Skip to content

Privacy

Who looks after your data: Art of Change 

Where I am based: 37 Manor Place, Stoneybatter, Dublin 7, D07E7C 

How to reach me: susan@artofchange.ie 

Last updated: June 2026 

Welcome! When you use my website or work with me, you trust me with your personal information. I take that responsibility very seriously. This policy explains in plain English exactly how I collect, use, and protect your data. 

1. Who I am and How I Work 

In short: I am a coach, consultant and facilitator, delivering professional development programs. I am the sole owner of your data, and any associates I invite to help me work strictly under my professional standards.  

As an organisation development consultant and coach, I am a natural collaborator and an enquirer, acting as an ally to the people and systems I work with. Because I value human truth and connection, I treat the stories, insights, and data you share with me with the deepest respect. I operate under European Union (EU) data protection laws and ensure that my team and I adhere to these professional standards.  

2. What Data I Collect & Why 

In short: I only collect what is strictly necessary to answer your questions, run our coaching sessions or consulting work, or send you updates with your permission. 

By law, I must have a specific reason to hold your information. Here is exactly what I collect and why: 

  • When you interact with my website, contact me, or network with me: 

  • What I collect: Your name, personal or business email address, phone number, time of submission, and the webpage you were visiting. 

  • My legal reason: Legitimate Interests (I need this data to reply to your questions, follow up on our conversations and run my business effectively). 

  • When you become a client: 

  • What I collect: Your name, job title, contact details, and any background information needed to guide our sessions including questionnaire responses. 

  • My legal reason: Performance of a Contract (I need this information to safely and successfully deliver the service you have booked). 
     

  • Our coaching notes and deep insights: 

  • What I collect: Personal reflections, professional goals, and lifestyle wellness details that naturally come up during our work together. I may hold these notes securely on paper or electronically. 

  • My legal reason: Explicit Consent (This is deeply personal data. Any notes taken or reports produced will be securely stored and I will never share your private breakthroughs or wellness details without your clear, written permission). 
     

  • My newsletter and marketing emails:  

  • What I collect: Your email address. 

  • My legal reason: Legitimate interest (If you have worked with me or enquired about my services, I may occasionally send you emails about upcoming events, news and offers. I always include a clear, instant “unsubscribe” link so you can choose to opt out at any time. 

  • Your Payment information: 

  • What I collect: Your billing address and contact details when you pay for your coaching sessions. Payments are processed securely through Stripe inside its own encrypted network. 

  • My legal reason: Performance of a Contract (I need this information to securely process your invoices and handle payments for the services you book). 

3. Sending Data Across Borders (Ireland to the UK) 

In short: Because some of my secure software and UK collaborators are outside the EU, your data moves between Ireland and the UK. This is fully legal and safely protected. 

Because my business associates and certain secure cloud platforms are based in the United Kingdom, your data will be transferred across borders. 

Don’t worry, this transfer is entirely safe and fully approved under the European Commission’s Adequacy Decision for the United Kingdom. This is a formal legal agreement recognising that the UK protects data just as strictly as the EU, allowing our information to flow safely between Ireland and the UK. 

4. Website Interactions: Comments, Cookies & Links 

Comments: When visitors leave comments on the site, I collect the data shown in the comments form and also the visitor’s IP address and browser user agent string to help spam detection. An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment. 

Cookies: Cookies are tiny files saved on your computer that help websites remember your preferences. I use “traffic log” cookies to see which pages are popular so I can improve my website. This data is purely statistical and is quickly deleted. I will never track your choices unless you actively click “Accept” on my website cookie banner. You can also turn off cookies in your browser settings, though it might change how the website looks. 

Videos and Content from Other Websites: Some articles on my site include embedded content (like YouTube videos or links). This content acts exactly as if you had visited that other website directly. They may collect data about you, use their own cookies, and track your interactions; especially if you are logged into an account with them (like Google or Facebook). 

External Links: If you click a link that takes you away from my website, I no longer have control over your privacy. Please be cautious and check the privacy policy of the new website you are visiting. 

5. Security: How I Protect Your Data 

In short: I use top-tier encryption and secure cloud environments. I will never sell or lease your information to third parties. 

I am dedicated to keeping your digital space safe. To prevent anyone from accessing your data without permission, I use industry-standard encryption and GDPR-compliant secure remote cloud storage. My website is backed up by the secure WordPress platform framework. 

6. What Happens If a Security Breach Occurs? 

In the highly unlikely event of a data hack or security breach that impacts your personal information, I am legally required to let you know within 72 hours of finding out. I will contact you directly via email to explain what happened and exactly what steps we should take next. 

7. Understanding Your Legal Data Rights 

In short: You are always in control of your data. You can ask to see it, change it, or delete it at any time. 

Under EU and Irish data laws, you have powerful rights. You can ask for any of the following: 

  1. The right to be informed: as to what data is being collected, how it’s being used, how long it will be kept and whether it will be shared with any third parties. 

  1. The right to access: you can submit subject access requests, which I am obliged to provide a copy of any personal data concerning you as a client. 

  1. The right to rectification: Should any of the information be incorrect or out of date, this can be requested to be updated. 

  1. The right to erasure (also known as ‘the right to be forgotten’): You can request that I erase your data in certain circumstances. 

  1. The right to object: You can request that I stop processing your data for specific reasons, including stopping all direct marketing immediately. 

How to use your rights: I have made this as simple as possible. You don’t need to fill out any complex forms. Simply send an email directly to me at susan@artofchange.ie. I will process your request completely free of charge within one calendar month. 

 

AI Policy


Company name: Art of Change 

Where I am based: 37 Manor Place, Stoneybatter, Dublin 7, D07E7C 

How to reach me: susan@artofchange.ie 

Last updated: May 2026 

 

Technology can be brilliant for keeping us organised, but it must be handled with care. This policy explains exactly how I use Artificial Intelligence (AI) tools in my coaching and consulting practice, and the strict boundaries I put in place to keep your private information safe. 

  1. How I Use AI to Support Our Work

In short: I use a few carefully chosen AI tools for administrative tasks, like typing up notes or helping me do background research, so I can stay 100% focused on you during our sessions. 

To ensure full compliance with the European Union Artificial Intelligence Act (EU AI Act), and the EU GDPR, I manage these tools under strict privacy boundaries. 

My current use of AI may include: 

  • Meeting & Session Transcription: To ensure I remain fully present and engaged during our calls rather than distracted by manual note-taking. 
  • Session Summaries: To help identify key themes, action items, and breakthroughs from our conversations. 
  • Content Research: Conducting initial background research for bespoke resources or coaching materials created specifically for you. 
  • Business Operations & Administration: Drafting preliminary outlines for newsletters, blogs, or automating basic administrative updates. 
  1. Transparency & Data Security

In short: I only use secure, trusted platforms. Most importantly, I ensure the settings are locked down so that your private information is never used to train public AI models. 

Your data privacy is my highest priority. I make sure my technology choices match my strict ethical standards: 

Enterprise-Grade Environments: I exclusively use established software platforms that feature mature, commercial-grade security frameworks. 

No Public Model Training: All AI tools used within my practice are strictly configured to ensure your personal data, session transcriptions, and notes remain completely confidential. I do not allow AI providers to use your data to train their public models. 

Proactive Notification: In the highly unlikely event of a security incident or data breach on any platform that could potentially impact your information, I commit to notifying you via email within 72 hours. 

  1. My “Human First” Approach to AI

In short: AI is just a digital assistant. I never use AI to analyse your emotions, and a real human is always in control of everything created for you. 

I view AI strictly as an administrative supplement to my coaching and consulting expertise, never a replacement. 

The “Human in the Loop” Rule: My professional intuition, empathy, and judgment remain the absolute foundation of our work together. Every AI-assisted output is thoroughly reviewed, edited, contextualised, and approved by me to ensure it meets my high professional standards. 

No AI Emotion Tracking: In strict accordance with Article 5 of the EU AI Act, I never use AI systems designed for biometric emotion recognition, sentiment tracking, or automated psychological surveillance. Your psychological and emotional progress is interpreted exclusively through human connection and expertise. 

AI Literacy & Standards: In line with the EU AI Act, I ensure that my practice maintains a high standard of AI literacy and privacy awareness. Any team members or subcontractors I work with are strictly required to adhere to these same high security standards, ensuring they fully understand the technical and privacy boundaries of the software we use. 

  1. Privacy, Confidentiality, and Consent

In short: I will never feed your identifiable personal data into creative AI tools without your permission, and all shared files are protected by legal contracts. 

Explicit Permission: I do not input your identifiable personal data into generative AI applications without your express permission. If data is extracted for case studies or collaborative analysis, it is strictly anonymised, aggregated, and used only with your prior consent. 

Strict Confidentiality: My practice observes the tightest confidentiality regarding all materials shared during our sessions, enforced through rigorous internal Data Processing Agreements with any subcontractors I use. 

  1. Your Platforms and Applications

In short: If we meet using your work accounts or corporate platforms, you are in charge of checking your own AI and privacy settings. 

If we conduct sessions or manage projects using your preferred corporate platforms, I rely on you to verify the AI settings and privacy policies of those accounts. I am not responsible for the data security, data processing, or model-training defaults hosted within client-controlled software. 

  1. Copyright and Intellectual Property

In short: Raw AI content cannot be copyrighted. Any materials we create together will protect your full ownership rights. 

I recognise that raw, AI-generated content does not automatically carry copyright protections. Any frameworks or materials we co-create that involve AI assistance will be managed in alignment with our existing contractual arrangements, ensuring you retain the full commercial and intellectual rights to the final outputs of our partnership. 

  1. Professional Standards

I hold advanced qualifications in organisational change, communications, and professional coaching. I am an Accredited Relational Dynamics Coach, an Accredited Action Learning Facilitator, and a certified Enneagram Professional (trained through the Chestnut Paes Academy and the ICF-accredited Coaching with the Enneagram program). I also hold an MSc in Organisational Change and Consulting from Ashridge Executive Education (UK), an Advanced Diploma in Management Practice (University of Ulster), and a BA in Communications from DCU. 

I abide strictly by the rigorous professional and ethical codes of practice set out by these global coaching and academic institutions. I will never use AI in any capacity that breaches my professional ethical standards, contractual obligations, or data sharing agreements. My use of technology is always secondary to my commitment to your personal growth and the total integrity of our partnership.