Last updated: 11/06/2026
Table of Contents
We recommend that you read this Privacy Notice in full to ensure you are completely informed about your personal data. However, if you only want to access a particular section of this Privacy Notice, then you can click on the relevant link above to jump to that section.
Sapphire Leadership Ltd respects your right to privacy. This Privacy Notice explains who we are, how we collect, share and use personal data about you and how you can exercise your privacy rights. This Privacy Notice only applies to personal data that we collect through our website at https://www.sapphiretransform.com (“Website”) and/or where you engage with us or our services, including attendance at or participation in one of our events (“Services“).
Sapphire Leadership Ltd is the controller of the data set out in this Privacy Notice. To understand the terms under which you use the services that we provide, please read the terms specific to the service provided in the contract document.
If you have any questions or concerns about our use of your personal data, then please contact us using the contact details under the “How to contact us” heading below.
1. What does Sapphire Leadership Ltd do?
Sapphire Leadership Ltd, supports individuals and businesses looking to grow and transform their business and themselves as leaders. We are headquartered in the UK. Our services involve providing bespoke conferences, events and related services.
For more information about Sapphire Leadership Ltd, please see our Website at www.sapphiretransform.com.
2. Personal data we collect and process
The personal data we collect from you, either directly or indirectly, will depend on how you interact with us, our Services and our Website. We collect personal data about you from the following different sources:
• Information that you provide directly
We collect personal data directly from you when you choose to provide us with this information online through our Website as well as through your interactions with us (such as correspondence via email) and in person when you engage with us or our Services, including where you attend one of our events. Certain parts of our Website ask you to provide personal data when you send us an enquiry or wish to register your interest in our Services.
• Information that we collect indirectly
We collect your personal data indirectly, including through automated means from your device when you use our Website. Some of the information we collect indirectly is captured using cookies and other tracking technologies, as explained further in the “Cookies and similar tracking technology” section below.
• Information from third parties
We also collect your personal data from third party sources (i.e. our service providers that provide operational assistance or analytics services on our Website, or other third parties that assist us in delivering our Services. This includes your employer, where your employer has put you forward to attend one of our events. These third party sources include your employer, where your employer has put you forward for one of our Services or our service providers that assist us to run our events (i.e. psychometric testing providers) Information received from third parties will be checked to ensure that the third party either has your consent or are otherwise legally permitted or required to disclose your personal data to us.
2b) The table below describes the categories of personal data we collect from and about you through our Website and Services. We will combine this information with other information contained in our systems.
| Personal Data Description | Source |
|---|---|
| Identity and Contact Data such as your name, email address and telephone number. | Directly from you (online or offline) Third parties |
| Customer Relationship Data such as data associated with your job title/role, company and/or employer and other information that you have disclosed to us in correspondence that assists us in developing and maintaining our relationship with you. | Directly from you Third parties |
| Transaction Data such as information associated with a bank transfer you make to us. Where you provide payment to us via payment service providers we will collect information which may include truncated credit or debit card details, payment method, transaction statements, your billing address, your delivery address or the delivery address of the intended recipient of the Services. Where we use payment service providers we do not collect or store your full credit or debit card details (which are processed by payment service providers who are separate controllers of your data. Please refer to your payment service provider’s privacy notice for further details on their data collection practices). | Directly from you Indirectly from you Third parties |
| Correspondence Data such as any communications with us (including when you interact with us offline), any queries you raise, email or call history. This data may also include metadata associated with the communication, for example, our Website will generate the metadata associated with communications made using our Website contact form. | • Directly from you • Indirectly from you • Third parties |
| Enquiry Data such as information collected when submitting an enquiry to us relating to our Services, including details of your job, employer/company and role, and any other information you disclose to us in connection with your enquiry. | • Directly from you • Third parties |
| Marketing Data such as your preferences in relation to receiving marketing materials from us, such as our newsletters, communication preferences for notifications associated with our Services. | • Directly from you |
| Event Data such as information you choose to share with us during your attendance or participation in our events. This also includes where you participate in activities during the event or in preparation for the event such as an interview and/or results from psychometric testing. This also includes any feedback or survey responses provided during or following attendance or participation in our events. | • Directly from you • Third parties |
| Booking Data such as information required in order to facilitate your attendance at one of our events and to provide (where applicable) you with flights and accommodation, including your passport details, or other identity documentation, nationality, date of birth, flight booking details, hotel booking details. | • Indirectly from you |
| Device and Usage Data collected from (or as a result of your using) your device (including by means of cookies and similar tracking technology) and interacting with our Website, including your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use | • Indirectly from you • Third parties |
| Photo / Video Data where photos or videos (including audio) are taken during your attendance at one of our events, if you participate in a marketing or promotional campaign for us or provide feedback via video. | • Directly from you • Third parties |
Some of the personal data that you provide in connection with our Services includes sensitive personal data, such as health-related information, which we need in order to manage your booking and attendance at our events.
For example, we may need to collect health-related information to take additional or appropriate steps to facilitate your attendance at our event, such as information about any disability, access requirements or allergies. We only collect this information where we have your explicit consent.
Other than as set out above we do not process sensitive personal data. Where we process Photo/Video Data for the purposes set out in this Notice this may incidentally reveal information about you, such as your race or ethnic origin, or health related characteristics. We do not use this information for the purpose of identifying or inferring sensitive personal data about you.
3. How we use your personal data (our purposes) and our legal basis for processing it
We use the personal data that we collect from and about you only for the purposes described in this Privacy Notice or for purposes that we explain to you at the time we collect your information. Depending on our purpose for collecting your information, we rely on one of the following legal bases:
• Contract – we require certain personal data in order to provide the Services you purchase or request from us;
• Consent – in certain circumstances, we may ask for your consent (separately from any contract between us) before we collect, use, or disclose your personal data, in which case you can voluntarily choose to give or deny your consent without any negative consequences to you;
• Legitimate interests – we will use or disclose your personal data for the legitimate interests of either Sapphire Leadership Ltd or a third party, but only when we are confident that your privacy rights will remain appropriately protected. If we rely on our (or a third party’s) legitimate interests, these interests will normally be to: operate, provide and improve our organisation, including our Website and Services; communicate with you and respond to your questions; improve our Website or use the insights to improve or develop marketing activities and promote our products and services and/or to manage the security of our IT infrastructure, and the safety and security of our employees, customers, and visitors. Where we require your data to pursue our legitimate interests or the legitimate interests of a third party, it will be in a way which is reasonable for you to expect as part of the running of our organisation and which does not materially affect your rights and freedoms. We have identified below what our legitimate interests are. or
• Legal obligation – there are be instances where we must process and retain your personal data to comply with laws or to fulfil certain legal obligations.
The following table provides more details on our purposes for processing your personal data and the related legal bases. The legal basis under which your personal data is processed will depend on the data concerned and the specific context in which we use it.
| Purpose/Activity | Type of personal data | Lawful basis for processing including basis of legitimate interest |
|---|---|---|
| Provide our Services to you, including to register and manage attendance at an event, deliver and run the event (and any associated activities). | Identity and Contact Data Customer Relationship Data Correspondence Data Enquiry Data Event Data Booking Data Sensitive personal data – Health | • Performance of a contract with you. • Otherwise, as necessary for our legitimate interests (to operate, provide and improve our organisation; to deliver and develop our Services further, where these activities are not necessary to perform a contract with you. • Explicit consent in the case of health related data required to manage your booking and attendance at an event. |
| Manage feedback in relation to our Services. | Identity and Contact Data Customer Relationship Data Correspondence Data Event Data Booking Data | • Our legitimate interests (to operate, provide and improve our organisation; including our Services in response to feedback) |
| Process transactions made for our Services | Identity and Contact Data Customer Relationship Data Correspondence Data Transaction Data | • Performance of a contract with you. |
| Respond to your communications regarding our Services, and respond to your enquiries, requests or complaints. | Identity and Contact Data Customer Relationship Data Correspondence Data | • Performance of a contract with you. • Otherwise, as necessary for our legitimate interests (to operate, provide and improve our organisation; to communicate with you) – where our communications are not necessary to perform or enter into a contract with you. |
| Reviewing communications with you for customer support and quality assurance and training purposes, and related record keeping. | Identity and Contact Data Customer Relationship Data Communications Data | • Necessary for our legitimate interests (to operate, provide and improve our organisation; to communicate with you) – where our communications are not necessary to perform or enter into a contract with you. |
| Manage compliance with any terms we have in place with you. | Identity and Contact Data Customer Relationship Data Correspondence Data Transaction Data Event Data Booking Data | • Performance of a contract with you. • Otherwise, as necessary for our legitimate interests (to operate, provide and improve our organisation, including our Website and Services. |
| To administer and maintain our Website and our IT systems (including monitoring, troubleshooting, data analysis, testing, system maintenance, repair and support, reporting and hosting of data). | Device and Usage Data | • Our and our third parties’ legitimate interests (to operate, provide and improve our organisation including our Website; to manage the security of our IT infrastructure. |
| Manage our use of tracking technologies such as cookies (including enabling you to manage your cookie preferences) and analyse collected data to learn about our Website, to improve our Website, and to develop new services. This includes website analytics, identifying browsing trends and patterns and evaluating this information on an aggregated, group(s) basis. | Device and Usage Data | • Consent (where required under applicable law – see cookie consent tool on our website). • Otherwise (for strictly necessary cookies) our legitimate interests to operate, provide and improve our organisation, including our Website to improve our Website or use the insights to improve or develop marketing activities to promote our organisation and our Services. |
| Contact current and prospective customers about our Services, and events we think may be of interest, including our newsletter and other promotional mailers and electronic communications. | Identity and Contact Data Marketing Data Enquiry Data | • Consent (where required under applicable law). • Otherwise our legitimate interests (to operate, provide and improve our organisation; to communicate with you and to develop marketing activities and promote our organisation and our Services. |
| Develop and promote our organisation and our Services through marketing and promotional materials/activities, including on our social media. | Photo / Video Data | • Necessary for our legitimate interests (to promote our organisation and Services). |
| Manage and develop our business relationship with you. | Identity and Contact Data Customer Relationship Data Correspondence Data Enquiry Data Marketing Data | • Consent (where required under applicable law). • Performance of a contract with you. • Otherwise our legitimate interests (to operate, provide and improve our organisation, to develop our Services and organisation including to build our relationship with you and further develop our Services. where these activities are not necessary to perform a contract with you. |
| Comply with legal and regulatory obligations to which we are subject, including our obligations to respond to your requests under data protection law. | Identity and Contact Data Customer Relationship Data Transaction Data Correspondence Data Enquiry Data Marketing Data Event Data Booking Data Device and Usage Data | • Legal obligation. |
| Protect our legal rights (including where necessary, to share information with law enforcement and others), for example to defend claims against us and to conduct litigation to defend our interests. | Identity and Contact Data Customer Relationship Data Transaction Data Correspondence Data Enquiry Data Marketing Data Event Data Booking Data Device and Usage Data | • Our legitimate interests to protect our organisation’s interests. |
| In the event of an emergency during attendance or participation in our events. | Identity and Contact Data Customer Relationship Data Correspondence Data Event Data Booking Data Sensitive personal data – Health | • To protect your vital interests and where it relates to sensitive personal data, where you are not physically able to give consent. |
4. Who we share your personal data with
We share your personal data with the following categories of recipients:
• third party service providers and partners who provide data processing services to us as necessary to provide you with Services, or who otherwise process personal data for purposes described in this Privacy Notice. The following table lists the main third party service providers we engage to process your personal data, the categories of services they provide, and the types of personal data they receive in order to provide us these services;
| Service Provider | Services | Personal data |
|---|---|---|
| Hotel companies | Hotel booking | Identity and Contact Data Customer Relationship Data Correspondence Data Enquiry Data Booking Data Sensitive Data to the extent it relates to the hotel booking |
| Hubspot | CRM platform | Identity and Contact Data Customer Relationship Data Transaction Data Correspondence Data Enquiry Data Marketing Data Event Data Booking Data Sensitive Data to the extent it relates to attendance at an event |
| Psychometric Testing providers | Psychometric Testing | Identity and Contact Data Customer Relationship Data Event Data |
10• third party services when you use third party services linked through our Website, for example, third party payment services, your personal data will be collected by the provider of such services. Please note that when you use third party services, their own terms and privacy notices will govern your use of their services;
• any competent law enforcement body, regulatory, government agency, court or other third party (such as our professional advisers) where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights or so a third party can defend theirs, or (iii) to protect your vital interests or those of any other person;
• our insurers or other professional advisors where disclosure is necessary for the purposes of maintaining insurance coverage, managing risks, and obtaining professional advice.
• a buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your personal data only for the purposes disclosed in this Privacy Notice; or
• any other person with your consent to the disclosure (obtained separately from any contract between us).
5. Cookies and similar tracking technology
We use cookies and similar tracking technology (collectively, “Cookies”) to collect and use personal data about you.
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
Cookies may be either “persistent” cookies or “session” cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
We use cookies for the following purposes:
• authentication – we use cookies to identify you when you visit our Website and as you navigate our Website
• status – we use cookies to help us to determine if you are logged into our website
• security – we use cookies as an element of the security measures used to protect user accounts, including preventing fraudulent use of login credentials, and to protect our Website and services generally
• advertising – we use cookies to help us to display advertisements that will be relevant to you
• analysis – we use cookies to help us to analyse the use and performance of our website and services
• cookie consent – we use cookies to store your preferences in relation to the use of cookies more generally
Our service providers use cookies and those cookies may be stored on your device when you visit our Website.
• We use Google Analytics to analyse the use of our Website. Google Analytics gathers information about website use by means of cookies. The information gathered relating to our Website is used to create reports about the use of our website. Google’s privacy policy is available at: https://www.google.com/policies/privacy/.
• We use www.godaddy.comto host our Website. This service uses cookies to improve the customer experience. You can view the privacy policy of this service provider at https://www.godaddy.com/en-uk/trust-center/privacy.
You can manage your cookies through the cookie banner and preference centre on our Website.
You can also manage cookies through your browser. Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
- https://support.google.com/chrome/answer/95647?hl=en (Chrome)
- https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences (Firefox)
- http://www.opera.com/help/tutorials/security/cookies/ (Opera)
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer)
- https://support.apple.com/kb/PH21411 (Safari)
- https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Edge)
Please note that blocking all cookies will have a negative impact upon the usability of many websites.
If you block cookies, you will not be able to use all the features on our Website.
6. How we keep your personal data secure
We use appropriate technical and organisational measures to protect the personal data that we collect and process about you. The measures are designed to provide a level of security appropriate to the risk of processing.
7. International data transfers
In some cases, where your personal data is transferred to third parties another, it is processed in countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective).
Specifically, our organisation and Website servers are located in the UK. Our third party service providers and partners operate around the world. This means that when we collect your personal data we will process it in any of these countries.
Where we transfer your personal data to countries or organisations outside of the UK, which have been formally recognised as providing an adequate level of protection for personal data, we rely on the relevant “adequacy regulations” (data bridges) from the Secretary of State in the UK.
Where the transfer is not subject to an adequacy decision or regulations, we have taken appropriate safeguards to ensure that your personal data will remain protected in accordance with this Privacy
Notice and applicable laws. The safeguards we use to transfer personal data are the European Commission’s Standard Contractual Clauses as issued on 4 June 2021 including the UK Addendum.
Our Standard Contractual Clauses entered into with our third party service providers and partners] can be provided on request. Please note that some sensitive commercial information will be redacted from the Standard Contractual Clauses.
The specific retention periods depend on the nature of the information
8. Data retention
We retain the personal data we collect from you where we have an ongoing legitimate need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements). and why it is collected and processed and the nature of the legal requirement. For example, generally, we will retain Event Data collected and provided during the course of your attendance at our events for a period of 12 months following conclusion of the event. However, where you provide us with Booking Data and/or sensitive personal data relating to health in order to facilitate specific arrangements for your attendance at our event (such as allergy, disability and other health information) we will only retain such data until the conclusion of the event. As an existing or prospective customer of Sapphire Leadership Limited we retain Identity and Contact Data, Customer
Relationship Data and Marketing Data within our CRM system until the conclusion of our engagement and/or relationship. Please note that we may keep your information for a longer period to deal with and resolve requests and complaints (for example, if there is an ongoing complaint), and for litigation or regulatory matters (for example we would retain your information if there was an ongoing legal claim and the information was relevant to the claim. This information would be retained until the legal claim had been concluded).
When we have no ongoing legitimate need or legal reason to process your personal data, we will either delete or anonymise it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.
Details of retention periods for different aspects of your personal data are available from us on request by contacting us using the contact details provided under the “How to contact us” heading below.
9. Your data protection rights
You have the following data protection rights. To exercise any of them see specific instructions below or contact us using the contact details provided under the “How to contact us” heading below.
• You may access, correct, update or request deletion of your personal data.
• You can object to processing of your personal data, ask us to restrict processing of your personal data or request portability of your personal data, (i.e. your data to be transferred in a readable and standardised format].
• You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided under the “How to contact us” heading below. If you choose to opt out of marketing communications, we will still send you non-promotional emails, such as emails about the Services you have engaged us for or our ongoing business relations.
• If we have collected and processed your personal data with your consent, then you can withdraw your consent at any time by using the contact details provided under the “How to contact us” heading below. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal data conducted in reliance on lawful processing grounds other than consent.
You have the right to complain to a supervisory authority about our collection and use of your personal data. For more information, please contact your local supervisory authority.
Contact details for supervisory authorities in Europe are available here and for the UK here.
Certain supervisory authorities will require that you exhaust our own internal complaints process before looking into your complaint.
• You also have a right to complain about how we have used or handled your personal data.
If you wish to make a complaint to us or have any questions about this, you can contact us using the details provided under the “How to contact us” heading below.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
10. Updates to this Privacy Notice
We may update this Privacy Notice from time to time in response to changing legal, regulatory, technical or organisational developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make.
You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.
11. How to contact us
If you have any questions or concerns about our use of your personal data, please contact us using the following details: keith@sapphiref.com
The data controller of your personal data is Sapphire Leadership Ltd, which is registered with the UK ICO.