Privacy Policy

Last updated: 6 June 2026

1. Who We Are

Stop the Cycle is a sole trader business based in the United Kingdom. We provide facilitated team development programmes, reflective practice training, and professional development services for educational organisations and practitioners.

In this Privacy Policy, "we", "us", and "our" refer to Stop the Cycle. We are the data controller for the personal data we collect through this website and through the services we provide.

This policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and the rights you have under UK data protection law.

If you have any questions about this policy or wish to exercise any of your rights, please contact us via our website contact form.

2. Information We Collect and How We Use Your Information

We only collect personal data where it is necessary for a clear purpose. The sections below explain what we collect, why we collect it, and the lawful basis we rely on under UK GDPR.

2.1 Contact Enquiries

When you submit an enquiry through our contact form, we collect:

  • Your name and email address
  • Your organisation name, where relevant to your enquiry
  • Your enquiry subject and message
  • Your IP address, which helps us prevent spam and misuse of the website

We collect this information so that we can respond to your enquiry, manage our communications with you, prevent misuse of the website, and keep appropriate records of correspondence. We rely on our legitimate interests to process this information.

2.2 Booking Requests

When you submit a booking request, we collect:

  • Your name, email address, and phone number
  • Your organisation name, where relevant
  • Your preferred date and time
  • Any additional message or information you choose to include

We collect this information so that we can respond to your booking request, discuss your requirements, take steps before entering into a service agreement, or fulfil a booking you have made. We process this information because it is necessary for contract-related purposes.

2.3 Client Accounts and Programme Participation

If you or your organisation take part in one of our programmes, we may create a client account for you. We collect and store:

  • Your name and email address, or a system-generated username for anonymised sub-accounts
  • A securely hashed password
  • Your organisation name
  • Your enrolment and participation records
  • Responses to programme forms, activities, or reflective tasks you complete
  • Your IP address and browser type when you submit programme forms, to support record-keeping, security, and data integrity

We collect this information so that we can create and manage your account, deliver the programme, record participation, provide access to relevant materials, and maintain the integrity and security of programme records. We process this information because it is necessary to provide the services that you or your organisation have engaged us to deliver.

2.4 Proposals and Commercial Engagement

When we prepare a proposal or discuss a potential service arrangement with you or your organisation, we may collect and hold:

  • Your name, email address, phone number, and business address
  • Your organisation name and relevant commercial details
  • Information about the programme, service scope, and investment terms discussed

We collect this information so that we can understand your requirements, prepare proposals, manage prospective client relationships, and maintain accurate business records. We rely on our legitimate interests when handling prospective client information. Where a proposal becomes a confirmed service agreement, we may process this information because it is necessary for contract-related purposes.

2.5 CRM Records

Information submitted through our contact form, booking form, or proposal process may be added to our internal customer relationship management system. This helps us manage relationships with clients and prospective clients in an organised and consistent way.

The information held in our CRM reflects the types of data described in sections 2.1 to 2.4 above.

We keep CRM records so that we can maintain accurate and consolidated records of our business relationships, previous communications, enquiries, bookings, and proposals. We rely on our legitimate interests to process this information in this way.

3. Cookies and Tracking

Our website uses only strictly necessary cookies that are required for the site to function properly. These include a session cookie to manage authenticated login sessions and a CSRF token cookie to help protect forms against cross-site request forgery attacks.

We do not use advertising cookies, behavioural tracking cookies, or third-party analytics platforms. We do not share personal data with advertising networks.

Because we only use essential cookies, we do not ask for cookie consent for these cookies under the UK Privacy and Electronic Communications Regulations (PECR).

4. Third-Party Services

We use a small number of third-party services to operate our website, communicate with clients, and deliver our services effectively:

  • Email delivery (SMTP2Go): We use SMTP2Go to send transactional emails, such as booking confirmations, enquiry notifications, and service-related messages. Your name and email address may be passed to SMTP2Go solely for the purpose of delivering these emails. SMTP2Go acts as a data processor on our behalf.
  • Email hosting (MXRoute): Our business email accounts are hosted by MXRoute. Emails you send to us may be stored on MXRoute's servers. MXRoute acts as a data processor on our behalf.
  • Video content (YouTube / Vimeo): Some programme materials may include embedded video content from YouTube or Vimeo. These videos are loaded directly from those platforms and are subject to their own privacy policies. Where available, we use privacy-enhanced embed options, such as youtube-nocookie.com. If you are concerned about third-party video tracking, you can choose not to play embedded videos.
  • Web hosting: This website and its database are hosted on a web server. Our hosting provider processes personal data only as instructed by us and in line with our agreements with them.

We do not sell, rent, or share your personal data with third parties for their own marketing or commercial purposes.

5. How Long We Keep Your Data

We keep personal data only for as long as necessary for the purpose it was collected, or for as long as we are required to keep it for legal, regulatory, contractual, or legitimate business reasons.

  • Contact enquiries: Retained for up to 5 years from the date of submission, unless an ongoing business relationship exists.
  • Booking records: Retained for up to 5 years from the booking date to support service records, correspondence history, and dispute resolution.
  • Client accounts and programme records: Retained for up to 5 years after the end of the programme engagement, unless deletion is requested earlier and there is no overriding legal or contractual reason to retain the data.
  • Proposals: Retained for up to 5 years from the proposal date.
  • Email correspondence: Retained in line with our general correspondence policy for up to 5 years.

Where we need to retain data for longer than the periods set out above, we will only do so where there is a clear legal, regulatory, contractual, or legitimate business reason.

6. Data Storage and Security

We take the security of personal data seriously and use appropriate technical and organisational measures to protect it. These include:

  • Transmitting website data over encrypted HTTPS connections
  • Storing passwords using strong cryptographic hashing, so they are never stored in plain text
  • Encrypting email account credentials stored within our system
  • Restricting access to personal data to authorised personnel only
  • Using security headers, including Content Security Policy, X-Frame-Options, and HSTS
  • Using IP addresses collected through forms only for anti-abuse, security, and integrity purposes

Although we take reasonable steps to protect your data, no method of transmission or storage is completely secure. If you become aware of a security concern, please contact us as soon as possible.

7. Your Rights Under UK GDPR

You have rights in relation to the personal data we hold about you. These include:

  • Right of access: You can ask for a copy of the personal data we hold about you.
  • Right to rectification: You can ask us to correct personal data that is inaccurate or incomplete.
  • Right to erasure: You can ask us to delete your personal data where there is no compelling reason for us to continue holding it. This right is not absolute and may be limited by legal or contractual obligations.
  • Right to restrict processing: You can ask us to limit how we use your personal data in certain circumstances.
  • Right to data portability: Where processing is based on consent or contract and carried out by automated means, you can ask to receive your data in a structured, commonly used, machine-readable format.
  • Right to object: You can object to processing based on legitimate interests. If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds to continue.
  • Rights related to automated decision-making: We do not use automated decision-making that has a legal or similarly significant effect on individuals.

To exercise any of these rights, please contact us. We will respond within one calendar month. We may need to verify your identity before we can process your request.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters, at ico.org.uk or by calling 0303 123 1113.

8. Data Transfers Outside the UK

We aim to keep personal data within the UK or the European Economic Area (EEA) wherever practical. Where personal data is transferred internationally, for example because a service provider operates servers outside these areas, we take steps to ensure appropriate safeguards are in place.

These safeguards may include Standard Contractual Clauses, an adequacy decision by the UK government, or other recognised data transfer mechanisms.

Email delivery through SMTP2Go may involve processing data on servers outside the UK. SMTP2Go maintains its own data transfer and security arrangements. For more information, please see SMTP2Go's privacy policy.

9. Children's Privacy

Our services are intended for professionals and organisations in the education sector. They are not directed at children.

We do not knowingly collect personal data directly from individuals under the age of 18. If you believe we have inadvertently collected personal data from or about a child, please contact us and we will take appropriate steps to delete it.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, website, technology, or legal obligations.

When we make changes, we will update the "Last updated" date at the top of this page. Where changes are significant, we will take reasonable steps to make them clear.

We encourage you to review this policy periodically so that you understand how we handle personal data.

11. Contact Us

If you have any questions, concerns, or requests about this Privacy Policy or how we handle your personal data, please get in touch with us via our contact form.

We take privacy matters seriously and will respond as promptly as possible. For formal rights requests, we will respond within one calendar month.