GDPR Policy
Effective Date: 25th March 2025
This GDPR Policy outlines how Andrew T. Austin and The Fresh Brain Company Ltd (“we”, “us”, or “our”) collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR).
1. Who We Are
This website (https://www.23nlpeople.com) is owned and operated by Andrew T. Austin and The Fresh Brain Company Ltd, registered in England and Wales. For all data protection matters, you can contact us via the contact form on this website.
2. What Data We Collect
- Full name
- Email address
- Phone number (if provided)
- Postal address (if applicable)
- Payment details (where applicable, processed via secure third-party processors)
- Website usage data (such as IP address, browser type, and browsing behaviour)
3. How We Collect Your Data
We collect personal data through:
- Contact forms
- Newsletter sign-ups
- Event and course registrations
- Purchases and bookings
- Cookies and analytics tools
4. Why We Collect Your Data
We use your data for the following purposes:
- To respond to your enquiries and messages
- To manage course and event bookings
- To process payments
- To send you relevant updates and newsletters (with your consent)
- To improve our website and user experience
5. Legal Basis for Processing
We rely on the following lawful bases to process your personal data:
- Consent – when you opt in to receive communications
- Contract – when processing is necessary to fulfil a booking or purchase
- Legal obligation – where required to comply with the law
- Legitimate interests – to operate and improve our services
6. Data Sharing and Third Parties
We do not sell or rent your data. We may share it with trusted third parties to help us deliver our services, such as:
- Email marketing providers (e.g., Mailchimp)
- Payment processors (e.g., Stripe, PayPal)
- Website hosting and analytics services (e.g., Google Analytics)
All third parties are GDPR-compliant and only process data as necessary for the services they provide to us.
7. Data Storage and Security
Your data is stored securely on GDPR-compliant servers. We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure or destruction.
8. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law. When no longer needed, your data will be securely deleted or anonymised.
9. Your Rights Under GDPR
You have the following rights:
- The right to access your personal data
- The right to rectify inaccurate data
- The right to erase your data (“right to be forgotten”)
- The right to restrict processing
- The right to data portability
- The right to object to processing
- The right to withdraw consent at any time
- The right to lodge a complaint with the ICO (Information Commissioner’s Office)
10. Cookies
Our website uses cookies to enhance user experience and analyse website traffic. You can choose to accept or reject cookies when you visit the site. For more information, please see our Cookie Policy.
11. Changes to This Policy
We may update this policy occasionally to reflect changes in the law or our data practices. The latest version will always be posted on this page with an updated effective date.
12. Contact Us
If you have any questions or concerns about this policy or your data, please contact us via freshnewbrain@gmail.com