Privacy Policy
Your privacy and trust are paramount. Learn how Sustainable Performance Leaders and Reclaim Your Control safeguard your personal data in full compliance with GDPR.
Effective Date: August 2026 | General Data Protection Regulation (EU 2016/679)
1. Data Controller & Organization
Under the EU General Data Protection Regulation (GDPR), the Data Controller responsible for processing your personal data across this website and associated executive services is:
Brand Operating Names: Sustainable Performance Leaders™ & Reclaim Your Control™
Founder & Executive Leader: Ellen Duffy-Lueb
Official Website: sustainableperformanceleaders.com
Privacy Enquiries Email: ellen@sustainableperformanceleaders.com
2. Our Core GDPR Principles
We adhere strictly to the core data protection principles set out in Article 5 of the GDPR:
Lawful & Fair
Data is processed lawfully, fairly, and transparently.
Purpose Limitation
Collected strictly for specific, explicit, legitimate purpose.
Data Minimization
We collect only data necessary for our executive services.
3. Personal Data Collected & Legal Basis
We collect personal information depending on how you interact with our platform:
A. Leadership Effectiveness Score™ Diagnostic
Data Collected: First Name, Last Name, Work Email, Company Name, Job Title, Company Size, Country, and Assessment Benchmark Answers.
Legal Basis (GDPR Art. 6(1)(a) & (f)): Consent provided when requesting your executive score, and legitimate interest in providing tailored organizational recommendations and follow-up consultation.
B. Calendar Bookings & Strategy Sessions
Data Collected: Name, Email, Phone Number, Organization Name, Selected Session Type (Discovery Call, Corporate Strategy, Keynote Booking), and Booking Notes.
Legal Basis (GDPR Art. 6(1)(b)): Necessary for taking pre-contractual steps at your request to schedule and deliver your consultation.
C. Workshop & Program Registrations
Data Collected: Contact details, billing address, tier selection (Standard, Plus, Team Package), corporate invoicing information.
Legal Basis (GDPR Art. 6(1)(b) & (c)): Contractual performance and compliance with statutory financial and tax record-keeping obligations.
4. CRM Integration & Data Storage
To streamline our corporate communications, schedule strategy sessions, and deliver diagnostic reports, we utilize secure, encrypted Customer Relationship Management (CRM) tracking tools.
- Data Tags: Contact profiles may be assigned administrative tags (e.g., High Performing Leadership, Leadership Risk, Corporate Opportunity) based on assessment outcomes to tailor subsequent executive insights.
- Security Measures: Data transmission occurs via encrypted TLS endpoints. Server architecture enforces strict role-based access control.
- Third-Party Vendors: We work only with compliant sub-processors adhering to Standard Contractual Clauses (SCCs) or GDPR adequacy frameworks.
5. Your Individual Rights Under GDPR
As a resident of the European Union or European Economic Area, you possess the following enforceable data subject rights under GDPR Chapter III:
To exercise any of these rights, please submit a request through our contact page. We respond to all verified data requests within 30 calendar days without charge.
6. Data Retention Policy
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Assessment & Lead Data: Retained for 24 months from last interaction unless consent is withdrawn earlier.
- Program & Billing Records: Retained for 7 years to comply with statutory accounting and tax obligations.
- Calendar Bookings: Retained for 12 months post-session for follow-up advisory continuity.
7. Cookies & Local Storage
Our application uses essential technical cookies and local storage state (e.g. saving your Leadership Effectiveness Score™ section progress while you complete the diagnostic). We do not deploy invasive third-party cross-site advertising cookies.
8. Supervisory Authority Complaints
If you believe our processing of your personal data infringes GDPR regulations, you have the right to lodge a formal complaint with a European Data Protection Supervisory Authority (for example, the Autoriteit Persoonsgegevens in the Netherlands or your local national data protection authority).
Exercise Your Data Rights
Submit a GDPR access, correction, or erasure request directly to our team.