is complex we may extend that by up to two further months, and we will tell you why.

8. Complaints

If you are unhappy with how we have handled your information, please tell us first — use the request form and choose “Make a complaint”, or email david@adacorporateadvisory.com. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome.

You also have the right to complain to the Information Commissioner's Office at any time:

9. Changes to this notice

We update this notice when our practices change. The date at the top shows when it was last updated.