Contract Sharp Privacy Policy

Last updated: Sept 2025

This privacy notice explains how Contract Sharp collects, uses, stores, and protects your personal information. It also explains your rights under UK data protection law.

1. Contact Details

2. What Information We Collect and Why

We collect personal information to provide, manage, and improve our services and customer experience.

a) To provide and improve services:

  • Names, contact details, and addresses

  • Occupation and professional details

  • Third-party information relevant to contracts

  • Contract information, company operations, and related documents

  • Payment details (card, bank transfer, or direct debit)

  • Financial and transaction data (products/services purchased, expenditures)

  • Usage data (how you interact with our website and services)

b) For client account operation:

  • Account information, login credentials, and registration details

  • Purchase/service history and billing data

  • Security and technical data (browser, device, IP address)

  • Marketing preferences

c) For updates or marketing:

  • Names, contact details, addresses, and profile information

  • Purchase/account history

  • Website and app usage data

  • IP addresses

d) For research or archiving purposes:

  • Names, contact details, addresses

  • Purchase/client account history

  • Website and app usage data

  • IP addresses

  • Data is anonymised or aggregated whenever possible

e) To comply with legal requirements:

  • Name, contact information, client account details

  • Any other personal information required by law

f) For queries, complaints, or claims:

  • Names, contact details, addresses

  • Payment, account, and transaction information

  • Correspondence and client records

3. Lawful Bases for Processing

  • Necessary to deliver services, operate accounts, and handle queries/complaints.

  • To improve services, provide insights, communicate updates, and support client needs. We limit impact, apply safeguards, and do not use data beyond expected business purposes.

  • For marketing communications and updates not strictly necessary for service delivery. Consent can be withdrawn at any time.

  • To comply with UK law.

Details of legitimate interests processing:

  • Processing client contract info (names, roles, business contacts) to provide actionable insights and recommendations.

  • Operating client accounts securely, issuing invoices, and managing subscriptions.

  • Sending service updates and relevant legal/regulatory information.

  • Anonymised data analysis to enhance features, identify trends, and improve service.

  • Handling queries, complaints, or claims efficiently.

4. Payment Processing

  • Masterclasses/training: Processed via Koalendar Stripe. Contract Sharp does not store your card details. You agree to Koalendar and Stripe’s terms.

  • Support Services: Payments may be made via direct UK bank transfer or Stripe. Only transaction references are retained.

  • Digital material: Payments are processed via Gumroad. Contract Sharp does not store your card details. You agree to Gumroad’s terms.

  • Data is used solely for service provision, invoicing, and legal compliance.

5. Data Storage and Security

  • Data is stored securely with encryption and access controls.

  • Only authorised personnel can access personal information.

  • Retention periods are defined and aligned with legal and contractual requirements.

6. Data Sharing

We share personal data only with:

  • Authorised service providers and processors (e.g., Koalendar, Stripe)

  • Professional/legal advisors

  • Organisations we are legally obliged to share information with

  • Other third parties only with your explicit consent

We do not share personal information publicly or for marketing without consent.

7. Data Retention

  • Personal information is retained only as long as necessary to deliver services, comply with legal obligations, or manage contracts/accounts.

  • After service completion or contract termination, client data is securely deleted within 30 days.

  • Retention schedules are maintained internally and accessible only to authorised staff.

8. Your Rights

Under UK data protection law, you have the right to:

  • Access your personal information and request details of its use

  • Correct or update inaccurate information

  • Request deletion of personal information

  • Restrict or object to processing

  • Request data portability

  • Withdraw consent where processing relies on consent

Requests will be responded to without undue delay and within 1 month.

9. Sources of Personal Information

  • Directly from you

  • Market research providers

  • Marketing lists/providers

  • Suppliers and authorised service providers

10. Complaints

  • Raise concerns directly with Contract Sharp using contact details above.

  • If unresolved, complaints can be submitted to the ICO: