Helen Dawson & Associates Ltd — Privacy Notice

This privacy notice tells you what to expect us to do with your personal information.

Last updated: 9 August 2026

Contact details

Helen Dawson & Associates Ltd

Registered in England and Wales, company number 13551939.

Registered office: 24 Cornes Close, Winchester, SO22 5DS

Email: info@helen-dawson.com

Website: https://www.helen-dawson.com

We are registered with the Information Commissioner’s Office (ICO), registration number ZB366212.

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details
  • Addresses
  • Occupation
  • Video recordings
  • Audio recordings (eg calls)
  • Records of meetings and decisions

We collect or use the following personal information for the operation of client or customer accounts:

  • Names and contact details
  • Addresses
  • Purchase or service history

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Marketing preferences
  • Website and app user journey information
  • IP addresses
  • Responses to self-assessment tools and lead-generation resources (e.g. the AI Confidence Snapshot)
  • Customer reviews, testimonials and photographs, including video testimonials, which we publish with consent to promote our services

We collect or use the following personal information to comply with legal requirements:

  • Name
  • Contact information
  • Client account information

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details
  • Purchase or service history
  • Correspondence

We collect or use the following personal information for podcast and content production, meeting recording and transcription, and business development research:

  • Names and contact details
  • Occupation
  • Records of meetings and decisions
  • Audio and video recordings, transcripts and photographs of podcast guests and event participants, published with consent
  • Publicly available professional information (e.g. LinkedIn profiles) used to research potential guests and clients

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. Which lawful basis we rely on may affect your data protection rights, which are set out in brief below. You can find out more about lawful bases, your rights and any exemptions which may apply on the ICO’s website: https://ico.org.uk/for-the-public/

  • Your right of access – You have the right to ask us for copies of your personal information. You can request other information, such as details about where we get personal information from and who we share personal information with. There are some exemptions, which means you may not receive all the information you ask for.
  • Your right to rectification – You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
  • Your right to erasure – You have the right to ask us to delete your personal information.
  • Your right to restriction of processing – You have the right to ask us to limit how we can use your personal information.
  • Your right to object to processing – You have the right to object to the processing of your personal data.
  • Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you.
  • Your right to withdraw consent – Where we use consent as our lawful basis, you have the right to withdraw your consent at any time.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are: where our contract is with an organisation rather than an individual, we process the contact details and business information of the people we work with there because this is necessary to deliver the services their organisation has engaged us for. We also record and transcribe some business meetings so that we have accurate records of discussions and decisions. Participants are told when a meeting is being recorded or transcribed.

Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – our legitimate interests are: we keep records of who we have worked with, the services we provided, and related invoicing and correspondence, because this is necessary to manage our client relationships and administer our business. All of your data protection rights may apply, except the right to portability.

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent – we have permission from you after we gave you all the relevant information. You have the right to withdraw your consent at any time.
  • Legitimate interests – our legitimate interests are: we stay in touch with business contacts we have met, worked with, or who have enquired about our services, to tell them about our work and services that may be relevant to them. We only do this in a business context, and anyone can ask us to stop at any time. All of your data protection rights may apply, except the right to portability.

Our lawful basis for collecting or using personal information to comply with legal requirements is:

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

Our lawful basis for collecting or using personal information for dealing with queries, complaints or claims is:

  • Legitimate interests – our legitimate interests are: we keep the information needed to respond to enquiries and to handle, resolve or defend any complaint or claim relating to our services. All of your data protection rights may apply, except the right to portability.

Our lawful bases for collecting or using personal information for podcast and content production, meeting recording and transcription, and business development research are:

  • Consent – we have permission from you after we gave you all the relevant information (for example, podcast guests agreeing to be recorded and published). You have the right to withdraw your consent at any time.
  • Legitimate interests – our legitimate interests are: we use professional information from publicly available sources, such as LinkedIn profiles and company websites, to identify and research potential podcast guests, clients and collaborators. We also transcribe business conversations to keep accurate records. We only use information people have made publicly available in a professional context, and we do not use it in ways they would find intrusive or unexpected. All of your data protection rights may apply, except the right to portability.

For more information on our use of legitimate interests as a lawful basis, you can contact us using the contact details set out above.

Where we get personal information from

  • Directly from you
  • Publicly available sources
  • Third parties: organisations we work with may give us the contact details of the people involved in an engagement, and business contacts sometimes introduce us to people who may be interested in our services.

How long we keep information

We keep personal information only for as long as we need it, in line with our retention schedule. In summary:

  • Client contracts, invoices and financial records: 6 years after the end of the financial year they relate to, as required by law.
  • Client delivery materials and correspondence: 2 years after the engagement ends.
  • Business development contacts and meeting notes: 2 years after the last contact.
  • Newsletter and marketing subscribers: for as long as you remain subscribed; removed when you unsubscribe.
  • Meeting recordings and transcripts: reviewed annually and deleted within 2 years, unless they form part of client delivery records.
  • Podcast raw recordings: 5 years after publication. Published episodes remain available while the guest’s consent stands.
  • Testimonials, reviews and photographs: while published; removed on request or withdrawal of consent.
  • Website analytics data: up to 14 months.
  • Cookie consent records: held by our consent management provider; searchable for one month and exportable for up to one year under our current plan.

For more information on how long we store your personal information or the criteria we use to determine this, please contact us using the details provided above.

Who we share information with

Data processors

Email marketing provider – they host our newsletter mailing list and send our email newsletter and marketing updates. They store subscribers’ names, email addresses and subscription preferences. Based in the United States.

Website hosting, forms and analytics providers – they host our websites and online tools, pass contact form and self-assessment submissions to us, provide spam filtering, and provide anonymised statistics about website visits. They handle names, email addresses, form responses and IP addresses. Our main website is hosted in the United Kingdom; our other website tools are based in the United States.

Cookie consent management provider – they operate the cookie consent banner on our website and record the choices visitors make about cookies. They handle consent records, which include a consent ID, the categories consented to, the date and time, and a pseudonymised IP address. Based in the United Kingdom.

Scheduling provider – they let people book meetings with us online, and store the name, email address and meeting details of the person booking. Based in the United States.

Meeting recording and transcription providers – they record and transcribe our video calls and podcast interviews so we have accurate records of conversations, and so podcast episodes can be edited and published. They handle participants’ names, images, voices and what was said. Based in the United States and Israel.

AI assistant tools – they provide AI tools we use to help run our business, which may process business correspondence, meeting records and documents containing names and contact details. Based in the United States.

Productivity and cloud storage providers – they provide our email, calendar, document storage and task management systems, which hold business correspondence and contact details. Based in the United States and European Union.

Accounting software provider – they provide our accounting system, which holds the names, contact details and payment records of the people and organisations we invoice. Based in New Zealand, with data hosted in the United States.

Video editing providers – freelance editors who edit our podcast episodes, video testimonials and marketing videos on our behalf, under confidentiality obligations. They handle participants’ names, images and voices. Based in the United Kingdom.

Others we share personal information with

  • Professional or legal advisors
  • Associate consultants who work with us on client engagements, under confidentiality obligations
  • Organisations we’re legally obliged to share personal information with
  • Publicly on our website, social media or other marketing and information media (for example podcast episodes, testimonials and case studies, published with consent)

Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place. For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Organisation name: Google, Microsoft. Category of recipient: cloud, productivity and analytics service providers. Country: United States. How the transfer complies with UK data protection law: the country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or the UK–US data bridge). Both providers are certified under the UK Extension to the EU–US Data Privacy Framework.

Organisation name: Anthropic, Kit, Calendly, Formspree, Vercel, Fathom, Granola. Category of recipient: AI, email marketing, scheduling, form-handling, website hosting and meeting transcription providers. Country: United States. How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs).

Organisation name: Riverside.fm. Category of recipient: podcast recording platform. Country: Israel. How the transfer complies with UK data protection law: the country has been assessed as providing adequate protection to data subjects (Adequacy Regulations).

Organisation name: Xero. Category of recipient: accounting software provider. Country: New Zealand. How the transfer complies with UK data protection law: the country has been assessed as providing adequate protection to data subjects (Adequacy Regulations).

Where necessary, our data processors will share personal information outside of the UK. When doing so, they comply with the UK GDPR, making sure appropriate safeguards are in place.

Organisation name: Amazon Web Services, Google Cloud and other cloud infrastructure providers used by our software suppliers. Category of recipient: cloud hosting and infrastructure providers. Country: United States. How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs).

Cookies

Our website uses cookies, including Google Analytics cookies, to understand how visitors use the site. For details of the cookies we use and how to manage them, see our Cookie Policy.

How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us:

Email: info@helen-dawson.com

Post: Helen Dawson & Associates Ltd, 24 Cornes Close, Winchester, SO22 5DS

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint