Privacy Notice

1. Who we are

Be More Inspired Limited, trading as BeMore (we, us or our), provides training, mentoring and consultancy services. We are committed to protecting personal data and handling it fairly, lawfully and securely. We are registered with the Information Commissioner’s Office under registration number ZB929215.

Our role depends on the purpose and circumstances of each processing activity. We act as a Controller when we decide why and how personal data is used, for example for our own bookings, finance, marketing, supplier and business administration. We act as a Processor when we handle personal data on the documented instructions of a commissioning client. We may act in both roles within the same client relationship for different processing activities.

2. Personal data we collect

Depending on the service and our relationship with you, we may collect and use:

·         name, job title, organisation and business contact details;

·         training, webinar, event and attendance information;

·         communications, enquiries, calendar information and contract records;

·         feedback, evaluation responses, testimonials and impact information;

·         mentoring or consultancy records, including agreed objectives, actions and session administration;

·         billing, payment, supplier and associate information;

·         website usage, cookie preferences and marketing subscription or engagement information;

·         client data supplied to us for contracted work, including non-pupil-level DfE adviser casework data where applicable;

·         accessibility or other special requirements where necessary to provide a service safely and inclusively; and

·         security, incident, complaint and data-rights request records.

We do not seek pupil-identifiable information unless a commissioning client expressly instructs us to process it under an appropriate contract and approved procedure.

3. Special category data

We do not routinely request special category data. Where it is necessary, for example to make accessibility arrangements or meet a specific contractual requirement, we identify both an Article 6 lawful basis and an appropriate Article 9 condition before processing begins. Where required, we also meet the relevant Data Protection Act 2018 condition and maintain an appropriate policy document. When we act as a Processor, we handle such data only on the Controller’s documented instructions.

4. Where we obtain personal data

We may obtain personal data:

·         directly from you through enquiries, bookings, forms, contracts, feedback, meetings or correspondence;

·         from your employer, school, local authority or another organisation booking or commissioning a service;

·         from a commissioning client when we act on its behalf;

·         from suppliers, associates or professional advisers involved in a contract; and

·         automatically through our website or business systems, where permitted and described in this notice.

Where we receive personal data from another source, we provide or make available appropriate privacy information within the applicable legal timescale, unless an exemption applies or the Controller is responsible for doing so.

5. How and why we use personal data

Service delivery. We use personal data to administer bookings, communicate with participants, deliver training, mentoring or consultancy, record attendance and provide agreed support. Lawful basis: contract, legitimate interests, or our client's instructions where we act as a Processor.

Client reporting. We use attendance and delivery information to evidence the work and agreed outcomes to commissioning clients. Lawful basis: contract, legitimate interests, or our client's instructions.

Evaluation and improvement. We analyse feedback to improve our services and to produce anonymised or aggregated information about impact. Lawful basis: legitimate interests, and consent where you agree to a comment being attributed to you.

Business administration. We use personal data to manage contracts, associates, suppliers, invoices, accounts, insurance and our legal obligations. Lawful basis: contract, legal obligation and legitimate interests.

Marketing. We send newsletters and information to people who have chosen to receive them, and keep suppression records so that people who unsubscribe are not contacted again. Lawful basis: consent, in line with the Privacy and Electronic Communications Regulations.

Security and compliance. We use personal data to protect our systems, investigate incidents, respond to data rights requests and meet legal or contractual requirements. Lawful basis: legal obligation, legitimate interests, and our client's instructions where applicable.

Where we rely on legitimate interests, we document the interest pursued and consider whether the processing is necessary, proportionate and balanced against the individual's rights. The precise lawful basis depends on the purpose and relationship. For example, where an attendee is not personally party to a commissioning contract, legitimate interests or the commissioning client's instructions may apply, rather than a contract with the attendee.

6. Sharing personal data

We share personal data only where necessary and with appropriate controls. Recipients may include commissioning clients, local authorities, schools, authorised associates, approved technology and professional service providers, accountants, insurers, legal advisers and regulators.

Where training is commissioned by another organisation, we may provide it with attendance information and agreed reporting information. Feedback is normally shared in anonymised or aggregated form unless we have clearly explained that individual responses will be shared, the commissioning arrangements require this lawfully, or the individual has agreed that a comment may be attributed. We do not sell personal data.

7. International transfers

Some service providers may store, access or process personal data outside the UK. Where this involves a restricted transfer, we ensure that an appropriate UK transfer mechanism is in place, such as UK adequacy regulations or appropriate contractual safeguards. When we act as a Processor, we also follow the Controller’s contractual instructions and approval requirements and do not make a restricted transfer without the authority required by the contract.

8. Data security

We use proportionate technical and organisational measures including named user accounts, access controls, multi-factor authentication where supported, secure cloud storage, device protection, secure remote-working arrangements, recovery and version-history features, access reviews, staff and associate training, incident management and contract-specific controls. Access is limited to people who need it for their role and is removed when no longer required.

9. Retention and deletion

We keep personal data only for as long as needed for the purpose for which it was collected, contractual and audit requirements, legal obligations and the establishment or defence of legal claims. Our internal retention schedule sets review points and deletion or anonymisation actions. Client data processed on behalf of a Controller is returned or securely deleted in accordance with the contract and documented instructions.

Where data is retained in anonymised form, we assess whether an individual could reasonably be identified from the remaining information alone or in combination with other information available to us. Removing a name alone is not treated as sufficient where re-identification remains reasonably possible.

10. Marketing, cookies and analytics

We use HubSpot to manage marketing subscriptions. People join our marketing lists only by actively choosing to sign up. HubSpot records each contact’s subscription status, the source and date of consent and any unsubscribe, giving an auditable record. Marketing communications include an unsubscribe facility. We keep a minimal suppression record where necessary to ensure that a person who has unsubscribed is not inadvertently contacted again.

Our website uses cookies necessary for it to operate. With the visitor’s permission, it may also use analytics or other non-essential cookies to help us understand website use. Where consent is required, non-essential cookies are not activated until a choice is made. Visitors can change their preferences through the website’s cookie settings. The live cookie notice and configuration are reviewed when the website or embedded services change.

11. Your rights

Depending on the circumstances and lawful basis, individuals may have rights to access, rectify or erase their data; restrict or object to processing; receive portable data; and withdraw consent. Individuals may also complain to the Information Commissioner’s Office. We may need to verify identity before responding.

Requests should be sent to info@be-more.uk. We log requests, normally acknowledge them within five working days and respond within the statutory timescale, usually one month. Where we act only as a Processor, we pass the request promptly to the relevant Controller and provide reasonable assistance in accordance with the contract.

12. Automated decision-making

We do not use personal data to make solely automated decisions that have legal or similarly significant effects on individuals. If this changes, we will assess the processing and update this notice before it begins.

13. Contact and complaints

The Data Protection Lead is Tanya Petherick, Director. Contact: info@be-more.uk. Concerns should be raised with us first where possible. Individuals also have the right to complain to the Information Commissioner’s Office.

14. Updates to this notice

We review this notice at least annually and whenever our purposes, systems, providers, legal obligations or contractual arrangements materially change. Material changes are communicated through an appropriate channel.