Privacy Policy
How we collect, use and protect your personal data when you use this website, our business healthcheck survey, our business plan tool, or get in touch with us.
On this page
- Who we are
- Information we collect
- The healthcheck survey & business plan tool
- How we use your information
- Our legal basis for processing
- Who we share information with
- International transfers
- How long we keep information
- Keeping your information secure
- Your rights
- Cookies
- Children
- Changes to this policy
- Contact us & complaints
Cliffen Consulting is committed to protecting and respecting your privacy. This policy explains what personal data we collect when you use this website — including our contact form, our free business healthcheck survey, and our business plan tool — why we collect it, and what your rights are. Please read it alongside our Terms of Use and Cookie Policy.
1. Who we are
This website, cliffen-consulting.com, is operated by Training Course Broker Ltd, trading as Cliffen Consulting (“we”, “us”, “our”). We are a company registered in England and Wales under company number 10855487, with our registered office at 8 The Fieldings, Sutton in Ashfield, Nottinghamshire, NG17 2TF, UK. Our VAT number is 275 3633 87. We are registered with the UK Information Commissioner's Office (ICO) under reference ZA271501.
For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for the personal data described in this policy.
2. Information we collect
We only collect the information you choose to give us, and a small amount of technical information needed to keep the site working and secure.
Information you give us
- Contact form. Your name, email address, phone number, an optional website address, and the subject and content of your message.
- Business healthcheck survey. Your first name, last name, job title, email address, phone number, company name, how long the business has been trading, number of employees, a description of what the business does, and your answers to the survey questions.
- Business plan tool. Whatever you choose to enter into your plan — for example financial figures, team member details, SWOT analysis, overheads, and product or service information — plus any logo or team photo you upload.
- Appointment booking. Your name, email address and the details needed to schedule a call with us.
- Administrator & associate accounts. If you register as a site administrator or associate/adviser, we collect your name, email address, username, and a securely hashed password (we never store your password in readable form). If you choose to sign in with Google, we receive your Google account email and a unique identifier from Google — we do not receive your Google password.
Information we collect automatically
- Technical information, including your IP address, browser type, and general device information, collected automatically when you visit any page.
- Cookies, used to keep you signed in, remember your cookie preferences, and (only if you consent) for analytics. See our Cookie Policy for full details.
3. The healthcheck survey & business plan tool
Because these two tools involve some processing that isn't obvious from the forms themselves, we want to be specific about them:
- Approximate location. When you register for the business healthcheck survey, we use your IP address to look up your approximate location (country, region and city) via a third-party geolocation service, ip2location.io. This is used only to understand where our visitors are based, and is not precise enough to identify your exact address.
- Business plan access. The business plan tool does not require you to create an account or password. Instead, each plan is accessed using a long, randomly generated link that is unique to your plan. You are responsible for keeping this link private — anyone with the link can view and edit that plan. If you believe your plan link has been shared without your permission, please contact us and we can help.
- Survey and plan results. We may use anonymised or aggregated healthcheck results (i.e. with anything that could identify you removed) to understand common issues facing the businesses we work with, and to improve our services. We will not publish or share your individual, identifiable results without your permission.
4. How we use your information
We use the information we collect to:
- respond to your enquiry, and provide the advice, coaching or service you have asked us for;
- run the business healthcheck survey and generate your results;
- save and let you return to your business plan;
- arrange and remind you about booked appointments;
- send you a confirmation or receipt after you submit a form (for example, an autoreply after a contact form enquiry);
- administer, secure and improve this website, including detecting and preventing spam or abuse (see our use of reCAPTCHA below);
- meet our legal and regulatory obligations; and
- where you have separately agreed to this, send you occasional updates about our services.
We do not use your data to make automated decisions that produce legal or similarly significant effects on you.
5. Our legal basis for processing
We rely on the following legal bases under UK GDPR:
- Contract — to provide a service you have asked us for, such as arranging an appointment or producing your healthcheck results.
- Legitimate interests — to respond to enquiries, keep our site secure, and understand how our services are used, in a way that we consider does not override your own interests and rights.
- Consent — for anything optional, such as marketing communications or non-essential cookies. You can withdraw consent at any time.
- Legal obligation — where we are required to keep or disclose information by law.
6. Who we share information with
We do not sell or rent your personal data. We share it only where necessary, with:
- Service providers who help us run this site — our website hosting and database provider, our email delivery provider (used to send enquiry confirmations, appointment details and, where applicable, marketing emails), Google reCAPTCHA (spam and bot protection on our forms), and ip2location.io (approximate location lookup for the healthcheck survey, as described above). Each of these providers only processes data on our instructions and for the purpose we've engaged them for.
- An associate or adviser you choose to contact. If you use the contact form or booking system to reach a specific associate, the details you submit are shared with that associate so they can respond to you.
- Legal and regulatory bodies, where we are required to disclose information by law, or to protect our rights, property or safety, or that of others.
- A buyer of our business, in the event that we sell or transfer all or part of our business — you would be told if this happened and if it affects how your data is handled.
7. International transfers
Some of the third-party services we use (for example, Google reCAPTCHA and Google Fonts) may process data on servers outside the UK. Where this happens, those providers are responsible for ensuring an adequate level of protection is in place, such as the UK's international data transfer safeguards or the provider's own certified transfer mechanisms.
8. How long we keep information
We keep personal data for as long as reasonably necessary for the purpose it was collected, and no longer. As a general guide:
- Contact form, appointment and business healthcheck survey enquiries are kept for up to 24 months from your last contact with us, then deleted or anonymised, unless you go on to become a client or associate — in which case your data continues under whichever of the periods below then applies.
- Business plan tool data is kept for as long as you're actively using your plan. If a plan has been untouched for 12 months, we treat it as inactive and delete it shortly afterwards; you're welcome to return and pick it up at any time before then.
- Administrator and associate account data is kept for as long as the account is active, plus up to 6 years afterwards, in line with our accounting, tax and contractual record-keeping obligations.
We review what we hold periodically and delete or anonymise data we no longer need. If you would like us to delete your data sooner, see Your rights below.
9. Keeping your information secure
We take the security of your data seriously. Passwords are never stored in readable form, sensitive pages are only accessible over an encrypted (HTTPS) connection, and we apply industry-standard protections against common web attacks. No method of transmission over the internet is completely secure, so while we work hard to protect your data, we cannot guarantee the security of data you send to us — any transmission is at your own risk.
10. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Erase your data, in certain circumstances (“the right to be forgotten”);
- Restrict or object to our processing of your data;
- Receive a copy of your data in a portable format; and
- Withdraw consent at any time, where we rely on consent.
To exercise any of these rights, contact us using the details below. We will normally respond within one month.
11. Cookies
We use a small number of cookies to run this site, remember your cookie preferences, and — only if you agree — for analytics. Full details, including exactly which cookies we use and how to change your preferences, are in our Cookie Policy.
12. Children
Our services are aimed at business owners and professionals. We do not knowingly collect personal data from children, and this website is not intended for use by anyone under 18.
13. Changes to this policy
We may update this policy from time to time, for example to reflect changes to our services or to data protection law. We will post any changes on this page with an updated date at the top. We encourage you to review this page occasionally.
14. Contact us & complaints
If you have any questions about this policy, or want to exercise any of your rights, please contact us or write to us at Training Course Broker Ltd, 8 The Fieldings, Sutton in Ashfield, Nottinghamshire, NG17 2TF, UK.
If you're not satisfied with our response, you have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
