Privacy Policy
Last updated: 24 July 2026
Stepping Through (‘we’, ‘us’, ‘our’) is committed to protecting your privacy. This policy explains what personal information we collect when you use steppingthrough.org, how we use it, and the rights you have under UK GDPR and the Data Protection Act 2018.
1. Who we are
Stepping Through is a coaching, education and ethical‑AI advisory practice founded by Raisa Razak, operating from London, United Kingdom. For any privacy question you can contact us at customerservices@steppingthrough.org. We are the data controller for the personal data described in this policy.
2. Information we collect
- Contact details you give us — name, email, phone, organisation — when you submit the contact form, book a consultation, or email us.
- Coaching & profiling data — responses to the Personality Breakthrough Profile (PBP), session notes and goals, only where you engage us as a client.
- Marketing‑agent inputs — prompts, briefs and messages you enter into the on‑site agents (content generator, SEO strategist, Ava chat).
- Technical data — IP address, device and browser type, pages visited, referrer, collected via essential cookies and privacy‑respecting analytics.
3. How we use your information
- To respond to enquiries and deliver the coaching, programmes or advisory services you request.
- To operate and improve the marketing‑agent tools on this site.
- To send you information you have asked for, or occasional updates where you have consented.
- To meet our legal, accounting and safeguarding obligations.
4. Lawful bases
We rely on: consent (marketing emails, optional cookies), contract (delivering paid engagements), legitimate interests (responding to enquiries, keeping the site secure), and legal obligation (tax and record‑keeping).
5. AI processing
The on‑site marketing agents use large‑language‑model providers via the Lovable AI Gateway. Prompts you submit may be transmitted to those providers strictly to generate a response. We do not use your inputs to train third‑party models, and we do not send special‑category personal data to the agents. Do not paste confidential client data into the public agent tools.
6. Sharing your data
We share personal data only with vetted processors that help us run the business: our hosting and database provider, email/communication tools, payment providers, accounting software, and the AI providers described above. All processors are bound by written agreements and appropriate safeguards.
7. International transfers
Some processors are based outside the UK/EEA. Where that is the case we rely on adequacy decisions or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
8. Retention
We keep enquiry data for up to 24 months, client records for up to 7 years to meet HMRC requirements, and agent conversation logs for up to 90 days for quality and abuse monitoring. You can ask us to delete your data sooner where no legal duty requires us to keep it.
9. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any of these rights, email customerservices@steppingthrough.org. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.
10. Cookies
We use strictly necessary cookies to run the site and, with your consent, limited analytics cookies to understand how the site is used. You can withdraw or change your consent at any time through your browser settings.
11. Security
We use encryption in transit, access controls, and reputable cloud infrastructure. No system is perfectly secure — please contact us immediately if you suspect any unauthorised use of your data.
12. Changes
We may update this policy from time to time. Material changes will be highlighted at the top of the page.
