mySMEleader Ltd
Last updated: 12 August 2026
1. Who we are
mySMEleader Ltd (“mySMEleader”, “we”, “us”, “our”) delivers a subscription-based leadership development programme for future SME business leaders.
We are the data controller for the personal information described in this policy.
|
Registered company name |
mySMEleader Ltd |
|
Company number |
16090365 (registered in England & Wales) |
|
Address |
Witney, OX28 4BH, United Kingdom |
|
|
|
|
Phone |
+44 7770 598 939 |
|
Website |
We are registered with the UK Information Commissioner’s Office (ICO), registration number ZB845540.
If you have any question about this policy or how we handle your information, email shyju@mysmeleader.com.
2. Scope of this policy
This policy explains how we collect, use, store and protect personal data when you:
- visit or interact with mysmeleader.com
- enquire about, register for, or subscribe to the mySMEleader programme
- participate in our live online sessions, modules or peer group activity
- subscribe to our newsletter or download resources
- attend an event or webinar we host
- contact us by email, phone or through social media
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
3. The personal data we collect
3.1 Information you give us
|
Category |
Examples |
When collected |
|
Identity & contact |
Name, job title, employer, work email, phone number, LinkedIn profile |
Enquiry forms, programme registration, newsletter sign-up, event bookings |
|
Programme data |
Learning objectives, module attendance, reflections and exercise submissions, peer discussion contributions, feedback and survey responses |
Throughout your participation in the programme |
|
Billing data |
Company name, billing address, VAT number, purchase order references |
Subscription set-up and invoicing |
|
Correspondence |
Emails, call notes, meeting notes, support requests |
When you contact us or we speak with you |
|
Marketing preferences |
Consent records, topic interests, unsubscribe status |
Sign-up forms and preference centre |
We do not ask for special category data (such as health, ethnicity, religion or political opinions). Please don’t share such information with us unless it is genuinely necessary — for example, an accessibility requirement for a live session, which we will handle on the basis of your explicit consent.
3.2 Information collected automatically
When you visit our website we may collect IP address, browser and device type, operating system, referring URL, pages viewed, time on page, and approximate location (city/region level). See Section 9 — Cookies for detail and how to control this.
3.3 Payment card information
We do not store or process your card details. Subscription payments are handled by our payment provider Stripe, who processes card or Direct Debit details under their own privacy terms. We receive only a transaction confirmation and the last four digits of the payment method.
3.4 Information from other sources
We may receive limited business-contact information from your employer (for example, when an organisation nominates delegates for the programme), from publicly available professional sources such as LinkedIn or company websites, and from event partners where you have consented to your details being shared.
4. How and why we use your data (lawful bases)
|
Purpose |
What this involves |
Lawful basis |
|
Delivering the programme |
Enrolling you, giving access to modules and live sessions, tracking progress, facilitating peer groups |
Contract — necessary to perform our agreement with you or your employer |
|
Billing and administration |
Invoicing, collecting subscription fees, managing cancellations and 30 days’ notice |
Contract and Legal obligation |
|
Responding to enquiries |
Answering questions, arranging calls, providing programme information |
Legitimate interests — responding to your request |
|
Newsletter and marketing |
Sending programme updates, leadership insights, event invitations and relevant offers |
Consent for new subscribers; Legitimate interests for existing clients and corporate contacts under PECR’s soft opt-in, always with a one-click unsubscribe |
|
Improving the programme |
Analysing feedback, attendance patterns and survey responses to refine modules |
Legitimate interests — improving our services |
|
Website analytics |
Understanding how visitors use our site |
Consent (via our cookie banner) |
|
Legal, accounting and tax records |
Retaining invoices and contracts; responding to regulators |
Legal obligation |
|
Protecting our business |
Fraud prevention, IT security, resolving disputes, enforcing our terms |
Legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm our interest does not override your rights. You may ask us for a summary of that assessment at any time.
Where we rely on consent, you may withdraw it at any time — this does not affect processing already carried out.
5. Marketing communications
If you have opted in to our newsletter, or you are an existing client or a business contact who enquired about the programme, we may email you programme updates, leadership content, event invitations and occasional related offers.
- Every marketing email contains a one-click unsubscribe link.
- You can also unsubscribe or change your preferences by emailing shyju@mysmeleader.com.
- Unsubscribing from marketing does not stop essential service emails (for example, session joining links, invoices, or programme schedule notices) if you are an active subscriber.
- We keep a suppression record of unsubscribed addresses so we don’t accidentally re-contact you.
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
6. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal or similarly significant effects about you. We may segment our mailing list by role, sector or engagement level so content is more relevant, but a person always reviews any material decision.
7. Who we share your data with
We share personal data only where necessary, and only with organisations that are contractually bound to protect it. Our categories of recipients are:
|
Recipient type |
Purpose |
Examples |
|
CRM and email platform |
Storing contact records, sending programme and marketing emails |
HubSpot |
|
Video conferencing |
Hosting live online sessions |
Zoom / Microsoft Teams |
|
Website hosting & forms |
Running mysmeleader.com and its enquiry forms |
WordPress, Typeform, Menti |
|
Payment and accounting |
Processing subscriptions, invoicing, bookkeeping |
Stripe, Xero |
|
Learning content delivery |
Hosting module materials and recordings |
Zoom, Microsoft Teams |
|
Programme facilitators and guest leaders |
Delivering sessions and case discussions |
Contracted facilitators, bound by confidentiality |
|
Professional advisers |
Legal, accounting and insurance advice |
As required |
|
Authorities |
Where legally required |
HMRC, courts, regulators |
Peer visibility: the programme is built on peer learning. Other participants in your cohort will see your name, job title, employer and any contributions you make in live sessions or group discussions. Please treat what other participants share as confidential, as we ask them to treat yours.
If our business is sold or reorganised, personal data may transfer to the acquiring entity, which will remain bound by this policy or an equivalent one.
8. International transfers
Some of our suppliers (including HubSpot) are based in, or store data in, the United States or other countries outside the UK. Where we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, being one or more of:
- a UK adequacy regulation for the destination country;
- the International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum; supported by a transfer risk assessment.
You can request details of the specific safeguard applying to a transfer by emailing us.
9. Cookies and similar technologies
Our website uses cookies and similar technologies.
|
Type |
Purpose |
Consent needed |
|
Strictly necessary |
Site security, load balancing, remembering your cookie choices, form functionality |
No — these are exempt under PECR |
|
Analytics / performance |
Understanding page views, traffic sources and site performance |
Yes |
|
Functional |
Embedded video, chat widgets, calendar booking tools |
Yes |
|
Marketing / tracking |
Measuring campaign performance; HubSpot and LinkedIn tracking of website activity linked to a contact record |
Yes |
Non-essential cookies are set only after you consent via our cookie banner. You can change or withdraw your choices at any time using the cookie settings link in our website footer, or by clearing cookies in your browser.
Most browsers also let you block or delete cookies through their settings. Blocking strictly necessary cookies may stop parts of the site working.
Our marketing emails may contain small tracking pixels that tell us whether an email was opened and which links were clicked. This helps us judge whether our content is useful. Disabling image loading in your email client prevents this.
10. How long we keep your data
|
Data |
Retention period |
|
Enquiries that don’t convert |
36 months from last contact, then archived |
|
Active subscriber records |
For the duration of your subscription |
|
Former subscriber programme records |
3 years after your subscription ends, so we can verify participation and issue confirmations |
|
Invoices, contracts and financial records |
6 years after the end of the relevant financial year (HMRC requirement) |
|
Newsletter subscriber data |
Until you unsubscribe, plus a minimal suppression record kept indefinitely to honour your opt-out |
|
Session recordings |
24 months, then archived |
|
Website analytics data |
Up to 26 months in aggregated form |
Where we no longer need data, we delete it securely or anonymise it so it can no longer identify you.
11. How we protect your data
We use appropriate technical and organisational measures, including access controls and least-privilege permissions, multi-factor authentication on business systems, encryption in transit (TLS) and at rest with our main suppliers, reputable suppliers with recognised security standards, secure device management, and contractual confidentiality obligations on facilitators and contractors.
No system is completely secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware and inform you without undue delay where the risk is high.
12. Your rights
Under the UK GDPR you have the right to:
|
Right |
What it means |
|
Be informed |
Know how we use your data — that’s this policy |
|
Access |
Get a copy of the personal data we hold about you |
|
Rectification |
Have inaccurate or incomplete data corrected |
|
Erasure |
Ask us to delete your data where there’s no overriding reason to keep it |
|
Restrict processing |
Ask us to pause processing while a concern is resolved |
|
Data portability |
Receive data you provided under consent or contract in a machine-readable format |
|
Object |
Object to processing based on legitimate interests, and object to direct marketing at any time — for marketing we will always stop |
|
Withdraw consent |
Withdraw consent where that’s our lawful basis |
|
Human review |
Not be subject to solely automated decisions with significant effects |
To exercise any right, email shyju@mysmeleader.com. We will respond within one month. If your request is complex or you’ve made several, we may extend this by up to two further months and will tell you why. There is normally no charge.
We may ask you to verify your identity before releasing data, to make sure it doesn’t go to the wrong person.
If you are unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13. Children’s data
Our programme and website are aimed at working professionals. We do not knowingly collect data about anyone under 18. If you believe we hold data about a child, contact us and we will delete it.
14. Third-party links
Our website and emails may link to third-party sites, such as LinkedIn or partner organisations. We are not responsible for their privacy practices — please read their own privacy notices.
15. Changes to this policy
We may update this policy to reflect changes to our services, technology or the law. The “last updated” date at the top will always show the current version. If we make a material change to how we use your data, we will tell you by email or a prominent notice on our website.
16. Contact us
mySMEleader Ltd
Witney, OX28 4BH, United Kingdom
Email: shyju@mysmeleader.com
Phone: +44 7770 598 939
Sources referenced when preparing this policy:
- mySMEleader Ltd company record, Companies House — https://find-and-update.company-information.service.gov.uk/company/16090365
- mySMEleader contact details — https://mysmeleader.com/contact-us/
- mySMEleader programme and subscription details — https://mysmeleader.com/
- UK Information Commissioner’s Office guidance — https://ico.org.uk
