home Home / Privacy Policy
shield Governance & Data Protection

Privacy Policy & Data Notice

This Privacy Policy outlines how Cynthia Thomas Consulting collects, safeguards, and processes institutional and personal data in strict compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Effective Date: September 12, 2026
Data Controller: Cynthia Thomas Consulting (London, UK)
Primary Contact: derbycynthia14@gmail.com
1

Identity of the Data Controller

Cynthia Thomas Consulting (“we”, “us”, or “our”) operates as an independent institutional accreditation advisory practice located in London, United Kingdom. Under the UK GDPR and the Data Protection Act 2018, Cynthia Thomas acts as the Data Controller responsible for your personal data when you interact with our website (https://cynthiathomas.consulting), submit inquiry forms, or engage in advisory briefings.

If you have any questions regarding this policy or our institutional confidentiality practices, please contact us directly at derbycynthia14@gmail.com.

2

Information We Collect

We operate on a principle of strict data minimization. We only collect personal and institutional information necessary to evaluate school accreditation readiness and deliver high-stakes executive counsel:

badge Leadership Contact Data

Full name, professional institutional email, direct phone number, institutional role (e.g. Board Chair, Foundation Head, Principal, Academic Director), and school name.

domain Institutional & Diagnostic Details

Campus geographical location, student enrollment figures, target accreditation agency (CIS, IB, NEASC), self-diagnostic RAG audit responses, and confidential briefing agenda notes.

calendar_month Scheduling Data

Preferred briefing dates, time slots, global timezone alignment, and video conferencing bridge records (via Google Meet and Calendly).

devices Technical & Telemetry Data

IP addresses (anonymized), browser user agents, referring headers, and interaction metrics logged automatically to safeguard server infrastructure from denial-of-service or automated abuse.

3

Lawful Bases for Processing (UK GDPR Art. 6)

We process your data strictly under recognized lawful bases:

  • verified
    Contractual Necessity & Pre-Contract Inquiries (Article 6(1)(b)): Processing intake records and booking requests to schedule confidential 30-minute advisory briefings and prepare Fast-Track Audit proposals at the institutional leader’s request.
  • verified
    Legitimate Business Interests (Article 6(1)(f)): Maintaining high-integrity advisory communications, safeguarding web assets against fraudulent activity, and verifying eligibility of accredited schools.
  • verified
    Legal Obligation (Article 6(1)(c)): Complying with statutory accounting, anti-fraud regulations, and UK corporate governance compliance.
4

Institutional Confidentiality & Sub-Processors

International school governance documentation (such as board minutes, safeguarding compliance registers, faculty rosters, and fee schedules) is sensitive. All discussions and diagnostic submissions are processed under Strict Non-Disclosure Terms (NDA).

We do not sell, rent, trade, or monetize institutional or personal data. Data is processed solely by enterprise-grade infrastructure providers under Data Processing Agreements:

Google Cloud & Firebase Hosting Hosting, Firestore database (EU/UK regional data centers, TLS 1.3 encrypted)
Calendly LLC Executive calendar appointment synchronization (UK/EU-US DPF compliant)
Google Meet / Google Workspace Encrypted video conferencing bridge delivery
Resend / Transactional Dispatch Automated intake confirmation with SPF/DKIM verification
5

Cookies & Local Storage

Our website uses minimal, privacy-centric cookies and browser storage mechanisms in accordance with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR:

  • 1. Strictly Necessary Storage:

    We store your cookie consent choices in local storage (ct_cookie_consent) so you are not asked on subsequent page views. These are essential for the operation of the site and do not require prior consent.

  • 2. Embedded Functional Third-Party Services:

    When scheduling a briefing via Calendly or viewing case studies through YouTube’s privacy-enhanced mode (youtube-nocookie.com), these embedded widgets may set third-party operational cookies. You can manage your preferences at any time using our cookie settings.

6

Your UK GDPR Rights

As a data subject under UK data protection law, you possess enforceable rights:

Right of Access (SAR) Request a copy of any personal data we hold about you.
Right to Rectification Request correction of inaccurate or incomplete leadership records.
Right to Erasure (“To Be Forgotten”) Request deletion of your information where statutory retention periods have lapsed.
Right to Object & Restrict Restrict or object to our processing of your personal data under legitimate interests.

To exercise any of these rights, email derbycynthia14@gmail.com. We respond to all verified requests within 30 calendar days as mandated by the Information Commissioner’s Office (ICO). You also have the right to lodge a complaint with the ICO at ico.org.uk.

7

Data Retention & Disposal

We retain executive briefing inquiries for 12 months following initial contact if an institutional advisory retainer is not commissioned. For retained institutional engagements, governance audit dossiers and advisory papers are archived under professional indemnity standards for 6 years, after which they are permanently and cryptographically shredded.

Ready to Discuss Institutional Accreditation?
Book a confidential 30-minute briefing under standard NDA terms.
Reserve Strategy Briefing arrow_forward
cookie

Institutional Privacy & Cookies

We use essential cookies for platform security and anonymous operational performance. Embedded tools like Calendly may use functional cookies. Read our Privacy Policy.