Privacy policy.

1. About this policy

Eave respects your privacy and is committed to protecting your personal information.

This privacy policy explains how personal information is collected, used, stored and shared when you:

  • visit the Eave website;

  • contact Eave or submit an enquiry;

  • become a client, supplier or business contact;

  • participate in a workflow audit, questionnaire, interview or feedback exercise; or

  • otherwise interact with Eave.

It also explains your data-protection rights and how to contact Eave with a question or complaint.

2. Who we are

Eave is the trading name of Emma Vaughan, a sole trader based in England.

For the purposes of UK data-protection law, Emma Vaughan, trading as Eave, is the controller of personal information where Eave decides how and why that information is used.

Trading name: Eave
Legal name: Emma Vaughan
Email: hello@witheave.co.uk
Website:www.witheave.co.uk

References in this policy to “Eave”, “we”, “us” or “our” mean Emma Vaughan, trading as Eave.

3. When Eave may act on behalf of a client

During some workflow-audit projects, Eave may process personal information on behalf of the organisation that commissioned the work.

In those circumstances:

  • the client organisation will normally be the data controller;

  • Eave may act as its data processor;

  • the client’s own privacy notice may also apply; and

  • Eave will handle the information in accordance with its agreement with the client.

Eave remains the controller of personal information used for its own business purposes, including enquiries, contracts, invoicing, website administration and client communications.

4. The information we collect

The information collected will depend on how you interact with Eave.

Information you provide through the website

When you submit an enquiry, Eave may collect:

  • your name;

  • work email address;

  • company or organisation;

  • job title or role;

  • information about the workflow or problem you would like help with;

  • details about the teams or people involved;

  • relevant deadlines, priorities or budget;

  • correspondence between you and Eave; and

  • any other information you choose to provide.

Please avoid including sensitive personal information about yourself or anyone else unless it is genuinely necessary.

Client and project information

When you become a client or work with Eave, we may collect:

  • business contact details;

  • proposals, contracts and project scopes;

  • project correspondence and meeting notes;

  • information about your organisation, teams and working practices;

  • documents, screenshots, templates and process examples;

  • invoices, payment records and transaction information;

  • feedback about the services provided; and

  • information required to manage complaints, disputes or legal obligations.

Eave does not ordinarily store full payment-card information. Payments may be processed by a bank, payment provider or accounting platform under that provider’s own privacy arrangements.

Workflow-audit participant information

If you participate in a workflow audit, interview, questionnaire or feedback exercise, Eave may collect:

  • your name and business contact details;

  • your role, department or area of responsibility;

  • information about your involvement in the workflow;

  • questionnaire or interview responses;

  • feedback about processes, systems, workload and decision-making;

  • examples of delays, duplication, workarounds or operational problems;

  • notes taken during interviews or workshops;

  • documents, screenshots or examples you provide; and

  • audio or video recordings where this has been explained and agreed in advance.

Feedback may include professional opinions about working practices, management decisions or interactions with colleagues. Participants should focus on processes and relevant workplace experiences rather than providing unnecessary personal details about other people.

Website and technical information

Squarespace and connected website services may collect technical information such as:

  • IP address;

  • browser, operating system and device type;

  • approximate location;

  • pages visited;

  • referring website or source;

  • dates and times of visits;

  • interactions with the website;

  • cookie identifiers; and

  • security, diagnostic and website-performance information.

Information received from other sources

Eave may receive personal information from:

  • your employer or the organisation commissioning a project;

  • another project participant;

  • a professional referral or introduction;

  • publicly available business websites or professional directories;

  • professional networking platforms;

  • website, email, scheduling or survey providers; and

  • professional advisers and service providers.

5. Sensitive personal information

Eave does not normally need to collect special-category information, such as information about:

  • health or disability;

  • race or ethnic origin;

  • religious or philosophical beliefs;

  • political opinions;

  • trade-union membership;

  • sexual orientation or sex life;

  • genetic or biometric information; or

  • criminal convictions or offences.

Clients and participants are asked not to provide this information unless it is relevant and genuinely necessary.

Where sensitive information is provided unexpectedly, Eave may redact, restrict or delete it. Where it must be processed, Eave will first identify an appropriate lawful basis and any additional legal condition required.

6. How we use personal information

Eave may use personal information to:

  • respond to enquiries;

  • understand the support you are seeking;

  • arrange introductory calls or meetings;

  • prepare proposals, scopes and quotations;

  • enter into and manage contracts;

  • provide workflow audits and implementation support;

  • communicate with clients and project participants;

  • arrange interviews, questionnaires and workshops;

  • understand how a workflow operates;

  • identify recurring patterns, friction and improvement opportunities;

  • create process maps, findings and recommendations;

  • manage invoices, payments and financial records;

  • maintain client and supplier relationships;

  • improve Eave’s services, templates and internal processes;

  • protect the website, systems and business from misuse or security incidents;

  • maintain records of communication preferences;

  • send relevant business communications where permitted;

  • respond to complaints and data-protection requests;

  • establish, exercise or defend legal claims; and

  • comply with legal, tax, accounting and regulatory obligations.

7. Our lawful bases

Eave relies on one or more lawful bases depending on why the information is being used.

Taking steps before entering a contract

Information may be used to respond to an enquiry, discuss your requirements or prepare a proposal at your request.

Performance of a contract

Information may be used where it is necessary to provide agreed services, communicate about a project, manage payments or meet contractual obligations.

Legitimate interests

Eave may use information where it is reasonably necessary for legitimate business interests and those interests are not overridden by your rights.

These interests may include:

  • operating and developing Eave;

  • responding to business enquiries;

  • providing effective consultancy services;

  • understanding and improving workflows;

  • communicating with clients and professional contacts;

  • maintaining appropriate records;

  • improving services;

  • protecting the business and its systems;

  • preventing misuse and fraud; and

  • establishing, exercising or defending legal rights.

Where Eave relies on legitimate interests, the nature of the information, your reasonable expectations, the potential effect on you and available safeguards will be considered.

Legal obligations

Information may be processed where necessary to comply with tax, accounting, regulatory, data-protection or other legal requirements.

Consent

Consent may be used for specific optional activities, such as:

  • non-essential website cookies;

  • recording an interview where consent is appropriate;

  • sending optional marketing communications;

  • publishing an identifiable testimonial; or

  • another use clearly explained when consent is requested.

You may withdraw your consent at any time. This will not affect processing that took place before consent was withdrawn.

Eave will decide and document the appropriate lawful basis before using personal information for a particular purpose.

8. Confidential audit feedback

Workflow audits may involve gathering confidential feedback from people directly involved in the process being reviewed.

Where confidential feedback is collected:

  • participants will be told how their information will be used;

  • access will be restricted to those who need it for the project;

  • findings will normally be reported as combined themes;

  • comments will not normally be attributed by name;

  • unnecessary identifying details will be removed;

  • raw responses will not normally be shared with the commissioning organisation;

  • recordings will only be made where participants have been informed in advance;

  • Eave will seek to prevent feedback being used to identify or penalise individual participants; and

  • information will only be retained for as long as it is needed.

Confidentiality does not necessarily mean complete anonymity.

In a small team, someone may be identifiable from their role, circumstances or examples even where their name is removed. Eave will be honest about this risk and take reasonable steps to avoid unnecessary identification.

Staff feedback will be treated as operational evidence. It will not be gathered for the purpose of deciding which individual is “the problem”.

9. Recordings

Eave will not ordinarily record interviews or meetings without telling participants.

Where a recording is proposed, participants will be informed about:

  • why it is being recorded;

  • how the recording will be used;

  • who will have access;

  • whether a transcript will be created; and

  • how long the recording will be retained.

Recordings will normally be deleted once they have been transcribed, checked and are no longer required.

10. Artificial intelligence and automation

Eave may use business software, automation or artificial-intelligence tools to support appropriate administrative or project tasks, including:

  • organising information;

  • identifying repeated themes;

  • producing initial internal summaries;

  • drafting working materials;

  • checking consistency; or

  • exploring possible process improvements.

Where these tools are used:

  • meaningful human review will remain part of the work;

  • personal information will be minimised or pseudonymised where practical;

  • confidential identifiable information will not knowingly be submitted to public consumer AI tools;

  • appropriate provider and privacy settings will be used;

  • client restrictions and contractual requirements will be respected; and

  • AI-generated outputs will be checked rather than treated as automatically accurate.

Eave does not use personal information to make solely automated decisions that have legal or similarly significant effects on individuals.

11. Business communications and marketing

Eave may contact clients, former clients and relevant business contacts about services or information that may be of professional interest where permitted by law.

This may include information obtained through a previous business relationship, professional referral or publicly available business source.

You may object to marketing or ask Eave to stop contacting you at any time by emailing hello@witheave.co.uk.

Eave does not sell personal information to advertisers or other organisations.

UK data-protection law can still apply to business-to-business marketing where a named person’s contact details are used.

12. Cookies and website analytics

The Eave website is hosted by Squarespace.

Squarespace and connected services may use cookies or similar technologies to:

  • make the website work;

  • maintain website security;

  • remember visitor preferences;

  • understand website traffic;

  • measure performance; and

  • support connected or embedded website features.

Strictly necessary cookies may operate because they are required for the website to function.

Non-essential analytics, performance or advertising cookies will only be used where permitted and, where required, after the visitor has made a choice through the cookie banner.

Visitors can accept, decline or manage non-essential cookies through the website’s cookie controls. Browser settings may also be used, although disabling necessary cookies may affect how the website functions.

Squarespace allows non-essential cookies to be restricted until visitors interact with the cookie banner.

13. Who we share information with

Eave may share personal information with trusted organisations that support the business, including:

  • Squarespace and website-service providers;

  • email, calendar and video-meeting providers;

  • cloud-storage and document-collaboration providers;

  • survey, questionnaire and scheduling providers;

  • accounting, invoicing, banking and payment providers;

  • IT, security and technical-support providers;

  • professional advisers, including accountants, insurers and legal advisers;

  • carefully selected contractors or associates supporting a project;

  • the client organisation that commissioned a project, where appropriate;

  • regulators, courts, government bodies or law-enforcement authorities where required; and

  • another organisation involved in a sale, restructure or transfer of the business.

Providers acting on Eave’s behalf are expected to use information only for the relevant purpose and protect it appropriately.

Workflow-audit reports will normally contain combined themes and relevant examples rather than unnecessary identifiable raw responses.

Eave does not sell or rent personal information.

14. International transfers

Some technology and service providers may store or process information outside the United Kingdom.

Where personal information is transferred internationally, Eave will take reasonable steps to ensure an appropriate transfer mechanism and safeguards are in place.

These may include:

  • UK adequacy regulations;

  • approved contractual clauses or addenda;

  • contractual, technical and organisational safeguards; or

  • another legally recognised transfer mechanism.

15. How long we retain information

Personal information will only be kept for as long as reasonably necessary.

Eave’s normal retention periods are:

Enquiries that do not become projects

Up to 12 months after the last meaningful contact.

Client and project records

Up to six years after the project or client relationship ends, where records may be required for contractual, insurance, tax or legal purposes.

Financial and tax records

Normally at least six years, where required for accounting and tax purposes.

Raw audit responses and interview notes

Normally up to 12 months after the final project deliverable, unless a different period has been agreed.

Audio or video recordings

Normally deleted within three months of the final project deliverable, or sooner once transcription and checking are complete.

Marketing records

Until you unsubscribe, object or Eave determines the information is no longer relevant. A minimal record may then be retained to ensure your preference continues to be respected.

Anonymised information

Information that has been genuinely anonymised so that no individual can be identified may be retained for longer for internal learning, service improvement or portfolio evidence.

Information may be retained for longer where required by law, necessary to resolve a dispute or relevant to anticipated legal proceedings.

16. How we protect information

Eave uses reasonable organisational and technical safeguards appropriate to the nature of the information processed.

These may include:

  • password-protected systems;

  • multi-factor authentication;

  • access controls;

  • secure cloud services;

  • device and software updates;

  • confidentiality obligations;

  • data-minimisation practices;

  • separating identifying information from feedback where practical;

  • restricting access to project material; and

  • secure retention and deletion procedures.

No internet transmission or storage system can be guaranteed to be completely secure, but Eave takes reasonable steps to reduce the risk of unauthorised access, loss, misuse or disclosure.

17. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • be informed about how your information is used;

  • request access to your personal information;

  • ask for inaccurate or incomplete information to be corrected;

  • ask for information to be erased;

  • ask for processing to be restricted;

  • object to processing based on legitimate interests;

  • object to direct marketing;

  • receive certain information in a portable format;

  • withdraw consent where processing is based on consent; and

  • raise concerns about automated decision-making.

These rights are not absolute and may depend on the circumstances and lawful basis involved.

To exercise a right, email:

hello@witheave.co.uk

Please use the subject line Data protection request.

Eave may ask for enough information to confirm your identity and understand the request. Requests will ordinarily be handled without charge and within the period required by law.

18. Complaints

Please contact Eave first if you have concerns about how your personal information has been handled.

Email: hello@witheave.co.uk
Subject: Data protection complaint
You also have the right to complain to the UK Information Commissioner’s Office.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113

19. Children

The Eave website and services are intended for businesses and working professionals and are not directed at children.

Eave does not knowingly collect personal information from children. If Eave learns that a child’s information has been collected without an appropriate legal basis, reasonable steps will be taken to delete it.

20. Third-party websites

The website may contain links to third-party websites or embedded services.

Those organisations may collect and use information under their own privacy notices. Eave is not responsible for the privacy practices or content of third-party websites.

21. Changes to this policy

This policy may be updated when Eave’s services, technology, providers or legal obligations change.

The current version will be published on this website with an updated revision date.