Last updated: 6 August 2026
1. Who we are
HazelGRC Limited (“HazelGRC”, “we”, “us”) is an independent UK advisory firm providing Technology Assurance, Cyber Governance and AI Advisory services. We are the controller of the personal information described in this policy.
Privacy enquiries: privacy@hazelgrc.com.
2. Information we collect
- Contact and professional details you provide through our enquiry forms, email or events (name, organisation, role, email, telephone).
- Correspondence and enquiry content, including the nature of the advisory support you are seeking.
- Resource download details where you request an executive guide or assessment.
- Website and analytics information, including pages viewed and interactions, as described in our Cookie Policy.
3. How we use information
- To respond to enquiries and provide advisory, assurance and advisory-related services.
- To administer relationships with clients, prospective clients and professional contacts.
- To send executive insights and updates where you have asked to receive them.
- To operate, secure and improve our website and services, and to meet our legal and regulatory obligations.
4. Lawful bases
Where UK GDPR applies, we rely on: performance of a contract (delivering services you have engaged us for), legitimate interests (responding to business enquiries, running and securing our business), consent (optional marketing communications and non-essential cookies), and legal obligation (accounting, tax and record-keeping requirements).
5. HazelGRC Academy, training and events
This section explains how we handle personal information relating to the HazelGRC Academy, including corporate training, executive education, masterclasses, mentoring and public or in-house events. It supplements, and does not replace, the rest of this policy.
Information we collect
- Participant details: name, work email, organisation, job title, and the programme or session booked.
- Purchaser and billing details where an organisation books on behalf of participants: contact name, billing address, purchase order or invoicing references, and VAT details where applicable.
- Booking and order information: ticket type, quantity, order reference, booking status, cancellations, transfers and substitutions.
- Payment information processed by our payment provider. We do not store full card numbers; we receive confirmation of payment and limited transaction details.
- Delivery information: attendance records, joining details, access credentials issued for virtual delivery, and questions or contributions submitted during a session.
- Accessibility and reasonable-adjustment requests, and dietary or access requirements for in-person events, which may include information you choose to share about health or disability.
- Feedback, evaluation responses and certificates or completion records where a programme provides them.
- Optional marketing preferences, recorded separately from your booking.
How we use it
- To take bookings, confirm orders, issue joining instructions and deliver the programme.
- To process payments, issue invoices and receipts, and maintain accounting records.
- To administer cancellations, transfers, substitutions and refunds under the Academy Programme Terms.
- To provide reasonable adjustments and meet accessibility, safety and venue requirements.
- To issue attendance or completion records and to gather feedback that improves programme quality.
- To send service messages about a programme you have booked (these are not marketing).
- To send Academy updates and executive insights only where you have separately opted in.
Lawful bases
- Contract: administering and delivering a programme you or your organisation has booked.
- Legitimate interests: managing our Academy operations, programme quality, security and record-keeping, and communicating with corporate purchasers about their bookings.
- Consent: optional marketing communications, and any accessibility or dietary information you choose to provide that relates to health.
- Legal obligation: tax, accounting and statutory record-keeping.
Recipients and service providers
We use established third-party services to operate the Academy. Depending on the programme, these may include:
- Ticket Tailor — event registration, ticketing and order management.
- Stripe — payment processing.
- Microsoft 365 — email, documents and business communications.
- Microsoft Teams or Zoom — virtual programme delivery where applicable.
- Accounting, invoicing and payment providers — financial records and reconciliation.
- Venues and delivery partners for in-person events, where attendance details are necessary.
The role of each provider under data protection law varies. Some act on our instructions in relation to specific processing, while others determine aspects of their own processing — for example payment providers acting for fraud prevention and regulatory compliance purposes. We do not represent that every provider listed is a processor. Each provider’s own privacy notice explains how it handles information it holds in its own right.
International transfers
Some providers process information outside the UK. Where personal information is transferred outside the UK, we rely on an applicable safeguard — such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — together with additional measures where appropriate. You can request further information about the safeguards applied.
Retention
- Booking, attendance and delivery records: retained for the duration of the relationship and a reasonable period afterwards for administration and dispute handling.
- Financial and tax records: retained for the period required by UK accounting and tax law.
- Accessibility and dietary information: deleted shortly after the relevant session, unless you ask us to retain it for future programmes.
- Marketing preferences: retained until you withdraw consent, plus a record of the withdrawal itself.
Recording of sessions
Some programmes may be recorded for participant access or quality purposes. Where a session will be recorded, we tell participants in advance and explain how the recording will be used and how long it will be kept. Participants may keep cameras and microphones off where recording takes place.
Marketing
Marketing consent is always a separate, optional and unticked choice. Booking a programme, or accepting the Academy Programme Terms, never opts you into marketing. You can withdraw consent at any time using the unsubscribe link in any message or by emailing us.
6. Sharing information
We do not sell personal information. We share it with the service providers described above, with professional advisers, and where required by law or to establish, exercise or defend legal claims.
7. Security
We apply technical and organisational measures appropriate to the sensitivity of the information we hold, including access control, encryption in transit and supplier due diligence.
8. Your rights
Subject to conditions in law, you may request access to your personal information, correction, erasure, restriction, portability, and object to certain processing. Where we rely on consent, you may withdraw it at any time. To exercise a right, contact privacy@hazelgrc.com. You may also complain to the Information Commissioner’s Office (ico.org.uk).
9. Contact
HazelGRC Limited — privacy@hazelgrc.com · General enquiries hello@hazelgrc.com. See also the Academy Programme Terms.