1. About this Privacy Notice

a. How have we made this notice easy to navigate?

We know privacy notices can be long and technical. We have written this one as a series of plain-English questions and answers so that you can find what matters to you quickly.

 

This notice is divided into numbered sections. Sections 1 to 4 and 6 to 13 apply to everyone. Section 5 is modular: it describes how we handle personal data depending on who you are – a website visitor, a prospective client or business contact, a marketing contact, a recruitment candidate, a member of a client’s personnel, or a supplier or partner. You only need to read the part of Section 5 that applies to you.

b. Which laws does this notice reflect?

This notice is written to comply with the data protection laws that apply to us in the United Kingdom, in particular:

  • the UK General Data Protection Regulation (“UK GDPR”);
  • the Data Protection Act 2018 (“DPA”);
  • the Data (Use and Access) Act 2025 (“DUAA”), which updates and sits alongside the UK GDPR and the DPA;
  • the Privacy and Electronic Communications Regulations 2003 (“PECR”), as amended, which govern cookies and electronic marketing; and
  • relevant guidance issued by the Information Commissioner’s Office (“ICO“).

c. What key terms do we use?

The following definitions apply throughout:

  • “Journey Further”, “we”, “us” and “our” means the Journey Further Group and the companies described in Section 2.
  • “Personal data” means any information relating to an identified or identifiable living individual (a “data subject”).
  • “Processing” means anything we do with personal data – including collecting, recording, storing, using, disclosing, combining, restricting, erasing or destroying it.
  • “Special category data” means the more sensitive categories of personal data listed in Article 9 of the UK GDPR (for example, data about health, racial or ethnic origin, religious beliefs, or sexual orientation). Data about criminal offences is protected separately under Article 10 of the UK GDPR.
  • “Controller” means the party that decides why and how personal data is processed.
  • “Processor” means a party that processes personal data on behalf of, and on the documented instructions of, a controller.
  • “Sub-processor” means a processor we engage to help us carry out processing on behalf of one of our clients.
  • “Client” means an organisation to which the Journey Further Group provides its services.
  • “Our services” means the digital marketing services described in Section 2, including Search Engine Optimisation (“SEO”), paid search and paid social (“PPC”), programmatic and display advertising, digital PR, influencer marketing, creative services, content, conversion optimisation, marketing analytics and marketing science, customer insight, campaign management, marketing technology and marketing consultancy.

2. Who are we and how can you contact us?

a. Who is responsible for your personal data?

Journey Further is a digital marketing agency group. We help brands to be found, be chosen and be ahead through data-driven marketing – including SEO, paid media, digital PR, influencer marketing, creative, content, conversion optimisation and marketing science. We work with clients across many sectors. Where we work with clients in regulated sectors such as healthcare, we provide standard digital marketing services only; we do not access medical records, patient systems or clinical databases (see Section 5, “Client personnel and client-provided content“).

 

The controller of the personal data collected through our public website is the Journey Further Group. For other processing, the group company that has the relationship with you (for example, the entity named in your contract or job offer) is the controller. The group companies are:

 

Entity Where incorporated Principal / registered office Registration number
Journey Further Group Limited

(group holding company; controller for the public website)

England & Wales Old Linen Court, 83-85 Shambles Street, Barnsley, South Yorkshire, England, S70 2SB 13498741
Journey Further Limited

(principal UK operating company)

England & Wales Registered office: Old Linen Court, 83-85 Shambles Street, Barnsley, South Yorkshire, England, S70 2SB 10389234
Saulderson Media Ltd Scotland Registered address: 22 Montrose Street, Glasgow, G1 1RE, United Kingdom SC593142
Journey Further LLC United States of America 

(New York)

Registered address: Suite 10, Floor 8, The Square, 205 Hudson Street, New York, NY 10013, USA EIN 87-4672117

 

All of these entities are operationally active and employ staff (in the United Kingdom and, for Journey Further LLC and part of Saulderson Media Ltd, the United States). If you are a client, the contracting entity is named in your services agreement. If you are a candidate, the entity is named in the role advertisement and any offer. If you are simply visiting our website, the responsible entity is Journey Further Group Limited.

b. What is our role under data protection law - controller or processor?

Our role depends on the activity, and it is important to distinguish the two:

  • As a controller. We act as a controller when we decide why and how personal data is processed for our own business purposes – for example, operating and securing our website, responding to enquiries, sending our own marketing, running our recruitment process, managing prospective-client and business-contact records, and administering our supplier relationships.
  • As a processor for our clients. When we deliver our services, we frequently process personal data on behalf of a client and on that client’s documented instructions. The client is the controller of that data. This includes, for example, personal data within a client’s advertising and analytics accounts, audience and campaign data, customer insight provided by the client, and creative assets (such as photographs, video, testimonials, customer stories and other marketing materials) that feature identifiable individuals. In these cases the client remains responsible for having a lawful basis and for obtaining all necessary permissions, consents and usage rights before providing the material to us.
  • As a sub-processor. Occasionally, where another agency or partner contracts directly with the end client and engages us in turn, we may act as a sub-processor within that arrangement.

 

Where we act as a processor or sub-processor, our processing is governed by a written data processing agreement (meeting the requirements of Article 28 of the UK GDPR). We process only on documented instructions, keep the data confidential, apply appropriate security, engage sub-processors only under equivalent obligations, and assist the client with data-subject requests and with its own compliance obligations.

c. Do we have a Data Protection Officer?

We are not required to appoint a statutory Data Protection Officer under Article 37 of the UK GDPR, and we have not appointed one. We take data protection seriously across the group: our Legal & Compliance Team owns our data protection framework, supported by our Security function within Technology & Innovation Team, and we operate an information security management system certified to ISO/IEC 27001:2022 (see Section 8).

 

For any data protection question, or to exercise your rights, contact our Legal & Compliance Team at legal@journeyfurther.com. Security matters can be raised with our Security team at security@journeyfurther.com.

3. Which supervisory authority oversees us?

As a UK-established group, our data protection supervisory authority is the ICO. Our UK entities are registered with the ICO, and, where applicable, our non-UK entity holds any equivalent registration required in its jurisdiction. You have the right to raise a concern with the ICO at any time (see Section 10 for how to do this and for your parallel right to complain to us directly).

4. What personal data do we collect?

a. Who does this notice apply to?

This notice applies to:

  • visitors to our websites (including journeyfurther.com and associated group domains);
  • prospective clients and business contacts, and people who contact us with sales or general enquiries;
  • people who subscribe to our marketing, including our newsletter, The Frontier, and our Book Club;
  • candidates who apply for a role with us;
  • members of our clients’ personnel, and individuals featured in content or creative assets our clients provide; and
  • our suppliers, partners and their staff.

 

It does not cover our own employees and workers, who receive a separate internal privacy notice.

b. What categories of personal data do we collect?

Depending on your relationship with us, we may process the categories below. The volume is usually small – for a website visitor it may be little more than usage data and, with consent, cookie data.

 

Category Examples
Identity and contact data First and last name, job title, employer, business email, business telephone, business address, and professional profile links (for example, LinkedIn).
Website, device and usage data IP address, device and browser type, operating system, referral pages, pages visited, on-site activity, timestamps and cookie identifiers.
Communication data The content of your enquiries, contact-form submissions, emails, and (where used and notified) meeting notes, recordings and transcripts.
Marketing data Marketing and communication preferences, subscription status, campaign interactions and engagement metrics.
Prospect data Business-contact and role information about potential clients, and information about your interest in our services.
Recruitment data CV, cover letter, employment and education history, qualifications, references, right-to-work information, interview notes, and any assessment results.
Client and supplier relationship data Business-contact details of client and supplier personnel (name, role, email, phone and billing-contact details), contract and account-management records, and correspondence.
Client campaign, audience and tracking data

(processed as a processor)

Pseudonymised online identifiers (cookies, ad-click IDs such as GCLID, mobile advertising IDs), device and browser data, truncated IP-derived location, on-site events and conversions, audience segments, and hashed customer-match lists that a client provides for audience targeting. Processed on the client’s documented instructions.
Client-provided content

(processed as a processor)

Where a client provides them, photographs, video, testimonials, customer stories, creative assets and campaign materials that may feature identifiable individuals – handled by us on the client’s behalf.
Financial and transactional data Billing contact details, purchase orders, invoices, VAT numbers and payment records (we do not need or seek payment-card numbers through the website).
Special category and criminal-offence data We do not intentionally collect special category data, and we do not process criminal-convictions or criminal-offence data. Special category data may arise only where you volunteer it during recruitment (for example, to arrange reasonable adjustments) or where a client includes it within content it provides to us. Where it does, we apply the additional safeguards in Section 8.

c. Where do we get your personal data from?

We collect personal data from three types of sources:

  • Directly from you – when you browse our site, complete a form, make an enquiry, subscribe to our newsletter or Book Club, apply for a role, or enter into a contract with us.
  • Automatically – through cookies and similar technologies on our websites (subject to your consent, see Section 12) and through our server and application logs.
  • From third parties – from our clients and partners (including the client-provided content described above); from publicly available and professional sources such as company websites and professional networks; and from business-contact and prospecting providers such as LinkedIn Sales Navigator, where permitted by law. Where we rely on a third-party prospecting source, we take reasonable steps to satisfy ourselves that the data was obtained lawfully.

5. How we handle your data depending on who you are

a. Website visitors

What we collect and how

 

When you visit our websites, we automatically process usage data from our server logs (including the pages requested, date and time, data volume, browser and operating system, referral link and IP address) and, subject to your consent, data from cookies and similar technologies (see Section 12). We also process any information you actively submit through a contact form, sales enquiry, newsletter or Book Club sign-up, or event registration.

 

Why we use it and our legal basis

 

  • To operate, maintain and secure our websites and IT systems – Article 6(1)(f) of the UK GDPR (our legitimate interest in running and protecting our systems, including detecting and preventing attacks, fraud and abuse).
  • To respond to your enquiries and contact-form submissions – Article 6(1)(b) of the UK GDPR (steps taken at your request before any contract) and Article 6(1)(f) of the UK GDPR (our interest in communicating with interested parties).
  • To provide our newsletter, Book Club and other content you request – Article 6(1)(a) of the UK GDPR (consent), which you can withdraw at any time.
  • To measure and improve website performance and, where enabled, to advertise – Article 6(1)(a) of the UK GDPR (consent given through our cookie banner).

 

Who we share it with

 

We use trusted providers acting as our processors, including web hosting and cloud infrastructure, content-management and delivery, analytics, marketing automation (HubSpot), forms and surveys (Typeform), consent management, and advertising and social platforms. Website analytics and behavioural measurement may include Google Analytics and Microsoft Clarity, and advertising may include Microsoft Advertising, Google Ads, the LinkedIn Insight Tag and similar tools, in each case only where you have consented via our cookie banner.

b. Prospective clients and business contacts

What we collect and how

 

We collect your name, job title, employer, business contact details, professional profile links, our communication history with you, and information about your interest in our services (for example, an enquiry, a proposal request, or attendance at an event). We collect this directly from you, from publicly available and professional sources, and from business-contact and prospecting providers such as LinkedIn Sales Navigator, where permitted by law.

 

Why we use it and our legal basis

 

  • To respond to enquiries and take pre-contract steps – Article 6(1)(b) of the UK GDPR.
  • For business development, relationship management and B2B marketing to prospective and existing business contacts – Article 6(1)(f) of the UK GDPR (our legitimate interest in growing our business), subject to your right to object, and, where required by PECR, Article 6(1)(a) of the UK GDPR (consent).
  • To maintain our customer-relationship management records and understand which of our services may be relevant to you – Article 6(1)(f) of the UK GDPR.

 

Who we share it with

 

Our sales, growth and marketing teams, and our CRM and marketing-automation providers (such as HubSpot), prospecting tools, and event and webinar platforms.

c. Marketing contacts

What we collect and how

 

If you subscribe to our newsletter (The Frontier), join our Book Club, or otherwise ask to hear from us, we process your contact details, your marketing preferences and subscription status, and your interactions with our campaigns (such as opens and clicks). You provide this directly, and we record engagement through our marketing tools.

 

Why we use it and our legal basis

 

  • To send you marketing you have asked for and to manage your subscription – Article 6(1)(a) of the UK GDPR (consent), which you can withdraw at any time using the unsubscribe link in any message or by contacting us.
  • For B2B marketing to existing and prospective business contacts where the law allows us to do so without consent – Article 6(1)(f) of the UK GDPR (legitimate interests), subject to your right to object.
  • To keep a suppression record of people who have unsubscribed, so that we can honour your choice – Article 6(1)(c) of the UK GDPR (compliance with our obligations under PECR and the UK GDPR).

 

Who we share it with

 

Our email marketing and marketing-automation providers (such as HubSpot and, for certain client newsletters, Mailchimp) acting as our processors. We also run our own paid media and remarketing campaigns to promote the Journey Further Group on platforms such as Google and Meta, and we host or sponsor events (for our own events, sign-up uses the standard opt-in/opt-out forms on our website). Every marketing email contains a one-click unsubscribe. We do not sell your personal data.

d. Recruitment candidates

What we collect and how

 

If you apply for a role, we process your contact details, CV and cover letter, employment and education history, qualifications, references and reference responses, right-to-work information, interview notes, and any assessment results. You provide most of this directly (including through our recruitment platform); we may also receive information from recruitment agencies and, with your knowledge, from referees. Where we record or transcribe an interview, we will tell you in advance and rely on your consent.

 

We carry out pre-employment checks in-house – right-to-work verification and reference checks. We do not carry out DBS or criminal-record checks, we do not process criminal-convictions data, and we do not use AI to screen candidates or to make recruitment or HR decisions.

 

Why we use it and our legal basis

 

  • To assess your application, manage the hiring process and communicate with you – Article 6(1)(b) of the UK GDPR (steps before a possible contract) and Article 6(1)(f) of the UK GDPR (running a fair and effective recruitment process).
  • To verify identity, right to work and references – Article 6(1)(f) of the UK GDPR and, where applicable, Article 6(1)(c) of the UK GDPR (legal obligation).
  • To record or transcribe an interview – Article 6(1)(a) of the UK GDPR (consent), which you can withdraw at any time.
  • To keep your details on file for future roles, where you agree – Article 6(1)(a) UK GDPR (consent).
  • Where you volunteer special category data (for example, to arrange reasonable adjustments), we process it under Article 9(2) UK GDPR in connection with our obligations and your explicit consent, and only so far as necessary.

 

Who we share it with

 

Internally, only those involved in the hiring decision. Externally, our recruitment and HR platforms (such as our applicant-tracking and HR systems) and interview and scheduling tools, each acting under appropriate contracts. Our pre-employment checks are conducted in-house, so we do not use a third-party background-screening provider.

e. Client personnel and client-provided content

This part is important for understanding when we act as a processor rather than a controller.

 

What we collect and how

 

To manage the client relationship, we process the business-contact details of our clients’ personnel (name, role, business email and phone, and billing-contact details), together with account-management and project records – for which we act as a controller. This information is held in our CRM and business systems (for example, HubSpot and Google Workspace).

 

Separately, to deliver our services we process personal data on the client’s behalf and on its documented instructions, as a processor. Most of this is aggregated or pseudonymised campaign and analytics data rather than directly identifying information. What we process depends on the service line:

 

Service line Personal data typically processed (as processor)
Paid Search Mostly aggregated, pseudonymised performance data (impressions, clicks, spend, conversions) from ad platforms (Google Ads, Microsoft Advertising) and analytics. Conversion tracking uses online identifiers such as cookies and ad-click IDs (for example, GCLID). May process client-supplied customer lists (email/phone) that are hashed before upload for audience matching (for example, Customer Match). No special-category data.
Paid Social Aggregated campaign performance and audience insights from platform pixels and SDKs across social platforms (for example, Meta, TikTok, LinkedIn, Pinterest, Snap, X). Custom and lookalike audiences may use hashed customer lists provided by the client; pixel and Conversions API events capture pseudonymised user actions. No special-category data.
Programmatic Pseudonymised online identifiers (cookies, mobile advertising IDs, IP-derived location), contextual and audience-segment data, and impression/click/conversion logs, through demand-side platforms (for example, DV360). Third-party audience segments are accessed via the platform. No directly identifying or special-category data is processed by us.
SEO Mostly aggregated, non-personal data: crawl data, rankings, and aggregated search-query and impression data (for example, from Google Search Console), plus site analytics. Any user-level analytics is pseudonymised.
Content Largely non-personal. May include contributor or contact details, and any personal data contained in client-supplied source material or assets. Performance is measured on aggregated engagement metrics.
Analytics and measurement Website and app behavioural data via analytics tags (GA4, server-side tagging, Tag Manager): online identifiers, device and browser data, IP (often truncated), on-site events and conversions. Processed within the client’s analytics properties and our reporting/warehouse environments, pseudonymised and configured to exclude directly identifying data unless agreed. May ingest client first-party data for attribution or modelling on documented instructions.
Conversion rate optimisation (CRO) Behavioural and interaction data from testing and session tools (online identifiers, device data, on-site behaviour, session recordings and heatmaps). Session recordings may incidentally capture data you enter; tools are configured to mask sensitive fields. Pseudonymised.
Influencer Personal data of creators and influencers (name, contact details, social handles, audience and engagement metrics, and commercial terms), and payment details for contracted creators, processed to manage relationships and contracts under formal agreements and NDAs. Campaign performance is reported in aggregate.

 

Client first-party data, tracking and account access

 

  • First-party customer data – Clients may provide first-party customer data (such as CRM or email lists) for audience matching (for example, Google Customer Match, Meta Custom Audiences and LinkedIn Matched Audiences). This is received through secure transfer mechanisms (such as secure Google Drive links or encrypted email), stored in our secure Google Workspace environment hosted in Europe, and encrypted in transit and at rest; lists are hashed for audience matching.
  • Tracking and tags – Where instructed, we implement tracking tags, pixels, server-side tracking (for example, Conversions API and Enhanced Conversions) and SDKs on client websites and apps. These are configured at project inception following a privacy by design process, with access restricted to authorised project teams on a role-based basis.
  • Account access – Access to a client’s advertising and analytics accounts is normally granted through delegated or managed access rather than shared credentials. We do not routinely use client-issued credentials to access client production systems; where credentials are ever issued, they are held in a project-specific vault, shared only with the relevant team, and deleted at the end of the project or contract.
  • Creative assets – Where a client provides creative assets (such as photographs, video or testimonials) that feature identifiable individuals, we handle them as a processor. Assets are stored securely within our corporate Google Workspace environment, which is hosted in European data centres and encrypted in transit and at rest.
  • No cross-client use – We do not share one client’s personal data with another client, and we do not use it for cross-client benchmarking.

 

Healthcare and other regulated-sector clients

 

For clients in healthcare and other regulated sectors, our work is standard digital marketing (such as SEO and paid media). We do not access, ingest or interface with electronic health records, clinical systems or patient databases. Any content we use (for example, a customer testimonial or case study) is pre-cleared and provided to us by the client. We treat all client operational data as confidential by default and limit access through role-based permissions.

 

Why we use it and our legal basis

 

  • For our own management of the client relationship (client-contact records, account management, billing) – Article 6(1)(b) and Article 6(1)(f) of the UK GDPR, and Article 6(1)(c) of the UK GDPR for tax and accounting records.
  • For personal data we process as a processor on the client’s behalf, the client is the controller and is responsible for identifying the lawful basis and for obtaining all necessary permissions, consents and usage rights (including for customer-match lists, for tracking and, where relevant, for testimonials or content featuring individuals). We process it only under our data processing agreement with the client and on the client’s documented instructions, in line with Article 28 of the UK GDPR. We do not use client data for our own purposes, and we do not use it to train, fine-tune or improve any artificial-intelligence models (see Section 7).
  • We do not carry out automated decision-making or profiling that has a legal or similarly significant effect on individuals (such as personalised pricing or eligibility/exclusion audiences) in delivering our services.

 

Who we share it with

 

The group companies and personnel who need it to deliver the engagement (systems are operated consistently across our entities), and our vetted sub-processors – including cloud hosting and infrastructure (primarily Google Workspace, and Google Cloud Platform, including BigQuery, and Vercel for applications in development), collaboration tools (such as Slack), advertising and analytics platforms, and reporting and creative-production tools. Where we act as a processor, we engage sub-processors only as permitted by our agreement with the client, under equivalent data-protection obligations.

f. Suppliers and partners

What we collect and how

 

We collect the name, job title, business-contact details, contract and invoicing data, and due-diligence records of our suppliers, partners and their staff, together with any information needed to onboard and manage the relationship. We collect this from you directly, from our onboarding and finance systems, and from business-information and credit-checking sources where a check is appropriate.

 

Why we use it and our legal basis

 

  • To enter into and perform our contract with you – Article 6(1)(b) of the UK GDPR.
  • To meet legal obligations, including tax, accounting and anti-fraud requirements – Article 6(1)(c) of the UK GDPR.
  • For supplier due diligence and onboarding (including a security risk assessment), relationship management and defence of legal claims – Article 6(1)(f) of the UK GDPR.

 

Who we share it with

 

Our finance, accounting and contract-management providers, our banks and payment providers, our professional advisers, and – where required – regulators or authorities.

6. Our legal bases (including our legitimate interests)

a. Which legal bases do we rely on?

We must have a lawful basis under Article 6 of the UK GDPR (and, for special category data, a condition under Article 9) of the UK GDPR for everything we do with personal data. In summary:

  • Consent (Article 6(1)(a)). For optional cookies, for email and other electronic marketing where the law requires it, for our newsletter and Book Club, and for recording or transcribing interviews. You can withdraw consent at any time, without affecting processing already carried out.
  • Contract (Article 6(1)(b)). To take steps at your request before entering into a contract and to perform our contracts – for example, delivering our services, and managing client and supplier relationships.
  • Legal obligation (Article 6(1)(c)). To comply with our legal duties – for example, tax and accounting records, right-to-work checks, keeping marketing suppression lists, and responding to lawful requests.
  • Legitimate interests (Article 6(1)(f)). For the interests described below, where these are not overridden by your interests, rights and freedoms.
  • Special category data (Article 9). Only in the limited circumstances described in Section 5, on the appropriate Article 9 condition (typically explicit consent, or a condition connected with employment).

b. What are our legitimate interests?

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that our processing is proportionate and would be within your reasonable expectations. You can object at any time (see Section 9). Our legitimate interests include:

  • Running and securing our business and IT systems, including our websites, and detecting and preventing fraud, misuse and security threats.
  • Business development and B2B marketing to prospective and existing business contacts, and understanding which services may be relevant to them.
  • Managing our client, supplier and partner relationships, including account management, service delivery, quality and reporting.
  • Improving our services and operations, using aggregated and, wherever possible, anonymised data.
  • Group administration, including sharing certain data between our group companies for shared functions such as IT, finance and people operations.
  • Establishing, exercising or defending legal claims, and protecting our rights and those of our clients.

7. How we use artificial intelligence (AI)

The Journey Further Group uses AI tools to support productivity, creativity and analysis in delivering our services and running our business. We do so within a governed framework set by our AI Policy, which forms part of our ISO/IEC 27001-certified information security management system.

a. Where might AI be used?

We may use enterprise-grade or business-managed generative-AI and machine-learning tools – primarily services from providers such as OpenAI and Google (Gemini), and AI features built into approved productivity tools – to help with tasks such as data analysis, drafting and copy, translation, code, research, summarisation, and content and creative production. The specific tools we use may change as this fast-moving field develops. AI outputs are reviewed, validated and approved by an appropriate member of our team before they are relied upon or used in a client deliverable; AI supports professional judgement, it does not replace it. We do not use AI to make recruitment or HR decisions, and we do not carry out solely-automated decision-making that has a legal or similarly significant effect on individuals.

b. What safeguards do we apply?

We apply the safeguards outlined below:

  • Business-managed accounts only – Our AI Policy prohibits the use of personal or free-tier AI accounts for business activities. We use approved, business-managed or enterprise accounts.
  • Training opt-out – Under our enterprise and business-managed licensing and our procurement controls, provider training on our inputs is disabled or opted out of, where the provider offers this. Our aim is that client data and prompt content are not used to train providers’ public models.
  • Data minimisation and approval – Confidential information, personal data and client data must not be entered into an AI tool unless this has been approved and appropriate safeguards are in place. We do not use client data to train, fine-tune or improve AI models.
  • Evaluation of new tools – Any new AI tool that would process personal or sensitive data is assessed before use including the categories of data involved, the provider’s security and handling practices, and whether the provider’s terms would permit training on inputs. Development-related AI is subject to additional review, including a data protection (privacy-by-design) impact assessment.
  • Confidentiality – Access is controlled on a least-privilege basis, and all client operational data is treated as confidential by default.

 

We keep this section under review as our tools and the law (including guidance on AI) develop, and we will update it as needed.

8. Sharing, security, international transfers and retention

a. Who do we share your personal data with?

We share personal data only where necessary, and only with recipients under appropriate confidentiality and data-protection obligations. Recipients fall into these categories:

  • Other Journey Further Group companies – for service delivery and shared functions such as IT, finance and people operations, under intra-group data-sharing arrangements.
  • Service providers acting as our processors – including cloud hosting and infrastructure (primarily Google Workspace, and Google Cloud Platform, including BigQuery, and Vercel for applications in development), collaboration tools (such as Slack), CRM and marketing automation, analytics and reporting, creative and design tools, recruitment and HR platforms, security tooling, and, where relevant, AI providers. All are bound by written data-processing terms meeting Article 28 of the UK GDPR.
  • Our clients – where we return or handle personal data on their behalf as processor.
  • Professional advisers and auditors – including lawyers, accountants, insurers and our certification auditors.
  • Prospective buyers or investors – in connection with a corporate transaction, under confidentiality obligations.
  • Authorities and regulators – where we are legally required to disclose. We will challenge requests where it is appropriate and lawful to do so.

b. How do we keep your personal data secure?

We maintain an information security management system that is certified to ISO/IEC 27001:2022 (certificate number 266883, issued by the British Assessment Bureau; first certified 20 October 2025, subject to annual assessment). The certification covers Journey Further Limited, including its entities and employees. We apply appropriate technical and organisational measures, which are reviewed regularly, including:

  • Encryption – personal data is encrypted in transit and at rest, and business devices are encrypted, in line with recognised standards (NIST FIPS 140-3).
  • Access control – single sign-on (“SSO”) and multi-factor authentication (“MFA”) where possible, role-based access on a “need to know” and least-privilege basis, an enforced password manager, and prompt removal of access when someone leaves.
  • Endpoint and network security – managed endpoint protection and extended detection and response (“XDR”), automatic patching, and logging and monitoring.
  • Backups – backups are maintained, with our SaaS providers responsible for backup under a shared-responsibility model.
  • People – confidentiality obligations, background verification where permitted, and mandatory security-awareness training: at onboarding and at least annually (delivered through KnowBe4), with periodic “snapshot” training throughout the year on topics such as AI, security and data protection.
  • Supplier management – security due diligence at onboarding and on an ongoing basis (using an industry-standard risk questionnaire), with contractual data-protection terms and, where appropriate, non-disclosure agreements.
  • Incident response – a documented incident response plan. Where we act as a processor and a personal data breach affects client data, we notify the affected client without undue delay so that it can meet its own obligations; where we are the controller, we report to the ICO, and to affected individuals, where the law requires.

c. How do we protect data transferred internationally?

We are a UK-based group with a US company (Journey Further LLC), and some of our providers are located outside the United Kingdom. Where personal data is transferred outside the UK, we use one or more of the following mechanisms so that it remains protected to UK standards:

  • Adequacy – where the recipient is in a country covered by UK adequacy regulations.
  • UK–US Data Bridge – for transfers to US organisations certified under the UK Extension to the EU–US Data Privacy Framework, where that mechanism applies.
  • International Data Transfer Agreement (“IDTA”) or the UK Addendum to the EU Standard Contractual Clauses (“SCCs”) – for other transfers, including intra-group transfers to Journey Further LLC and transfers to providers without an adequacy or data bridge basis.
  • Transfer risk assessments – where required, we assess the destination country and put in place any supplementary measures needed.
  • Supplementary measures – such as encryption in transit and at rest, access restrictions and contractual protections.

 

Intra-group transfers between our UK companies and Journey Further LLC are governed by an intra-group data-sharing arrangement incorporating the appropriate transfer mechanism. 

d. How long do we keep your personal data?

We keep personal data only for as long as necessary for the purposes described in this notice, after which we delete or anonymise it. In each case the period is no longer than necessary, having regard to the purpose, the amount and sensitivity of the data, the risk of harm, applicable legal, tax and accounting obligations, and whether there is any prospect of a dispute. The periods below are our general guidance.

 

Type of data Retention
Website enquiries and contact-form data Retained no longer than necessary; typically deleted within a reasonable period after we have dealt with your enquiry, unless a relationship develops.
Website server logs and IP addresses Typically retained for a limited period for security purposes, then deleted or anonymised.
Marketing contact and preference data Until you unsubscribe or object, or the data is no longer relevant; we keep a limited suppression record so we can honour your choice.
Newsletter and Book Club subscription data Until you unsubscribe, plus a short audit log for compliance.
Prospective-client and business-contact data For the duration of the prospect relationship and a reasonable period afterwards, reviewed periodically.
Recruitment – unsuccessful candidates Up to 12 months unless you consent to a longer period for future roles.
Recruitment – successful candidates Transferred to your employee record and dealt with under our internal (employee) privacy notice.
Client relationship, contract and operational records Term of the engagement plus a retention period of up to 7 years (or longer where a legal obligation or a prospective dispute requires).
Client personal data processed as a processor In accordance with our contract and the client’s instructions. Where data sits in the client’s own advertising or analytics accounts, our access is removed when the engagement ends and we do not retain copies. Where we hold data on the client’s behalf, it is deleted or returned by default within 6 months of the end of the relevant processing, unless the client specifies otherwise.
Supplier and partner contact data For the duration of the relationship plus applicable statutory periods.
Financial and tax records Retained to meet UK statutory requirements (generally 6–7 years).
Analytics and aggregated data Once effectively anonymised, data protection law no longer applies, and we may keep it for statistical purposes.

 

Where we must keep data to meet a legal obligation but no longer need it actively, we restrict its use until the obligation ends and then delete or securely destroy it.

9. Your rights

a. What rights do you have?

Subject to certain conditions and exemptions, you have the following rights:

  • Access – to be told whether we process your personal data and, if so, to receive a copy and information about the processing. Under the DUAA, our search is one that is reasonable and proportionate.
  • Rectification – to have inaccurate data corrected and incomplete data completed.
  • Erasure – to have your data deleted in certain circumstances (for example, where it is no longer needed, or where you withdraw consent). Exceptions apply, for example where we must keep data by law; in that case we will restrict its use instead.
  • Restriction – to ask us to limit our processing in certain circumstances, for example while we check the accuracy of your data.
  • Portability – where processing is based on consent or contract and is automated, to receive certain data in a structured, commonly used, machine-readable format, or to have it sent to another controller where technically feasible.
  • Objection – to object to processing based on legitimate interests, and to object to direct marketing at any time (we will stop marketing to you immediately).
  • Withdraw consent – where we rely on consent, at any time, without affecting processing already carried out.
  • Automated decisions – not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not make such decisions about you – including in our recruitment process or in delivering our services.
  • Complain – to us and to the ICO (see Section 10).

b. How do you exercise your rights?

Contact our Legal & Compliance Team at legal@journeyfurther.com. Exercising your rights is free in most cases; we may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive, and we will explain why.

 

We may need to verify your identity before responding, and we may ask you to clarify your request. Under the DUAA we can pause the response clock while we do so. We will respond within one month, which we may extend by up to two further months for complex or numerous requests, telling you if we do.

 

Where your request relates to personal data we process as a processor on a client’s behalf, we will refer it to the relevant client (the controller) and support them in responding.

10. Raising a concern or making a complaint

a. What should you do if you have a concern?

Please contact us first so we can try to put things right. Email our Legal & Compliance Team at legal@journeyfurther.com, describing your concern. Under the DUAA you have a right to complain to us directly; we will acknowledge your complaint within 30 days and respond without undue delay.

b. How can you complain to the ICO?

You also have the right to complain to the ICO. We would, however, appreciate the chance to address your concerns before you approach the ICO.

 

Supervisory authority Contact
ICO Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113 – www.ico.org.uk 

 

Making a complaint does not affect any other legal remedy you may have.

11. Cookies, marketing and other website practices

a. How do we use cookies and similar technologies?

We use cookies and similar technologies on our websites. Under PECR, we set strictly necessary cookies (needed to operate the site securely) without consent, and we set all other cookies only after you have given consent through our cookie banner. You can change or withdraw your preferences at any time using the “Cookie Settings” link on our website.

b. What about links and embedded content?

Our website may contain links to, and embedded content from, third-party sites and platforms (such as LinkedIn and YouTube). We are not responsible for their privacy practices, and this notice does not apply to them. Embedded third-party content loads only after you consent through our cookie banner. We encourage you to read the privacy notices of any third-party site you visit.

c. How do we use your data for marketing?

We use contact and interaction data to send you information about our services, insights, events and our newsletter, The Frontier – only where the law allows. Where consent is required (for example, for most email marketing to individuals), we rely on your consent; where the law permits B2B marketing without consent, we may rely on our legitimate interests. Every marketing email has a one-click unsubscribe, and you can update your preferences at any time.

d. What about anonymised and aggregated data?

We use anonymised and aggregated data (for example, statistics about website usage and campaign performance) for analysis, reporting and improving our services. Once data is effectively anonymised so that it no longer identifies anyone, data protection law no longer applies to it.

12. Changes to this Privacy Notice

We may update this notice from time to time to reflect changes in our processing, our services, the law or regulatory guidance. The current version is always available on our website, with the version number and “Last updated” date at the top, and we keep a change log of material amendments. For significant changes (for example, new purposes or new categories of recipient), we will take appropriate steps to bring them to your attention, and where the law requires your consent, we will obtain it before the change applies to your data.

13. How to get in touch

We are always happy to hear from you:

  • Legal & Compliance Team (data protection queries and rights requests): legal@journeyfurther.com
  • Security team: security@journeyfurther.com
  • Website controller: Journey Further Group Limited (company number 13498741), Old Linen Court, 83-85 Shambles Street, Barnsley, South Yorkshire, England, S70 2SB; group head office: 4 The Dockside, Leeds, LS10 1EG.
  • Postal address for data protection matters: Legal & Compliance Team, Journey Further, 4 The Dockside, Leeds, LS10 1EG, United Kingdom.