NUCLEUS OF CHANGE
Privacy Notice
How we collect, use and protect personal information
Last updated: 1 September 2026
1. About this notice
This Privacy Notice explains how nucleus of change (“nucleus of change”, “we”, “us” or “our”) collects and uses personal information when you visit our websites, contact us, complete an assessment or application, subscribe to our communications, attend an event, purchase or use our services, or otherwise interact with us.
It applies principally to francinebeleyi.com and nucleusofchange.com, including pages, forms, assessments and services connected with those websites. It also applies to our professional activities on third-party platforms, including social media, video-conferencing, messaging, booking, payment and event platforms, where we determine why and how personal information is used.
This notice is written in accordance with applicable UK data-protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
2. Who is responsible for your information?
nucleus of change is the controller of the personal information described in this notice. This means we decide why and how it is processed.
Controller: Francine Beleyi, nucleus of change
Contact: hello@nucleusofchange.com
ICO registration number: 09910307860
Privacy enquiries and complaints should be sent to the contact details above.
3. The information we collect
Depending on how you interact with us, we may collect the following categories of personal information:
- Identity information, such as your name, title, organisation, professional role and social-media profile.
- Contact information, such as your email address, telephone number, postal address and communication preferences.
- Professional and business information, such as your career history, expertise, business activities, goals, challenges, positioning, audience, revenue range and professional ambitions.
- Assessment and application information, including answers submitted through the i2i Scorecard, programme application forms, discovery questionnaires, surveys and feedback forms, other quizzes together with calculated scores, result bands and recommendations.
- Client-service information, including notes, correspondence, working documents, strategic assets, recordings, transcripts, action plans, feedback and materials created during advisory, speaking, training or coaching engagements.
- Transaction and contractual information, including services purchased, invoices, payment status, billing details and records needed to administer a contract. We do not normally receive or store full payment-card details; these are handled by payment providers.
- Marketing information, such as newsletter subscriptions, consent records, interests, campaign interactions, event attendance and opt-out preferences.
- Technical and usage information, such as IP address, browser and device type, approximate location, referring page, pages visited, time spent, cookie identifiers and website interaction data.
- Communications and media, including emails, WhatsApp or social-media messages, telephone or video calls, event photographs, testimonials, audio/video recordings and podcast contributions.
- Information supplied by another person, organisation, event organiser, referral partner or publicly available professional source.
Special-category information
We do not ask for special-category information as a routine part of our services. However, you may choose to share information about accessibility, beliefs or other sensitive matters where relevant to an event, coaching conversation or change assignment. Please avoid sending sensitive information unless it is necessary. Where we need to process it, we will identify an additional legal condition—normally your explicit consent, a legal obligation or the establishment, exercise or defence of legal claims—and apply appropriate safeguards.
We do not intentionally collect criminal-conviction data unless it is necessary, lawful and subject to appropriate safeguards.
4. How we obtain personal information
We obtain information:
- directly from you when you complete a form, Scorecard, application, survey or questionnaire; contact us; book or buy a service; attend an event; subscribe; or work with us;
- automatically through websites, cookies, server logs and similar technologies;
- from clients, employers, event organisers, collaborators, referral partners or people who introduce you to us;
- from payment, booking, email-marketing, form, video-conferencing and social-media platforms; and
- from publicly accessible professional sources, such as company websites, conference programmes and LinkedIn, where it is reasonable and relevant to our work.
If you give us information about another person, you should have a lawful reason to do so and, where appropriate, make this notice available to them.
5. How and why we use personal information
We process personal information only when we have a lawful basis. The basis depends on the context and may be contract, steps requested before a contract, legal obligation, consent, or our legitimate interests (or those of another person) where those interests are not overridden by your rights.
Responding to enquiries and assessing fit
To respond to questions, review applications, arrange discovery calls, prepare proposals and decide—with human judgement—whether a service is suitable.
Delivering services
To provide the i2i Scorecard, i2i Strategy Session, i2i Experience, ai readiness assessment, advisory, speaking, workshops, research, content, reports, recordings, support and agreed deliverables.
Administering payments and records
To process orders, issue invoices, reconcile payments, manage refunds, maintain accounting records and prevent fraud.
Communicating with you
To send service messages, appointment information, reports, access links, follow-ups and replies by email, telephone, video, WhatsApp or another agreed channel.
Improving and protecting our services
To analyse service use, troubleshoot, secure our systems, prevent misuse, understand demand and improve content, offers and user experience.
Marketing and thought leadership
To send newsletters, invitations, updates and relevant information; manage preferences; measure engagement; and undertake proportionate business-to-business outreach.
Testimonials, case studies and media
To publish an identifiable testimonial, image, recording, case study, podcast or contribution.
Legal, regulatory and business administration
To enforce agreements, obtain professional advice, manage disputes, respond to rights requests and complaints, maintain insurance and comply with law.
6. Artificial intelligence and AI-assisted tools
We may use artificial intelligence (“AI”) and AI-assisted tools to support our business and the delivery of services. Uses may include research, transcription, summarisation, analysis, synthesis of questionnaire or session material, idea development, preparation of recommendations, drafting, editing, visual exploration and development of client materials.
Where AI tools process personal information for us, the lawful basis is the same as for the underlying activity—for example, contract for delivering an agreed client service or legitimate interests for proportionate business administration. We do not treat the use of an AI tool as blanket permission to use personal information for unrelated purposes.
Our approach to AI includes the following safeguards:
- Purpose limitation: we use information only for a defined and relevant task.
- Data minimisation: we limit, redact, pseudonymise or anonymise personal and confidential information where reasonably possible before using an AI tool.
- Provider and settings review: we consider available privacy, security, retention and contractual settings and use business-grade or protected configurations where appropriate.
- Training restrictions: we do not intentionally authorise confidential client material or personal information supplied for a service to be used to train a provider’s general-purpose public models unless we have a valid lawful basis and have clearly informed the affected person.
- Human oversight: AI output may assist our thinking, but it is reviewed by a person before it is relied on for client-facing strategy, recommendations or decisions.
- Accuracy and fairness: we do not assume AI output is correct. We assess it in context and take reasonable steps to identify errors, bias or inappropriate inferences.
- Confidentiality: clients should not submit another person’s confidential or personal information unless they are authorised to do so and it is necessary for the engagement.
We may use third-party AI providers, including OpenAI services where appropriate, and may change providers as technology and safeguards evolve. Some providers may process information outside the UK; the international-transfer section below applies.
We do not currently use AI to make solely automated decisions that have legal or similarly significant effects on individuals. If this changes, we will update this notice before the processing begins and explain the logic, likely consequences and available safeguards, including human intervention and a route to challenge the decision.
7. Applications and service decisions
Information supplied in an application is used to understand your goals, needs, readiness and the likely fit of the service. A person reviews applications and makes any invitation or acceptance decision. We may use AI to organise or summarise application information, but we do not delegate the final decision to AI.
Submitting an application does not commit you to buying a service. We may contact you to clarify information or discuss another relevant option. Marketing subscription remains separate from the application unless you actively choose it or another lawful route applies.
8. Direct marketing
We may send newsletters, event invitations, service information and thought-leadership updates where you have consented or where legitimate interests are appropriate and electronic-marketing law permits. Rules differ for individuals and sole traders compared with corporate subscribers. We assess the appropriate basis for the audience and communication channel.
You can unsubscribe at any time by using the link in an email or contacting hello@nucleusofchange.com. Withdrawing consent does not affect processing that was lawful before withdrawal. We may keep a minimal suppression record so that we can respect your opt-out and avoid contacting you again by mistake.
We do not sell or rent mailing lists. If we ever conduct targeted professional outreach using publicly available business information, we will keep it proportionate, identify ourselves, explain the source where required and provide a clear way to object.
9. Cookies and similar technologies
Our websites use cookies and similar technologies. Some are strictly necessary for security, page delivery, forms, preferences or transactions. Others may support analytics, embedded media, advertising or measurement.
We ask for consent before placing or accessing non-essential cookies where required. You should be able to reject non-essential cookies as easily as accepting them and change your preference later. Google Analytics and other non-essential measurement or marketing technologies must remain disabled until the required consent has been obtained.
A separate Cookie Notice should identify the cookies and similar technologies actually used, their providers, purposes and duration. Browser controls can also remove or block cookies, although strictly necessary features may then work less effectively.
10. Who we share personal information with
We may share personal information only where necessary with trusted service providers, professional advisers and other recipients. Depending on the activity, these may include:
- website and hosting providers, including WordPress-related infrastructure and Fasthosts where used;
- email and cloud-productivity providers, including Google Workspace and related Google services;
- email-marketing and customer-communication providers, including Mailchimp;
- form and assessment providers, including website forms and Google Forms where used;
- checkout, payment and accounting providers, including ThriveCart and the payment processor selected at checkout, such as PayPal or Stripe where enabled;
- video-conferencing, recording, transcription and messaging providers, including Zoom, Google Meet and WhatsApp where used;
- analytics, security, anti-spam, backup and website-maintenance providers, including Google Analytics where enabled;
- AI and technology providers, including OpenAI services where appropriate;
- contractors, associates, facilitators and delivery partners who need information for an agreed engagement and are subject to appropriate confidentiality obligations;
- accountants, insurers, legal advisers, auditors and other professional advisers; and
- public authorities, regulators, courts, law-enforcement bodies or other parties where disclosure is required or permitted by law, or necessary to establish, exercise or defend legal rights.
Some third parties, particularly payment platforms and social-media services, may act as independent controllers for their own purposes. Their privacy notices explain how they use information. We are not responsible for processing that they control independently.
We may disclose relevant information in connection with a merger, reorganisation, sale or transfer of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal information.
11. International transfers
Some suppliers and platforms operate or store information outside the United Kingdom, including in the United States and other countries. When a restricted transfer is made, we use a lawful transfer mechanism where required. This may include UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework where applicable, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or a permitted legal exception.
Where appropriate safeguards are used, we consider the transfer risk and any additional technical, contractual or organisational measures needed so that protection is not materially lower after transfer. You may contact us for further information about the safeguard relevant to your personal information, subject to legitimate confidentiality restrictions.
12. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including contractual, legal, accounting, insurance and dispute-resolution requirements. We consider the amount, sensitivity and risk of the information, whether we can achieve the purpose another way, and applicable limitation or regulatory periods.
13. Security
We use reasonable and proportionate technical and organisational measures designed to protect personal information from accidental or unlawful loss, alteration, disclosure, access or destruction. Measures may include access controls, strong authentication, secure cloud services, encryption in transit, device protection, backups, supplier review, confidentiality arrangements, updates and incident procedures.
No internet or storage system is completely secure. If a personal-data breach creates a risk to individuals, we will assess it promptly and notify the Information Commissioner and affected individuals where the law requires.
14. Your rights
Depending on the circumstances and lawful basis, you may have the right to:
- ask for access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where there is no lawful reason to continue using it;
- ask us to restrict how information is used in certain circumstances;
- receive information you provided in a structured, commonly used and machine-readable format, and ask for it to be transferred where the portability right applies;
- object to processing based on legitimate interests, including profiling based on those interests;
- object at any time to use of your information for direct marketing;
- withdraw consent at any time where processing relies on consent;
- request safeguards relating to a solely automated significant decision, if we ever use such processing; and
- make a complaint to us and to the Information Commissioner.
These rights are not absolute and exemptions may apply. We may ask for information needed to verify identity and clarify the request. We will not normally charge a fee, although the law permits a reasonable fee or refusal in limited circumstances, such as a manifestly unfounded or excessive request.
To exercise a right, email hello@nucleusofchange.com with “Data protection request” in the subject line. We will respond within the period required by law and tell you if an extension or exemption applies.
15. Data-protection complaints
If you believe we have infringed your data-protection rights, you may complain directly to us at hello@nucleusofchange.com. Please include your contact details, what happened, relevant dates or correspondence, and the outcome you are seeking.
We will facilitate the complaint, acknowledge receipt within 30 days, make appropriate enquiries without undue delay, keep you informed where appropriate and tell you the outcome. If we identify a problem, we will consider proportionate remedial action.
You also have the right to complain to the Information Commissioner’s Office (“ICO”). The ICO will generally expect you to raise the issue with us first.
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/
16. Children
Our websites and commercial services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children through our quizzes, applications or marketing forms. If you believe a child has supplied information without appropriate authorisation, contact us so that we can investigate and take appropriate action.
Where we deliver a specifically commissioned youth programme, the organiser and we will agree appropriate roles, notices, consent or safeguarding arrangements before collecting children’s information. This may be covered by a separate, age-appropriate privacy notice.
17. Third-party websites and platforms
Our websites and communications may link to third-party websites, embedded content or platforms. Once you leave our environment or interact with a third party acting independently, its privacy notice applies. We encourage you to read it before supplying personal information. A link does not mean that we control or accept responsibility for that third party’s processing.
18. Changes to this notice
We review this notice periodically and may update it when our services, suppliers, use of AI, Scorecard, legal obligations or data practices change. The latest version will be published on our websites with the revision date. If a change materially affects how we use information already collected, we will take reasonable steps to bring it to the attention of affected people before the new use begins where required.
19. Contact us
For questions, rights requests or complaints about personal information, contact:
Francine Beleyi, nucleus of change
Email: hello@nucleusofchange.com
ICO registration number: 09910307860
