PRIVACY NOTICE

How we handle your personal data

Aice Limited (Company No. 14726496) trading as GoZtartUp. Last updated 25 June 2026.

This notice explains how Aice Limited, trading as GoZtartUp, collects, uses, and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have written this in plain language. If anything is unclear, contact [email protected].

1. Who we are

GoZtartUp is the trading name of Aice Limited, a company registered in England and Wales (Company No. 14726496), with its registered office at 335 Manchester Road East, Little Hulton, Manchester M38 9AR.

We are a done-for-you business launch consultancy that helps healthcare and childcare professionals in the UK transition from employment to owning a regulator-ready business. We build and submit CQC or Ofsted applications within a structured 16-week delivery window.

For the purposes of UK data protection law, Aice Limited is the data controller of your personal data. This means we decide how and why your personal data is processed.

Data ControllerAice Limited trading as GoZtartUp
Company Number14726496
Registered Office335 Manchester Road East, Little Hulton, Manchester M38 9AR
Data Protection LeadAkinlolu Adeojo (Sole Director)
Contact[email protected]
ICO Registration808634

We have not appointed a statutory Data Protection Officer as we are not required to under UK GDPR Article 37. The Director acts as our internal Data Protection Lead. Direct any data protection queries to [email protected].

2. What this notice covers

This notice applies when you:

  • Visit our website (www.goztartup.com or mygoztartup.com)
  • Make an enquiry, complete an eligibility application, or book a discovery call
  • Enter into a Service Agreement with us for the Regulated Care and Childcare Business Launch Package
  • Provide us with personal documents (identification, proof of address, DBS information, qualifications) as part of your regulatory application
  • Make payments through our payment provider
  • Receive marketing communications from us
  • Interact with our Partnership Programme as a referral source or prospect

This notice is provided under UK GDPR Articles 13 and 14, which require us to give you clear information about how we process your personal data at the time we collect it from you.

3. What personal data we collect

The personal data we collect depends on how you interact with us.

CategoryExamplesWhen collected
Identity dataFull name, date of birth, nationality, copies of passport or driving licence, photographWhen you sign up for our service or book a call
Contact dataPostal address, email, phone, WhatsAppWhen you enquire, sign up, or communicate
Professional dataQualifications, employment history, professional registrations (NMC, HCPC), training recordsDuring onboarding for your regulatory application
Financial dataPayment card details (processed by Stripe, we do not see or store your full card number), bank details for refunds, instalment payment recordsWhen you make a payment or set up an instalment plan
Application dataBusiness model details, premises information, staffing plans, governance documents, policies and procedures for your CQC or Ofsted applicationThroughout the 16-week delivery process
DBS dataDBS certificate reference number, type of check, outcome summary. We do not retain your full DBS certificate.When you provide DBS information for your application
Health data (limited)Only where you voluntarily disclose health information relevant to your fitness as a registered manager. We do not routinely request health data.Only if you choose to disclose
Marketing dataName, email, phone, how you heard about us, consent preferences, communication historyWhen you engage with our content or forms
Technical dataIP address, browser, device type, pages visited, time spent, referring URLAutomatically when you visit our website, subject to your cookie preferences

We only collect personal data that is necessary for the purpose for which it is collected. We do not collect personal data "just in case".

4. How we collect your personal data

4.1 Directly from you

  • When you complete our onboarding questionnaire or provide documents
  • When you book a discovery or eligibility call through our calendar booking system
  • When you sign a Service Agreement
  • When you communicate with us by email, phone, or WhatsApp
  • When you make a payment via Stripe
  • When you engage with our social media content or community

4.2 Automatically from your devices

When you visit our website, we may collect technical data using cookies and similar technologies, subject to your consent for non-essential cookies. See Section 14.

4.3 From third parties

Referral partners in our Partnership Programme may provide us with your name and contact details (with your knowledge) so we can contact you about our services. Where your contact details are obtained from publicly available professional directories, we will tell you how we obtained your details when we first contact you.

Where we obtain your personal data from a source other than you, we will tell you within a reasonable period and no later than one month, or at the point of first communication with you, whichever is earlier (UK GDPR Article 14).

5. Why we process your personal data and our lawful bases

We only process your personal data where we have a lawful reason to do so. UK GDPR Article 6 sets out six lawful bases for processing. The table below explains what we use your data for and which lawful basis applies.

What we use your data forLawful basisMore detail
Delivering the 16-week build-and-submit serviceContract (Art.6(1)(b))Processing is necessary to perform the Service Agreement
Collecting your identity documents and onboarding informationContractWe need this to prepare your regulatory application
Preparing and submitting your CQC or Ofsted applicationContractThe core service we are contracted to provide
Processing your DBS informationContract + DPA 2018 Sch.1 Pt.1 Para.1Necessary for your application. DBS data has extra legal protection, see Section 6
Taking your payments and managing instalmentsContractNecessary to collect fees under your Service Agreement. Payments are processed by Stripe, see Section 8
Providing post-registration launch supportContractIncluded in your Service Agreement for 4 to 8 weeks after registration
Handling complaints and resolving disputesLegitimate interests (Art.6(1)(f))Our interest: investigating and resolving complaints fairly. Your interest: having your complaint properly addressed
Defending or pursuing legal claimsLegitimate interestsEstablishing, exercising, or defending legal claims, including PI insurance notifications
Sending you marketing communicationsConsent (Art.6(1)(a)) or Legitimate interests with PECR soft opt-inFor new prospects: your consent. For existing clients: PECR soft opt-in to market similar services. See Section 13
Website analytics and improvementConsent for non-essential cookiesNon-essential cookies (analytics, advertising) only placed with your prior consent. See Section 14
Keeping financial and accounting recordsLegal obligation (Art.6(1)(c))Required under Companies Act 2006 ss.386-389 and for HMRC tax purposes
Reporting to the ICO on a data breachLegal obligationRequired under UK GDPR Article 33

What "legitimate interests" means

Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests do not override your rights and freedoms. We have documented these assessments internally. You have the right to object to processing based on legitimate interests at any time, see Section 11.

6. Special category and criminal offence data

Some types of personal data have extra legal protection because they are more sensitive. These include health information and criminal record data such as DBS checks.

6.1 DBS (criminal record) data

If you are applying for CQC or Ofsted registration, you may need to provide DBS check information.

  • Lawful basis: Art.6(1)(b) (contract performance)
  • Additional condition: DPA 2018, Schedule 1, Part 1, Paragraph 1 (employment, health, social care)

How we handle your DBS data: we only record the DBS certificate reference number, the type of check, and the outcome summary. We do not retain your full DBS certificate. Once your regulatory application has been submitted, any copy of your DBS certificate in our possession will be securely destroyed within six months, in line with the DBS Code of Practice.

6.2 Health data

We do not routinely collect health data. However, you may voluntarily disclose health information relevant to your fitness as a registered manager (for example, if the regulator requires a declaration about your health). Where you do disclose health data, we process it under Art.9(2)(b) (employment and social protection obligations) combined with DPA 2018, Schedule 1, Part 1, Paragraph 1. We will only use this data for the specific purpose of your regulatory application and will not share it with anyone other than the regulator, unless required by law.

6.3 Consequences of not providing your data

You are not legally required to provide us with personal data. However, if you choose not to provide certain information (for example, your identity documents, DBS information, or professional qualifications), we may not be able to deliver our service or submit your regulatory application. We will always explain what information is essential and why before you provide it.

7. Who we share your personal data with

We do not sell your personal data to anyone. We only share your data where necessary to deliver our service, comply with the law, or protect our legitimate interests.

RecipientWhy we shareTheir role
CQC or OfstedTo submit your regulatory applicationIndependent controller (own privacy policies)
Companies HouseWhere we assist with company formation, director and PSC details are filed as required by lawPublic register (legal requirement)
StripeTo process your card payments securelyProcessor (PCI-DSS compliant)
GoHighLevel (GHL)To host our marketing funnel, manage form submissions, schedule eligibility calls, and run automated communicationsProcessor under Art.28 DPA
Assembly.comTo manage your client record, communications, and delivery milestonesProcessor under Art.28 DPA
Mailcow / hosting providerTo send and receive email communicationsProcessor (hosting provider)
n8nTo send automated notifications and follow-upsProcessor under Art.28 DPA
NetlifyTo host our website infrastructureProcessor under Art.28 DPA
External accountantTo maintain accounts and tax recordsProcessor under Art.28 DPA
PI insurer (Markel)To notify circumstances or claims under our PI policyIndependent controller for claims
HMRCTo comply with tax obligationsPublic authority (independent controller)
ICOTo report personal data breaches where requiredSupervisory authority

Where we use processors (organisations that process your data on our behalf), we have written data processing agreements in place that require them to process your data only on our instructions, keep it confidential, and implement appropriate security measures. This is required by UK GDPR Article 28.

8. Payment provider

Stripe (card payments)

When you pay by card, your payment is processed by Stripe. We pass Stripe your name, email, and transaction amount. Your card details are entered directly into Stripe's PCI-DSS compliant environment. We do not see, store, or have access to your full card number.

Stripe has certified under the EU-US Data Privacy Framework (including the UK extension) and uses the UK International Data Transfer Addendum for transfers outside the UK. Read Stripe's privacy policy at stripe.com/privacy.

What GoZtartUp does not do with your financial data: we do not assess your creditworthiness, we do not recommend or advise on financial products, we do not store your payment card details, and we are not authorised or regulated by the Financial Conduct Authority (FCA).

9. International transfers

Your personal data is primarily stored and processed in the United Kingdom. However, some of our technology providers may store or process data outside the UK (for example, Stripe processes data in the United States).

Where your data is transferred outside the UK, we ensure that:

  • The destination country benefits from a UK adequacy decision, or
  • The transfer is covered by appropriate safeguards such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), or
  • The recipient participates in the EU-US Data Privacy Framework (as extended to the UK)

We carry out transfer risk assessments for each international transfer. The EU renewed the UK's adequacy status through to December 2031, confirming that data flows between the EU and UK remain protected. Contact [email protected] for further details about safeguards in place for any specific international transfer.

10. How long we keep your personal data

We keep your personal data only for as long as we need it for the purpose for which it was collected, or as required by law. We do not keep data indefinitely.

Data categoryRetention periodReason
Client files (active engagement)Duration of engagement + 6 yearsLimitation Act 1980 (6-year claim period); PI insurance run-off
Completed client files6 years from completionSame as above
DBS reference recordsDestroyed within 6 months of application submissionDBS Code of Practice; data minimisation
Marketing or prospect data24 months from last engagement, or until you withdraw consentData minimisation
Financial and accounting records6 years from end of the relevant financial yearCompanies Act 2006; HMRC
Website analytics dataUp to 26 monthsAligned with analytics provider settings
Complaints and dispute records6 years from resolutionDefence of legal claims under Limitation Act 1980

When the retention period expires, we securely delete or anonymise your personal data. Electronic data is permanently erased. Physical documents are cross-cut shredded.

11. Your rights under UK GDPR

You have the following rights over your personal data. These rights are not absolute. There are situations where we may lawfully decline a request (for example, if we need to keep data to comply with a legal obligation or defend a legal claim). Where we decline, we will explain why.

Your rightWhat it means
Right to be informedYou have the right to know how we use your data. This notice fulfils this right.
Right of access (DSAR)You can ask for a copy of all the personal data we hold about you. We respond within 1 calendar month. Free of charge.
Right to rectificationYou can ask us to correct inaccurate or incomplete data.
Right to erasureYou can ask us to delete your data in certain circumstances. We may not erase data needed for legal claims or statutory records.
Right to restrict processingYou can ask us to temporarily stop processing your data, for example, while we verify accuracy.
Right to data portabilityYou can ask for your data in a portable format. Applies where processing is based on consent or contract and carried out by automated means.
Right to objectYou can object to processing based on legitimate interests. We will stop unless we have compelling grounds. You can always object to direct marketing.
Right to withdraw consentWhere we rely on consent, you can withdraw it at any time. Withdrawal does not affect lawfulness of processing before withdrawal.

12. How to exercise your rights

Contact us by email at [email protected] or by post at Aice Limited, 335 Manchester Road East, Little Hulton, Manchester M38 9AR. Use the subject line "Data Protection Request" followed by your name. You do not need to fill in a special form.

We may need to verify your identity before responding, to protect your data from being disclosed to someone else. We will respond within one calendar month. If your request is complex, we may extend by up to two further months, but we will tell you within the first month.

There is no charge for exercising your data rights.

13. Marketing communications and your choices

We may send you information about our services, including educational content about regulatory compliance and business ownership. We only send marketing where we have a lawful basis.

13.1 When we need your consent

Under the Privacy and Electronic Communications Regulations 2003 (PECR), we need your consent to send you electronic marketing messages (email, SMS, WhatsApp) unless the soft opt-in exception applies. We will always:

  • Clearly ask for your consent before adding you to our marketing list
  • Tell you what types of communications you will receive
  • Make it as easy to unsubscribe as it was to subscribe
  • Never use pre-ticked boxes or assume you want to receive marketing

13.2 The soft opt-in (existing clients)

If you are an existing client and we obtained your email during the course of providing our service, we may use the PECR soft opt-in to send you marketing about similar services. This only applies where: we obtained your contact details in the context of a sale or negotiations for a sale, we are marketing our own similar products or services, and we gave you a clear opportunity to opt out when we collected your details and in every subsequent message.

13.3 How to opt out

  • Click the "unsubscribe" link in any marketing email
  • Reply "STOP" to any WhatsApp marketing message
  • Email [email protected] with the subject "Opt Out"

We will process your opt-out without delay. Opting out of marketing will not affect service-related communications needed to deliver your contracted service.

14. Cookies and website tracking

Our website uses cookies and similar technologies. See our Cookie Policy for full details.

Cookie typePurposeConsent required?
Strictly necessaryEssential for the website to function (session management, security)No, exempt under PECR Regulation 6
AnalyticsHelp us understand how visitors use our websiteYes, consent via cookie banner
Marketing or advertisingTrack visitors across websites to display relevant advertisementsYes, only placed with your prior consent

You can change your cookie preferences at any time through our cookie banner or by adjusting your browser settings. Refusing non-essential cookies will not prevent you from using our website.

15. Automated decision-making

UK GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you.

Our position: GoZtartUp does not use automated decision-making or profiling that produces legal or significant effects on you. All material decisions about your application, service delivery, and account are made by our team with human oversight. We do not use algorithms to determine your eligibility, pricing, or service outcomes.

16. Data security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or damage. Our measures include:

  • Role-based access controls (only authorised team members can access your data)
  • Multi-factor authentication (MFA) on all critical systems (CRM, email, payments)
  • Encryption in transit (HTTPS/TLS) for all web-based communications
  • Full-disk encryption on all devices that access your data
  • Up-to-date anti-malware protection and operating systems
  • Password management using a password manager with minimum 12-character passwords
  • Secure disposal of data when retention periods expire
  • No client personal data is input into AI tools unless the tool is approved and a data processing agreement is in place

While we take all reasonable steps to protect your data, no method of transmission or storage is 100% secure. If you become aware of any security concern, contact us immediately at [email protected].

17. Children's data

Our services are designed for adults who are healthcare and childcare professionals. We do not knowingly collect or process personal data from children (individuals under the age of 18). If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly and securely.

18. Changes to this privacy notice

We may update this Privacy Notice from time to time. Where we make material changes, we will:

  • Update the date at the top of this notice
  • Notify you directly (for example, by email) if the change significantly affects how we use your data
  • Publish the updated notice on our website

This notice was last updated on 25 June 2026.

19. Limitation of liability

This Privacy Notice is provided for transparency and to meet our obligations under UK GDPR Articles 13 and 14. It does not create any contractual rights beyond those in your Service Agreement.

  • Aice Limited's aggregate liability to any client in respect of all claims (including data protection claims) arising from a Service Agreement shall not exceed the total fees paid or payable under that agreement
  • We exclude liability for indirect, consequential, and special losses, including loss of profits, revenue, or business opportunity, to the maximum extent permitted by law
  • Nothing in this notice or the Service Agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited by law
  • Under UK GDPR Article 82, you have the right to claim compensation for material or non-material damage caused by a breach of UK GDPR. This statutory right cannot be excluded by contract.

20. Governing law

This Privacy Notice, and any dispute or claim arising from or in connection with it, shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction.

Your data protection rights under UK GDPR are not affected by this governing law clause. You always have the right to lodge a complaint with the ICO regardless of any contractual provisions.

21. How to contact us

If you have any questions about this Privacy Notice or how we handle your personal data:

Data ControllerAice Limited trading as GoZtartUp
Data Protection LeadAkinlolu Adeojo
Email[email protected]
Post335 Manchester Road East, Little Hulton, Manchester M38 9AR

22. How to complain

If you are unhappy with how we have handled your personal data, contact us first so we can try to resolve the issue directly. You also have the right to complain to the Information Commissioner's Office (ICO) at any time.

ICO Websiteico.org.uk
ICO Helpline0303 123 1113
ICO AddressInformation Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

You may also have the right to seek a judicial remedy through the courts if you believe your data protection rights have been infringed.

GoZtartUp
THE PROPER WAY FORWARD

GoZtartUp is a trading name of Aice Limited, a company registered in England and Wales, Company No. 14726496, registered office 335 Manchester Road East, Little Hulton, Manchester M38 9AR. GoZtartUp provides business education and compliance document preparation only. We are not affiliated with, endorsed by, or acting on behalf of the Care Quality Commission or Ofsted. We are not authorised by the SRA, OISC or FCA, and we do not provide legal, immigration or financial advice. We do not guarantee regulatory registration or approval. These statements form part of our contract with you under the Consumer Rights Act 2015.

ICO Registration 808634. Email [email protected]. Phone 0161 399 3584.

Privacy Notice | Cookie Policy | Terms | Your 14-day cancellation rights