This Privacy Policy applies between you, the User of this Website, and MDW Consulting Limited trading as WayfinderHQ, the owner and provider of this Website. MDW Consulting Limited trading as WayfinderHQ takes the privacy of your information very seriously. This Privacy Policy applies to our use of any and all Data collected by us or provided by you in relation to your use of the Website.
This Privacy Policy should be read alongside, and in addition to, our Terms and Conditions, which can be found at: wayfinderhq.co.uk/terms; our Cookie Policy at wayfinderhq.co.uk/cookies; and, where we act as a processor for a subscribing firm, our Data Processing Agreement at wayfinderhq.co.uk/dpa.
Please read this Privacy Policy carefully.
Definitions and Interpretation
- In this Privacy Policy, the following definitions are used:
| Term | Definition |
|---|
| Data | collectively all information that you submit to MDW Consulting Limited trading as WayfinderHQ via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws; |
| Cookies | a small text file placed on your computer by this Website when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out in the clause below (Cookies); |
| Data Protection Laws | any applicable law relating to the processing of personal Data, including but not limited to the GDPR and, where applicable, POPIA, and any national implementing and supplementary laws, regulations and secondary legislation; |
| DPA | the Data Processing Agreement between us and a Firm, available at wayfinderhq.co.uk/dpa, which governs our processing of Firm Client Data on that Firm’s behalf; |
| Firm | a business (typically an accounting or professional services firm) that subscribes to the WayfinderHQ service and uses it to manage its own clients and prospects; |
| Firm Client Data | personal data about a Firm’s own clients, prospects and their representatives which the Firm, or a person acting on its behalf, uploads into or generates within the WayfinderHQ service; |
| GDPR | the UK General Data Protection Regulation; |
| MDW Consulting Limited trading as WayfinderHQ, we or us | MDW Consulting Limited trading as WayfinderHQ, a company incorporated in England and Wales with registered number 15902128 whose registered office is at 1501 Norton House, Duke of Wellington Avenue, London, SE18 6PD; |
| POPIA | the Protection of Personal Information Act, 2013 of South Africa, together with its regulations; |
| UK and EU Cookie Law | the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 & the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2018, and as further amended by the Data (Use and Access) Act 2025; |
| User or you | any third party that accesses the Website and is not either (i) employed by MDW Consulting Limited trading as WayfinderHQ and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to MDW Consulting Limited trading as WayfinderHQ and accessing the Website in connection with the provision of such services; and |
| Website | the website that you are currently using, wayfinderhq.co.uk (and, for our South African service, wayfinderhq.co.za), and any sub-domains of those sites, unless expressly excluded by their own terms and conditions. |
- In this Privacy Policy, unless the context requires a different interpretation:
- the singular includes the plural and vice versa;
- references to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this Privacy Policy;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- “including” is understood to mean “including without limitation”;
- reference to any statutory provision includes any modification or amendment of it;
- the headings and sub-headings do not form part of this Privacy Policy.
Scope of this Privacy Policy
- This Privacy Policy applies only to the actions of MDW Consulting Limited trading as WayfinderHQ and Users with respect to this Website and the WayfinderHQ service. It does not extend to any websites that can be accessed from this Website, including, but not limited to, any links we may provide to social media websites.
- We handle personal data in two different roles, and it matters which one applies to you. In some cases we decide why and how personal data is processed, and we are the controller of it. In other cases we simply hold and process personal data on behalf of a Firm that subscribes to WayfinderHQ, and that Firm decides why and how it is processed. The two clauses below explain which is which.
- Where we are the controller. We are the “data controller” (and, under POPIA, the “responsible party”) for personal data about the subscribing Firm and its staff, and about visitors to the Website. This includes:
- account registration and login details;
- billing, subscription and payment information;
- support and other correspondence with us;
- marketing communications and related preferences; and
- Website visitor and technical data (for example IP address and diagnostic information).
This Privacy Policy governs that processing in full, and it is the processing described in the sections headed “Data Collected”, “Our Use of Data” and “Your Rights” below unless we say otherwise.
- Where we are the processor (UK GDPR) or operator (POPIA). Personal data about a Firm’s own clients and prospects, which Firm staff upload into or generate inside the CRM, is Firm Client Data. For that data the Firm is the controller (and, under POPIA, the responsible party) and decides why and how it is processed. We process it only on the Firm’s documented instructions, under the DPA, and not for our own purposes. Firm Client Data includes identity and anti-money-laundering (AML) verification data processed through our verification partner, Thirdfort, where a Firm chooses to run a check. That is a more sensitive category of data: it can include images of identity documents such as passports and driving licences, address verification information, and the results and risk indicators produced by the check. We handle it strictly as processor, on the instructing Firm’s behalf, and never use it for any purpose of our own.
- If you are a client of an accounting firm that uses WayfinderHQ, that firm, and not us, is responsible for your personal data. Please direct any data subject rights request (for example a request for a copy of your data, or for it to be corrected or deleted), and any question about why your data is held, to that firm in the first instance. Where a firm asks us to, we will assist it in responding to your request. If you contact us directly about data held in a Firm’s account, we will normally need to refer you, or pass your request, to the Firm.
- The terms on which we process Firm Client Data are set out in our Data Processing Agreement at wayfinderhq.co.uk/dpa. The current list of sub-processors we use is published at wayfinderhq.co.uk/subprocessors.
Data Collected
- Where we act as controller (see the clauses above), we may collect the following Data, which includes personal Data, from you:
- name;
- job title;
- profession;
- contact Information such as email addresses and telephone numbers;
- financial information such as credit / debit card numbers;
- web browser type and version (automatically collected);
- operating system (automatically collected);
in each case, in accordance with this Privacy Policy.
Data Processed Inside the CRM on Behalf of Firms
- Separately from the Data described above, the WayfinderHQ service holds Firm Client Data that a Firm puts into, or generates within, its account. Depending on how a Firm uses the service, this can include:
- contact details for the Firm’s clients and prospects, and for their directors, officers and other representatives;
- postal and business addresses;
- responses to onboarding questionnaires, including information about the client’s business, services required and circumstances;
- pricing, quote and fee data, including quote versions and amendments;
- engagement letters, agreements and other documents, including signed and countersigned copies and signature audit information;
- messages, notes and documents exchanged through the client portal or recorded against a client or prospect record;
- activity and audit records showing what happened to a client or prospect record and when; and
- identity and AML verification data, where a Firm chooses to run an identity or anti-money-laundering check, including identity document images, address verification information and verification results.
- We process all of the above as a processor under the UK GDPR, and as an operator under POPIA, on behalf of the Firm, which is the controller or responsible party. We act only on the Firm’s documented instructions, as set out in the DPA. We do not sell Firm Client Data, do not use it for our own marketing, and do not use it to train machine learning or artificial intelligence models. The Firm decides what data to enter, how long to keep it, who inside the Firm may see it, and when it should be corrected or deleted. If you want to know why a Firm holds your data, ask the Firm.
How We Collect Data
- We collect Data in the following ways:
- data is given to us by you;
- data is collected automatically; and
- in the case of Firm Client Data, data is entered into, uploaded to or generated within the service by a Firm or by someone acting on its instructions (including a client of the Firm completing an onboarding step).
Data That is Given to Us by You
- MDW Consulting Limited trading as WayfinderHQ will collect your Data in a number of ways, for example:
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you register with us and set up an account to receive our products/services;
- when you make payments to us, through this Website or otherwise;
- when you elect to receive marketing communications from us;
- when you use our services;
in each case, in accordance with this Privacy Policy.
Data That is Collected Automatically
- To the extent that you access the Website, we will collect your Data automatically, for example:
- we automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed “Cookies”.
Our Use of Data
- Any or all of the Data for which we are the controller may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, that Data may be used by us for the following reasons:
- delivery of the WayfinderHQ service;
- creating and administering your account, and authenticating you when you log in;
- taking payment, managing your subscription and keeping billing records;
- responding to your support enquiries and other correspondence;
- sending service and administrative messages about your account;
- sending marketing communications about our own services, where you have asked to receive them or we are otherwise permitted to send them;
- keeping the Website and the service secure, diagnosing faults and improving them;
in each case, in accordance with this Privacy Policy.
- We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed “Your rights” below).
- When you register with us and set up an account to receive our services, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
- This section describes only the Data for which we are the controller. We do not use Firm Client Data for any of the purposes above. Firm Client Data is used only to provide the service to the Firm, on the Firm’s documented instructions and as permitted by the DPA, together with the limited processing needed to keep the service secure, available and supported.
Free Trial and Demo Sandbox
- When you sign up for a free trial, we collect and process the same categories of Data, for the same purposes and on the same legal bases, as for any other account. No additional categories of Data are collected simply because you are on a trial. If you choose to add payment details to continue after the trial, those details are handled by our payments provider as described in the section below.
- We also provide a public demo environment so you can explore the product without signing up. The demo is populated with fictional sample data and is reset regularly. It is not intended to hold real personal Data, and you should not enter any real personal information into it.
Third-Party Service Providers
- To provide the service, we share certain Data with the third-party providers (sub-processors) listed below. Each processes Data only on our instructions and for the purpose described:
| Provider | Data processed and purpose |
|---|
| Stripe | Payments. Processes your name, email and payment card details when you subscribe or pay. We do not store full card numbers on our own systems. |
| DocuSeal | E-signature. Processes the names, email addresses and contents of engagement letters and agreements that are signed through the platform. |
| Thirdfort | Identity and anti-money-laundering (AML) verification. Processes identity documents and verification data where a firm runs an ID/AML check on you. |
| Twilio | SMS delivery. Processes mobile phone numbers and message content when we send SMS notifications. |
| FreshBooks | Accounting sync. Where a firm connects its FreshBooks account, we process the accounting and billing data synced from it. |
| Supabase | Database, authentication and file storage. Hosts our core database in the United Kingdom and manages account login, storing the account Data described in this Policy together with documents and files uploaded to the platform. |
| Resend | Transactional email. Processes email addresses and message content to deliver account, onboarding and notification emails. |
| Sentry | Error and performance monitoring. Processes technical diagnostic data (such as error reports, IP address and browser information) to help us find and fix faults. |
| Vercel | Application hosting and execution, and cookieless analytics. Our application runs on Vercel, so Data is processed in transit and in memory for as long as it takes to serve a request, including data you submit and data read from our database and shown back to you. Vercel also processes the technical request data (such as IP address) needed to serve the application, and runtime logs, which may incidentally contain limited personal Data. Vercel does not store application data at rest; that data is held by Supabase. We also use Vercel Analytics to measure anonymous page views and site performance; this does not use cookies and does not identify you personally. |
A fuller description of what each provider does, and where it processes Data, is set out at wayfinderhq.co.uk/subprocessors.
- Our core database and the infrastructure our application runs on are both located in the United Kingdom, so the Data we hold is stored and served from the UK. Some of the other providers listed above may process Data outside the UK. Where they do, we rely on appropriate safeguards, such as the UK’s International Data Transfer Agreement or Addendum, or an adequacy decision, to protect your Data.
- Where these providers process Firm Client Data, they act as our sub-processors under the DPA. The current list is maintained at wayfinderhq.co.uk/subprocessors, and we give Firms notice of any intended addition or replacement of a sub-processor in accordance with the DPA.
Keeping Data Secure
- We use technical and organisational measures to safeguard Data, for example:
- all traffic between your browser and the service is encrypted in transit using TLS;
- Data is stored on managed, access-controlled infrastructure operated by reputable hosting and database providers;
- credentials for connected third-party integrations are encrypted at rest using AES-256-GCM;
- each Firm’s data is separated from every other Firm’s by Postgres row-level security, which enforces tenant isolation in the database itself rather than relying only on application code;
- access to your account is controlled by a user name unique to you and a password, and access within a Firm’s account is governed by role-based access control;
- administrative access by our own staff is restricted to the small number of people who need it, and payment card details are handled by our payments provider rather than stored on our systems.
- Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: hello@wayfinderhq.co.uk.
- Where we are the controller and a personal data breach occurs, we will notify the Information Commissioner’s Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals, in accordance with Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to individuals, we will also inform the affected individuals without undue delay. Where we are the processor, we will notify the affected Firm without undue delay after becoming aware of a breach, so that the Firm can meet its own notification obligations, and will assist it in doing so.
- If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
Data Retention
- Unless a longer retention period is required or permitted by law, we only hold your Data for as long as necessary to provide the service or until you ask us to delete it. Where an account is closed or its subscription is cancelled, we apply a grace period before its Data is permanently deleted:
- for accounts that have never made a payment (for example, trials that end without converting), Data is permanently deleted 7 days after cancellation;
- for accounts that have previously paid, Data is permanently deleted 30 days after cancellation.
During the grace period the account can be reinstated; once the grace period ends, deletion is permanent.
- Even after we delete your Data, it may persist on backup or archival media for a limited period, and where retention is required for legal, tax or regulatory purposes.
- Records the Firm must keep by law. The grace periods above are the periods for which we keep data in our systems. They are not a retention schedule for the Firm’s own records. Where a Firm is the controller of records that are subject to its own statutory retention duties, for example the five year duty to keep customer due diligence and transaction records under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, it is the Firm’s responsibility to export and retain those records before the grace period ends. Once the grace period ends we delete the account’s data permanently and do not hold or archive those records on the Firm’s behalf. We are not the Firm’s record keeper, and deletion by us does not discharge the Firm’s obligations.
Your Rights
- You have the following rights in relation to your Data:
- Right to access - the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is “manifestly unfounded or excessive.” Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- Right to correct - the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase - the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data - the right to “block” us from using your Data or limit the way in which we can use it.
- Right to data portability - the right to request that we move, copy or transfer your Data.
- Right to object - the right to object to our use of your Data, including where we use it for our legitimate interests.
- Right to complain - the right to raise a complaint with us directly about how we handle your Data.
- Who to send your request to. You can exercise the rights above against us in respect of Data for which we are the controller. If your request concerns Firm Client Data, in other words information held about you inside an accounting firm’s WayfinderHQ account, the Firm is the controller and you should send your request to that firm in the first instance. We are not permitted to disclose, amend or delete a Firm’s data on the instruction of a third party. If you send such a request to us, we will tell you so and, where appropriate, forward it to the Firm; we will then assist the Firm in responding to it as required by the DPA.
- To make enquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: hello@wayfinderhq.co.uk.
- If you have a complaint about how we handle your Data, please contact us in the first instance via this e-mail address: hello@wayfinderhq.co.uk. We will acknowledge your complaint within 30 days, investigate and respond without undue delay and inform you of the outcome.
- If you are not satisfied with the way your complaint is handled by us, you may refer your complaint to the relevant data protection authority. For the UK, this is the Information Commissioner’s Office (ICO). The ICO’s contact details can be found on their website at https://ico.org.uk/.
- It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
South Africa (POPIA)
- WayfinderHQ is also offered to firms in South Africa, including via wayfinderhq.co.za. Where POPIA applies, the same two-role split described above applies, using POPIA’s terms:
- for personal information about a subscribing firm, its staff and visitors to the Website (account, billing, support and marketing information), we are the responsible party; and
- for personal information about a firm’s own clients and prospects held inside its WayfinderHQ account, we are an operator processing on the firm’s behalf, and the firm is the responsible party. The firm determines the purpose and means of the processing, and we act only with the firm’s knowledge or authorisation, as required by section 20 of POPIA.
- Under POPIA you have rights broadly equivalent to those listed under “Your Rights” above, including the right to be notified that your personal information is being collected, to request confirmation of what information is held and access to it, to request correction, destruction or deletion of inaccurate, irrelevant, excessive or unlawfully obtained information, to object to processing on reasonable grounds, and to complain to the Information Regulator. Direct those requests to us where we are the responsible party, and to the firm where the firm is the responsible party. As an operator we will not act on a request about a firm’s client information without that firm’s authorisation, but we will assist the firm in responding.
- Personal information of South African data subjects held in the service is hosted outside South Africa. Where that is the case, the transfer is made under the binding agreement required by section 72 of POPIA, which is set out in our Data Processing Agreement at wayfinderhq.co.uk/dpa. That agreement requires us, and any sub-operator we appoint, to give effect to protection of the information substantially similar to the conditions for lawful processing under POPIA, and imposes equivalent obligations on onward transfers.
- If you are not satisfied with how your personal information is handled, you may lodge a complaint with the Information Regulator (South Africa). Its contact details are available on its website at https://inforegulator.org.za/. Where the complaint concerns information held in a firm’s account, we would encourage you to raise it with the firm first.
- This Privacy Policy, and our agreements with firms, are governed by the law of England and Wales. That choice of law does not remove or displace any mandatory obligation or right that applies to us or to you under South African data protection law, including POPIA, and nothing in this Privacy Policy should be read as limiting the powers of the Information Regulator.
Links to Other Websites
- This Website may, from time to time, provide links to other websites. We have no control over such websites and are not responsible for the content of these websites. This Privacy Policy does not extend to your use of such websites. You are advised to read the Privacy Policy or statement of other websites prior to using them.
Changes of Business Ownership and Control
- MDW Consulting Limited trading as WayfinderHQ may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of MDW Consulting Limited trading as WayfinderHQ. Data provided by Users will, where it is relevant to any part of our business so transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy Policy, be permitted to use the Data for the purposes for which it was originally supplied to us.
- We may also disclose Data to a prospective purchaser of our business or any part of it.
- In the above instances, we will take steps with the aim of ensuring your privacy is protected.
- Firm Client Data is treated differently. Because we hold it only as processor, it is not ours to repurpose. On any such transfer it passes to the new owner subject to the DPA and to the Firm’s continuing instructions, and the new owner may use it only to continue providing the service to the Firm. Any disclosure to a prospective purchaser during due diligence will be limited to what is necessary and made under a duty of confidence, and will not include bulk export of Firm Client Data unless the Firm has agreed to it.
Cookies
- This Website places only the Cookies described in this section and in the Cookies Schedule below. We do not use Cookies for advertising, profiling or cross-site tracking, and we do not allow third parties to set advertising Cookies through the Website.
- All Cookies used by this Website are used in accordance with current UK and EU Cookie Law.
- The only Cookie set by this Website is the authentication session Cookie used by our database and authentication provider, Supabase, which keeps you signed in as you move between pages. It is strictly necessary in order to provide the service you have requested, and is therefore exempt from the consent requirement under regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003.
- We use Vercel Analytics to measure anonymous page views and site performance. It is cookieless: it does not set a Cookie, and does not store or read anything on your device. We do not use any other analytics, advertising or tracking technology on the Website.
- Because we do not use any storage or access technology that requires your consent, you will not be shown a Cookie consent banner on this Website. If we ever introduce a Cookie or similar technology that is not exempt from the consent requirement, we will ask for your consent before it is set, and we will update this Privacy Policy and our Cookie Policy first.
- This Website may place the following Cookies:
| Type of Cookie | Purpose |
|---|
| Strictly necessary cookies | These are cookies that are required for the operation of our website. They include, for example, the cookie that keeps you logged into secure areas of our website and maintains your session. Without them the service you have asked for cannot be provided. |
- You can find a list of Cookies that we use in the Cookies Schedule.
- You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies, but this can be changed. For further details, please see the help menu in your internet browser. You can switch off Cookies at any time; because the only Cookie we set is the one that keeps you signed in, blocking it will prevent you from logging into the service.
- You can choose to delete Cookies at any time. If you delete the session Cookie you will be signed out and will need to log in again.
- It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
- For more information generally on cookies, including how to disable them, please refer to aboutcookies.org. You will also find details on how to delete cookies from your computer. Our standalone Cookie Policy is at wayfinderhq.co.uk/cookies.
General
- You may not transfer any of your rights under this Privacy Policy to any other person. We may transfer our rights under this Privacy Policy where we reasonably believe your rights will not be affected.
- If any court or competent authority finds that any provision of this Privacy Policy (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this Privacy Policy will not be affected.
- Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
- This Agreement will be governed by and interpreted according to the law of England and Wales. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the English and Welsh courts. This does not displace any mandatory data protection obligation or right that applies under the law of another country, including under POPIA in South Africa.
Changes to This Privacy Policy
- MDW Consulting Limited trading as WayfinderHQ reserves the right to change this Privacy Policy as we may deem necessary from time to time or as may be required by law. Any changes will be immediately posted on the Website and you are deemed to have accepted the terms of the Privacy Policy on your first use of the Website following the alterations.
You may contact MDW Consulting Limited trading as WayfinderHQ by email at hello@wayfinderhq.co.uk.
Attribution
- Parts of this Privacy Policy were originally created using a document from Rocket Lawyer, and this attribution applies to those parts. Substantial sections have since been written by us and are not derived from that template.
This Privacy Policy was created on 12 June 2026 and last updated on 3 August 2026.
Cookies Schedule
Below is a list of the cookies that we use. We have tried to ensure this is complete and up to date, but if you think that we have missed a cookie or there is any discrepancy, please let us know.
Strictly Necessary
We use the following strictly necessary cookies:
| Description | Purpose |
|---|
| Supabase authentication session cookie | Set by our database and authentication provider, Supabase, when you log in. It remembers you and maintains your session while you are using the service, and is cleared when you log out or the session expires. This is the only cookie we set. |
Analytical/Performance
We use the following analytical/performance tools. They do not set cookies:
| Description | Purpose |
|---|
| Vercel Analytics | We use Vercel Analytics to measure anonymous page views and site performance. It is cookieless and does not set or read anything on your device. |
We do not use functionality, advertising, profiling or cross-site tracking cookies. If that changes, this schedule and our Cookie Policy will be updated first, and consent will be sought where the law requires it.