How we collect, use, and protect your personal and business information.
Last updated: September 10, 2026
OA Advisory ("we," "us," "our") provides advisory, project, and staffing services to professional services businesses. To do that work, we collect and process personal and business information belonging to our clients and their staff where relevant. This policy explains what we collect, why, how we protect it, and the rights you have over it.
We process personal data in accordance with the Data Protection (Privacy of Personal Information) Act, 2003 of The Bahamas ("the Act"). Where we act as a data controller under the Act, this policy reflects our obligations under it.
Depending on your relationship with us, we may collect:
We do not knowingly collect information from anyone under the age of 18, and our services are directed at businesses, not individual consumers.
We use this information only for the purposes it was collected for, including to:
We do not sell personal or business information, and we do not use client data for marketing purposes.
We share information only where necessary to deliver the service, including with:
We require that any third party we share data with handles it securely and only for the purpose it was shared. We do not otherwise sell, rent, or trade client information to third parties.
Our website may use analytics tools to understand how visitors use our site — for example, which pages are viewed and how visitors found us. These tools may use cookies and collect information such as your approximate location, device and browser type, and browsing activity on our site. This information is used only to improve our website and is not linked to the engagement data described elsewhere in this policy. You can opt out of analytics tracking using your browser settings or a browser extension.
We aim to process and store client data within The Bahamas wherever possible. Where a service we rely on (such as our scheduling or payment provider) stores or processes data outside The Bahamas, we take reasonable steps to ensure it's handled with an equivalent standard of care, consistent with the Act's provisions on data transferred outside the jurisdiction.
We apply reasonable administrative, technical, and physical safeguards to protect the personal and business information we hold against unauthorized access, alteration, disclosure, or loss, including restricted access to client records, secure storage of documents and credentials, and limiting access to team members who need it to do their work.
We retain client records and related personal data for as long as our engagement with you continues, and afterward only as long as needed to meet our own legal, tax, and recordkeeping obligations. When information is no longer needed for these purposes, we take reasonable steps to securely delete or destroy it.
Under the Act, you have the right to know what personal data we hold about you, request a copy of it, request that inaccurate data be corrected, and request that data be erased where it's no longer needed for the purpose it was collected. To exercise any of these rights, contact us using the details below.
We may update this policy from time to time as our services or legal obligations change. The "last updated" date at the top of this page reflects the most recent revision.