PRIVACY POLICY

1. Introduction and scope

The Codex Protocol® Limited (company number 17235272) whose registered office is at Crown Walk, 1 Jewry Street, Winchester, Hampshire, United Kingdom, SO23 8BB (“The Codex Protocol”, “we”, “us” or “our”) is responsible for this website and for the processing of your Personal Data as described in this Privacy Policy.

The Codex Protocol is committed to safeguarding the privacy and personal data of all individuals with whom we interact. We respect the rights of individuals to control their personal information and handle all personal data in accordance with applicable data protection and privacy laws that apply to us. Our approach to data privacy reflects our broader commitment to transparency, accountability, and regulatory compliance, ensuring that personal information is collected, used, stored, and disclosed responsibly and lawfully.

This Privacy Policy explains how The Codex Protocol collects and processes Personal Data through your use of our website, The Codex Protocol platform and any related products or services, including any Personal Data you provide when you visit our website, create an account, register for or access The Codex Protocol, purchase access, participate in coaching sessions, live sessions, cohort-based activities or community features, submit reflections, comments, questions, feedback or other content, request marketing, contact us or otherwise interact with us.

This Privacy Policy applies to:

  • any Personal Data provided to us through our website (“Website Data”);
  • any Personal Data provided to us in connection with your account, registration, onboarding, purchase, access to The Codex Protocol, coaching support, customer support or contractual relationship with us (“Guest Data”); and
  • any Personal Data contained in content, reflections, comments, questions, feedback, coaching interactions, live sessions, community activities or other materials that you choose to submit, share or make available through The Codex Protocol (“Submission Data”).

Where we process Website Data, Guest Data and Submission Data, The Codex Protocol is the controller.

For further information regarding how The Codex Protocol processes Personal Data relating to its personnel—including prospective and current employees, independent contractors, and other staff—you may contact us at [email protected]. This includes inquiries about data collection, use, retention, and your rights under applicable data protection laws.

Our website and services, including The Codex Protocol platform, are not directed at individuals under the age of 18, and we do not knowingly collect Personal Data from them.

2. What Personal Data do we collect and how do we use it?

As part of our business operations, we collect various categories of Personal Data to support the delivery of our website and The Codex Protocol platform, and to fulfil our contractual and legal obligations.

Website Data

The Codex Protocol collects Website Data, including but not limited to email addresses, telephone numbers, company names (where applicable), job titles, and any additional information voluntarily provided when submitting a request or inquiry through the website’s contact forms or interactive features.

In addition to the information you may provide directly, we may also collect certain technical data about your device and browsing behaviour. This may include your computer’s IP address, operating system, browser type, and similar information. Such data is gathered for system administration purposes and may be used to compile statistical reports on website usage, which we may use in aggregated form to understand website usage and improve our website, services and marketing activities. This information helps us improve the functionality and accessibility of our website and services.

We also collect Personal Data through the use of cookies and similar tracking technologies. Further details on how we use cookies, and how you can manage your preferences, are available in our Cookie Policy.

We use the Website Data in the following ways where it is necessary for our legitimate interests:

  • to ensure that content from our website is presented in the most effective manner;
  • to analyse the data for the purposes of improving our website and services;
  • to prevent fraud and/or for security; and
  • to respond to a request submitted via our website.

Where applicable, we use Website Data to fulfil our obligations under any terms and conditions applicable between you and The Codex Protocol. This may include, for example, responding to service inquiries or processing requests submitted via the website. In certain instances, we may also seek your explicit consent to use your Website Data—for example, when registering you for newsletters, updates, or other forms of direct communication that you have requested.

The Codex Protocol does not sell or rent Website Data to third parties. We may share Website Data only as described in this Privacy Policy, including with our service providers where necessary for the operation of our website, communications, analytics, security and business administration. However, Website Data may be entered into our internal contact database for the purposes of managing ongoing communications and business relationships. We retain such information in accordance with the retention periods and principles described in the Storage and Retention section of this Privacy Policy.

We do not use your Personal Data for automated decision-making, including profiling, that produces legal or similarly significant effects on you. The Codex Protocol may generate or make available AI-assisted, avatar-led, narrative, coaching, reflective, educational or programme-related content and outputs. These are provided for personal and professional development purposes only and do not produce legal or similarly significant effects on you.

Guest Data

Where you create an account, purchase access, complete registration or onboarding, access digital content, book or attend coaching sessions, participate in live sessions, cohort-based activities or community features, or otherwise access The Codex Protocol platform, the collection and processing of your Personal Data may be necessary for the performance of the contract between you and The Codex Protocol.

The types of Personal Data we may collect include:

  • your full name;
  • your job title;
  • your contact details, including your e-mail address, phone number and, where applicable, the name of your company;
  • account information, login credentials and authentication information;
  • billing information, payment status, transaction references, purchase history, access period, programme participation and session booking information; and
  • support communications and information about your use of The Codex Protocol platform.

We may also collect and process the following additional Personal Data about you:

  • if you contact us, we may keep a record of that correspondence;
  • where you log into the website, you will be required to set up an account following which we will also process your account information including your username and authentication credentials; and
  • details of your visits to our website including, but not limited to, traffic data, location data, weblogs and other communication data, and the resources that you access (see section on Website Data below).

Where payments are processed by a third-party payment provider, we may receive limited payment and transaction information, such as payment status, transaction references, billing details and purchase history. We do not usually receive or store full payment card details.

We process Guest Data to create and manage your account, authenticate your access, process purchases, manage access, deliver programme content, administer coaching sessions, provide support, communicate with you and operate The Codex Protocol platform. Where you use The Codex Protocol platform on behalf of a company or organisation, we may process your Personal Data for our legitimate interests in providing The Codex Protocol to that company or organisation and managing the related business relationship.

While you are not legally required to provide us with your Personal Data, failure to do so may prevent us from delivering the services in full or may limit our ability to meet our contractual requirements to you.

We use Personal Data for the following purposes and lawful bases:

  • to operate our website, present content effectively, analyse website usage, prevent fraud and maintain security — our legitimate interests;
  • to create and manage your account, provide access to The Codex Protocol platform, process purchases, manage access, deliver programme content, administer coaching sessions, provide support, communicate with you and operate The Codex Protocol platform — performance of a contract with you, or our legitimate interests where you act on behalf of an organisation;
  • to send marketing communications — consent where required by law, or our legitimate interests where permitted;
  • to comply with applicable law or regulation — compliance with legal obligations; and
  • for record-keeping, audit, security, fraud prevention and the establishment, exercise or defence of legal claims — legal obligation and/or our legitimate interests.

In certain circumstances, where required by law or regulatory guidance, we may seek your explicit consent to process your Personal Data. In such cases, we will ensure that any request for consent is presented in a clear, transparent, and easily understandable manner, and that your consent is freely given, specific, informed, and unambiguous.

Submission Data

Information you submit, share or make available through The Codex Protocol may, depending on its content, include Personal Data (“Submission Data”). For example, Submission Data may include reflections, comments, questions, feedback, coaching notes, session interactions, community contributions, preferences, development goals or other information relating to your personal or professional development.

Where Submission Data includes Personal Data, we may process it to:

  • provide The Codex Protocol and deliver programme content, coaching support, live sessions, cohort-based activities, community features and related services;
  • personalise or support your experience within The Codex Protocol;
  • administer live or recorded sessions, coaching interactions and related communications;
  • create summaries, notes, transcripts or other programme-related records where applicable;
  • provide customer support, troubleshoot issues and maintain records;
  • improve The Codex Protocol, including programme structure, content, resources, tools, coaching support, user experience and service quality; and
  • comply with legal obligations, enforce our terms, protect our rights and establish, exercise or defend legal claims.

You are responsible for ensuring that you do not submit or disclose Personal Data about another person unless you have an appropriate basis to do so.

We do not use Submission Data to make decisions that produce legal or similarly significant effects on individuals.

Our lawful bases for processing Submission Data, where it includes Personal Data, are performance of a contract with you, our legitimate interests in providing, maintaining, improving and protecting The Codex Protocol, compliance with legal obligations, and, where applicable, your consent.

Where we record or transcribe any live session or coaching session, we will notify you in advance and, where required by law, obtain your consent.

3. Where we store your Personal Data

3.1 Storage and Retention

Unless otherwise permitted or required by applicable law or regulation, The Codex Protocol will retain your Personal Data only for as long as is necessary to fulfil the specific purpose for which it was collected. For example, enquiry data submitted via our website is generally retained for up to twelve months, while account-related information is kept for as long as your account remains active. Business contact details may be retained for longer where necessary to maintain an ongoing business relationship. Programme, account, transaction, billing, coaching, support, attendance and access records may be retained for as long as necessary to provide The Codex Protocol, maintain business records, resolve disputes, comply with legal, accounting and tax obligations, and establish, exercise or defend legal claims.

When determining the appropriate retention period, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether we can achieve those purposes by other means, and applicable legal, accounting, tax and regulatory requirements.

Where we generate recordings, transcripts, summaries, notes, usage analytics, preferences, programme engagement data or other technical or analytical data, and such data includes or can reasonably be linked to Personal Data, we may retain it for as long as reasonably necessary for programme delivery, coaching support, quality assurance, service improvement, security, audit and legitimate business purposes, subject to applicable data protection laws.

In some circumstances, we may anonymise Personal Data so that it can no longer be associated with you. We may use anonymised information indefinitely for research, statistical, benchmarking and product improvement purposes.

In certain cases, we may retain data for longer periods where required to comply with legal or regulatory obligations, or where necessary for the establishment, exercise, or defence of legal claims.

If you request the deletion of your Personal Data, we will respond to your request in accordance with applicable data protection laws. Our response will consider our legal obligations and any permissible grounds for continued retention, including where we are required or permitted to retain certain records or anonymised or non-identifiable data.

For further details regarding how to exercise your rights—including the rights of access, correction, deletion, or objection—please refer to the “Your Rights” section of this Privacy Policy below.

3.2 Transfers out of the UK and EEA

The Codex Protocol typically stores Personal Data on secure servers located within the United Kingdom or the European Economic Area (“EEA”). However, in the course of our operations, we may transfer Personal Data to third-party service providers, professional advisers, group companies, business partners or other recipients described in this Privacy Policy who are located outside the United Kingdom or the EEA, including in the United States.

Where we transfer Personal Data outside the United Kingdom or the EEA, we will do so in accordance with applicable data protection laws and will ensure that appropriate safeguards are in place. These safeguards may include reliance on UK adequacy regulations, an adequacy decision issued by the European Commission, or the use of legally recognised contractual protections, such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

These safeguards are intended to ensure that your Personal Data receives an appropriate level of protection when transferred internationally.

4. How we protect your data

The Codex Protocol has implemented appropriate technical and organisational measures to safeguard Personal Data and protect it against accidental loss, unauthorised access, use, alteration, disclosure or destruction. These measures are designed to support the ongoing confidentiality, integrity, and availability of the Personal Data we process.

Electronic data and databases are securely stored on protected computer systems, and access to such data is restricted and managed through a combination of physical controls and electronic safeguards. Access rights are granted on a need-to-know basis and only to employees, agents, contractors and other third parties who have a business need to access the relevant Personal Data and are regularly reviewed to maintain appropriate levels of protection.

In addition, our personnel receive training on data protection and privacy obligations. We adhere to our internal data protection policies and procedures, which all employees and relevant third parties are required to follow when handling Personal Data. Where third parties process Personal Data on our behalf, they are required to process it only for specified purposes, in accordance with our instructions where applicable, and subject to appropriate confidentiality and security obligations. These measures help ensure that data is processed responsibly, securely, and in accordance with applicable legal and regulatory standards.

We have put in place procedures to deal with any suspected Personal Data breach and will notify affected individuals and any applicable regulator where we are legally required to do so.

5. Disclosures of Personal Data

We may share your Personal Data with selected third-party suppliers and service providers, including payment processors and billing providers, who assist us in delivering our website, The Codex Protocol platform and related services and in fulfilling the purposes described in this Privacy Policy.

These may include IT hosting providers, cloud hosting providers, platform providers, coaching support providers, scheduling providers, payment processors and billing providers, AI, avatar, video, audio, transcription, analytics and content delivery providers, CRM providers, email and communications providers, security, fraud prevention and compliance providers, professional advisers such as accountants, auditors and legal advisers, and other trusted suppliers who support the operation of our business.

All such disclosures are made in accordance with applicable data protection laws and are subject to appropriate safeguards to ensure the security and confidentiality of your Personal Data. Where legally required, disclosures will be made on a confidential basis and subject to contractual or statutory obligations that protect your privacy and limit the use of the data to the specified purposes. Where third-party service providers process Personal Data on our behalf, we require them to process it only for specified purposes, in accordance with our instructions where applicable, and subject to appropriate confidentiality and security obligations. Some third parties, such as payment providers, professional advisers or analytics providers, may act as independent controllers in respect of certain processing activities.

We may also disclose your Personal Data to third parties:

  • in the event that we sell or buy a business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets;
  • if The Codex Protocol or substantially all of its assets are acquired by a third party, in which case Personal Data held by it will be one of the transferred assets; or
  • if we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation, to enforce or apply our terms of use and other agreements, or to protect the rights, property or safety of The Codex Protocol, our customers, users, service providers or others. This includes providing information to our accountants, auditors and legal advisers and exchanging information with other companies and organisations for the purposes of fraud protection, security, compliance and risk reduction.

If a change happens to our business, the new owner may use your Personal Data in the same way as described in this Privacy Policy.

6. Your Rights

6.1 Opt-Out

You have the right to object to the processing of your Personal Data for direct marketing purposes. You can exercise this right at the point of data collection by selecting the appropriate options on our data submission forms, which allow you to opt out of receiving marketing communications.

Additionally, you may withdraw your consent or object to marketing-related processing at any time by contacting us directly at [email protected] or by following the unsubscribe or opt-out link included in any marketing communication we send to you. Upon receipt of such a request, we will promptly update our records to ensure that your preferences are respected in accordance with applicable data protection laws.

All direct marketing communications will be sent in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR), meaning we will only send you electronic marketing where we have your prior consent or are otherwise permitted to do so by law. Where you opt out of marketing, we may still send you service, transactional or administrative communications relating to your account, purchases, programme access, coaching sessions, legal notices or use of The Codex Protocol platform.

6.2 Data Subject Rights

In addition to the right set out above, applicable data protection laws provide individuals the following rights:

  • to request access to the Personal Data we hold about you;
  • to request correction or deletion of your Personal Data;
  • to withdraw your consent for a specific use of your Personal Data provided to us;
  • to request restriction of processing by us of your Personal Data;
  • to object to processing of your Personal Data by us;
  • to obtain copies of the data that we hold about you in a machine-readable format and to transfer such data to another company on your request.

Where we rely on legitimate interests as our lawful basis, you may have the right to object to that processing.

However, please note that some of these rights may not always apply, as there are sometimes requirements and exemptions which may mean we need to keep processing the Personal Data or not disclose it, or other times when the rights may not apply at all. As such, each request will be evaluated based on the request type, context of the personal information in question, and other applicable factors.

If you wish to exercise any of these rights, please contact us at [email protected]. We will process such requests promptly and in accordance with applicable data protection laws.

You will not usually have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse to comply with a request if it is clearly unfounded, repetitive or excessive.

We may need to request specific information from you to confirm your identity and ensure that Personal Data is not disclosed to someone who is not entitled to receive it.

We aim to respond to legitimate requests within one month. If your request is complex or you have made a number of requests, it may take us longer, in which case we will notify you and keep you updated.

7. Data Protection Complaints Process

Please read our full Complaints Policy, which can be found here.

If you have a complaint about how we process your Personal Data, please contact us at [email protected] and provide enough information for us to understand and investigate your complaint.

We will acknowledge your complaint within 30 days of receipt and will respond without undue delay once we have investigated the matter, including by informing you of the outcome of your complaint. If you are not satisfied with our response, or if you believe that our processing of your Personal Data violates your rights under applicable data protection laws, you have the right to lodge a complaint with the relevant supervisory authority.

In the United Kingdom, this is the Information Commissioner’s Office (ICO), which can be contacted via its website at https://ico.org.uk or at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We are registered with the ICO with registration number ZC233023.

We encourage you to contact us directly in the first instance at [email protected] so that we may address your concerns promptly and fairly. However, you are entitled to escalate the matter to the supervisory authority at any time.

A full list of supervisory authorities in the EEA can be found on the European Data Protection Board’s website at www.edpb.europa.eu/about-edpb/about-edpb/members_en.

8. Links to Third Party Websites

From time to time, our website or The Codex Protocol platform may include links to or from third-party websites, platforms, tools or services. Please be aware that these external sites and services operate independently and are governed by their own privacy policies. If you choose to follow a link to any such website or use any such third-party service, you do so at your own discretion and risk.

The Codex Protocol accepts no responsibility or liability for the content, practices, or privacy standards of third-party websites, platforms, tools or services, nor for any Personal Data you choose to submit to them. We strongly encourage you to review the applicable privacy policies of those websites and services before providing any personal information or engaging with their services.

9. Contact

Any questions you have in relation to this policy and how we use your Personal Data should be sent to [email protected].

We are not required to appoint a Data Protection Officer under UK data protection law. If we are required to appoint an EU representative or any other local representative in the future, we will update this Privacy Policy with the relevant details.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our website, The Codex Protocol platform, our processing activities, applicable law or regulatory guidance. Any updated Privacy Policy will be posted on our website and will take effect when published, unless otherwise stated.

Please review this Privacy Policy periodically so that you remain informed about how we process your Personal Data. Please also keep us informed if your Personal Data changes during your relationship with us, as it is important that the Personal Data we hold about you is accurate and current.

Last updated: 2 September 2026