Privacy policy
What we collect, why, and what you can do about it. In plain English, because you should be able to read it.
Last updated 6 August 2026
The short version. We collect your name and email when you fill in a form, we use it to reply to you or to send you what you asked for, we never sell it, and you can have it deleted whenever you like by emailing [email protected]. Everything below is the detail.
On this page
1. Who is responsible
Brightrose is the data controller for personal data collected through brightrose.studio and brightrose.org. Brightrose is a trading name based in London, United Kingdom, founded by Paul Brightrose.
For anything about your data, email [email protected]. It comes straight to Paul, and it is answered personally.
This policy explains what is collected, why, how long it is kept and what you can do about it. It is written under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR where that applies to you.
2. What we collect
Only what is needed to reply to you or to deliver what you asked for.
Information you give us
- Name and email, whenever you submit any form on this site.
- Phone number, on the forms that request it, so a session can be confirmed.
- What you are building, or the challenge you are stuck on, where a form asks.
- Business stage and city, on the forms that ask, to judge fit.
- Booking details, when you schedule a call, including the time you chose and anything you write in the booking notes.
Payment information
When you buy something, card details go directly to our payment provider. We never see or store your full card number. We receive confirmation that payment succeeded, the amount, and what it was for.
Information collected automatically
- Technical data such as IP address, browser type, device and operating system.
- Usage data such as the pages you viewed, how long you stayed and where you arrived from.
What we do not collect
We do not ask for or want special category data. Please do not include health information, and note that coaching is not a medical or therapeutic service.
3. Why we use it, and our lawful basis
| What we do | Why | Lawful basis |
|---|---|---|
| Reply to an enquiry | You asked us something and expect an answer | Legitimate interests |
| Deliver a paid service | You bought coaching, a programme or a subscription | Performance of a contract |
| Send a free download | You asked for it | Consent |
| Send the newsletter | You opted in | Consent, withdrawable at any time |
| Assess an application | To decide whether a place is right for you | Legitimate interests, then contract |
| Keep financial records | Required for tax and accounting | Legal obligation |
| Measure how the site is used | To understand what is working | Consent, through the cookie banner |
| Show relevant advertising | To reach people like you | Consent, through the cookie banner |
Where we rely on legitimate interests, we have considered whether it is fair to you, and you can object at any time.
4. Marketing, and how to stop it
We only email marketing to people who asked for it, or to existing customers about closely related services, which UK PECR permits. Every email has a one click unsubscribe, and unsubscribing is honoured immediately.
You are never added to a list simply for booking a call or making an enquiry.
5. Cookies and similar technology
Cookies that are strictly necessary for the site to function are set without consent, as the law allows. Everything else, including analytics and advertising, is set only after you agree through the banner.
You can change your choices at any time using the consent icon in the bottom left of any page. Refusing does not restrict your use of the site.
Categories used
- Function. Needed for forms, booking and security. Always on.
- Measurement. Tells us which pages lead to enquiries. Optional.
- Marketing. Used to measure and target advertising. Optional.
Browser settings can also block or delete cookies, though some parts of the site may then stop working.
6. Who else processes your data
We use a small number of providers. Each one only handles what it needs to, under contract, and none of them may use your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| HighLevel | CRM, forms, booking calendars, email delivery | United States |
| Payment provider | Takes card payments securely | EU and United States |
| Cloudflare | Hosting security, performance, email obfuscation | Global |
| Analytics and tag management, only with consent | United States | |
| Google Fonts | Serves the typeface used on this site | United States |
We do not sell your personal data. We never have and we will not.
7. Transfers outside the UK
Some of the providers above are based in the United States, so your data may be transferred there. Where that happens we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework, depending on the provider.
If you would like to know which mechanism applies to a specific provider, ask and we will tell you.
8. How long we keep it
| What | Kept for |
|---|---|
| Enquiries that go nowhere | 24 months, then deleted |
| Newsletter subscribers | Until you unsubscribe, then removed |
| Client records | 6 years after the last engagement, for tax and legal reasons |
| Financial records | 6 years, as HMRC requires |
| Session notes | 12 months after the engagement ends |
| Analytics | 14 months |
9. Your rights
Under UK and EU data protection law you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong or incomplete.
- Delete it, where we have no continuing reason to keep it.
- Restrict what we do with it while a concern is resolved.
- Object to processing based on legitimate interests, including profiling.
- Receive it in a portable format, where processing is by consent or contract.
- Withdraw consent at any time, without affecting what was done before.
Email [email protected] and we will respond within one month. There is no charge.
If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but it is your right either way.
10. Automated decisions
No decision affecting you is made by automated means alone. Applications are read by a person, and that person is Paul.
11. Security
Data is held in access controlled systems, transmitted over encrypted connections, and reachable only by people who need it. No system is perfectly secure, but if a breach occurred that put your rights at risk, we would tell you and the ICO within 72 hours as the law requires.
12. Children
Nothing here is aimed at anyone under 18, and we do not knowingly collect their data. If you believe a child has given us information, tell us and it will be deleted.
13. Changes to this policy
If this policy changes materially, the date below the title changes with it, and anyone on the mailing list is told. Please look at it occasionally.
14. Contact
Questions, requests or complaints about your data all go to the same place. Email [email protected], or write to Brightrose, London, United Kingdom.
Just ask
Data questions are answered by me, not a ticketing system. Read the terms too if you are about to buy something.