Clesia Publishing Ltd Privacy Notice
1. Who we are
Clesia Publishing Ltd ("Clesia", "we", "us" or "our") is responsible for deciding how and why personal information is used when we act as a data controller. We operate publishing, media, educational and Christian course activities.
Privacy contact email: [email protected]
Company number: 17024399
2. What this notice covers
This notice explains how we use personal information relating to customers, course participants, website visitors, email subscribers, prospective customers, church and ministry contacts, counsellors or professional contacts, suppliers and people who contact us with enquiries.
3. Personal information we may collect
Identity and contact information, such as your name, email address, postal address, telephone number and organisation or church where relevant.
Account and course information, such as course enrolment, login or account details, course progress and completion information made available to us through our course platform.
Transaction and customer-service information, such as purchases, invoices, payment status, refunds, enquiries and correspondence. We do not normally receive or store full payment-card details where payment is handled by a third-party payment provider.
Marketing information, such as how you joined our mailing list, marketing preferences, consent records, unsubscribe status and engagement with emails where our email platform provides this information.
Website and technical information, such as IP address, device/browser information and cookie or analytics information where applicable.
Professional or business contact information used for legitimate business-to-business outreach, including publicly available church, ministry or professional contact details.
Information you choose to give us when you contact us, including information contained in messages, forms or support requests.
4. Sensitive and special category information
Some interactions with our Christian educational content may relate to matters that are personal or sensitive. We design our course so that learners do not need to submit private workbook answers, trauma histories, counselling notes or other deeply personal healing reflections to us as part of normal course participation.
If you voluntarily provide information that reveals or concerns health, mental health, religious beliefs or other special category information, we will only use it where we have a lawful basis and an applicable condition under data protection law, and only to the extent reasonably necessary for the purpose for which it was provided. We do not use sensitive course disclosures for advertising or profiling.
5. How we collect information
Directly from you when you purchase, enrol, subscribe, complete a form, make an enquiry or correspond with us.
Through service providers that support our activities, such as Thinkific for course delivery and MailerLite for email marketing and landing pages.
From our websites and related technologies, including cookies or analytics tools where used.
From publicly available sources in connection with proportionate business-to-business outreach, such as church or professional websites and directories.
6. Why we use your information and our lawful bases
Provide products, courses and customer services
We use your information to process enrolments or purchases, provide access to products or courses, respond to service requests, and manage our relationship with you.
Typical lawful basis: Contract; legitimate interests where appropriate.
Payments, accounting and legal records
We use your information to administer transactions, maintain financial records, and meet tax, accounting and other legal obligations.
Typical lawful basis: legal obligation, contract, services and legitimate interests.
Email newsletters and direct marketing
We use your information to send updates, course information, launch announcements and other marketing where permitted.
Typical lawful basis: Consent where required by PECR; legitimate interests where legally available and appropriate.
Business-to-business outreach
We may contact relevant organisations or professional contacts about resources that may be relevant to their work or communities.
Typical lawful basis: Legitimate interests, subject to applicable UK GDPR and PECR requirements and the recipient’s right to object.
Course administration and improvement
We use information about enrolment, participation and course completion to operate the learning platform, troubleshoot issues and improve course delivery.
Typical lawful basis: Contract; legitimate interests.
Website operation, security and analytics
We use information to operate and secure our websites and online services, and to understand how they are used.
Typical lawful basis: Legitimate interests; consent where required for cookies or similar technologies.
Enquiries and complaints
We use your information to respond to questions, requests, service issues and data protection complaints.
Typical lawful basis: legitimate interests; legal obligation where applicable.
Establishing or defending legal claims
We may use relevant information to protect our legal rights, respond to disputes, or establish, exercise or defend legal claims.
Typical lawful basis: legitimate interests, legal obligation and, where relevant, applicable conditions for special category data.
7. Email marketing
We use MailerLite to manage email lists and marketing communications. Where consent is required, we aim to keep a record of when and how consent was obtained. Every marketing email will provide an appropriate way to unsubscribe or object. If you unsubscribe, we may retain a minimal suppression record so that we can respect your preference and avoid sending further marketing to that address.
8. Cookies and similar technologies
Our websites or service providers may use cookies and similar technologies to make services work, remember preferences, measure usage or support other functions. Where the law requires consent for a particular cookie or technology, we will seek it. More detailed information should be provided in our cookie settings or cookie notice where applicable.
9. Who we share information with
We may share personal information with trusted service providers where this is necessary to operate our business. These may include:
Thinkific or other learning-platform providers used to deliver courses.
MailerLite or other email and landing-page providers used to manage communications.
Website hosting, domain, IT, cloud storage and business software providers.
Payment, accounting and professional advisers where relevant.
Government bodies, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law.
We require service providers handling personal information on our behalf to protect it appropriately and use it only for authorised purposes, subject to the contractual and legal arrangements that apply.
10. International transfers
Some technology providers may process or store personal information outside the United Kingdom. Where a restricted international transfer occurs, we take reasonable steps to ensure that an appropriate transfer mechanism or other lawful safeguard is in place, where required by UK data protection law.
11. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, comply with legal, tax and accounting requirements, resolve disputes and establish or defend legal claims. Retention periods vary according to the type of information and the reason we hold it.
Marketing records are normally kept while you remain subscribed, with a minimal suppression record retained after opt-out where needed to honour your preference.
Course and customer records are retained for the period needed to administer the relationship and for appropriate legal, accounting and support purposes.
Enquiry and correspondence records are kept only as long as reasonably necessary in light of their content and any follow-up required.
Sensitive information voluntarily supplied to us is not retained longer than necessary for the specific purpose for which it was provided.
12. Security
We use proportionate technical and organisational measures to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction. Access is limited to people and service providers who need the information for legitimate purposes.
13. Your data protection rights
Depending on the circumstances, you may have rights to:
ask for access to your personal information;
ask us to correct inaccurate or incomplete information;
ask us to erase information in certain circumstances;
ask us to restrict how information is used in certain circumstances;
object to certain processing, including direct marketing;
receive certain information in a portable format where the right to data portability applies;
withdraw consent at any time where we rely on consent, without affecting processing carried out before withdrawal; and
raise a complaint about how we use your personal information.
These rights are not absolute and may be subject to legal conditions or exemptions. We may need to verify your identity before acting on a request.
14. Data protection complaints
If you are concerned about how we have handled your personal information, please contact us using the privacy contact details below. We will acknowledge and consider data protection complaints, investigate them as appropriate, and tell you the outcome without undue delay in accordance with applicable data protection law.
You also have the right to complain to the UK Information Commissioner. Further information about making a complaint is available from the Information Commissioner’s Office (ICO).
15. Changes to this notice
We may update this Privacy Notice from time to time to reflect changes in our services, technology or legal requirements. The current version will show its effective date at the top of the notice.
16. Contact
Privacy enquiries and requests: [email protected]
Postal address: 117 Cowley Road, SW14 8QD, London, United Kingdom