Legal
Privacy Policy
Last updated · 10 August 2026
Who we are and our role
ConsultSuite Pro (“ConsultSuite Pro”, “we”, “us”) provides practice-management software for independent consultants and consulting firms.
For account and billing data about our own customers, we act as the data controller. For the content our customers put into the product — client records, documents, time entries, portal messages — we act as a data processor on the customer firm's behalf. If you are a client of a firm using ConsultSuite Pro and want your data changed or removed, contact that firm directly; we will assist them in responding.
Data we collect
Account information. Name, work email address, password hash, firm name, role, and any profile details you choose to add. If you sign in with a third-party identity provider, we receive your name, email and provider account identifier.
Billing information. Subscription plan, seat count, billing contact and invoice history. Card details are entered directly with our payment processor and are never stored on our systems.
Customer content. Everything you create or upload in the product: clients and contacts, engagements, deliverables and documents, uploaded files used in research, timesheets, invoices, portal messages and knowledge-library material.
Usage and technical data. Log records of requests to the service, including IP address, browser and device type, pages or screens used, timestamps, and error diagnostics. We use this to operate, secure and improve the service.
Communications. Messages you send us by email or in-product, and records of support conversations.
How we use data
We use personal data to:
- provide, maintain and secure the service, including authentication and tenant isolation;
- process subscriptions, seats, invoices and renewals;
- generate the drafts, analyses and reports you explicitly request;
- respond to support requests and communicate service and security notices;
- detect, investigate and prevent abuse, fraud and security incidents;
- understand aggregate product usage so we can improve it; and
- meet legal, accounting and tax obligations.
Where our processing relies on legitimate interests, those interests are operating a secure and reliable service and developing our product. Where it relies on contract, it is the provision of the service you have subscribed to. Marketing email is sent only with consent or to existing customers about closely related features, and every message includes an unsubscribe link.
We do not sell personal data, and we do not use customer content to train general-purpose AI models.
AI features and your content
Several features draft or analyse text on request — proposals, contract reviews, meeting minutes, thought-leadership pieces. When you use one, the relevant content is sent to our AI provider to generate that specific output and returned to you. We instruct providers not to retain the content for model training, and prompts and completions are not stored by us beyond what is needed to show you the result.
Grounding is always scoped to your own firm's data. No other firm's content is used to produce your drafts, and yours is never used to produce theirs.
Subprocessors and third parties
We use a small set of vendors to run the service. Each is bound by a data-processing agreement and may use data only to provide services to us. The categories are:
- Hosting and database. Application hosting, managed database, authentication and file storage.
- Payment processing. Subscription billing, card processing and invoicing. Card numbers are held by the processor, not by us.
- Email delivery. Transactional email such as sign-in links, portal invitations and billing notices.
- AI model providers. Generation of the drafts and analyses you request, under no-retention terms.
- Product analytics and error monitoring. Aggregate usage measurement and crash diagnostics.
We may also disclose data where legally required, to enforce our terms, or in connection with a merger or acquisition — in which case we will notify affected customers before their data becomes subject to a different policy. A current list of named subprocessors is available on request at support@consultsuitepro.com.
Data retention
We keep customer content for as long as your account is active. If you delete content in the product, it is removed from active systems promptly and from routine backups within 30 days.
When a subscription ends, customer content remains available for export for 30 days and is then deleted. Account and billing records are retained for as long as required for tax and accounting purposes, typically six years. Operational logs are retained for up to 12 months. Aggregate, non-identifying statistics may be kept indefinitely.
Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, export it in a portable format, object to or restrict certain processing, and withdraw consent where consent is the basis for processing.
Most of these are available directly in the product: you can edit your profile, export your firm's data, and delete records or your entire account. For anything else, write to support@consultsuitepro.com and we will respond within 30 days. We will not discriminate against you for exercising a right. If you are in the EEA or UK, you may also complain to your local data-protection authority.
Cookies
We use a small number of cookies and similar technologies for sign-in, preferences and aggregate analytics. The categories, their purposes and how to control them are set out in our Cookie Policy.
Children's privacy
ConsultSuite Pro is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
International data transfers
We and our subprocessors operate internationally, so personal data may be processed in countries other than your own, including the United States. Where data leaves the EEA or the UK, transfers are covered by an approved mechanism — typically the European Commission's Standard Contractual Clauses together with the UK Addendum — alongside technical measures such as encryption in transit and at rest.
Security
Data is encrypted in transit with TLS and at rest by our hosting provider. Every tenant's data is isolated at the database level with row-level security keyed to the firm, so one firm's queries cannot reach another's rows. Client-portal access uses scoped, expiring session tokens, and portal visibility is off by default until someone deliberately shares an item.
Access to production systems is limited to the people who need it and protected by multi-factor authentication. No system is perfectly secure; we are candid about the current maturity of our programme on our security page. To report a suspected vulnerability or incident, email support@consultsuitepro.com.
Changes to this policy
We may update this policy as the product and our vendors change. The “last updated” date above always reflects the current version, and we will notify account administrators by email before any material change takes effect.
Contact us
For privacy questions, data-subject requests or a copy of our subprocessor list, email support@consultsuitepro.com with “Privacy” in the subject line.