Skip to main content

Privacy Policy

We are committed to protecting and respecting your privacy. This policy (together with our Terms & Conditions and any other documents referred to in it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us across our website, community and training platforms, and our events (including Plannex Live). Please read it carefully to understand how we will treat your personal data. 

For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), the data controller is NextGen Planners Ltd, trading as Plannex, of 16 Blackfriars Street, Salford, Manchester, England, M3 5BQ. 

Questions and requests about this policy or your data should be sent to our Data Protection Lead at contact@plannex.co.uk or the address above. 

INFORMATION WE MAY COLLECT FROM YOU

We may collect and process the following data about you: 

  • Information you provide by filling in forms on our site or that you email to us, including when you take a course, subscribe to or register for any of our services, or report a problem with our site. 
  • Event bookings: when you book tickets for our events (via our ticketing partner, Ticket Tailor), we collect the buyer’s name, email address, billing address and company; and for each attendee: name, email address, job title, firm name, and (optionally) dietary requirements. We also record your answers to the marketing and sponsor questions asked at checkout. 
  • Records of correspondence if you contact us, and notes from meetings and reports written. 
  • Responses to surveys we may ask you to complete for research purposes (you do not have to respond to them). 
  • Details of your visits to our site, including traffic data, location data, weblogs and other communication data, and the resources you access. 

Dietary requirements can reveal information about health or religious belief. We collect this only if you choose to provide it. We use it solely for event catering and never share it with sponsors or other third parties beyond our catering providers. 

HOW WE USE YOUR INFORMATION

UK GDPR requires a lawful basis for each use of personal data. Ours are: 

Where we rely on legitimate interests, we have carried out and documented an assessment balancing our interests against your rights, and you can object at any time

IP ADDRESSES AND COOKIES

A cookie is a small text file placed on your computer or device when you visit a website. Cookies help us understand how visitors use our site and allow us to improve your experience. For example, they can help us tailor content or measure which pages are most popular.

We use Google Analytics, a third-party analytics tool, to collect standard internet log information and visitor behaviour in an anonymised form. This helps us analyse site traffic and improve our services.
Google Analytics sets cookies to collect this information without identifying individual users. You can opt out of Google Analytics across all websites by visiting http://tools.google.com/dlpage/gaoptout.

Plannex-Privacy-Policy-Image

Note: This list may be updated periodically. You can review all cookies via your browser’s developer tools or cookie settings.

We do not use cookies to modify prices or services specifically for individual users.

Our website is powered by WordPress. As part of its core functionality, WordPress may set cookies related to login sessions, comments and content protection (e.g. anti-spam); these are strictly necessary. Additional cookies may be placed by plugins or embedded content, as disclosed in our cookie banner. 

Under PECR and UK GDPR, non-essential cookies, including analytics, require your consent before being placed on your device. When you first visit our website you will be asked to accept or reject these cookies via our cookie banner, and you can change or withdraw your consent at any time via the banner or your browser settings. We do not use cookies to modify prices or services for individual users. 

Most browsers allow you to block or delete cookies through their settings (“Help” section). To learn more about managing cookies, visit www.allaboutcookies.org. 

You can also find detailed guidance for major browsers here:

WHERE WE STORE YOUR PERSONAL DATA

Almost all data we store about you is held securely within the UK. We work with trusted third-party providers, some based outside the UK or European Economic Area, to support delivery of our services, communication, payment processing and data storage. In all cases we take appropriate steps to ensure your data is processed in accordance with the UK GDPR and Data Protection Act 2018, including approved transfer safeguards (the UK International Data Transfer Agreement or Addendum, the UK-US Data Bridge / EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum, as applicable). 

Depending on the services you use, your data may be processed in the following ways:

GoHighLevel (GHL)

We use GoHighLevel, a secure customer relationship management (CRM) platform, to store client contact data and manage communications such as service updates and email marketing. Data is processed using Amazon Web Services (AWS) and Google Cloud Platform (GCP) infrastructure. All data is encrypted in transit (TLS v1.2+) and at rest (AES256), with regular backups and multiregion redundancy. GHL is GDPR-compliant and participates in the EUUS Data Privacy Framework. You can find more information here:

Microsoft OneDrive

We use Microsoft OneDrive to securely store supplementary client files and documents. OneDrive provides robust privacy, encryption, and compliance controls, including AES256 encryption for data at rest and TLS for data in transit. It supports GDPR response features such as Data Subject Requests, DPIAs, and data residency configurations within Microsoft 365. For more details:

Dropbox

Where applicable, data may be stored via Dropbox. Dropbox encrypts files using AES-256 at rest and uses SSL/TLS encryption (128-bit or higher) during transfer. Dropbox complies with GDPR and offers enterprise-grade access controls.

Google Forms

When collecting data via Google Forms, submissions are protected under Google’s comprehensive privacy framework. Data submitted is stored in our secured Google Workspace environment, protected by end-to-end encryption. Google maintains compliance with GDPR, and their product policies outline content handling, review procedures, and user data rights.

WordPress (Website Platform)

Our website is built using WordPress, which supports data protection compliance by enabling Privacy Policy publishing, cookie consent banners, and user data access features. WordPress also provides integration with GDPR-compliant plugins and tools.

Gravity Forms (Data Collection Plugin)

We use Gravity Forms on our WordPress website to collect user-submitted data (e.g., registrations, surveys). Gravity Forms does not sell or misuse data. It includes built-in GDPR tools such as:
• Consent fields
• Personal data controls (e.g., IP logging settings)
• Compatibility with WordPress data erasure/export tools
We also use a GDPR add-on and limit data retention by auto-deleting form entries      after a short period.
• Gravity Forms Privacy Policy
• GDPR Compliance Documentation

Stripe Payments Europe Ltd.

We use Stripe to process payments. While Stripe is based in the EU, data may be transferred to its U.S. parent company. Stripe complies with GDPR and uses Standard Contractual Clauses (SCCs) to ensure lawful data transfers outside the UK and EEA.

Mighty Networks

Our online community is hosted on Mighty Networks, a US-based platform. Use of this platform is optional, and users contract directly with Mighty Networks by accepting their terms. They use SCCs and comply with GDPR where applicable.
Mighty Networks Privacy Statement

Security of Data Transmission

Please note that while we follow strict security protocols, the transmission of information via the internet is never completely secure. Any data you transmit to us is done at your own risk. Once received, we apply robust security controls to prevent unauthorised access or misuse. Our staff may access personal data securely when working abroad, but data remains stored within the UK/EU.

Your Responsibility

You are responsible for keeping any account passwords or access credentials secure. If you believe your account has been compromised, please notify us immediately.

DISCLOSURE OF YOUR INFORMATION

We may disclose your personal information to third parties: 

  • To event sponsors, strictly as described in the “Event & Sponsors” section. 
  • If you have given your consent for us to do so for marketing or other specified purposes. 
  • To our service providers listed above, acting on our instructions. 
  • If we are under a duty to disclose or share your personal data to comply with any legal obligation, to enforce or apply our terms and other agreements, or to protect our rights or property and the safety of our customers or others, including exchanging information with other companies and organisations for fraud protection and credit risk reduction. 

HOW LONG WE KEEP YOUR DATA

We do not keep information longer than necessary for the purposes it was collected for: 

  • Financial and contractual records: up to 7 years, in line with legal and accounting obligations. 
  • Customer and member records: for the duration of our relationship and up to 7 years afterwards. 
  • Event attendee data: retained for 24 months after the event for follow-up and planning, then deleted or anonymised. Dietary requirements are deleted within 3 months of the event. 
  • Marketing preferences and opt-outs: we keep a record of opt-outs indefinitely so we can honour them. 

MARKETING

When you buy from us, we may send you email updates about similar Plannex events, services and resources. You can opt out when you book and via the unsubscribe link included in every email. Opting out never affects the services or tickets you’ve purchased. You will always receive essential communications about anything you’ve booked. 

We will never sell your personal data. We will inform you before collecting your data if we intend to use it for marketing or to disclose it to any third party for such purposes, and you can prevent such processing at the point of collection or at any time by contacting contact@plannex.co.uk.

EVENTS & SPONSORS

Some of our events, particularly Plannex Live, are supported by sponsors, and connecting attendees with relevant partners is part of the value of attending. We are transparent about exactly what sponsors receive.

Pre-event: Before the event, we share a list of job titles and firm names (not attendee names or contact details) with confirmed event sponsors (A list of sponsors for 2027 will show here) so they understand who will be in the room. We share this under legitimate interests; if you’d prefer your details excluded, contact us at contact@plannex.co.uk.

Contact details: We share attendee contact details with sponsors only where you have opted in at checkout to receive partner offers, tools and resources. Where you attend on behalf of an incorporated firm using a firm email address, we may also include your work contact details under legitimate interests, with an opt-out available at any time via contact@plannex.co.uk.

Sponsor obligations: Sponsors receiving attendee data are bound by written data terms with us, including limits on use, a requirement to honour opt-outs immediately, and deletion requirements. If you receive contact from a sponsor that you believe breaches these limits, tell us at contact@plannex.co.uk and we will take it up with them.

Badge scanning: At our events, sponsors can collect your details only if you choose to have your badge scanned at their stand. A scan, made using our event app, shares your attendee details (name, firm, job title, email) with that sponsor so they can follow up with you. You can decline any scan.

Never shared with sponsors: your dietary requirements, phone number, address and payment details.

YOUR RIGHTS

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the right to: 

  • Access the personal data we hold about you. 
  • Correct inaccurate or incomplete data. 
  • Erase your data in certain circumstances. 
  • Restrict or object to our processing, including any processing based on legitimate interests, and to object to direct marketing at any time (we will always stop). 
  • Data portability: receive the data you provided to us in a usable format. 
  • Withdraw consent at any time where consent is our basis (for example, sponsor contact), without affecting processing that took place beforehand. 

To exercise any of these rights, contact contact@plannex.co.uk. We will respond within one month. If there is a legitimate and permissible reason why we cannot fulfil a request, we will explain why.

We have a retention policy which means we do not keep information we hold about you for longer than necessary unless we there is a legal obligation to do so.

More information about your rights is available from the Information Commissioner’s Office Here.

MAKING A COMPLAINT

If for any reason you are not satisfied with our response, you can complain to the supervisory authority
for data protection. In the UK this is:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
0303 123 1113

CHANGES TO OUR PRIVACY POLICY

Any changes we may make to our privacy policy in the future will be updated on this page and, where appropriate, notified to you by email.

TERMS OF USE

For our Terms Of Use please click here.

CONTACT

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to contact@plannex.co.uk

Supercharge your Financial Planning firm with Plannex Connect Scale Training Live

Unlock new growth, sharpen your skills and build a thriving financial planning business, with confidence and clarity.