Privacy policy

Conexus Consulting Ltd

Last updated: 31st August 2026 · Version 2.0

1. Who we are

Conexus Consulting Ltd ("Conexus", "we", "us", "our") is a leadership coaching, consulting and facilitation practice registered in Ireland.

Registered name:

Conexus Consulting Ltd

Company registration number:

60399149

Registered address:

9 The Moorings, Marina Village, Greystones, Co Wicklow, A63 TX65, Ireland.

Website:

www.conexus.ie

Contact for data protection matters:

info@conexus.ie

We are the data controller for the personal data described in this policy. We are not required to appoint a data protection officer under Article 37 of the GDPR, given the scale and nature of our processing. Patrick Boland, Director, is our point of contact for all data protection queries.

This policy explains how we collect and use personal data about visitors to our website, prospective and current clients, individuals we coach or work with in programmes, and our suppliers and contacts. It applies alongside our data policy, which sets out in more detail how we handle information arising from coaching, facilitation and assessment engagements.

2. The law we work under

We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679) and the Data Protection Act 2018. Our use of cookies and electronic marketing is governed by the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011).

Our supervisory authority is the Data Protection Commission in Ireland.

3. Whose personal data we hold, and where it comes from

We hold personal data about:

  • Website visitors - collected directly from you when you browse the site or complete an enquiry form.

  • Clients and prospective clients - collected directly from you, and sometimes from publicly available professional sources such as your organisation's website or LinkedIn.

  • Coaching clients and programme participants - collected directly from you during our work together, and also from the organisation that has engaged us, which may pass us your name, role and contact details before we meet.

  • Assessment participants - collected directly from you through the relevant assessment platform, and from the sponsoring organisation.

  • Suppliers, associates and professional contacts - collected directly from you.

Where your organisation has given us your details rather than you giving them to us yourself, we will tell you this at or before our first contact with you, and this policy serves as the notice required by Article 14 of the GDPR.

4. What we collect and why

4.1 Website visitors

Enquiry form contents - name, email address, organisation, message Why we hold it: to respond to your enquiry Legal basis: steps taken at your request prior to entering a contract, Article 6(1)(b); or our legitimate interest in responding to business enquiries, Article 6(1)(f)

Technical and analytics data - IP address (truncated where possible), browser and device type, pages viewed, referring site Why we hold it: to keep the site secure and to understand how it is used Legal basis: your consent to non-essential analytics cookies, Article 6(1)(a); and our legitimate interest in the security and integrity of the site, Article 6(1)(f)

4.2 Clients and prospective clients

Name, role, organisation and business contact details Why we hold it: to agree, deliver and administer engagementsLegal basis: performance of a contract, Article 6(1)(b)

Correspondence, proposals, contracts, invoices and payment records Why we hold it: to perform the contract and to meet our accounting and tax obligations Legal basis: performance of a contract, Article 6(1)(b); and compliance with a legal obligation, Article 6(1)(c)

Marketing preferences Why we hold it: to send occasional updates where you have asked for them Legal basis: your consent, Article 6(1)(a); or the existing-customer exemption under Regulation 13(11) of S.I. 336/2011

4.3 Coaching clients and programme participants

Name, role, organisation and contact details Why we hold it: to arrange and deliver sessions Legal basis: performance of a contract, Article 6(1)(b); or our and the sponsoring organisation's legitimate interest in delivering agreed development work, Article 6(1)(f)

Coaching goals, session notes, actions and reflections Why we hold it: to deliver an effective and continuous coaching relationship Legal basis: as above

Assessment responses, profiles and reports, including Enneagram and other psychometric instruments Why we hold it:to provide assessment feedback and development insight Legal basis: your explicit consent, Article 9(2)(a), read with Article 6(1)(a)

Information you choose to disclose during sessions that is sensitive in nature Why we hold it: because it arises naturally in coaching conversation and is relevant to the work Legal basis: your explicit consent, Article 9(2)(a)

4.4 A note on sensitive information in coaching

Coaching conversations are open-ended. In the course of them you may choose to tell us things that fall into the special categories of personal data under Article 9 of the GDPR - for example information touching on your physical or mental health, your religious or philosophical beliefs, your racial or ethnic origin, your sexual orientation, or your trade union membership. Some assessment instruments may also produce insight of this kind.

We do not seek this information out, and you are never obliged to share it. Where you do share it, we rely on your explicit consent to hold it, and we record only what is necessary to support the work. You may ask us at any time to delete anything you have shared, and we will do so unless we are legally required to keep it.

Holding this information is one thing; passing it on is another, and it needs your agreement separately. Where an engagement involves reporting anything from your sessions back to your organisation, that is dealt with in section 5, and your agreement to it is yours alone to give or withdraw.

4.5 Automated decision-making

We do not make decisions about you by automated means alone, and we do not carry out profiling that produces legal effects concerning you or similarly significantly affects you.

Where an assessment platform generates a report algorithmically from your responses, that report is a starting point for a conversation, not a decision. It is always interpreted and delivered by a qualified practitioner, and it is not used by us to select, rank, promote or exclude anyone. If your organisation intends to use assessment output as part of a selection or performance decision, that is the organisation's decision as controller, and it should tell you so.

5. Who we share personal data with

We do not sell personal data, and we do not share it for anyone else's marketing purposes.

We share personal data with:

  • Assessment and psychometric platform providers, who host assessment responses and generate reports. Only providers of established professional standing that can demonstrate compliance with data protection law are used.

  • Business software providers supporting email, file storage, calendar, video conferencing, scheduling and invoicing.

  • Associate coaches and facilitators, where we engage them on an assignment. They are bound by written confidentiality and data protection obligations.

  • Our accountants and professional advisers, and our insurers, where necessary.

  • Public authorities, where we are required by law to disclose information.

A current list of the providers we use is available on request.

Where we work under the instruction of a sponsoring organisation, we may share limited information with that organisation - for example attendance, engagement themes at an aggregate level, and confirmation that sessions took place.

Some engagements are set up on a different basis, where some of what is discussed is reported back to the organisation - for example against development objectives agreed at the start of a programme. Where that applies, we will agree the scope of what will be shared with you and with the organisation together, before coaching begins, and confirm it to you in writing. You will always know what is being reported before you say anything that falls within it.

Your agreement is what makes such an arrangement possible, and it cannot be given on your behalf by your employer. You may decline those terms, and you may withdraw your agreement at any time under Article 7(3) of the GDPR. If you withdraw, we will tell the organisation only that the reporting arrangement is no longer in place, and nothing about why. Anything already shared within the agreed scope before you withdrew cannot be recalled, but nothing further will be shared.

Beyond what has been agreed with you in that way, we do not share the content of individual coaching sessions with your employer. What is discussed in a coaching session stays between us, subject only to the exceptions set out in section 6.

6. Limits to confidentiality

Coaching confidentiality is a professional obligation as well as a data protection one, and we take it seriously. Separately from any reporting arrangement you have agreed to under section 5, there are narrow circumstances in which we may need to disclose something you have told us:

  • where there is a serious and imminent risk to your life or safety, or to the life or safety of another person;

  • where disclosure is required by law, by a court order, or by a regulatory or statutory body acting within its powers;

  • where the information concerns a risk of significant harm to a child or a vulnerable adult.

Where we can do so lawfully and safely, we will tell you before making any such disclosure.

7. Sending personal data outside the EEA

Some of the providers we rely on are established outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA we ensure an appropriate safeguard is in place under Chapter V of the GDPR, which will be one of:

  • an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the provider is certified under it;

  • the European Commission's standard contractual clauses, supported where necessary by a transfer impact assessment and additional technical measures.

We keep the status of these safeguards under review. You can ask us which mechanism applies to a particular provider.

8. How long we keep personal data

Category

Retention period

Website enquiries that do not lead to an engagement: 12 months from last contact

Client contract, engagement and correspondence records: 7 years from the end of the engagement, reflecting the six-year limitation period under the Statute of Limitations Act 1957 plus a margin

Financial and accounting records, including invoices: 6 years from the end of the accounting period, as required under the Companies Act 2014 and the Taxes Consolidation Act 1997

Coaching session notes: 24 months from the end of the coaching relationship, unless you ask us to delete them sooner

Assessment responses and reports: 24 months from the date of the assessment debrief, or the period set by the assessment provider, whichever is shorter

Marketing contact details: until you withdraw consent or ask us to stop, and reviewed every 24 months

Where a client organisation has instructed us to apply a different retention period for an engagement, that period applies to the data we hold on its behalf. At the end of the retention period we delete or securely destroy the records concerned.

9. How we protect personal data

We take appropriate technical and organisational measures under Article 32 of the GDPR, proportionate to the scale of our practice and the sensitivity of the information involved. These include:

  • full-disk encryption on all devices used for our work, with device passcodes and automatic screen locking;

  • individually credentialled accounts with multi-factor authentication on business systems, and passwords held in a password manager;

  • encrypted connections for all data in transit, and no use of removable media for client information;

  • access limited to those who need it for a specific engagement, and removed when that engagement ends;

  • paper notes, where they exist, kept in locked storage and destroyed by cross-cut shredding;

  • written confidentiality and data protection terms with any associate engaged on our work.

No system is completely secure, and we do not claim otherwise. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay.

10. Your rights

Under the GDPR you have the right to:

  • be informed about how your personal data is used, which is what this policy is for;

  • access the personal data we hold about you, and receive a copy of it;

  • rectification of personal data that is inaccurate or incomplete;

  • erasure of your personal data in certain circumstances;

  • restrict processing in certain circumstances;

  • data portability, where processing is based on consent or contract and is carried out by automated means;

  • object to processing based on our legitimate interests, and to object at any time to direct marketing;

  • withdraw consent at any time, where we rely on consent. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it;

  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise any of these rights, contact us at info@conexus.ie. We will respond within one month. If your request is complex, or if you have made several requests, we may extend that period by up to two further months and will tell you if we do. There is no charge, unless a request is manifestly unfounded or excessive.

We may ask you for enough information to satisfy ourselves of your identity before we act on a request.

11. Complaints

If you are unhappy with how we have handled your personal data, please tell us first - we would rather put it right. You also have the right to complain to the Data Protection Commission at any time:

Data Protection Commission 6 Pembroke Row, Dublin 2, D02 X963, Ireland Telephone: (01) 765 0100 or 1800 437 737 www.dataprotection.ie

12. Cookies

Our website uses cookies. Cookies that are strictly necessary for the site to function are set automatically. All other cookies — including analytics, advertising and embedded third-party content — are set only where you have given your consent through our cookie banner.

You can change or withdraw your cookie preferences at any time through the cookie settings link on our website, and you can delete cookies through your browser settings. Declining non-essential cookies will not affect your ability to use the site.

Full details of the cookies we use are set out in our cookie policy.

13. Marketing

We will only send you marketing by email where you have opted in, or where you are an existing client, the message relates to services similar to those we have already provided, and you were given the opportunity to opt out when we first collected your details.

Every marketing message includes an unsubscribe link, and you can also ask us to stop at any time by contacting us directly. We act on such requests immediately.

14. Children

Our services are directed at adults in professional settings and are not intended for anyone under 18. We do not knowingly collect personal data from children.

Where any service we offer online relies on consent and is directed at a child, the digital age of consent in Ireland is 16 under section 31 of the Data Protection Act 2018. If you believe we hold personal data relating to a child, please contact us and we will delete it.

15. Other websites

Our website may link to other sites. This policy does not apply to them, and we are not responsible for their content or their privacy practices. We would encourage you to read the privacy policy of any site you visit from ours.

16. Changes to this policy

We review this policy at least annually and update it whenever our practices change. The version number and date at the top of this page show when it was last revised. Where a change materially affects how we use personal data we already hold, we will contact affected individuals directly.