Privacy Policy
Here’s all the info you need to know how I comply with the Data Protection Act (DPA), the General Data Protection Regulations (GDPR) and the Privacy and Electronic Communications Regulations (PECR). I’ve made it as short and as clear as I can, but it’s still pretty boring.
Can't be bothered to read it all? Here's the gist
I am, as the popular meme goes, some sort of permanently exhausted pigeon who has neither the time, inclination nor skill to do anything scammy with your information.
I collect and store information that is necessary for me to manage my business – contact details for clients so I can actually speak to you, notes from our sessions because my memory isn’t good enough to remember everything that we talk about, details of purchases you have made (although no payment processing details are held – all of that goes through Stripe) for HMRC and, for anybody who agrees to me doing so, clients or not, email addresses so I can send you information about services that you may be interested in, blog posts, special offers etc.
My website is set up to track usage – which pages get visited most and by people in which areas of the world. I believe this includes your IP address but I have no idea how to find them and wouldn’t know what to do with them if I did.
Comments
If you comment, some anonymised data (a hash) may be sent to the Gravatar service to see if you are using it. If you are, your profile picture will be visible next to your comment after approval and publication. The Gravatar service privacy policy is available here: https://automattic.com/privacy/.
Site Analytics
I use Google Analytics to track how many of you wondrous people are visiting my site, which pages you spend most time looking at and where in the world you are.
I’m told this also collects your IP address but I don’t know how they work and almost certainly have a whole acre of paint to watch drying before I have any desire to learn what they can be used for.
Data Storage
Okay, so this is the juicy bit!
I store your data in a couple of different places for different reasons, depending on what data I hold on you and why:
This website – If you leave a comment or register an account (you can’t do this yet, but maybe in the future), that data will be stored here. Only I and my amazing tech buddy have access to this and as we are both
Active Campaign – If you sign up to my email list or for anything that has to be emailed to you, this will be done via Active Campaign. They tell me they are GDPR compliant and if you get fed up and want to stop them, you can click on the unsubscribe button at the bottom of any email. I also use Active Campaign for my CRM system and it stores information on whether you open emails I send you, if you click on any of my website links
Acuity Scheduling – If you book any sessions with me, Acuity will collect and store your name, contact details (email and phone number). The type and
Zoom.us – Name and appointment
Googledrive – All documents, spreadsheets, and other files related to our interactions are securely stored in Google Drive. This includes contracts, invoices, and any work-in-progress files. Google Drive is secured with encryption, and I follow strict access controls to ensure that only I and authorized collaborators have access to these files. Regular backups ensure that your data isn’t lost in case of technical failures.
Paperform – When you fill out forms on my site, such as feedback forms or sign-up sheets, this data is managed through Paperform. Paperform ensures that your data is stored securely and is GDPR compliant. Only authorised personnel (that’s me and occasionally a designated assistant) have access to this information, which is used solely to respond to your inquiries or manage your requests.
Heights Platform – If you participate in any online courses or workshops I offer, your enrolment and progress information are managed through Heights Platform. This includes your registration details, course progression, and any submissions or tests. Heights Platform complies with all relevant privacy laws ensuring that your educational data is handled responsibly and with respect.
Pabbly Connect – I use Pabbly Connect to automate workflows between apps. For example, when you sign up for a webinar, Pabbly Connect helps in registering your information across platforms like Zoom and Active Campaign seamlessly. Your data is only used to automate processes you’ve engaged with, and Pabbly’s robust security measures ensure your information is protected at all times.
Payment Details
When you book any sessions with me or buy any products/courses, you will pay through Stripe. I don’t see any card or bank details at all. Stripe is GDPR compliant, more details here:https://stripe.com/privacy-center/legal.
Email Marketing
If you want to join my email list, you can add your email address in the appropriate box on my website.
I currently send out 1 email per week. It will arrive in your inbox at, or close to, 6am on Saturday mornings (UK time).
There is an unsubscribe link at the bottom of every email though so if even my infrequent and irregular emails are too much, just click the link and Active Campaign will automatically remove you from the list.
Your right to be deleted
If you want to do that very British thing of avoiding eye contact, pretending that we’ve never met, email helen@helensoutar.com and I will delete all information I hold on you, bar details of payments made (HMRC makes me keep this for at least 6 years after the end of the tax year it relates to).
Embedded content
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.