Privacy Policy

Last updated: July 2026

Version 5

© Nadine Powrie Consultancy Limited. All rights reserved.


About this Privacy Policy


This Privacy Policy explains how Nadine Powrie Consultancy Limited (we, us, our or the Company) collects, uses, shares, stores and protects personal data. It applies when you visit www.nadinepowrie.com, make an enquiry, book or purchase a service or digital product, subscribe to communications, attend an event, take part in coaching, mentoring, consultancy, facilitation, training, mediation, investigation or advisory work, or otherwise interact with us.

It also applies where an employer, school, commissioning organisation, client or other authorised person provides information about you in connection with an engagement. Where we process personal data solely on a client’s documented instructions, the client’s own privacy notice will be the primary notice for that processing.



Who we are


Data controller: Nadine Powrie Consultancy Limited

Company number: 10279740, registered in England and Wales

Registered office: The Old Bakery, 90 Camden Road, Tunbridge Wells, Kent, TN1 2QP

Contact email: npowrie@nadinepowrie.com

Data Protection Officer: Phil Powrie, philpowrie@nadinepowrie.com



When we are a controller or processor


We are the controller when we decide why and how personal data is used, including for enquiries, contracts, invoicing, professional correspondence, website administration, our own service records, marketing, complaints and legal compliance.

For some client engagements, particularly where we access documents or systems supplied by a school, employer or other organisation, that client may be the controller and we may act as its processor. In other engagements, the parties may each be separate controllers for different information. The contract or data-processing agreement will clarify the roles, purposes, instructions, retention and security requirements.

Where we act as a processor, we use the information only on the controller’s documented instructions, subject to the law, and assist the controller with individuals’ rights and data-protection obligations.



Whose personal data we may process


Depending on the service, we may process information about:

  • clients, prospective clients and people who purchase or download products;

  • coaching, mentoring, training, facilitation or event participants;

  • employees, leaders, governors, trustees, contractors and professional contacts;

  • pupils, students, parents or carers where this is necessary for authorised school-related work;

  • complainants, witnesses and other people involved in mediation, investigations or reviews;

  • suppliers, advisers, associates and representatives of organisations; and

  • website visitors and subscribers to our communications.



The personal data we collect


  • Identity and contact data. Names, titles, pronouns, organisation, role, postal address, email address, telephone number and similar identifiers.

  • Professional data. Employment history, responsibilities, qualifications, professional interests, leadership context, organisational relationships and development goals.

  • Enquiry and client data. Enquiries, proposals, contracts, service preferences, booking details, availability, attendance and engagement administration.

  • Transaction data. Invoices, payment status, billing contact and limited transaction details. Card information is normally collected directly by the payment provider and is not made fully available to us.

  • Service-delivery data. Information, reflections, goals, feedback, professional notes and documents needed to provide the agreed work, including documents made available through Google Drive, SharePoint, OneDrive, client portals or other approved systems.

  • Communications data. Emails, messages, correspondence, meeting arrangements and records of consent or preferences.

  • Feedback and complaint data. Survey responses, evaluations, testimonials where authorised, concerns, complaints, investigations, outcomes and improvement actions.

  • Technical and website data. IP address, browser and device information, referral source, pages visited, interaction information, cookie identifiers, consent choices and security logs.

  • Image, audio and recording data. Photographs, video, audio, meeting recordings or transcripts only where there is a clear purpose and appropriate prior agreement.

  • Incident and security data. Information about access, suspected misuse, data incidents, device or account security and remedial action.



Special category and criminal-offence information


We do not ask you to provide special category data through our general website enquiry forms. During coaching, consultancy, mediation, investigation, safeguarding or school-related work, we may nevertheless receive information about health, disability, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, political opinions, sex life or sexual orientation, or other particularly sensitive matters.

Where we are the controller, we process special category information only when it is necessary, proportionate and supported by both an Article 6 lawful basis and an appropriate Article 9 condition. Depending on the particular circumstances, the condition may include explicit consent, the establishment, exercise or defence of legal claims, substantial public interest supported by UK law, including relevant safeguarding conditions, or vital interests in a genuine emergency. We document the applicable condition rather than applying one condition to every engagement.

Criminal-offence information, including allegations, is processed only where authorised by UK law or where we act on the documented instructions of a controller that has identified the relevant legal condition and safeguards. Where an Appropriate Policy Document is required by the Data Protection Act 2018, one must be in place.



How we obtain personal data


We may obtain personal data:

  • directly from you through forms, email, bookings, calls, meetings, surveys, contracts, purchases or service delivery;

  • from an employer, school, client, commissioning organisation or authorised representative;

  • from professional platforms and public sources, such as LinkedIn, organisational websites, Companies House or professional directories;

  • from referral partners, associates, advisers or event organisers where lawful and reasonably expected;

  • from website, booking, payment, assessment, communication and technology providers; and

  • automatically through cookies, security logs and similar technologies when you use the website.

Where we obtain your information from another source and act as controller, we will provide privacy information within the period required by law unless an exemption applies or the relevant controller has already provided the information on our behalf.



Why we use personal data and our lawful bases

  • Enquiries and pre-contract discussions. We respond to enquiries, prepare proposals and arrange diagnostic or introductory conversations. We rely on steps taken at your request before a contract and our legitimate interests in developing professional relationships.

  • Contracts and direct service delivery. Where you contract with us personally, we use necessary information to arrange and provide the service, communicate, invoice and manage the engagement. We normally rely on performance of a contract and legitimate interests for associated administration.

  • Organisation-sponsored services. Where an employer, school or other organisation commissions the work, we use participant information to deliver the agreed service. We normally rely on our legitimate interests and those of the commissioning organisation, together with the contract between the organisations. We consider the individual’s reasonable expectations and privacy.

  • Business administration and finance. We manage contracts, accounts, taxation, insurance, professional advisers, suppliers and business records. We rely on contract, legal obligations and legitimate interests in running and protecting the business.

  • Service quality and improvement. We seek feedback, evaluate services, manage risks and improve content and delivery. We normally rely on legitimate interests. We use testimonials, attributable case studies or confidential material only with appropriate permission.

  • Marketing and professional updates. We send relevant communications where you have consented, where the electronic-marketing soft opt-in lawfully applies, or where business-to-business rules allow contact with a corporate subscriber. Under data-protection law, we rely on consent or legitimate interests as appropriate. Every marketing email offers an easy way to opt out.

  • Website operation and security. We operate, secure and troubleshoot the website, prevent misuse and understand aggregate performance. Necessary processing is based on legitimate interests and legal obligations. Non-essential analytics and similar technologies are used only with consent where required, as explained in our Cookie Policy.

  • Complaints, disputes and legal matters. We investigate and respond to concerns, establish facts, protect legal rights and comply with lawful requests. We rely on legitimate interests, legal obligations and, where relevant, the establishment, exercise or defence of legal claims.

  • Safeguarding and serious risk. We may use or share necessary information to protect a child or adult at risk, respond to an emergency or comply with a legal or professional duty. The lawful basis and any special category condition depend on the particular circumstances.



Our legitimate interests


Where we rely on legitimate interests, these may include providing and improving professional services, maintaining appropriate records, managing client and supplier relationships, communicating with corporate contacts, securing systems, preventing misuse, recovering debts, obtaining professional advice and establishing or defending legal rights. We assess necessity, reasonable expectations and possible impact, and do not rely on legitimate interests where your rights and freedoms override those interests.



When providing information is optional or necessary


You may choose whether to make an enquiry, subscribe to marketing or provide optional feedback. You can withdraw consent where consent is the basis for processing.

Some information is necessary to enter into or perform a contract, verify instructions, arrange a service, issue an invoice or meet a legal requirement. If required information is not provided, we may be unable to offer or continue the relevant service. We will explain this where it is not obvious.



Confidentiality in coaching, mediation and commissioned work


Where an organisation sponsors coaching or another professional service, we agree in advance what administrative or progress information may be provided to the sponsor. We do not normally disclose the content of confidential sessions without the participant’s agreement, except where disclosure is required or permitted by law, necessary to address a safeguarding or serious-risk concern, or otherwise covered by the engagement agreement.

Mediation, investigations and similar work remain subject to the confidentiality, reporting and disclosure provisions agreed for the engagement. Privacy rights do not automatically require us to disclose another person’s confidential information.



Children and school-related information


Our website and services are not offered directly to children for them to purchase independently. During authorised work for a school or other organisation, we may receive limited information about pupils or students. The commissioning organisation will normally be the controller for that information and will determine the lawful basis, instructions and safeguards.

We use only the minimum information needed for the agreed purpose, remain within the authorised system where reasonably possible and do not use children’s information for marketing or unrelated profiling.



Recordings, transcription and artificial intelligence


We do not record or automatically transcribe meetings, calls or coaching sessions without prior agreement from the relevant client and participants. We do not enter confidential client documents or identifiable personal data into generative AI, automated note-taking or transcription services unless the client has given prior written permission and the data-protection, confidentiality, contractual and security implications have been assessed.



Cookies and similar technologies


The website uses cookies and similar technologies for essential operation, security, consent management and, with permission where required, analytics or optional functionality. Our Cookie Policy at www.nadinepowrie.com/cookie-policy explains the technologies, providers, purposes and controls.



Who we share personal data with


We do not sell personal data. Where necessary and lawful, we may share it with:

  • the client, commissioning organisation or authorised sponsor, but only to the extent agreed or where reasonably necessary and lawful to administer the engagement or handle a concern or complaint;

  • approved contractors, associates or reviewers who need the information and are bound by suitable confidentiality and data-protection obligations;

  • website, email, storage, collaboration, booking, payment, analytics, video, assessment, survey and security providers;

  • accountants, insurers, auditors, banks, legal advisers and other professional advisers;

  • regulators, courts, law-enforcement bodies, safeguarding authorities or public bodies where disclosure is required or permitted by law; and

  • a prospective purchaser, investor or professional adviser in connection with a genuine business reorganisation or sale, subject to appropriate confidentiality safeguards.

Current key providers may include Podia for the website, digital products and email; Microsoft 365 for business email and documents; Google Workspace, Drive and Analytics; Zoom; Book Like A Boss; Stripe; CookieScript; Cloudflare; and approved assessment or survey platforms. The provider used depends on the service. Some providers, including payment providers and social-media platforms, may act as independent controllers for their own purposes and provide their own privacy notices.



International transfers and access


Some providers, clients or authorised users may process or access information outside the UK. We also work internationally. A restricted transfer or overseas access will take place only where it is necessary, consistent with the engagement and permitted by data-protection law.

Depending on the destination and provider, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, a legally recognised certification or another permitted mechanism. Where required, we assess transfer risks and apply supplementary contractual, technical or organisational safeguards. You may contact us for more information about the safeguard used for a particular transfer and how to obtain a copy, subject to any lawful redactions. 



How we protect personal data


We use proportionate technical and organisational safeguards, including access on a need-to-know basis, business accounts, multifactor authentication where available, encryption and device security, supported software, secure client platforms, recipient checks, controlled downloads, confidential working arrangements and secure deletion.

Our Data Handling and Confidentiality Policy provides more detail. No system can be guaranteed completely secure, but suspected incidents are investigated promptly and notified to clients, individuals or the Information Commissioner’s Office where the law requires.



How long we keep personal data


We keep information only for as long as needed for the stated purpose, contractual requirements and legal, accounting, insurance or regulatory obligations. Our normal periods are:

  • Enquiries that do not lead to an engagement Normally 12 months after the last meaningful contact.

  • Contracts, invoices and necessary business correspondence Normally up to six years after the engagement or relevant financial period, as applicable.

  • Client source documents, temporary downloads and routine working copies Returned or securely deleted as soon as no longer needed and normally within 30 calendar days after the engagement, unless another period is agreed or a lawful hold applies.

  • Recordings and transcripts For the purpose-specific period agreed in advance; otherwise deleted as soon as the purpose is complete and normally within 30 days after the engagement.

  • Complaints, incidents and related correspondence Normally up to six years after the final response or resolution where necessary for accountability, insurance or legal claims.

  • Marketing contacts Until you opt out or the information is no longer necessary. A minimal suppression record may be kept to respect the opt-out.

  • Safeguarding, investigation, dispute or legal-hold material For the documented period required by the client, law, insurer or need to establish, exercise or defend legal rights, with restricted access.

  • Website, consent and analytics information For the period stated in the Cookie Policy and current cookie declaration, or the configured service-retention period.

Copies held only in resilient system backups are protected from routine access and expire through the provider’s normal backup cycle. A retention period may be shortened where information is no longer necessary or extended where required by a legal hold, active dispute or other lawful requirement.



Your data-protection rights


Depending on the circumstances and lawful basis, you may have the right to:

  • request access to your personal data and information about how it is used;

  • ask us to correct inaccurate or incomplete information;

  • ask for deletion where the right to erasure applies;

  • ask us to restrict processing in certain circumstances;

  • object to processing based on legitimate interests;

  • receive or transfer information you provided where data portability applies;

  • withdraw consent at any time where we rely on consent, without affecting earlier lawful processing; and

  • ask for human intervention where a solely automated decision with legal or similarly significant effects is used. We do not currently make such decisions.



Your right to object


You have an absolute right to object to direct marketing, and we will stop using your personal data for that purpose. You may also object to processing based on legitimate interests; we will stop unless we can demonstrate compelling legitimate grounds or the processing is needed for legal claims.



How to exercise your rights


Please email npowrie@nadinepowrie.com. You do not need to use particular wording. We may request proportionate information to confirm identity and understand the request. We normally respond without charge and within one month, although the law permits extensions or fees in limited circumstances. Rights are not absolute, and we will explain any lawful restriction or refusal.

Where we act as a processor, we will promptly pass the request to the relevant controller and assist it as required.



Complaints about personal data


If you are concerned about how we have used your personal data, you may contact us and we will handle the matter under this Privacy Policy and our Complaints Policy. You may also complain to the Information Commissioner’s Office at any point; you do not have to complete our complaints process first:

Website: ico.org.uk

Telephone: 0303 123 1113

Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF



External websites and social media


Our website may link to external websites, embedded services and social-media platforms. Those organisations control their own processing and privacy notices. We are not responsible for their independent privacy practices, although we are responsible for selecting and configuring services we place on our website.



Changes to this Privacy Policy


We may update this policy when services, providers, legal requirements or data-handling practices change. Material changes will be communicated where appropriate.



Contact


Privacy and data-protection questions should be sent to npowrie@nadinepowrie.com.

Related policies: Cookie Policy; Data Handling and Confidentiality Policy; Complaints Policy

Nadine Powrie Consultancy Limited

Company number 10279740

Approved by Nadine Powrie, Director.