Privacy Policy

Carolyn Spring Ltd

Last updated: 13 June 2026


1. Introduction

This privacy notice provides you with details of how we collect and process your personal data through your use of our sites www.carolynspring.com, www.yellowfrogtraining.com and training.carolynspring.com.

By providing us with your data, you warrant to us that you are over 13 years of age.

Carolyn Spring Ltd is the data controller and is responsible for your personal data (referred to as ‘we’, ‘us’ or ‘our’ in this privacy notice).

Contact details

Our full details are:

  • Full name of legal entity: Carolyn Spring Ltd
  • Company registration: registered in England, company number 11109933
  • Email address: info@carolynspring.com
  • Postal and registered address: Pera Business Park, Nottingham Road, Melton Mowbray, Leicestershire, LE13 0PB
  • Data Protection Lead: Carolyn Spring

This privacy policy is compliant with the UK General Data Protection Regulation (‘UK GDPR’) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

It is very important that the information we hold about you is accurate and up to date. Please let us know if at any time your personal information changes by emailing us at info@carolynspring.com.

2. What data we collect about you, for what purpose, and on what grounds we process it

Personal data means any information capable of identifying an individual. It does not include anonymised data.

We may process the following categories of personal data about you:

  • Communication Data – any communication that you send to us, whether through the contact form on our website, by email, text, social media messaging, social media posting or any other communication. We process this data to communicate with you, for record-keeping, and for the establishment, pursuance or defence of legal claims. Our lawful ground is our legitimate interests, namely to reply to communications sent to us, to keep records, and to establish, pursue or defend legal claims.
  • Customer Data – data relating to any purchase of goods or services, such as your name, title, billing address, delivery address, email address, phone number, contact details, purchase details and card details. We process this data to supply the goods or services you have purchased and to keep records of those transactions. Our lawful ground is the performance of a contract between you and us, and/or taking steps at your request to enter into such a contract.
  • User Data – data about how you use our website and online services, together with any data you post for publication on our website or through other online services. We process this data to operate our website and provide relevant content, to ensure security, to maintain back-ups, and to enable publication and administration of our website, services and business. Our lawful ground is our legitimate interests, namely to administer our website and business properly.
  • Technical Data – data about your use of our website and online services, such as your IP address, login data, browser details, length of visit, page views and navigation paths, the number of times you use our website, time zone settings and other technology on the devices you use. The source is our analytics tracking system. We process this data to analyse your use of our website and services, to administer and protect our business and website, to deliver relevant content and to understand the effectiveness of our advertising. Our lawful ground is our legitimate interests, namely to administer and grow our business and to decide our marketing strategy.
  • Marketing Data – data about your preferences in receiving marketing from us and our communication preferences. We process this data to enable you to take part in our promotions, to deliver relevant content, and to understand the effectiveness of that activity. Our lawful ground is our legitimate interests, namely to study how customers use our products and services, to develop them, to grow our business and to decide our marketing strategy.
  • Training and Consultation Data – personal information you may share during training sessions, workshops, consultations or similar interactions, whether delivered in person or virtually. This may include personal experiences, case details, professional challenges, or other information you choose to disclose. We process this data to deliver our services to you, to create recordings and summaries (with your consent), for internal learning and development, and to improve our services. Our lawful ground is the performance of our contract with you, your explicit consent for recordings, and/or our legitimate interests to improve our services and train our staff.

We may use Customer Data, User Data, Technical Data and Marketing Data to deliver relevant website content and advertisements to you (including Facebook adverts or other display advertisements) and to measure or understand the effectiveness of that advertising. Our lawful ground is legitimate interests, namely to grow our business. We may also use such data to send you other marketing communications. Our lawful ground for that is either consent or legitimate interests (namely to grow our business).

Where we rely on legitimate interests as a lawful basis, we have conducted legitimate interests assessments to ensure our interests are balanced against your rights and freedoms.

Automated decision-making and profiling: we do not currently carry out automated decision-making or profiling. Automated decision-making refers to decisions made about you by technological means without human intervention that have legal or similarly significant effects. Profiling involves using your personal data to evaluate certain personal aspects, particularly to analyse or predict aspects concerning your performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Should our practices change, we will update this policy with clear information about your rights, including the right to object to profiling and the right to contest automated decisions.

Records of processing: in accordance with Article 30 of the UK GDPR, we maintain records of our data processing activities, including categories of personal data processed, purposes of processing, retention periods, and security measures. These records are available to regulatory authorities upon request.

Sensitive (special category) data: in the course of training, consultation and supervision, you may choose to share special category data – in particular information relating to health. Where you do, we process it on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR, and/or where the processing is necessary for the establishment, exercise or defence of legal claims. We do not otherwise seek special category data, and we do not collect information about criminal convictions and offences. Where special category data is shared, we apply additional safeguards, including anonymising material before it is used in any AI tool.

Where we are required to collect personal data by law, or under the terms of a contract between us, and you do not provide that data when requested, we may not be able to perform the contract (for example, to deliver goods or services to you). If that happens, we will notify you at the time.

We will only use your personal data for the purpose it was collected for, or a reasonably compatible purpose if necessary. We may process your personal data without your knowledge or consent where this is required or permitted by law.

3. How we collect your personal data

We may collect data about you through various channels:

  • direct provision by you through our website forms, email communications, or other correspondence;
  • in-person meetings, video conferences (for example Zoom calls), telephone conversations, or other direct interactions where you share personal information;
  • automatic collection through your use of our website via cookies and similar technologies (please see our cookie policy at www.carolynspring.com/cookies); and
  • third parties such as analytics providers (for example Google), advertising networks (for example Facebook), search information providers, payment processors, and other technical service providers, some of which may be based outside the UK and/or the EU.

4. Marketing communications

Our lawful ground for processing your personal data to send you marketing communications is either your consent or our legitimate interests (namely to grow our business).

Under the Privacy and Electronic Communications Regulations, we may send you marketing communications if (i) you made a purchase or asked for information from us about our goods or services, or (ii) you agreed to receive marketing communications, and in each case you have not opted out since. Under these regulations, if you are a limited company, we may send you marketing emails without your consent. You can still opt out of receiving marketing emails from us at any time.

Before we share your personal data with any third party for their own marketing purposes, we will get your express consent.

You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message, or by emailing us at info@carolynspring.com.

If you opt out of receiving marketing communications, this opt-out does not apply to personal data provided as a result of other transactions, such as purchases or warranty registrations.

5. Disclosures of your personal data

We may have to share your personal data with the parties set out below:

  • service providers who provide IT and system administration services;
  • professional advisers including lawyers, bankers, auditors and insurers;
  • third party delivery/courier organisations (such as Royal Mail) for the delivery of purchased goods;
  • government bodies that require us to report processing activities; and
  • third parties to whom we sell, transfer or merge parts of our business or assets.

We require all third parties to whom we transfer your data to respect its security and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.

6. International transfers

Where you are within the United Kingdom:

We are subject to the UK GDPR, which protects your personal data. When we transfer your data to third parties outside the UK, we ensure appropriate safeguards are in place:

  • we will only transfer your personal data to countries that have UK adequacy regulations in place, or that the UK has determined provide a standard of protection that is not materially lower than under UK law (the ‘data protection test’);
  • where we use certain service providers based outside the UK, we may use specific contracts approved by the UK government, known as International Data Transfer Agreements (IDTAs) or the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses; and
  • for transfers to the US, we use providers certified under the UK Extension to the EU-US Data Privacy Framework, or equivalent approved mechanisms.

We maintain a register of all international data transfers and regularly review the safeguards in place. If none of the above safeguards is available, we may request your explicit consent to the specific transfer, which you may withdraw at any time.

Where you are within the EEA:

We are subject to the EU GDPR, which protects your personal data. Where we transfer your data to third parties outside the EEA, we ensure appropriate safeguards are in place to provide a similar degree of security – through transfers to countries the European Commission has approved as providing adequate protection, through US-based providers that are part of an EU-approved privacy framework, or through specific contracts, codes of conduct or certification mechanisms approved by EU regulators. If none of these is available, we may request your explicit consent to the specific transfer, which you may withdraw at any time.

7. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, altered, disclosed or accessed without authorisation. These measures include:

  • encryption of personal data where appropriate;
  • regular security assessments of our systems and providers;
  • staff training and confidentiality agreements;
  • access controls and authentication protocols;
  • regular backups and disaster recovery protocols; and
  • incident response procedures.

We allow access to your personal data only to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they must keep it confidential.

We regularly test, assess and evaluate the effectiveness of our security measures. We have procedures in place to deal with any suspected personal data breach, and will notify you and the Information Commissioner’s Office of a breach where we are legally required to do so, within the timeframes specified by the UK GDPR.

8. Data retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting or reporting requirements.

We have established a data retention policy that sets out retention periods for different categories of data. The criteria used to determine these periods include:

  • the nature and sensitivity of the personal data;
  • the potential risk of harm from unauthorised use or disclosure;
  • the purposes for which we process the data, and whether we can achieve those purposes through other means;
  • legal, regulatory or contractual requirements; and
  • industry guidelines.

We regularly review our retention periods to ensure they remain appropriate and compliant. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use that information indefinitely without further notice to you.

9. Your legal rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  • the right to be informed about how we use your personal data (the purpose of this privacy notice);
  • the right of access to the personal data we hold about you;
  • the right to rectification – to have inaccurate or incomplete personal data corrected;
  • the right to erasure (the ‘right to be forgotten’) – to have your personal data deleted in certain circumstances;
  • the right to restrict processing – to request the temporary suspension of processing of your data;
  • the right to data portability – to request your data in a structured, commonly used, machine-readable format for transfer to another controller;
  • the right to object to processing – particularly processing based on legitimate interests or for direct marketing; and
  • rights related to automated decision-making and profiling, though we do not currently engage in these.

To exercise any of these rights, please email us at info@carolynspring.com. We will respond to all legitimate requests within one month. This period may be extended by up to two further months where necessary, taking into account the complexity and number of requests.

You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive.

When responding to a request we will carry out searches that are reasonable and proportionate. We may need to request specific information from you to confirm your identity and ensure your right to access your personal data (or to exercise your other rights) – this is a security measure to ensure that data is not disclosed to anyone with no right to receive it. We may also contact you to clarify your request. Where we need information that we reasonably require to deal with your request, we may pause the response period until you provide it.

You have the right to complain to us directly if you are unhappy with how we have handled your personal data. You can do this by emailing info@carolynspring.com. We will acknowledge your complaint within 30 days and investigate it without undue delay, keeping you informed of progress. Complaints are handled in accordance with our Data Protection Complaints-Handling Procedure.

If you are within the UK and are not happy with any aspect of how we collect and use your data, you also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection issues (www.ico.org.uk). We would be grateful if you would contact us first so that we can try to resolve the matter for you.

If you are within the EU and are not happy with any aspect of how we collect and use your data, you have the right to complain to the data protection authority of the country in which you are based. We would be grateful if you would contact us first so that we can try to resolve the matter for you.

10. Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

11. Cookies

Our website uses cookies to distinguish you from other users. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree.

We use explicit cookie consent mechanisms that allow you to make clear and informed choices. On your first visit you will be presented with a cookie banner that:

  • categorises cookies by purpose (strictly necessary, performance, functionality, targeting);
  • allows you to selectively consent to non-essential cookies; and
  • provides information about each cookie’s purpose, duration, and the third parties who may access the information collected.

Strictly necessary cookies do not require consent, as they are essential for the website to function. For all other cookie types, we will only set them if you have given your explicit consent.

You can manage your cookie preferences at any time by clicking ‘Cookie Settings’ in the website footer. You can also set your browser to refuse all or some cookies, or to alert you when websites set or access them. If you disable or refuse cookies, some parts of this website may become inaccessible or not function properly – in particular, the completion certificate on our online courses, and the checkout and payment process, will not work unless strictly necessary cookies are enabled.

For more detailed information about the cookies we use, please see www.carolynspring.com/cookies.

12. Use of artificial intelligence services

12.1 We may use artificial intelligence (AI) and machine learning technologies to process your personal data for specific purposes, including:

  • customer service automation;
  • content personalisation;
  • website and service optimisation;
  • data analysis and insights generation; and
  • creating summaries of consultation or training sessions for learning and development purposes.

12.2 When using AI services, we implement the following safeguards:

  • we only engage AI service providers who are compliant with UK data protection laws;
  • we conduct data protection impact assessments before implementing new AI technologies;
  • we maintain human oversight of all AI-driven decisions that may affect you;
  • we anonymise or pseudonymise client and consultation material before it is used in any AI tool; and
  • we regularly audit AI systems to ensure they process data in accordance with our instructions.

12.3 We do not permit your personal data to be used for training, developing or improving AI models beyond the specific purposes outlined in this policy. Our arrangements with AI service providers include prohibitions on using your data to train their general AI models, requirements to delete your data after processing for the specified purpose, and obligations to implement technical measures preventing data retention or repurposing.

12.4 In addition to your other data protection rights, you have specific rights regarding AI processing of your data:

  • the right to know when your data is being processed by AI systems;
  • the right to object to AI processing of your personal data;
  • the right to human intervention in any significant decision made by an AI system; and
  • the right to an explanation of how an AI-driven decision affecting you was reached.

12.5 We are committed to transparency in our AI usage. Upon request, we will provide information about which of your data is processed by AI systems, the purposes and legal basis, the safeguards in place, and the source of any AI technologies used.

13. Data protection impact assessments

Where our processing activities are likely to result in a high risk to your rights and freedoms, we conduct data protection impact assessments (DPIAs) in accordance with UK GDPR requirements. These help us identify and minimise data protection risks. We conduct DPIAs in scenarios including, but not limited to:

  • implementation of new technologies, including AI systems;
  • systematic monitoring of individuals on a large scale;
  • processing special category data on a large scale; and
  • profiling activities that have significant effects on individuals.

14. Consultation recordings and meeting summaries

14.1 With your explicit consent, we may record consultation sessions conducted via video conferencing platforms or in person. These recordings are:

  • created to provide you with a record of the consultation;
  • created for our internal learning and development purposes;
  • stored securely with appropriate technical and organisational measures; and
  • shared only with individuals who participated in the consultation, unless otherwise agreed.

14.2 Recordings may be stored and shared through password-protected cloud storage services (such as Google Drive), private password-protected video hosting platforms (such as Vimeo), or other secure file transfer methods. Access is restricted by password protection and/or limited sharing permissions.

14.3 We may use AI technology to create summaries of consultation meetings. In such cases:

  • the AI processing is subject to the safeguards outlined in section 12 of this policy, including anonymisation or pseudonymisation of material before use;
  • summaries may be used for our internal purposes, including quality assurance, learning and development, and service improvement;
  • summaries may be provided to individuals who participated in the consultation;
  • original recordings or transcripts used to generate summaries are subject to our data retention policies; and
  • we maintain human oversight of all AI-generated summaries before they are shared.

14.4 We maintain a specific retention schedule for consultation recordings and summaries, which we review regularly to ensure compliance with data protection principles.