Privacy Policy
How we handle your data.
This policy covers renewmethod.co.uk and renewmarketing.co.uk — one controller, one policy, covering every Renew product and service. Last updated 30 July 2026.
1. Who we are
This policy covers renewmethod.co.uk and renewmarketing.co.uk. The data controller for both is Renew Marketing Ltd, a company registered in England and Wales (company number 07985759, VAT number GB 130 7728 25). Renew Method™ is a trading name of Renew Marketing Ltd, so one policy covers both practices.
Registered office: Unit 20 Ptarmigan Place, Attleborough Fields Industrial Estate, Nuneaton, CV11 6RX, United Kingdom.
Contact: hello@renewmethod.co.uk · +44 (0)345 094 0993
We process personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What this policy covers
Both websites, and every Renew product and service: the Decision Debt® Diagnostic and METHOD™ Diagnostic, the CPD Journey programme, The Lift, and ATLAS™, together with enquiries, strategy call bookings, engagements, and email. It does not cover third-party sites we link to, including LinkedIn. Their policies apply there.
3. The line we draw: identified vs anonymised
We draw a hard line between two kinds of data, and much of this policy hangs on it.
Identified personal data is anything connected to you: your name, email address, job title, organisation, and the content of your enquiries. We collect it only when you give it to us, and we process it on the basis of consent or, where we are delivering something you asked for, contract. We do not buy lists or scrape contacts.
Anonymised diagnostic data is your diagnostic answers, scores, and completion behaviour with everything that identifies you stripped out. We process it under our legitimate interest in understanding how businesses actually make decisions: it is the research base behind our published work and benchmarks. Once anonymised it cannot be traced back to you, which is also why it sits outside the scope of rights requests in section 9.
Linking diagnostic results to your identity, so we can send you your results or follow up, happens only with your consent, and you can withdraw that consent at any time.
4. What we collect and why
Diagnostics. Name, email address, job title, organisation name, and your responses. Responses are scored through the CARE™ decision engine to generate your results and a recommended next step. Lawful basis: consent (you explicitly submit the form) and legitimate interest in providing your diagnostic response. We may follow up with relevant information about Renew services.
Strategy call bookings. Name, email address, and anything you add to the booking form, via Acuity Scheduling. Lawful basis: contract. Kept 12 months from the appointment.
Enquiries. Name, email address, and your message, whether by form (WPForms) or email. Lawful basis: legitimate interest in responding to people who contact us. Kept 12 months from last contact.
Email marketing. Your email address, only if you opted in. Every email has a working unsubscribe link, or email us and we will remove you.
Website analytics. Anonymised usage data via Google Analytics 4, with IP anonymisation enabled. Analytics cookies are set only after you consent via the cookie banner.
5. AI processing
Parts of our products use Claude, a large language model supplied by Anthropic, via Anthropic’s commercial API. Where a product interprets your diagnostic answers or generates narrative output, that processing may run through the API.
Two things matter here. First, data sent through Anthropic’s commercial API is not used to train Anthropic’s models. Second, Anthropic retains API inputs and outputs only for a limited period for reliability and safety monitoring, typically up to 30 days, after which they are deleted. Anthropic’s commitments are published at privacy.claude.com.
We do not use AI to make automated decisions with legal or similarly significant effects about you. Diagnostic scores are informational, and any commercial decision that follows them is made by a human.
6. Shareable results links
Some diagnostics let you share your results via a unique URL. Treat that link like the document it is: anyone who has it can view the results page it points to. The page shows scores and answers, not your contact details.
If you want a shared link killed, tell us. We delete the underlying record, the URL stops resolving for everyone, everywhere, and no cached copy remains on our side. This is part of your right to erasure in section 9.
7. Who else touches the data
We use a small number of third-party processors. Each processes data on our instructions under a data processing agreement, and none may use your data for its own purposes.
- Anthropic · AI processing as described in section 5 · US
- Supabase · database infrastructure for our diagnostic and programme platforms · hosted in EU regions (Frankfurt and Ireland)
- Mailchimp (Intuit) · email delivery for lists you opted into · US
- Cloudflare · security, DNS, and content delivery · global network, US company
- Notion · diagnostic records and CRM · US
- Zapier · workflow automation between systems · US
- Acuity Scheduling · appointment booking · US
- WPForms and our WordPress hosting (GoDaddy) · form handling and website hosting
- Google Analytics 4 · anonymised website analytics · US
- ElevenLabs · voice interaction for The Lift only, where you choose to use it · US
We do not sell personal data. We do not share it with advertisers. We disclose it beyond this list only if the law compels us to.
8. How long we keep it
Diagnostic and other identified data: 24 months from your last interaction, then deleted or anonymised. Booking and enquiry records: 12 months as set out in section 4. If you become a client, engagement records are kept for the engagement’s duration, and invoicing records for the six years UK tax law requires.
Anonymised diagnostic data is retained indefinitely for research and benchmarking. It contains nothing that identifies you.
9. Your rights, including erasure
Under UK GDPR you can ask us for access to your data, correction, deletion, a portable copy, restriction of processing, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.
Erasure works like this: email hello@renewmethod.co.uk from the address we hold, or tell us enough to find your record. We delete your identified data, including any shareable results URL tied to it, within one month, and we confirm when it is done. What we cannot delete is data already anonymised into the research base, because we can no longer tell which of it was yours. That is the point of anonymisation, and it is why the line in section 3 is drawn where it is.
If you are unsatisfied with our response, you can complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113. We would rather you told us first, so we can fix it.
10. International transfers
Where a processor stores data outside the UK, notably Anthropic, Mailchimp, Notion, Zapier, Acuity, Google, and Cloudflare in the United States, transfers rely on the UK Extension to the EU-US Data Privacy Framework or the UK International Data Transfer Agreement and addendum, as applicable to that provider, alongside each provider’s data processing agreement.
11. Cookies
Essential cookies (no consent required): session and security cookies needed to make the site work.
Analytics cookies (consent required): Google Analytics 4, set only after you consent via the cookie banner. You can change your preferences via the banner or your browser at any time, and withdrawing consent does not affect your use of the site. We run no advertising cookies.
12. Data security
We apply appropriate technical and organisational measures against unauthorised access, loss, alteration, or disclosure, and restrict access to personal data to authorised people only. If a breach is likely to put your rights and freedoms at risk, we will notify the ICO within 72 hours and affected individuals without undue delay.
13. Client operational data
This section addresses a specific question relevant to enterprise and commercial clients. Renew operates as a systems architect, not a data processor, in respect of client operational data. We do not collect, store, or transact it. Operating systems built through the Method Stack™ run inside the client’s own infrastructure, on the client’s own tools, governed by the client’s own data policies. Our role is to design the decision architecture and workflow logic, not to own, access, or process the data that flows through it.
Any client data encountered incidentally during an engagement, for example in workflow design sessions, is treated as confidential and is not retained, analysed, or used for any purpose outside the engagement. The frameworks, scoring models, and workflow structures we deliver are architectural outputs; the data that subsequently flows through them belongs entirely to the client. Enterprise clients requiring a formal Data Processing Agreement covering incidental access during delivery should contact hello@renewmethod.co.uk.
14. Changes and contact
When this policy changes, the date at the top changes with it, and we will notify you of material changes by email where we hold your contact details. For any data protection query: Renew Marketing Ltd, Unit 20 Ptarmigan Place, Attleborough Fields Industrial Estate, Nuneaton, CV11 6RX · hello@renewmethod.co.uk · +44 (0)345 094 0993.