Privacy Policy

This Privacy Policy explains how Executive Grapevine International Ltd (EGIL) collects and uses Personal Data across its publications, websites, reader accounts, professional audiences, events, research, directories and business-to-business marketing services.

We use professional and behavioural information to operate our services, understand professional interests and provide relevant content. In defined campaigns, we may also provide a named engagement signal to a clearly identified client where a registered reader meaningfully engages with that client's content and the conditions in section 8 are met. A routine page view, advertisement impression or brief visit is not a named engagement signal.

1. WHO WE ARE

1) Executive Grapevine International Ltd is the Controller responsible for the Personal Data described in this Policy unless a separate notice says otherwise.

2) Our registered company number is 2789779. Our address is Gate House, Fretherne Road, Welwyn Garden City, Hertfordshire, AL8 6NS, United Kingdom.

3) You can contact our Data Protection team at [email protected] or +44 (0)1707 351451.

4) This Policy covers EGIL and its brands and services, including HR Grapevine, HR Grapevine Live, HR Grapevine Virtual, Executive Grapevine and myGrapevine.

5) Additional notices may appear when you register for an event, access client content, complete a form, join a research project or use a new feature. Those notices explain the particular activity and should be read with this Policy.

2. WHO THIS POLICY COVERS

1) This Policy covers readers, registered users, newsletter recipients, event participants, speakers, contributors, survey participants, directory contacts, client and supplier contacts, prospects, website visitors and other professional contacts.

2) Our services are designed for adults acting in a professional or business capacity and are not directed at children. We do not knowingly create reader accounts for children under 16 or use their information for marketing or engagement signals.

3) Corporate contact details can still be Personal Data where they identify an individual. The use of a work email address or job title does not remove your data protection rights.

3. PERSONAL DATA WE COLLECT

1) Depending on your relationship with us, we may collect the following categories:

(a) identity and business contact information, including name, title, role, employer, business email, business telephone number and work address;

(b) professional information, including sector, function, seniority, skills, areas of responsibility, company size and publicly available professional profile information;

(c) account information, including username, encrypted or hashed password, account status, preferences and authentication records;

(d) subscription and communication information, including newsletter choices, topic preferences, communications sent, delivery, opens where measurable, clicks, responses, opt-outs and suppression records;

(e) website and application information, including IP address, browser, device, identifiers, approximate location derived from IP, referral source, pages viewed, clicks, scroll depth, session duration and reading activity;

(f) event and webinar information, including registration, attendance, sessions joined, participation, questions, polls, content requests, meeting choices and event-platform activity;

(g) content, research and contribution information, including survey responses, comments, feedback, submissions, recordings, photographs and speaker information;

(h) commercial and transaction information, including orders, Booking Forms, invoices, payment status and business correspondence. Payment-card information is normally processed by our payment provider rather than stored by us;

(i) campaign and engagement information, including the client or content involved, engagement type, engagement band, professional-interest category, recency, source and whether information was disclosed;

(j) inferences and segments, including broad professional interests or likely relevance derived from your role, preferences and engagement. These are indicators, not verified facts about you; and

(k) security and compliance information, including consent records, objections, rights requests, complaints, access logs, fraud indicators and incident records.

2) We do not seek to collect personal email addresses or personal telephone numbers for our core professional-audience products, although you may provide them in limited circumstances such as an event registration or enquiry.

4. SPECIAL CATEGORY AND SENSITIVE INFORMATION

1) We do not intentionally build audience products or engagement signals using health, ethnicity, religion, political opinion, trade union membership, genetic or biometric data, sex life or sexual orientation.

2) You may reveal sensitive information voluntarily in a question, comment, survey response, accessibility request or event discussion. We use it only for the purpose for which it was provided, restrict access and delete or anonymise it when it is no longer required, unless the law permits or requires longer retention.

3) We do not infer Special Category Data from the articles, event sessions or client content you view. Engagement with content about health, wellbeing, diversity, employment relations or another sensitive subject must not be treated as evidence of your own health, beliefs, membership or personal circumstances.

4) We will identify an applicable UK GDPR Article 9 condition, and obtain explicit consent where required, before deliberately Processing Special Category Data for a new purpose.

5. HOW WE COLLECT PERSONAL DATA

1) We collect Personal Data directly when you create an account, subscribe, register, attend, complete a form or survey, request content, communicate with us, enter into a contract or contribute to our services.

2) We collect technical and engagement information when you use our websites, emails, applications and event platforms. Some collection depends on your cookie or similar-technology choices.

3) We may receive professional information from your employer, event partners, clients, service providers, professional directories and publicly available professional sources. We do not treat a social-media profile as permission to contact you for any purpose.

4) Where we obtain your information from another source and Article 14 UK GDPR applies, we provide privacy information within the required period unless a lawful exception applies.

5) If you provide information about another person, you must be authorised to do so and should direct them to this Policy where appropriate.

6. HOW AND WHY WE USE PERSONAL DATA

1) We use Personal Data for the following purposes and lawful bases. The appropriate basis depends on the context and any applicable electronic-marketing or cookie rules.

1. Provide reader accounts, registrations, requested content, events and contracted services: Performance of a contract or steps requested before a contract; legitimate interests where the service is not contractual.

2. Publish editorial contributions, administer communities and communicate about our services: Contract, consent where appropriate, or legitimate interests in operating professional information services.

3. Send service messages, manage accounts, payments and client relationships: Contract, legal obligation and legitimate interests.

4. Send newsletters and EGIL marketing: Consent where PECR requires it; otherwise legitimate interests, subject to your right to object.

5. Send a client-sponsored message from EGIL without disclosing your details to the client: Consent where PECR requires it; otherwise legitimate interests, subject to your right to object.

6. Measure, secure, troubleshoot and improve websites, emails, content and events: Consent for non-essential cookies or similar technologies where required; legitimate interests for subsequent Processing and essential security or service operation.

7. Personalise content and create broad professional-interest segments: Consent where required by PECR; otherwise legitimate interests, with transparency and an objection mechanism.

8. Create and disclose a Named Engagement Signal: Legitimate interests only where the conditions in section 8 are satisfied, or consent where the circumstances, technology or risk require it.

9. Provide aggregate or organisation-level campaign reporting: Legitimate interests, using data minimisation and safeguards.

10. Maintain professional directories and audience records: Legitimate interests in accurate business-to-business information, subject to transparency and objection.

11. Prevent fraud, protect systems, handle complaints and establish or defend legal claims: Legitimate interests and legal obligation.

12. Meet tax, accounting, regulatory and legal requirements: Legal obligation.

2) Where we rely on legitimate interests, our interests include operating and improving professional information services, understanding audience needs, measuring client campaigns, maintaining relevant business contacts, protecting our systems and offering proportionate business-to-business marketing services.

3) We carry out and document a Legitimate Interests Assessment where appropriate. We consider necessity, reasonable expectations, sensitivity, possible harm, the relationship between the parties, safeguards and your ability to object. A summary is available on request, subject to protection of confidential and legally privileged information.

4) Creating an account does not amount to consent to every use of your information. Where we rely on consent, we ask for it separately and you may withdraw it at any time without affecting earlier lawful Processing.

7. PROFILING PERSONALISATION AND AUTOMATED PROCESSING

1) We may analyse role, employer, topic preferences and engagement to recommend content, manage frequency, understand professional interests, create audience segments and measure campaign relevance.

2) Our interest categories and engagement bands are inferences based on limited information. They may be incomplete or wrong. We do not present them as confirmed facts and provide ways to update preferences or object.

3) We do not use reader profiling to make solely automated decisions that produce legal or similarly significant effects on you. If this changes, we will provide specific information about the logic, significance, consequences and applicable rights before that Processing begins.

4) We apply human oversight, access controls, data minimisation, testing and review to profiling and machine-assisted analysis. We do not use engagement profiles to assess employment suitability, credit, insurance, health, eligibility or another high-impact decision.

8. NAMED ENGAGEMENT SIGNALS

1) A Named Engagement Signal is a limited disclosure to an identified client indicating that a registered professional has meaningfully engaged with that client's clearly identified content or activity. It is not a statement that the person requested contact or intends to buy.

2) We may create and disclose a Named Engagement Signal on legitimate interests only where all of the following conditions are met:

(a) the client is clearly named on the relevant partner page, content, event activity or other experience before the qualifying engagement;

(b) a prominent notice near the interaction explains that meaningful engagement may be shared with that client and links to this Policy;

(c) the campaign has a written Data Sharing Schedule defining the purpose, threshold, fields, permitted use, contact limits, retention and safeguards;

(d) the engagement meets an objective threshold showing more than a routine impression, accidental click, isolated brief visit or background page load;

(e) we have completed a campaign or model-level Legitimate Interests Assessment and concluded that disclosure is necessary and not overridden by your rights and interests;

(f) you have been given a clear opportunity to object to named signal disclosure, including through your account or privacy controls and the contact details in this Policy;

(g) the information is limited to what the client reasonably needs for the stated professional purpose; and

(h) the client has agreed to use the signal responsibly, provide its own privacy information, respect marketing law, honour objections and not sell or disclose the information onward.

3) A routine advertisement impression, newsletter open, page impression, brief page view, single accidental click or general reading elsewhere on our services does not qualify as a Named Engagement Signal.

4) A Named Engagement Signal will normally be limited to name, corporate email address, job title, employer, broad professional-interest category, engagement band, recency and the identified client activity. We do not provide the client with your complete browsing history, precise reading timeline, private messages, unrelated activity or raw behavioural profile.

5) The client must not call a Named Engagement Signal a Lead, enquiry, recommendation, purchase intention or request for contact. Disclosure does not itself give the client consent to send electronic marketing. The client must establish its own lawful basis and comply with PECR and other direct-marketing rules.

6) Where meaningful engagement includes an affirmative action, such as requesting the client's content, asking for follow-up or submitting a lead form, we will explain the intended disclosure at that point. This may be treated as a Qualified Response rather than a Named Engagement Signal.

7) If the intended use, technology, audience, sensitivity or likely impact means legitimate interests is not appropriate, we will seek consent or will not make the named disclosure.

8) You may object to named engagement signals at any time by using the privacy controls in your account or contacting [email protected]. Once recorded, your objection applies to future disclosures. We will also take reasonable steps concerning signals not yet used or retained by a client where appropriate.

9. DIRECT MARKETING

1) We may send professional news, content, event and service marketing in accordance with UK GDPR and PECR. The lawful route depends on the recipient, channel, relationship and type of contact details.

2) For employees of limited companies and other corporate subscribers, PECR's consent rule for email marketing generally does not apply in the same way as it does to individual subscribers, but UK GDPR still applies. We may rely on legitimate interests where the communication is relevant, proportionate and within reasonable expectations.

3) Sole traders and certain partnerships are treated as individual subscribers under PECR. We use consent or another applicable PECR permission before sending them electronic marketing.

4) We check applicable telephone preference services and comply with channel-specific rules before marketing calls. We do not make automated marketing calls without the consent required by law.

5) Every marketing message identifies the sender and provides a simple way to opt out. Service, security and contractual messages may still be sent where necessary and are not treated as marketing merely because they relate to your account or booking.

6) You can change topics or unsubscribe through links in our messages, your myGrapevine account where available, or by contacting us. We retain a minimal suppression record so we do not contact you again contrary to your choice.

10. COOKIES AND SIMILAR TECHNOLOGIES

1) We use cookies and similar technologies for essential operation, security, preferences, measurement, personalisation and advertising. Our Cookie Policy identifies the technologies, providers, purposes and durations in more detail.

2) We ask for prior consent before using non-essential cookies or similar technologies where PECR requires it. Rejecting non-essential technologies must be as easy as accepting them, and you can change your choice through our cookie controls.

3) We do not treat acceptance of general terms, creation of an account, continued browsing or a pre-ticked control as consent to non-essential cookies.

4) Withdrawing cookie consent stops future use of the relevant technologies but does not automatically delete information already lawfully collected. We assess the lawful basis and retention of that information separately.

11. WHO WE SHARE PERSONAL DATA WITH

1) We may share Personal Data with:

(a) service providers that host, secure, support, analyse, distribute or process our websites, accounts, communications, payments and events;

(b) professional advisers, auditors, insurers and payment or debt-recovery providers;

(c) event venues, production partners and platform providers where needed to operate an event;

(d) identified clients, sponsors and partners where you make a Qualified Response or where the Named Engagement Signal conditions in section 8 are met;

(e) regulators, courts, law-enforcement bodies and other authorities where required or permitted by law;

(f) a purchaser, investor or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality and safeguards; and

(g) other recipients that we identify to you at the relevant time.

2) Service providers acting as Processors may use Personal Data only on our documented instructions and under a contract containing required data protection terms.

3) A client receiving a Qualified Response or Named Engagement Signal will normally act as an independent Controller for its subsequent use. The client must provide its own privacy information and is responsible for its lawful basis, marketing activity, security, retention and response to your rights.

4) We do not give every advertiser or sponsor the names of everyone who viewed, registered for or attended an activity. The applicable notice and campaign terms determine whether identifiable information is disclosed.

12. INTERNATIONAL TRANSFERS

1) Some service providers, clients or group systems may Process Personal Data outside the United Kingdom or the country in which you are located.

2) Where UK transfer restrictions apply, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses or another lawful safeguard. We assess transfer risks and apply supplementary measures where appropriate.

3) You may contact us for information about the relevant safeguard. We may redact confidential commercial or security information from copies.

13. HOW LONG WE KEEP PERSONAL DATA

1) We keep Personal Data only for as long as reasonably necessary for the stated purpose, including legal, accounting, security and dispute requirements. Typical periods are:

1. Reader account and profile: while active and normally up to 24 months after the last meaningful account activity, unless you ask us to close it sooner or another lawful reason applies.

2. Newsletter and marketing record: until you unsubscribe, object or remain inactive beyond our review period; a minimal suppression record may be retained for as long as needed to honour your choice.

3. Raw website and content engagement: normally up to 13 months, unless a shorter cookie duration applies or longer retention is justified for security.

4. Professional-interest segment or inference: normally up to 24 months from the activity supporting it, with periodic refresh or deletion.

5. Named Engagement Signal source record: normally up to 24 months for accuracy, accountability and objection handling; client use is subject to the shorter campaign period in its Data Sharing Schedule.

6. Event registration and attendance: normally up to 3 years after the event.

7. Client contracts, invoices and transaction records: normally 7 years after the relevant financial year or longer where a dispute or legal requirement applies.

8. Consent, objection and compliance records: normally 6 years after the last reliance, withdrawal, objection or closure of the matter.

9. Routine security and access logs: normally up to 12 months, with longer retention for an incident or investigation.

10. Published editorial and archival material: for the life of the publication or archive where continued retention is justified by journalism, freedom of expression, historical record or legal claims, subject to periodic review and applicable rights.

2) We may keep anonymised information that no longer identifies you. We review retention where a complaint, objection, legal hold, regulatory matter or security incident applies.

14. SECURITY

1) We use risk-based technical and organisational measures designed to protect Personal Data, including access controls, encryption in transit where appropriate, multi-factor authentication, backups, monitoring, vulnerability and patch management, staff training and incident procedures.

2) No internet or information system is completely secure. We therefore review controls according to the nature, volume, context and risk of the Personal Data rather than guaranteeing absolute security.

3) If a Personal Data Breach occurs, we investigate, contain and assess it and notify the ICO and affected people where the law requires.

15. YOUR RIGHTS

1) Depending on the law that applies, you may have the right to:

(a) receive information about our Processing and obtain a copy of your Personal Data;

(b) correct inaccurate or incomplete Personal Data;

(c) ask us to erase Personal Data in certain circumstances;

(d) restrict Processing in certain circumstances;

(e) object to Processing based on legitimate interests, including profiling related to it;

(f) object at any time to direct marketing, including related profiling;

(g) receive certain Personal Data in a portable format where the right applies; and

(h) withdraw consent at any time where we rely on consent.

2) An objection to legitimate-interests Processing is not automatically decisive in every context. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the Processing is needed for legal claims. We will always stop direct marketing when you object to it.

3) You may exercise your rights by contacting [email protected]. We may request proportionate information to verify identity and clarify the request.

4) We normally respond within one month. The law allows an extension for complex or multiple requests, in which case we will explain the extension within the initial period.

5) You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would welcome the opportunity to address your concern first, but you are not required to contact us before approaching the ICO.

16. EUROPEAN ECONOMIC AREA REPRESENTATIVE

1) Where Article 27 EU GDPR requires an EU representative, our representative is Instant EU GDPR Representative Limited, Office 2, 12A Lower Main Street, Lucan, County Dublin, K78 X5P8, Ireland. Email: [email protected].

2) Individuals in the EEA may also complain to the data protection authority in the country where they live or work or where the issue occurred.

17. UNITED STATES PRIVACY INFORMATION

1) Residents of certain US states may have additional rights where the relevant state privacy law applies to EGIL and the Processing. These may include rights to know, access, correct, delete and obtain a copy of Personal Data, and to opt out of sale, targeted advertising or certain profiling.

2) For applicable US laws, the categories collected are described in section 3; sources in section 5; purposes in sections 6 to 10; recipient categories in section 11; and retention in section 13.

3) A commercial disclosure of identifiers, professional information, internet or network activity, and related professional-interest inferences to a client may be treated as a 'sale', 'sharing' or targeted advertising under some US state laws, even where no money is paid specifically for the Personal Data. We do not describe those disclosures as outside US opt-out rights merely because they concern business contacts.

4) Where required, we provide a clearly labelled 'Your Privacy Choices' or 'Do Not Sell or Share My Personal Information' control and honour legally recognised browser-based opt-out preference signals, including Global Privacy Control. Email requests may be sent to [email protected].

5) We do not knowingly sell or share the Personal Data of children under 16. We do not use or disclose sensitive Personal Data for purposes requiring a right to limit under California law.

6) We will not unlawfully discriminate against you for exercising a privacy right. We may verify requests and authorised agents as permitted by law and provide an appeal process where an applicable state law requires one.

18. CHANGES TO THIS POLICY

1) We review this Policy regularly and update it when our services, data uses or legal obligations change. The effective date appears at the top.

2) If a change materially affects how we use or disclose Personal Data, we will provide a prominent notice and, where required, seek consent before applying the new use.

19. CONTACT US

1) Questions, objections, rights requests and complaints may be sent to [email protected].

2) Postal address: Data Protection Team, Executive Grapevine International Ltd, Gate House, Fretherne Road, Welwyn Garden City, Hertfordshire, AL8 6NS, United Kingdom.

3) Telephone: +44 (0)1707 351451.


Executive Grapevine International Ltd

Registered in England & Wales: 2789779 | VAT: 6259453 20

Gate House, Fretherne Road, Welwyn Garden City, AL8 6NS, United Kingdom | +44 (0)1707 351451

Last reviewed by: Helen Fish, Director, 11 September 2026