DEEP WORK, SHARED OPENLY
Long-form thinking for complex realities.
We publish playbooks, white papers, practical guides and thought pieces - much of it drawn from work in production. They are written for leaders and teams who need AI to be trustworthy, predictable and useful in day-to-day operations.

Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.




Title of piece goes here and here. Title of piece goes here and here. Title of piece goes here and here.



Brightbeam / Our policies
DATA PROTECTION
POLICY
Our approach to collecting, using, protecting and retaining personal data.
1. Introduction
Brightbeam is committed to safeguarding the privacy and security of the data we handle. As a forward-thinking company, we understand the importance of personal data and are dedicated to processing it responsibly and in line with the highest global standards. This Data Protection Policy outlines our commitment to the principles set out in the General Data Protection Regulation (GDPR) and provides a framework for ensuring the lawful and transparent processing of personal data.
2. Scope
This policy applies to all personal data processed by Brightbeam, irrespective of the data subject or the medium on which that data is stored. It encompasses all operations and locations of Brightbeam and is applicable to all employees, contractors, vendors, and other stakeholders who handle or have access to data processed by the company.
3. Principles
Brightbeam abides by the GDPR's fundamental principles:
-
Lawfulness, fairness, and transparency.
-
Purpose limitation.
-
Data minimisation.
-
Accuracy.
-
Storage limitation.
-
Integrity and confidentiality.
-
Accountability.
4. Data Subject Rights
We recognise and respect the rights of data subjects as laid out in GDPR, including:
-
Right of access.
-
Right to rectification.
-
Right to erasure.
-
Right to restrict processing.
-
Right to data portability.
-
Right to object.
Where you exercise any of the above rights, Brightbeam will respond without undue delay and in any event within one calendar month of receipt of your request, in accordance with GDPR. No fee is normally charged for making a request. We may need to request specific information from you to confirm your identity before responding.
5. Data Collection and Usage
Brightbeam ensures that data is collected for specified, explicit, and legitimate purposes. We do not process data in a manner incompatible with these purposes, and we always seek the minimal amount of data necessary for our operations.
Purposes and Lawful Basis for Processing
-
Registering and onboarding a client organisation or learner — Type of Data: Identity, Contact. Lawful Basis: Performance of a contract; legitimate interests.
-
Delivering training programmes and coaching sessions — Type of Data: Identity, Contact, Usage. Lawful Basis: Performance of a contract.
-
Processing payments and invoicing — Type of Data: Identity, Contact, Financial. Lawful Basis: Performance of a contract; legal obligation.
-
Communicating programme updates and administrative notices — Type of Data: Identity, Contact. Lawful Basis: Performance of a contract; legitimate interests.
-
Evaluating and improving programme content (surveys, feedback) — Type of Data: Identity (optional), Usage. Lawful Basis: Legitimate interests.
-
Marketing Brightbeam's services to prospective clients — Type of Data: Identity, Contact, Marketing. Lawful Basis: Consent; legitimate interests.
-
Complying with legal, tax and regulatory obligations — Type of Data: Identity, Financial. Lawful Basis: Legal obligation.
Data Retention
Brightbeam retains personal data only for as long as necessary for the purposes set out in this policy: typically for the duration of the client or learner relationship, plus six years thereafter to meet Irish tax, accounting and regulatory requirements. Learner attendance and assessment records are retained for the same period to support certification and accreditation evidencing. Data no longer required is securely deleted or anonymised.
6. Data Sharing and Transfers
We do not share personal data with third parties unless it's essential for our operations and services. Any data transfers outside the European Economic Area (EEA) are conducted with appropriate safeguards in place.
7. Data Security
Brightbeam employs robust technical and organisational security measures to ensure the protection of personal data from unauthorised access, alteration, disclosure, or destruction.
8. Breach Notification
In the unlikely event of a data breach, Brightbeam is committed to informing relevant supervisory authorities and affected individuals in line with GDPR requirements.
9. Roles and Responsibilities
Brightbeam has appointed the COO, Paul Savage, as designated Data Protection Officer (DPO) responsible for overseeing the implementation of this policy and ensuring that all activities are compliant with GDPR.
10. Training and Awareness
All employees are trained on the principles of GDPR and the importance of data protection. Regular training sessions and updates ensure that the team remains informed of the latest best practices.
11. Reviews and Audits
This policy and all associated data protection activities are subject to regular reviews and audits to ensure compliance and continuous improvement.
12. Contact and Queries
For any concerns or queries related to data protection at Brightbeam, please reach out to our designated DPO at paul.savage@brightbeam.com.




