Solon Corporate Finance
Privacy notice
Who we are
Solon Corporate Finance Ltd (“Solon”, “we”) is the data controller for the personal data described in this notice. Company no. 17320026. ICO registration reference ZC190171. Registered office 124 City Road, London EC1V 2NX. For anything in this notice, write to hello@soloncorporate.com.
The personal data we process, and where it comes from
We process limited personal data about company officers and decision-makers: identity and role (name, job title), business contact details (work email, phone, business address), and publicly available business and financial information about the companies you are associated with. Where we have not obtained this from you directly, it comes from these sources: the public register at Companies House, including the filings and charges your company has made; your company’s own website, including archived copies of earlier versions; your company’s listings in published business directories and its public pages on business social networks; other pages on the public web where your company publishes its contact details; a business-contact directory licensed for business use; and, where a company publishes its email addresses in a consistent format, that same pattern applied to a named officer — an inferred address, which we treat as unverified until it is confirmed. We do not buy consumer marketing lists, and we do not seek or hold home addresses or personal email addresses. If you contact us, we also hold what you choose to tell us about your situation, and on a mandate we hold the financial and corporate information needed to prepare and run a financing process.
How we identify the companies we approach
We work from the public register. Our systems screen Companies House data at scale, across the population of active UK companies, to identify those whose filings suggest a live financing question — a registered charge approaching maturity, for example. That screening evaluates companies, not people, and for most companies the outcome is that we never contact anyone. Officer names and roles from the register enter the picture only for companies we may actually approach, and business contact details are gathered only for the smaller number still that we do. Where we approach a professional adviser, such as an accountancy firm, we identify it from its clients’ filed accounts, which name the firm as accountant or auditor.
We use artificial-intelligence systems, under human supervision, to help analyse public filings and draft our research and correspondence. Facts are checked against their source, every communication is reviewed and sent by a person, and no decision that affects you is made by an automated system alone.
Because this screening works from the public register across a large number of companies, writing individually to every officer whose register entry passes through it would mean contacting people precisely to tell them we do not intend to contact them. UK GDPR (Article 14(5)(b)) recognises this and permits us to provide the required information through this notice instead, which is what we do. If you want to know whether we hold anything about you, ask and we will tell you; if you would rather we held nothing, we will act on that too.
Why we process it, and our lawful basis
We use this data to contact you about, and to provide, debt advisory services to your company. We also contact professional advisers, principally accountants, in their business capacity, where public filings show their firm acts for companies in our market, to build working relationships. For business development and correspondence with businesses, we rely on legitimate interests (UK GDPR Article 6(1)(f); Recital 47 recognises business-to-business direct marketing as a legitimate interest) — our Legitimate Interests Assessment is available on request. Where you become a client, we process data to perform the engagement and to meet legal and record-keeping duties, relying on contract and legal obligation. We do not use personal data for advertising, and we do not sell it.
Who we share it with
Service providers who help us operate process data for us under data-processing terms. They fall into five categories: email delivery; client-relationship and database systems; cloud, code and data hosting; artificial-intelligence providers that assist with our analysis and drafting, named on request and not permitted to use the data to train their models; and business-contact directory and search providers. Enquiries you submit, and the record of how you arrived, are stored in a Supabase database hosted in the European Union, operated under a shared internal arrangement recorded in our Record of Processing Activities. If you subscribe to the quarterly briefing, your email address is held by Resend, our email processor, on a double-opt-in basis — we add it only after you confirm, use it for nothing else, and remove it when you unsubscribe. On a mandate, and only where you have instructed or agreed it, we share information with prospective lenders as part of running a competitive process: we share what is necessary to secure terms, and no more.
International transfers
Some of our processors are outside the UK: our email-delivery, artificial-intelligence, code-hosting and directory providers are in the United States. Where that is the case we rely on the UK adequacy regulations or on the International Data Transfer Agreement / Standard Contractual Clauses.
How long we keep it
Prospect data is kept while there is a live prospecting interest; records for companies that no longer fit our criteria are reviewed at each monthly register refresh and removed when no longer relevant. Business contact details are kept for no longer than twelve months without engagement before we re-verify or remove them. Records of what we sent and any reply are kept for twenty-four months as our record of having handled the contact properly. If you decline an approach without asking us to stop, we record that too and leave you alone for twelve months; the record of the decline is kept so we honour it. Only an opt-out is permanent. If you opt out we keep a minimal suppression record — identifiers only, so the stop sticks — and that record we do not delete, because deleting it would expose you to being contacted again. Client data is kept for the engagement plus the period required by law and by our insurers.
Analytics and cookies
This site sets no cookies. We use PostHog, an analytics service hosted in the European Union, configured so that nothing durable is written to your device — analytics state is session-scoped and discarded when you close the tab, and there is no cross-site tracking and no advertising. So that we know which content leads to enquiries, your browser also keeps a session-scoped note of how you arrived (the referring site or campaign link); it too is discarded when you close the tab and is sent to us only with an enquiry you choose to submit, at which point we connect the enquiry to the visit that produced it.
Your rights
You have the right to access, rectify, erase, restrict and port your data. You also have the right to object to direct marketing at any time — an absolute right under Article 21 — and we will stop immediately. To exercise any right, or to opt out, write to hello@soloncorporate.com. You may also complain to the Information Commissioner’s Office at ico.org.uk.
Last reviewed July 2026.