Who We Are
The data controller responsible for your personal data is:
Greatness Academy Ltd (Company Number: 16062394), trading as Professional Performance System™
Registered Office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ
We are registered as a data controller with the Information Commissioner's Office (ICO). Our ICO registration number is [ICO Registration Number — to be inserted before deployment].
For all data protection queries, please contact us at: support@ppsprotocol.com
We have assessed our processing activities and determined that, at this time, the appointment of a Data Protection Officer (DPO) is not mandatory under Article 37 UK GDPR. We will keep this assessment under review.
The Personal Data We Collect
We collect and process personal data from the following categories of data subjects: website visitors, PPS Index™ users, programme participants, email subscribers, and prospective customers.
2.1 Data You Provide DirectlyIdentity Data: First name, last name, professional title, organisation name.
Contact Data: Email address, postal address, telephone number.
Professional Data: Job role, professional sector, years of experience, description of professional responsibilities and performance challenges, organisational context, and other professional information you provide in connection with our Services.
Programme Data: Responses to the PPS Index™ diagnostic instrument; domain profile results across the five PPS domains (Governed Source, State Architecture, Attentional Governance, Standardised Execution, Evidence-Based Realignment); profile classification; programme participation records (PPS Performance Audit, Governed Standard Protocol, Governance Intensive); session notes and practitioner records; deliverable documents produced during programme delivery; Alignment Action Report submissions; Constraint Bank records; and any other information you share in the course of receiving our Services.
Financial Data: Payment card details (processed by our third-party payment processor — we do not store card data), billing address, and transaction history.
Communications Data: Records of your correspondence with us, including emails and messages sent through our Platform.
Preferences Data: Your preferences in relation to receiving marketing communications.
Technical Data: IP address, browser type and version, time zone and location, operating system and platform, and other technology on devices you use to access our Services.
Usage Data: Information about how you use our Website and Platform, including pages visited, links clicked, time spent, and navigation patterns.
Cookie Data: Data collected through cookies and similar tracking technologies, as described in our Cookie Policy (Section 11).
Platform Data: Data from third-party platforms we use to deliver our Services (including Ghost, Loops, Stripe, and Vercel), to the extent such data is shared with us in accordance with those platforms' terms and privacy policies.
Referral Data: Where you have been referred to us by a third party, we may receive your name and contact details from that referrer.
How We Use Your Personal Data — Lawful Bases
3.1 Performance of a ContractWe process personal data where processing is necessary for the performance of a contract to which you are a party. This includes: delivering the PPS Performance Audit, Governed Standard Protocol, and Governance Intensive; processing payment; administering your account; providing access to our Platform and Content; and responding to your enquiries.
3.2 Legitimate InterestsWe process personal data where processing is necessary for the purposes of our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include: operating and improving our Services; understanding usage patterns to improve programme outcomes; preventing fraud; maintaining quality assurance records; pursuing and defending legal claims; and communicating information about our Services to existing customers and warm prospects (subject to your right to opt out). Where we rely on legitimate interests, we conduct a Legitimate Interests Assessment (LIA). Summaries are available on request.
3.3 ConsentWe rely on your freely given, specific, informed, and unambiguous consent for: sending marketing communications to individuals who are not existing customers; setting non-essential cookies; and processing special category data where applicable (see Section 3.5). You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3.4 Compliance With a Legal ObligationWe process personal data where necessary to comply with our legal obligations, including maintaining financial and accounting records and responding to lawful requests from law enforcement or regulatory authorities.
3.5 Special Category DataProgramme Data collected in the course of our Services may, in some cases, include information that falls within the definition of special category data under UK GDPR (Article 9). Professionals participating in our programmes may voluntarily share information relating to religious or philosophical beliefs, professional identity, or personal values in the context of programme sessions or self-assessment.
Where we process special category data, we do so on the basis of your explicit consent under Article 9(2)(a) UK GDPR. You are never required to share special category data with us. Where you choose to do so, explicit consent is obtained through a specific consent acknowledgement presented at the relevant point in the programme, expressly identifying the categories of data and the purpose of processing.
You may withdraw your consent at any time by contacting support@ppsprotocol.com.
We implement additional safeguards for special category data, including: restricted access limited to the delivering practitioner and essential administrative personnel; enhanced confidentiality obligations; secure encrypted storage; separate retention tracking; and audit logging of access.
Purposes for Which We Use Your Personal Data
| Purpose | Data Categories | Lawful Basis |
|---|---|---|
| Delivering programme Services to participants | Identity, Contact, Professional, Programme, Financial | Contract |
| Processing payment and managing billing | Identity, Contact, Financial | Contract |
| Administering your account and Platform access | Identity, Contact, Technical | Contract |
| Responding to enquiries and pre-sales communications | Identity, Contact, Communications | Legitimate Interests / Pre-contract |
| Sending service and operational communications | Identity, Contact, Preferences | Contract / Legitimate Interests |
| Sending marketing communications to existing customers | Identity, Contact, Preferences | Legitimate Interests (with opt-out) |
| Sending marketing communications to new prospects | Identity, Contact, Preferences | Consent |
| Delivering the PPS Weekly Letter newsletter | Identity, Contact, Preferences | Consent |
| Improving our Services and understanding usage patterns | Technical, Usage, Cookie | Legitimate Interests |
| Maintaining quality assurance and programme records | Programme, Communications | Contract / Legitimate Interests |
| Preventing fraud and ensuring system security | Technical, Usage | Legitimate Interests |
| Complying with legal obligations | All categories as required | Legal Obligation |
| Processing special category data shared in programme sessions | Programme (special category) | Explicit Consent |
Marketing Communications
We may send you information about our Services, new programmes, and relevant performance content by email and other electronic channels.
We may send you marketing communications on the basis of the PECR soft opt-in and our legitimate interests, subject to all of the following conditions being met: (i) your email address was collected in the course of a sale or negotiations for a sale of our Services; (ii) the marketing relates to our own similar products and services; (iii) we provided you with a clear opportunity to opt out at the point we collected your email address; and (iv) we provide a clear and simple opt-out mechanism in every subsequent marketing communication. You may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting support@ppsprotocol.com. Opt-out requests are processed within 5 business days.
Where you have not previously purchased from us, we will only send you marketing communications with your consent, obtained at the time you complete the PPS Index™ or sign up to receive communications from us.
Where you have completed the PPS Index™, our email communications may be personalised based on your domain profile and programme routing. This personalisation is based on your voluntary completion of the Index and does not involve automated decision-making with legal or similarly significant effects.
We will never sell your personal data to third parties for their marketing purposes.
Automated Decision-Making and Profiling
The PPS Index™ uses an automated scoring algorithm to generate domain profiles and programme routing recommendations. We consider that this processing does not constitute automated decision-making with legal or similarly significant effects within the meaning of Article 22 UK GDPR, because: (a) the outputs are advisory and indicative tools, not binding determinations; (b) all programme routing recommendations are subject to human review; and (c) no individual is denied access to a Service solely on the basis of a PPS Index™ output.
You have the right to request human review of any PPS Index™ output that you consider inaccurate or unfair, by contacting us at support@ppsprotocol.com.
We use email platform segmentation tools (Loops) to tag subscribers by domain profile and send profile-personalised email sequences. This constitutes basic profiling for communications personalisation. We rely on legitimate interests for existing customers and on consent for new prospects. You may opt out of personalised communications at any time.
Data Sharing and Third-Party Processors
We do not sell, rent, or trade your personal data to third parties.
We engage third-party service providers who process personal data on our behalf as data processors under Article 28 UK GDPR data processing agreements:
| Category | Provider(s) | Purpose | Data Processed |
|---|---|---|---|
| Website & Portal Hosting | Vercel | Website and programme portal delivery | Technical, Usage |
| Newsletter & Blog Publishing | Ghost | Newsletter delivery and content publishing | Identity, Contact, Usage |
| Email Marketing & Automation | Loops | Email communications, sequences, and segmentation | Identity, Contact, Preferences, Programme |
| Payment Processing | Stripe | Payment processing and subscription management | Identity, Contact, Financial |
| Analytics | [Provider — to be confirmed before deployment] | Website analytics | Technical, Usage, Cookie |
We may disclose personal data to law enforcement agencies, regulatory authorities, courts, or other third parties where we are legally required to do so, or where we believe in good faith that such disclosure is necessary to prevent crime or comply with a legal obligation.
In the event of a merger, acquisition, or sale of all or substantially all of our business assets, personal data held by us may be transferred to the relevant third party. We will notify you of any such transfer where required by applicable law.
International Data Transfers
Some of our third-party processors may process personal data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR Chapter V and the International Data Transfer Agreement (IDTA) framework or equivalent mechanisms approved by the Secretary of State.
Transfers to countries that benefit from UK adequacy regulations are permitted without further safeguards. Transfers to other countries are made subject to IDTAs, Standard Contractual Clauses (SCCs) adapted for UK compliance, or other lawful transfer mechanisms. Details of specific transfer mechanisms applicable to each processor are available on request by contacting support@ppsprotocol.com.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in any event for no longer than required by applicable law.
| Data Category | Retention Period | Rationale |
|---|---|---|
| Client programme records (Governance Intensive) | 7 years from end of programme | Quality assurance; potential legal claims |
| Programme participant data (PPS Performance Audit, GSP — active) | Duration of programme access plus 2 years | Contract administration; re-engagement |
| Programme participant data (post-completion) | 2 years from programme completion | Legitimate interests; legal claims |
| Financial records | 7 years from end of relevant tax year | Legal obligation (HMRC requirements) |
| Marketing data (opted-out) | Suppression list maintained indefinitely | Prevention of re-contact |
| PPS Index™ responses and profile data | 3 years from completion | Quality assurance; programme improvement |
| Newsletter subscriber data (active) | Duration of subscription | Contract / Consent |
| Newsletter subscriber data (unsubscribed) | Suppression list maintained indefinitely | Prevention of re-contact |
| Website analytics data | 26 months | ICO guidance for analytics data |
| Enquiry / pre-sales data | 2 years from last contact | Legitimate interests |
| Legal claim records | 7 years from resolution of claim | Limitation periods under Limitation Act 1980 |
Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
Contact us at support@ppsprotocol.com. We may verify your identity before processing your request. No fee will be charged unless your request is manifestly unfounded or excessive.
Right to Complain: You have the right to lodge a complaint with the Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Tel: 0303 123 1113. www.ico.org.uk. We would appreciate the opportunity to address your concerns before you contact the ICO.
Cookie Policy
11.1 What Are Cookies?Cookies are small text files placed on your device when you visit our Website. Similar technologies include web beacons, local storage, and session storage. References to “cookies” include all such similar technologies unless otherwise specified.
11.2 How We Use Cookies 11.3 Your Cookie ChoicesWhen you first visit our Website, you will be presented with a cookie consent banner allowing you to accept or decline non-essential cookies. You may change your cookie preferences at any time by clicking Manage Cookie Preferences in the footer of our Website. You may also control cookies through your browser settings.
11.4 Cookie Consent RecordsWe maintain records of cookie consents given through our consent management tool, including the date and time of consent, the categories of cookies consented to, and the version of the cookie policy in force at the time. These records are retained for 3 years as evidence of compliance.
AI Systems and Automated Data Collection
We do not make our Content, frameworks, diagnostic instruments, programme architecture, or any other materials available for use as training data, fine-tuning data, or any other input for artificial intelligence systems, large language models, or machine learning models.
Automated scraping, crawling, and systematic extraction of our Website, Platform, or Content is prohibited. We publish robots.txt directives restricting AI crawlers and data harvesting tools. All automated systems are required to comply with these directives.
To the extent that any automated system collects personal data about our users or visitors in contravention of our terms and robots.txt directives, such collection is unauthorised and unlawful. We reserve the right to pursue all available remedies against operators of non-compliant automated systems.
Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include: encryption of personal data in transit and at rest where technically feasible; access controls limiting access to authorised personnel on a need-to-know basis; confidentiality obligations on all staff, contractors, and processors; regular review of our security practices; and secure deletion and disposal protocols.
Programme session content and participant records are treated with enhanced confidentiality. Access to programme records and deliverables is restricted to the relevant practitioner and administrative personnel directly responsible for programme delivery.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware in accordance with Article 33 UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with Article 34 UK GDPR.
Children's Privacy
Our Services are directed at adults and are not intended for individuals under the age of 18. We do not knowingly collect personal data from individuals under 18.
If you believe we have inadvertently collected personal data from a child under 18, please contact us at support@ppsprotocol.com and we will take immediate steps to delete such data.
Changes to This Privacy Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance.
We will notify existing programme participants and newsletter subscribers of material changes by email with reasonable notice before the changes take effect. We will also update the Last Updated date at the top of this Policy.
Your continued use of our Services after any changes take effect constitutes your acceptance of the revised Policy, subject to any consent requirements for new processing activities.
International Users
While our primary operations are in the United Kingdom, we receive enquiries and clients from international jurisdictions. We are committed to processing personal data of all individuals in accordance with the standards set out in UK GDPR and this Privacy Policy, regardless of where the individual is located.
Where we process personal data of individuals in the European Economic Area in connection with the offering of goods or services, we comply with EU GDPR in addition to UK GDPR where applicable. We rely on appropriate transfer mechanisms for any onward transfers of EEA data.
Where local data protection law imposes requirements beyond those set out in this Privacy Policy, we will comply with such requirements to the extent applicable. If you have questions about how your personal data is handled under the laws of your jurisdiction, please contact us.
Contact Us and Complaints
Email: support@ppsprotocol.com
We will acknowledge your communication within 5 business days and provide a substantive response within one calendar month, or notify you if additional time is required.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
www.ico.org.uk/make-a-complaint
We would appreciate the opportunity to address your concerns before you contact the ICO.