Business Clinic
    • Business Independence Program
    • Sale Readiness Program
    • Fractional CFO
    • Fractional CCO
  • AI in Practice
    • About us
    • Resources
    • Contact
Founder Reality Check
  • Programs
  • Business Independence Program
  • Sale Readiness Program
  • Expert on Demand
  • Fractional CFO
  • Fractional CCO
  • AI in Practice
  • About
  • About us
  • Resources
  • Contact
Founder Reality Check
Legal

Privacy Policy

Effective: 27 September 2026 · Last updated: 27 September 2026

The data controller
Trading name
Business Clinic
Legal entity
Aksiro LLC
State of registration
Florida, USA
EIN
42-4395996
Registered office
7901 4th St N STE 300, St. Petersburg, FL 33702, United States of America
Privacy contact
office@businessclinic.cc

This Privacy Policy explains how Aksiro LLC, trading as Business Clinic ("we", "us", "our"), collects, uses, stores, and shares personal data when you use our website at businessclinic.cc, complete the Founder Reality Check or Exit Readiness Assessment, or purchase a paid digital report (together, the "Service").

We are the data controller for the personal data we collect about you. We process personal data in accordance with applicable US federal and Florida state privacy laws (including the California Consumer Privacy Act — CCPA/CPRA — where it applies to you as a California resident) and, where it applies to you because of your residence in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1.What we collect

We collect the following categories of personal data:

CategoryExamplesSource
Identity & contact Name, email address, business name, country, industry You — at submission
Assessment answers Your responses to the Founder Reality Check (up to 10 self-ratings + 40 diagnostic questions) or Exit Readiness Assessment (up to 40 diagnostic questions + belief value + optional target) You — during the assessment
Business financials (Exit Readiness Assessment only) Annual revenue, operating costs, owner compensation, family payroll, business debt, and other financial line items you choose to enter You — during Stage 2
Traffic & referral data UTM parameters from the URL (source, medium, campaign, content, term), fbclid identifier, and document referrer Your browser — automatic
Transaction data (paid reports only) Payment confirmation reference and paid amount, received from our payment processor (Stripe, Inc.). We do not receive your card number. Stripe, Inc.
Communications Emails you send us, support requests, replies to our follow-up sequence You

We do not intentionally collect special-category data (such as health data, racial or ethnic origin, religious beliefs, or biometric data). We do not collect payment-card details — card details are entered on the Stripe-hosted payment page and never reach our systems.

2.How we use your data & legal bases

PurposeData usedLegal basis (GDPR Art. 6)
Generating & delivering your free provisional read Identity, assessment answers Performance of a contract (Art. 6(1)(b)) — you requested the read
Generating & delivering the paid full report Identity, assessment answers, financials, transaction data Performance of a contract (Art. 6(1)(b))
Sending follow-up emails about your assessment (up to seven touches over the first 14–21 days after submission) Identity, assessment summary Legitimate interests (Art. 6(1)(f)) — delivering the value you signed up for; you can opt out of every email
Improving our scoring system & question library (in aggregated, anonymised form only) Assessment answers, traffic source Legitimate interests (Art. 6(1)(f))
Marketing analytics (which channels bring users) UTM parameters, country Legitimate interests (Art. 6(1)(f))
Compliance with legal & tax obligations Transaction data, identity (where required) Legal obligation (Art. 6(1)(c))
Defending or bringing legal claims Any relevant data Legitimate interests (Art. 6(1)(f))

3.Automated decision-making

Your assessment answers are scored by software using a defined rule set, which produces your readiness score, weakest domain, red flags, and — for the Exit Readiness Assessment — a valuation range based on your financials and industry-multiple benchmarks. These outputs inform the report you receive. This is automated processing, but it does not produce legal effects or similarly significant effects on you within the meaning of GDPR Article 22 — the report is informational and educational. You may contact us at any time to request a human re-review of your report's findings.

4.Who we share your data with

We share personal data only with the third parties listed below, and only to the extent necessary for the stated purpose:

RecipientPurposeLocation
Google LLC / Google Ireland Limited (Google Workspace, Apps Script, Sheets, Gmail) Storage of submissions, automated processing, email delivery fallback EU & USA (Standard Contractual Clauses)
Resend, Inc. Transactional and follow-up email delivery United States of America (Standard Contractual Clauses / UK IDTA for EEA and UK transfers)
Stripe, Inc. (paid reports only) Card payment processing United States of America (Standard Contractual Clauses / UK IDTA for EEA and UK transfers)
Cloudflare, Inc. Site hosting, edge functions, and DDoS protection United States of America (Standard Contractual Clauses / UK IDTA for EEA and UK transfers)
Tax authorities & auditors Where required by law United States of America

We do not sell your personal data, share it with advertising networks, or use it to build profiles for advertising purposes.

5.International transfers

Because we are established in the United States, personal data we collect is processed on servers located in the United States. Our processors (Google, Resend, Stripe, Cloudflare) are also predominantly US-based. Where personal data of EEA or UK residents is transferred to the United States or another country outside the EEA/UK, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses and, where the UK GDPR applies, the UK International Data Transfer Addendum — to ensure your data continues to receive an essentially equivalent level of protection.

6.How long we keep your data

  • Assessment submissions and reports: retained for up to 36 months from your last interaction, so we can re-issue or follow up on your report. After this period, identifying fields are deleted and only fully anonymised data may be retained for product improvement.
  • Hosted report pages: generated report pages are retained on our infrastructure for up to 12 months after publication and then automatically expire. If you purchased and want a longer-lived copy, save or print the page.
  • Email correspondence: retained for up to 24 months after the last message.
  • Transaction records (paid reports): retained for the period required by US federal and Florida state tax and accounting law (typically 7 years for business and tax records).
  • Marketing analytics: retained in aggregated, non-identifying form indefinitely.

You may ask us to delete your data earlier — see Section 7 below.

7.Your rights

Subject to the conditions in applicable data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") where we no longer have a lawful basis to retain it.
  • Restrict our processing of your data in certain circumstances.
  • Object to processing carried out on the basis of legitimate interests, including marketing follow-ups.
  • Receive your data in portable form and have it transferred to another controller where technically feasible.
  • Withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of past processing).
  • Lodge a complaint with a supervisory authority — see Section 11 below.

To exercise any of these rights, email us at office@businessclinic.cc. We will respond within 30 days (or sooner where required by applicable law). We may need to verify your identity before acting on a request.

8.How we keep your data secure

We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include access controls on the source spreadsheet and Apps Script project, secure transport (HTTPS) for all submissions, two-factor authentication on administrator accounts, and use of vetted enterprise providers (Google, Resend, Cloudflare, Stripe).

No method of electronic transmission or storage is 100% secure. If we ever become aware of a personal-data breach affecting you, we will notify you and the relevant supervisory authority within the timeframes required by law.

9.Cookies & tracking

The Site uses Google Analytics 4 to measure how the Site is used, and the Meta Pixel to measure the performance of our advertising and to build advertising audiences. Both services set cookies or similar identifiers in your browser and process data under their own privacy policies. We capture UTM parameters and the referrer URL when you arrive; these are stored alongside your submission and used for marketing analytics.

If you are visiting from the European Economic Area, the United Kingdom, or Switzerland, we ask for your consent before analytics and advertising cookies are set — a banner appears at the bottom of the page on your first visit, and your choice is stored in your browser for twelve months. Declining is one click, and the Site works normally either way. Visitors from other regions are not shown the banner and tracking runs by default; you can still decline by contacting us and we will honour the request going forward.

Stripe may set its own cookies on its own pages (for example the Stripe-hosted payment page). Its use is governed by its privacy and cookie notices.

10.Children

The Service is intended for users aged 18 or over. We do not knowingly collect personal data from children under 16. If we learn that we have collected such data without verified parental consent, we will delete it.

11.Supervisory authorities

If you believe our handling of your personal data infringes the law, you can complain to the supervisory authority in your country:

  • United States: the Federal Trade Commission at reportfraud.ftc.gov, or the Attorney General of your state. California residents may also exercise their CCPA/CPRA rights directly by contacting us using the details in Section 13.
  • European Union: the data protection authority in your country of residence (list at edpb.europa.eu).
  • United Kingdom: the Information Commissioner's Office (ico.org.uk).

12.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our processing or legal obligations. The "Last updated" date at the top tells you when the current version took effect. For material changes, we will notify users by email where we have your contact details.

13.Contact

For privacy questions, requests to exercise rights, or any other matter under this policy, contact:

Aksiro LLC (trading as Business Clinic)
7901 4th St N STE 300, St. Petersburg, FL 33702
United States of America
Email: office@businessclinic.cc

← Back home
Terms Refunds Contact
Business Clinic

Running a business. Simplified. For business owners.

Programs
  • Business Independence Program
  • Sale Readiness Program
Ongoing support
  • Expert on Demand
  • AI in Practice
Company
  • About us
  • Resources
  • Contact
  • Privacy
  • Terms
  • Refunds
© 2026 Business Clinic · Aksiro LLC office@businessclinic.cc