Legal
How your personal information is collected, used, and protected.
Last updated: 3 August 2026
This Privacy Policy explains how personal information is collected, used, shared and protected when someone visits the website, makes an enquiry, books a service, joins a programme, or purchases a product. It also explains the rights that individuals have under UK data protection law.
Data controller: Raj Holness, trading as Empower Beyond Coaching and Empower Beyond, is the data controller for the personal information described in this policy.
Empower Beyond Coaching is the trading name of Raj Holness, who provides trauma-informed coaching, group programmes, speaking and training. For the purposes of UK data protection law, Raj Holness is the data controller.
Contact email: info@rajholness.co.uk
Website: www.rajholness.co.uk
If you enquire or book a consultation, we may collect your name, the name you would like to be called, your email address, a phone number if you give one, what your enquiry is about, anything you choose to tell us in your message, and the date and time of any consultation you book.
If you become a coaching client or join a group programme, we may collect application answers, an emergency contact name and number, notes made during and after sessions, payment records, and correspondence between us.
If you book a speaking or training engagement for an organisation, we may collect your name, role, organisation, contact details, what you need, your audience and your objectives, and invoicing records.
If you use a form on this site, the information collected depends on the form and its purpose.
If you buy a book, journal or affirmation cards, payment and order information may be handled by the relevant payment or selling platform, and we receive only what is needed to fulfil the order or administer the purchase.
Personal information is used to answer enquiries, arrange consultations, assess suitability, deliver coaching or group programmes, fulfil speaking and training bookings, process purchases, keep appropriate records, and meet legal, insurance, safeguarding or administrative requirements.
The lawful bases relied upon may include legitimate interests, performance of a contract, steps taken at your request before entering a contract, compliance with legal obligations, vital interests, and consent where appropriate. For example: answering your enquiry and arranging a consultation relies on legitimate interests; deciding whether a programme is right for you and delivering coaching relies on performance of a contract or steps taken at your request; keeping session notes relies on legitimate interests, and where notes contain sensitive information, explicit consent; and acting on a serious concern for someone's safety relies on vital interests and the safeguarding condition in the Data Protection Act 2018.
Some information shared may be what the law calls special category data. This can include information about health or mental health, religious or philosophical beliefs where faith is part of the work, and anything shared about abuse or harm that has been experienced.
This information is treated with particular care and is collected only where necessary to work safely and appropriately. The basis for holding it is normally explicit consent, unless a safeguarding or vital-interests exception applies.
You may withdraw consent at any time, and we will explain what that means for the work being provided.
What is shared is treated as confidential. In group programmes, participants are asked to respect each other's privacy and keep what is said in the room private.
Absolute confidentiality can never be promised. If there is serious concern for your safety, or the safety of a child or another person, action may need to be taken in line with professional and safeguarding responsibilities. Information may also need to be disclosed where the law requires it, for example in response to a court order.
If you join a group programme, an emergency contact may be requested. This information is held securely and used only in a genuine emergency. The emergency contact will not be told the content of the programme or what you have shared.
Personal information is not sold and is not shared for advertising. A small number of trusted providers are used to run the practice and website, and they process information on appropriate terms.
Depending on the service used, providers may include website hosting, TidyCal for consultation bookings, Microsoft Teams for online sessions, PayPal and Payhip for payments, Google Forms for forms, and other reputable services required to operate the business.
Information may also be shared with emergency or safeguarding services where necessary, and with professional insurers, supervisors or advisers where proportionate and appropriate.
Some service providers may be based outside the United Kingdom, including in the United States. Where information is transferred outside the UK, recognised safeguards are relied upon, such as UK adequacy regulations or standard contractual clauses with appropriate protections.
Information is kept only for as long as it is needed and then deleted or securely destroyed.
Typical retention periods are: enquiries that do not become work, 12 months from the last contact; client records and session notes, 7 years after the work ends; applications from people not accepted onto a programme, 6 months; emergency contact details, deleted when the programme ends, unless there is a lawful reason to retain them longer.
Access is limited to Raj Holness and, where necessary, trusted providers acting under appropriate obligations.
Devices and accounts are protected by strong passwords and two-factor authentication where available. Sensitive records are stored separately from general contact details. Session notes avoid unnecessary detail, and paper notes, if any, are kept locked and are not removed from a secure location.
No system is completely secure. If something goes wrong and information is put at risk, the Information Commissioner's Office will be notified where the law requires, and affected individuals will be told where appropriate.
Under UK data protection law you have the right to ask what information is held about you and receive a copy, have inaccurate information corrected, ask for information to be deleted or restricted in some circumstances, object where legitimate interests are relied upon, receive information you gave in a portable format in some circumstances, and withdraw consent at any time where consent is relied upon.
Some rights have limits. For example, records may need to be retained for safeguarding, insurance or tax reasons. If that applies, the reason will be explained.
To exercise your rights, email info@rajholness.co.uk. We aim to respond within one month.
This website does not use cookies for analytics, advertising or tracking. It does not profile visitors and does not follow people around the internet.
The site may load typefaces from Google Fonts and may link to third-party platforms such as TidyCal or Google Forms. When your browser loads those assets or you follow those links, your IP address may be visible to that company and their own privacy policy will apply.
Services are intended for adults. Personal information about anyone under 18 is not knowingly collected through this website unless a specific service or safeguarding arrangement states otherwise.
This policy may be updated from time to time. The date at the top of the document shows when it was last changed. If a change materially affects how information is used, reasonable steps will be taken to make that clear.
If you have a question, or you are unhappy with how your information has been handled, please contact info@rajholness.co.uk first. We would rather hear the concern and try to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk or by telephone on 0303 123 1113.
As a Senior Fellow of the ACCPH, complaints about professional practice may also be raised with their organisation where relevant.