Pre-launch disclosure: The company entity, registered address, operational contact mailbox, retention schedule and approved subprocessors are not yet finalised. This page should not be treated as a completed Article 13/14 UK GDPR privacy notice. A full, legally reviewed notice will be published before live marketing or debtor-data processing begins.
TWO DISTINCT PURPOSES
Business prospect enquiries
When conducting B2B outreach or receiving corporate enquiries, Avencrest would ordinarily determine its marketing purposes and act as controller for personal contact information. A legitimate-interests assessment, transparency notice and accessible opt-out are planned.
Creditor collection portfolios
Where acting on a creditor's documented instructions, Avencrest would usually be a processor and the creditor the controller. The parties must confirm the actual allocation of responsibilities in a written contract.
Planned safeguards
01 / PURPOSEMinimum necessary data
Only receive account details needed for the authorised service, such as debtor business, verified contact, invoices, disputed status and communication log.
02 / ACCESSRestricted systems
Use individual staff credentials, appropriate multifactor authentication, role-limited permissions, audit trails and secure transfer — not shared unsecured spreadsheets.
03 / SUBCONTRACTINGApproved personnel
Obtain the client's prior written general or specific authorisation for subprocessors where applicable, and execute Article 28-compliant downstream contracts, confidentiality terms and security obligations.
04 / LOCATIONUK-first delivery
Keep the proposed collections desk and approved freelance operators in the UK initially. Any international access or transfer would require separate legal assessment and client approval.
05 / RETENTIONDocumented retention
Agree a retention and deletion schedule, identify legitimate retention obligations, and return or securely delete client information at contract end as applicable.
06 / INCIDENTSAccountability
Record concerns, restrict further access as appropriate and report suspected security incidents promptly to the creditor under the agreed procedure.
Marketing email privacy
Our proposed introductory emails will identify Avencrest and its service, explain why a corporate contact is being approached, provide a genuine route to opt out, and point to a full privacy notice once approved. We will document the source of professional contact details, apply a suppression list and screen the contact against the relevant PECR rules; sole traders and certain partnerships require different treatment.
Payment information
As a default, commercial debt payments should be made directly to the instructed creditor through its established payment channels. Avencrest will not seek card numbers, bank credentials or detailed debtor information through the public website.
What remains to be implemented
A formal privacy notice identifying the controller and contact details, lawful bases, categories and sources of information, recipients, international transfers if any, actual retention periods, data rights, complaints contact and ICO rights, together with creditor data-processing agreements, a security policy, staff training and a tested incident procedure.
For the applicable principles see the ICO guidance on controller–processor contracts and ICO B2B marketing guidance. No operational accreditation or guarantee is implied by this draft.