Little Big Minds Privacy Notice

Effective date: 19 June 2025

This Privacy Notice explains how Little Big Minds ("we", "us" or "our"), based at littlebigminds.uk, collects, uses, shares and protects the personal information of visitors to our website and subscribers to our services. We are committed to respecting your privacy and ensuring your data is handled securely and transparently.

 


 

What data we collect

• Subscription and account data: name, email, billing details (handled by our payment provider), subscription status.

• Intake form responses: background information you choose to share so we can tailor support (this may include health-related information, which is special category data).

• Chat content: messages you send during support.

• Communication data: emails and messages if you contact us via email, WhatsApp or other channels you choose.

• Website and device data: IP address, device/browser information, pages viewed, approximate location, cookies (see Cookies section).

 

Why we use your data and our lawful bases (UK GDPR)

• To provide the service (create/manage your subscription, respond to messages, deliver support) — Contract (Art. 6(1)(b)).

• To understand your needs and tailor support (using intake and chat information) — Consent (Art. 6(1)(a)); for special category data, Explicit Consent (Art. 9(2)(a)).

• Safeguarding if there is a serious risk of harm to you or others — Legitimate interests (Art. 6(1)(f)); and, where necessary and appropriate, Vital interests (Art. 6(1)(d) and Art. 9(2)(c)). We rely on explicit consent for special category data wherever possible; vital interests is reserved for rare situations where someone cannot consent and immediate protection is necessary.

• To improve and protect our website/service (troubleshooting, security, analytics where used) — Legitimate interests (Art. 6(1)(f)).

• To comply with legal and tax obligations (e.g., billing records) — Legal obligation (Art. 6(1)(c)).

 

Who we share data with (processors/recipients)

We use trusted providers to run our service. They process data on our instructions:

• Website hosting/builder: Webador B.V.

• Forms and storage: Google (Google Forms, Google Sheets, Google Drive).

• Email and productivity: Google Workspace (Gmail).

• Messaging (if you choose to use it): WhatsApp / Meta Platforms.

• Payment provider: [Stripe / PayPal / other — replace with your provider]. Your payment details are sent directly to the provider; we don’t store full card details.

• Only if required: police/authorities or health services where there is a serious safety risk or legal requirement.

We do not sell your data.

 

International transfers

Some providers may process data outside the UK/EEA (for example, in the US). Where this happens, we rely on approved safeguards such as the UK Addendum to the EU Standard Contractual Clauses and providers’ additional measures. See each provider’s privacy information for details.

 

How long we keep your data (retention)

• Intake forms: 3 years after your last interaction with us (unless a safeguarding record needs to be kept longer).

• Chat records: 2 years after your last interaction.

• Subscription and billing data: 6 years to meet tax and legal requirements.

• Website analytics and server logs: up to 12 months, then aggregated or deleted.

We delete or anonymise data when these periods end unless we must keep it for legal reasons.

 

Your rights

You have rights over your personal data: access, rectification, erasure, restriction, portability, and the right to object to certain processing. Where we rely on consent, you can withdraw it at any time.

To exercise your rights, contact: steve@littlebigminds.uk

 

You can also complain to the UK Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/

 

Children and young people

Under-18s can use the service with parent/guardian consent. We ask only for the information needed to provide support. If there is a serious concern for safety, we may contact your emergency contact, GP, or emergency services.

 

Cookies and similar technologies (PECR)

• Essential cookies: used to make the site work (e.g., security, basic functionality). These do not require consent.

• Non-essential cookies (e.g., analytics): we will ask for your consent on your first visit and only set these if you accept. You can change your choice at any time.

If you use analytics, we may process approximate location and device information to understand how the site is used.

For details, see our Cookie Notice or contact us.

 

Security

We use platform security (Webador and Google) and access controls to protect personal data. We limit who can access intake/chat information and review access regularly. No system is perfect, but we work to keep your data safe.

 

Safeguarding and confidentiality

What you share is private. We only share information if there is a serious and immediate concern about risk of harm to you or others, or where the law requires it. We will try to discuss this with you first where possible.

 

Changes to this notice

We may update this Privacy Notice if our practices change. The latest version will always be at littlebigminds.uk/privacy.

 

 

Note: This notice is provided for transparency under UK GDPR and the Data Protection Act 2018. It is not legal advice. If you need specific legal guidance, consider speaking to a solicitor.