Privacy Policy

PRIVACY NOTICE  |  Powered by New Legal

Last updated: 23 July 2026

Thanks for viewing our Privacy Notice (aka “Privacy Policy”). Your trust is important to us. We are committed to protecting your personal data (aka personal information) and being transparent about how and why we collect, use, and share it.

LEGAL INFORMATION

We are: ZenBoss, a business carried on by Kirsty Favell as a sole trader in the United Kingdom (“Business”, “ZenBoss”, “we”, “our”, and “us”). We provide the Heartbeat platform and related community, learning and wellbeing services.

Contact details: hello@zen-boss.com

Website: https://www.zen-boss.com, including any web or mobile application as applicable from time to time (“Website” or “Platform”).


Legal Documentation: This includes any legal information and documentation relevant to our processing of personal data, including a separate cookie policy, and additional contracts/terms and policies/notices (for example: our Heartbeat Platform Terms & Conditions, a Recording and Image Consent Form, a Data Retention Schedule, a Third Party Providers/Processors list and, if applicable, an AI Privacy/Confidentiality Notice), which may be supplied directly to you, linked in the footer of our Website and/or made available via a contract or upon request.


Cookies: Please see our cookies via the Legal Documentation or the settings banner/widget on your screen and the cookie policy in section (7) below.



INTRODUCTION

This privacy notice applies to you and describes how and why we collect and use personal data and provides information about your rights. It applies to any personal data we collect or obtain about you, or that you provide to us, through the Website and the Heartbeat platform, or any related platforms, websites or apps, when your organisation purchases access for you, when you register and create a user profile, when you use the platform and its features (including the community, monthly wellbeing circles, bi-weekly “Hotseat” coaching calls, training materials, personalised learning pathway and self-assessment process), or when you communicate or interact with us in any other way.


Heartbeat is a workplace platform made available to organisations for their nominated managers and personnel (“Authorised Users”). The Website and our services are not intended for children under the age of 18. We do not knowingly collect data relating to children. If we become aware that we have collected such data, we will delete it promptly, unless we are legally required to keep it.


It is important that you read this privacy notice together with any other privacy/data protection notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you, so that you are fully aware of how and why we are using your data. Please also read the Glossary, which explains the meaning of some of the terms used in this notice.


(1) IMPORTANT INFORMATION AND WHO WE ARE


Controller

The Business described in the Legal Information is the data controller and responsible for your personal data. We determine the purposes and means of processing the personal data we collect to provide and operate the Heartbeat platform and our services.

Contact Details

If you have any questions about this privacy notice or our privacy practices, including any request to exercise your legal rights, please contact us using the Contact Details in the Legal Information.

Complaints

You have the right to make a complaint at any time to your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO): ico.org.uk/concerns or 0303 123 1113. We would, however, appreciate the chance to deal with your concerns first, and invite you to contact us in the first instance.


Statutory Data Protection Complaints Procedure (s.164A DPA 2018 and DUAA). Under Section 164A of the Data Protection Act 2018 (as inserted by the DUAA), we operate a formal data protection complaints procedure. If you have a concern about how we handle your personal data, please: (1) submit your complaint using our complaints form at the end of this notice and email it to us; (2) we will acknowledge your complaint within 30 days of receipt; and (3) we will take appropriate steps to investigate, respond, and keep you informed of progress. If you remain dissatisfied, you may complain to the ICO.


Changes to the privacy notice and your duty to inform us of changes

We keep our privacy notice under regular review and reserve the right to change it at any time. Any changes are effective immediately upon posting to our Website or written notice to you. This version was last updated on the date above. It is important that the personal data we hold about you is accurate and current; please keep us informed if your personal data changes during your relationship with us.


Third-party links

The Website and Platform may include links to third-party websites, plug-ins, applications and/or other materials which are not provided by us. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. These are not under our control and we are not responsible for their privacy notices/policies. We recommend that you check their privacy policies before you submit any personal data to them.


(2) THE DATA WE MAY COLLECT ABOUT YOU

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer the following kinds of personal data about you:

Identity Data includes your first name, last name, username or similar identifier, and your job title/role. It may include a profile photograph if you choose to add one.

Contact Data includes your (work) email address and, where relevant, business telephone number and address.

Profile & Learning Data includes your username and password, your user profile, your preferences and settings, your personalised learning pathway and progress, your self-assessment responses and results, your participation in the community, wellbeing circles and Hotseat calls, and your feedback and survey responses.

Accessibility Data includes any accessibility preferences, adjustments or support needs you tell us about so that we can provide an accessible, neurodiversity-aware experience (see section (5.C)). Where this reveals information about your health or neurodivergence it is Special Category Data and is handled as set out below.

Technical & Usage Data includes information about how you access and use the Website and Platform, such as your device’s IP address (stored in an anonymised format where possible), device and browser type, operating system, general (country-level) location, and log/interaction data.

Marketing & Communications Data includes your preferences in receiving communications from us and your communication preferences.

Financial/Transaction Data relates primarily to the organisation that purchases access (billing and payment details). We do not usually collect payment details from individual Authorised Users.

Not all categories of personal data will apply to every individual. We only process the personal data necessary for the specific purposes relevant to our relationship with you. We also collect, use and share Aggregated Data (statistical or demographic data) which is not personal data in law because it does not directly or indirectly reveal your identity for example, aggregate engagement statistics we may share with your organisation (see section (9)).

Special Category Data

Some information is “Special Category Data” under Article 9 UK GDPR (including information about health, and information that reveals neurodivergence). We do not require you to disclose special category data to use Heartbeat. Where you voluntarily choose to disclose such information (for example, to request accessibility adjustments, or when you share experiences in wellbeing circles, Hotseat calls or the community), we will process it only on the basis of your explicit consent under Article 9(2)(a) UK GDPR, or another applicable Article 9 condition (such as protecting someone’s vital interests in an emergency, or the establishment, exercise or defence of legal claims). Audio-visual recordings of sessions may in some cases constitute biometric data; where this is the case we rely on your explicit consent obtained via our Recording and Image Consent Form. You can withdraw your consent at any time (see “Your Legal Rights”).

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract, and you (or your organisation) fail to provide that data when requested, we may not be able to provide access to the Platform or the relevant services, and we will notify you if this is the case.


(3) HOW IS YOUR PERSONAL DATA COLLECTED?

We use different methods to collect data from and about you, including:

(a) Direct interactions. You provide personal data when you register and create your user profile, set your preferences and accessibility settings, complete the self-assessment, use the learning pathway, participate in the community, wellbeing circles or Hotseat calls, give us feedback, or otherwise communicate with us.

(b) Automated technologies. As you use the Website and Platform, we automatically collect Technical and Usage Data about your equipment and activity, using cookies and similar technologies (see section (7)).

(c) From your organisation and other third parties. The organisation that purchases access for you may provide your name, work email and role in order to set up your account as an Authorised User. We may also receive Technical Data from analytics providers and information from the third-party platforms we use to deliver the services (see section (9)).


(4) HOW WE USE YOUR PERSONAL DATA

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data:

  • where we need to perform the contract we have entered into (with your organisation, and/or with you);

  • where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;

  • where processing falls within a category of ‘recognised legitimate interests’ under Article 6(1)(ea) UK GDPR and Annex 1 (introduced by the DUAA, in force 5 February 2026) — for example, safeguarding vulnerable individuals or responding to an emergency — for which no balancing test is required;

  • where we need to comply with a legal obligation; and

  • where we have your consent (including your explicit consent for special category data).

Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to special category data, certain cookies, and (where legally required) direct marketing. You have the right to withdraw consent at any time by contacting us.


(5.A) PURPOSES FOR WHICH WE MAY USE YOUR PERSONAL DATA

We have set out below a description of the main ways we plan to use your personal data, and the legal bases we rely on. We may process your personal data for more than one lawful ground depending on the specific purpose. Please contact us if you need details of the specific ground where more than one has been set out.

How we use your data
Purpose / Activity Type of data Lawful basis for processing
To set you up and register you as an Authorised User and create/manage your account and profile. (a) Identity, (b) Contact, (c) Profile. (a) Performance of a contract; (b) our legitimate interests (to administer access for our organisational clients).
To provide the Heartbeat platform and its features — community, monthly wellbeing circles, bi-weekly Hotseat coaching calls, training materials, the personalised learning pathway and the self-assessment process. (a) Identity, (b) Contact, (c) Profile & Learning, (d) Usage. (a) Performance of a contract; (b) our legitimate interests (to deliver, personalise and improve the services).
To provide an accessible, neurodiversity-aware experience and to make reasonable adjustments you request. (a) Profile, (b) Accessibility Data (may include Special Category Data). (a) Our legitimate interests (accessible, inclusive services); (b) explicit consent (Article 9(2)(a)) where special category data is involved.
To operate community, wellbeing circles and Hotseat sessions, including recording where applicable. (a) Identity, (b) Profile, (c) audio-visual recordings. (a) Performance of a contract / legitimate interests; (b) consent (and explicit consent for any special category or biometric data, via our Recording and Image Consent Form).
To produce anonymised and aggregated engagement reporting for the purchasing organisation. Aggregated Data (not personal data once aggregated). Our legitimate interests (to demonstrate value to our clients) — individuals are not identified (see section (9)).
To protect any person from an imminent risk of serious harm (safeguarding). Any relevant data, which may include Special Category Data. Vital interests (Article 6(1)(d)); recognised legitimate interests — safeguarding / emergencies (Article 6(1)(ea)); and, for special category data, Article 9(2)(c).
To manage our relationship with you, provide support, and notify you of changes to our terms or policies. (a) Identity, (b) Contact, (c) Profile. (a) Performance of a contract; (b) legal obligation; (c) our legitimate interests (to keep records updated).
To administer and protect our business and the Platform (troubleshooting, security, testing, hosting, analytics). (a) Identity, (b) Contact, (c) Technical, (d) Usage. (a) Our legitimate interests (running and securing our business and IT); (b) legal obligation.
To send you service and (where relevant) marketing communications. (a) Identity, (b) Contact, (c) Marketing & Communications. For business contacts: our legitimate interests (direct marketing, per the DUAA), subject to your right to object. Where consent is legally required, we rely on consent. You may opt out at any time.

(5.B) TECHNOLOGY AND AUTOMATION

We, and where relevant our approved service providers, may use technology (including automated systems and, where applicable, artificial intelligence or machine learning) to deliver and improve our services, manage operations and support, carry out analytics, and support legal, regulatory and risk-management requirements. Where such tools involve processing personal data, this will be done in accordance with applicable laws, with appropriate safeguards, and only for the purposes described in this notice. We apply data minimisation appropriate to the context. Lawful bases may include our legitimate interests, your consent (where required), performance of a contract, and/or compliance with legal obligations.

Automated Decision-Making: Articles 22A–22D UK GDPR (as amended)

The DUAA replaced Article 22 UK GDPR with new Articles 22A–22D, which permit automated decision-making producing significant effects on individuals, subject to safeguards. Where we make such decisions: (a) we will inform you before the decision is made, including the logic involved and its likely consequences; (b) you have the right to request human review; (c) you have the right to contest the decision; and (d) where special category data is involved, an additional Article 9 condition must be satisfied. We do not currently make solely automated decisions producing legal or similarly significant effects about you.


(5.C) ACCESSIBILITY, NEURODIVERSITY & SPECIAL CATEGORY DATA

Heartbeat is designed with an accessibility-first, neurodiversity-aware approach. We aim to make the Platform usable and comfortable for a wide range of people, including neurodivergent users, and to support reasonable adjustments.

You are never required to disclose health information, a diagnosis, or that you are neurodivergent in order to use Heartbeat or to access support. Where you choose to share such information for example, to request an adjustment, to set your accessibility preferences, or when you contribute to wellbeing circles, Hotseat calls or the community. That information is Special Category Data and we will:

  • process it only on the basis of your explicit consent under Article 9(2)(a) UK GDPR (together with a lawful basis under Article 6), unless another Article 9 condition applies (such as protecting vital interests in an emergency);

  • use it only for the purpose for which you shared it (such as providing accessibility adjustments or appropriate support), and apply data minimisation;

  • keep it confidential and not disclose it to your organisation in a way that identifies you, except with your consent, where required by law, or under the safeguarding exception below (see section (9)); and

  • allow you to withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal although this may affect our ability to provide a specific adjustment or support.


(6) MARKETING

You can change your marketing preferences at any time by following the opt-out links in any marketing message, or by contacting us. The DUAA confirms that direct marketing to business contacts can constitute a legitimate interest under Article 6(1)(f) UK GDPR, subject to your right to object at any time. Where you are an individual consumer, or where consent is otherwise required, we will rely on your consent. We will obtain your express opt-in consent before we share your personal data with any third party for their own marketing purposes. Where we rely on consent, you may withdraw it at any time, and it will always be as easy to withdraw as it was to give.


(7) COOKIE POLICY

We use cookies and similar technologies to distinguish you from other users, to operate and secure the Platform, and to improve it. A cookie is a small file of letters and numbers stored on your browser or device.

The DUAA amended the Privacy and Electronic Communications Regulations 2003 (PECR) to introduce consent exemptions for certain cookies. Statistical/analytics cookies used solely to measure Website performance without significantly affecting users, and functionality cookies used solely to improve user experience, may be deployed without prior consent, provided an opt-out is available. Advertising, targeting and cross-site tracking cookies continue to require your prior consent.

The main categories are: strictly necessary cookies (required to operate the Platform, including secure log-in); analytical/performance cookies; functionality cookies; and (only if used) targeting cookies. You can manage your preferences via our cookie settings banner/widget, or through your browser settings; blocking all cookies may affect access to parts of the Platform.

(7A) SOCIAL MEDIA

Our pages and interactions. We operate pages and accounts on third-party social media platforms [for example LinkedIn, Instagram, Facebook and YouTube]. When you follow, like, comment on, tag, share, message or otherwise interact with us on those platforms, we (and the platform) may process personal data such as your profile name or handle and the content of your interaction. We use this to engage with our community, respond to queries and promote our services. Our lawful basis is our legitimate interests (managing our social media presence and engaging with our audience) and, where required, your consent. Each platform processes your data on its own site under its own privacy policy, which we recommend you review, along with your privacy settings.

Insights and joint controllership. For some platforms (for example Facebook and Instagram “page insights”), we and the platform may act as joint controllers for aggregated statistics about people who interact with our pages. The platform provides those insights under its own terms and we receive only aggregated data from which we cannot identify individuals. The platform remains responsible for the personal data it processes on its own service.

Social media advertising, pixels and audiences. Our Website may use social media pixels or tags [for example the Meta Pixel or the LinkedIn Insight Tag], and we may run advertising and create custom or “look-alike” audiences on social media platforms. These are tracking technologies and, where they require consent (including advertising and targeting cookies), we only deploy them with your prior consent through our cookie banner (see section (7)). Where we match limited contact data to build or target audiences, we do so in accordance with the platform’s terms and applicable law, and you can opt out at any time.

Social login. If we offer the option to register or sign in using a third-party account [for example Google, Microsoft or LinkedIn], that provider will share limited profile information (such as your name and email address) with us to create and authenticate your account, in accordance with the permissions you grant and the provider’s privacy policy.

International transfers. Many social media and advertising providers are based in, or transfer personal data to, countries outside the United Kingdom (including the United States). Where this happens, we rely on the safeguards described in section (10) (International Transfers).

Third-party responsibility. We are not responsible for the social media platforms themselves or for how they process your personal data on their own services. Please review each platform’s privacy policy and adjust your settings to control how your information is used.

(8) CHANGE OF PURPOSE

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible reason. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis. We may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.


(9) DISCLOSURES OF YOUR PERSONAL DATA & CONFIDENTIALITY COMMITMENTS

Confidentiality commitments

We treat what you share within Heartbeat as confidential. In particular: (a) reporting to the organisation that purchases access is limited to anonymised and aggregated engagement data only — we do not tell your employer/management about your individual participation, self-assessment responses, wellbeing disclosures or contributions, except with your consent, where required by law, or under the safeguarding exception below; (b) participants are required to keep other participants’ contributions confidential; and (c) these commitments mirror the confidentiality provisions in our Heartbeat Platform Terms & Conditions.

Safeguarding exception. Where we reasonably consider it necessary to protect any person from an imminent risk of serious harm (including a risk to life, or of serious physical or mental harm), we may use and disclose relevant information to the extent necessary — for example, to the emergency services, appropriate authorities or a relevant third party. We rely on vital interests / recognised legitimate interests under Article 6, and Article 9(2)(c) for any special category data, and we limit disclosure to what is reasonably necessary.

Who we may share your data with

We may share your personal data with: (a) external third parties who process personal data on our behalf as processors under Article 28 UK GDPR contracts (including the platform host and the providers of the technologies we use to deliver the services); (b) professional advisers (such as lawyers, accountants and insurers); (c) regulators and authorities where required; and (d) parties to any business reorganisation, sale or merger. We require all third parties to respect the security of your personal data, to treat it in accordance with the law, and not to use it for their own purposes. Further detail is set out in our Third Party Providers/Processors list available upon request.


(10) INTERNATIONAL TRANSFERS

Different countries have different rules for how personal data can be transferred internationally. We follow the standards required under the data protection laws that apply to you, so that your personal data is protected wherever it goes.

As our business and platform grow, and depending on the providers we use, we may share your personal data with service providers or affiliates who are or become based outside the United Kingdom (for example in the European Economic Area, the United States, Canada, Australia or other jurisdictions). This means your personal data may be transferred outside your country of residence.

The DUAA introduced a revised UK test for assessing whether a third country provides adequate data protection. Whenever we transfer your personal data internationally, we ensure it is protected by implementing at least one of the following safeguards: (a) transferring only to countries recognised as providing an adequate level of protection under applicable UK data protection law; and/or (b) using specific contractual safeguards, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other lawful mechanisms, to ensure an equivalent level of protection.


(11) DATA SECURITY

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We seek to apply data-protection-by-design-and-default principles, and implement measures that are reasonable and proportionate, taking into account the nature of the data, the risks involved and available technology. We limit access to your personal data to those who have a business need to know, and they are subject to a duty of confidentiality.

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator (including the ICO) where we are legally required to do so under Article 33 UK GDPR (generally within 72 hours), and will notify you without undue delay where a breach is likely to result in a high risk to your rights and freedoms. However, no transmission over the internet or storage technology can be guaranteed to be 100% secure, and transmission of personal data to and from our Website is at your own risk.


(12) DATA RETENTION

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying any legal, regulatory, tax, accounting or reporting requirements. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes by other means, and applicable legal requirements.

In general: account and profile data is retained for the duration of your access to Heartbeat and for a limited period afterwards; basic business records (including any Contact, Identity, Financial and Transaction Data relating to our organisational clients) are kept for six years for tax purposes; special category data (such as accessibility/health information) and session recordings are retained only for as long as necessary for the purpose and your consent, and are deleted or anonymised thereafter. In some circumstances we will anonymise your personal data for research or statistical purposes, in which case we may use it indefinitely without further notice to you.


(13) YOUR LEGAL RIGHTS

Under data protection law you have rights in relation to your personal data, including the right to: request access to your personal data; request correction; request erasure; object to processing; request restriction of processing; request transfer (portability); withdraw consent (where we rely on consent, including explicit consent for special category data); and rights in relation to automated decision-making under Articles 22A–22D UK GDPR (to be informed before a significant automated decision is made, to obtain human review, and to contest the decision).

You will not usually have to pay a fee. We may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive. We may need to request specific information to confirm your identity. Under the DUAA, we are only required to conduct reasonable and proportionate searches in response to a subject access request; the response period (ordinarily one month) runs from the latest of receipt of your request, any identity verification we reasonably require, or any permitted fee, and pauses if we reasonably need clarification. We may extend by up to two further months for complex or numerous requests and will keep you informed. To exercise any right, please contact us using the Contact Details.


(14) GLOSSARY

Legitimate Interest means the interest of our business in conducting and managing it to enable us to give you the best and most secure experience. We balance any potential impact on you and your rights before processing for our legitimate interests, and do not use your data where our interests are overridden by the impact on you (unless we have your consent or are otherwise permitted by law).

Recognised Legitimate Interests (Article 6(1)(ea) UK GDPR, DUAA) means processing within one of the categories in Annex 1 of the UK GDPR for which no balancing test is required — including safeguarding vulnerable individuals and responding to emergencies threatening life, health or safety. This basis does not ordinarily apply to commercial processing.

Performance of contract means processing your data where necessary for a contract to which you are a party, or to take steps at your request before entering into such a contract.

Legal obligation means processing where necessary to comply with a legal obligation we are subject to.

Consent means you have given clear permission to process your personal data for a specific purpose. For special category data we rely on explicit consent. You can withdraw consent at any time using the Contact Details.

External Third Parties means service providers (including the platform host and technology providers) acting as processors under Article 28 UK GDPR contracts; professional advisers; regulators and authorities; and any party we are required by law to share data with, as further described in our Third Party Providers/Processors list.



ANNEX — DATA PROTECTION COMPLAINTS FORM

Pursuant to Section 164A, Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025)

Download and fill out HERE.