Privacy Statement
Introduction
Gemma Gilbert Ltd is a company registered in England and Wales (company number 12496440) with a registered address of 7 Chaworth Road, West Bridgord, Nottingham, Nottinghamshire, United Kingdom, NG2 7AE (‘we’, ‘our’, ‘us’ in this privacy statement).
Gemma Gilbert Ltd is responsible for collecting, processing, storing and safe-keeping personal and other information as part of providing a service and carrying out our regular business activities. We manage personal information in accordance with data protection legislation including the Data Protection Act 2018 and we are registered as a Data Controller with the Information Commissioner’s Office Registration Number ZB403369
Any questions regarding our processing of personal data should be directed to us via gemma@gemmagilbert.com.
Data processing principles
We take protecting online privacy and data security seriously. Please read the whole of this statement carefully as it sets out our approach to processing personal data including what information we may collect from you, how we may use it, store it and protect it, and your rights as a data subject.
Our Privacy Statement outlines our approach to any kind of data processing where we are acting as a data controller or co-controller (including collection, use, transfer, storage and deletion) of personally identifiable information (any information that may be used to identify a physical person, and any other information associated therewith) about natural persons. This statement applies to our processing of data collected through any means, actively as well as passively, from persons located anywhere in the world.
We are guided by the following principles when processing data:
1. We will only collect data for specific and specified purposes;
2. We will not collect data beyond what is necessary to accomplish those purposes; we will minimise the amount of information we collect from you to what we need to deliver the services required;
3. We will collect and use your personal information only if we have sensible business reasons for doing so, such as making available to you our services and products;
4. We will not use your data for purposes other than those for which it was collected, accepted as stated within our policy, or with your prior consent;
5. We will seek to verify and/or update your data periodically and we will accept requests from you for amendment of the data held;
6. We will apply high technical standards to make our processing of data secure;
7. Except otherwise stated, we will not store data in identifiable form longer than is necessary to accomplish its purpose or as required by law.
What information we collect
In accordance with Data Protection Legislation we only collect and process information which we require to meet the specific purposes as stated above. The information we may collect about you could include, but is not limited to:
1. Contact details;
2. Personal details and identifiers;
3. Bank details and financial information;
4. Details about your occupation and business;
5. Details about your lifestyle and social circumstances;
6. Your aspirations and career ambitions;
7. Personal development goals and targets;
8. Details about how you use our website including technical data such as IP address.
Occasionally we may ask for special category data if necessary for delivery of a particular service or product, such as medical information. Any such special category data will only be collected with your express consent and will be handled in line with ICO best practice guidelines for special category data. As per our Data Processing Principles we will only ask for information that is necessary to deliver our services, and therefore we encourage you not to provide us with personal data or special category data which we do not ask for.
How we collect, use and share personal data
Most personal information is provided directly and voluntarily by you when you engage with us in order to enquire about, or purchase, our services or products. We will collect information from you when:
1. You sign up to our newsletter or mailing list;
2. You download an opt-in;
3. You book onto a course, event or programme we are running;
4. You contact us for information via our website or social media channels, by phone or email;
5. You post on our social media channels, website or blog;
6. You work with us in a commercial capacity.
We may also collect personal information about you from third party sources, such as when you choose to connect your social media accounts with our site or log in through a social media platform such as Facebook or Instagram. However, we will only use this information where these third parties either have your consent or are otherwise legally permitted or required to share your personal information with us.
We collect this information in order to make available to you our services or products and to communicate with you in relation to our services or products. We may use the information collected to:
1. Allow us to process a booking for a product or service which you purchase from us;
2. Create a profile for you on our client database;
3. Send you our newsletters and/or provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes;
4. Respond to enquiries you make about our services or products;
5. Ask you to take part in surveys or quiz events;
6. Ensure that content from our site is presented to you in the most effective manner for you and your computer or device;
7. Allow you to access and utilise the service or product you have purchased from us;
8. Notify you about changes to our services or products;
9. Provide personalised content and advertising that is targeted to your interests;
10. Get feedback from you regarding the quality of our services or products.
We will not sell or lend your personal data to third parties, or share your personal data for marketing purposes without your express consent. We will only share your personal data with third party service providers where it is necessary for the delivery of our products or services, and only where we are confident that and such third party service providers have appropriate data protection systems and measures in place that are compliant with UK Data Protection Legislation.
We will not give consent to third party service providers or platforms to use your information, including audio and video recordings, for purposes, other than those for which the information was collected and which are necessary for the delivery of our products and services. We will not give consent for your information to be used by third party service providers for the training and development of AI modelling software, or similar purposes.
How we store and transfer your information
We have in place appropriate technical and organisational measures to ensure the security, confidentiality, integrity and availability of personal data we control. Your information is securely stored on our company cloud storage database and our third-party CRM system, Dubsado, which is not publicly accessible or stored in any public domain – it is accessible to our employees and affiliates only, and is password protected. Your information may also be stored on our third-party email marketing platform, Convertkit. Our third-party provider has their own privacy policy which you can view on their website.
We may store or process your data on cloud based platforms or service providers whose servers are based outside of the UK/EEA which may constitute a transfer of data under GDPR. We will only use such third party service providers where we are confident that appropriate safeguards are in place to ensure that any personal data transferred outside of the UK/EEA is subject to an equivalent level of security and protection as required under UK Data Protection Legislation, such as the UK Extension to the EU-U.S. Data Privacy Framework. To learn more about the EU-U.S. Data Privacy Framework, visit the U.S Department of Commerce’s website at: Home (dataprivacyframework.gov)
We also have in place appropriate procedures to handle any potential Personal Data Breaches, in accordance with Data Protection Legislation. Any such breaches will be reported to the relevant supervisory authority and notified to the affected data subjects where we are legally required to do so.
We will only keep your personal data for as long as is necessary to meet the requirements for which it was collected. This will vary depending on the nature of the requirements and the processing, but apart from in exceptional circumstances where longer retention is necessary we will only retain your personal data for 6 years. After this period of time we will delete your personal data unless there is a legitimate business reason to retain all or parts of the data we hold.
Legal basis for processing your data
The General Data Protection Regulation (GDPR) provides that processing of your data shall only be lawful if and to the extent that at least one of the following applies:
1. You have consented;
2. For the performance of a contract;
3. For compliance with a legal obligation which we must perform;
4. To protect the vital interests of your or another person;
5. It is in the public interest;
6. It is in the legitimate interests pursued by us or a third party.
We collect data for the purposes set out above. All personal data is managed to ensure that it is either erased from our system when it is no longer required for the purpose for which it was collected, retained for legal reasons or minimised and retained.
Any special category data collected from you has special protection and is limited to that permissible by law. In all instances where special category data is collected we will obtain your express consent.
Your legal rights as a data subject
You have a number of legal rights in relation to the personal data that we hold about you and you can exercise your rights by contacting us using the details at the end of this statement. These rights include:
the right to obtain information regarding the processing of your personal data and access to the personal data which we hold about you. If you wish to access your personal data please email us at the address provided in this statement;
the right to withdraw your consent to our processing of your personal data at any time. Please note, however, that we may still be entitled to process your personal data if we have another legitimate reason (other than consent) to do so;
in some circumstances, the right to receive some personal data in a structured, commonly used and machine-readable format and/or request that we transmit those data to a third party where this is technically feasible. Please note that this right only applies to personal data that you have provided to us;
the right to request that we correct your personal data if it is inaccurate or incomplete;
the right to request that we erase your personal data in certain circumstances. Please note that there may be circumstances where you ask us to erase your personal data but we must retain it;
the right to request that we restrict our processing of your personal data in certain circumstances. Again, there may be circumstances where you ask us to restrict our processing of your personal data but we must refuse that request;
the right to lodge a complaint with the applicable data protection regulator, in the UK this is the Information Commissioner’s Office (ICO).
when we are processing on the grounds of legitimate interest, you have the right to object to the processing and we must stop unless we have an overriding reason which will be communicated to you.
Links from our website
Our site contains links to and from other websites which are operated by individuals and companies over which we have no direct control. If you follow a link to any of these websites, please note that these websites have their own privacy and terms of use polices. We do not accept any responsibility or liability for these policies. We advise you to check the policies for third party sites before you submit any personal data to the website.
Marketing emails
We may send you marketing emails and communications when you have opted in or otherwise given consent for us to do so. We will make it as easy as we can for you to opt out of unwanted processing, providing it does not restrict our ability to provide you with the primary service you have requested.
Please note if you wish to unsubscribe from any marketing emails that you have signed up for, you can do so by emailing gemma@gemmagilbert.com or clicking onto the unsubscribe link on the marketing email that was sent to you. It may take 24 hours for this to become effective.
Cookies and website analytics
We use website analytics to provide the best user experience and service to you and to evaluate and improve our site. We utilise third party data analytics service providers to improve our visibility and to monitor website browser behaviour and navigation across our site.
These third-party data analytics service providers collect this information using cookies on our behalf in accordance with our instructions and in line with their own privacy policies. Our service providers may collect the following data about the way you use our site, which will almost always be anonymised and aggregated before reporting back to us:
Number of visitors to our site;
Pages visited whilst using the site and time spent per page;
Page interaction information, such as scrolling, clicks and browsing methods;
Source location and details about where users go when they leave the site;
Page response times and any download errors;
Technical information relating to end user devices, such as IP address or browser plug-in
From time to time we may use the information collected about you to present you with targeted advertisements using platforms such as Facebook, X (formerly known as Twitter), Google and/or Instagram.
If you wish to limit or reject cookies associated with our website you can do this in your browser settings. Please be aware that by choosing to limit or reject cookies from our website may you may not be able to use or benefit from certain features, particularly the features designed to personalise your experience.
Changes to our policy & future processing
This Privacy Policy was last updated on 10 July 2025 and is reviewed every 6 months, or upon changes to relevant Data Protection Legislation being published, whichever is sooner.
We do not intend to process your personal information except for the reasons stated within this privacy notice. We reserve the right to update this Privacy Notice from time to time. Where appropriate, we shall contact you to notify you of any material changes to the Privacy Notice. You should also refer to our website periodically so that you may access and view our updated Privacy Notice. This will ensure that you understand how we are using your personal data and your legal rights around our usage of such personal data.
If you have any questions or concerns regarding our data protection or privacy policies, please contact us at gemma@gemmagilbert.com and we will be happy to respond to any concerns.
Should you still have concerns about the way in which we manage your personal data then you should contact the relevant supervisory authority, which in the UK is the Information Commissioner’s Office: Contact us | ICO