Data Protection & Confidentiality Policy
For Paul M. Caffrey Speaking & Training (Prepared Selling)
Introduction
Paul M. Caffrey Speaking & Training (“we”, “us”) is committed to protecting personal data and respecting confidentiality in all speaking, training, consulting, coaching, and CPD-accredited learning activities.
This policy explains how we collect, manage, store, and protect personal information from delegates, clients, suppliers, third-party partners, and website users.
Purpose of this Policy
This policy ensures that personal data is:
- Collected lawfully, fairly, and transparently
- Used for specific, legitimate purposes
- Accurate and kept up to date
- Stored securely and protected against loss, misuse, or unauthorised access
- Kept only for as long as necessary
Who We Are
Business name: Paul M. Caffrey Speaking & Training (Prepared Selling)
Website: www.paulcaffrey.com
Email: [email protected]
Paul M. Caffrey is the data controller, responsible for determining how personal information is processed.
The Data We Collect
We may collect the following types of personal data during the course of our business activity:
- Identity data: name, job title, organisation
- Contact data: email address, telephone number
- Professional data: role, sector, learning objectives
- Marketing preferences: newsletter sign-ups or unsubscribe requests
- Delegate information: event attendance, workshop completion, CPD certificate details
We do not collect sensitive “special category” data unless specifically required and agreed in advance.
How We Collect Personal Data
Personal data may be collected via:
- Website forms
- Booking systems for workshops or keynotes
- Email communication
- Contract documents or invoices
- Event organisers providing delegate lists
- Newsletter sign-up requests
We do not purchase lists or use automated scraping tools.
How Personal Data Is Used
Personal data is used only for legitimate business purposes, including:
- Confirming event bookings
- Issuing CPD certificates
- Providing workshop content or follow-up materials
- Responding to enquiries
- Requesting feedback or testimonials
- Sending relevant information to subscribed users
We never sell data to third parties.
Data Sharing & Third Parties
We may share data with trusted partners only where necessary for business operation, including:
- Event organisers
- Email newsletter providers
- Accountancy firms for invoicing
- CRM or booking platforms
- CPD accreditation bodies (where required)
All third parties must agree to handle data safely and confidentially.
We do not share data for marketing by third parties.
Data Security
We keep data safe by:
- Using password-protected storage
- Using secure cloud services
- Limiting access to only essential personnel
- Encrypting or anonymising files where appropriate
- Not printing physical documents containing personal data unless essential
If a data breach is suspected, we will notify affected persons and, if required, the appropriate data protection authority.
Data Retention
We retain personal data only as long as reasonably necessary for business, financial, and legal purposes.
Standard retention guidelines:
- Delegate records: 24 months
- Invoice details: 6 years
- Email enquiries: 12 months
Personal data can be deleted upon request.
Your Legal Rights
Individuals have the right to:
- Request access to personal information
- Request correction or deletion
- Request restriction of processing
- Object to marketing communication
- Withdraw consent at any time
Requests should be sent to: [email protected]
We will respond within 30 days.
Confidentiality
We treat all personal, business, and learning information shared with us as confidential. This includes:
- Client contact details
- Training session content
- Recorded session notes
- Participant contributions during workshops
- Any documents or files supplied for training or consulting purposes
Confidential information will not be disclosed unless:
- Required by law
- Consent has been given
- It is necessary to prevent harm or malpractice
Policy Review
This policy will be reviewed annually, or sooner if:
- Legislation changes
- Business processes change
- New systems or suppliers are introduced
Approval & Version
Policy owner: Paul M. Caffrey
Date approved: December 2025
Next review due: December 2026
Version: 1.0Â