PRIVACY POLICY
Last updated: March 2026
This policy applies to: https://www.pollyrusyn.com
Your privacy matters to me. This policy explains what personal information I collect, why I collect it, how I use it, and what your rights are. I've done my best to write this in plain English rather than legal jargon — because that's more useful to both of us.
This policy is compliant with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The data controller is Polly Rusyn, trading as Polly Rusyn Coaching, based in the United Kingdom.
1. Who I Am
Polly Rusyn Coaching
Email: [email protected]
Website: https://www.pollyrusyn.com
Location: United Kingdom
If you have any questions about this policy or how your data is handled, please get in touch — I'm always happy to chat.
2. What Information I Collect
I only collect information that's genuinely needed to provide my services or to communicate with you. Here's what that looks like in practice:
Information you give me directly
- Your name and email address when you sign up to my mailing list
- Your name, email, and any details you share when you fill in a contact form or Google Form
- Booking details (name, email, sometimes a phone number) when you book a session via my scheduling system
- Any information you choose to share with me via social media direct messages
- Payment information — note: I don't store your card details. These are handled securely by my payment processor
Information collected automatically
- Website usage data via analytics tools (such as Google Analytics), including pages visited, time on site, and general location data (country/region level). This is anonymised and aggregated.
- Cookies — see Section 8 for more on this
Sensitive information
In the context of coaching and counselling work, you may choose to share personal or sensitive information with me during sessions or in written communications. This is handled with the utmost care, confidentiality, and in line with my professional ethical obligations. I do not store session content in any shared or cloud-based system without your knowledge.
3. Why I Collect It & My Lawful Basis
Under UK GDPR, I need a lawful reason to process your personal data. Here's how that maps to what I do:
- Contractual necessity — to deliver a course or coaching service you've purchased, process your booking, or send you what you've signed up for.
- Legitimate interests — to respond to enquiries, improve my website and services, and communicate with existing clients.
- Consent — to send you marketing emails or newsletters. You can withdraw this consent at any time (see Section 6).
- Legal obligation — to retain certain records as required by law (e.g. financial records).
4. How I Use Your Information
I use your information to:
- Deliver digital courses and coaching services you've purchased
- Send you course access details, session confirmations, and relevant follow-ups
- Respond to your enquiries and messages
- Send email newsletters or updates (only if you've opted in)
- Improve my website and understand how people are finding and using it
- Meet my legal and financial record-keeping obligations
I will never sell your data, and I will never pass it on to third parties for their own marketing purposes.
5. Third Parties I Work With
To run my business, I use a small number of trusted third-party platforms. Each has their own privacy policy and data protection measures in place:
- Email marketing platform (Kajabi / Substack) — stores your name and email if you've opted in to my list. You can unsubscribe at any time via the link in any email.
- Course & payment platform (Kajabi / Stripe) — processes purchases and stores your account and order details.
- Booking system (zCal) — stores your name, email, and booking details.
- Google (Forms & Analytics) — Google Forms collects responses you submit; Google Analytics collects anonymised website usage data.
- Video conferencing (Zoom / Kajabi / Google Meet) — used for coaching and counselling sessions. Session recordings are only ever made with your explicit consent, and I don't typically record sessions.
All third-party platforms I use are either UK/EU GDPR compliant or have appropriate data transfer safeguards in place.
6. Your Rights Under UK GDPR
You have the following rights regarding your personal data, and I take them seriously:
- Right to access — you can ask me what personal data I hold about you.
- Right to rectification — you can ask me to correct inaccurate data.
- Right to erasure — you can ask me to delete your data ('the right to be forgotten'), subject to any legal obligations I have to retain records.
- Right to restrict processing — you can ask me to pause how I use your data in certain circumstances.
- Right to data portability — you can request your data in a commonly used, machine-readable format.
- Right to object — you can object to me processing your data on the basis of legitimate interests, or for direct marketing purposes.
- Right to withdraw consent — if you've opted in to emails, you can unsubscribe at any time via the link in any email, or by contacting me directly.
To exercise any of these rights, please email me at [email protected]. I'll respond within 30 days.
If you're not happy with how I've handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7. How Long I Keep Your Data
- Client records (coaching / counselling) — retained for 7 years after our work together ends, in line with professional practice guidelines.
- Financial and purchase records — retained for 6 years in line with HMRC requirements.
- Email marketing list — held until you unsubscribe or ask to be removed.
- Enquiry and contact form data — held for up to 2 years, or longer if it leads to an ongoing client relationship.
- Website analytics data — retained in accordance with Google Analytics' own data retention settings (typically 26 months).
When data is no longer needed, I delete it securely.
8. Cookies
My website uses cookies — small text files stored on your device — to help the site function and to understand how people use it.
Types of cookies I use
- Essential cookies — necessary for the website to work (e.g. remembering your login on Kajabi).
- Analytics cookies — Google Analytics uses cookies to collect anonymised data about how visitors use the site. No personally identifiable information is collected through these cookies.
You can manage or disable cookies through your browser settings at any time. Disabling analytics cookies won't affect your ability to use the site.
9. Data Security
I take reasonable steps to protect your personal information. This includes using password-protected systems, secure platforms, and limiting access to data to only what's necessary.
No method of transmission over the internet is 100% secure, but I do my best to protect your information and will notify you promptly if I become aware of any data breach that affects you.
10. Children's Privacy
My services are intended for adults (18+). I do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided me with their data, please get in touch and I will delete it promptly.
11. Changes to This Policy
I may update this privacy policy from time to time — for example, if I start using a new platform or if the law changes. Any updates will be posted on this page with a revised date at the top. If changes are significant, I'll do my best to let you know directly.
12. Get in Touch
If you have any questions, concerns, or requests relating to your data or this policy, please don't hesitate to reach out. I'm a real human and I'll always respond personally.
Email: [email protected]
Website: https://www.pollyrusyn.com
Thanks for reading.