Privacy Policy

Last updated: June 2026

Gem Roberts, trading as Gem Roberts – Systems Strategist (“we”, “us”, “our”), is committed to protecting and respecting your privacy. We are registered with the Information Commissioner’s Office (ICO). Our ICO registration number is ZB293438.

1. - Who This Policy Applies To

This policy applies to anyone who visits gemroberts.co.uk, contacts us, or purchases any of our services. 

1.1 - Data We Collect

Contact and identity information

  • Name, email address and business name when you contact us, book a session, or make a purchase.
  • Any information submitted via our website contact or enquiry forms.

Business information via intake forms

  • Website URL’s, funnel details, tech stack information, business revenue information and any other details provided in our intake or onboarding forms. 
  • A full list of questions is available on the relevant intake form at the time of submission.
  • Please do not submit login credentials, passwords or any sensitive account access details via intake forms. If access to your platform is required as part of service delivery, this will be requested separately via a secure credential sharing method.

Payment and purchase information

  • Order details and purchase history. Payment are processed via Stripe for card payment, or by bank transfer for returning clients and projects over £650 and above. We do not store your card numbers or full payment details. Card details are processed entirely by Stripe – for information on how Stripe handles your payment data, please refer to their Privacy Policy at https://stripe.com/gb/privacy. Bank transfer payments are processed directly through our business bank account and no payment data is shared with any third party. 

Booking Information

  • Name, email address and answers to booking questions submitted via Tidycal when scheduling a session.
  • Tidycal may collect timezone and location information for scheduling purposes.

Document and signature information

  • Name, email address and digital signature data collected via Google Workspace esignature when you sign a contract or agreement. Google Workspace is GDPR compliant and operates under Standard Contractual Clauses approved under UK GDPR for data transfers outside the UK. For full details of how Google handles this data, please refer to Google’s Privacy Policy at https://policies.google.com/privacy.

Session recordings

  • Live session including, but not limited to, Power Hours and Diagnostic Consultations take place via Zoom. Where consent is given at the start of a session, the call maybe recorded via Zoom. Async video walkthroughs and deliverables are recorded and via Boom (boomshare.ai) and shared via a client specific private folder in Google Drive.
  • All recordings are stored for a maximum of 21 days from the session or delivery date and then permanently deleted. Clients have 14 days to download their recording, see Client Terms of Service for full recording terms. 

Remote access

  • For Diagnostic Consultation sessions where remote access if required, Chrome Remote Desktop (operated by Google) may be used. Access is granted temporarily by the client for the duration of the session only. No data is retained beyond the agreed session recording. 

AI-assisted processing

  • For certain services, including post-session reports and audit summaries, we use Claude (Anthropic) to assist with drafting outputs. Client information used is limited to what is necessary for the specific task. 
  • All AI-generated outputs are reviewed by Gem Roberts before delivery. We do not use AI tools that train on submitted data without your knowledge. 

Behavioural and analytics data

  • Mouseflow is installed on this website and records visitor interactions including mouse movements, clicks, scrolling and page behaviour on all pages. This is activated only with your consent. Mouseflow does not record sensitive form fields. 
  • Google Analytics and Google Tag Manager are installed via Site Kit. These are activated only with your consent via the cookie banner.

Security data

  • Wordfence Security logs IP addresses of visitors for website security and threat detection purposes. IP data may be shared with the Wordfence threat intelligence network (Defiant Inc, USA).

Popup and lead capture

  • Poptin is used to display popup forms on this website. Poptin tracks visitor behaviour including pages visited and time on site. This is only activated only with your consent. 

Contact forms

  • If you submit an enquiry via our website contact form (built with Elementor), we collect your name, email address and any information you provide in your message. 

Google Sign-in

  • If you choose to sign in using Google when accessing shared documents, singing a contract via Google Workspace eSignature, or using any Google-connected tool as part of your service delivery, we receive your name, email address and profile picture from Google with your explicit permissions. This data is used solely to verify your identity and facilitate access to the relevant document or tool. 

1.2 - How We Use Your Data

  • To provide, deliver and administer services that you have purchased
  • To process bookings, payments and enquiries
  • To communicate with you about your project, session or purchase
  • To sent post-purchase and marketing communications where you have given consent
  • To generate reports and session summaries using AI-assisted tools
  • To protect our website from security threats (Wordfence)
  • To understand how our website is used and improve our services (with your consent for analytics)
  • To comply with legal and regulatory obligations

1.3 - Lawful Basis for Processing

  • Contract performance: to protect your purchase and deliver the service
  • Legitimate interests: to manage our business, improve our services and protect our website
  • Consent: for marketing emails, behavioural tracking, analytics and non-essential cookies
  • Legal obligation: for financial record-keeping and ICO compliance

1.4 - Third Party Processors

We work with the following third-party providers, some of whom are based outside the UK. Where personal data is transferred outside the UK, we take reasonable steps to ensure appropriate safeguards are in place. Where possible, we select providers who operate under the Standard Contractual Clauses, adequacy decision or equivalent protections recognised under UK GDPR. You can find details of each provider’s data protection arrangements via the privacy policy links in the table below.

Provider

Purpose

Location

Privacy Policy

Stripe

Payment processing

USA

stripe.com/gb/privacy

Omnisend

Email Service Provider

EU (Estonia)

omnisend.com/privacy-policy 

Tidycal (Sumo Group)

Booking and scheduling

USA

tidycal.com/privacy-policy

Tally

Intake and onboarding forms and testimonial release form collection 

EU (Belgium)

tally.so/help/privacy-policy

Airtable

Data management

USA

airtable.com/privacy

N8n

Workflow automation

EU (Germany)

n8n.io/privacy

Boom (Boomshare.ai / Mazalore Ltd)

Video recording — desktop app and Chrome extension

Cyprus (EU)

boomshare.ai/privacy-policy

Google Workspace

Email, documents, Chrome Remote Desktop, and remote backup storage via Google Drive

USA

policies.google.com/privacy

Claude (Anthropic)

AI-assisted report drafting

USA

anthropic.com/privacy

WordPress / Hostinger

Website hosting

Lithuania / Cyprus EU

hostinger.com/uk/legal/privacy-policy

Elementor / Elementor Pro

Website page builder. Elementor forms (if used as contact or enquiry form) collect name and email address submitted by the visitor.

Israel / USA

elementor.com/about/privacy

Elementor Ally

Website accessibility widget

Israel / USA

elementor.com/about/privacy

LiteSpeed Cache

Website caching. Sets a functional caching cookie (essential, no consent required).

USA

litespeedtech.com/privacy-policy

Wordfence Security (Defiant Inc)

Website security. Logs IP addresses for threat detection. May share IP data with Wordfence threat intelligence network.

USA

wordfence.com/privacy-policy

Poptin

Popup and lead capture forms. Collects visitor behaviour data. Sets cookies. Consent required before activation.

USA / Israel

poptin.com/privacy-policy

Mouseflow

Session recording and heatmaps (all pages). Sensitive form fields masked. Consent required.

USA / EU

mouseflow.com/privacy-policy

CookieYes

Cookie consent management

EU (Ireland)

cookieyes.com/privacy-policy

Site Kit by Google (Google Analytics, Google Tag Manager, Google Search Console)

Website analytics and tag management. GA and GTM require consent. Search Console does not collect visitor personal data.

USA

policies.google.com/privacy

UpdraftPlus

Website backups stored locally and optionally on Google Drive. Google Drive storage covered under Google Workspace entry.

USA

updraftplus.com/privacy-policy

System.io (Systeme.io)

Marketing and funnel platform

EU (France)

systeme.io/privacy-policy

MemberVault

Membership and course delivery

USA

membervault.co/privacy-policy

Kartra

Marketing and funnel platform

USA

kartra.com/page/privacy-policy

ThriveCart

Checkout and course delivery

USA

thrivecart.com/privacy-policy

Kit (ConvertKit)

Email marketing platform

USA

kit.com/privacy

Meta Pixel (planned)

Marketing analytics

USA

facebook.com/privacy/policy

Google Sign-In (optional)

Authentication

USA

policies.google.com/privacy

Zoom

Live video sessions and call recordings 

USA

zoom.com/en/trust/privacy/privacy-statement/

Fathom Notetaker 

AI transcription and note-taking during live Zoom sessions 

USA

fathom.video/privacy

WeTransfer

Alternative file delivery where Google Drive is unsuitable for the recipient 

Netherlands

wetransfer.com/legal/privacy 

WPForms LLC 

Contact form submission handling and enquiry data collection 

USA

https://wpforms.com/privacy-policy/

QUIC.cloud (LiteSpeed Technologies) 

CDN and website performance optimisation 

USA

https://www.quic.cloud/privacy-policy/

1.5 - AI Use in Our Business

We use Claude, made by Anthropic, to assist with drafting post-session Action Reports, audit summaries and certain internal documents. 

  • AI tools are used as a drafting aid, not as an autonomous decision-maker
  • Client data shared with AI tools is limited to what is necessary for the specific task
  • All AI-generated content is reviewed, edited and approved by Gem Roberts before use or delivery
  • We do not use AI tools that train on your data without your explicit knowledge
  • If you have concerns about AI-assisted processing, contact legal@gemroberts.co.uk before purchasing a service that involves a written report

1.6 - Marketing and Post-Purchase Emails

When you make a purchase, you will be added to our post-purchase email sequence and marketing communications via Omnisend. Consent is collected explicitly at checkout. You can unsubscribe at any time using the link in any email. Unsubscribe requests via the link are processed within 72 hours. Manual requests submitted to support@gemrobets.co.uk are processed within 14 days. You may receive emails during the processing window; these are not international continuation of marketing. 

1.7 - Cookies

Please see section, Cookie Policy, for full details

1.8 - How Long We Keep Your Data

Please see our separate Data Retention and Deletion Policy for full details of retention periods and deletion procedures.

1.9 - Your Rights Under GDPR

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data
  • Restrict how we process your data
  • Receive a copy of your data in a portable format
  • Object to processing based on legitimate interests
  • Withdraw your consent at any time where processing is consent-based.

To exercise any of these rights, contact legal@gemroberts.co.uk. We will respond within one calendar month.

1.10 - Right to Complain to Us

You have the right to complain directly to Gem Roberts – Systems Strategist about how your personal data has been handled. Complaints should be submitted to legal@gemroberts.co.uk. We will acknowledge your complaint within 30 days of receipt and respond fully without undue delay.

1.11 - Right to Complain to the ICO

If you remain unhappy after raising a complaint with us, you have the right to complain to the ICO.

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioners Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

1.12 - Data Breach Notification

In the event of a personal data breach, we will notify the ICO within 72 hours where the breach is likely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you personally, we will also notify you direct without undue delay.

1.13 - Changes to This Policy

We may update this Privacy Policy from time to time. The data at the top of the page reflects the most recent update. Significant changes will be communicated by email where we hold your contact details.