← Back

Privacy Notice

Last updated: 10 August 2026 · Notice version: 2026-08-10.1

This notice explains how Alex Brownett, trading as The Brownett Method, uses personal data when you visit the site, apply for coaching, become a client, use the client app, contact us, or appear in material published with your permission. UK data protection law applies to our UK activities. EU GDPR and US privacy law may also apply depending on where you are.

Controller and contact

Alex Brownett, trading as The Brownett Method, is the controller. Contact privacy@thebrownettmethod.com about this notice or a privacy request. A physical correspondence address and an EEA representative are not yet published; those are unresolved launch gates. We do not begin coaching for an EEA applicant until the required representative arrangement is in place.

Data we collect and where it comes from

We normally obtain data from you. A guardian, coach, payment provider or scheduling provider may also supply limited records needed for the service.

Purposes and lawful bases

For health and other special category data, we rely on your explicit consent under Article 9(2)(a), alongside the applicable Article 6 basis. You can withdraw consent, but we may then be unable to provide safe personalised coaching. Withdrawal does not make earlier processing unlawful.

Children and guardians

Under-16s cannot apply. A person aged 16 or 17 may apply, but onboarding, payment and coaching remain blocked until a parent or guardian has approved the arrangement through a staff-issued one-time link. To keep this safeguard simple, we do not use under-18 client data for optional marketing or publication.

Recipients and service providers

We do not sell personal data. Access is limited to authorised coaching or administrative staff and providers needed for the stated purposes:

We may display a testimonial, result, first name, photo or video publicly only within the separate permissions given. Existing media must pass a permission audit before this notice is used for production.

International transfers

Some providers may process data outside the UK or EEA. Before production use, we require the relevant data-processing terms and an applicable safeguard, such as UK adequacy regulations, the UK International Data Transfer Addendum or approved standard contractual clauses. Contact us for available safeguard information. EEA coaching remains blocked until the EEA representative requirement is resolved.

Retention

Deletion can be delayed or limited where law requires retention, a legal hold applies, or backups cannot safely be altered immediately. We minimise or isolate retained data and notify relevant processors when required.

Cookies, device storage and external content

We do not currently use analytics or advertising cookies. Essential session cookies keep client and staff accounts signed in. Local device storage remembers themes and limited notification state. Service workers support the installed client app; push subscriptions are created only after push is enabled. Turnstile loads on public forms for security. Calendly opens only after you choose its external link and then operates under Calendly's notice. Enabling analytics, advertising or embedded scheduling requires a fresh consent review.

Security and automated decisions

We use access controls, hashed session and form tokens, encrypted transport, rate limits, audit records, purpose-limited staff access and service-provider controls. No internet service is risk-free. No solely automated decision produces legal or similarly significant effects. Automated age and region checks only prevent an ineligible or legally blocked flow from progressing; staff can review a correction request.

AI message assistance (Notice version: 2026-08-20.1)

If you separately opt in, Cloudflare Workers AI may analyse your messages to your coach and the relevant coaching records you have shared — your conversation thread, your coach's saved FAQs, programme and phase summaries, recent check-in summaries, and current text documents in your Vault — for two purposes only: prioritising your coach's inbox, and drafting a suggested reply when your coach explicitly asks for one. Nothing is sent automatically; every reply is written or approved by your coach, and no automated decision is made about your coaching, programme, payments or account. AI is never used for medical diagnosis or emergency response. Saying no changes nothing about your service: normal messaging always works. You can withdraw at any time in the client app under Privacy or by emailing privacy@thebrownettmethod.com; withdrawal stops all new AI processing immediately. This processing runs on the same UK/EU transfer terms described above, prompt and response logging is disabled, and triage records are covered by the access, correction, export and erasure rights below.

Your rights and how to use them

Depending on the law and lawful basis, you may ask for access, portability, correction, erasure or restriction; object to processing; and withdraw consent. Logged-in clients can download their data, withdraw marketing choices and submit a privacy request under Account → Privacy. Anyone can email privacy@thebrownettmethod.com. We may verify identity. We normally respond within one calendar month under UK/EU law; lawful extensions and exemptions may apply.

Your right to object

You may object to processing based on legitimate interests. You may object at any time to direct marketing, and we will stop that marketing.

US consumer health data

US users should also read our Consumer Health Data Privacy Policy. Promotional messaging to US residents remains suppressed until address and channel-specific requirements are resolved.

Complaints and changes

Please contact us first. You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint, or to the supervisory authority where you live or work if EU GDPR applies. We will post material changes here and seek fresh consent before using consent-based data for a new incompatible purpose.