1. Who we are
ENPOWER is the brand through which co-founders Andrea Tennant Cox and Alexandra Johansson Wall provide education, guided programmes and personal development experiences for women. For personal data handled through this website, the data controller is Empower Life Legacy Ltd, trading as ENPOWER, registered in England and Wales, company number 17311835.
This website provides an enrolment enquiry form and an optional email sign-up. It does not provide user accounts or an online checkout.
Privacy contact: [email protected]
Website: enpower.team
2. Personal information we collect
Information collected when you visit
When you request a page, our hosting and security provider may process technical information needed to deliver and protect the site. This can include your IP address, browser and device information, the page requested, request time, referring page and security signals.
Your privacy choice
We store a first-party consent record containing the policy version, the categories you selected and the time you made the choice. It does not contain your name, email address or an advertising identifier.
Information you give us through the enrolment form
If you complete the form to request a place on a programme, we collect your name, your email address, your phone number if you choose to give it, and whether you ticked the box agreeing to receive email from us. We also record the date and time of your request and the page you sent it from.
These details are stored in our customer relationship system so we can respond to you, keep track of your request, and send you the information you asked for. That system is Nucleus HQ, named in section 4.
Bot protection on the form
The form is protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than an automated script. To do this it processes technical signals from your browser and device. Without this check the form cannot be submitted, because it protects against abuse.
Information you choose to provide outside this site
If you contact ENPOWER by email, social channel or another method, we may receive your name, contact details and the content of your message. If you later enrol, the information needed to administer the programme and payment will be explained at the point it is collected.
Please do not send medical records, diagnosis information or other sensitive health information through a general email or social message. ENPOWER does not ask for special-category data through this website.
3. How and why we use information
| Purpose | Information | UK GDPR lawful basis |
|---|---|---|
| Deliver, secure and troubleshoot the website | Technical request and security data | Legitimate interests in operating a secure and reliable website |
| Remember your privacy choices | Consent version, selected categories and timestamp | Legal obligation and legitimate interests in respecting and recording privacy choices |
| Respond to a request for a place on a programme | Name, email address, phone number if given, and the time of your request | Steps taken at your request before entering a contract |
| Send you the acknowledgement email confirming we have your request | Name and email address | Steps taken at your request before entering a contract |
| Protect the form from automated abuse | Technical browser and device signals processed by Cloudflare Turnstile | Legitimate interests in preventing spam, fraud and abuse of our systems |
| Reply to an enquiry you send outside the website | Your contact details and message | Steps at your request before a contract, or legitimate interests in responding to genuine enquiries |
| Administer a programme after enrolment | Identity, contact, booking and transaction records | Performance of a contract and compliance with legal obligations |
| Send optional marketing | Contact details and consent record | Consent where required by UK GDPR and PECR |
We do not use the website for solely automated decisions that produce legal or similarly significant effects. We do not sell personal information.
5. International data transfers
Some technology providers operate internationally. This means technical information may be processed outside the United Kingdom or European Economic Area. Where data protection law requires safeguards, we rely on the provider's applicable adequacy arrangements, approved contractual protections or another lawful transfer mechanism.
You may contact us if you would like more information about safeguards relevant to a particular transfer.
6. How long we keep information
- The privacy preference cookie lasts for 180 days unless you delete it sooner or the consent version changes.
- Technical security information is retained only for as long as reasonably needed to deliver, secure and diagnose the website, subject to hosting-provider settings and legal requirements.
- Details submitted through the enrolment form are kept in our customer relationship system for no more than 24 months after the last meaningful contact, unless you enrol, in which case they become part of your programme record.
- General enquiry correspondence is normally kept for no more than 24 months after the last meaningful contact, unless it becomes part of a contract or legal issue.
- Contract, payment and accounting records may be kept for up to six years after the relevant relationship ends, or longer where law requires it.
- Marketing records are kept until consent is withdrawn or the information is no longer needed, with a minimal suppression record retained where necessary to honour an opt-out.
7. Your data protection rights
Depending on the information and lawful basis involved, you may have the right to:
- ask for access to your personal information;
- ask us to correct information that is inaccurate or incomplete;
- ask us to erase information in certain circumstances;
- ask us to restrict how information is used;
- object to processing based on legitimate interests or to direct marketing;
- receive information you provided in a portable format where the right applies; and
- withdraw consent at any time, without affecting processing that was lawful before withdrawal.
You have an absolute right to object to the use of your personal information for direct marketing.
To exercise a right, email the privacy contact above. We may need proportionate information to confirm your identity. We normally respond within one month.
8. How we protect information
We use proportionate technical and organisational safeguards designed to protect information against unauthorised access, loss, alteration or disclosure. These include encrypted HTTPS connections, restrictive browser security headers, access controls and a minimal-data approach.
No internet service can guarantee absolute security. If a personal data breach is likely to create a risk to people, we will assess it promptly and notify the Information Commissioner's Office within the period required by law. Where the risk is high, affected people will also be informed without undue delay.
9. Children
The website and programme are intended for adults. We do not knowingly collect personal information from children through this website. If you believe a child has provided information, contact us so it can be reviewed and, where appropriate, deleted.
10. Contact, complaints and changes
Questions, rights requests and privacy concerns can be sent to [email protected].
You also have the right to complain to the Information Commissioner's Office. You can visit ico.org.uk/make-a-complaint or telephone 0303 123 1113. We would appreciate the opportunity to address your concern first.
We will update this notice when the website starts collecting information in a new way, adds a new provider or changes how information is used. The date at the top shows the latest revision.