Legal
Privacy notice
How Brand Strategy UK collects, uses and protects personal data, in line with UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
Last updated: 29 September 2026
Who we are
Brand Strategy UK is the trading name of Nadine Benjamin, ACIM, a sole trader established in England ("we", "us", "our"). For the purposes of UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, we are the data controller for the personal data described here.
You can contact us about anything in this notice by emailing our data protection contact. A postal correspondence address is provided by return on request.
This notice describes what this website and our records actually do. Where a feature is still being connected, that is said plainly.
Information you give us
When you use the contact form, we collect your name, email address, enquiry type, subject and message, plus any business name or telephone number you choose to give. If you arrived through a tagged link, you may separately opt in to save its short campaign labels and tagged page with your enquiry. The option is unticked by default; we do not join your other page views or store a visitor ID with it. When you submit a project brief, we also collect your business name, selected service, business context and intended outcome, the answers to the questions for that service, and any optional role, website, timing, budget range, telephone number or additional notes you provide. If you apply for a named case-study partner rate, we record your agreement to its stated terms. A telephone number is used for project administration, never for marketing. If you choose “Continue on another device” on an unsent brief, we keep a copy of your draft answers (never your email address or phone number) for 30 days so you can finish it elsewhere; it is deleted when you send the brief, when you delete it from the link, or automatically after 30 days.
If you subscribe to Strategy notes, we collect only your email address. If you email us directly, we hold your message and the details in it.
Please do not send us information that UK GDPR treats as special category data, such as health, beliefs or background, or information about criminal offences. None of our services need it. If it arrives in a free-text field, tell us and we will remove it.
The positioning statement generator
The free generator runs entirely in your browser. Your answers are saved in this browser’s local storage so you can return to them, and are never sent to us. Choosing “Start again” clears them. Clearing your browser’s site data also removes them.
The client area and chat
If you are a client, we hold your name, company, email address and a securely hashed password so you can sign in to the client area, together with your engagement details, deliverables and the messages you send us there. Messages are also emailed to your lead consultant so they can reply. We keep this for as long as your engagement is active and then for the period set out below. Your password is never stored in readable form, and we cannot see it.
If you buy a download from the resources page, payment is taken by Stripe on its own secure page; we never see or store your card details. Stripe sends us your name, email address, the amount paid, the product and a payment reference. We use them to email your download link and receipt, to let you download again from the client area if you have an account with the same email address, and to keep our accounts. Your download link is random and we store only a one-way hash of it. We record each download against the order so we can stop a link that has been shared.
When you continue from our checkout page we record which resource you chose and a random reference that lets us match the payment when Stripe confirms it. Giving an email address there is optional. We keep it only if you also tick the separate box asking for a reminder, and then use it for one email, about two hours later, if you have not finished paying. It is never used for marketing or added to a mailing list, it is deleted as soon as you pay or after 14 days at most, and the checkout record itself is deleted after 90 days.
If you buy the Positioning Workbook, you can use its online companion to save your own notes. We store what you save, with each saved version, so you can return to it. The notes are kept for 180 days after your last save, then deleted; you can export or delete them yourself at any time, and deleting them does not affect your purchase. Your companion link is random and we store only a one-way hash of it. We read your notes only if you choose to share a version with us. Daily database backups may hold a copy for up to their retention period.
The website assistant gives automated answers from our own site content. When AI answers are switched on, your question and up to twenty recent messages from this tab are sent to Anthropic to write an answer; if AI is unavailable, answers come from website content in your browser. The automated conversation remains in this browser tab and clears after five minutes without a message or when the tab closes. We do not keep the automated chat text on our server; choosing “Speak to a human agent” starts a separate, consented conversation. The automated conversation is copied into that request only if you select the separate, unticked option to include up to eight recent AI questions and answers; obvious contact details are excluded. Anthropic does not use it to train its models under our API terms. We keep aggregate question counts, broad intent categories and AI usage figures without the automated chat text. A short-lived security record and an opaque cookie are used if a sustained chat needs a Turnstile check after twelve questions from one connection within an hour. Please do not enter personal or confidential material into automated chat. If you choose “Speak to a human agent”, we collect the name, email and message you deliberately provide, store the conversation in our admin workspace, and attempt to email a copy of our reply through Resend. A team member may join live during scheduled availability, but this is not guaranteed. Otherwise we usually reply within one working day. Human chat handoffs are included in the 12-month enquiry retention setting and removed when the admin clean-up runs. A strictly necessary cookie lets you return to the conversation in the same browser for 30 days; we attempt to send an email copy of a reply to the address you provided. Do not share sensitive personal or confidential material in the handoff message; use the client area for active private work.
Information collected automatically
Our hosting provider, Cloudflare, processes the technical information every website receives in order to serve pages, defend the site and keep it available: your IP address, browser user-agent, the page requested and approximate location derived from your IP address. This happens at network level and is described in Cloudflare’s own privacy documentation.
This website does not use advertising or tracking cookies. To understand which pages are useful, it counts page views and a few actions (such as a brief being started or sent) as daily totals per page, with the referring website and whether the device is a phone or a computer. No cookies are used for these page and action totals, and they do not store an IP address, visitor identifier or profile. We also estimate the number of distinct connections viewing public pages. For each qualifying page view, our server briefly uses the connection IP address in memory with a private cryptographic key to update a daily aggregate estimate; it does not keep the address, its individual hash, a visitor record or a device fingerprint for this purpose. No cookie or browser storage is used for this estimate. It is an approximate count of connections rather than people: shared connections, changing addresses and automated traffic can affect the figure. On-site search matches public pages in your browser. If you submit a search using ordinary strategy terms, it reports only a restricted set of generic topic words, daily no-result counts and the public page selected. Your typed query, IP address and a session identifier are not stored in search reporting. Searches containing other words or personal details are not reported. The site sets strictly necessary cookies for client and admin sign-in, for a human chat conversation that you request, and for a one-hour proof after a sustained automated chat Turnstile check. See the cookie notice.
To limit repeated form submissions and sign-in attempts, we temporarily store the request IP address and, for account or subscription attempts, the submitted email address in security rate-limit keys. Old entries are removed after 30 days once any lock has expired. These keys are used for abuse prevention, not site analytics or marketing.
How and why we use it
We use enquiry and brief information to respond, assess fit, scope and quote the work, and to keep a record of the enquiry. If you choose the separate attribution option, we keep the campaign labels with your enquiry for marketing assessment. You can decline it without affecting your enquiry, and ask us to remove those labels later. The lawful basis is taking steps at your request before entering into a contract (Article 6(1)(b)) and our legitimate interests in running and improving the consultancy (Article 6(1)(f)). We briefly use the connection IP address for the public-page aggregate estimate under our legitimate interest in measuring and improving the site (Article 6(1)(f)); the result is not used to profile or target individual visitors.
For clients, we use the information needed to deliver and administer the engagement, invoice and keep proper business records. The lawful bases are performance of a contract (Article 6(1)(b)) and legal obligation for accounting records (Article 6(1)(c)).
For downloads you buy, including the workbook companion, the lawful bases are performance of a contract (Article 6(1)(b)) and legal obligation for accounting records (Article 6(1)(c)). For a checkout reminder, the lawful basis is your consent (Article 6(1)(a)), which you give by ticking the reminder box and can withdraw by replying to the reminder or emailing us.
Strategy notes are sent only with your consent (Article 6(1)(a)), confirmed by email. You can unsubscribe from any issue or by emailing us, and we will stop.
Artificial intelligence
We use AI tools, including Anthropic’s Claude, to help draft, structure, research and check material. Every recommendation is reviewed and issued on the lead consultant’s own judgement, and no decision about you is taken solely by automated means. Content sent to the Anthropic API is not used to train Anthropic’s models. This includes assessing a brief you send us, reading the public website of the business named in an enquiry to prepare for our reply, preparing internal notes from a client’s record and the documents they share with us, labelling incoming email by priority, and drafting replies to your enquiry or client-area messages; a member of our team reads and approves every email or client-area reply before it is sent. The public website assistant provides automated answers directly in its chat, as described above. If you would prefer that your confidential material is not processed by an AI provider, tell us at the outset. In the private admin area, a consultant may add a reviewed, source-labelled note to help the assistant carry relevant working context forward. These notes are limited to that consultant or to staff assigned to the client and are sent to the AI provider only when an authorised staff member uses the assistant or requests a suggested next step. Suggestions remain internal until a person chooses to create a task.
Who we share it with
We do not sell personal data. We use a small number of service providers who process data on our behalf under written terms: Cloudflare (hosting, security and storage), Resend (email delivery), Anthropic (AI assistance, as described above), Asana (project administration) and Stripe (card payments for downloads and invoice payment links; Stripe is also a controller for its own fraud prevention and regulatory duties). Some providers process data outside the United Kingdom; where they do, transfers rely on UK adequacy regulations or the International Data Transfer Addendum to the EU standard contractual clauses.
How long we keep it
Enquiries that do not proceed and human chat handoffs are deleted within 12 months of the last contact when the retention action is run. Client records are kept for six years after the end of the tax year in which the engagement ended, to meet accounting and legal requirements. Download orders are kept for six years after the end of the tax year of purchase for the same reason. Newsletter records are kept while you remain subscribed, plus a record of consent and withdrawal. Aggregate on-site search topics and daily visitor-estimate sketches older than 180 days are removed from the live database when the admin clean-up runs; optional campaign labels follow the relevant enquiry retention period. Restricted recovery backups may contain earlier copies and are scheduled for deletion 90 days after each snapshot is created. Reviewed AI context expires after 180 days by default, at most one year after the last review, and stops being supplied to the assistant as soon as it expires. Archived or expired notes become eligible for deletion after 30 days when retention clean-up runs. Internal AI task suggestions become eligible for deletion after 30 days if unused, or 90 days after being handled, when the same clean-up runs. A task someone chooses to create follows the relevant client record retention period.
Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its use, to data portability, and to withdraw consent at any time. To exercise any of these rights, email our data protection contact. We will respond within one month.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
Changes to this notice
We update this notice when what the website or the consultancy does changes. The date at the top shows the latest version.