Privacy policy

Last updated: 27 August 2026

1. Data controller

Corepathbase is the data controller for personal data collected through corepathbase.click and in connection with our training services. Address: 72WillowDriveBungayNR351AZ. Email: hello@corepathbase.click.

2. What data we collect

  • Contact enquiries: name, email address, message content, selected session, and preferred date when you submit our contact form.
  • Bookings: name, email, phone number, payment reference, and session details when you reserve a workshop or private review.
  • Website usage: cookie consent preference stored locally in your browser.
  • Communications: content of emails and phone calls relating to bookings or enquiries.

3. How we use your data

We use personal data to respond to enquiries, process bookings, deliver training sessions, send booking confirmations, and comply with legal obligations. We do not use your data for automated decision-making or profiling.

4. Legal basis

Under UK GDPR we rely on: (a) contract — processing necessary to fulfil a booking; (b) legitimate interests — responding to enquiries and operating our business; (c) consent — where you opt in to marketing communications (we send marketing only with explicit consent).

5. Data retention

Enquiry form submissions are retained for twelve months unless a booking follows, in which case data is kept for seven years for accounting and legal purposes. Booking records are retained for seven years after the session date. Cookie consent preferences are stored in your browser until cleared.

6. Your rights

You have the right to access, rectify, erase, restrict processing, object to processing, and data portability in respect of your personal data. You may withdraw consent at any time where processing is consent-based. To exercise rights, contact hello@corepathbase.click. You may lodge a complaint with the Information Commissioner's Office (ico.org.uk).

7. International transfers

We store and process data within the United Kingdom. If we use service providers outside the UK, we ensure appropriate safeguards such as UK adequacy decisions or standard contractual clauses are in place.

8. Sharing with third parties

We do not sell personal data. We may share data with payment processors, email service providers, and professional advisers where necessary to operate our business, under contractual confidentiality obligations.

9. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or alteration. No transmission over the internet is completely secure.

10. Changes

We may update this policy periodically. The current version is always available at this address. Material changes will be noted by updating the date above.

See also our cookie policy.

We use essential cookies to remember your preferences. See our cookie policy for details.