GDPR Data Protection

    Privacy Policy

    Your privacy and trust are paramount. Learn how Sustainable Performance Leaders and Reclaim Your Control safeguard your personal data in full compliance with GDPR.

    Effective Date: August 2026 | General Data Protection Regulation (EU 2016/679)

    1. Data Controller & Organization

    Under the EU General Data Protection Regulation (GDPR), the Data Controller responsible for processing your personal data across this website and associated executive services is:

    Brand Operating Names: Sustainable Performance Leaders™ & Reclaim Your Control™

    Founder & Executive Leader: Ellen Duffy-Lueb

    Official Website: sustainableperformanceleaders.com

    Privacy Enquiries Email: ellen@sustainableperformanceleaders.com

    2. Our Core GDPR Principles

    We adhere strictly to the core data protection principles set out in Article 5 of the GDPR:

    Lawful & Fair

    Data is processed lawfully, fairly, and transparently.

    Purpose Limitation

    Collected strictly for specific, explicit, legitimate purpose.

    Data Minimization

    We collect only data necessary for our executive services.

    3. Personal Data Collected & Legal Basis

    We collect personal information depending on how you interact with our platform:

    A. Leadership Effectiveness Score™ Diagnostic

    Data Collected: First Name, Last Name, Work Email, Company Name, Job Title, Company Size, Country, and Assessment Benchmark Answers.

    Legal Basis (GDPR Art. 6(1)(a) & (f)): Consent provided when requesting your executive score, and legitimate interest in providing tailored organizational recommendations and follow-up consultation.

    B. Calendar Bookings & Strategy Sessions

    Data Collected: Name, Email, Phone Number, Organization Name, Selected Session Type (Discovery Call, Corporate Strategy, Keynote Booking), and Booking Notes.

    Legal Basis (GDPR Art. 6(1)(b)): Necessary for taking pre-contractual steps at your request to schedule and deliver your consultation.

    C. Workshop & Program Registrations

    Data Collected: Contact details, billing address, tier selection (Standard, Plus, Team Package), corporate invoicing information.

    Legal Basis (GDPR Art. 6(1)(b) & (c)): Contractual performance and compliance with statutory financial and tax record-keeping obligations.

    4. CRM Integration & Data Storage

    To streamline our corporate communications, schedule strategy sessions, and deliver diagnostic reports, we utilize secure, encrypted Customer Relationship Management (CRM) tracking tools.

    • Data Tags: Contact profiles may be assigned administrative tags (e.g., High Performing Leadership, Leadership Risk, Corporate Opportunity) based on assessment outcomes to tailor subsequent executive insights.
    • Security Measures: Data transmission occurs via encrypted TLS endpoints. Server architecture enforces strict role-based access control.
    • Third-Party Vendors: We work only with compliant sub-processors adhering to Standard Contractual Clauses (SCCs) or GDPR adequacy frameworks.

    5. Your Individual Rights Under GDPR

    As a resident of the European Union or European Economic Area, you possess the following enforceable data subject rights under GDPR Chapter III:

    Right of Access (Art. 15): Request a copy of all personal data held about you.
    Right to Rectification (Art. 16): Correct inaccurate or incomplete records.
    Right to Erasure (“Right to be Forgotten” - Art. 17): Request deletion of your data.
    Right to Restrict Processing (Art. 18): Pause processing under specific conditions.
    Right to Data Portability (Art. 20): Receive your data in a structured CSV format.
    Right to Object (Art. 21): Object to processing for direct marketing at any time.

    To exercise any of these rights, please submit a request through our contact page. We respond to all verified data requests within 30 calendar days without charge.

    6. Data Retention Policy

    We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

    • Assessment & Lead Data: Retained for 24 months from last interaction unless consent is withdrawn earlier.
    • Program & Billing Records: Retained for 7 years to comply with statutory accounting and tax obligations.
    • Calendar Bookings: Retained for 12 months post-session for follow-up advisory continuity.

    7. Cookies & Local Storage

    Our application uses essential technical cookies and local storage state (e.g. saving your Leadership Effectiveness Score™ section progress while you complete the diagnostic). We do not deploy invasive third-party cross-site advertising cookies.

    8. Supervisory Authority Complaints

    If you believe our processing of your personal data infringes GDPR regulations, you have the right to lodge a formal complaint with a European Data Protection Supervisory Authority (for example, the Autoriteit Persoonsgegevens in the Netherlands or your local national data protection authority).

    Exercise Your Data Rights

    Submit a GDPR access, correction, or erasure request directly to our team.