Privacy Policy
Effective 14 September 2026 · Version 2.0
This policy explains what personal information Radford Enterprises Limited collects about you, why we collect it, who we share it with, and what you can do about it.
1. Who we are
Radford Enterprises Limited is the data controller for the information described in this policy. We are registered in Malta.
Radford Enterprises LimitedCompany registration number C102082
36, FL3, Abbate Savoia Street
Naxxar NXR 1141, Malta
info@roseradford.com
Because we are established in Malta, the EU General Data Protection Regulation applies to us and our lead supervisory authority is the Office of the Information and Data Protection Commissioner (IDPC) in Malta.
We also market to and track people in the United Kingdom, so UK data protection law applies to that activity. If you are in the UK, see section 12. If you are in the United States, see section 13.
We have not appointed a Data Protection Officer, and are not required to. Any question about this policy or your information should go to the email address above, and we aim to respond within 30 days.
2. What this policy covers
This policy covers our website and the pages we run on connected platforms, including our checkout, booking and webinar registration pages, and our email marketing. It does not cover other companies' websites that we link to.
Our services are sold to businesses and to adults. You must be 18 or over to buy from us, register for our events, or subscribe to our emails. We do not knowingly collect information about children. If you believe a child has given us their information, email us and we will delete it.
3. What we collect
What we hold about you depends on how you have dealt with us. In most cases you give it to us directly. Some of it is collected automatically.
| Category | What it includes | Where it comes from |
|---|---|---|
| Contact details | Name, email address, phone number, business name, country | You give it to us |
| Purchase records | What you bought, when, the amount, invoices, billing address, and a partial card reference. We never see or store your full card number. | You and our payment providers |
| Enquiry and application answers | Anything you write in our contact forms, application forms and booking questions, including free-text answers about your business | You give it to us |
| Call and webinar recordings | Audio, video and chat from calls and webinars you attend, where recording is on | Recorded during the session |
| Event attendance | Whether you registered, whether you attended live, how long you stayed, and whether you watched a replay | Collected automatically |
| Email engagement | Whether you opened an email, which links you clicked, and when | Collected automatically |
| Website and advertising data | IP address, pages viewed, referring source, advertising identifiers, and detailed characteristics of your device and browser used to recognise you on later visits. See section 5. | Collected automatically |
| Community activity | Messages and files you post in our client community | You post it |
| Correspondence | Emails and messages between us | You and us |
Sensitive information
We do not ask for special category information, meaning information about your health, race or ethnicity, political opinions, religious beliefs, trade union membership, genetics, biometrics, sex life or sexual orientation. We do not ask about criminal offences or convictions.
However, our work is coaching and consulting, and our forms and calls include open questions about your business and your circumstances. People sometimes volunteer personal information we did not ask for. Where that happens, we treat it as confidential, we do not use it for marketing, and we delete it when it is no longer needed. Please do not include information in a form or a call that you would rather we did not hold.
4. Why we use it, and our legal basis
We must have a lawful basis for everything we do with your information.
| What we do | Information used | Legal basis |
|---|---|---|
| Deliver the programme or service you bought, including calls, community access and materials | Contact details, purchase records, application answers, recordings, community activity | Contract |
| Take payment and issue invoices | Contact and purchase records | Contract |
| Respond to your enquiry or run an application and booking process | Contact details, enquiry answers | Legitimate interests |
| Send you our newsletter and marketing emails when you have signed up | Contact details, email engagement | Consent |
| Send marketing about similar services to people who have recently bought from us | Contact details, purchase records | Legitimate interests |
| Run and measure advertising, including tracking across devices and matching ad clicks to sales | Website and advertising data, contact details in hashed form | Consent |
| Record calls and webinars for training, delivery and replay | Recordings, attendance | Consent |
| Keep accounting, tax and company records | Purchase records, contact details | Legal obligation |
| Keep our systems secure, prevent fraud, and establish or defend legal claims | Any of the above, as needed | Legitimate interests |
Where we rely on legitimate interests, our interest is running and protecting a business and reaching people likely to want our services. We have considered whether that interest is overridden by your rights, and you can object at any time. Where we rely on consent, you can withdraw it at any time, and withdrawing it does not affect anything we did before you withdrew it.
5. Advertising, tracking and profiling
We want to be direct about this, because it is the part most policies gloss over.
We advertise on Meta (Facebook and Instagram). To do that, and to understand which adverts lead to sales, we use advertising and analytics tools that build a profile of how you interact with us.
One of those tools, Hyros, works by device fingerprinting. Rather than relying on a cookie, it reads a combination of characteristics from your device and browser, including screen size, timezone, language, installed fonts, graphics and audio processing behaviour, and IP address. Together these are distinctive enough to recognise your device when it returns. Once you give us your email address through a form, that identifier is linked to you, including to the visits you made before you filled the form in.
You should know two things about this. It is more persistent than a cookie, because clearing your cookies or using private browsing does not remove it. And it is harder for you to see or control, which is why we set it out here in detail and why the opt-out in section 6 is the route that actually works.
We may also share a hashed, non-readable version of your email address with Meta so that it can match you to an account and show you our adverts, exclude you from them, or find people who resemble our existing customers.
All of this is profiling, and we would rather say so than pretend otherwise.
We do not make decisions about you by automated means alone that have a legal effect on you or similarly significantly affect you. No algorithm decides whether you can buy from us, what you pay, or whether your application succeeds. A person makes those decisions.
You have an absolute right to object to profiling for direct marketing. If you object, we will stop sending you marketing, remove you from our advertising audiences, and add you to a suppression list so we do not target you again.
6. Cookies, tracking, and how to opt out
Cookies that are strictly necessary for the website to function are set automatically.
The advertising and analytics tracking described in section 5 currently begins when you arrive on our site, rather than waiting for you to agree to it. We are changing that, and we will update this policy when it is done. We would rather tell you where we actually stand than describe a control that is not yet live.
In the meantime, email info@roseradford.com and we will stop tracking you and remove you from our advertising audiences. That is a real request that a person actions, and it covers the fingerprinting too, which browser settings do not.
Our cookie policy sets out each tool, what it does and how long it keeps things.
7. Who we share it with
We do not sell your personal information. We do not share it with third parties for their own marketing.
We use the service providers below to run the business. They process your information on our instructions and are contractually required to keep it secure and to use it only for the purpose we engaged them for.
| Provider | What we use it for |
|---|---|
| ActiveCampaign | Email list, marketing emails, customer records |
| Lovable | Our website and landing pages |
| ThriveCart | Checkout and course delivery |
| Stripe, PayPal, Revolut | Payment processing |
| Calendly | Call booking |
| Zoom | Calls, webinars and recordings |
| Hyros | Advertising analytics and attribution, using device fingerprinting as described in section 5 |
| Meta | Advertising, audience matching and measurement |
| Slack | Client community |
We may also share your information with our accountants and professional advisers; with a buyer or seller if we buy or sell a business or assets; and where we are required to by law, by a court, or by a regulator, or where we need to in order to establish or defend a legal claim.
Artificial intelligence tools
We use AI assistants to help us draft and review our own material, such as marketing copy, course content and internal documents.
We do not put your personal information into them. We do not upload your name or contact details, the answers you gave on an application or booking form, or recordings or transcripts of calls you took part in. Where we want a second opinion on something that began as client work, we remove anything that identifies the person before we do.
This is a deliberate choice rather than an oversight. If it ever changes, we will put a data processing agreement in place with the provider and update this policy before it does, not afterwards.
8. Sending information outside the EEA
Several of the providers listed above are based in the United States or store data there. When your information goes outside the European Economic Area, we make sure one of the following applies:
- the country has been formally recognised by the European Commission as providing adequate protection;
- the provider is certified under the EU-US Data Privacy Framework, and its UK Extension where UK data is involved;
- we have the European Commission's Standard Contractual Clauses in place with the provider, together with the UK International Data Transfer Addendum where UK data is involved; or
- you have explicitly consented to the transfer.
We keep a record of which mechanism applies to each provider and review it at least once a year, because these frameworks change. If you want to know which one applies to a specific provider, email us and we will tell you.
9. How long we keep it
| What | How long |
|---|---|
| Marketing contacts | Until you unsubscribe or object. We then keep a minimal record of your email address on a suppression list indefinitely, so that we do not contact you again by mistake. |
| Enquiries and applications that do not lead to a purchase | 24 months from your last contact with us |
| Customer records, invoices and accounting records | 10 years from the end of the financial year, to meet Maltese company and tax record-keeping requirements |
| Call and webinar recordings | 12 months |
| Event registration and attendance data | 24 months |
| Email engagement data | 24 months |
| Advertising and analytics identifiers | 14 months for individual-level records. Aggregated reporting that cannot identify you is kept indefinitely. |
| Client community content | For as long as you are a member, plus 12 months |
| General correspondence | 3 years |
We may keep information longer where we need it for a legal claim or where the law requires it.
10. How we protect it
We limit access to your information to the people who need it to do their job, we use reputable providers with their own security measures, and we use access controls on the accounts that hold your information.
No system is completely secure, and information sent over the internet is never entirely risk-free. If there is a breach affecting your personal information, we will notify the relevant supervisory authority within 72 hours where we are required to, and we will tell you directly where the breach is likely to result in a high risk to your rights.
11. Your rights
You have the following rights. They are free to use, and we will respond within one month.
- Access. Ask for a copy of the information we hold about you.
- Correction. Ask us to fix anything inaccurate or incomplete.
- Erasure. Ask us to delete your information, where we do not have a legal reason to keep it.
- Restriction. Ask us to pause using your information while a dispute about it is resolved.
- Portability. Ask for the information you gave us in a structured, machine-readable format, or ask us to send it to someone else.
- Objection. Object to us using your information where we rely on legitimate interests.
- Withdraw consent. Withdraw any consent you have given, at any time.
You also have an absolute right to object to direct marketing at any time. If you tell us to stop, we must stop, and we do not get to weigh it against our own interests. Use the unsubscribe link in any email, or email us. This right stands on its own and is separate from every other right listed above.
To use any of these rights, email info@roseradford.com. We may ask you to confirm your identity first.
If you are unhappy with how we have handled your information, you can complain to the Office of the Information and Data Protection Commissioner in Malta at idpc.org.mt. You can also complain to the supervisory authority in the country where you live or work.
12. If you are in the United Kingdom
Because we market to people in the UK and monitor how UK visitors use our website, UK data protection law applies to that activity alongside the EU rules described above. Your rights are the same as those in section 11.
You can complain to the Information Commissioner's Office at ico.org.uk, or to the Maltese authority named in section 11, whichever you prefer.
We only send marketing emails to UK subscribers who have opted in, or to recent customers about services similar to what they already bought. Every marketing email carries an unsubscribe link, and we act on it.
13. If you are in the United States
Our marketing emails comply with the CAN-SPAM Act. They identify us as the sender, include our postal address, and contain a working unsubscribe link that we honour promptly.
Depending on where you live, you may have rights under your state's privacy law, including the right to know what we collect about you, to get a copy, to correct it, to delete it, and to opt out of targeted advertising.
We do not sell your personal information for money. However, our use of advertising tools that track you across different websites may count as "sharing" for targeted advertising or as a "sale" under some state laws. To opt out, email info@roseradford.com and we will action it. We will not discriminate against you for exercising any of these rights.
14. Other websites
Our website and emails contain links to other websites. We are not responsible for their privacy practices. Check their policies before giving them your information.
15. Changes to this policy
We review this policy at least once a year, and update it when our tools or practices change. The version number and effective date at the top tell you which version you are reading.
If we make a change that materially affects how we use your information, we will tell you directly by email before it takes effect, where we hold your email address. We will not rely on your continued use of the website as agreement to a material change.
