Privacy Notice
Last updated: 10 August 2026 · Notice version: 2026-08-10.1
This notice explains how Alex Brownett, trading as The Brownett Method, uses personal data when you visit the site, apply for coaching, become a client, use the client app, contact us, or appear in material published with your permission. UK data protection law applies to our UK activities. EU GDPR and US privacy law may also apply depending on where you are.
Controller and contact
Alex Brownett, trading as The Brownett Method, is the controller. Contact privacy@thebrownettmethod.com about this notice or a privacy request. A physical correspondence address and an EEA representative are not yet published; those are unresolved launch gates. We do not begin coaching for an EEA applicant until the required representative arrangement is in place.
Data we collect and where it comes from
- Application data: name, email, phone, date of birth, country or US state, goals, barriers, commitment, free-text answers, and optional marketing choices, supplied by you.
- Client and health data: identity and contact details; medication, injury, condition, allergy, diet, activity, sleep, stress, height, weight, body measurements, goals, plans, check-ins, progress photos, messages and files, supplied by you or created with your coach. Health and some biometric information is special category data.
- Account and service data: account settings, coaching notes, programme records, bookings, contracts, payment and Stripe identifiers, transactional correspondence, consent history and privacy requests.
- Technical and security data: IP address, user agent, login attempts, session and audit records, push subscription details, and limited device storage used for authentication, theme and notification preferences.
- Guardian data: a guardian's name, email, relationship, approval and verification record where the client is 16 or 17.
We normally obtain data from you. A guardian, coach, payment provider or scheduling provider may also supply limited records needed for the service.
Purposes and lawful bases
- Assess applications and take requested steps before a contract: Article 6(1)(b).
- Set up accounts, deliver coaching, communicate, take payment and administer the agreement: Article 6(1)(b).
- Meet tax, accounting, consumer, safeguarding and legal duties: Article 6(1)(c).
- Secure, troubleshoot and administer the service, prevent abuse and establish or defend legal claims: Article 6(1)(f), our legitimate interests in operating a safe and accountable service.
- Send optional email, SMS/WhatsApp or social-DM marketing: Article 6(1)(a) consent and, where applicable, PECR consent. Each channel is optional and separate.
- Publish an approved testimonial, result, name, photo or video: Article 6(1)(a) consent, separately selected and limited to no more than 24 months.
For health and other special category data, we rely on your explicit consent under Article 9(2)(a), alongside the applicable Article 6 basis. You can withdraw consent, but we may then be unable to provide safe personalised coaching. Withdrawal does not make earlier processing unlawful.
Children and guardians
Under-16s cannot apply. A person aged 16 or 17 may apply, but onboarding, payment and coaching remain blocked until a parent or guardian has approved the arrangement through a staff-issued one-time link. To keep this safeguard simple, we do not use under-18 client data for optional marketing or publication.
Recipients and service providers
We do not sell personal data. Access is limited to authorised coaching or administrative staff and providers needed for the stated purposes:
- Cloudflare provides hosting, security checks, Turnstile, Workers and D1 database services.
- Stripe processes payments and supplies payment, customer and transaction identifiers. We do not store full card details.
- Web3Forms and the relevant email providers deliver limited transactional email. Public application and onboarding answers are not emailed.
- Calendly handles scheduling only when you choose the external Calendly link; we do not prefill or embed it.
- Browser push providers deliver encrypted notifications if a user enables push.
- Professional advisers, insurers, regulators, courts or law enforcement receive information only where reasonably necessary or legally required.
We may display a testimonial, result, first name, photo or video publicly only within the separate permissions given. Existing media must pass a permission audit before this notice is used for production.
International transfers
Some providers may process data outside the UK or EEA. Before production use, we require the relevant data-processing terms and an applicable safeguard, such as UK adequacy regulations, the UK International Data Transfer Addendum or approved standard contractual clauses. Contact us for available safeguard information. EEA coaching remains blocked until the EEA representative requirement is resolved.
Retention
- Unsuccessful or withdrawn applications: six months after the last meaningful activity.
- Detailed health and coaching data: three years after coaching ends, or until age 21 for a person coached as a minor if later, unless a longer period is required for a legal claim or confirmed by our insurer or solicitor.
- Contracts, invoices, payments and tax records: six years, subject to accountant or solicitor confirmation.
- Security, login and ingest logs: 90 days unless needed to investigate an incident.
- Publication permissions: no more than 24 months and removed from future use sooner if withdrawn.
- Consent and suppression evidence: only as long as reasonably needed to prove and enforce the choice or resolve a claim.
Deletion can be delayed or limited where law requires retention, a legal hold applies, or backups cannot safely be altered immediately. We minimise or isolate retained data and notify relevant processors when required.
Cookies, device storage and external content
We do not currently use analytics or advertising cookies. Essential session cookies keep client and staff accounts signed in. Local device storage remembers themes and limited notification state. Service workers support the installed client app; push subscriptions are created only after push is enabled. Turnstile loads on public forms for security. Calendly opens only after you choose its external link and then operates under Calendly's notice. Enabling analytics, advertising or embedded scheduling requires a fresh consent review.
Security and automated decisions
We use access controls, hashed session and form tokens, encrypted transport, rate limits, audit records, purpose-limited staff access and service-provider controls. No internet service is risk-free. No solely automated decision produces legal or similarly significant effects. Automated age and region checks only prevent an ineligible or legally blocked flow from progressing; staff can review a correction request.
AI message assistance (Notice version: 2026-08-20.1)
If you separately opt in, Cloudflare Workers AI may analyse your messages to your coach and the relevant coaching records you have shared — your conversation thread, your coach's saved FAQs, programme and phase summaries, recent check-in summaries, and current text documents in your Vault — for two purposes only: prioritising your coach's inbox, and drafting a suggested reply when your coach explicitly asks for one. Nothing is sent automatically; every reply is written or approved by your coach, and no automated decision is made about your coaching, programme, payments or account. AI is never used for medical diagnosis or emergency response. Saying no changes nothing about your service: normal messaging always works. You can withdraw at any time in the client app under Privacy or by emailing privacy@thebrownettmethod.com; withdrawal stops all new AI processing immediately. This processing runs on the same UK/EU transfer terms described above, prompt and response logging is disabled, and triage records are covered by the access, correction, export and erasure rights below.
Your rights and how to use them
Depending on the law and lawful basis, you may ask for access, portability, correction, erasure or restriction; object to processing; and withdraw consent. Logged-in clients can download their data, withdraw marketing choices and submit a privacy request under Account → Privacy. Anyone can email privacy@thebrownettmethod.com. We may verify identity. We normally respond within one calendar month under UK/EU law; lawful extensions and exemptions may apply.
Your right to object
You may object to processing based on legitimate interests. You may object at any time to direct marketing, and we will stop that marketing.
US consumer health data
US users should also read our Consumer Health Data Privacy Policy. Promotional messaging to US residents remains suppressed until address and channel-specific requirements are resolved.
Complaints and changes
Please contact us first. You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint, or to the supervisory authority where you live or work if EU GDPR applies. We will post material changes here and seek fresh consent before using consent-based data for a new incompatible purpose.