top of page

Privacy Policy

1. Introduction

This privacy policy explains how MYBUSINESS GROUP collects, uses, shares and protects personal information when you visit our website, enquire about our services, attend our events, become a client, or otherwise interact with us.

We are committed to protecting your privacy and handling your data openly and transparently. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

This policy covers all of our brands and trading names, including MYBUSINESS COACH, KNEKT, FORGE, GrowthCLUB and Steel City GrowthCLUB, MYBUSINESS ANGEL, and our training programmes, Learning Hub and Member's Area.

2. Who we are

MYBUSINESS GROUP is a group of companies operating from a single office in Sheffield. In this policy, "we", "us" and "our" refer to the group company responsible for your personal data — which depends on which of our services you use.


2.1 The companies in our group
All four companies are registered in England and Wales, and all share the same registered office:

Terminal 2, Terminal Warehouse, Victoria Quays, Sheffield, S2 5SY

​​

MY BUSINESS GROUP HOLDINGS LIMITED: 15785832

MY BUSINESS COACH LTD: 11811243

MY BUSINESS COACH (RUGBY) LTD: 13250157

KNEKT LIMITED: 16642885

Each of these companies is registered with the Information Commissioner's Office as a data controller where required to be. You can search the ICO's public register of fee payers at ico.org.uk.

2.2 Who is the controller of your data
MY BUSINESS GROUP HOLDINGS LIMITED operates this website and is the data controller for website visitor and cookie data, enquiries and contact form submissions, free consultation requests, and newsletter and marketing subscriptions.

When you go on to use one of our services, the company delivering that service becomes the controller of your data for that purpose:

Website, enquiries and marketing list: MY BUSINESS GROUP HOLDINGS LIMITED

MYBUSINESS COACH — Sheffield territory: MY BUSINESS COACH LTD

MYBUSINESS COACH — Doncaster territory: MY BUSINESS COACH (RUGBY) LTD

GrowthCLUB and Steel City GrowthCLUB: MY BUSINESS COACH LTD

Training programmes: MY BUSINESS COACH LTD

KNEKT — networking community and membership: KNEKT LIMITED

FORGE — conference and events: MY BUSINESS GROUP HOLDINGS LIMITED

MYBUSINESS ANGEL — angel investment: MY BUSINESS GROUP HOLDINGS LIMITED

Learning Hub and Member's Area: MY BUSINESS GROUP HOLDINGS LIMITED
 

The invoice or contract you receive will tell you which company you are dealing with. If you are not sure, ask us and we will confirm.

 
2.3 Sharing between our group companies
Our group companies are separate legal entities, so sharing your data between them is a disclosure rather than an internal transfer. We share data between them only where there is a genuine need, for example:

Passing an enquiry to the company that delivers the service you asked about

Providing shared central functions such as accounting, IT, marketing and administration, which are operated by My Business Group Holdings Limited on behalf of the group

Letting you know about relevant services from elsewhere in the group, where you have not objected

We rely on legitimate interests for this sharing — operating an integrated group efficiently and giving you a joined-up service — and on consent where the sharing is for direct marketing that requires it. You can object to group sharing for marketing purposes at any time.

 
2.4 How to contact us
Email: info@mybusinessgroup.co.uk

Telephone: 0114 358 2788

Post: Data Protection, MYBUSINESS GROUP, Terminal 2, Terminal Warehouse, Victoria Quays, Sheffield, S2 5SY

You can use these details to contact any of our group companies about your data — you do not need to work out which entity holds it first. We will identify the right company and respond on its behalf.

None of our companies is required to appoint a statutory Data Protection Officer, but we have a named person responsible for data protection across the group, and the contact details above will reach them.

3. The personal information we collect

The information we collect depends on how you interact with us.

3.1 Website visitors
IP address, and approximate location derived from it

Browser type, device type, operating system and screen resolution

Pages viewed, time spent, links clicked and referring website

Cookie and similar identifiers (see section 7)
 

3.2 Enquiries and contact forms
When you complete a contact form, request a free session or consultation, or contact us by phone, email or social media:

First name and last name

Email address

Telephone number

Company name

The subject and content of your message

Any other information you choose to give us
 

3.3 Newsletter and event notifications
Name and email address

Marketing preferences and consent records, including the date, time and source of your consent

Email engagement data, such as whether an email was opened or a link clicked
 

3.4 Event registrations and attendance
For GrowthCLUB, FORGE, KNEKT and our training programmes:

Name, job title, company name, email address and telephone number

Booking, ticketing and attendance records

Dietary requirements and accessibility or access needs (see section 3.10)

Payment and billing information (see section 3.6)

Discount, promotional or referral codes used

Feedback, survey responses and testimonials

Photography, video and audio recordings taken at events (see section 3.9)
 

3.5 Coaching, training and consultancy clients
Contact and business details for you and, where relevant, members of your team

Information about your business: financial performance, turnover, margins, targets, KPIs, strategy, sales pipeline and operational data

Session notes, action plans, 90-day plans, goals and progress records

Assessment, profiling and diagnostic results where you complete them, including behavioural profiles and business scorecards

Contractual, invoicing and payment records

Correspondence with us
 

3.6 Payments
Billing name and address

Payment amounts, dates, invoice and transaction references

Direct debit or standing order details where applicable

We do not store full card numbers or card security codes. Card payments are handled by regulated payment providers.
 

3.7 MYBUSINESS ANGEL applicants and investors
If you apply for investment or express interest in investing:

Contact details and business details

Business plans, financial statements, forecasts, cap tables and due diligence materials

Founder and director information, including background and experience

Where you are an investor: investor categorisation and self-certification information, such as high net worth or sophisticated investor declarations

Information required for anti-money laundering and identity verification checks, which may include copies of identity documents, proof of address and source of funds information
 

3.8 Member's Area and Learning Hub accounts
Account name, email address, profile details and profile photo where you provide one

Login and authentication records

Content you post, including blog comments and messages sent via our chat function

Records of the resources and training content you access
 

3.9 Photography, filming and recording
We film and photograph our events, and we may record online sessions and webinars. This means we may capture your image, voice and likeness. We use this material for event records and for marketing and promotional purposes, including on our website, social media and in future event promotion.

Where practical we will tell you in advance, mark filming and non-filming areas, and give you a way to opt out. You can also ask us to remove or stop using material featuring you — see section 12.
 

3.10 Special category and sensitive information
We do not generally seek "special category" data. However, we may receive it incidentally, for example:

Dietary requirements that reveal a religious belief or health condition

Accessibility, mobility or health information needed to make reasonable adjustments at an event or in a coaching session

Personal circumstances you choose to disclose during coaching

Where we process this data we rely on your explicit consent, or another lawful condition under Article 9 UK GDPR, and we limit access to those who need it.
 

3.11 Recruitment
If you apply for a role or work experience with us, we collect your CV, application, references, right-to-work information and interview notes.

 
3.12 Information from other sources
Publicly available sources such as Companies House, LinkedIn and company websites

Referrals and introductions from clients, members and partners

Event co-hosts, sponsors and venues

Our franchisor and its systems (see section 8)

Analytics and advertising platforms

4. Why we use your information, and our lawful basis

Under UK GDPR we must have a lawful basis for each use of your data. Ours are set out below.
 

What we use it for: Lawful basis

Responding to your enquiry or consultation request: Legitimate interests (responding to a request you have made); or contract where you are progressing to an agreement

Providing coaching, training, events, networking or investment services: Contract

Processing bookings and taking payment: Contract; legal obligation for tax and accounting records

Sending our newsletter and marketing about our services and events: Consent, or legitimate interests where we are marketing to you in a business capacity and you have not objected (see section 6)

Managing your Member's Area account: Contract

Running the website securely and preventing fraud or misuse: Legitimate interests

Analytics and measuring website performance: Consent (via cookie preferences)

Advertising and audience measurement on social and search platforms: Consent (via cookie preferences)

Photography, filming and marketing use of event footage: Legitimate interests, and consent where we ask for it

Client feedback, surveys, testimonials and case studies: Legitimate interests; consent where we name or identify you

Investor categorisation, identity and anti-money laundering checks: Legal obligation; legitimate interests

Keeping records to establish, exercise or defend legal claims, and to meet insurance and regulatory requirements: Legal obligation; legitimate interests

Recruitment: Legitimate interests; legal obligation for right-to-work checks
 

Where we rely on legitimate interests, we have considered whether our interests are fair and balanced against your rights, and concluded the processing would not be unexpected or unduly intrusive. You can ask us for details of that assessment at any time.

5. What we will never do

We will not:

Sell, rent or trade your personal information to third parties

Share your data with sponsors, exhibitors or other delegates for their own marketing without your consent

Use your coaching session content or business figures in marketing without your specific, written permission
 

6. Marketing and your choices

If you are a consumer or a sole trader, we will only send you electronic marketing where you have consented, or where you have bought from or negotiated with us about similar services and we gave you the chance to opt out.

If you are a corporate subscriber — a limited company, LLP or similar — we may send business-to-business marketing on the basis of legitimate interests, and we will always give you a clear way to stop it.

You can opt out at any time by clicking "unsubscribe" in any marketing email, emailing info@mybusinessgroup.co.uk, or telling any member of our team.

Opting out of marketing will not stop essential service messages, such as booking confirmations, event logistics, invoices or coaching administration.

7. Cookies and similar technologies

Under UK GDPR we must have a lawful basis for each use of your data. Ours are set out below.
 

What we use it for: Lawful basis

Responding to your enquiry or consultation request: Legitimate interests (responding to a request you have made); or contract where you are progressing to an agreement

Providing coaching, training, events, networking or investment services: Contract

Processing bookings and taking payment: Contract; legal obligation for tax and accounting records

Sending our newsletter and marketing about our services and events: Consent, or legitimate interests where we are marketing to you in a business capacity and you have not objected (see section 6)

Managing your Member's Area account: Contract

Running the website securely and preventing fraud or misuse: Legitimate interests

Analytics and measuring website performance: Consent (via cookie preferences)

Advertising and audience measurement on social and search platforms: Consent (via cookie preferences)

Photography, filming and marketing use of event footage: Legitimate interests, and consent where we ask for it

Client feedback, surveys, testimonials and case studies: Legitimate interests; consent where we name or identify you

Investor categorisation, identity and anti-money laundering checks: Legal obligation; legitimate interests

Keeping records to establish, exercise or defend legal claims, and to meet insurance and regulatory requirements: Legal obligation; legitimate interests

Recruitment: Legitimate interests; legal obligation for right-to-work checks
 

Where we rely on legitimate interests, we have considered whether our interests are fair and balanced against your rights, and concluded the processing would not be unexpected or unduly intrusive. You can ask us for details of that assessment at any time.

8. Who we share your information with

We share personal data only where necessary, and only with organisations that are contractually required to protect it.

Our own group companies — the four companies listed in section 2.1 share central systems and functions. See section 2.3.
 

Service providers acting on our instructions, including:

  • Website hosting and platform providers

  • Email, marketing and communications platforms

  • Customer relationship management systems

  • Accounting, invoicing and bookkeeping systems

  • Online assessment, scorecard and survey tools

  • Booking, scheduling and ticketing platforms

  • Cloud storage and file sharing

  • Payment processors and direct debit providers

  • IT support and security providers
     

Our franchise network. We operate our coaching business as a franchisee of ActionCOACH. Client and prospect information may be shared with ActionCOACH (UK) Ltd and processed within its systems for the purposes of delivering the coaching programme, franchise reporting, quality assurance and licensed materials. ActionCOACH acts as a separate controller for some of these purposes and applies its own privacy notice.

Event delivery
 

  • Venues, caterers and accommodation providers, for example names, dietary and access requirements

  • Photographers, videographers and production suppliers

  • Speakers and trainers where needed to deliver a session

  • Co-hosts and sponsors, but only with your consent, or in aggregated and anonymised form
     

Professional and legal

  • Accountants, auditors, insurers, banks and legal advisers

  • HMRC, regulators, courts and law enforcement, where we are legally required to disclose

  • Prospective buyers or investors in our business, subject to confidentiality, if we reorganise, merge or sell part of the business


We do not allow our service providers to use your data for their own purposes, and we require them to act only on our instructions. You can ask us for a current list of the providers we use.

9. International transfers

Some of our providers are based outside the UK, or store data outside the UK — including in the European Economic Area, the United States and Israel.

Where we transfer personal data outside the UK, we make sure it is protected by one of the following safeguards:

  • The country has UK "adequacy" status, which currently includes the EEA and Israel

  • The transfer is covered by the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses

  • The recipient is certified under the UK Extension to the EU–US Data Privacy Framework

You can ask us for details of the safeguards applying to a particular transfer.

10. How long we keep your information

Under UK GDPR we must have a lawful basis for each use of your data. Ours are set out below.
 

What we use it for: Lawful basis

Responding to your enquiry or consultation request: Legitimate interests (responding to a request you have made); or contract where you are progressing to an agreement

Providing coaching, training, events, networking or investment services: Contract

Processing bookings and taking payment: Contract; legal obligation for tax and accounting records

Sending our newsletter and marketing about our services and events: Consent, or legitimate interests where we are marketing to you in a business capacity and you have not objected (see section 6)

Managing your Member's Area account: Contract

Running the website securely and preventing fraud or misuse: Legitimate interests

Analytics and measuring website performance: Consent (via cookie preferences)

Advertising and audience measurement on social and search platforms: Consent (via cookie preferences)

Photography, filming and marketing use of event footage: Legitimate interests, and consent where we ask for it

Client feedback, surveys, testimonials and case studies: Legitimate interests; consent where we name or identify you

Investor categorisation, identity and anti-money laundering checks: Legal obligation; legitimate interests

Keeping records to establish, exercise or defend legal claims, and to meet insurance and regulatory requirements: Legal obligation; legitimate interests

Recruitment: Legitimate interests; legal obligation for right-to-work checks
 

Where we rely on legitimate interests, we have considered whether our interests are fair and balanced against your rights, and concluded the processing would not be unexpected or unduly intrusive. You can ask us for details of that assessment at any time.

8. Who we share your information with

We share personal data only where necessary, and only with organisations that are contractually required to protect it.

Our own group companies — the four companies listed in section 2.1 share central systems and functions. See section 2.3.
 

Service providers acting on our instructions, including:

  • Website hosting and platform providers

  • Email, marketing and communications platforms

  • Customer relationship management systems

  • Accounting, invoicing and bookkeeping systems

  • Online assessment, scorecard and survey tools

  • Booking, scheduling and ticketing platforms

  • Cloud storage and file sharing

  • Payment processors and direct debit providers

  • IT support and security providers
     

Our franchise network. We operate our coaching business as a franchisee of ActionCOACH. Client and prospect information may be shared with ActionCOACH (UK) Ltd and processed within its systems for the purposes of delivering the coaching programme, franchise reporting, quality assurance and licensed materials. ActionCOACH acts as a separate controller for some of these purposes and applies its own privacy notice.

Event delivery
 

  • Venues, caterers and accommodation providers, for example names, dietary and access requirements

  • Photographers, videographers and production suppliers

  • Speakers and trainers where needed to deliver a session

  • Co-hosts and sponsors, but only with your consent, or in aggregated and anonymised form
     

Professional and legal

  • Accountants, auditors, insurers, banks and legal advisers

  • HMRC, regulators, courts and law enforcement, where we are legally required to disclose

  • Prospective buyers or investors in our business, subject to confidentiality, if we reorganise, merge or sell part of the business


We do not allow our service providers to use your data for their own purposes, and we require them to act only on our instructions. You can ask us for a current list of the providers we use.

9. International transfers

Some of our providers are based outside the UK, or store data outside the UK — including in the European Economic Area, the United States and Israel.

Where we transfer personal data outside the UK, we make sure it is protected by one of the following safeguards:

  • The country has UK "adequacy" status, which currently includes the EEA and Israel

  • The transfer is covered by the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses

  • The recipient is certified under the UK Extension to the EU–US Data Privacy Framework

You can ask us for details of the safeguards applying to a particular transfer.

10. How long we keep your information

Under UK GDPR we must have a lawful basis for each use of your data. Ours are set out below.
 

What we use it for: Lawful basis

Responding to your enquiry or consultation request: Legitimate interests (responding to a request you have made); or contract where you are progressing to an agreement

Providing coaching, training, events, networking or investment services: Contract

Processing bookings and taking payment: Contract; legal obligation for tax and accounting records

Sending our newsletter and marketing about our services and events: Consent, or legitimate interests where we are marketing to you in a business capacity and you have not objected (see section 6)

Managing your Member's Area account: Contract

Running the website securely and preventing fraud or misuse: Legitimate interests

Analytics and measuring website performance: Consent (via cookie preferences)

Advertising and audience measurement on social and search platforms: Consent (via cookie preferences)

Photography, filming and marketing use of event footage: Legitimate interests, and consent where we ask for it

Client feedback, surveys, testimonials and case studies: Legitimate interests; consent where we name or identify you

Investor categorisation, identity and anti-money laundering checks: Legal obligation; legitimate interests

Keeping records to establish, exercise or defend legal claims, and to meet insurance and regulatory requirements: Legal obligation; legitimate interests

Recruitment: Legitimate interests; legal obligation for right-to-work checks
 

Where we rely on legitimate interests, we have considered whether our interests are fair and balanced against your rights, and concluded the processing would not be unexpected or unduly intrusive. You can ask us for details of that assessment at any time.

11. How we keep your information secure

We use appropriate technical and organisational measures, including:

  • Encryption of data in transit, and at rest where our providers support it

  • Access controls, so staff only see what they need for their role

  • Multi-factor authentication on business systems

  • Strong password requirements

  • Staff training on data protection and information security

  • Written contracts with all processors

  • Regular review of user accounts, permissions and third-party access

  • A documented process for identifying, containing and reporting personal data breaches, including reporting qualifying breaches to the ICO within 72 hours and notifying affected individuals where required


No system is completely secure, and transmission of information over the internet is never entirely risk-free. Please do not send us sensitive financial or identity documents by unencrypted email — ask us for a secure method.

12. Your rights

You have the following rights over your personal data:

  • Access: Get a copy of the personal data we hold about you

  • Rectification: Have inaccurate or incomplete data corrected

  • Erasure: Ask us to delete your data where we no longer have a good reason to keep it

  • Restriction: Ask us to pause our use of your data while a concern is resolved

  • Objection: Object to processing based on legitimate interests, and to direct marketing. We must stop marketing on request, without exception

  • Portability: Receive data you gave us in a portable format, or have it sent to another provider

  • Withdraw consent: Withdraw consent at any time where consent is our basis. This does not affect processing already carried out

  • Automated decisions: Not be subject to solely automated decisions with legal or similarly significant effects


How to exercise your rights: contact us using the details in section 2.4. We will respond within one month. If your request is complex we may extend this by up to two further months, and will tell you if we do. There is normally no charge.

We may ask you to verify your identity before we act on a request, so that we do not disclose data to the wrong person.

13. Automated decision-making and profiling

We do not make decisions about you that are based solely on automated processing and that have legal or similarly significant effects on you.

We do use tools that score or segment information, for example online business scorecards and email marketing segmentation. These produce recommendations and prioritisation only; a person always reviews and decides what happens next.

14. Children

Our services are aimed at business owners and professionals, and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Other websites and social media

Our website links to other websites, including partner and client websites and our social media profiles. This policy does not apply to those sites. We are not responsible for their content or privacy practices, and we encourage you to read their own privacy notices.

Where you interact with us on social media, that platform will also process your data as a controller under its own terms.

16. Complaints

If you are unhappy with how we have handled your personal data, please contact us first using the details in section 2.4. We take complaints seriously and will investigate.

 

You also have the right to complain to the UK's data protection regulator:

Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 Website: ico.org.uk/make-a-complaint

You can complain to the ICO at any time, but we would appreciate the chance to resolve things with you first.

17. Changes to this policy

We review this policy at least annually, and whenever we make significant changes to our services or systems. The current version and its date are shown at the top of this page. Where changes are significant, we will notify you by email or by a prominent notice on our website.

MY BUSINESS GROUP HOLDINGS LIMITED (15785832), MY BUSINESS COACH LTD (11811243), MY BUSINESS COACH (RUGBY) LTD (13250157) and KNEKT LIMITED (16642885) are registered in England and Wales at Terminal 2, Terminal Warehouse, Victoria Quays, Sheffield, S2 5SY

bottom of page