Legal
Privacy Notice
How Human Formulas handles your personal information.
The short version. We collect the minimum personal information we need to do our work. We tell you why. We keep it secure. We do not sell it. You can ask to see it, change it, or delete it at any time.
Who we are
Human Formulas Ltd (referred to below as “we”, “us”, or “Human Formulas”) is an evidence-based employee engagement consultancy registered in England and Wales. This notice explains what personal information we collect from you, why, and what you can do about it. It applies to individuals in the United Kingdom, the European Economic Area, and anywhere else our services reach.
For questions or requests about your personal information, email us at claire@humanformulas.co.uk.
The information we collect, and why
We only collect personal information where we have a lawful reason to — meaning one of the legal bases set out in the UK GDPR and EU GDPR (the twin regulations that govern how organisations across the UK and European Economic Area handle personal data). The three we rely on are legitimate interest (we need the data to do the thing you’ve asked us to do or to run our business responsibly, and it’s a reasonable use of it), consent (you’ve actively opted in), and contract (we need it to deliver a service you’re paying for).
If you visit our website
What we collect: Basic technical information your browser sends automatically — IP address (the numeric label identifying your internet connection), browser type, device type, pages viewed, and the site you came from.
About IP addresses: This is standard for every website on the internet — the same information your web browser shares with any site you visit. We use it only to keep our site running, to spot and stop malicious traffic, and to understand which pages are being read. We do not use it to build a profile of you or to track you across other sites.
Why: To keep the site secure, functional, and to spot problems.
Lawful basis: Legitimate interest — every website operator has a legitimate interest in keeping their site safe and understanding how it is used.
How long we keep it: Server logs are retained for 90 days, then discarded.
If you sign up for our email list
What we collect: Your name, email address, place of work, and job title.
Why: To send you research, insights, event invitations, occasional updates on our work, and news about our services and offerings — including our forthcoming paper. We use your role and industry to make sure the content we send is relevant to you.
Lawful basis: Consent — you opted in, and you can opt out any time using the link at the bottom of every email.
How long we keep it: Until you unsubscribe or ask to be removed.
If you engage us for consulting work (including the diagnostic)
What we collect: Business contact details, your role, and any personal information you or your colleagues share with us as part of the engagement — including diagnostic responses, workshop input, interview notes, and project documents. Where the engagement involves your employees, we process their personal data on your behalf as your data processor (the party handling data under your instructions, while you remain the data controller).
Why: To deliver the consulting work you’ve engaged us for — whether that’s a diagnostic report, a workshop, a culture review, an executive advisory piece, or something else.
Lawful basis: Contract. Where diagnostic data is anonymised and aggregated, we also rely on legitimate interest to use it for improving our tools and methodology.
How long we keep it: For the duration of the engagement, plus 6 years afterwards for tax, insurance, and professional obligations. Anonymised aggregate data may be kept indefinitely.
If your organisation has commissioned training you’re attending
What we collect: Your name, work email, job title, organisation, any dietary or accessibility requirements you share for in-person sessions, and any feedback you give us afterwards.
Why: To register you for the session, deliver the training, and share follow-up materials. Feedback helps us improve future sessions.
Lawful basis: Legitimate interest — your organisation has commissioned the training, and we have a legitimate interest in delivering it well and keeping in touch with attendees who’ve asked us to.
How long we keep it: Attendance and delivery records: 3 years. Feedback: 12 months individually, then anonymised for our own analysis.
If you become a coaching client
What we collect: Your name, contact details, session notes, and anything you share during coaching.
Why: To deliver the coaching relationship you’ve engaged us for.
Lawful basis: Contract.
How long we keep it: For the duration of our coaching relationship, plus 6 years afterwards to meet our professional insurance and record-keeping obligations. Then destroyed.
If you contact us
What we collect: Whatever you’ve sent us — usually name, email, and the content of your message.
Why: To reply to you and, where relevant, to follow up on what we discussed.
Lawful basis: Legitimate interest.
How long we keep it: 2 years from your last contact with us. If you engage with us in that time (reply to an email, meet with us, ask a follow-up question), the clock resets — this way we don’t lose the thread of an active conversation.
More on legitimate interest
Where we rely on legitimate interest as our lawful basis, we’ve considered whether our interest is genuine, whether the processing is necessary, and whether it’s reasonable given your rights and expectations. The specific interests we rely on are:
- Business-to-business outreach. Where we reasonably believe our work is relevant to your organisation, we may contact you at your work email or via LinkedIn. You can ask us to stop at any time and we will.
- Marketing to prior enquirers. If you’ve previously enquired about our services or downloaded something from us, we may follow up with related content. Every message includes an opt-out.
- Service improvement. Using anonymised, aggregated data from our diagnostics, website, and training to improve our tools, our content, and our methodology.
- Security and site operation. Using technical data such as IP addresses and browser types to keep our site safe and running.
If you’d like a copy of our full Legitimate Interests Assessment for any of the above, just email us.
Who we share your information with
We do not sell or trade personal information. Ever.
We do use a small number of trusted service providers (data processors — companies we pay to help us run things, who are contractually bound to protect your data). They are:
- Microsoft 365 — email and business documents.
- Squarespace — domain registrar.
- Cloudflare Pages — website hosting and content delivery. Cloudflare is a US-headquartered company that serves our website from UK and EU edge locations. Standard Contractual Clauses and the EU–US Data Privacy Framework are in place to safeguard the transfer.
- Formspree — processes contact-form submissions from our website.
- Typeform — powers our diagnostic tool.
- Notion — internal project and client tracking.
- MailerLite — for sending list emails and handling consent and unsubscribes. MailerLite is headquartered in the Republic of Ireland (EU).
Each of these is subject to UK/EU data protection standards. We only share the minimum information they need to do their bit.
We may also share information where we’re legally required to (for example, if a court orders it), or where we need to protect someone from harm.
Where your information is stored
Some of our service providers are based in, or transfer data to, the United States. Where personal data leaves the UK or the European Economic Area, we rely on the safeguards recognised under UK and EU GDPR — including the UK–US Data Bridge, the EU–US Data Privacy Framework, and Standard Contractual Clauses (the standard legal terms approved by regulators for international data transfers). Providers headquartered or processing within the UK or EEA (such as Typeform, headquartered in Spain) keep data within that region wherever possible.
Your rights
Under UK GDPR and EU GDPR you have the right to:
- Access — see the personal information we hold about you.
- Correction — ask us to fix anything that’s wrong.
- Deletion — ask us to delete your information (with limited legal exceptions — for example, we may need to retain coaching notes for the insurance retention period above).
- Portability — get a copy of your data in a portable format.
- Objection — object to any use of your data that relies on legitimate interest, including direct marketing.
- Withdraw consent — where we’re relying on your consent (like the email list), you can withdraw it any time.
To exercise any of these, email claire@humanformulas.co.uk. We’ll respond within one calendar month.
Cookies
Our website uses the minimum cookies needed for the site to function. We do not use tracking cookies or third-party advertising cookies. If we ever add analytics, we’ll update this notice and give you the option to opt out.
Automated decision-making
We do not use AI to make automated decisions about you or to process your personal information.
Complaints
If you think we’ve mishandled your personal information, please tell us first — we’d like the chance to put it right. If we can’t resolve it, you have the right to complain to your data protection regulator.
In the UK: the Information Commissioner’s Office (ICO) — ico.org.uk.
In the EU / EEA: your national supervisory authority (the data protection regulator in your country of residence). A directory is maintained by the European Data Protection Board at edpb.europa.eu.
Changes to this notice
If we make significant changes, we’ll update the date below and let email subscribers know.