top of page
Blue Gnu Logo (grey font).png
Get in Touch

General Privacy Policy

Last updated:  18th August 2026 

​

Introduction 

​

Blue Gnu Consulting Limited ("Blue Gnu", "we", "us", "our") is committed to protecting and respecting the privacy of individuals whose personal information we process. 

​

This Privacy Notice explains how we collect, use, store, share and protect personal information in connection with our business activities and services. 

​

It applies to: 

​

  • Clients and prospective clients 

  • Participants attending learning and development programmes 

  • Individuals completing assessment and profiling tools 

  • Associates, facilitators and contractors 

  • Suppliers and business contacts 

  • Individuals who contact us directly by email, telephone or other means 

 
This Privacy Notice should be read alongside any project-specific privacy information that may be provided by our clients, assessment providers or service partners. 

​

Who We Are 

​

Blue Gnu Consulting Limited provides learning, leadership development, team development and organisational development services. 

​

For many of our business activities, Blue Gnu acts as a data controller, meaning we determine the purposes and means of processing personal information.

 

For certain client engagements, Blue Gnu acts as a data processor, processing personal data on behalf of and under the instructions of our clients. 

​

Contact Details 

​

Blue Gnu Consulting Limited 
Ashfield House, Grange Road, Ash, Surrey. GU12 6HB 

​

Email: admin@bluegnuco.com 

​

If you have any questions about this Privacy Notice or our data protection practices, please contact us using the details above. 

​

Personal Information We Collect 

​

Depending on our relationship with you, we may collect and process: 

​

Contact Information 

​

  • Name 

  • Job title 

  • Organisation 

  • Email address 

  • Telephone number 

  • Postal address 

 

Client and Service Information 

​

  • Programme participation records 

  • Workshop attendance information 

  • Learning and development records 

  • Feedback and evaluation information 

  • Communication records relating to services 

 

Assessment and Profiling Information

 

Where relevant, we may process: 

  • Insights Discovery profiles 

  • Motivational Maps profiles 

  • Assessment reports 

  • Learning and development outputs generated through assessment tools 

 

Business Administration Information 

​

  • Contract information 

  • Invoicing and payment records 

  • Supplier and contractor records 

 

Technical Information 

​

  • Email communications 

  • Online meeting participation details 

  • Limited system and security information where necessary 

  • We do not intentionally collect special category personal data unless required for a specific engagement and supported by an appropriate lawful basis. 
     

We will never sell your personal data to third parties. 

​

How we Use Personal Information 

​

We use personal information to: 

​

  • Deliver learning and development services 

  • Manage client relationships 

  • Facilitate workshops, coaching and team development activities 

  • Administer assessments and profiling tools 

  • Manage contracts and commercial relationships 

  • Communicate with clients, participants and associates 

  • Maintain business records 

  • Meet legal, regulatory and professional obligations 

  • Protect the security of our systems and information 

 

We use personal information only for legitimate business purposes and in accordance with applicable data protection legislation. 

​

Lawful Bases for Processing 

​

When acting as a data controller, we rely on one or more of the following lawful bases under UK GDPR: 

​

Contract 

​

Where processing is necessary to: 

​

  • Deliver services 

  • Manage client relationships 

  • Administer agreements and engagements 

 

Legitimate Interests 

​

Where processing is necessary for: 

​

  • Managing and developing our business 

  • Maintaining client relationships 

  • Delivering professional services 

  • Internal administration 

  • Information security 

 

We carefully balance our legitimate interests against the rights and freedoms of individuals. 

​

Legal Obligation 

​

Where processing is necessary to comply with legal obligations, including: 

​

  • Tax and accounting requirements 

  • Regulatory obligations 

  • Legal claims and dispute management 

 

Consent 

​

Where consent is required, such as for certain marketing activities or specific assessment-related uses, individuals may withdraw consent at any time. 

​

Assessment and Profiling Tools 

​

Blue Gnu Consulting facilitates the use of assessment and profiling tools including: 

​

  • Insights Discovery 

  • Motivational Maps 

 

These tools are intended to support learning, development, self-awareness and team effectiveness. 

Assessment information is used solely for development purposes and is not used by Blue Gnu for automated decision-making. 

​

Participants are provided with information regarding the processing of their assessment data by the relevant assessment provider. Blue Gnu may have access to resulting profile information where necessary to facilitate development activities and provide professional services. 

​

When We Act as a Data Processor 

​

For certain learning and development engagements, Blue Gnu may process personal data on behalf of a client organisation. 

​

In these situations:

 

  • The client remains the data controller. 

  • Blue Gnu processes data only in accordance with client instructions. 

  • Blue Gnu does not use such data for its own independent purposes. 

  • Blue Gnu implements appropriate security measures to protect personal data. 

 

Where we receive requests relating to information controlled by a client, we will refer the request to the relevant data controller. 

​

Sharing Personal Information 

​

We may share personal information where necessary with: 

​

  • Clients 

  • Approved associates and facilitators 

  • Assessment providers 

  • IT service providers 

  • Cloud storage providers 

  • Professional advisers 

  • Regulatory bodies where required by law 

 

All third parties are expected to manage personal information securely and in accordance with applicable legal requirements. 

​

International Transfers 

​

Some service providers used by Blue Gnu may process information outside the United Kingdom. 

​

Where international transfers occur, we take reasonable steps to ensure that appropriate safeguards are in place to protect personal information in accordance with UK GDPR requirements. 

​

Information Security 

​

Blue Gnu is committed to protecting personal information through appropriate technical and organisational measures. 

​

These measures include: 

​

  • Access controls 

  • Password protection 

  • Multi-factor authentication where available 

  • Secure cloud-based systems 

  • Device encryption 

  • Staff awareness and training 

  • Incident management procedures 

 

Access to personal information is restricted to those who require it for legitimate business purposes. 

​

How Long we Keep Personal Information 

​

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected. 

​

Retention periods are determined by: 

​

  • Legal obligations 

  • Contractual requirements 

  • Professional requirements 

  • Legitimate business needs 

 

Further details are available within our Data Retention Schedule. 

​

Your Rights  

​

Where Blue Gnu acts as a data controller, individuals have the right to: 

​

  • Be informed about how their information is used 

  • Access their personal information 

  • Request correction of inaccurate information 

  • Request deletion of personal information in certain circumstances 

  • Restrict processing 

  • Object to processing 

  • Request portability of personal information where applicable 

  • Withdraw consent where consent has been relied upon 

 

Requests should be submitted using the contact details provided within this notice. 

​

Data Breaches 

​

Blue Gnu maintains procedures for identifying, reporting and managing personal data breaches. 

Where required by law, we will notify relevant authorities and affected individuals in accordance with applicable legal requirements. 

​

Complaints 

​

If you have concerns about how your personal information has been handled, please contact us in the first instance. 

​

You also have the right to make a complaint to the Information Commissioner's Office (ICO). 

​

Information Commissioner's Office 
Website: www.ico.org.uk 

​

Changes to this Privacy Notice 


This Privacy Notice may be updated periodically to reflect changes in legislation, business practices or services. 

​

The latest version will be made available upon request and, where appropriate, published on our website. 

​

Policy Reviews 

​

This policy is reviewed annually or when there are significant changes to our services or legal obligations 

​

Contact 

​

For any queries, please contact: 

​

Elaine Gosden 
Email: elaine@bluegnuco.com 
Telephone: +44 (0)7881 650745 

​

Commitment 

​

Blue Gnu Consulting Limited is committed to maintaining high standards of data protection and ensuring that all personal data processed on behalf of clients is handled securely, lawfully, and transparently. 

​

Approval and Ownership 

​

  • Policy Owner: CEO (Elaine Gosden) 

  • Approval Date: 18.08.2026 

  • Next Review Date: 07.04.2027 

bottom of page