Identity of the Data Controller
Cynthia Thomas Consulting (“we”, “us”, or “our”) operates as an independent institutional accreditation advisory practice located in London, United Kingdom. Under the UK GDPR and the Data Protection Act 2018, Cynthia Thomas acts as the Data Controller responsible for your personal data when you interact with our website (https://cynthiathomas.consulting), submit inquiry forms, or engage in advisory briefings.
If you have any questions regarding this policy or our institutional confidentiality practices, please contact us directly at derbycynthia14@gmail.com.
Information We Collect
We operate on a principle of strict data minimization. We only collect personal and institutional information necessary to evaluate school accreditation readiness and deliver high-stakes executive counsel:
Full name, professional institutional email, direct phone number, institutional role (e.g. Board Chair, Foundation Head, Principal, Academic Director), and school name.
Campus geographical location, student enrollment figures, target accreditation agency (CIS, IB, NEASC), self-diagnostic RAG audit responses, and confidential briefing agenda notes.
Preferred briefing dates, time slots, global timezone alignment, and video conferencing bridge records (via Google Meet and Calendly).
IP addresses (anonymized), browser user agents, referring headers, and interaction metrics logged automatically to safeguard server infrastructure from denial-of-service or automated abuse.
Lawful Bases for Processing (UK GDPR Art. 6)
We process your data strictly under recognized lawful bases:
-
verified
Contractual Necessity & Pre-Contract Inquiries (Article 6(1)(b)): Processing intake records and booking requests to schedule confidential 30-minute advisory briefings and prepare Fast-Track Audit proposals at the institutional leader’s request.
-
verified
Legitimate Business Interests (Article 6(1)(f)): Maintaining high-integrity advisory communications, safeguarding web assets against fraudulent activity, and verifying eligibility of accredited schools.
-
verified
Legal Obligation (Article 6(1)(c)): Complying with statutory accounting, anti-fraud regulations, and UK corporate governance compliance.
Institutional Confidentiality & Sub-Processors
International school governance documentation (such as board minutes, safeguarding compliance registers, faculty rosters, and fee schedules) is sensitive. All discussions and diagnostic submissions are processed under Strict Non-Disclosure Terms (NDA).
We do not sell, rent, trade, or monetize institutional or personal data. Data is processed solely by enterprise-grade infrastructure providers under Data Processing Agreements:
Your UK GDPR Rights
As a data subject under UK data protection law, you possess enforceable rights:
To exercise any of these rights, email derbycynthia14@gmail.com. We respond to all verified requests within 30 calendar days as mandated by the Information Commissioner’s Office (ICO). You also have the right to lodge a complaint with the ICO at ico.org.uk.
Data Retention & Disposal
We retain executive briefing inquiries for 12 months following initial contact if an institutional advisory retainer is not commissioned. For retained institutional engagements, governance audit dossiers and advisory papers are archived under professional indemnity standards for 6 years, after which they are permanently and cryptographically shredded.