LEGAL
PRIVACY POLICY
Incharge Wellbeing Ltd
Trading as Incharge Wellbeing and Incharge Futures
Last updated: 25 September 2026
1. ABOUT THIS PRIVACY POLICY
Incharge Wellbeing Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling personal information lawfully, fairly and transparently.
For the purposes of our services, “young person” may be used descriptively for participants aged approximately 14–25, particularly within Incharge Futures. Where legal status matters, a “child” or “under-18 participant” means someone who has not yet reached their 18th birthday. A participant aged 18 or over is an adult, even where we continue to describe them as a young person in the context of our programmes.
This Privacy Policy explains how we collect, use, store and share personal information when you:
visit our website;
contact or enquire about our services;
purchase or participate in one of our services;
participate in coaching, hypnotherapy, wellbeing, education or personal-development work;
participate in Future Compass or Future by Design;
attend a workshop, programme, training session or event;
are the parent or carer of a young person using our services;
participate through a school, college, business, charity or other organisation;
subscribe to communications from us; or
otherwise interact with Incharge Wellbeing Ltd.
This Policy applies to adults and children and young people. Because some of our services are specifically designed for young people aged 14–25, we take particular care when handling children's personal information.
We also provide a shorter Young Person's Privacy & Safety Guide to explain our use of personal information in more accessible language.
2. WHO WE ARE
The data controller is:
Incharge Wellbeing Ltd
Company number: 11474911
Registered in England and Wales
Registered office:
4th Floor Office 205
Regent Street
London
W1B 4HB
Privacy Lead: Diana Rogerson
Email: contact@inchargewellbeing.com
For some work commissioned by schools or other organisations, our data-protection role may differ depending on the arrangement. This is explained further below.
3. THE LAW THAT APPLIES
We process personal information in accordance with applicable UK data-protection and privacy legislation, including the:
UK General Data Protection Regulation (“UK GDPR”);
Data Protection Act 2018;
Privacy and Electronic Communications Regulations 2003 (“PECR”), as amended; and
Data (Use and Access) Act 2025, where applicable.
4. WHAT PERSONAL INFORMATION WE MAY COLLECT
The information we collect depends upon your relationship with us and the service involved.
Identity and contact information
This may include your name, age, date of birth, postal address, email address, telephone number and other contact information.
For young people, we may also collect the name and contact details of a parent/carer and relevant emergency contacts.
Education and career information
For services such as Future Compass and Future by Design, this may include information about:
school, college, university or employment;
subjects and qualifications;
interests and activities;
strengths and preferences;
educational and career aspirations;
courses, universities, apprenticeships or employment being considered;
learning preferences;
work experience; and
decisions or challenges the young person wishes to explore.
Personal-development and session information
Depending on the service, we may create professional notes relating to:
goals;
reflections;
values;
personal circumstances;
areas discussed during coaching or other sessions;
progress;
agreed actions;
professional observations; and
information necessary to prepare personalised materials.
We aim to keep these records relevant and proportionate to the service being provided.
Health, disability, SEND and wellbeing information
Where relevant to providing a safe and appropriate service, you may choose to tell us about:
physical or mental health;
medication;
disability;
neurodivergence;
special educational needs or disabilities;
access requirements;
emotional wellbeing; or
other health-related circumstances.
Health and disability information is classed as special-category personal data and receives additional protection under data-protection law.
We do not ask for health information unless we have an appropriate reason for doing so.
Birth information and personalised reflective tools
Where astrology or Human Design has been agreed as part of a service, we may collect:
date of birth;
time of birth; and
place of birth.
This information may be used to prepare relevant charts or personalised reflective material.
Astrology and Human Design are used as reflective tools and are not medical, psychological or diagnostic assessments.
Where their use is optional, choosing not to provide this information will not prevent you from accessing parts of a service that do not require it.
Safeguarding information
Where a safeguarding concern arises, we may record information reasonably necessary to understand, respond to and document that concern.
This may include sensitive or special-category information where necessary to protect a child, young person or individual at risk.
Payment and transaction information
We may process information concerning:
services purchased;
amounts paid;
payment-plan status;
invoices;
refunds; and
transaction references.
Card information is normally processed directly by our payment provider. We do not ordinarily receive or store complete payment-card details.
Website and technical information
When you use our website, certain technical information may be collected automatically, such as:
IP address;
device and browser information;
pages visited;
approximate location derived from technical data;
referring pages; and
information about your interaction with our website.
Further information about cookies and similar technologies is contained in our Cookie Policy.
Communications
We may retain correspondence including emails, enquiry forms, questionnaires and other communications where reasonably required for our services or business administration.
Images, audio and video
We do not routinely record private client sessions.
Where photographs, audio recordings or video recordings are proposed, we will explain the purpose and obtain appropriate permission beforehand.
Feedback and testimonials
Where you provide feedback, we may retain it for service evaluation.
We will not publish an identifiable testimonial, image, case study or quotation for marketing purposes without appropriate permission.
5. WHERE WE GET YOUR INFORMATION FROM
Most information is provided directly by you.
Where the participant is under 18, information may also be provided by their parent or carer.
Where services are commissioned by a school or other organisation, relevant information may be supplied by the commissioning organisation.
We may also receive information from:
a referring professional or organisation;
other individuals where you have authorised them to provide information;
our website and booking systems;
payment providers; or
publicly available sources where there is a legitimate and appropriate reason to use them.
Where we receive personal information about someone from another source, we will provide or make them aware of appropriate privacy information as required by law.
For young people, we will seek to do this in a form that is understandable and appropriate to their age and maturity.
6. WHY WE USE PERSONAL INFORMATION AND OUR LAWFUL BASES
We only process personal information where we have a lawful basis for doing so.
| Purpose | Main lawful basis |
|---|---|
| Responding to enquiries and taking steps before an adult or parent enters into a contract | Necessary to take steps at your request before entering into a contract |
| Providing services to an adult client | Performance of a contract |
| Administering a service purchased by a parent/carer | Performance of our contract with the purchaser |
| Processing a young person's ordinary personal information where their parent or an organisation has commissioned the service | Our legitimate interests in providing the requested professional service, balanced carefully against the young person's rights and interests |
| Providing optional elements requested or agreed by the participant | Consent where appropriate |
| Keeping proportionate professional records | Legitimate interests in providing safe, consistent professional services, administering the relationship and protecting legal rights |
| Payments, invoicing and accounting | Contract and legal obligations |
| Responding to safeguarding concerns | Legitimate interests, legal obligations or vital interests as appropriate to the circumstances |
| Handling complaints or legal claims | Legitimate interests and, where applicable, legal obligations |
| Providing workshops or organisational services | Contract and/or legitimate interests |
| Improving our services through non-identifiable feedback and analysis | Legitimate interests |
| Publishing identifiable testimonials, recordings, photographs or case studies | Consent |
| Direct marketing | Consent, legitimate interests or the applicable PECR customer “soft opt-in”, depending upon the circumstances |
| Maintaining website and information security | Legitimate interests and, where applicable, legal obligations |
Where we rely on legitimate interests, those interests may include delivering requested professional services, maintaining appropriate professional records, safeguarding, running and protecting our business, communicating with professional contacts, improving services and establishing or defending legal rights.
When the information concerns a child, we give particular weight to the child's interests, rights, welfare and reasonable expectations.
7. SPECIAL-CATEGORY PERSONAL INFORMATION
Special-category information includes information about matters such as:
health;
disability and some SEND information;
racial or ethnic origin;
religious or philosophical beliefs;
sexual orientation;
genetic information; and
certain biometric information.
We only process special-category information where it is relevant and where we have both:
a lawful basis under Article 6 of UK GDPR; and
an appropriate additional condition under Article 9 UK GDPR and, where required, the Data Protection Act 2018.
For ordinary service provision, this may include explicit consent, where appropriate.
Where explicit consent is used, it will be specific and can normally be withdrawn.
Where information must be processed for a safeguarding purpose and seeking consent would be inappropriate, unsafe or impracticable, we may rely upon the relevant substantial-public-interest safeguarding provisions of data-protection law.
We may also process information where necessary to establish, exercise or defend legal claims or where another lawful condition applies.
We minimise the amount of special-category information we collect and restrict access to it appropriately.
8. CHILDREN AND YOUNG PEOPLE
We provide some services directly to young people, including participants aged 14–17.
Children and young people have their own privacy and data-protection rights.
Where possible, we will explain:
what information we are collecting;
why we need it;
what we will do with it;
who it might be shared with;
how long we may keep it; and
what rights the young person has
in language appropriate to their age and level of understanding.
A parent's agreement to purchase a service does not mean that the parent automatically owns or has unrestricted access to everything the young person tells us.
We recognise the importance of giving young people an appropriate degree of privacy so that they can participate honestly and meaningfully.
Where a parent or carer requests access to information relating to a young person, we will consider the young person's age, maturity, understanding, wishes, best interests, confidentiality and applicable data-protection law before disclosing information.
Where a young person is sufficiently competent to understand and exercise their data-protection rights, we may deal with them directly.
9. PARENTS AND CARERS
Where you purchase a service for a young person, we will use your personal information to:
administer the booking;
communicate with you;
take payment;
arrange sessions;
obtain appropriate consent and background information;
provide any parent/carer element included within the programme; and
deal with safeguarding or administrative matters where necessary.
Being the purchaser does not automatically give a parent or carer access to all session content or records relating to a young person. Where a parent debrief forms part of a programme, we will explain its purpose and boundaries at the beginning of the work.
For participants aged 18 or over, the participant is an adult. A parent, carer or other purchaser has no automatic right to information about their sessions, records or personal information unless the participant has authorised disclosure or another lawful basis for sharing applies.
10. SAFEGUARDING AND CONFIDENTIALITY
Information shared in private sessions will normally be treated confidentially.
However, confidentiality is not absolute.
Where we reasonably believe that a child, young person or another individual may be at risk of harm, abuse, neglect or exploitation, we may need to record and share relevant information with an appropriate person or organisation.
Depending upon the circumstances this may include:
a parent or carer;
a school's Designated Safeguarding Lead;
a local authority safeguarding service;
healthcare or emergency services;
the police; or
another appropriate safeguarding body.
Where possible and safe to do so, we will explain the proposed disclosure to the person concerned.
We only share information that is reasonably necessary for the safeguarding purpose.
Our Safeguarding & Child Protection Policy provides further information about our safeguarding approach.
11. SCHOOLS AND OTHER ORGANISATIONS
We may provide services commissioned by schools, colleges, universities, charities, businesses or other organisations.
Depending upon the arrangement, Incharge Wellbeing Ltd may act as:
an independent data controller;
a processor acting on the organisation's documented instructions; or
in some cases, a joint controller.
The legal role depends upon who determines why and how personal information is processed, rather than simply what the parties call themselves.
Where required, appropriate data-processing or data-sharing terms will be agreed with the commissioning organisation.
Where we act only as a processor, we will handle personal information according to the commissioning organisation's lawful instructions and the relevant data-processing agreement.
Certain activities, such as independent professional record keeping or safeguarding decisions, may nevertheless require us to act as an independent controller.
Where an organisation supplies information about a young person, we will work with that organisation to ensure appropriate privacy information is made available to the young person and, where appropriate, their parent or carer.
12. WEBSITE, BOOKINGS AND PAYMENTS
Our website and online store use third-party technology providers to operate functions such as:
website hosting;
forms;
online bookings;
e-commerce;
payment processing;
email delivery; and
website analytics.
Our website is currently operated through Squarespace.
Payments may be processed through third-party payment providers such as Stripe, depending upon the payment method used.
These providers process information in accordance with their own privacy obligations and contractual arrangements with us.
We do not normally receive your full card details.
13. COOKIES AND ANALYTICS
Our website may use cookies and similar technologies necessary for the website to function.
We may also use analytics or other non-essential technologies where permitted by law.
Where consent is legally required, non-essential cookies will not be used until the appropriate consent has been obtained.
Further information is available in our Cookie Policy.
14. MARKETING
We may send information about Incharge Wellbeing or Incharge Futures services where permitted under data-protection law and PECR.
For individuals, this will normally be because:
you have expressly opted in; or
you have previously purchased or actively enquired about a similar service and the legal requirements of the customer “soft opt-in” are satisfied.
You can unsubscribe from marketing at any time.
Marketing consent is separate from consent to receive our professional services.
For professional contacts at schools, organisations and businesses, we may process business contact information under our legitimate interests where lawful to do so.
We do not use therapy notes, health information, SEND information, safeguarding records, astrology/Human Design information or similarly sensitive personal information to target people with marketing.
We do not profile children for targeted direct marketing.
15. TESTIMONIALS, CASE STUDIES AND PUBLICITY
Providing a service does not give us permission to publish your identity, image, story or private information.
Where we wish to use an identifiable:
testimonial;
case study;
photograph;
video;
audio recording; or
quotation
for publicity, teaching or marketing, we will obtain separate permission.
Where the person concerned is under 18, we will take particular care to obtain appropriate consent and to respect the young person's own wishes.
You may refuse marketing or testimonial consent without affecting the professional service you receive.
16. RESEARCH
Personal information obtained through a professional service is not automatically available for research simply because we already hold it.
Where identifiable client information is proposed for formal research, appropriate additional information, lawful bases, consent and ethical procedures will be considered separately.
Where information has been genuinely anonymised so that an individual is no longer identifiable, it is no longer personal data for the purposes of UK GDPR.
17. AUTOMATED DECISION-MAKING
We do not make decisions about clients or young people based solely on automated processing where those decisions would have legal or similarly significant effects.
We may use software or digital tools to assist with administrative processes or the preparation of agreed personalised materials.
Any significant professional recommendations or interpretations are human-led and are not treated as automatic determinations of what a person should study, pursue professionally or do with their life.
18. WHO WE MAY SHARE INFORMATION WITH
We do not sell personal information.
Where necessary and lawful, information may be shared with:
technology and software providers that help us operate the business;
website, booking and payment providers;
cloud storage and email providers;
professional advisers such as accountants, lawyers and insurers;
contractors who genuinely need information to provide services on our behalf;
schools or commissioning organisations where appropriate to the service and privacy arrangements;
safeguarding authorities or professionals where necessary;
courts, law-enforcement bodies, regulators or public authorities where legally required;
professional supervisors or professional consultants where reasonably necessary for safe and appropriate professional practice, with identifying information minimised wherever reasonably practicable; and
another person or organisation where you have authorised us to share information.
Where we use a processor to handle personal information on our behalf, we require appropriate contractual and security protections.
We endeavour to share only the minimum information reasonably necessary.
19. INTERNATIONAL TRANSFERS
Some technology and service providers may process or make personal information accessible outside the United Kingdom.
Where we are responsible for making a restricted international transfer, we will ensure that an appropriate transfer mechanism is in place.
Depending upon the destination and provider, this may include:
UK adequacy regulations;
appropriate contractual safeguards such as an approved UK international data-transfer mechanism; or
another lawful exception permitted by UK data-protection legislation.
Where required, we also assess whether the protection available after transfer meets the standard required by UK law.
20. HOW LONG WE KEEP INFORMATION
We keep personal information only for as long as it is reasonably required for the purpose for which it was collected and for any legitimate legal, safeguarding, insurance, tax or professional record-keeping requirements.
Our usual retention approach is:
| Information | Typical retention |
|---|---|
| General enquiry that does not become a client relationship | Up to 18 months after the last meaningful contact |
| Adult client/service records | Normally up to 7 years after the professional relationship ends |
| Records relating to someone who was under 18 when receiving the service | Normally until at least their 25th birthday, unless there is a documented reason for a longer or shorter period |
| Safeguarding records | Retained for an appropriate period according to the circumstances, safeguarding requirements and potential legal obligations |
| Financial, invoice and transaction records | Normally at least 6 years where required for company/tax purposes |
| Event/workshop administration records | Only for as long as reasonably required for administration, follow-up, contractual or legal purposes |
| Marketing information | Until you opt out, consent is withdrawn or the information is no longer reasonably required; limited information may then be retained on a suppression list so that we can respect your opt-out |
| Testimonials or publicity material | Until consent is withdrawn where withdrawal is applicable, or for the agreed period |
| Website analytics | According to the relevant cookie and analytics settings and retention arrangements |
Where we rely on legitimate interests, those interests may include delivering requested professional services, maintaining appropriate professional records, safeguarding, running and protecting our business, communicating with professional contacts, improving services and establishing or defending legal rights.
When the information concerns a child, we give particular weight to the child's interests, rights, welfare and reasonable expectations.
7. SPECIAL-CATEGORY PERSONAL INFORMATION
Special-category information includes information about matters such as:
health;
disability and some SEND information;
racial or ethnic origin;
religious or philosophical beliefs;
sexual orientation;
genetic information; and
certain biometric information.
We only process special-category information where it is relevant and where we have both:
a lawful basis under Article 6 of UK GDPR; and
an appropriate additional condition under Article 9 UK GDPR and, where required, the Data Protection Act 2018.
For ordinary service provision, this may include explicit consent, where appropriate.
Where explicit consent is used, it will be specific and can normally be withdrawn.
Where information must be processed for a safeguarding purpose and seeking consent would be inappropriate, unsafe or impracticable, we may rely upon the relevant substantial-public-interest safeguarding provisions of data-protection law.
We may also process information where necessary to establish, exercise or defend legal claims or where another lawful condition applies.
We minimise the amount of special-category information we collect and restrict access to it appropriately.
8. CHILDREN AND YOUNG PEOPLE
We provide some services directly to young people, including participants aged 14–17.
Children and young people have their own privacy and data-protection rights.
Where possible, we will explain:
what information we are collecting;
why we need it;
what we will do with it;
who it might be shared with;
how long we may keep it; and
what rights the young person has
in language appropriate to their age and level of understanding.
A parent's agreement to purchase a service does not mean that the parent automatically owns or has unrestricted access to everything the young person tells us.
We recognise the importance of giving young people an appropriate degree of privacy so that they can participate honestly and meaningfully.
Where a parent or carer requests access to information relating to a young person, we will consider the young person's age, maturity, understanding, wishes, best interests, confidentiality and applicable data-protection law before disclosing information.
Where a young person is sufficiently competent to understand and exercise their data-protection rights, we may deal with them directly.
9. PARENTS AND CARERS
Where you purchase a service for a young person, we will use your personal information to:
administer the booking;
communicate with you;
take payment;
arrange sessions;
obtain appropriate consent and background information;
provide any parent/carer element included within the programme; and
deal with safeguarding or administrative matters where necessary.
Being the purchaser does not automatically give a parent or carer access to all session content or records relating to a young person. Where a parent debrief forms part of a programme, we will explain its purpose and boundaries at the beginning of the work.
For participants aged 18 or over, the participant is an adult. A parent, carer or other purchaser has no automatic right to information about their sessions, records or personal information unless the participant has authorised disclosure or another lawful basis for sharing applies.
10. SAFEGUARDING AND CONFIDENTIALITY
Information shared in private sessions will normally be treated confidentially.
However, confidentiality is not absolute.
Where we reasonably believe that a child, young person or another individual may be at risk of harm, abuse, neglect or exploitation, we may need to record and share relevant information with an appropriate person or organisation.
Depending upon the circumstances this may include:
a parent or carer;
a school's Designated Safeguarding Lead;
a local authority safeguarding service;
healthcare or emergency services;
the police; or
another appropriate safeguarding body.
Where possible and safe to do so, we will explain the proposed disclosure to the person concerned.
We only share information that is reasonably necessary for the safeguarding purpose.
Our Safeguarding & Child Protection Policy provides further information about our safeguarding approach.
11. SCHOOLS AND OTHER ORGANISATIONS
We may provide services commissioned by schools, colleges, universities, charities, businesses or other organisations.
Depending upon the arrangement, Incharge Wellbeing Ltd may act as:
an independent data controller;
a processor acting on the organisation's documented instructions; or
in some cases, a joint controller.
The legal role depends upon who determines why and how personal information is processed, rather than simply what the parties call themselves.
Where required, appropriate data-processing or data-sharing terms will be agreed with the commissioning organisation.
Where we act only as a processor, we will handle personal information according to the commissioning organisation's lawful instructions and the relevant data-processing agreement.
Certain activities, such as independent professional record keeping or safeguarding decisions, may nevertheless require us to act as an independent controller.
Where an organisation supplies information about a young person, we will work with that organisation to ensure appropriate privacy information is made available to the young person and, where appropriate, their parent or carer.
12. WEBSITE, BOOKINGS AND PAYMENTS
Our website and online store use third-party technology providers to operate functions such as:
website hosting;
forms;
online bookings;
e-commerce;
payment processing;
email delivery; and
website analytics.
Our website is currently operated through Squarespace.
Payments may be processed through third-party payment providers such as Stripe, depending upon the payment method used.
These providers process information in accordance with their own privacy obligations and contractual arrangements with us.
We do not normally receive your full card details.
13. COOKIES AND ANALYTICS
Our website may use cookies and similar technologies necessary for the website to function.
We may also use analytics or other non-essential technologies where permitted by law.
Where consent is legally required, non-essential cookies will not be used until the appropriate consent has been obtained.
Further information is available in our Cookie Policy.
14. MARKETING
We may send information about Incharge Wellbeing or Incharge Futures services where permitted under data-protection law and PECR.
For individuals, this will normally be because:
you have expressly opted in; or
you have previously purchased or actively enquired about a similar service and the legal requirements of the customer “soft opt-in” are satisfied.
You can unsubscribe from marketing at any time.
Marketing consent is separate from consent to receive our professional services.
For professional contacts at schools, organisations and businesses, we may process business contact information under our legitimate interests where lawful to do so.
We do not use therapy notes, health information, SEND information, safeguarding records, astrology/Human Design information or similarly sensitive personal information to target people with marketing.
We do not profile children for targeted direct marketing.
15. TESTIMONIALS, CASE STUDIES AND PUBLICITY
Providing a service does not give us permission to publish your identity, image, story or private information.
Where we wish to use an identifiable:
testimonial;
case study;
photograph;
video;
audio recording; or
quotation
for publicity, teaching or marketing, we will obtain separate permission.
Where the person concerned is under 18, we will take particular care to obtain appropriate consent and to respect the young person's own wishes.
You may refuse marketing or testimonial consent without affecting the professional service you receive.
16. RESEARCH
Personal information obtained through a professional service is not automatically available for research simply because we already hold it.
Where identifiable client information is proposed for formal research, appropriate additional information, lawful bases, consent and ethical procedures will be considered separately.
Where information has been genuinely anonymised so that an individual is no longer identifiable, it is no longer personal data for the purposes of UK GDPR.
17. AUTOMATED DECISION-MAKING
We do not make decisions about clients or young people based solely on automated processing where those decisions would have legal or similarly significant effects.
We may use software or digital tools to assist with administrative processes or the preparation of agreed personalised materials.
Any significant professional recommendations or interpretations are human-led and are not treated as automatic determinations of what a person should study, pursue professionally or do with their life.
18. WHO WE MAY SHARE INFORMATION WITH
We do not sell personal information.
Where necessary and lawful, information may be shared with:
technology and software providers that help us operate the business;
website, booking and payment providers;
cloud storage and email providers;
professional advisers such as accountants, lawyers and insurers;
contractors who genuinely need information to provide services on our behalf;
schools or commissioning organisations where appropriate to the service and privacy arrangements;
safeguarding authorities or professionals where necessary;
courts, law-enforcement bodies, regulators or public authorities where legally required;
professional supervisors or professional consultants where reasonably necessary for safe and appropriate professional practice, with identifying information minimised wherever reasonably practicable; and
another person or organisation where you have authorised us to share information.
Where we use a processor to handle personal information on our behalf, we require appropriate contractual and security protections.
We endeavour to share only the minimum information reasonably necessary.
19. INTERNATIONAL TRANSFERS
Some technology and service providers may process or make personal information accessible outside the United Kingdom.
Where we are responsible for making a restricted international transfer, we will ensure that an appropriate transfer mechanism is in place.
Depending upon the destination and provider, this may include:
UK adequacy regulations;
appropriate contractual safeguards such as an approved UK international data-transfer mechanism; or
another lawful exception permitted by UK data-protection legislation.
Where required, we also assess whether the protection available after transfer meets the standard required by UK law.
20. HOW LONG WE KEEP INFORMATION
We keep personal information only for as long as it is reasonably required for the purpose for which it was collected and for any legitimate legal, safeguarding, insurance, tax or professional record-keeping requirements.
Our usual retention approach is:
| Information | Typical retention |
|---|---|
| General enquiry that does not become a client relationship | Up to 18 months after the last meaningful contact |
| Adult client/service records | Normally up to 7 years after the professional relationship ends |
| Records relating to someone who was under 18 when receiving the service | Normally until at least their 25th birthday, unless there is a documented reason for a longer or shorter period |
| Safeguarding records | Retained for an appropriate period according to the circumstances, safeguarding requirements and potential legal obligations |
| Financial, invoice and transaction records | Normally at least 6 years where required for company/tax purposes |
| Event/workshop administration records | Only for as long as reasonably required for administration, follow-up, contractual or legal purposes |
| Marketing information | Until you opt out, consent is withdrawn or the information is no longer reasonably required; limited information may then be retained on a suppression list so that we can respect your opt-out |
| Testimonials or publicity material | Until consent is withdrawn where withdrawal is applicable, or for the agreed period |
| Website analytics | According to the relevant cookie and analytics settings and retention arrangements |
These are general periods rather than absolute rules.
We may keep information longer where reasonably necessary because of a safeguarding matter, complaint, legal claim, insurance requirement or legal obligation.
We may securely delete information sooner where it is no longer required.
We may retain information indefinitely where it has been genuinely anonymised so that no individual can be identified.
21. HOW WE KEEP INFORMATION SECURE
We use appropriate technical and organisational measures designed to protect personal information against:
unauthorised access;
loss;
misuse;
alteration;
accidental disclosure; and
destruction.
Measures may include password protection, access controls, secure systems, encryption where appropriate, secure backups and limiting access to people who genuinely need the information.
No internet or electronic-storage system can guarantee absolute security, but we take reasonable measures proportionate to the sensitivity of the information we hold.
If a personal-data breach occurs, we will assess it and make any notifications required by data-protection law.
22. YOUR DATA-PROTECTION RIGHTS
Depending upon the circumstances, you may have the right to:
be informed about how we use your personal information;
request access to your personal information;
have inaccurate or incomplete information corrected;
request deletion of information;
request restriction of processing;
object to certain processing;
receive certain information in a portable format;
withdraw consent where we rely upon consent;
object to direct marketing; and
raise a complaint about our use of your information.
These rights are not absolute and may be subject to legal exemptions or competing rights.
If we rely upon consent, withdrawing consent does not make processing that occurred before withdrawal unlawful.
We may also need to retain certain information despite a deletion request where there is a lawful reason to do so.
23. SUBJECT ACCESS REQUESTS
You may ask us for access to personal information we hold about you.
A request does not need to use the words “subject access request” and may be made verbally or in writing.
We may ask for reasonable information to verify identity or authority before releasing personal information.
We will normally respond without undue delay and within the statutory time period.
We do not normally charge for responding to a subject access request.
A reasonable administrative fee may only be charged in circumstances permitted by law, for example where a request is manifestly unfounded or excessive or where additional copies are requested.
24. REQUESTS CONCERNING A CHILD'S INFORMATION
Personal information about a child belongs to the child for data-protection purposes.
A parent or carer therefore does not automatically have an unrestricted right to obtain all information held about a child.
When responding to a request concerning a young person's personal information, we will consider:
the young person's age and maturity;
whether they understand their data-protection rights;
their wishes;
whether they have authorised the parent or another person to act for them;
the nature and sensitivity of the information;
any duty of confidentiality;
any safeguarding concerns; and
the young person's best interests.
Where a young person is sufficiently competent to exercise their rights themselves, we will normally deal with them directly or obtain their authority before releasing information to another person.
25. YOUR RIGHT TO COMPLAIN
If you believe we have not handled your personal information appropriately, you can raise a data-protection complaint with us under our Complaints & Concerns Procedure.
We aim to acknowledge complaints within 5 working days. In all cases we will comply with applicable data-protection requirements, including acknowledging a data-protection complaint within the statutory period, making appropriate enquiries without undue delay, keeping you informed and explaining the outcome.
You also have the right to complain to the Information Commissioner's Office (ICO). You do not have to complain to us before exercising that right.
26. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in:
our services;
technology;
our business; or
applicable law and regulatory guidance.
The current version will be published on our website with the date of the latest revision.
Where we make a material change to how we use information we already hold, we will take appropriate steps to inform affected individuals where required.
27. CONTACT US
For questions about this Privacy Policy, requests concerning your information or concerns about our handling of personal data, please contact:
Privacy Lead: Diana Rogerson
Incharge Wellbeing Ltd
4th Floor Office 205
Regent Street
London
W1B 4HB
Email: contact@inchargewellbeing.com
Last updated: 25 September 2026