Data and Privacy Policy
We are committed to safeguarding the privacy of our customers while providing the highest possible quality of service.
NSDesign takes the privacy and security of your personal information seriously. This privacy notice explains what information we collect, why we collect it, how we use and protect it, how long we keep it, and the rights you have under UK data protection law. We process personal information in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable data protection legislation, as amended from time to time.
Who we are
We are NSDesign Limited, a company registered on the ICO Data Protection Register (Registration number: Z9555899). We are also known as the data controller (and/or processor). We are a Digital Training Consultancy, providing (among other things) workshops, webinars, coaching and consultancy on the topics of AI, social media, digital marketing, cyber security and more. The NSDesign website, is owned and operated by Us. Should you wish to access any of the information that we store about you, or wish to request we remove the data entirely, please simply email us (via the details below).
Collection of Information from our Clients.
In order to fulfill your order (for example – for booking training), we need to know certain personal information collected at time of order.
We may collect and process the following data about you:-
(1) information that you provide by filing in forms on our website (or via those on the partner websites we make use of);
(2) information provided at the time of registering to use our website, subscribing to our service, posting material or requesting further services;
(3) correspondence from you and your responses to any research surveys sent to you by us;
(4) details of transactions you carry out through our site and of the fulfillment of your orders; and
(5) details of your visits to our site including but not limited to traffic data, location data, and other communication data, whether this is required for our own billing purposes or not.
It is our policy that this information is private and confidential. Unfortunately the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information the personal information you provide to us (where required) is stored in a secure location, and is accessible only by designated staff. We will use it only for the purposes for which you provide the information under this privacy statement.
We will not sell, rent or trade to third parties any personal information you provide to us, and we will only store it for as long as is necessary to continue providing the required service(s) to you.
Delivery on behalf of public-sector and partner organisations.
Where NSDesign delivers training, consultancy, mentoring or events on behalf of a public-sector body or other commissioning organisation, we may receive limited participant information directly from that organisation. This may include names, business contact details, job roles and booking or attendance information. In these circumstances, the commissioning organisation will normally act as the data controller and NSDesign will act as its data processor. We will use the information only to administer and deliver the commissioned service, in accordance with the controller’s documented instructions and the applicable contract.
We will not use programme participant information for unrelated marketing purposes or enter personally identifiable participant information into public generative AI tools. Access will be restricted to authorised personnel, and the information will be securely deleted or returned at the end of the agreed retention period or in accordance with the controller’s instructions. Where the respective data protection roles differ for a particular service, these will be explained through the applicable privacy information or contractual arrangements.
Security Best Practice
Our website uses SSL to help protect (and encrypt) any data sent between your browser and the site (submitted forms etc), and as a company we have achieved the Government approved “Cyber Essentials” compliance. We are also fully insured with public/product liability, employee liability, and professional indemnity insurance.
Keeping you informed
We would like to tell you by e-mail or other electronic means about our news, products and services which we believe would be of interest to you. If you do not want us to do this, simply do not check this option during the order process, or email us at any time and request removal. Please note that by choosing not to opt-in means that we will not be able to tell you about additional benefits and services available to our customers.
Computer Tracking and ‘Cookies’
NSDesign makes use of internet browser cookies, which we use to ensure that your experience of our website and business offerings is as effective as possible. Cookies are small amounts of information which we store on your computer and exist to improve the ease of use of this site. You may choose not to use cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However if you select this setting you may be unable to access certain parts of our site.
In addition to cookies, our website also makes use of ‘tracking code’ (often called beacons, or pixels) from organisations such as Google Analytics, Facebook and Twitter. Google Analytics allows us to better understand traffic patterns and user behaviour while on our website, and the social media pixels allow us to share our news and services with you on these 3rd party platforms. None of the data collected through cookies, analytics, or social media pixels allows us to identify you as an individual (we don’t “see” any personal data about you, other than things like your IP address), and with regard things like Facebook etc, you can opt out of such tracking within Facebook’s privacy settings, and won’t impact you at all if you’re not actually a Facebook user.
For more information on cookies, please visit www.allaboutcookies.org.
Partner Websites and Data Collection/Storage
In order to deliver our services effectively, we make use of a small number of trusted third-party systems. These tools help us manage things like email communications, accounting, event bookings, file storage and content creation. We carefully select these providers, ensure they meet GDPR requirements, and only use them in ways that protect your privacy and keep your data secure. These include:
Campaign Monitor Email Marketing
Over the last 20 years or so, we’ve built up a sizeable mailing list, collecting emails (lawfully) through a variety of methods, primarily by allowing people to “subscribe” themselves via a form on our website. We use Campaign Monitor – an email marketing system to manage and store this data, and to send out occasional commercial emails to everyone who has consented to this.
To ensure GDPR best practices, we recently simplified things: We cleaned up the data, deleted old (unused) subscribers, merged subscriber lists (into 1 simple list) re-requested opt-in consent from those who hadn’t already explicitly given it, and reduced the information we collect (and store) to essentially just a name (optional) and email address.
If you have previously given your consent to receive such emails, you can chose to opt-out (or change your preferences) at any time by clicking the relevant links included in all marketing emails sent to you.
We believe the data held in Campaign Monitor to be safe, secure, and only available to NSDesign Ltd for the purposes listed above. For more information on this, or their rules around email collection and their Zero tolerance Anti-Spam policy, please visit the Campaign Monitor Policies Page (which we are legally bound to comply with).
FreeAgent Cloud Accounting System
We use FreeAgent for our business accounting, specifically to invoice our customers for training and consultancy services that we have supplied to them under contract.
HMRC require businesses to keep company financial records for at least 6 years from the end of the last financial year, so if you’ve been a paying customer over that time frame, then we’ll likely hold data about you on FreeAgent which was required to invoice you for the goods/services supplied.
While legally we cannot delete this data, we can make changes to the contact details etc where it is inaccurate. If you’d like to see what data we hold, or you think we should update the accuracy of it, please just contact us at any time.
We believe the data held on the FreeAgent systems to be safe, secure, and only available to NSDesign Ltd for the purposes listed above. For more information, please visit FreeAgent and GDPR Compliance.
Eventbrite Booking System
We use Eventbrite to manage bookings for most of our commercial workshops. As well as collecting the required data from attendees, Eventbrite also handles the associated credit card payments. NSDesign are not privy to the payment details (only gaining access to attendee name, phone, email, and booking information). Eventbrite processes invoices for all transactions related to the booking of an event. As such, we are required by HMRC to retain these financial records for at least 6 years from the end of the last financial year.
We believe the data held on the Eventbrite systems to be safe, secure, and only available to NSDesign Ltd for the purposes listed above. For more information, please visit the Eventbrite Privacy Policy.
Dropbox Cloud Storage
We use Dropbox to securely store and share certain files relating to our client work, including training materials, project documents and other resources. Dropbox is a well-established cloud storage provider, and we only use it where necessary to deliver our services effectively.
While Dropbox acts as the data processor, NSDesign remains the data controller, which means we are responsible for how your data is used and managed. Dropbox complies with UK GDPR requirements and provides strong security measures to protect stored data.
Access to files in Dropbox is restricted to NSDesign staff who need it, and we review permissions regularly. We only keep data in Dropbox for as long as is required to provide our services or meet legal obligations, after which it will be deleted.
We believe the data held on the Dropbox system to be safe, secure, and only available to NSDesign Ltd for the purposes listed above. For more information, please visit the Dropbox Privacy Policy.
Generative AI Tools (such as ChatGPT)
From time to time we may use generative AI tools, including ChatGPT and Claude, to help us create and improve resources such as training materials, reports, or marketing content. These tools can assist with drafting text, brainstorming ideas, or repurposing existing content, helping us to deliver services more efficiently.
We are careful about how we use AI systems and take steps to protect your privacy. We do not upload or share any sensitive or personally identifiable information about our clients when using these tools. Any information we do provide is limited to what is necessary, anonymised where possible, and used strictly for the purposes of supporting our work with you.
As with all third-party systems, we remain the data controller and take full responsibility for how your information is managed. We assess the AI tools we use and apply appropriate data protection, information security and human-review controls. Our use of AI is kept under regular review as tools, supplier terms and regulatory guidance evolve. For more information, please visit the OpenAI Privacy Policy and the Anthropic Privacy Policy.
Giving your consent
It is important that you read and understand these statements. By ordering any of our products or services, a binding agreement between yourself (and/or your business) and NSDesign Limited will be created such that we can use your information in this way.
Disclosures
We warrant that we will not disclose your information or personal details to any other third party without your approval other than is set out elsewhere in this privacy statement
We will not send you any unsolicited commercial e-mail unless you have given your prior consent. We will seek to act in the best interest of our customers, and will not abuse our position of data controller for any commercial gain.
In the event we sell our business or assets the personal data we collect about you may be transferred to the purchaser of our business or assets. We may also use the information we collect about you in order to enforce or apply our terms of use or supply. To prevent or detect fraud or abuse of this site, or to assist in verifying your identity, we may make searches of our data records and reserve the right to cooperate with law enforcement agencies should fraud or illegal activities occur. If you give us false or inaccurate information and we suspect fraud, we will record this. We may use this information to protect our interests including without limitation to protect the rights property or safety of NSDesign Limited, our customers or others. This includes exchanging information with other companies and organisations for the purposes of credit risk and fraud reduction.
Contact us
Should you wish to contact us regarding this privacy statement please contact us using the contact details set out at the bottom of this webpage. For the purposes of complying with GDPR, please note that our Managing DIrector Gary Ennis is our appointed Data Protection Lead and principal contact for data protection matters, and can also be reached directly via the contact details below.
Have we done something wrong?
If you think there is a problem with the way we have handled your data then be aware you have the right to raise a complaint to the ICO (Information Commissioner’s Office). We’d be grateful if you spoke to us about the issue first, but if you’d prefer to go direct to the ICO please visit: https://ico.org.uk/.
Thank you for your trust.
This policy was last updated July 2026.