1. Who we are
Talent Journey Operations Limited (company number 15828503) operates the Talent Journey website, member platform and AI advisory services. Our registered office is 21 Navigation Business Village, Navigation Way, Ashton-on-Ribble, Preston, PR2 2YP.
For most processing described in this policy, Talent Journey Operations Limited is the independent controller. Where we process personal data solely on a customer’s documented instructions, the applicable customer data processing terms will apply.
Contact our Data Protection Lead at dpo@wearetalentjourney.com. We use this email address even though we may not be legally required to appoint a statutory Data Protection Officer.
2. Who this policy covers
- website visitors, prospective customers and people who contact us;
- customers, members, authorised users and people attending Talent Journey sessions or events;
- people who use our text-based or avatar-based AI advisory features;
- advisers, suppliers, partners and other business contacts; and
- people whose information is mentioned by a member or participant in an advisory session, upload, email or AI interaction.
Our services are intended for business users and are not directed at children.
3. Personal data we collect
| Category | Examples |
|---|---|
| Identity and business contact data | Name, role, employer, business address, email address, telephone number and company information. |
| Account and contract data | Login details, Named User status, package, agreement version, trial and conversion dates, acceptance records and communications. |
| Payment and billing data | Invoices, payment status, Direct Debit mandate information and transaction references. Full bank details are handled by our payment provider. |
| Website and device data | IP address, browser, device, pages viewed, security events, referral source and cookie or consent choices. |
| Advisory session data | Audio or video recordings where enabled, transcripts, notes, emails, uploaded documents and information discussed during sessions. |
| AI interaction data | Prompts, questions, chat history, voice or avatar interaction data, generated responses, feedback and safety or technical logs. |
| Usage and support data | Feature use, timestamps, error reports, support requests, quality feedback and account activity. |
| Incidental third-party data | Information about clients, candidates, employees, contractors, colleagues or other people mentioned by a user. |
We do not ask users to submit special-category data or criminal-offence data to the AI Advisory Features. Users must not submit that information unless we have expressly authorised it and the legal requirements have been addressed. If such information is received inadvertently, we will restrict, redact or delete it where reasonably practicable and will not intentionally add identifiable special-category data to the shared AI Knowledge Base.
4. How we obtain personal data
- directly from you when you contact us, sign up, attend sessions, use the platform or communicate with us;
- from your organisation or an authorised colleague;
- from advisers, session participants or customers who provide session materials or mention another person;
- from our website, platform, security tools and approved service providers; and
- from public business sources where lawful and relevant.
Where we receive personal data indirectly, we provide privacy information directly where required and reasonably practicable. Where an exemption applies, including where direct notice would involve disproportionate effort, we maintain this public policy and apply safeguards such as redaction, access controls, limited retention and anonymisation.
5. How and why we use personal data
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Provide the website, platform, account and contracted services | Identity, account, contract, AI interaction, session and support data | Performance of a contract or steps requested before entering a contract. |
| Set up and collect payments | Identity, contract, invoice and payment data | Contract performance and legal obligations. |
| Operate, secure and troubleshoot the services | Account, device, usage, security and limited content data | Legitimate interests in service security, fraud prevention, reliability and support. |
| Record and transcribe advisory sessions where enabled | Session recordings, transcripts and participant details | Contract performance and legitimate interests in delivering, documenting and improving the service. Appropriate notice is given. |
| Develop and maintain the AI Knowledge Base | Advisory session content and authorised materials | Legitimate interests in converting advisory expertise into a scalable service, subject to the safeguards and opt-out described below. |
| Provide AI text and avatar interactions | Prompts, voice, video, responses and account context | Contract performance. |
| Quality assurance, analytics and product development | Usage data, feedback and anonymised or aggregated insights | Legitimate interests in improving the service. Non-essential website technologies are used only with consent where required. |
| Communicate about services and relevant business content | Business contact and communication preferences | Legitimate interests or consent, and PECR where applicable. |
| Meet legal, regulatory and dispute-resolution requirements | Relevant account, financial, communications and incident data | Legal obligation and legitimate interests in establishing, exercising or defending legal rights. |
Where we rely on legitimate interests, we assess necessity and balance our interests against the rights and reasonable expectations of the people affected. Our AI knowledge-base assessment is documented in a Legitimate Interests Assessment.
6. AI processing and the AI Knowledge Base
6.1 Advisory content used to build the knowledge base
Authorised advisory recordings, transcripts, notes, emails and learning materials may be processed to identify and structure reusable advisory insights. Raw content may contain names or other identifying information and may be transmitted to approved technology providers before anonymisation or pseudonymisation is completed.
- Only approved business or API services may be used. Consumer AI accounts and unapproved interfaces must not be used for customer personal data.
- Live personal data is sent only to the minimum approved provider or providers necessary for the task. Parallel testing across multiple providers is limited to controlled evaluation using redacted, synthetic or specifically approved material.
- Knowledge-base entries are reviewed by an authorised person before being made available through the service.
- Identifiable customer or third-party information is not made available to other members. Shared insights must be effectively anonymised so that neither an individual nor the customer is identifiable by means reasonably likely to be used.
- We do not permit providers to use customer content to train general-purpose models for third-party use or to commercialise it for their own purposes.
6.2 AI advisory interactions
When a user submits a text prompt or interacts with an AI avatar, approved AI, speech, avatar and hosting providers process the information needed to produce the response. Live AI responses are not individually pre-approved by a human. They may be incomplete, inaccurate or out of date and are provided for general business guidance only. We do not use the AI Advisory Features to make solely automated decisions producing legal or similarly significant effects about individuals.
6.3 Opting out of knowledge-base use
A customer or member may object to or opt out of further use of their advisory session content for development of the shared AI Knowledge Base by emailing dpo@wearetalentjourney.com. The request applies prospectively as soon as reasonably practicable. It does not require removal of information already effectively anonymised, because that information is no longer personal data and cannot reasonably be linked back to the person or customer. Opting out will not remove access to the general service, but may reduce personalisation or features that depend on the customer’s own session history.
7. Sharing personal data
We share personal data only where necessary and under appropriate contractual, confidentiality and security arrangements. Recipients may include:
- hosting, database, cybersecurity and platform infrastructure providers;
- approved AI language-model, transcription, speech and avatar providers;
- technical development, systems-integration and support providers;
- payment, accounting, CRM, email, video-conferencing, e-signature and customer-support providers;
- professional advisers, insurers, auditors and prospective business transaction advisers; and
- regulators, courts, law-enforcement bodies or other recipients where required by law.
Further information about our recipient categories and individual suppliers is available from the Data Protection Lead where required by data protection law or an applicable customer contract. We do not sell personal data.
8. International transfers
Some approved providers process personal data outside the United Kingdom. Before making a restricted transfer, we use an applicable adequacy regulation or appropriate safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Where appropriate safeguards are used, we complete and maintain a transfer risk assessment, also referred to in current law as a data protection test. Additional technical and organisational measures are applied where necessary. To obtain further information or a copy of the relevant transfer safeguards, contact the Data Protection Lead at dpo@wearetalentjourney.com.
9. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, legal or regulatory requirements, security, and the establishment or defence of legal claims. Our detailed retention schedule governs the operational periods. Key periods are:
| Data | Typical retention |
|---|---|
| Account access and operational profile data | Active membership plus up to 90 days, unless needed for an unresolved issue. |
| Contracts, acceptance records and material customer correspondence | Six years after the contract ends. |
| Invoices and accounting records | Six years after the end of the relevant financial year, or longer if legally required. |
| Raw files submitted to the AI ingestion portal | Deleted from the active portal after processing, normally within 24 hours. Provider security or abuse-monitoring logs may persist for the period stated in the approved provider register, normally no more than 30 days unless a longer period is legally required. |
| Advisory recordings and identifiable transcripts | Normally 24 months after the session, subject to earlier deletion, legal holds or a justified customer-specific requirement. |
| AI interaction content | Normally 90 days for support and quality review, then deleted or anonymised. Limited security logs may be retained for up to 12 months. |
| Approved anonymised knowledge-base insights | For the life of the knowledge base. Effective anonymisation means they are no longer personal data. |
| Complaints, rights requests and breach records | Six years after closure. |
Deletion from active systems may not immediately remove data from encrypted backups or transient provider systems. Those copies are isolated from normal use and expire or are overwritten in line with documented backup and provider retention cycles.
10. Your rights
Contact dpo@wearetalentjourney.com to exercise your rights. Depending on the circumstances, these may include access, correction, erasure, restriction, portability, objection to processing based on legitimate interests, withdrawal of consent, and rights relating to automated decision-making.
We respond without undue delay and normally within one month after receiving a valid request and any information reasonably needed to verify identity. We may extend the period by up to two further months where the request is complex or numerous, and will explain the extension within the first month. Rights are subject to legal conditions and exemptions. Rights do not apply to information that has been effectively anonymised.
11. Security and personal data breaches
We use risk-appropriate technical and organisational measures, including encryption in transit, access controls, least-privilege permissions, authentication controls, secure development practices, logging designed to minimise sensitive content, supplier due diligence, incident response and staff confidentiality obligations.
We record and assess personal data breaches. Where a breach is likely to create a risk to people’s rights and freedoms, we notify the Information Commissioner’s Office as soon as possible and, where feasible, within 72 hours after becoming aware. Where the risk is high, we also inform affected individuals without undue delay.
12. Cookies and similar technologies
We use essential technologies needed for security, authentication and preference storage. We do not set non-essential analytics, functional or marketing technologies before obtaining consent, unless a specific legal exception applies. The current cookie-level list and preference controls are available through the cookie settings tool and our Cookie Notice at wearetalentjourney.com/cookies.
13. Data protection complaints
You may submit a data protection complaint by emailing dpo@wearetalentjourney.com or using the complaints form at wearetalentjourney.com/data-protection-complaints. We acknowledge complaints within 30 days, investigate appropriately, keep you informed where necessary and communicate the outcome without undue delay.
You may also complain to the Information Commissioner’s Office. Details are available at ico.org.uk or by telephone on 0303 123 1113. We would normally appreciate the opportunity to address the concern first.
14. Changes to this policy
We review this policy regularly and when our processing, suppliers, services or the law change. We will notify customers of material changes through an appropriate channel. The current version is published at wearetalentjourney.com/privacy-policy.