Legal

Privacy policy

What we collect, why, and what you can do about it. In plain English, because you should be able to read it.

Last updated 6 August 2026

The short version. We collect your name and email when you fill in a form, we use it to reply to you or to send you what you asked for, we never sell it, and you can have it deleted whenever you like by emailing [email protected]. Everything below is the detail.

1. Who is responsible

Brightrose is the data controller for personal data collected through brightrose.studio and brightrose.org. Brightrose is a trading name based in London, United Kingdom, founded by Paul Brightrose.

For anything about your data, email [email protected]. It comes straight to Paul, and it is answered personally.

This policy explains what is collected, why, how long it is kept and what you can do about it. It is written under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR where that applies to you.

2. What we collect

Only what is needed to reply to you or to deliver what you asked for.

Information you give us

  • Name and email, whenever you submit any form on this site.
  • Phone number, on the forms that request it, so a session can be confirmed.
  • What you are building, or the challenge you are stuck on, where a form asks.
  • Business stage and city, on the forms that ask, to judge fit.
  • Booking details, when you schedule a call, including the time you chose and anything you write in the booking notes.

Payment information

When you buy something, card details go directly to our payment provider. We never see or store your full card number. We receive confirmation that payment succeeded, the amount, and what it was for.

Information collected automatically

  • Technical data such as IP address, browser type, device and operating system.
  • Usage data such as the pages you viewed, how long you stayed and where you arrived from.

What we do not collect

We do not ask for or want special category data. Please do not include health information, and note that coaching is not a medical or therapeutic service.

3. Why we use it, and our lawful basis

What we doWhyLawful basis
Reply to an enquiryYou asked us something and expect an answerLegitimate interests
Deliver a paid serviceYou bought coaching, a programme or a subscriptionPerformance of a contract
Send a free downloadYou asked for itConsent
Send the newsletterYou opted inConsent, withdrawable at any time
Assess an applicationTo decide whether a place is right for youLegitimate interests, then contract
Keep financial recordsRequired for tax and accountingLegal obligation
Measure how the site is usedTo understand what is workingConsent, through the cookie banner
Show relevant advertisingTo reach people like youConsent, through the cookie banner

Where we rely on legitimate interests, we have considered whether it is fair to you, and you can object at any time.

4. Marketing, and how to stop it

We only email marketing to people who asked for it, or to existing customers about closely related services, which UK PECR permits. Every email has a one click unsubscribe, and unsubscribing is honoured immediately.

You are never added to a list simply for booking a call or making an enquiry.

5. Cookies and similar technology

Cookies that are strictly necessary for the site to function are set without consent, as the law allows. Everything else, including analytics and advertising, is set only after you agree through the banner.

You can change your choices at any time using the consent icon in the bottom left of any page. Refusing does not restrict your use of the site.

Categories used

  • Function. Needed for forms, booking and security. Always on.
  • Measurement. Tells us which pages lead to enquiries. Optional.
  • Marketing. Used to measure and target advertising. Optional.

Browser settings can also block or delete cookies, though some parts of the site may then stop working.

6. Who else processes your data

We use a small number of providers. Each one only handles what it needs to, under contract, and none of them may use your data for their own purposes.

ProviderWhat it doesWhere
HighLevelCRM, forms, booking calendars, email deliveryUnited States
Payment providerTakes card payments securelyEU and United States
CloudflareHosting security, performance, email obfuscationGlobal
GoogleAnalytics and tag management, only with consentUnited States
Google FontsServes the typeface used on this siteUnited States

We do not sell your personal data. We never have and we will not.

7. Transfers outside the UK

Some of the providers above are based in the United States, so your data may be transferred there. Where that happens we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework, depending on the provider.

If you would like to know which mechanism applies to a specific provider, ask and we will tell you.

8. How long we keep it

WhatKept for
Enquiries that go nowhere24 months, then deleted
Newsletter subscribersUntil you unsubscribe, then removed
Client records6 years after the last engagement, for tax and legal reasons
Financial records6 years, as HMRC requires
Session notes12 months after the engagement ends
Analytics14 months

9. Your rights

Under UK and EU data protection law you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong or incomplete.
  • Delete it, where we have no continuing reason to keep it.
  • Restrict what we do with it while a concern is resolved.
  • Object to processing based on legitimate interests, including profiling.
  • Receive it in a portable format, where processing is by consent or contract.
  • Withdraw consent at any time, without affecting what was done before.

Email [email protected] and we will respond within one month. There is no charge.

If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but it is your right either way.

10. Automated decisions

No decision affecting you is made by automated means alone. Applications are read by a person, and that person is Paul.

11. Security

Data is held in access controlled systems, transmitted over encrypted connections, and reachable only by people who need it. No system is perfectly secure, but if a breach occurred that put your rights at risk, we would tell you and the ICO within 72 hours as the law requires.

12. Children

Nothing here is aimed at anyone under 18, and we do not knowingly collect their data. If you believe a child has given us information, tell us and it will be deleted.

13. Changes to this policy

If this policy changes materially, the date below the title changes with it, and anyone on the mailing list is told. Please look at it occasionally.

14. Contact

Questions, requests or complaints about your data all go to the same place. Email [email protected], or write to Brightrose, London, United Kingdom.

Anything unclear

Just ask

Data questions are answered by me, not a ticketing system. Read the terms too if you are about to buy something.