Who is responsible for your personal data?
I, Hilary Ellis, will be registered as a data controller in the United Kingdom for the purposes of the General Data Protection Regulations (GDPR).
Where is your personal data stored?
All the personal data we have is stored on our database in the UK. The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (”EEA”). It may be transferred to and processed by third parties outside of the EEA for the purpose of assessment services. It may also be processed by one of our suppliers. This includes web hosting services and the provision of marketing services. By submitting your personal data, you agree to this transfer, storing or processing. I will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy notice.
The information we collect and how we use it
I collect information that you give me when filling in a contact form on my website (www.talent-for-change.com), subscribing to my mailing list, attending one of my events, participating in a survey or completing a feedback form, giving me your business card or by corresponding with me by phone, email or apps.
If you engage me to provide coaching services, I may also with your permission, hold notes taken during coaching sessions on paper and electronically. As a client, your personal details you share with me and I then hold may include your name, address, private and corporate e-mail address and phone number; financial information; curriculum vitae and photograph; completed questionnaires and exercise responses; assessments and links to your professional profiles available in the public domain e.g. LinkedIn, Twitter, Facebook or corporate website.
This information is held and used for some or all of the following purposes:
- To assist me in providing you with career and leadership coaching services
- For purposes of Continuing Professional Development and Accreditation :
- Name, e-mail, address and number of coaching hours for Continued Professional Coach Development and Accreditation
- Anonymised issues may be discussed with my coach supervisor
- To improve my customer service and make my services more valuable to you;
- To notify you about upcoming events, news and offers when you have granted me permission to do so.
- For invoicing and billing purposes
Information we obtain from other sources
This is information I obtain about you from other sources such as your business card or personal recommendations. In this case I will inform you, by sending you this privacy notice, within a maximum of 30 days of collecting the data, of the fact I hold personal data about you, the source the personal data originates from and for what purpose I intend to retain and process your personal data.
Disclosure of your information
With your consent I may share your data responsibly with selected third parties including:
- Professional Associates I work with or who may work for me
- Marketing and technology platforms and suppliers
- Providers of assessments, psychometrics and self-perception tests that you decide you wish to take as part of a coaching or development programme
These third parties have their own privacy policies on their websites which you should check. I do not accept any responsibility or liability for their policies whatsoever as I have no control over them.
I may disclose your personal information to third parties where I am legally required to do so.
Retention of your data
I understand my legal duty to retain accurate data and only retain personal data for as long as I need it for legitimate business interests and contracts related to the provision of coaching services and/or marketing purposes and that you are happy for me to do so. I segregate data so that I keep different types of data for different time periods. The criteria I use to determine whether I should retain your personal data include:
- The nature of the personal data;
- Its perceived accuracy;
- My legal obligations.
Depending upon the criteria used as to whether I should retain your information I may:
- Retain your personal data (first name, last name, email address, start and end date of the coaching programme, number of coaching hours received) on a coaching log to comply with ICF Continuous Professional Development and Accreditation requirements. If at any time I cease to practice as an ICF accredited coach this data will be destroyed.
- Retain your personal data (name and address) on copies of the invoices I have sent to you or invoices you / your organisation have sent me to you for as long as required by HMRC.
- Retain your personal data (first name, last name, email address) on a Mailchimp mailing list if you have opted-in to receiving marketing information from me.
All other client information and data collected during the course of your coaching programme whether held on paper or electronically, will be destroyed on completion of your coaching programme plus 36 months.
How do I store and protect your personal data?
All the electronic personal data I have is stored on my password protected laptop and is backed-up on a separate hard-drive. Emails are also accessible on my password protected mobile phone. I have a robust anti-virus / malware software on my laptop and take all reasonable care to avoid clicking on potentially malicious links or attachments to ensure risk from phishing and other malware is minimal.
I store my lap-top, hard-drive and paper-based records at my home office. The doors and windows of my home are protected securely in accordance with the requirements of my household insurance policy. I take my lap-top with me when I travel from time to time. I will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy notice.
The data that I collect from you may be also collected or transferred to and processed by third parties outside of the European Economic Area (“EEA”) by one of my suppliers – this includes web hosting services and email servers (e.g. Google and Special Domain Services) and the provision of marketing services (e.g.Mail Chimp), or for the purpose of assessment services such as psychometric or self-perception tools (e.g. RocheMartin) . By submitting your personal data, you agree to this transfer, storing or processing.
These suppliers have their own privacy policies on their websites which you should check. I do not accept any responsibility or liability for their policies whatsoever as I have no control over them.
What are your rights?
You have the right to ask me not to process your personal data for marketing purposes. From May 25th 2018 I will always obtain your consent before using your data for such purposes. You can exercise your right to accept or prevent such processing by checking certain boxes on the forms I use to collect your data.
You have the right to request information about the personal data I hold on you at any time. If you would like to make a request for information please email firstname.lastname@example.org
You also have the right to request modifications, updates or removal of your data held for other purposes (legal obligations, Continuous Professional Development and Accreditation). I may ask you to verify your identity and for more information about your request.