HAPPY BUSINESS GLOBAL LTD – PRIVACY NOTICE
Last updated: 9 August 2026
1. About this Privacy Notice
This Privacy Notice explains how Happy Business Global Ltd collects, uses, stores and shares personal data.
Happy Business Global Ltd is the data controller for the personal data covered by this Notice unless we specifically tell you otherwise.
We are registered in Scotland.
Company name: Happy Business Global Ltd
Company number: SC518154
VAT number: 391 2243 10
Registered office: 1 Waterloo Bank, Penicuik, Midlothian, EH26 8NS
Privacy contact: Julie Begbie
Email: julie@thehappybusinessco.com
We trade under brands including The Happy Business Company and The Happy AI Company.
This Notice applies when you:
-
visit or use our website;
-
contact or enquire with us;
-
subscribe to our emails or other marketing;
-
purchase or use one of our products, memberships, programmes or services;
-
attend a workshop, training session, event or online community;
-
take part in coaching, mentoring or consultancy;
-
communicate with us by email, direct message, voice note, meeting, call or another channel;
-
work with us as a business client;
-
use an AI-enabled service that we provide or configure;
-
supply goods or services to us;
-
interact with us through social media or another platform; or
-
otherwise provide personal data to us.
This Notice should be read alongside our Terms of Business, AI Usage & Responsible AI Policy and Cookie Policy.
For bespoke business services, a separate Client Services Agreement or data-processing schedule may also apply.
2. Data protection law
We process personal data in accordance with applicable UK data-protection law, including:
-
the UK General Data Protection Regulation (“UK GDPR”);
-
the Data Protection Act 2018, as amended;
-
the Data (Use and Access) Act 2025; and
-
the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), where applicable.
We aim to handle personal data lawfully, fairly, transparently and securely and to use only the information reasonably needed for the relevant purpose.
3. Personal data we may collect
The personal data we collect depends on how you interact with us.
Identity and contact data
This may include:
-
name;
-
business or organisation name;
-
job title or role;
-
postal or business address;
-
email address;
-
telephone number;
-
social-media profile or username; and
-
other contact details you provide.
Purchase, booking and account data
This may include:
-
products or services purchased;
-
booking information;
-
membership status;
-
programme participation;
-
subscription information;
-
transaction dates and amounts;
-
invoice and billing information;
-
payment status;
-
limited payment information supplied to us by payment providers; and
-
account or portal-access information.
We do not normally receive or store your full payment-card details. These are usually processed by the payment provider used at checkout.
Communications data
This may include:
-
emails and messages;
-
direct messages and social-media conversations;
-
voice notes;
-
enquiry forms;
-
customer-service correspondence;
-
feedback;
-
survey responses;
-
notes of conversations;
-
meeting or call information;
-
meeting transcripts where recording has been agreed;
-
AI-generated summaries of meetings, calls or messages;
-
actions and follow-up notes; and
-
complaints or other correspondence.
Service and client data
Where you work with us, this may include information needed to provide the service, such as:
-
business information;
-
goals and priorities;
-
notes from coaching, mentoring or consultancy sessions;
-
materials you ask us to review;
-
information contained in a Business Brain, AI Supersheet, project knowledge file or similar business resource;
-
workflow and system information;
-
client instructions and permissions;
-
project files; and
-
other information relevant to the service.
Member Memory and relationship personalisation data
Where you are a member, client or programme participant, we may keep limited Member Memory or relationship notes to help us provide continuity and a more useful, personal service.
These notes may be created from information you choose to share with us during calls, meetings, messages, voice notes, emails, events, forms or ordinary conversations. They may include information such as:
-
your business and what you do;
-
your current goals or priorities;
-
the areas where you would like support;
-
projects, offers, launches or events you are working on;
-
business or communication preferences;
-
relevant interests you have mentioned;
-
wins, progress or achievements you have shared;
-
business challenges or blockers;
-
previous conversations and agreed actions;
-
useful follow-up questions;
-
relevant dates or business milestones you have told us about; and
-
other limited context that helps us remember the relationship and provide relevant support.
We may use AI tools to help summarise, organise or update these notes. A human remains responsible for deciding what information is useful to retain and how it is used.
Member Memory notes may be stored in business-management tools such as Notion or another appropriate CRM, database or workspace used by us.
We use these notes to:
-
provide continuity between conversations;
-
remember agreed actions and follow-ups;
-
avoid repeatedly asking you for information you have already provided;
-
personalise coaching, mentoring, member support and service communications;
-
make our support more relevant to your current goals; and
-
maintain an accurate working record of our relationship.
We do not aim to create intrusive or secret profiles about members or clients. We apply a data-minimisation approach and aim to keep only information that is reasonably useful for the relationship.
We do not intentionally record unnecessary special category or highly sensitive personal information in Member Memory notes. If sensitive information is shared with us, we will consider whether it is necessary to retain it and whether an appropriate lawful basis and additional condition are required.
AI-related data
Where AI is used as part of our business or a service, this may include:
-
prompts and instructions;
-
information submitted to an AI-enabled workflow;
-
meeting, call or message summaries;
-
AI-generated outputs;
-
project or business knowledge files;
-
authorised information retrieved from connected systems;
-
records of approvals or automated actions; and
-
technical or usage information associated with an AI service.
We aim to minimise personal data provided to AI systems and to anonymise or pseudonymise information where practical and appropriate.
Marketing and preferences data
This may include:
-
whether you have asked to receive marketing;
-
marketing preferences;
-
email engagement information;
-
interests indicated through forms, events or interactions;
-
opt-in and opt-out records; and
-
suppression-list information used to respect marketing choices.
Technical and website data
This may include:
-
IP address;
-
browser and device information;
-
operating system;
-
time zone or approximate location derived from technical information;
-
website activity;
-
referring website;
-
pages visited;
-
interactions with website features;
-
cookie identifiers; and
-
analytics or similar technical data.
More information about cookies and similar technologies is provided in our Cookie Policy.
Social media and platform data
If you interact with us through a social network or third-party platform, we may receive information made available through that platform, such as your name, profile, comments, messages or engagement.
The platform also processes personal data under its own privacy information.
Images, recordings and testimonials
Where relevant and appropriate, we may process:
-
photographs;
-
video or audio recordings;
-
event recordings;
-
meeting recordings where agreed;
-
testimonials;
-
reviews; and
-
case-study information.
Where consent or another permission is required for a particular use, we will seek it as appropriate.
Supplier and professional-contact data
If you supply services to us or work with us professionally, we may process:
-
contact details;
-
business information;
-
payment information;
-
contracts;
-
correspondence; and
-
information needed to manage the relationship.
4. Special category and sensitive personal data
We do not routinely require special category personal data for ordinary website use, memberships or most business services.
However, people may sometimes provide information relating to matters such as health or wellbeing during coaching, mentoring, training, enquiries, calls or other communications.
We ask you not to provide special category or highly sensitive personal data unless it is reasonably necessary for the purpose for which you are dealing with us.
Where we intentionally process special category personal data, we will identify both:
-
a lawful basis under Article 6 UK GDPR; and
-
an appropriate condition under Article 9 UK GDPR.
Depending on the circumstances, this may include your explicit consent where that is appropriate.
Our ordinary AI-enabled business services and Member Memory system are not designed for unnecessary special category personal data. Clients and members using AI-enabled services should minimise such information and follow any agreed data-handling instructions.
5. How we collect personal data
We may collect personal data:
Directly from you
For example when you:
-
complete a form;
-
purchase or book;
-
join a membership or programme;
-
subscribe to marketing;
-
email, message, send a voice note or speak with us;
-
attend an event, meeting or call;
-
complete an onboarding process;
-
sign an agreement;
-
provide project information;
-
share information during a membership, mentoring or client relationship; or
-
use a service.
From our own relationship records
We may create brief notes, action points or summaries from previous conversations, meetings, voice notes, emails or messages so that we can maintain continuity in the relationship.
Where appropriate, AI tools may help us create or organise these summaries, subject to our data-minimisation and responsible-AI practices.
Automatically
Our website and online services may collect technical and usage information through cookies, server logs and similar technologies.
From third parties
We may receive personal data from:
-
payment providers;
-
booking or form platforms;
-
email and marketing platforms;
-
social-media platforms;
-
event or training partners;
-
referral partners;
-
business clients;
-
professional advisers;
-
publicly available business sources; and
-
connected software or systems that you have authorised us to use.
If we obtain personal data from another source, we will provide privacy information where required by law.
From business clients
When we provide business or AI-enabled services, a client may provide personal data relating to its staff, customers, suppliers, prospects or other people.
In those circumstances, our legal role depends on why and how the information is being processed.
Where we process such data solely on the client’s documented instructions, the client will normally be the controller and we will normally act as processor. The relevant Client Services Agreement or data-processing terms will govern that processing.
6. How and why we use personal data
We use personal data only where we have a lawful basis.
The main purposes and lawful bases are set out below.
| Purpose | Types of data | Main lawful basis |
|---|---|---|
| Responding to enquiries and discussing potential services | Identity, contact, communications and relevant service data | Legitimate interests and/or steps requested before entering a contract |
| Processing purchases, bookings and memberships | Identity, contact, transaction, account and service data | Contract |
| Providing programmes, memberships, training, mentoring, consultancy and other services | Identity, contact, service and communications data | Contract and, where appropriate, legitimate interests |
| Maintaining Member Memory and relationship notes, remembering follow-ups and personalising support and service communications | Identity, contact, service, communications and Member Memory data | Contract and/or legitimate interests |
| Creating or organising meeting, message, voice-note or call summaries with AI | Communications, service and Member Memory data | Contract and/or legitimate interests, subject to data minimisation and any additional requirements for sensitive data |
| Providing or configuring AI-enabled business services | Identity, contact, business, project, AI-related and authorised connected-system data | Contract and/or legitimate interests; processor terms may apply where we act for a client |
| Taking and managing payments | Identity, contact, transaction and billing data | Contract, legal obligation and legitimate interests |
| Managing customer service, queries and complaints | Identity, contact, communications, service and transaction data | Contract, legal obligation and legitimate interests |
| Keeping business, accounting and tax records | Identity, transaction, contract and billing data | Legal obligation and legitimate interests |
| Preventing fraud, misuse and security incidents | Identity, contact, technical, transaction and communications data | Legitimate interests and, where relevant, legal obligation |
| Operating and improving our website and services | Technical, usage, service and communications data | Legitimate interests and consent where required for cookies or similar technologies |
| Sending direct marketing | Identity, contact, marketing and preferences data | Consent or legitimate interests where permitted, subject to PECR |
| Maintaining suppression lists | Identity, contact and opt-out data | Legitimate interests and legal obligation/compliance interests |
| Managing events, groups and communities | Identity, contact, participation and communications data | Contract and legitimate interests |
| Using testimonials, images or recordings | Identity, image, recording and testimonial data | Consent, contract or legitimate interests depending on the specific use |
| Managing suppliers and professional relationships | Identity, contact, business, payment and communications data | Contract and legitimate interests |
| Establishing, exercising or defending legal rights | Relevant records and communications | Legitimate interests and legal obligation where applicable |
| Complying with law and regulatory requirements | Relevant personal data | Legal obligation |
Where we rely on legitimate interests, those interests may include:
-
running and improving our business;
-
responding to business enquiries;
-
providing effective customer service;
-
maintaining continuity in member and client relationships;
-
remembering appropriate actions, preferences and follow-ups;
-
personalising support and service communications in a proportionate way;
-
avoiding unnecessary repetition for clients and members;
-
protecting our systems and business;
-
keeping appropriate business records;
-
understanding how our services are used;
-
communicating with business contacts where permitted; and
-
establishing or defending legal rights.
We consider whether those interests are overridden by the rights and interests of the individual before relying on this basis.
7. Marketing and personalised communications
We may send you information about our products, services, training, events, memberships or other offers where the law allows us to do so.
Depending on the circumstances, we may rely on:
-
your consent;
-
the “soft opt-in” for marketing our own similar products or services to eligible existing customers where the legal conditions are met; or
-
legitimate interests for certain business-to-business marketing where PECR permits the communication.
Different PECR rules can apply depending on whether the recipient is an individual subscriber, such as an individual or sole trader, or a corporate subscriber, such as a limited company.
Where appropriate, we may use limited information you have chosen to share with us about your business, interests, goals, previous conversations or current projects to make a human-written or AI-assisted draft communication more relevant to you.
For example, we may remember that you told us about an upcoming launch and ask how it went, or refer back to a goal you previously discussed with us.
We do not use Member Memory to make significant automated decisions about you.
Where personal data is used to personalise direct marketing or amounts to profiling for marketing purposes, we will use it only where lawful, fair and transparent and will respect your right to object to direct marketing.
We do not intentionally use unnecessary sensitive personal information to personalise direct marketing.
Every marketing email we send will provide a straightforward way to opt out where required.
You can unsubscribe at any time by:
-
clicking the unsubscribe link in a marketing email; or
-
contacting us at julie@thehappybusinessco.com.
If you opt out, we may retain a limited record of your email address or other contact detail on a suppression list so that we can respect your choice.
Opting out of marketing does not prevent us from sending service messages that are necessary for a product, membership, booking or contract you have with us.
8. Cookies and similar technologies
Our website may use cookies and similar technologies for purposes such as:
-
essential website operation;
-
security;
-
remembering preferences;
-
analytics;
-
functionality; and
-
marketing or advertising.
Where UK law requires consent for a non-essential cookie or similar technology, we will seek that consent through our cookie controls before using it.
Please see our Cookie Policy for more information about the technologies currently used and how to change your choices.
9. How we use AI with personal data
We use AI and automated tools in parts of our business and services.
AI may help us with activities such as:
-
drafting;
-
summarising;
-
administration;
-
research;
-
content preparation;
-
organising business information;
-
summarising agreed meeting transcripts;
-
summarising messages or voice notes;
-
organising Member Memory or client relationship notes;
-
identifying actions and follow-ups from conversations;
-
helping prepare personalised draft communications for human review;
-
supporting customer-service administration;
-
analysing information;
-
creating or configuring AI assistants and workflows; and
-
delivering agreed AI-enabled business services.
Where AI is used to help create Member Memory or meeting notes, we aim to keep the useful business or relationship context rather than storing a complete transcript indefinitely where the full transcript is no longer necessary.
We do not assume that AI output is accurate simply because it has been generated by an AI system.
Where personal data is involved, we aim to:
-
use only data reasonably needed for the task;
-
minimise, anonymise or pseudonymise data where practical;
-
avoid retaining unnecessary sensitive detail;
-
use appropriate accounts, settings and providers;
-
apply meaningful human oversight proportionate to the risk;
-
check important summaries and records for accuracy where appropriate;
-
allow inaccurate information to be corrected;
-
restrict AI authority through instructions, permissions and approvals where appropriate; and
-
avoid putting passwords, secret keys, authentication codes or unnecessary sensitive information into ordinary AI prompts.
Our AI Usage & Responsible AI Policy explains our approach in more detail.
10. Automated decision-making and profiling
We do not currently use solely automated decision-making about our ordinary customers, members or website users where the decision produces legal effects or similarly significant effects on them.
We may use automated tools for lower-risk activities such as:
-
organising information;
-
helping retrieve relevant member or client context;
-
summarising conversations;
-
preparing personalised drafts for human review;
-
email or marketing automation;
-
categorising or summarising information;
-
website analytics; and
-
routine administrative workflows.
Using limited Member Memory or client information to help us remember relevant context or prepare a more personal communication does not determine whether someone may access a service, what they must pay, or another similarly significant decision.
Where information is used to personalise direct marketing, applicable marketing, profiling and objection rights continue to apply.
If we introduce significant automated decision-making involving personal data, we will assess the applicable legal requirements and provide additional information and safeguards where required.
Where we process data as a processor for a business client, any significant automated decision-making by that client is subject to the client’s responsibilities and the agreed scope of our service.
11. Who we share personal data with
We may share personal data where reasonably necessary with categories of recipients such as:
-
website hosting and technology providers;
-
cloud storage and productivity providers;
-
database, CRM and workspace providers, including services such as Notion;
-
email and marketing platforms;
-
form, survey and e-signature providers;
-
payment processors and accounting providers;
-
booking and scheduling platforms;
-
learning, membership and course platforms;
-
video-conferencing and event platforms;
-
social-media platforms;
-
AI and automation providers;
-
IT, cybersecurity and technical-support providers;
-
professional advisers such as accountants, lawyers, insurers and consultants;
-
contractors or suppliers helping us provide a service;
-
regulators, courts, public authorities or law-enforcement bodies where required; and
-
a purchaser, investor or adviser involved in a genuine business sale, restructuring or similar transaction subject to appropriate safeguards.
Depending on the service, providers we use may include services supplied by organisations such as Google, OpenAI, Notion, Jotform, Meta and video-conferencing or payment providers, as well as other business software selected from time to time.
We do not sell personal data to advertisers.
Third-party providers process data under their own contractual, security and privacy arrangements.
Where a provider acts as our processor, we take reasonable steps to use appropriate contractual protections.
12. International transfers
Some of the technology and service providers we use operate internationally.
This means personal data may be transferred to, stored in or accessed from countries outside the United Kingdom, including countries outside the UK and European Economic Area.
Where a restricted international transfer is made, we take steps required by UK data-protection law.
Depending on the destination and provider, these safeguards may include:
-
UK adequacy regulations;
-
the UK Extension to the EU-US Data Privacy Framework where applicable;
-
the UK International Data Transfer Agreement;
-
the UK Addendum to approved EU Standard Contractual Clauses; or
-
another lawful transfer mechanism.
Where required, we also consider whether additional transfer-risk measures are appropriate.
You can contact us if you would like more information about the safeguards used for a particular transfer.
13. Security
We use reasonable and proportionate technical and organisational measures intended to protect personal data from accidental or unlawful:
-
loss;
-
destruction;
-
alteration;
-
unauthorised disclosure; or
-
unauthorised access.
Measures may include appropriate account controls, restricted access, secure providers, authentication controls, backups, confidentiality requirements and data minimisation.
Access to Member Memory and relationship notes is limited to people and systems that reasonably need the information for the relevant business purpose.
No internet, email, cloud, database or AI system can be guaranteed to be completely secure.
If we become aware of a personal-data breach, we will assess it and take action in accordance with applicable law, including notifying the Information Commissioner’s Office or affected individuals where legally required.
14. Accuracy and keeping Member Memory useful
We aim to keep personal data accurate and reasonably up to date.
Member Memory is intended to be a helpful working record rather than a permanent historical archive.
We may therefore:
-
update notes when circumstances change;
-
replace outdated information with more current information;
-
remove details that are no longer useful;
-
correct errors when they are identified;
-
distinguish confirmed information from ideas or future plans; and
-
periodically review whether information still needs to be retained.
You can ask us to correct inaccurate information we hold about you.
15. How long we keep personal data
We do not keep personal data for longer than we reasonably need it.
Retention depends on:
-
why the information was collected;
-
whether we have an ongoing relationship with you;
-
contractual requirements;
-
tax, accounting and company-law obligations;
-
limitation periods for legal claims;
-
the sensitivity of the information;
-
whether a dispute or complaint exists; and
-
technical retention by relevant service providers.
Our normal approach is:
| Category | Typical retention approach |
| Customer, contract, invoice and transaction records | Normally retained for up to six years after the end of the relevant financial year or relationship where needed for tax, accounting, contractual or legal purposes |
| Enquiries that do not become customers | Normally up to two years after the last meaningful contact unless there is a reason to keep them longer |
| Active membership or client records | For the duration of the relationship and then for an appropriate period based on contractual, legal and record-keeping needs |
| Member Memory and relationship/personalisation notes | Normally for the duration of the relevant relationship and then only for as long as reasonably useful or necessary for an ongoing lawful purpose. Notes may be reviewed, updated, deleted or anonymised when no longer relevant |
| Raw meeting transcripts or recordings | Normally only for as long as needed to create agreed notes, provide the service, deal with a query or meet another stated purpose. Where a transcript has an ongoing client-service purpose, it may be retained for the duration of the relevant relationship, subject to periodic review and data minimisation |
| AI-generated meeting or relationship summaries | For as long as the summary remains relevant to the service or relationship, subject to review, correction and deletion when no longer needed |
| Marketing contacts | Until you unsubscribe, withdraw consent or we decide the information is no longer useful, subject to retaining limited suppression information |
| Marketing suppression records | Retained as necessary to ensure we continue to respect an opt-out |
| Event recordings | For the period stated for the relevant event, programme or recording purpose |
| Coaching, mentoring or consultancy notes | For as long as reasonably required for the service, professional record-keeping and legal purposes, taking account of the nature and sensitivity of the notes |
| AI project data and outputs | For as long as needed for the relevant service or business purpose, subject to our deletion practices and the retention arrangements of the relevant technology provider |
| Website technical and cookie data | In accordance with the periods described in our Cookie Policy and relevant platform settings |
| Complaints and disputes | For as long as needed to investigate and resolve the matter and protect legal rights |
We may delete or anonymise information sooner where appropriate.
Where anonymised information can no longer identify an individual, we may retain and use it for legitimate statistical, analytical or business purposes.
16. Your data-protection rights
Depending on the circumstances, you may have the right to:
Be informed
To receive clear information about how your personal data is used.
Access
To request a copy of personal data we hold about you, including relevant Member Memory or relationship notes.
Rectification
To ask us to correct inaccurate or incomplete personal data, including inaccurate notes or AI-generated summaries.
Erasure
To ask us to delete personal data in certain circumstances.
Restriction
To ask us to restrict the use of personal data in certain circumstances.
Data portability
To receive certain personal data in a structured, commonly used and machine-readable format and, where applicable, ask for it to be transferred.
Object
To object to processing based on legitimate interests in certain circumstances.
You have an absolute right to object to the use of your personal data for direct marketing.
Withdraw consent
Where we rely on consent, you may withdraw it at any time.
Withdrawal does not affect processing that was lawful before the consent was withdrawn.
Rights concerning significant automated decisions
Where applicable, you may have rights and safeguards relating to significant decisions made solely by automated processing.
These rights are subject to legal conditions and exemptions.
To exercise a right, contact:
We may need to ask for information reasonably necessary to confirm your identity before acting on a request.
We will respond within the period required by applicable law.
17. Data-protection complaints
If you are unhappy with how we have handled your personal data, you have the right to make a data-protection complaint to us.
Please contact:
Julie Begbie
Happy Business Global Ltd
1 Waterloo Bank
Penicuik
Midlothian
EH26 8NS
Email: julie@thehappybusinessco.com
We will:
-
provide an accessible way to complain;
-
acknowledge a data-protection complaint within 30 days;
-
investigate it appropriately;
-
keep you informed where appropriate; and
-
communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator.
Website: https://ico.org.uk/
We would welcome the opportunity to address your concern directly first, but this does not remove your right to contact the ICO.
18. Personal data about other people
If you provide us with personal data about another person, you are responsible for ensuring that you have a lawful basis or other appropriate authority to provide it.
For business and AI-enabled services, clients must follow their own data-protection obligations when giving us access to information about employees, customers, prospects, suppliers or other people.
Where we act as processor, we will process such data in accordance with the relevant contractual data-processing terms.
19. Children’s privacy
Our website, memberships and ordinary services are intended for adults aged 18 and over unless we expressly state otherwise for a particular service.
We do not knowingly collect personal data directly from children through ordinary website or membership services.
Where we provide training or business services to organisations that work with children, information about children should not be provided to us unless this is necessary, lawful, appropriately safeguarded and within the specifically agreed scope of the service.
20. Third-party websites and platforms
Our website, emails and services may contain links to third-party websites, apps, social networks or platforms.
Those organisations are responsible for their own processing where they act as independent controllers.
We encourage you to read their privacy information.
We are not responsible for the privacy practices of a third party merely because we link to or use its service.
21. Changes to this Privacy Notice
We review this Privacy Notice regularly and may update it to reflect:
-
changes in our business or services;
-
new membership or relationship-management practices;
-
new technology or AI use;
-
changes in service providers;
-
changes in data-protection law or regulatory guidance; or
-
changes in how we process personal data.
The current version will be published on our website with the date it was last updated.
If we introduce a materially new use of personal data that requires additional notice, we will provide appropriate information before that processing begins.
22. Contact us
For privacy questions, rights requests or data-protection complaints, contact:
Julie Begbie
Happy Business Global Ltd
Company number: SC518154
VAT number: 391 2243 10
1 Waterloo Bank
Penicuik
Midlothian
EH26 8NS
Email: julie@thehappybusinessco.com