Legal
Privacy notice
Last updated 13 August 2026
The short version
- If you email us, we keep your message so we can reply and, if it goes further, work with you.
- Our web server keeps short-lived technical logs. That is how we keep the site up and secure.
- There are no analytics, no advertising trackers and no third-party cookies on our public pages. We do not load fonts or scripts from anyone else's servers either.
- We do not sell your data or share it for marketing. Ever.
- You can ask us what we hold about you, ask us to correct it, or ask us to delete it.
1. Who is responsible for your data
The data controller for this website and for our coaching services is REGISTERED ENTITY NAME, trading as GMP Pathfinder, registered at REGISTERED ADDRESS, COUNTRY (company reg. no. — if applicable).
For anything in this notice, write to privacy@gmp-pathfinder.com.
We have not appointed a Data Protection Officer. We are not required to: we are a small operation, we do not monitor people systematically at scale, and processing special-category data is not part of our core activity.
2. What we collect, why, and on what legal basis
"Legal basis" below refers to Article 6 of the UK/EU General Data Protection Regulation (GDPR). We apply the same standard to enquiries from outside Europe, including under Kenya's Data Protection Act 2019.
| What | Why | Legal basis |
|---|---|---|
| Enquiry emails. Your name, email address, and whatever you choose to tell us — typically what you make, where you are based, and what stage you are at. | To reply to you and work out whether we can help. | Art. 6(1)(b) — steps taken at your request before entering a contract. |
| Client records. Contact details, engagement notes, and the compliance documentation we build with you. | To deliver the coaching you have engaged us for. | Art. 6(1)(b) — performance of our contract with you. |
| Login accounts. If you are a client, a username and email address held in our authentication system, plus sign-in timestamps. | To give you access to your private course material and keep other people out of it. | Art. 6(1)(b) — performance of our contract with you. |
| Server logs. IP address, browser user-agent, requested URL, timestamp, response code. | To operate the site, diagnose faults, and detect abuse. | Art. 6(1)(f) — our legitimate interest in a secure, working service. |
| Accounting records. Invoices and payment references. | Because tax law requires us to keep them. | Art. 6(1)(c) — compliance with a legal obligation. |
We do not ask for special-category data (health, beliefs, and so on) and you should not send it to us. If your compliance documentation happens to contain staff health records — occupational health screening is part of some GMP systems — tell us before you share it so we can agree how to handle it properly.
3. Cookies and tracking
Our public pages — this one and the home page — set no cookies at all and run no analytics. There is nothing to consent to, which is why you are not being shown a cookie banner.
If you log in as a client, our authentication system sets a session cookie. It exists only to keep you signed in. It is strictly necessary for a service you have actively requested, so it does not require consent, and it is not used to track you.
We self-host our fonts rather than loading them from Google Fonts, so visiting this site does not disclose your IP address to a third party.
UPDATE THIS SECTION when privacy-friendly analytics or the Formbricks contact form go live — both change what is collected here.
4. Who else sees your data
We keep the list of processors deliberately short:
- Our email provider, Proton AG, Switzerland, which delivers and stores our mail.
- Our hosting provider, HOSTING PROVIDER AND COUNTRY, which runs the server this site is served from.
- Our accountant, IF APPLICABLE, for invoicing records.
We do not sell personal data, we do not share it with advertising networks, and we do not use it to train machine-learning models. If we are ever legally compelled to disclose something, we will tell you unless we are prohibited from doing so.
Client confidentiality. Audit findings, formulations, site details and anything else you share during an engagement are treated as confidential. They are never used in our published course material or marketing without your explicit written agreement.
5. Where your data goes
Our servers are located in COUNTRY. We work with clients across Europe and Africa, so your data may be transferred outside the European Economic Area. Where that happens we rely on an adequacy decision / Standard Contractual Clauses — pick the one that applies. Switzerland, where our email provider is based, benefits from a European Commission adequacy decision.
6. How long we keep things
| Data | Kept for |
|---|---|
| Enquiries that do not become engagements | 12 months, then deleted |
| Client records and engagement documentation | The engagement, plus 6 years |
| Login accounts | Until you ask us to close it, or 12 months after the engagement ends |
| Server logs | CONFIRM — 30 days is typical; set nginx log rotation to match |
| Invoices and accounting records | As required by tax law — 7 years in NL, confirm for your jurisdiction |
7. Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct it if it is wrong or incomplete.
- Delete it, where we have no overriding reason to keep it — tax records being the usual exception.
- Restrict what we do with it while a dispute is resolved.
- Send it to you or another provider in a portable, machine-readable format.
- Object to processing we base on legitimate interest.
Where we rely on your consent, you can withdraw it at any time. That does not affect anything we did lawfully before you withdrew it.
Write to privacy@gmp-pathfinder.com. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to your national supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens; in Kenya, the Office of the Data Protection Commissioner. Adjust to your actual place of establishment. We would appreciate the chance to put it right first.
8. How we protect your data
- The whole site is served over HTTPS.
- Client material sits behind individual authenticated accounts, not a shared password.
- Each client can only reach their own private folder.
- Access to the underlying server is restricted to WHO — e.g. "the founder only".
No system is perfectly secure. If a breach ever affects your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and tell you directly where the law requires it.
9. Automated decision-making
We do not make automated decisions about you, and we do not profile you. Every judgement about your compliance position is made by a human.
10. Changes to this notice
When we change this notice we update the date at the top. If a change materially affects your rights we will contact clients directly rather than relying on you to re-read the page.