This notice explains how Aice Limited, trading as GoZtartUp, collects, uses, and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have written this in plain language. If anything is unclear, contact [email protected].
GoZtartUp is the trading name of Aice Limited, a company registered in England and Wales (Company No. 14726496), with its registered office at 335 Manchester Road East, Little Hulton, Manchester M38 9AR.
We are a done-for-you business launch consultancy that helps healthcare and childcare professionals in the UK transition from employment to owning a regulator-ready business. We build and submit CQC or Ofsted applications within a structured 16-week delivery window.
For the purposes of UK data protection law, Aice Limited is the data controller of your personal data. This means we decide how and why your personal data is processed.
| Data Controller | Aice Limited trading as GoZtartUp |
|---|---|
| Company Number | 14726496 |
| Registered Office | 335 Manchester Road East, Little Hulton, Manchester M38 9AR |
| Data Protection Lead | Akinlolu Adeojo (Sole Director) |
| Contact | [email protected] |
| ICO Registration | 808634 |
We have not appointed a statutory Data Protection Officer as we are not required to under UK GDPR Article 37. The Director acts as our internal Data Protection Lead. Direct any data protection queries to [email protected].
This notice applies when you:
This notice is provided under UK GDPR Articles 13 and 14, which require us to give you clear information about how we process your personal data at the time we collect it from you.
The personal data we collect depends on how you interact with us.
| Category | Examples | When collected |
|---|---|---|
| Identity data | Full name, date of birth, nationality, copies of passport or driving licence, photograph | When you sign up for our service or book a call |
| Contact data | Postal address, email, phone, WhatsApp | When you enquire, sign up, or communicate |
| Professional data | Qualifications, employment history, professional registrations (NMC, HCPC), training records | During onboarding for your regulatory application |
| Financial data | Payment card details (processed by Stripe, we do not see or store your full card number), bank details for refunds, instalment payment records | When you make a payment or set up an instalment plan |
| Application data | Business model details, premises information, staffing plans, governance documents, policies and procedures for your CQC or Ofsted application | Throughout the 16-week delivery process |
| DBS data | DBS certificate reference number, type of check, outcome summary. We do not retain your full DBS certificate. | When you provide DBS information for your application |
| Health data (limited) | Only where you voluntarily disclose health information relevant to your fitness as a registered manager. We do not routinely request health data. | Only if you choose to disclose |
| Marketing data | Name, email, phone, how you heard about us, consent preferences, communication history | When you engage with our content or forms |
| Technical data | IP address, browser, device type, pages visited, time spent, referring URL | Automatically when you visit our website, subject to your cookie preferences |
We only collect personal data that is necessary for the purpose for which it is collected. We do not collect personal data "just in case".
When you visit our website, we may collect technical data using cookies and similar technologies, subject to your consent for non-essential cookies. See Section 14.
Referral partners in our Partnership Programme may provide us with your name and contact details (with your knowledge) so we can contact you about our services. Where your contact details are obtained from publicly available professional directories, we will tell you how we obtained your details when we first contact you.
Where we obtain your personal data from a source other than you, we will tell you within a reasonable period and no later than one month, or at the point of first communication with you, whichever is earlier (UK GDPR Article 14).
We only process your personal data where we have a lawful reason to do so. UK GDPR Article 6 sets out six lawful bases for processing. The table below explains what we use your data for and which lawful basis applies.
| What we use your data for | Lawful basis | More detail |
|---|---|---|
| Delivering the 16-week build-and-submit service | Contract (Art.6(1)(b)) | Processing is necessary to perform the Service Agreement |
| Collecting your identity documents and onboarding information | Contract | We need this to prepare your regulatory application |
| Preparing and submitting your CQC or Ofsted application | Contract | The core service we are contracted to provide |
| Processing your DBS information | Contract + DPA 2018 Sch.1 Pt.1 Para.1 | Necessary for your application. DBS data has extra legal protection, see Section 6 |
| Taking your payments and managing instalments | Contract | Necessary to collect fees under your Service Agreement. Payments are processed by Stripe, see Section 8 |
| Providing post-registration launch support | Contract | Included in your Service Agreement for 4 to 8 weeks after registration |
| Handling complaints and resolving disputes | Legitimate interests (Art.6(1)(f)) | Our interest: investigating and resolving complaints fairly. Your interest: having your complaint properly addressed |
| Defending or pursuing legal claims | Legitimate interests | Establishing, exercising, or defending legal claims, including PI insurance notifications |
| Sending you marketing communications | Consent (Art.6(1)(a)) or Legitimate interests with PECR soft opt-in | For new prospects: your consent. For existing clients: PECR soft opt-in to market similar services. See Section 13 |
| Website analytics and improvement | Consent for non-essential cookies | Non-essential cookies (analytics, advertising) only placed with your prior consent. See Section 14 |
| Keeping financial and accounting records | Legal obligation (Art.6(1)(c)) | Required under Companies Act 2006 ss.386-389 and for HMRC tax purposes |
| Reporting to the ICO on a data breach | Legal obligation | Required under UK GDPR Article 33 |
Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests do not override your rights and freedoms. We have documented these assessments internally. You have the right to object to processing based on legitimate interests at any time, see Section 11.
Some types of personal data have extra legal protection because they are more sensitive. These include health information and criminal record data such as DBS checks.
If you are applying for CQC or Ofsted registration, you may need to provide DBS check information.
How we handle your DBS data: we only record the DBS certificate reference number, the type of check, and the outcome summary. We do not retain your full DBS certificate. Once your regulatory application has been submitted, any copy of your DBS certificate in our possession will be securely destroyed within six months, in line with the DBS Code of Practice.
We do not routinely collect health data. However, you may voluntarily disclose health information relevant to your fitness as a registered manager (for example, if the regulator requires a declaration about your health). Where you do disclose health data, we process it under Art.9(2)(b) (employment and social protection obligations) combined with DPA 2018, Schedule 1, Part 1, Paragraph 1. We will only use this data for the specific purpose of your regulatory application and will not share it with anyone other than the regulator, unless required by law.
You are not legally required to provide us with personal data. However, if you choose not to provide certain information (for example, your identity documents, DBS information, or professional qualifications), we may not be able to deliver our service or submit your regulatory application. We will always explain what information is essential and why before you provide it.
We do not sell your personal data to anyone. We only share your data where necessary to deliver our service, comply with the law, or protect our legitimate interests.
| Recipient | Why we share | Their role |
|---|---|---|
| CQC or Ofsted | To submit your regulatory application | Independent controller (own privacy policies) |
| Companies House | Where we assist with company formation, director and PSC details are filed as required by law | Public register (legal requirement) |
| Stripe | To process your card payments securely | Processor (PCI-DSS compliant) |
| GoHighLevel (GHL) | To host our marketing funnel, manage form submissions, schedule eligibility calls, and run automated communications | Processor under Art.28 DPA |
| Assembly.com | To manage your client record, communications, and delivery milestones | Processor under Art.28 DPA |
| Mailcow / hosting provider | To send and receive email communications | Processor (hosting provider) |
| n8n | To send automated notifications and follow-ups | Processor under Art.28 DPA |
| Netlify | To host our website infrastructure | Processor under Art.28 DPA |
| External accountant | To maintain accounts and tax records | Processor under Art.28 DPA |
| PI insurer (Markel) | To notify circumstances or claims under our PI policy | Independent controller for claims |
| HMRC | To comply with tax obligations | Public authority (independent controller) |
| ICO | To report personal data breaches where required | Supervisory authority |
Where we use processors (organisations that process your data on our behalf), we have written data processing agreements in place that require them to process your data only on our instructions, keep it confidential, and implement appropriate security measures. This is required by UK GDPR Article 28.
When you pay by card, your payment is processed by Stripe. We pass Stripe your name, email, and transaction amount. Your card details are entered directly into Stripe's PCI-DSS compliant environment. We do not see, store, or have access to your full card number.
Stripe has certified under the EU-US Data Privacy Framework (including the UK extension) and uses the UK International Data Transfer Addendum for transfers outside the UK. Read Stripe's privacy policy at stripe.com/privacy.
What GoZtartUp does not do with your financial data: we do not assess your creditworthiness, we do not recommend or advise on financial products, we do not store your payment card details, and we are not authorised or regulated by the Financial Conduct Authority (FCA).
Your personal data is primarily stored and processed in the United Kingdom. However, some of our technology providers may store or process data outside the UK (for example, Stripe processes data in the United States).
Where your data is transferred outside the UK, we ensure that:
We carry out transfer risk assessments for each international transfer. The EU renewed the UK's adequacy status through to December 2031, confirming that data flows between the EU and UK remain protected. Contact [email protected] for further details about safeguards in place for any specific international transfer.
We keep your personal data only for as long as we need it for the purpose for which it was collected, or as required by law. We do not keep data indefinitely.
| Data category | Retention period | Reason |
|---|---|---|
| Client files (active engagement) | Duration of engagement + 6 years | Limitation Act 1980 (6-year claim period); PI insurance run-off |
| Completed client files | 6 years from completion | Same as above |
| DBS reference records | Destroyed within 6 months of application submission | DBS Code of Practice; data minimisation |
| Marketing or prospect data | 24 months from last engagement, or until you withdraw consent | Data minimisation |
| Financial and accounting records | 6 years from end of the relevant financial year | Companies Act 2006; HMRC |
| Website analytics data | Up to 26 months | Aligned with analytics provider settings |
| Complaints and dispute records | 6 years from resolution | Defence of legal claims under Limitation Act 1980 |
When the retention period expires, we securely delete or anonymise your personal data. Electronic data is permanently erased. Physical documents are cross-cut shredded.
You have the following rights over your personal data. These rights are not absolute. There are situations where we may lawfully decline a request (for example, if we need to keep data to comply with a legal obligation or defend a legal claim). Where we decline, we will explain why.
| Your right | What it means |
|---|---|
| Right to be informed | You have the right to know how we use your data. This notice fulfils this right. |
| Right of access (DSAR) | You can ask for a copy of all the personal data we hold about you. We respond within 1 calendar month. Free of charge. |
| Right to rectification | You can ask us to correct inaccurate or incomplete data. |
| Right to erasure | You can ask us to delete your data in certain circumstances. We may not erase data needed for legal claims or statutory records. |
| Right to restrict processing | You can ask us to temporarily stop processing your data, for example, while we verify accuracy. |
| Right to data portability | You can ask for your data in a portable format. Applies where processing is based on consent or contract and carried out by automated means. |
| Right to object | You can object to processing based on legitimate interests. We will stop unless we have compelling grounds. You can always object to direct marketing. |
| Right to withdraw consent | Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect lawfulness of processing before withdrawal. |
Contact us by email at [email protected] or by post at Aice Limited, 335 Manchester Road East, Little Hulton, Manchester M38 9AR. Use the subject line "Data Protection Request" followed by your name. You do not need to fill in a special form.
We may need to verify your identity before responding, to protect your data from being disclosed to someone else. We will respond within one calendar month. If your request is complex, we may extend by up to two further months, but we will tell you within the first month.
There is no charge for exercising your data rights.
We may send you information about our services, including educational content about regulatory compliance and business ownership. We only send marketing where we have a lawful basis.
Under the Privacy and Electronic Communications Regulations 2003 (PECR), we need your consent to send you electronic marketing messages (email, SMS, WhatsApp) unless the soft opt-in exception applies. We will always:
If you are an existing client and we obtained your email during the course of providing our service, we may use the PECR soft opt-in to send you marketing about similar services. This only applies where: we obtained your contact details in the context of a sale or negotiations for a sale, we are marketing our own similar products or services, and we gave you a clear opportunity to opt out when we collected your details and in every subsequent message.
We will process your opt-out without delay. Opting out of marketing will not affect service-related communications needed to deliver your contracted service.
Our website uses cookies and similar technologies. See our Cookie Policy for full details.
| Cookie type | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Essential for the website to function (session management, security) | No, exempt under PECR Regulation 6 |
| Analytics | Help us understand how visitors use our website | Yes, consent via cookie banner |
| Marketing or advertising | Track visitors across websites to display relevant advertisements | Yes, only placed with your prior consent |
You can change your cookie preferences at any time through our cookie banner or by adjusting your browser settings. Refusing non-essential cookies will not prevent you from using our website.
UK GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you.
Our position: GoZtartUp does not use automated decision-making or profiling that produces legal or significant effects on you. All material decisions about your application, service delivery, and account are made by our team with human oversight. We do not use algorithms to determine your eligibility, pricing, or service outcomes.
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or damage. Our measures include:
While we take all reasonable steps to protect your data, no method of transmission or storage is 100% secure. If you become aware of any security concern, contact us immediately at [email protected].
Our services are designed for adults who are healthcare and childcare professionals. We do not knowingly collect or process personal data from children (individuals under the age of 18). If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly and securely.
We may update this Privacy Notice from time to time. Where we make material changes, we will:
This notice was last updated on 25 June 2026.
This Privacy Notice is provided for transparency and to meet our obligations under UK GDPR Articles 13 and 14. It does not create any contractual rights beyond those in your Service Agreement.
This Privacy Notice, and any dispute or claim arising from or in connection with it, shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction.
Your data protection rights under UK GDPR are not affected by this governing law clause. You always have the right to lodge a complaint with the ICO regardless of any contractual provisions.
If you have any questions about this Privacy Notice or how we handle your personal data:
| Data Controller | Aice Limited trading as GoZtartUp |
|---|---|
| Data Protection Lead | Akinlolu Adeojo |
| [email protected] | |
| Post | 335 Manchester Road East, Little Hulton, Manchester M38 9AR |
If you are unhappy with how we have handled your personal data, contact us first so we can try to resolve the issue directly. You also have the right to complain to the Information Commissioner's Office (ICO) at any time.
| ICO Website | ico.org.uk |
|---|---|
| ICO Helpline | 0303 123 1113 |
| ICO Address | Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
You may also have the right to seek a judicial remedy through the courts if you believe your data protection rights have been infringed.