Privacy Policy
Last updated: 1 September 2025
Who we are
Coach with Tom (the “Site”). Data Controller: Thomas Hugo Beardshaw (registered Autonomo in Spain, NIE Y6976469P).
What data we collect
Contact details you provide (name, email, phone).
Intake/scheduling details (availability, goals), session notes (minimal).
Payment + invoice data (via third‑party processors).
Website analytics (cookies/GA4) and form security (e.g., hCaptcha/Turnstile).
Emails/messages you send us.
How we use your data (lawful bases)
To respond to enquiries and deliver coaching (Contract/Legitimate Interests).
Scheduling, billing, and client administration (Contract/Legal Obligation).
Improving services and website security (Legitimate Interests).
Marketing with your opt‑in consent (Consent; you can withdraw any time).
Sharing
We use processors to run the Site and deliver services (e.g., Squarespace/hosting; email; scheduling; payments; video; file storage). We only share what’s necessary. We don’t sell your data.
International transfers
If data is transferred outside the UK/EU, we use appropriate safeguards (e.g., EU SCCs/UK IDTA) with reputable providers.
Retention
Contact enquiries: up to 12 months. Client files: 2 years after coaching ends (unless law requires longer). Invoices: 6–10 years (tax law). We delete or anonymise when no longer needed.
Your rights
Access, rectify, erase, restrict, object, data portability, and withdraw consent. To exercise rights, contact us via site contact form
Security
We use encrypted services, access controls, and least‑data practices. No method is 100% secure.
Children
This Site targets adults. Please don’t submit children’s data.
Complaints
UK: ICO (ico.org.uk). Spain/EU: AEPD (aepd.es). We’d appreciate a chance to resolve issues first.
Changes
We’ll update this notice as needed and change the date above.