PRIVACY POLICY
1. Introduction
We are Confidence with SJ Ltd t/a Her Pathway, a provider of an online platform (cloud-based software product) for women's workplace wellbeing, career development and coaching. This privacy policy sets out the types of personal information we collect about you when you use our platform and we provide services to you, or when you provide services to us, how we use and store that personal information, who we share it with, and what rights you may have in respect of your personal information. Our services are not intended for children and we do not knowingly collect data relating to children.
Confidence with SJ Ltd t/a Her Pathway is the controller and responsible for your personal information (we refer to Confidence with SJ Ltd t/a Her Pathway as "we", "us" or "our" in this privacy policy). Where we instruct our suppliers, clients and other third parties to use your personal information, these data processors will process your information on our behalf and only on our instructions and for the purposes set out in this privacy policy. If you have any questions about this privacy policy or our privacy practices, please email us at confidencewithsj@gmail.com.
This privacy policy is about the rights of individuals. While we are also committed to protecting the information we receive from and about companies, this policy is not about them.
2. Personal information we collect about you
Personal information (or personal data) means any information about you from which you can be identified. It does not include information where your identity has been removed (this is anonymous data).
We may collect and use the following personal information about you:
- Identity Data including your first name, last name, username or similar identifier, date of birth (where voluntarily shared), gender, employment history, professional background, job title and function. We may also collect identity-related information through journalling or coaching interactions, such as life-stage, caring responsibilities, or leadership aspirations, where disclosed voluntarily;
- Contact Data including your email;
- Financial and Payment Data including your billing information and payment card details processed securely via our third-party payment provider. We do not store full card details on our servers. We may collect purchase history and subscription details (e.g. freemium to premium upgrades). We do not carry out credit checks;
- Technical Data including IP address, login data, device type, browser type and version, time zone setting, approximate location, operating system, and device information used to access our website or app. We may also collect diagnostic and usage data for app improvement and support;
- Profile Data including username and password, coaching or journalling activity (if logged into the app), mood check-in responses, preferences and engagement patterns, any user feedback or survey responses, and interests related to personal development or wellbeing. We may also collect publicly available profile data (e.g. LinkedIn) if you choose to link external accounts;
- Usage Data including information about how you interact with our website and app, including session length, features used, buttons clicked, and content viewed. This helps us understand usage patterns and improve the user experience. To learn more about how we use cookies or similar technologies, please see our Cookies Policy here;
- Marketing and Communications Data including your preferences for receiving updates from us, including news about new pathways, features, events or offers. You may also choose how and when you prefer to be contacted (e.g. email or in-app notifications);
- Special Categories of Personal Data: In the course of our providing services to you we may need to collect, use and/or otherwise process your sensitive personal information (namely information about your racial or ethnic background, physical or mental health (including menopause, stress, trauma, and burnout experiences), neurodiversity, gender identity, sexual orientation, and lived experience of discrimination or caregiving). These may be shared voluntarily by you in journalling, coaching, or onboarding content. We only collect this information where you choose to share it with us and where it is necessary to provide trauma-aware, tailored support as part of our services. We may do so if we have obtained your prior consent to such processing, but also in circumstances permitted by law, namely where such processing is necessary for our compliance with employment and social security and social protection law; is necessary for the protection of your vital interests in situations where you are physically or legally unable to give consent; relates to personal sensitive personal information about you that you have made public; is necessary for reasons of substantial public interest; or is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.
If you provide information to us about any person other than yourself, you must ensure that they understand how their information will be used, and that they have given their permission for you to disclose it to us and for you to allow us, and our outsourced service providers, to use it.
3. How we collect your personal information
Generally, we collect your personal information directly from you – by telephone, email and through your use of our website and platform. In particular, this may occur in the following circumstances:
- when you or your organisation seek our products and/or services or use any of our online services;
- when you or your organisation offer to provide, or provides, products and/or services;
- when you correspond with us by phone, email or other electronic means, or in writing, or when you provide other information directly to us;
- when you create an account on our website or within our software;
- when you subscribe to our service or publications;
- when sign up to attend and/or attend our events, or sign up to receive marketing communication and offers from us, including offers for training;
- when you enter a competition, promotion or survey; and
- when you give us feedback or contact us.
We may also collect information about you indirectly, including:
- from publicly accessible sources, e.g. Companies House;
- from third parties, e.g. sanction screening providers or credit reference agencies;
- from third parties with your consent, e.g. your bank;
- from cookies saved by our website in your browser; and
- through our IT systems monitoring your interaction with us.
4. How we use your personal information
Under data protection law, we can only use your personal information if we have a proper reason for doing so, for example:
- for the performance of our contract with you or to take steps at your request before entering into a contract;
- to comply with our legal and regulatory obligations;
- for our legitimate interests or those of a third party; or
- where you have given consent.
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.
Generally, we do not rely on consent as a legal basis for processing your personal information although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with the rules set out in this section, where this is required or permitted by law.
We may also request your consent to process Special Categories of Personal Data or process this data without your consent where this is required or permitted by law.
We will use your personal information for the following purposes and on the following grounds:
- On the basis of fulfilling our contract with you or entering into a contract with you on your request, in order to:
- register you as a new customer and update our customer records;
- register you as a new supplier and update our supplier records;
- process and deliver your order, including sending you updates and managing payments, fees and charges;
- manage your user account; and
- deal with and respond to requests, enquiries and complaints.
- On the basis of our legal obligations, we process your personal information when it is necessary:
- for compliance with tax, accounting, anti-money laundering and other applicable law and obligations which we are subject to;
- for managing your statutory rights;
- for notifying you about changes to our terms or privacy policy; and
- for ensuring security of your personal data by preventing unauthorised access to it.
- On the basis of our legitimate interest, we will use your personal information for:
- allowing effective performance of our business by ensuring necessary internal administrative, commercial, and security processes (including in finance, controlling, business intelligence, legal & compliance, information security);
- verifying your identity, assessing your creditworthiness, and preventing and detecting fraud against you or us;
- collecting and recovering money you owed to us;
- asking you to provide feedback, leave a review or take a survey;
- sending you information about and enabling you to participate in events (including online events) organised by us (with or without another party), including seminars, charity events, prize draws and competitions; and surveys, marketing campaigns, market analysis or other promotional activities;
- communicating with you and keeping you up-to-date on the latest developments, announcements, and other information about our services, events and initiatives;
- analytics about your use of our website, our services to improve the platform, our services, marketing, customer relationships and experiences;
- preventing unauthorised access and modifications to systems;
- carrying out and dealing with security-related tasks, such as troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data; and
- establishing, exercising and/or defending our legal rights.
5. Promotional Communications
We may use your personal information to send you updates (by email, text message, telephone or post) about our services, including exclusive offers, promotions or information about new products and/or services.
We have a legitimate interest in processing your personal information for promotional purposes (see above). This means we do not usually need your consent to send you promotional communications. However, where consent is needed, we will ask for this consent separately and clearly.
We will not sell your personal information to or share it with other organisations for marketing purposes.
You have the right to opt out of receiving promotional communications at any time by contacting us at confidencewithsj@gmail.com or updating your marketing preferences in your user profile on our website.
We may ask you to confirm or update your marketing preferences if you instruct us to provide further products and/or services in the future, or if there are changes in the law, regulation, or the structure of our business.
6. Who we share your personal information with
We routinely share personal information with service providers we use to help deliver services to you, such as security providers and payment service providers. We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, e.g. in the audit of our accounts;
We may also share personal information with:
- credit reference agencies who may, for example, supply anti-fraud and credit-insight information to us;
- social media companies and our advertising partners. For example, we might match your email address with Facebook and Twitter to enable us to run promotions on their platforms;
- our professional advisors such as our lawyers or auditors when they need to give us their professional advice;
- public authorities, agencies and other government bodies. We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations;
- potential corporate buyer. We may also share some personal information in the case of transfer of some or all of our business, during re-structuring or change of ownership of the business. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations;
- our insurers or brokers. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations; and
- our banks. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.
Your personal information may be held at our offices and those of our service providers, representatives and agents as described above. Some of these third parties may be based outside the United Kingdom. For more information, including on how we safeguard your personal information when this occurs, see Section 9 below.
7. How long your personal information will be kept
We will keep your personal information while you have an account with us or we are providing services to you. Thereafter, we will keep your personal information for as long as is necessary:
- to respond to any questions, complaints or claims made by you or on your behalf;
- to show that we treated you fairly; and
- to keep records required by law.
We will not retain your personal information for longer than necessary for the purposes set out in this policy. Different retention periods apply for different types of personal information. If you want to learn more about our specific retention periods for your personal information, please contact us.
When it is no longer necessary to retain your personal information we will securely destroy your personal information in accordance with applicable laws and regulations. In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
8. International transfers of your personal information
We do not generally transfer your personal information abroad.
If, to deliver our services to you, it is necessary for us to share or transfer your personal information outside the United Kingdom, then some additional safeguards will apply.
Where we need to make a transfer of this nature, we will only do so if such a transfer is safe and your personal information will be secure.
This means that when we transfer your personal information outside the UK we will only do so where (i) there are binding corporate rules in place; or (ii) the country where we are making the transfer to is a country deemed by the UK Information Commissioner's Office to have an adequate level of protection in place for your personal information; or (iii) if there is no adequacy decision, where we have a lawful contractual arrangement with the service provider containing protections for your personal information (i.e. an international data transfer agreement).
Please contact us if you want further information on the mechanisms used by us when transferring your personal information out of the UK.
9. Your rights
Under the applicable data protection laws you have a number of rights, as set out below:
- Right to access your personal information. You may request confirmation that we hold personal information about you, as well as access to a copy of any such data.
- Right to rectification. You may ask us to correct any inaccurate information we hold about you.
- Right to erasure (or Right to be forgotten). You may, in certain circumstances, ask us to delete your personal information.
- Right to restriction. You may ask us to restrict the processing of your personal information if (i) you want us to establish the accuracy of the information, (ii) where our use of the information is unlawful but you do not want us to erase it, (iii) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims, or (iv) you have objected to our use of your personal information but we need to verify whether we have overriding legitimate grounds to use it.
- Right to portability. You may request the receipt of the personal information that you have provided to us, in a structured, commonly used and machine-readable form, or its transfer to another organisation.
- Right to object. You may object to our processing of your personal information (i) at any time when your personal information is being processed for direct marketing, or (ii) where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Right not to be subject to automated individual decision making. You have the right not be subject to a decision based solely on automated processing (or profiling) that produces legal effects concerning you or similarly significantly affects you.
- Right to withdraw consent. Where our processing of your personal information is based on your consent, you may withdraw this consent at any time, although this will not affect the lawfulness of any prior processing where we relied on your consent.
- Right to make a complaint. You may make a complaint about our processing of your personal information by contacting us via the contact details set out in this privacy policy. While we hope that we would be able to address any issues you have in respect of this processing, you may also make a complaint to the UK's data protection regulator (see below).
For further information on each of these rights, including the circumstances in which they apply, please contact us or see the Guidance from the UK Information Commissioner's Office (ICO) on individuals' rights under the General Data Protection Regulation available via the following link: https://ico.org.uk/for-the-public/.
If you would like to exercise any of these rights, please contact us using our contact details set out below.
You will not have to pay a fee to access your data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
10. Keeping your personal information secure
We have put in place appropriate security measures to prevent personal information from being accidentally lost, used or accessed unlawfully, altered or disclosed. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
11. How to complain
We hope that we can resolve any query or concern you may raise about our use of your personal information.
The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns or telephone: 0303 123 1113.