Privacy Policy
Last updated: March 31, 2026
This Privacy Policy explains how ControlFi LLC (“ControlFi,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you visit control-fi.com (the “Site”), submit an enquiry, book a call, receive communications from us, or otherwise interact with us.
1. Scope of Our Privacy Policy
This Privacy Policy applies to personal data we collect through the Site and related communications, including website forms, meeting-booking flows, email, and similar interactions.
It does not necessarily apply to personal data processed by us on behalf of a client under a separate signed engagement letter, statement of work, services agreement, or data processing addendum, where additional or different terms may apply.
2. Personal Data We Collect
We may collect the following categories of personal data:
A. Information you provide directly
When you contact us, submit a form, request information, or book a call, we may collect:
- name;
- work email address;
- phone number;
- company name;
- job title;
- website or LinkedIn URL;
- the contents of your message or enquiry;
- any information you voluntarily provide about your business, goals, or financial planning needs.
B. Information collected automatically
When you use the Site, we may automatically collect certain technical and usage data, such as:
- IP address;
- browser type and version;
- device type and operating system;
- time zone and language settings;
- referring pages and exit pages;
- page views, clicks, scroll behavior, and session timing;
- cookie identifiers and similar technology data.
C. Information from third parties or public sources
Where lawful and relevant to our business development, marketing, or service delivery, we may collect limited professional information from:
- public websites;
- company websites;
- publicly available professional profiles;
- referral partners or introducers;
- CRM enrichment or lead intelligence providers;
- scheduling or form platforms;
- analytics, hosting, or communications providers.
We do not intentionally collect sensitive personal data through the Site unless it is clearly necessary and lawfully handled.
3. How We Collect Personal Data
We collect personal data:
- directly from you when you submit a form, email us, request information, or book a meeting;
- automatically through cookies, pixels, logs, scripts, and similar technologies when you browse the Site;
- through tools and providers we use to operate the Site and our communications, including HubSpot and other service providers used for forms, scheduling, CRM, communications, and analytics;
- from public or professional sources where lawful.
4. How We Use Personal Data
We use personal data for the following purposes:
A. To respond to enquiries and manage pre-engagement communications
We use your information to:
- respond to enquiries;
- schedule and conduct calls;
- evaluate potential fit for our services;
- send proposals or follow-up communications.
B. To operate, improve, and secure the Site
We use technical and usage information to:
- maintain Site functionality;
- detect, prevent, and investigate fraud, misuse, and security incidents;
- understand Site traffic and user behavior;
- improve Site performance, content, and user experience.
C. To market our services
We may use personal data to:
- send newsletters, insights, or updates if you request them or where otherwise lawful;
- send limited B2B marketing communications about ControlFi’s services;
- track email engagement such as opens, clicks, replies, and unsubscribes.
D. To run and administer our business
We may use personal data to:
- maintain internal records;
- manage contracts, billing, compliance, and disputes;
- enforce our legal rights;
- comply with applicable law, regulation, court order, or lawful request.
E. To support internal operations and service delivery
We may use tools, including automation and AI-assisted workflows, to help organize enquiries, draft communications, summarize notes, enrich company context, support internal workflows, and improve response quality. We do not use solely automated decision-making through the Site to make decisions that produce legal or similarly significant effects on individuals.
5. Legal Bases for Processing
Depending on your location and the applicable law, we rely on one or more of the following legal bases:
- Contract / pre-contract steps: where processing is necessary to respond to your request, evaluate a potential engagement, or perform a contract with you.
- Legitimate interests: where processing is necessary for our legitimate business interests, including operating the Site, securing the Site, improving our services, managing business development, and communicating in a proportionate B2B context.
- Consent: where required by law, including for certain non-essential cookies and certain marketing communications.
- Legal obligation: where processing is necessary to comply with applicable laws, regulations, tax obligations, legal claims, or enforcement requests.
Where we rely on legitimate interests, we seek to do so in a way that is proportionate and does not override your rights and freedoms.
6. Forms, Meetings, CRM, and HubSpot
We use website forms, booking workflows, CRM systems, and communications tools to manage enquiries and relationships. These tools may include HubSpot and other service providers used to support:
- website forms and enquiry capture;
- scheduling and meeting management;
- CRM and contact records;
- communications and follow-up;
- marketing and subscription preferences;
- lawful-basis and consent records where applicable.
If you book a meeting with us, your booking and contact information may be processed through these tools so we can schedule the meeting, manage the enquiry, and follow up appropriately.
7. Marketing Communications and Outbound B2B Outreach
We may send marketing or business-development communications where permitted by law.
If you sign up or enquire directly
If you contact us, request information, submit a form, or book a call, we may send you relevant service-related and follow-up communications. Where lawful, we may also send you marketing communications.
If we source professional contact data from public or third-party sources
In some cases, we may process limited professional contact data — such as your name, work email, company, title, and public professional profile — to determine whether ControlFi’s services may be relevant to your business and to send limited B2B outreach where lawful.
In that context:
- we aim to keep the data set proportionate;
- we do not knowingly use sensitive personal data for marketing;
- we seek to provide a clear opt-out in the first relevant communication;
- we maintain suppression records so that opt-out requests are honored.
You can opt out of marketing emails at any time by:
- clicking the unsubscribe link in the email;
- replying “unsubscribe”; or
- contacting us at info@control-fi.com.
We may continue to send non-marketing administrative or relationship messages where permitted.
8. Cookies and Similar Technologies
We use cookies and similar technologies, including technologies associated with website infrastructure, analytics, CRM tracking, forms, scheduling, and communications tools such as HubSpot, to:
- operate the Site;
- keep it secure;
- understand traffic and usage;
- improve performance;
- support forms, meeting scheduling, CRM attribution, and campaign measurement where lawful.
Where required by law, we will obtain your consent before placing non-essential cookies or similar technologies on your device.
For more detail, please review our Cookie Policy.
9. Sharing of Personal Data
We do not sell your personal data for money.
We may share personal data with trusted service providers and professional advisers who help us operate the Site and our business, such as providers of:
- website hosting and infrastructure;
- forms and scheduling;
- analytics and performance monitoring;
- CRM and communications;
- cloud storage and document management;
- email delivery and marketing tools;
- legal, accounting, and compliance support.
These providers may include HubSpot and other vendors we use from time to time to operate the website, manage enquiries, schedule meetings, maintain CRM records, send communications, and support business operations.
We may also disclose personal data:
- in connection with a merger, sale, financing, acquisition, restructuring, or similar transaction;
- to comply with law, regulation, subpoena, court order, or lawful government request;
- to protect our rights, users, systems, property, and security.
Where required, we seek to bind service providers to appropriate confidentiality and data-protection obligations.
10. International Transfers
Because we operate globally and may use service providers in different countries, your personal data may be transferred to and processed outside your country, including outside the European Economic Area or the United Kingdom.
Where required by law, we take steps designed to provide appropriate safeguards for international transfers, such as relying on adequacy decisions, contractual safeguards, or other recognized transfer mechanisms.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Our general retention approach is as follows:
- Enquiry and contact form data: up to 24 months after the last meaningful interaction.
- Prospecting and outreach records: up to 12 months after the last outreach activity, unless a shorter period is appropriate or an objection/opt-out is received sooner.
- Suppression / unsubscribe records: as long as reasonably necessary to ensure we honor your opt-out preferences.
- Client and transaction-related records: for the duration of the engagement and afterward as needed for tax, accounting, legal, contractual, and dispute-resolution purposes.
- Analytics and cookie data: according to tool settings, cookie durations, and applicable legal requirements.
- Security and log data: for as long as reasonably necessary to detect, investigate, and prevent misuse, fraud, or security incidents.
- CRM lawful-basis, consent, and communications records: for as long as reasonably necessary to manage the relationship, document compliance, and honor preferences.
When personal data is no longer needed, we delete it, anonymize it, or place it beyond active use, unless retention is required by law.
12. Data Security
We use commercially reasonable technical, organizational, and administrative safeguards designed to protect personal data against unauthorized access, disclosure, alteration, misuse, and destruction.
However, no internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
13. Your Rights
Depending on where you are located, you may have rights regarding your personal data, including the right to:
- access your personal data;
- correct or update inaccurate personal data;
- request deletion of personal data;
- restrict certain processing;
- object to direct marketing;
- withdraw consent where processing is based on consent;
- request portability of personal data in certain cases;
- lodge a complaint with an applicable supervisory authority.
To exercise any rights request, please contact info@control-fi.com. We may need to verify your identity before fulfilling certain requests.
14. Children’s Privacy
The Site is intended for business users and is not directed to children. We do not knowingly collect personal data from children under 13 through the Site. If you believe a child has provided personal data to us, please contact us so that we can take appropriate steps.
15. Third-Party Websites
The Site may contain links to third-party websites, scheduling tools, or other external services. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy notices.
16. Do Not Track
Some browsers offer a “Do Not Track” setting. Because there is no universally accepted standard for how to respond to such signals, the Site may not respond to them in a uniform way. You can still manage cookies and tracking preferences through the controls described in our Cookie Policy.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we do, we will revise the “Last updated” date above. Material changes will take effect when posted unless otherwise required by law.
18. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our handling of personal data, please contact:
ControlFi LLC
66 West Flagler Street
Suite 900, PMB 12387
Miami, FL 33130, USA
info@control-fi.com