Connection Intelligence System — Inspiring Connections / Rethinking Work
Privacy Notice
Privacy Notice — Connection Intelligence System (CIS)
Status: v1.0 draft · Effective: 2026-07-07 (draft — not yet published) · Owner: John Bennett Review cadence: at least annually, and on any material change to processing or sub-processors.
> What this is. A plain-English privacy notice for people whose professional data CIS holds, and > for partners and clients who bring data into CIS. It is written to be served later at a public URL > (e.g. `rethinkingwork.life/privacy`). It describes the system as it actually is on the effective > date — where a control is planned but not yet built, it says so. Companion documents: > `dpa-summary.md` (sub-processors and roles), `data-inventory-and-retention.md` (what is stored > where), and `gdpr-gap-register.md` (the honest scorecard).
1. Who is responsible for your data (the controller)
The data controller is John Bennett, trading as Inspiring Connections (IC) and Rethinking Work (RTW). Rethinking Work is the parent brand and IP home; Inspiring Connections is the connection/brokerage brand (DEC-174). For the purposes of UK GDPR and the Data Protection Act 2018, John Bennett is a sole natural-person controller — CIS is a solo-founder operation at the time of writing.
Contact for any privacy matter: john@rethinkingwork.life. Mobile: 07787 543546.
CIS is a multi-tenant platform. When a client or member brings their own contacts into their own workspace, that client/member may be the controller (or joint controller) for their data and IC acts as a processor for them — see `dpa-summary.md` for how controller and processor roles split by workspace.
2. What personal data CIS holds
CIS is a relationship-intelligence and introduction-brokerage platform for professional (B2B) contacts. It holds, for each contact:
- Identity and contact data — name, work email address, telephone number, LinkedIn profile URL.
- Professional data — job title, employer/company, sector, seniority, and public professional
history.
- Relationship and enrichment data — notes, call and meeting summaries, inferred "connection
angles", company information, and enrichment attributes derived from public and third-party sources.
- Interaction history — a log of touches (calls, emails, LinkedIn actions, status changes) held
in an audit stream (`activity_feed`), used to keep records current and to avoid contacting people who have opted out.
Where this data comes from (provenance):
- LeadDelta CSV exports of professional LinkedIn networks.
- John Bennett's own LinkedIn network export (the founder's first-degree connections).
- Enrichment from third-party and public sources — company registries (Companies House),
web pages, and enrichment providers (see `dpa-summary.md` §3 for the full list).
As at the effective date CIS holds roughly 15,800 contact records (of which ~14,600 are live and not soft-deleted). CIS does not deliberately collect special-category data (health, race, political opinions, etc.); it is a professional-contact system.
3. Why we hold it and our lawful basis
| Processing | Lawful basis (UK GDPR Art. 6) | |---|---| | Holding and organising professional (B2B) contact data to understand relationships and surface relevant connection opportunities | **Legitimate interest** (Art. 6(1)(f)) — building relationship intelligence between professionals. Balanced against the individual's rights; B2B professional contact data, with a clear opt-out. | | Sending outreach email / making calls to a contact | **Legitimate interest**, subject to the opt-out and suppression controls in §5, and to PECR for electronic marketing. | | Making a **connection-partner introduction** (surfacing a person in one member's network to another party) | **Consent** — a double-opt-in, human-brokered model: the relationship owner consents to make the introduction **and** the receiving side consents to receive it (DEC-178). No standing cross-workspace visibility is ever created. | | Enriching a record from public/third-party sources | **Legitimate interest**, limited to professional attributes. |
On consent capture (honest note). CIS has a `consent` field on each contact, but on the effective date it is populated inconsistently — the large majority of records carry no recorded consent value, and the legitimate-interest basis above is the working default for the existing B2B pool. Normalising and reliably capturing the basis per record is a tracked improvement (see `gdpr-gap-register.md`). We do not claim consent we have not recorded.
4. Your rights
Under UK GDPR you have the right to:
- be informed (this notice);
- access the personal data we hold about you;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restrict or object to processing — including an absolute right to object to direct
marketing;
- data portability — receive your data in a structured, machine-readable form.
How to exercise them. Email john@rethinkingwork.life. We will respond within one calendar month.
Honest note on tooling. Objection to marketing / opt-out is handled by an automated, self-service path today (see §5). Access, erasure, and portability are, as at the effective date, handled manually by the operator on request — a self-service erasure/export endpoint is planned and tracked (`gdpr-gap-register.md`, DSAR endpoint task). Requests are honoured regardless; the automation is what is still being built.
5. How to opt out (this works today)
Opt-out is a real, automated, fail-closed control, not a promise:
- One-click unsubscribe. Every compliant outbound email carries an unsubscribe link and an
RFC 8058 one-click `List-Unsubscribe` header, handled by the `cis-unsub` service. Clicking it records your suppression immediately.
- Say "stop". Telling us to stop — by reply, on a call, or via the website chat — records a
suppression (`site-bot` writes a website opt-out).
- What suppression means. Once you are suppressed you are blocked for every partner and
workspace across CIS — suppression is global, not per-sender (DEC-119). A pre-send filter (`cis-suppression-filter`) checks every bulk send against the suppression register and fails closed (if it cannot verify the list, nothing sends). Suppression records are kept indefinitely — an opt-out must persist forever (UK GDPR Art. 17(3)).
Opting out of contact is distinct from erasure of your record; you can request either or both.
6. Who we share it with
CIS uses a small set of third-party processors to run the platform — hosting, email/telephony, enrichment, and AI model providers. Each is listed, with its role and hosting location, in `dpa-summary.md`. We do not sell personal data. Contacts within a member's brought network are never pooled into the shared operator graph or cross-matched; cross-member value flows only through the double-opt-in introductions described in §3 (DEC-178).
7. International transfers
Some of our processors are based outside the UK (for example, AI-model and email providers hosted in the United States). Where data is transferred internationally we rely on the provider's UK/EU transfer safeguards (adequacy or Standard Contractual Clauses / the UK Addendum). A per-processor confirmation of transfer mechanism is being completed and is tracked in `gdpr-gap-register.md`.
8. How long we keep it (retention)
- Suppression / opt-out records: kept indefinitely (they must never lapse) — DEC-119.
- Send logs: intended retention 24 months — DEC-119.
- Contact and relationship records: as at the effective date there is **no automated retention or
deletion schedule** for the main contact pool or for historic backup/staging copies. A retention policy and an automated purge are planned and tracked (`gdpr-gap-register.md`).
We hold data no longer than necessary; making that a scheduled, enforced control (rather than a manual one) is work in progress and is documented honestly rather than overstated.
9. Security
Data is held in a single access-controlled Supabase (PostgreSQL) project. Secrets and API keys are held only in managed secret stores and never in source code or documents (DEC-176). Each client/member workspace is scoped by a `workspace_id` boundary; database-level Row-Level Security enforcement keyed to that boundary is being rolled out — application-level scoping is enforced today (DEC-163). See `dpa-summary.md` §5 for the security cross-reference.
10. Complaints
If you are unhappy with how we handle your data, please contact john@rethinkingwork.life first. You also have the right to complain to the UK Information Commissioner's Office (ICO) — [ico.org.uk](https://ico.org.uk/) — 0303 123 1113.
*This notice describes CIS as at 2026-07-07. Claims of "planned"/"in progress" are tracked in `docs/legal/gdpr-gap-register.md` with task ids. British English throughout.*
Cold Email Outreach — Why You’re Getting This
Why you're getting this email
I've written to you because you're a [role] at [company], and I think what I do (leadership development and coaching work through Inspiring Connections / Rethinking Work) might be relevant to you. This isn't a mass blast. I hold a small amount of business information about you so I can send a genuinely relevant message and not waste your time.
What I hold about you
Just business contact details: your name, job title, company, and your business email address (and sometimes a business phone number or your LinkedIn profile URL). I don't hold anything about your personal life, and I don't collect sensitive data of any kind.
Where I got it
From public professional sources, mainly your LinkedIn profile and your company's own website, and from business-networking exports (LeadDelta and my own LinkedIn contacts). I also use a professional enrichment tool (Apollo) to fill in gaps like a verified work email, using the same public information about you, not new sources.
Why this is allowed
Under UK data protection law, this counts as legitimate interest: I have a genuine, ordinary business reason to contact you (inviting a real conversation about your work), it's proportionate (just business details, low volume, easy to ignore or stop), and it doesn't override your own rights and interests, especially because you can opt out permanently at any time (see below). Under UK e-marketing rules, emailing you at your business address about your business role, where your employer is a company, doesn't need your consent first, though sole traders and some partnerships are treated differently and I don't cold-email those.
How long I keep it
I keep ordinary business contact data for as long as it's genuinely relevant to what I do. If you tell me to stop, I keep a permanent record that you've opted out, forever, so you never get contacted again by mistake. That opt-out record is the one thing I never delete, because deleting it would risk contacting you again.
Your rights, and how they actually work today
You can ask me to:
- stop contacting you (object to marketing). This is instant and automatic: click unsubscribe
in any email, or just reply and say stop, or tell me on a call. It's recorded straight away and it's permanent, across everything I do, not just this one email address.
- see what I hold about you, correct it, or have it deleted (access, rectification, erasure).
I do these by hand today when you ask, rather than through a self-service button. That's honest about where I am right now, not a way of avoiding it. Ask and I'll sort it, normally within a month.
How to contact me
Email me at john@rethinkingwork.life or call/text my mobile on 07787 543546. If you're not happy with how I've handled your data, you also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.