Privacy Policy

Privacy Policy

This policy explains what personal data we collect, why we collect it, how we use it, and what your rights are under UK data protection law. We've written it in plain English so it's easy to understand.

Last updated: June 2026

UK GDPR & Data Protection Act 2018

This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Business Handbook is the data controller for the personal data described in this policy. If you have questions or want to exercise your rights, contact us at [email protected].

Section 1

Who We Are

Business Handbook ("we", "us", "our") is a UK-based online platform providing business guidance, handbooks, templates, tools and AI-assisted guidance for UK business owners. Our website is businesshandbook.co.uk.

For the purposes of UK data protection law — including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 — Business Handbook is the data controller of the personal data we collect about you. This means we are responsible for deciding how and why your personal data is used, and for ensuring it is handled lawfully and securely.

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at [email protected].

Section 2

Information We Collect

We only collect personal data that is necessary for the purposes described in this policy. The types of personal data we may collect include:

Identity data: Your name and, where provided, your business name.

Contact data: Your email address and, where provided, your telephone number or postal address.

Account data: Your username, password (stored in encrypted form), account preferences and subscription status.

Payment data: Records of purchases and subscription payments. We do not store your full card details — these are handled by our payment processor, Stripe.

Usage data: Information about how you use our website, including pages visited, features used, time spent on pages and navigation paths.

Technical data: Your IP address, browser type and version, device type, operating system and general location (country or region level).

Communications data: Records of any messages you send us through our contact form or by email, including the content of those messages.

Marketing data: Your preferences regarding receiving marketing communications from us, and your engagement with those communications (email opens and clicks).

AI query data: The text of any queries you submit to our Business AI tool.

We do not collect any special category data (such as health information, racial or ethnic origin, political opinions or religious beliefs) and we do not knowingly collect data from children under the age of 16.

Section 3

How We Collect Information

We collect personal data in the following ways:

Directly from you: When you create an account, purchase a membership, complete a contact form, sign up for our newsletter, or communicate with us by email.

Automatically: When you browse our website, we automatically collect technical and usage data through cookies and similar technologies. See the Cookies section for more detail.

From third parties: We may receive limited data from payment processors (such as confirmation of a successful payment) and analytics providers.

Section 4

Website Analytics

We use website analytics software to understand how visitors use Business Handbook. This helps us identify which content is most useful, where visitors encounter difficulties, and how to improve the platform.

Our analytics software collects anonymised data including pages visited, session duration, the general location of visitors (at country or region level — not precise location), the device and browser used, and how visitors arrived at the site (for example, from a search engine or a link).

We configure our analytics to anonymise IP addresses so that individual visitors cannot be identified from analytics data alone. We do not use analytics data to build profiles of individual users or for advertising purposes.

Our legal basis for collecting analytics data is our legitimate interest in understanding how our website is used so we can improve it. You can opt out of analytics tracking by adjusting your cookie preferences — see the Cookies section below.

Section 5

Cookies

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work, to remember your preferences, and to provide information to website owners about how their site is being used.

We use the following types of cookies:

Strictly necessary cookies: These are essential for the website to function. They include cookies that keep you logged in to your account and maintain your session. These cookies cannot be disabled without affecting your ability to use the site.

Preference cookies: These remember your choices and settings, such as your cookie consent preferences and display settings.

Analytics cookies: These collect anonymised information about how you use the website. We use this data to improve the site. You can opt out of analytics cookies through our cookie settings.

Marketing cookies: We do not currently use marketing or advertising cookies. If this changes, we will update this policy and seek your consent.

You can control cookies through your browser settings or through our cookie consent tool. For more detail on the specific cookies we use, see our Cookie Policy.

Section 6

Contact Forms

When you use our contact form, we collect the information you provide — typically your name, email address and the content of your message. We use this information solely to respond to your enquiry.

Our contact forms are hosted by JotForm. When you submit a form, your data is processed by JotForm in accordance with their privacy policy, as well as by us. We do not use the information you submit through contact forms for marketing purposes unless you have separately opted in to receive marketing communications.

We retain records of contact form submissions for up to 24 months, after which they are deleted unless there is an ongoing matter that requires us to retain them for longer.

Our legal basis for processing contact form data is our legitimate interest in responding to enquiries from visitors and customers.

Section 7

Newsletter Signups

If you sign up for our newsletter, we collect your email address and, where provided, your name. We use this information to send you our newsletter and other updates about Business Handbook content, features and offers.

Our legal basis for sending marketing emails is your consent. By signing up for our newsletter, you are giving us your consent to send you marketing communications. You can withdraw this consent at any time by clicking the "unsubscribe" link in any email we send you, or by contacting us at [email protected].

Withdrawing your consent will not affect the lawfulness of any processing we carried out before you withdrew it. It will not affect your ability to use the website or your membership account.

We track email opens and clicks to understand which content is most useful to our subscribers. This data is used only to improve our newsletter — it is not shared with third parties or used for advertising purposes.

Section 8

Membership Accounts

When you create a membership account, we collect your name, email address and a password (which is stored in encrypted form — we cannot see your password). We use this information to create and manage your account, provide access to premium content, and communicate with you about your membership.

When you purchase a membership subscription, payment is processed by Stripe. We receive confirmation of your payment and retain a record of your purchase for accounting and customer service purposes. We do not store your full payment card details — these are held securely by Stripe.

We may send you transactional emails related to your account — such as payment confirmations, renewal reminders and account notifications. These are necessary for the operation of your account and are not marketing communications. You cannot opt out of transactional emails while your account is active, but you can close your account at any time.

Our legal basis for processing membership account data is the performance of a contract — we need to process your data in order to provide the service you have subscribed to.

Section 9

Business AI Usage

Business Handbook includes a Business AI tool that allows you to ask questions and receive AI-generated responses about UK business topics. When you use this tool, the text of your query is processed by our AI model provider in order to generate a response.

We recommend that you do not include sensitive personal information, financial details, or confidential business information in queries you submit to the Business AI tool. Treat it as you would a general internet search — useful for general guidance, but not the right place for sensitive specifics.

AI query data may be retained for a limited period for the purposes of improving the tool and monitoring for misuse. We do not use AI query data to identify individual users or to build personal profiles.

Responses from the Business AI tool are AI-generated and are not subject to the same editorial review process as our published content. They should be treated as a starting point for research, not as definitive professional advice. See our Disclaimer for more detail.

Our legal basis for processing AI query data is our legitimate interest in providing and improving the Business AI tool.

Section 10

How We Use Personal Information

We use the personal data we collect for the following purposes:

To create and manage your account and provide access to the services you have subscribed to

To process payments and send payment confirmations and receipts

To send transactional emails necessary for the operation of your account

To send you our newsletter and marketing communications where you have given your consent

To respond to your enquiries and provide customer support

To improve our website, content and services based on usage patterns and feedback

To monitor and maintain the security of our website and prevent fraud or misuse

To comply with our legal and regulatory obligations

To enforce our Terms and Conditions

We will not use your personal data for any purpose that is incompatible with the purposes described in this policy without first obtaining your consent or having another lawful basis to do so.

Section 12

Data Retention

We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Account data: For the duration of your account, plus 90 days after closure to allow for reactivation requests. After this, account data is deleted.

Financial records: Seven years from the date of the transaction, as required by HMRC for accounting purposes.

Contact form submissions: Up to 24 months from the date of submission, unless there is an ongoing matter that requires longer retention.

Newsletter subscriber data: For as long as you remain subscribed. If you unsubscribe, your data is deleted within 30 days.

Analytics data: Anonymised analytics data may be retained indefinitely as it cannot be used to identify individuals.

AI query data: Up to 12 months, after which it is deleted or fully anonymised.

When your data is no longer needed, we delete it securely or anonymise it so that it can no longer be linked to you.

Section 13

Third-Party Services

We share personal data with a small number of trusted third-party service providers who help us operate the website and deliver our services. We only share the data that is necessary for each provider to perform their function, and we require all providers to handle data securely and in accordance with UK data protection law.

We do not sell your personal data to third parties. We do not share your data with third parties for their own marketing purposes.

Purpose: Payment processing for membership subscriptions and purchases.

Data shared: Payment card details, billing address, transaction records.

We do not store your full card details. Stripe processes and stores payment data on our behalf.

Email Service Provider

Purpose: Sending transactional emails (account confirmations, receipts) and newsletters.

Data shared: Email address, name, email engagement data (opens, clicks).

Used only to deliver communications you have requested or that are necessary for your account.

Analytics Provider

Purpose: Understanding how visitors use the website so we can improve it.

Data shared: Anonymised usage data including pages visited, session duration and general location (country/region level).

We configure our analytics to anonymise IP addresses and not collect personally identifiable information.

Purpose: Hosting our contact forms and newsletter signup forms.

Data shared: Information you submit through our contact and signup forms.

JotForm's privacy policy applies to data submitted through their platform.

AI Model Provider

Purpose: Powering the Business AI tool that responds to user queries.

Data shared: The text of queries you submit to the Business AI tool.

Queries are processed to generate responses. We recommend not including sensitive personal or financial information in AI queries.

All third-party providers we use are either based in the UK or the EEA, or operate under appropriate data transfer safeguards (such as Standard Contractual Clauses) where data is transferred outside these areas.

Section 15

Data Security

We take the security of your personal data seriously and have put in place appropriate technical and organisational measures to protect it against unauthorised access, loss, disclosure or destruction.

All data transmitted between your browser and our website is encrypted using HTTPS/TLS.

Passwords are stored using strong one-way encryption — we cannot see your password.

Payment card data is handled entirely by Stripe and is not stored on our servers.

Access to personal data is restricted to staff and contractors who need it to perform their role.

We regularly review our security practices and update them as necessary.

No method of data transmission or storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately at [email protected].

Section 16

Your Rights Under UK GDPR

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are not absolute — there are some circumstances in which they may not apply — but we will always respond to requests promptly and explain if we are unable to fulfil them.

Right of Access

You can ask us to confirm whether we hold personal data about you and request a copy of that data.

Right to Rectification

You can ask us to correct any personal data we hold about you that is inaccurate or incomplete.

Right to Erasure

You can ask us to delete your personal data in certain circumstances — sometimes called the "right to be forgotten".

Right to Restrict Processing

You can ask us to pause the processing of your personal data in certain circumstances, for example while a correction is being verified.

Right to Data Portability

You can ask us to provide your personal data in a structured, commonly used, machine-readable format so you can transfer it to another service.

Right to Object

You can object to us processing your personal data where we rely on legitimate interests as our legal basis. You can also object to direct marketing at any time.

Right to Withdraw Consent

Where we rely on your consent to process your data (for example, for email marketing), you can withdraw that consent at any time.

Right to Complain

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have handled your data unlawfully.

To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month. There is no charge for making a request, unless requests are manifestly unfounded or excessive.

Section 17

How To Contact Us

If you have any questions about this Privacy Policy, want to exercise any of your data protection rights, or have a concern about how we have handled your personal data, please contact us:

We will respond to all data protection requests within one calendar month of receiving them, as required by UK GDPR. In complex cases, we may extend this by a further two months — if we need to do this, we will let you know within the first month.

If you are not satisfied with our response, or if you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Website: ico.org.uk

Helpline: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Section 18

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or changes in UK data protection law. When we make changes, we will update the "Last updated" date at the top of this page.

If we make material changes — changes that significantly affect how we use your personal data or your rights — we will notify registered members by email before the changes take effect. We will also display a notice on the website.

We encourage you to review this Privacy Policy periodically to stay informed about how we handle your personal data. Your continued use of Business Handbook after any changes to this policy constitutes your acceptance of those changes.

If you have any concerns about changes to this policy, please contact us at [email protected].

Questions About Your Data?

If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how we've handled your data — please get in touch. We'll always respond within one calendar month.