Privacy Policy
Brookside Consultancy Group LLC (“Brookside”, “we”, “us”, or “our”) operates under uncompromising institutional fiduciary standards. This statement outlines how we collect, safeguard, process, and govern proprietary corporate information, executive intelligence, and personal data across our advisory practices and digital touchpoints.
1. Information & Data We Collect
Brookside operates primarily as an executive corporate advisory and management consultancy. We do not engage in public consumer profiling or commercial data aggregation. We gather personal and enterprise data only to the extent necessary to deliver high-stakes advisory mandates, conduct due diligence, maintain commercial communications, and secure our platforms.
A. Executive & Professional Identifiers
Full legal name, corporate title, employer organization, verified business email address, direct telephone and WhatsApp contact coordinates, and geographic jurisdiction provided during mandate inquiries, advisory workshops, or contract negotiations.
B. Mandate Scoping & RFP Documentation
Organizational telemetry, strategic objective briefs, tender files, capital allocation parameters, balance-sheet summaries, and confidential project attachments transmitted via our encrypted briefing intake portals.
C. Technical, Device & Telemetry Data
Internet Protocol (IP) addresses, browser architecture, operating system versions, referring URLs, session durations, and anonymized user telemetry generated while navigating our thought leadership publications and digital client portals.
2. Purposes & Lawful Bases for Processing
Under statutory data protection regimes—including the EU/UK General Data Protection Regulation (GDPR) and the Kenya Data Protection Act 2019 (KDPA)—we process corporate and personal information exclusively under the following lawful bases:
| Processing Purpose | Categories of Data | Statutory Lawful Basis |
|---|---|---|
| Contractual Mandate Delivery | Executive IDs, Project Scope, Deal Documents | Performance of Contract |
| Strategic Inquiry Triage | Business Email, Phone, Company Context | Legitimate Advisory Interest |
| Boardroom Briefing Dispatch | Executive Email, Subscription Topics | Explicit Consent |
| Anti-Money Laundering & KYC | Beneficial Ownership, Corporate Registries | Legal & Regulatory Obligation |
| Infrastructure Security & Defense | IP Logs, System Telemetry, Access Tokens | Legitimate Interest (Security) |
3. Consent & Withdrawal Mechanisms
Where processing is grounded in your affirmative consent—such as subscription to the Brookside Boardroom Briefings, participation in specialized executive fellowships, or optional web telemetry—you retain the unrestricted right to withdraw consent at any time without compromising the legality of historical processing.
How to Revoke Consent Instantly:
One-Click Dispatch Opt-Out: Click the “Unsubscribe” link embedded in every executive dispatch email.
Interactive Cookie Toggle: Launch the to disable optional analytics immediately.
Direct Data Officer Notice: Email our Data Protection Officer directly at privacy@brookside-consultancy.com.
4. Cookies & Platform Analytics
Our web platforms utilize minimal, cryptographic session cookies and aggregated analytics to maintain page state, verify language preferences, and evaluate readership engagement across whitepapers.
Strictly Necessary
Always ActiveEssential for cryptographic token verification, load balancing across Nairobi and London servers, and preventing CSRF attacks.
Editorial Telemetry
ConfigurableMeasures scroll velocity, whitepaper downloads, and publication time-on-page without harvesting personal identifiers.
5. Information Sharing & Third-Party Processors
Brookside never sells, rents, monetizes, or trades client dossiers or executive contact lists. We disclose information strictly under the following narrow institutional parameters:
Tier-1 Cloud Infrastructure Sub-processors
Encrypted data hosting managed by ISO 27001 and SOC 2 Type II compliant hosting facilities located in secure European and East African availability zones.
Statutory & Sovereign Regulatory Disclosure
Where strictly compelled by competent judicial subpoenas, the Capital Markets Authority (CMA), or statutory financial intelligence bodies, under prior notice to client counsel wherever legally permitted.
Verified Professional Co-Counsel & Auditors
External legal barristers, independent statutory financial auditors, and technical specialists engaged directly on client mandates under strict bilateral non-disclosure covenants.
6. Cross-Border International Data Transfers
Given our operational corridors linking Nairobi, London, Kigali, New York, and Singapore, data may be transferred across international borders. We ensure that all cross-border transmissions adhere to strict statutory adequacy benchmarks:
Standard Contractual Safeguards
We execute EU/UK Standard Contractual Clauses (SCCs) and comply with Section 48 of the Kenya Data Protection Act 2019 regarding cross-border transfers. These covenants mandate identical organizational, legal, and cryptographic safeguards across all affiliate partner desks.
7. Enterprise Security & Cryptographic Standards
Brookside implements defense-in-depth architectural security protocols certified against leading institutional standards:
In-Transit Encryption
TLS 1.3 cryptographic cipher suites across all public and internal web applications, enforcing Perfect Forward Secrecy.
At-Rest Encryption
AES-256 resting encryption across all corporate databases, secure cloud buckets, and encrypted briefing archives.
Role-Based Access (RBAC)
Least-privilege partner access controls protected by hardware-bound FIDO2 Multi-Factor Authentication (MFA).
SOC 2 & ISO 27001
Annual third-party penetration testing and continuous vulnerability monitoring across our core digital infrastructure.
8. Data Retention Schedules & Secure Purging
We retain personal and corporate information only for the minimum horizon required to fulfill the original engagement, comply with statutory financial audits, or defend legal covenants:
9. Data-Subject Rights & Access Requests
Subject to statutory exemptions (such as legal professional privilege or ongoing fraud investigations), you possess comprehensive rights over your personal data:
Right of Access
Obtain confirmation of data held, processing purposes, and a machine-readable export.
Right of Rectification
Request immediate correction of inaccurate or incomplete corporate or personal records.
Right of Erasure (“To Be Forgotten”)
Request secure, permanent deletion of personal files where statutory retention has lapsed.
Right to Object & Restrict
Halt processing based on legitimate interests or restrict use during active dispute resolution.
Initiate a Formal DSAR Request
Our Data Protection Office fulfills verified requests within 30 statutory days.
10. Protection of Children's Privacy
Brookside provides strategic management, financial advisory, and transformation services exclusively to commercial enterprises, sovereign entities, and adult executive professionals. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we identify that data belonging to a minor has been transmitted without verified parental or guardian consent, we will purge such records from our servers immediately.
11. Policy Updates & Revision Log
We review and update this Privacy Policy periodically to reflect emerging statutory requirements, technological safeguards, or expanded practice corridors. When substantive modifications occur, we will post an updated revision timestamp on this page and, where appropriate, notify active corporate clients via executive email advisory.
12. Contact Our Data Protection Office
For inquiries regarding this policy, to exercise your statutory rights, or to report a perceived data security issue, please contact our Data Protection Officer directly:
Global Headquarters (Nairobi)
Brookside Data Protection Office
Riverside Green Park, Block C, Riverside Drive
Westlands, P.O. Box 48201-00100, Nairobi, Kenya
Email: privacy@brookside-consultancy.com
Direct: +254 (0)20 794 6000
European & UK Desk (London)
Brookside Group Legal & Compliance
25 Bank Street, Canary Wharf
London E14 5JP, United Kingdom
Email: dpo-uk@brookside-consultancy.com
Direct: +44 (0)20 7946 0832
Supervisory Authority Escalation: If you believe our response did not adequately resolve your concern, you have the right to lodge a formal complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya, the Information Commissioner's Office (ICO) in the UK, or your local data protection regulator.
Subscribe to Brookside Boardroom Briefings
Curated macroeconomic insights, transformational frameworks, and boardroom briefings delivered directly to C-suite and institutional leaders.
International Advisory Presence
Delivering on-the-ground strategic counsel across the world's leading financial capitals and commercial epicenters.
London
United Kingdom25 Bank Street, Canary Wharf
E14 5JP London
New York
United States375 Park Avenue, 32nd Floor
NY 10152, New York
Singapore
Singapore1 Marina Boulevard, #28-00
018989 Singapore