This policy explains what personal data we collect, why we collect it, how we use it, and what your rights are under UK data protection law. We've written it in plain English so it's easy to understand.
Last updated: June 2026
UK GDPR & Data Protection Act 2018
This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Business Handbook is the data controller for the personal data described in this policy. If you have questions or want to exercise your rights, contact us at [email protected].
Contents
Business Handbook ("we", "us", "our") is a UK-based online platform providing business guidance, handbooks, templates, tools and AI-assisted guidance for UK business owners. Our website is businesshandbook.co.uk.
For the purposes of UK data protection law — including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 — Business Handbook is the data controller of the personal data we collect about you. This means we are responsible for deciding how and why your personal data is used, and for ensuring it is handled lawfully and securely.
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at [email protected].
We only collect personal data that is necessary for the purposes described in this policy. The types of personal data we may collect include:
Identity data: Your name and, where provided, your business name.
Contact data: Your email address and, where provided, your telephone number or postal address.
Account data: Your username, password (stored in encrypted form), account preferences and subscription status.
Payment data: Records of purchases and subscription payments. We do not store your full card details — these are handled by our payment processor, Stripe.
Usage data: Information about how you use our website, including pages visited, features used, time spent on pages and navigation paths.
Technical data: Your IP address, browser type and version, device type, operating system and general location (country or region level).
Communications data: Records of any messages you send us through our contact form or by email, including the content of those messages.
Marketing data: Your preferences regarding receiving marketing communications from us, and your engagement with those communications (email opens and clicks).
AI query data: The text of any queries you submit to our Business AI tool.
We do not collect any special category data (such as health information, racial or ethnic origin, political opinions or religious beliefs) and we do not knowingly collect data from children under the age of 16.
We collect personal data in the following ways:
Directly from you: When you create an account, purchase a membership, complete a contact form, sign up for our newsletter, or communicate with us by email.
Automatically: When you browse our website, we automatically collect technical and usage data through cookies and similar technologies. See the Cookies section for more detail.
From third parties: We may receive limited data from payment processors (such as confirmation of a successful payment) and analytics providers.
We use website analytics software to understand how visitors use Business Handbook. This helps us identify which content is most useful, where visitors encounter difficulties, and how to improve the platform.
Our analytics software collects anonymised data including pages visited, session duration, the general location of visitors (at country or region level — not precise location), the device and browser used, and how visitors arrived at the site (for example, from a search engine or a link).
We configure our analytics to anonymise IP addresses so that individual visitors cannot be identified from analytics data alone. We do not use analytics data to build profiles of individual users or for advertising purposes.
Our legal basis for collecting analytics data is our legitimate interest in understanding how our website is used so we can improve it. You can opt out of analytics tracking by adjusting your cookie preferences — see the Cookies section below.
When you use our contact form, we collect the information you provide — typically your name, email address and the content of your message. We use this information solely to respond to your enquiry.
Our contact forms are hosted by JotForm. When you submit a form, your data is processed by JotForm in accordance with their privacy policy, as well as by us. We do not use the information you submit through contact forms for marketing purposes unless you have separately opted in to receive marketing communications.
We retain records of contact form submissions for up to 24 months, after which they are deleted unless there is an ongoing matter that requires us to retain them for longer.
Our legal basis for processing contact form data is our legitimate interest in responding to enquiries from visitors and customers.
When you create a membership account, we collect your name, email address and a password (which is stored in encrypted form — we cannot see your password). We use this information to create and manage your account, provide access to premium content, and communicate with you about your membership.
When you purchase a membership subscription, payment is processed by Stripe. We receive confirmation of your payment and retain a record of your purchase for accounting and customer service purposes. We do not store your full payment card details — these are held securely by Stripe.
We may send you transactional emails related to your account — such as payment confirmations, renewal reminders and account notifications. These are necessary for the operation of your account and are not marketing communications. You cannot opt out of transactional emails while your account is active, but you can close your account at any time.
Our legal basis for processing membership account data is the performance of a contract — we need to process your data in order to provide the service you have subscribed to.
Business Handbook includes a Business AI tool that allows you to ask questions and receive AI-generated responses about UK business topics. When you use this tool, the text of your query is processed by our AI model provider in order to generate a response.
We recommend that you do not include sensitive personal information, financial details, or confidential business information in queries you submit to the Business AI tool. Treat it as you would a general internet search — useful for general guidance, but not the right place for sensitive specifics.
AI query data may be retained for a limited period for the purposes of improving the tool and monitoring for misuse. We do not use AI query data to identify individual users or to build personal profiles.
Responses from the Business AI tool are AI-generated and are not subject to the same editorial review process as our published content. They should be treated as a starting point for research, not as definitive professional advice. See our Disclaimer for more detail.
Our legal basis for processing AI query data is our legitimate interest in providing and improving the Business AI tool.
We use the personal data we collect for the following purposes:
To create and manage your account and provide access to the services you have subscribed to
To process payments and send payment confirmations and receipts
To send transactional emails necessary for the operation of your account
To send you our newsletter and marketing communications where you have given your consent
To respond to your enquiries and provide customer support
To improve our website, content and services based on usage patterns and feedback
To monitor and maintain the security of our website and prevent fraud or misuse
To comply with our legal and regulatory obligations
To enforce our Terms and Conditions
We will not use your personal data for any purpose that is incompatible with the purposes described in this policy without first obtaining your consent or having another lawful basis to do so.
UK GDPR requires us to have a lawful basis for processing your personal data. We rely on the following legal bases:
Contract
Where processing is necessary to provide the service you have subscribed to — for example, creating your account, processing your payment and providing access to premium content.
Legitimate interests
Where we have a legitimate business interest in processing your data that is not overridden by your rights — for example, improving our website based on usage data, responding to enquiries, preventing fraud, and communicating with existing customers about relevant updates to the service.
Consent
Where you have given us your explicit consent — for example, signing up for our newsletter. You can withdraw consent at any time.
Legal obligation
Where we are required to process data to comply with UK law — for example, retaining financial records for HMRC purposes.
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our retention periods are as follows:
Account data: For the duration of your account, plus 90 days after closure to allow for reactivation requests. After this, account data is deleted.
Financial records: Seven years from the date of the transaction, as required by HMRC for accounting purposes.
Contact form submissions: Up to 24 months from the date of submission, unless there is an ongoing matter that requires longer retention.
Newsletter subscriber data: For as long as you remain subscribed. If you unsubscribe, your data is deleted within 30 days.
Analytics data: Anonymised analytics data may be retained indefinitely as it cannot be used to identify individuals.
AI query data: Up to 12 months, after which it is deleted or fully anonymised.
When your data is no longer needed, we delete it securely or anonymise it so that it can no longer be linked to you.
We share personal data with a small number of trusted third-party service providers who help us operate the website and deliver our services. We only share the data that is necessary for each provider to perform their function, and we require all providers to handle data securely and in accordance with UK data protection law.
We do not sell your personal data to third parties. We do not share your data with third parties for their own marketing purposes.
Stripe
Privacy policyPurpose: Payment processing for membership subscriptions and purchases.
Data shared: Payment card details, billing address, transaction records.
We do not store your full card details. Stripe processes and stores payment data on our behalf.
Email Service Provider
Purpose: Sending transactional emails (account confirmations, receipts) and newsletters.
Data shared: Email address, name, email engagement data (opens, clicks).
Used only to deliver communications you have requested or that are necessary for your account.
Analytics Provider
Purpose: Understanding how visitors use the website so we can improve it.
Data shared: Anonymised usage data including pages visited, session duration and general location (country/region level).
We configure our analytics to anonymise IP addresses and not collect personally identifiable information.
JotForm
Privacy policyPurpose: Hosting our contact forms and newsletter signup forms.
Data shared: Information you submit through our contact and signup forms.
JotForm's privacy policy applies to data submitted through their platform.
AI Model Provider
Purpose: Powering the Business AI tool that responds to user queries.
Data shared: The text of queries you submit to the Business AI tool.
Queries are processed to generate responses. We recommend not including sensitive personal or financial information in AI queries.
All third-party providers we use are either based in the UK or the EEA, or operate under appropriate data transfer safeguards (such as Standard Contractual Clauses) where data is transferred outside these areas.
Some links on Business Handbook are affiliate links. When you click an affiliate link, you are taken to a third-party website. That website may set its own cookies and collect its own data about your visit, in accordance with its own privacy policy.
We do not receive personal data about you from affiliate partners as a result of you clicking an affiliate link. We may receive aggregated, anonymised data about the number of clicks and conversions generated through our affiliate links, but this data does not identify individual users.
We are not responsible for the privacy practices of third-party websites you visit through affiliate links. We recommend reading the privacy policy of any website before providing your personal data to it.
For more information about how we handle affiliate relationships, see our Affiliate Disclosure.
We take the security of your personal data seriously and have put in place appropriate technical and organisational measures to protect it against unauthorised access, loss, disclosure or destruction.
All data transmitted between your browser and our website is encrypted using HTTPS/TLS.
Passwords are stored using strong one-way encryption — we cannot see your password.
Payment card data is handled entirely by Stripe and is not stored on our servers.
Access to personal data is restricted to staff and contractors who need it to perform their role.
We regularly review our security practices and update them as necessary.
No method of data transmission or storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately at [email protected].
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are not absolute — there are some circumstances in which they may not apply — but we will always respond to requests promptly and explain if we are unable to fulfil them.
Right of Access
You can ask us to confirm whether we hold personal data about you and request a copy of that data.
Right to Rectification
You can ask us to correct any personal data we hold about you that is inaccurate or incomplete.
Right to Erasure
You can ask us to delete your personal data in certain circumstances — sometimes called the "right to be forgotten".
Right to Restrict Processing
You can ask us to pause the processing of your personal data in certain circumstances, for example while a correction is being verified.
Right to Data Portability
You can ask us to provide your personal data in a structured, commonly used, machine-readable format so you can transfer it to another service.
Right to Object
You can object to us processing your personal data where we rely on legitimate interests as our legal basis. You can also object to direct marketing at any time.
Right to Withdraw Consent
Where we rely on your consent to process your data (for example, for email marketing), you can withdraw that consent at any time.
Right to Complain
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have handled your data unlawfully.
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month. There is no charge for making a request, unless requests are manifestly unfounded or excessive.
If you have any questions about this Privacy Policy, want to exercise any of your data protection rights, or have a concern about how we have handled your personal data, please contact us:
We will respond to all data protection requests within one calendar month of receiving them, as required by UK GDPR. In complex cases, we may extend this by a further two months — if we need to do this, we will let you know within the first month.
If you are not satisfied with our response, or if you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or changes in UK data protection law. When we make changes, we will update the "Last updated" date at the top of this page.
If we make material changes — changes that significantly affect how we use your personal data or your rights — we will notify registered members by email before the changes take effect. We will also display a notice on the website.
We encourage you to review this Privacy Policy periodically to stay informed about how we handle your personal data. Your continued use of Business Handbook after any changes to this policy constitutes your acceptance of those changes.
If you have any concerns about changes to this policy, please contact us at [email protected].
See also: Cookie Policy · Disclaimer · Affiliate Disclosure · Terms & Conditions
[email protected]If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how we've handled your data — please get in touch. We'll always respond within one calendar month.