Data policy
Conexus Consulting Ltd
Last updated: 31st August 2026 · Version 2.0
This policy sets out how Conexus Consulting Ltd handles personal data arising from coaching, facilitation, assessment and consulting engagements. It is written for client organisations and for the individuals who take part in our work, and it is intended to give both a clear picture of what we do and what we will not do.
It sits alongside our privacy policy, which covers our website and our wider handling of personal data. Where an engagement contract or data processing agreement says something different, that document takes precedence.
1. Our approach
Three principles run through everything below.
We collect very little. Coaching and facilitation need a name, a way to contact someone, and a record of the work. We do not build profiles, we do not enrich data from outside sources, and we do not retain more than the engagement requires.
Session content belongs to the participant. What is said in a coaching session is not reported back to the sponsoring organisation, unless a reporting arrangement has been agreed with the participant in advance and confirmed to them in writing. Where such an arrangement exists, the participant knows its scope before saying anything that falls within it, and may withdraw from it at any time. This is a professional obligation as much as a legal one, and it is the foundation on which coaching works at all.
We say plainly what we do not do. We do not develop or host software. We do not operate servers. We are a small practice using established third-party platforms, and we describe our controls as they actually are rather than as an enterprise supplier would.
2. Who is the controller
Getting this right matters, because it determines who is answerable for what. In a typical engagement the roles divide as follows.
Participant name, role and contact details supplied to us to set up the workThe client organisation: controller Conexus: processor, acting on the organisation's instructions
Attendance, scheduling and engagement administrationThe client organisation: controller Conexus: processor
Content of individual coaching sessions and our notes of themThe client organisation: no role, and no right of access to this material Conexus: independent controller, holding the material in confidence for the participant
Material reported back to the organisation under a reporting arrangement agreed with the participant in advanceThe client organisation: controller of what it receives, within the agreed scope only Conexus: independent controller of the underlying record, disclosing only the agreed subset
Assessment responses and individual reportsThe client organisation: depends on who commissions and receives the report, to be agreed in writing before the assessment begins Conexus: processor or independent controller, as agreed
Aggregated, anonymised themes reported to the organisationThe client organisation: controller of the output Conexus: producer of the output
Our own contract, invoicing and business recordsThe client organisation: no role Conexus: controller
We recommend that the role allocation for each engagement is confirmed in writing at the outset, and that a data processing agreement under Article 28 of the GDPR is put in place wherever we act as processor. We are happy to work from your template or to provide one.
2.1 Reporting arrangements
Some engagements are set up on the basis that part of what is discussed is reported back to the organisation — for example against development objectives agreed at the start of a programme.
Where that applies, the scope of what will be shared is agreed with the participant and the organisation together, before coaching begins, and confirmed to the participant in writing. The participant knows what falls within the reporting scope before saying anything that falls within it.
Two points follow from this, and client organisations should be clear about both before commissioning work on this basis:
The participant's agreement is what makes the arrangement lawful, and it cannot be given on their behalf. Session content is where special category data arises, and we rely on the participant's explicit consent under Article 9(2)(a) of the GDPR to hold it. A sponsoring organisation cannot supply that consent for its employee. Under Article 7(3) the participant may withdraw it at any time; if they do, we will tell the organisation only that the reporting arrangement is no longer in place, and nothing about why.
The arrangement does not give the organisation access to the wider record. We remain independent controller of the underlying session material and disclose only the agreed subset. A reporting arrangement is a defined disclosure, not a change in who holds the record.
Anything outside the agreed scope is treated as ordinary session content and is subject only to the limits on confidentiality set out in our privacy policy.
3. What we process, and on what basis
The personal data we handle in an engagement is limited to:
Identity and contact data - name, role, organisation, email address, and where relevant a telephone number. Where an assessment platform requires it, gender may also be collected, because some instruments use gender-referenced norm groups.
Engagement data - session dates, attendance, coaching goals, agreed actions, and our working notes.
Assessment data - responses to psychometric or Enneagram instruments, and the profiles and reports generated from them.
Anything a participant chooses to disclose in the course of a session.
Any further information an assessment platform may request - age, occupation, educational background and similar - is optional, and participants are told so.
Where we act as processor, our legal basis follows the client organisation's. Where we act as controller in our own right, we rely on the performance of a contract, on our legitimate interests in delivering and administering the work, and - for assessment data and for sensitive information disclosed in session - on the participant's explicit consent under Article 9(2)(a) of the GDPR.
4. Assessment and psychometric instruments
Assessment raw data is held on the secure infrastructure of the relevant test publisher rather than by us. We use only publishers of established professional standing that can evidence their own compliance with data protection law, and we work within the licensing and ethical conditions of each instrument.
Participants are told before completing an assessment what the instrument is, who will see the output, and how long the data will be held. Participation is voluntary, and a participant may withdraw at any point up to the debrief.
Assessment output is always interpreted by an accredited practitioner in conversation with the participant. It is never delivered as a bare report, and it is not used for selection, promotion, performance management or exit decisions. If a client organisation intends to use assessment output in that way, it must tell us and tell participants before the assessment takes place, because that changes both the lawful basis and the transparency obligations that apply.
5. Recording, transcription and AI tools
We do not record coaching or facilitation sessions, and we do not use automated transcription or AI notetaking tools in them, unless every participant has been told in advance and has agreed.
Where a recording is made by agreement - for example for a participant's own use, or for supervision - we will say who will have access to it, where it will be held and when it will be deleted. Consent may be withdrawn, and a participant who does not consent will not be disadvantaged.
Where a client organisation's own conferencing platform applies automatic recording or transcription, we will ask for it to be turned off for coaching sessions.
6. Sub-processors and associates
We rely on a small number of third-party providers for assessment hosting, email, file storage, calendar, video conferencing, scheduling and invoicing. Each is engaged under terms that include the obligations required by Article 28(3) of the GDPR. A current list is available on request.
Where we engage an associate coach or facilitator on an engagement, that associate is a sub-processor. We will:
seek the client organisation's written agreement before engaging an associate on its work;
put written confidentiality and data protection terms in place with the associate before any data is shared;
give the associate access only to the specific engagement material needed, and remove that access when the work ends;
remain fully responsible to the client for the associate's handling of personal data.
We will give reasonable notice of any intended change to our sub-processors and will consider any objection raised.
7. Security measures
The measures we apply under Article 32 of the GDPR are proportionate to a small practice holding sensitive but low-volume information:
full-disk encryption, device passcodes and automatic screen locking on every device used for client work;
individually credentialled accounts with multi-factor authentication on all business platforms, and credentials held in a password manager;
encryption in transit for all data, through platform interfaces and encrypted email; no removable media;
access on a least-privilege basis, granted per engagement and revoked when it ends;
prompt application of operating system and application updates, with the operating system firewall and malware protection enabled;
paper records, where they exist, held in locked storage and destroyed by cross-cut shredding;
reliance on platform providers for infrastructure-level controls, since we operate no servers or network of our own.
We do not claim controls we do not have. We do not operate an intrusion detection system, a security operations centre or a formal vulnerability management programme, because we hold no infrastructure to which those controls would apply.
8. Personal data breaches
We maintain an internal record of any personal data breach, including those we are not required to report.
Where we act as processor, we will notify the client organisation's nominated contact without undue delay and in any event within 24 hours of becoming aware of a breach affecting its data, so that the organisation can meet its own 72-hour notification obligation under Article 33 of the GDPR. Our notification will describe what happened, the categories and approximate number of records affected, the likely consequences and the steps taken.
Where we act as controller, we will notify the Data Protection Commission within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, and will inform affected individuals directly where the risk is high.
We will co-operate fully with any investigation, and will not withhold information because it is unflattering to us.
9. Assisting with individual rights
Where we act as processor, we will assist the client organisation in responding to requests from individuals exercising their rights, and will pass on any request we receive directly rather than answering it ourselves.
Requests relating to coaching session content are directed to us rather than to the sponsoring organisation, because that material is held under our own confidentiality obligation. A participant may ask us at any time to correct or delete our notes, and we will do so unless we are legally required to keep them.
A participant may also withdraw from a reporting arrangement of the kind described in section 2.1 at any time, with effect from the point of withdrawal. We will confirm the withdrawal to the participant in writing and inform the organisation that the arrangement is no longer in place, without giving a reason. Material already disclosed within the agreed scope before withdrawal is not recalled, but nothing further is shared.
10. International transfers
Some providers we rely on are established outside the EEA, principally in the United States. Any such transfer is made under an appropriate safeguard from Chapter V of the GDPR - an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified, or the European Commission's standard contractual clauses supported by a transfer impact assessment.
We keep the status of these safeguards under active review, and will tell clients if a change materially affects an engagement.
11. Retention, return and deletion
Retention periods are set out in our privacy policy. Where a client organisation specifies a different period for an engagement, that period applies to the data we hold on its behalf.
At the end of an engagement we will, at the client's option, return or delete the personal data we hold as processor, other than material we are required to retain by law or that is held under our own confidentiality obligation to a participant. We will confirm deletion in writing on request.
12. Records and accountability
We maintain a record of our processing activities under Article 30 of the GDPR, a record of personal data breaches, and a register of the sub-processors we use. These are available to client organisations on request as part of due diligence.
We do not currently hold ISO 27001 or equivalent certification, and we say so rather than implying otherwise.
13. Contact
Questions about this policy, or about how we handle information in a particular engagement, should go to:
Patrick Boland, Director Conexus Consulting Ltd info@conexus.ie
You may also contact the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland — www.dataprotection.ie