Privacy policy
1. Who is responsible for your information?
Forum Leadership Services Ltd is the data controller responsible for the personal information described in this policy.
Forum Leadership Services Ltd
Company number: 16047315
Registered office: 61 Mosley Street, International House, Manchester, United Kingdom, M2 3HZ
Email: info@forumleadership.co.uk
We have not appointed a data protection officer because our current processing activities do not require one. Privacy enquiries should be sent to the email address above.
2. Who this policy applies to
This policy applies to website visitors, people who contact us or book a conversation, prospective and current members, coaching clients, suppliers, professional contacts, and anyone else whose personal information we process in connection with Gavin Bryce and The Forum.
3. Information we collect
Depending on your relationship with us, we may collect:
- Identity and contact information, such as your name, role, organisation, email address, telephone number, and correspondence address.
- Professional information, including your responsibilities, career background, leadership priorities, and organisational context.
- Booking and communication information, including appointment details, messages, enquiries, and records of our correspondence.
- Membership and service information, such as agreements, attendance, goals, coaching records, shared notes, agreed actions, resources, feedback, and other information needed to provide the service.
- Member-area account information, including your account identifier, email address, access status, membership tier, time zone, sign-in activity, and security logs.
- Financial and transaction information, including invoices, payment status, and accounting records. We do not normally store complete payment-card details.
- Technical information, such as IP address, browser type, device information, security logs, and basic website request data.
- Marketing preferences, including whether you have asked to receive or stop receiving communications.
We usually collect information directly from you. We may also receive professional information from your employer, a colleague who introduces you, publicly available professional sources or service providers acting on our behalf. Where required, we will provide privacy information no later than our first communication with you or within one month of receiving the information.
Free resources and assessments
For the free book, we use your name and email address to fulfil your request and send a download link through Resend. This processing is based on our legitimate interest in responding to your request. Requesting the book does not subscribe you to marketing. The download link is valid for seven days.
The Mask Assessment is hosted by Zoho Survey. We use your responses to provide summary results and, if you book a discovery call, prepare your full personalised report. We use your email address to match your assessment and booking. The assessment supports reflection and does not make automated decisions with legal or similarly significant effects.
Beehiiv handles newsletter subscriptions. You choose whether to subscribe, and you can unsubscribe using the link in newsletter emails. Neither a book request nor an assessment automatically subscribes you.
4. Sensitive personal information
We do not ask you to provide special category information through this website. Leadership coaching or confidential discussions may occasionally involve information about health, wellbeing or other sensitive matters that you choose to share. We will only process that information where it is necessary, proportionate and supported by an appropriate condition under data protection law, such as your explicit consent or the establishment, exercise or defence of legal claims.
Please do not send sensitive information by ordinary email unless it is necessary. We can agree a more appropriate way to share it.
5. How and why we use personal information
| Purpose | Information used | Lawful basis |
|---|---|---|
| Responding to enquiries and arranging conversations | Identity, contact, professional, and booking information | Steps at your request before entering a contract and our legitimate interest in responding to genuine enquiries |
| Assessing suitability and administering membership | Identity, professional, communication, and service information | Steps before a contract, performance of a contract and our legitimate interest in protecting the quality and confidentiality of The Forum |
| Providing peer forums, coaching, and strategic support | Contact, professional, service, and relevant sensitive information | Performance of a contract; explicit consent or another Article 9 condition where special category data is involved |
| Operating the secure member area | Account, membership, coaching, action, resource and security information | Performance of a contract and our legitimate interests in providing secure, confidential access to member services |
| Invoicing, accounting and legal compliance | Identity, contact, financial, and transaction information | Performance of a contract and compliance with legal obligations |
| Protecting the website, services and confidential discussions | Technical, communication, and service information | Our legitimate interests in security, preventing misuse and protecting participants |
| Sending relevant updates or invitations | Identity, contact, and marketing preferences | Consent, or legitimate interests where electronic marketing law permits and you can reasonably expect it |
| Managing or defending legal claims | Relevant information connected with the matter | Legitimate interests and the establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against your rights and reasonable expectations. You may ask for more information about this assessment.
6. If you do not provide information
You are not generally required by law to give us personal information. However, if information is needed to respond to an enquiry, assess membership, enter an agreement or provide a service, we may be unable to proceed without it. We will explain when providing information is necessary.
8. International transfers
Some service providers may process information outside the United Kingdom or European Economic Area. Where data protection law requires safeguards, we use an applicable adequacy decision, the UK International Data Transfer Agreement or Addendum, approved standard contractual clauses, or another lawful transfer mechanism. You may contact us for further information about the safeguard relevant to a particular transfer.
9. How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose collected, including legal, accounting, safeguarding, and dispute-resolution requirements. Our usual retention periods are:
| Record | Usual retention period |
|---|---|
| General enquiries that do not become a client or membership relationship | Up to 24 months after the last meaningful contact |
| Membership, coaching and contractual records | For the relationship and normally up to six years after it ends, unless a longer period is necessary |
| Member-area accounts and access records | While access remains active; essential account and security records may be retained for up to 12 months after access ends |
| Accounting, invoice and tax records | Normally six years after the relevant financial year |
| Marketing records and suppression preferences | Until consent is withdrawn or you object, with a minimal suppression record retained to respect your preference |
| Security and technical logs | Normally no longer than 12 months, unless needed to investigate a security incident |
We may retain specific information for longer where required by law, where a complaint or legal claim is anticipated or ongoing, or where safeguarding or professional obligations make this necessary. We securely delete or anonymise information when it is no longer required.
10. How we protect information
We use proportionate technical and organisational safeguards, including access controls, secure service providers, confidentiality commitments, and procedures for responding to suspected personal-data breaches. Access is limited to people who need the information for a legitimate business purpose.
No internet transmission or storage system can be guaranteed to be completely secure. If a breach is likely to create a risk to people, we will notify the relevant supervisory authority and, where the risk is high, affected individuals, in accordance with applicable law.
11. Marketing communications
You can ask us to stop sending marketing communications at any time by using the unsubscribe option provided or emailing info@forumleadership.co.uk. Stopping marketing will not prevent service or administrative messages that are necessary for an existing relationship.
12. Automated decisions and children
We do not use personal information to make solely automated decisions that have legal or similarly significant effects. The website and our services are intended for adults acting in a professional capacity and are not directed at children.
13. Your data protection rights
Depending on the circumstances and applicable law, you may have the right to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format;
- withdraw consent at any time, without affecting earlier lawful processing; and
- raise a concern with a data protection supervisory authority.
These rights are not absolute and exemptions may apply. We may need information to confirm your identity. We do not charge a fee for a reasonable request, but may charge a permitted fee or refuse a manifestly unfounded or excessive request. We normally respond within one month.
15. Changes to this policy
We review this policy periodically and will publish changes on this page. If a change materially affects how we use existing personal information, we will provide additional notice where appropriate before the change takes effect.
16. Contact and complaints
Please contact us first if you have a question, want to exercise a right or are concerned about how your information has been handled:
You also have the right to complain to the UK Information Commissioner’s Office. Information about making a complaint is available at ico.org.uk/make-a-complaint. If the EU GDPR applies to your situation, you may also contact the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
