Privacy & Cookies

This Privacy Policy is for Alicja Nocon as a sole trader, trading as Expand the Circle or Alicja Nocon Coaching (“I/me”) registered with the Information Commissioner’s Office (reference ZB069019). This Privacy Policy also applies to my website: www.expandthecircle.co.uk

Under the UK Data Protection Act 2018 and EU/UK General Data Protection Regulations (GDPR), I am a data controller and collect personal data about you for the purposes of delivering services to best suit your requirements and preferences, as detailed below.

This notice applies to:

● All clients

● All third parties and suppliers with whom I have dealings in the ordinary course of our business

I respect your privacy and confidentiality and take appropriate steps to protect your personal data.

It is important that you read this notice, together with any other privacy notice I may provide on specific occasions when I am collecting or processing personal information about you, so that you are aware of how and why I am using such information.

1. Why do you need my information and how do you use it?

Under section 6(1)(b) of the GDPR, I may collect your personal data for the legal bases of:

● Contract for services (for example, coaching, facilitation, training and consulting),

● Consent (for example, professional log of coaching hours, sign-up to newsletters) and

● Legitimate Interest (registration for events such as webinars, pilot workshops etc.)

I will only retain data which I reasonably require and for a period which is reasonably necessary.

I will not disclose your data to the third parties unless you have consented for me to do so or I am otherwise required to do either contractually or under another law or enactment; for example, where you disclose any criminal or fraudulent activities, where there is a valid court order or witness summons, or there is imminent or likely risk of danger to self or others.

Your personal data will never be sold to third parties for marketing purposes.

2. What information do you collect about me and how?

1) Non-personal information

When you visit my website (www.expandthecircle.co.uk), which is hosted by Squarespace, information such as IP addresses (the location of the computer on the internet), pages accessed, and files downloaded. This helps me to understand how many people use my website, how many people visit on a regular basis and how popular/useful my web pages are. This information does not tell me anything about who you are or where you live.

2) Personal information

I will ask you for personal information (any information about an individual from which that person can be identified) in order to provide you with the services requested. I collect personal information about clients directly from themselves when they contact me via telephone, email, social media or my through my website. The type of personal information I collect may include, for example:

● Your name

● Your contact details: home and/or business address, email address, telephone number

● The name of your employer and your job title

● Notes and email communications from coaching sessions, questionnaire and psychometric profiles and 360 stakeholder reports

● Name, contact details, feedback and meeting times and duration for the purposes of professional accreditation with the European Mentoring and Coaching Council (EMCC) UK and insurance.

3. Communicating with you and opting out

In some cases, I may use your personal information to pursue legitimate interests of our own or those of third parties, provided your interests and fundamental rights do not override those interests. The situations in which I will process your personal information are listed below.

● Administering the contract that I have entered into with you.

● Dealing with legal disputes involving you.

● To prevent fraud.

● To market other products or services which I offer which may be of interest to you.

● To inform you about updates about my services.

● To administer my business which may include disclosure of client data to my accountant.

Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information.

In certain circumstances listed above, I hold your data to market other services to you, send you inspirational blogs, or send you information that I think may interest you. I have a legitimate business interest in retaining your data for this purpose, but you may ‘opt out’ of receiving these types of communication from me. You can do so by following the “unsubscribe” instructions included in my communication or by emailing me at hello@expandthecircle.co.uk.

4. How is the information you collect stored?

Client and business data is stored within a GDPR compliant Gmail cloud account. This data can be accessed through my laptop located in my office and my mobile telephone, both oh which are password encrypted. I store no paper records.

If our coaching is carried out via Zoom or a similar communication application, contact data will be stored within the application while we are actively in a coaching relationship.

If you register for an online event with me via Eventbrite, the registration information will be stored on Eventbrite’s servers in the USA.

I reserve the right to change the systems in which data is stored to another equivalent system without notification. At all times I will ensure the appropriate security of your data and GDPR compliance.

5. Data retention: How long is the information I provide held for?

I will only retain your personal information for as long as necessary to fulfil the purposes I collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, I consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which I process your personal data and whether I can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances I may anonymise your personal information so that it can no longer be associated with you, in which case I may use such information without further notice to you.

In respect of client data, you can expect me to hold data relating to your instructions for a period of seven years after completion of the last coaching interaction. The reason for this is that the Limitation Act 1980 typically provides that legal proceedings for breach of contract or negligence can be brought up to six years after the events. I therefore have a legitimate business interest in retaining the data should any subsequent legal proceedings ensue.

Given the nature of my services clients often return to me with repeat instructions within weeks, months or years of contacting me in the first instance. The seven-year period referred to above will start from the last contact I had with the client, third party or supplier, to ensure I am able to assist as and when I need to. Should you not contact me for seven years, I will confidentially destroy all data held for you.

6. Data security: How do you keep my information secure?

In line with the principles defined in the UK Data Protection Act 2018 and the UK/EU General Data Protection Regulation (GDPR), I will ensure that personal data will be processed in ways that are:

🗹 Lawful, fair and transparent

🗹 Collected for specific explicit and legitimate purposes

🗹 Adequate, relevant and limited

🗹 Accurate and up to date

🗹 Not kept for longer than necessary

🗹 Secure

I have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Details of these measures may be obtained directly from me hello@expandthecircle.co.uk.

I have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where I am are legally required to do so.

The transmission of information via the internet is not completely secure. I cannot guarantee the security of your data transmitted online and transmission is made at your own risk. If you communicate with me by email then you assume the risks of such communications being intercepted, not received or delivered, or received by individuals other than the intended recipient.

7. Cookies policy

A cookie is a small data file that is created by our website and stored on your computer when you visit my site. The use of cookies is standard across most websites.

I have a visible banner to remind users that by using my website you consent to the use of cookies. The cookie does not collect or contain personal information about you and poses no security or virus risk to your computer. Its only purpose is to help me evaluate how often visitors return to the site.

You can still make full use of my website if you choose not to accept the cookie on your browser, or to delete it at any time after having accepted it.

Unfortunately, I cannot guarantee that your user experience will be totally free from cookies, data tracking or data analytics if you found the website via a third-party website or search engine.

Other cookies may be stored to your computer’s hard drive by external vendors if the website uses referral programs, sponsored links or adverts. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. No personal information is stored, saved or collected.

8. Your rights in relation to your personal information

Where I am using your personal information on the basis of your consent, you have the right to withdraw that consent at any time.

I will always endeavour to keep accurate and up to date information on you but if you think any of the personal information I hold about you is not correct, you may also request that it is corrected.

Any person whose personal information I hold or process has the following rights:

● To know what I am doing to comply with the UK Data Protection Act 2018 and EU/UK General Data Protection Regulation.

● Right of Access (also known as a “data subject access request”) – You have the right to request copies of the personal information which I hold on you.

If you wish to exercise this right, please contact me at hello@expandthecircle.co.uk. I will respond within one month, providing that the request includes appropriate contact details and proof of identity so that I can validate the request.

● Right to be Informed – You have the right to be told how your personal information will be used. This policy document, and shorter summary statements used in my written and verbal communications, are intended to be a clear and transparent description of how your data may be used.

● Right to withdraw consent to other processing – Where the only legal basis for processing your personal data is that I have your consent to do so, you may withdraw your consent to that processing at any time and I will have to stop processing your personal data. Please note, this will only affect a new activity and does not mean that processing carried out before you withdrew your consent is unlawful.

● Right to Object – You have an absolute right to stop the processing of your personal data for direct marketing purposes. You can exercise this right at any time and can update your preferences yourself by contacting me.

● Right of Rectification – If you believe that my records are inaccurate, you have the right to ask for those records concerning you to be updated.

● Right to Restrict processing – In certain circumstances you may be able to require me to restrict processing of your personal data. For example, if you consider the data I hold to be inaccurate and we disagree, then processing may be restricted until the accuracy of the data has been verified.

● Right of Erasure – Where I have no lawful basis for holding onto your personal data, you may ask that it is deleted under your right to be forgotten. In many cases I would recommend that it suppresses you from future communications, rather than data deletion due to a legal obligation, contractual or other legitimate business interest.

● Right to Data Portability – In limited circumstances you may be entitled to have the personal data you have provided to us sent electronically to you for you to provide to another organisation.

If you have any questions in relation to any of these rights, you can email me at hello@expandthecircle.co.uk.

9. Making a complaint

If you are unhappy at any time about the way I process your personal information, please contact me at hello@expandthecircle.co.uk and I will investigate your concerns.

If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Tel: 0303 1231113

Website: www.ico.org.uk/global/contact-us

10. Changes to this Privacy Policy

This Privacy Policy was last updated on 16 November 2020. I reserve the right to update and change this Privacy Policy from time to time to reflect any changes to the way in which I process your personal data or changing legal requirements.