Privacy Policy

Last Updated: 5 August 2026

1. Who We Are and How to Contact Us

Data Controller: M&M Finance Advisory

Website: www.mmfinanceadvisory.com

Email: mudassir@mmfinanceadvisory.com

M&M Finance Advisory (“we,” “us,” “our”) operates this website and provides financial modeling, business valuation, bookkeeping, financial reporting, tax advisory, virtual CFO support, equity research and portfolio monitoring, and related financial analysis services (collectively, “Services”).

This Privacy Policy explains what personal data we collect about you, why we collect it, how we use and protect it, who we share it with, how long we keep it, and what rights you have over it.

Please read this policy carefully. By using this website, you confirm you have read and understood it. If you do not agree, please do not use this website.

2. What Personal Data We Collect

2.1 Data You Provide to Us Directly

When you interact with us, for example by completing a contact form, booking a consultation, or engaging our Services, you may provide us with:

  • Identity data: full name
  • Contact data: email address, phone number (if provided)
  • Business data: company or business name, industry sector, jurisdiction of operation
  • Financial and project data: financial statements, transaction records, portfolio holdings, business plans, and other data needed to perform the engagement
  • Transaction data: records of Services you have purchased (payment details are handled by third-party processors or freelance platforms; we do not store full card numbers)
  • Communication data: correspondence between us, including emails, contact form submissions, and platform messages

Providing this information is voluntary. However, if you choose not to provide certain data, we may not be able to respond to your enquiry or deliver our Services.

2.2 Data Collected Automatically When You Visit Our Website

When you access our website, certain technical information may be collected automatically by us and by third-party service providers (such as Google Analytics, if enabled). This can include:

  • Device and browser data: IP address, browser type and version, operating system, device type
  • Usage data: pages visited, time spent on each page, links clicked, referring URL, exit pages
  • Location data: approximate country and city level location derived from your IP address; we do not collect precise GPS location
  • Cookie and tracking data: information stored in or accessed from cookies and similar technologies placed on your device, described in Section 5

2.3 Data Received from Third Parties

We may receive information about you from:

  • Freelance platforms (Upwork, Fiverr): profile, project history, and communication records relevant to engagements booked through those platforms
  • Google Analytics (if enabled): aggregated and anonymised website traffic statistics
  • Payment processors: transaction confirmation and fraud prevention signals; we do not receive full payment card details
  • Referral or review sources: if you leave a review or are referred to us by another client

2.4 Client Due Diligence and Anti-Money Laundering (AML) Data

Because we provide financial advisory, bookkeeping, and investment-related analytical services, certain engagements, particularly those involving equity research, portfolio monitoring, or higher-value financial modeling work, may require us to collect basic identity verification information as a matter of good professional practice, consistent with client due diligence principles under UK Money Laundering Regulations and equivalent standards recognised internationally. This may include your full legal name, proof of identity, and confirmation of the business or individual on whose behalf we are engaged.

We are not a bank, regulated financial institution, or reporting entity under these regulations, and this data is collected solely to confirm who we are working with and to meet the professional conduct standards our team follows, not for any regulatory reporting obligation on our part.

3. How We Use Your Data and Why

We use your personal data only for legitimate, clearly defined purposes. The table below sets out each purpose, the type of data involved, and the lawful basis we rely on under UK GDPR Article 6, which we apply as a general standard across all clients regardless of location.

Purpose

Type of Data

Lawful Basis

Respond to contact form submissions and enquiries

Identity, Contact, Business

Contract / Legitimate Interests

Deliver the financial services you have engaged us for

Identity, Contact, Financial, Transaction

Contract

Send administrative communications (invoices, milestone confirmations)

Identity, Contact, Transaction

Contract

Send marketing communications, only where opted in

Identity, Contact

Consent

Analyse website traffic and improve our website and content

Usage, Technical

Legitimate Interests

Detect and prevent fraud or abuse

Technical, Usage

Legitimate Interests / Legal Obligation

Comply with legal and accounting obligations (e.g., tax records)

Identity, Transaction

Legal Obligation

Exercise or defend legal claims

Any relevant data

Legitimate Interests / Legal Obligation

Where we rely on Legitimate Interests, we have assessed that our interests in operating and improving our business are not overridden by your rights. You may object to this processing; see Section 9.

Where we rely on Consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4. Cookies and Tracking Technologies

Cookies are small text files placed on your device when you visit a website, allowing it to remember your actions and preferences.

4.1 Types of Cookies We Use

Strictly Necessary Cookies: essential for the website to function (security, page loading, session continuity). No consent is required for these under UK ePrivacy Regulations.

Performance and Analytics Cookies: if enabled, we use Google Analytics to understand how visitors use our website. This data is aggregated and does not directly identify individual users.

4.2 Cookie Consent and Management

Where non-essential cookies are used, visitors will be presented with a cookie consent notice allowing them to accept all cookies, reject non-essential cookies, or manage preferences at any time. Cookies can also be managed or deleted through browser settings.

5. Who We Share Your Data With

We do not sell your personal data to third parties. We may share data in the following limited circumstances.

5.1 Service Providers (Data Processors)

Service Provider

Purpose

Location

Anthropic (Claude)

AI-assisted preparation of financial models, reports, and analysis

United States

Microsoft / Google Workspace

Document preparation, email, cloud storage

United States / EU

Freelance platforms (Upwork, Fiverr)

Contract management, messaging, payment facilitation

United States

Payment processors (as applicable)

Payment processing

United States / as applicable

Website hosting provider

Website operation

As applicable

These providers are contractually bound or bound by their own terms of service to process data only as necessary to provide services to us, and we take reasonable steps to limit how much client data is shared with any tool to what is necessary for the engagement.

5.2 Legal Requirements

We may disclose personal data without consent where required by applicable law, court order, or government authority, or to protect the rights, property, or safety of M&M Finance Advisory, our clients, or the public.

5.3 Business Transfers

In the event of a restructuring or transfer of business assets, your personal data may be transferred as part of that transaction. We will notify you if this occurs and take reasonable steps to ensure equivalent protection is maintained.

6. International Data Transfers

Our business currently operates from Pakistan, with team members and clients located across the United States, United Kingdom, UAE, Canada, and Austria. We use third-party services (including Anthropic, Google, and payment processors) whose servers may be located in the United States and other countries.

If you are located in the United Kingdom or European Economic Area, your personal data may be transferred to and processed in countries outside the UK or EEA, including the United States and Pakistan. Where we transfer personal data from the UK, we rely on the following safeguards where applicable:

  • Transfers to countries with an adequacy decision from the UK Secretary of State
  • Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreements (IDTAs) where no adequacy decision exists
  • Contractual commitments from service providers to apply an equivalent standard of protection

7. UAE Clients and Data Protection

For clients based in the United Arab Emirates, we handle personal and financial data in a manner consistent with the UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), including limiting collection to what is necessary for the engagement, applying reasonable security safeguards, and honouring requests to access, correct, or delete personal data where legally permissible.

8. How Long We Keep Your Data

Data Category

Retention Period

Reason

Contact form submissions and enquiries

2 years from last contact

Business records, follow-up

Client and project records (financial models, reports, working files)

7 years from project completion

Accounting and legal compliance

Transaction and payment records

7 years

Tax and accounting obligations

Marketing opt-in records

Duration of relationship + 3 years

Proof of consent

Website analytics data (if enabled)

26 months

Trend analysis

Legal correspondence

7 years

Legal defence and compliance

When data is no longer required, we delete it securely or anonymise it so it can no longer be linked to you.

9. Your Rights Under UK GDPR

If you are in the United Kingdom or European Economic Area, you have the following rights, subject to certain legal limitations and exemptions.

9.1 Right of Access

You may request a copy of the personal data we hold about you (a Subject Access Request). We will respond within one calendar month, extendable by two further months for complex requests.

9.2 Right to Rectification

You may request that we correct or complete inaccurate or incomplete personal data.

9.3 Right to Erasure

You may request deletion of your data where it is no longer necessary for the purpose collected, you withdraw consent with no other lawful basis, you object with no overriding legitimate grounds, or the data was unlawfully processed. This does not apply where we are required to retain data by law, such as accounting records.

9.4 Right to Restrict Processing

You may request that we suspend processing in certain circumstances, such as while accuracy is being verified.

9.5 Right to Data Portability

Where we process data by automated means on the basis of consent or contract, you may request it in a structured, machine-readable format.

9.6 Right to Object

You may object to processing based on legitimate interests at any time. We must stop unless we can demonstrate compelling legitimate grounds, or the processing is needed for legal claims. You have an absolute right to object to direct marketing.

9.7 Automated Decision-Making

We do not currently make decisions about you solely by automated means that produce legal or similarly significant effects.

9.8 How to Exercise Your Rights

Contact us at mudassir@mmfinanceadvisory.com with the subject line “Data Rights Request.” We will acknowledge your request within 72 hours and respond within one calendar month, at no charge for reasonable requests. We may need to verify your identity first.

10. Your Right to Complain to the ICO

If you are in the United Kingdom and believe we have handled your personal data in breach of UK GDPR, you may lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/, telephone 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We ask that you contact us first so we can address your concerns directly.

11. California Residents: Your Rights Under the CCPA/CPRA

This Section applies to California residents, in compliance with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

11.1 Categories of Personal Information Collected

Category

Examples

Collected

Identifiers

Name, email address, IP address

Yes

Commercial information

Service records, transaction history

Yes

Internet/network activity

Website interactions, if analytics enabled

As applicable

Geolocation data

Approximate location (country/city from IP)

As applicable

Sensitive personal information

Financial account details you provide for an engagement

Only as needed for the engagement

11.2 Your California Privacy Rights

  • Right to Know: request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third parties it is shared with.
  • Right to Delete: request deletion of personal information collected from you, subject to legal exceptions such as accounting record retention.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information: direct us to limit use of sensitive personal information to what is necessary to perform the requested Services.
  • Right to Non-Discrimination: we will not deny you services, charge different prices, or reduce service quality because you exercised your rights.

We do not sell personal information for monetary consideration and do not currently use cross-context behavioural advertising.

11.3 How to Submit a Request

Email mudassir@mmfinanceadvisory.com with subject line “California Privacy Rights Request.” We will acknowledge within 10 business days and respond within 45 calendar days.

12. Children’s Privacy

This website and our Services are not directed to, and are not intended for use by, children under 13 (or 16 for users in the UK or EEA). We do not knowingly collect personal data from children. If you believe we have inadvertently done so, contact us immediately and we will promptly delete the information upon verification.

13. Security of Your Personal Data

We implement reasonable technical and organisational measures to protect your personal data, including SSL/TLS encryption for data transmitted via our website, restricted access on a need-to-know basis, and the use of reputable third-party providers bound to maintain appropriate security standards.

No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach likely to affect your rights, we will notify affected individuals and relevant regulators (such as the ICO) without undue delay, and within 72 hours where feasible.

14. Professional Confidentiality Standards

Beyond the data protection rights described above, our ACCA qualified members, ACCA affiliates, and ACCA finalists follow the confidentiality principle set out in the ACCA Code of Ethics and Conduct, which requires that client information acquired in the course of professional work not be disclosed to third parties without proper authority, and not be used for personal advantage or the advantage of any third party. This professional confidentiality obligation applies alongside, and does not replace, the data protection rights described in this Privacy Policy.

15. Affiliate Links and Software Referral Disclosure

From time to time, we may recommend third-party accounting or financial software (such as QuickBooks or Xero) as part of our advisory work, including through an affiliate or referral arrangement where we may receive a commission if you sign up through our link, at no additional cost to you. Any such material connection will be clearly disclosed near the relevant recommendation, consistent with FTC Endorsement Guides and UK advertising disclosure requirements. Our recommendations are based on genuine professional judgement about what best fits your needs and are not influenced by the presence of a referral arrangement.

16. Links to Third-Party Websites

Our website may contain links to third-party websites or platforms. This Privacy Policy applies only to our website. We are not responsible for the privacy practices of third-party sites and encourage you to review their policies.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically. The “Last Updated” date will be revised accordingly, and for material changes we will take reasonable steps to inform you. Continued use of our website following any changes constitutes acceptance of the updated policy.

18. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy, contact us at mudassir@mmfinanceadvisory.com or via www.mmfinanceadvisory.com/contact. We aim to respond to all legitimate enquiries within one calendar month.

We are always here.