- hello@connectedape.com
- +44 (0) 7753 496 544
At Connected Ape (CAPE), we care deeply about the people we work with — and that includes protecting your personal information. This policy explains how we collect, use, and safeguard your data in line with the UK General Data Protection Regulation (UK GDPR). Whether you’re a client, workshop participant, or visiting our site, we want you to feel confident that your data is safe, used responsibly, and only when necessary.
If you have any questions, just reach out — we’re happy to talk it through in plain English.
Connected Ape (“CAPE”, “we”, “us”, “our”) is committed to protecting the personal data we process. We recognise the importance of data privacy and security, and we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws.
This policy outlines how we collect, use, store, share, and protect personal data in our operations, particularly when providing services to organisations such as the NHS.
This policy applies to all personal data processed by CAPE in the course of our business activities, including data relating to:
Clients (individuals and organisations)
Workshop and session participants
Prospective clients and partners
Our own employees and associates
We are committed to processing personal data in accordance with the following principles:
Lawfulness, Fairness, and Transparency: Personal data must be processed lawfully, fairly, and transparently.
Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Data Minimisation: Only data necessary for the purposes stated will be collected and processed.
Accuracy: Personal data must be accurate and kept up to date.
Storage Limitation: Data will be retained only for as long as necessary for the purposes it was collected.
Integrity and Confidentiality: Appropriate security measures will be taken to protect data.
Accountability: We are responsible for and must be able to demonstrate compliance with these principles.
We will only process personal data when we have a valid lawful basis, which may include:
Consent
Performance of a contract
Compliance with a legal obligation
Legitimate interests (where those interests are not overridden by the rights and freedoms of individuals)
Where required, consent will be obtained explicitly and can be withdrawn at any time.
Depending on the services provided, we may collect:
Names, job titles, and contact details
Health information relevant to service provision (only with explicit consent)
Employment details (for workshops or therapy-related services)
Feedback and service evaluations
We do not knowingly collect unnecessary personal information.
We may use personal data to:
Deliver contracted services (e.g., coaching, therapy, training)
Communicate with clients and participants
Comply with our legal obligations
Improve our services based on feedback
We will not use personal data for automated decision-making or profiling without explicit consent.
We do not sell personal data.
We may share data with:
Client organisations (with consent or contractually necessary information)
Trusted third-party service providers (e.g., IT support, cloud storage providers), under strict confidentiality agreements
Legal or regulatory authorities if required by law
We implement appropriate technical and organisational measures to protect data, including:
Secure passwords and multi-factor authentication
Encrypted storage and backup
Access control — only authorised personnel can access sensitive data
Regular reviews of security procedures
We retain personal data only for as long as necessary:
For service delivery and legitimate business purposes
As required by law (e.g., tax or regulatory obligations)
Typically, personal data will be reviewed and securely deleted after 7 years, unless otherwise agreed.
Individuals have the following rights regarding their personal data:
The right to access their personal data
The right to request correction of inaccurate data
The right to request erasure (‘right to be forgotten’)
The right to restrict or object to processing
The right to data portability
The right to lodge a complaint with the Information Commissioner’s Office (ICO)
Requests to exercise any rights can be made by contacting us (details below).
If you have any questions about this policy or how we process personal data, please contact:
Data Protection Lead
Connected Ape (CAPE)
Email: Simon@connectedape.com
Phone:
We may update this policy from time to time to ensure ongoing compliance with UK GDPR and other relevant laws. Any changes will be communicated appropriately.
Signed:
Simon Davis
Connected Ape (CAPE)