Last updated: 3 August 2026

1. Who we are

NProject is a company registered in England and Wales under company number 12098527.

Our registered office is:

NProject: 3rd Floor, 207 Regent Street, London, England, W1B 3HH

Email: hello@nproject.co.uk

For the purposes of applicable UK data protection law, NProject is generally the data controller of the personal information described in this Privacy Policy.

In some consultancy assignments, we may process personal information solely on the instructions ofa client. In those circumstances, the client is normally the controller and NProject acts as its processor. The client’s privacy information will govern that processing, and our responsibilities will also be set out in our contract with the client.

2. Scope of this policy

This Privacy Policy explains how we collect, use, disclose, retain and protect personal information relating to:

·        visitors toour website;

·        people who contact us or book a discovery call;

·        individual and corporate customers;

·        consultancy clients and their personnel;

·        delegates, learners and course participants;

·        people whose employer or another organisation purchases training for them;

·        newsletter subscribers and business contacts;

·        trainers, consultants,suppliers and professional partners;

·        job applicants, contractors and prospective workers; and

·        people who exercise their data protection rights or make a complaint.

It applies to our consultancy, project and programme management, Agile, Waterfall and Scrum services, business analysis, process-improvement services, professional training, PMP and CAPM-related training, Certified Sustainable Project Professional training and other courses delivered by or through NProject.

3. Personal information we collect

Depending on your relationship with us, we may collect the following categories ofpersonal information.

Identity and contact information

This may include your name, title, employer, job title, business or home address, email address, telephone number, signature and professional contact details.

Enquiry and communication information

This includes information contained in website forms, emails, telephone calls, discovery-callbookings, proposals, feedback, surveys, complaints and other correspondence.

Client and consultancy information

This may include projectroles, stakeholder information, meeting details, project documentation, access permissions, professional opinions, work products and other information neededto provide consultancy or project services.

You should not send us personal information about other people unless you are authorised to do so.

Training and professional-development information

This may include:

·        course registrations and bookings;

·        employer or sponsoring-organisation details;

·        attendance and participation records;

·        learning requirements;

·        assessment results and submitted work;

·        course feedback;

·        certificates and certificate identifiers;

·        professional membership or credential details;

·        continuing professional development or professional development unit information; and

·        information required by an accreditation, certification or training partner.

Payment and transaction information

This may include billing addresses, purchase orders, invoice details, payment status and transaction references.

Where payment-card information is collected through a payment provider, the card information is normally submitted directly to that provider. We do not normally receive or retain complete payment-card numbers or card security codes.

Marketing information

This includes newsletter subscriptions,marketing preferences, consent records, event interests and records of whether you opened or interacted with a communication, where applicable.

Website and technical information

This may include your IP address, browser and device information, approximate location, pages visited, referring website, dates and times of access, cookie identifiers, security logs and information about how you use our website.

Recruitment and employment information

This may include CVs,employment history, education, professional qualifications, references, interview notes, right-to-work information, remuneration expectations andinformation supplied by recruiters or job boards.

Successful applicantsand workers will receive further privacy information where appropriate.

4.Special-category and criminal-offence information

We do not routinely request special-category information from customers or learners.

However, we may need to process limited health, disability, accessibility, dietary or similar information where this is necessary to provide reasonable adjustments, protect someone’s wellbeing or safely deliver a course or event.

We may also process special-category information in connection with employment, equality monitoring, legal claims or legal obligations.

Where we process special-category information, we will identify an appropriate lawful basis and an additional condition under applicable data protection law. Depending on the circumstances, this may include explicit consent, employment and social-protection obligations, substantial public interest, protection of vital interests or the establishment, exercise or defence of legal claims.

Information about criminal convictions or offences will only be processed where necessary and where an appropriate legal condition applies, for example for a role orclient assignment requiring lawful vetting.

5. How we obtain personal information

We may obtain information:

·        directly from you;

·        from your employer, client or sponsoring organisation;

·        from a training, certificationor accreditation partner;

·        from trainers, consultants, subcontractors or referral partners;

·        from publicly available professional sources, such as a business website or professional networking profile;

·        from recruitment agencies, jobboards and referees;

·        through our website, booking tools, email systems and course platforms; or

·        from one of our consultancy clients where we are providing services on the client’s behalf.

Where another organisation gives us your information, that organisation is responsible for ensuring it has an appropriate basis for doing so.

6. How and why we use personal information

We use personal information only where we have a lawful basis for doing so.

Responding to enquiries and preparing proposals

We use contact and enquiry information to respond to questions, arrange discovery calls, understand requirements and prepare proposals or quotations.

Ourlawful bases are:

·        taking steps at your requestbefore entering into a contract; and

·        our legitimate interests inresponding to enquiries and developing appropriate business relationships.

Providing consultancy and professional services

We use information to plan, manage and deliver consultancy, project management, programme management, business analysis, process-improvement and related services.

Ourl awful bases are:

·        performance of a contract withyou;

·        our legitimate interests andthose of our corporate clients in administering and delivering agreed services;and

·        compliance with legal obligations.

Administering and delivering training

Weuse learner and delegate information to:

·        register participants;

·        communicate course arrangements;

·        provide course materials;

·        deliver classroom, virtual or blended training;

·        monitor attendance and participation;

·        conduct assessments;

·        issue certificates;

·        answer learner questions;

·        provide reasonable adjustments;

·        collect feedback; and

·        maintain appropriate training and verification records.

Our lawful bases are:

·        performance of a contract ortaking steps before entering into a contract;

·        our legitimate interests in properly administering and improving our training services;

·        compliance with legal obligations; and

·        consent where a particular optional activity requires it.

Certification, accreditation and professional-development reporting

Where applicable, we may use or share learner information to:

·        confirm attendance orsuccessful completion;

·        verify certificates;

·        administer professional development units or equivalent credits;

·        satisfy accreditation or quality-assurance requirements; and

·        support applications or records connected with PMI, GPM or another relevant professional body.

The lawful basis will normally be performance of a contract, our legitimate interests in providing accredited or professionally recognised training, orconsent where the sharing is optional.

PMI, GPM and other professional or certification bodies may process information as independent controllers for their own credentialing, accreditation, quality-assurance or membership purposes. Their own privacy notices will applyto that processing.

Employer-sponsored and corporate training

Where an employer, client or other organisation books or pays for training, we may provide that organisation with information reasonably necessary to administer the booking. This may include registration, attendance, completion status,assessment outcomes or certificate information.

We will not normally disclose detailed assessment responses, health information or confidential learner communications unless this has been clearly explained, is necessary for the service, is required by law or the learner has agreed.

The sponsoring organisation may be a separate controller of the information itreceives.

Payments, accounting and business administration

We use transaction and contact information to take payments, issue invoices, manage accounts, recover debts, maintain business records and meet tax, accounting and regulatory obligations.

Our lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in managing our business and recovering amountsowed.

Managing suppliers, trainers and partners

We use business contact, contract, qualification and payment information to select, engage, manage and pay trainers, consultants, subcontractors, suppliersand professional partners.

Our lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in managing our supply chain and maintainingservice quality.

Marketing and professional communications

We may send newsletters, course announcements, event information, professional insights and information about services that may be relevant to you.

For individual subscribers, we will normally rely on consent where PECR requiresit.

For certain business-to-business communications, we may rely on our legitimate interests where the communication is lawful under PECR and is relevant to the recipient’s professional role.

Every electronic marketing message will provide an appropriate unsubscribe or opt-outmethod.

You have an absolute right to object to the use of your personal information for direct marketing at any time.

We may retain a minimal suppression record after you unsubscribe so that we canensure that we do not add you back to marketing lists.

Website operation, analytics and security

We use technical information to operate and secure the website, detect abuse,troubleshoot problems, understand website performance and improve the experience provided to visitors.

Our lawful bases are our legitimate interests in maintaining a secure and effective website and consent where consent is required for a particular cookie orsimilar technology.

Recruitment

We use applicant information to assess suitability, communicate with candidates, arrange interviews, verify information and make recruitment decisions.

Our lawful bases may includetaking steps at the applicant’s request before entering into a contract, our legitimate interests in recruiting suitable personnel and compliance with employment and immigration obligations.

We will not rely on an assumption that submitting a CV constitutes consent for every possible use of the information.

Legal obligations, complaints, security and claims

We may use information to:

·        respond to data protection requests and complaints;

·        protect our systems, personnel,learners and clients;

·        prevent or investigate fraud and misuse;

·        comply with a court order orlegal obligation;

·        obtain legal advice;

·        establish, exercise or defendlegal claims; and

·        cooperate with regulators andlaw-enforcement authorities.

Our lawful bases may include legal obligation, legitimate interests and, where applicable, a recognised legitimate interest provided by UK data protectionlaw.

7. Our legitimate interests

Where we rely onlegitimate interests, those interests may include:

·        operating and developing ourconsultancy and training business;

·        responding to businessenquiries;

·        managing professional and corporate relationships;

·        administering contracts andservices;

·        improving service quality;

·        maintaining accurate training and certification records;

·        protecting systems and confidential information;

·        preventing fraud and misuse;

·        recovering debts; and

·        establishing, exercising or defending legal claims.

We consider whether the proposed processing is necessary and proportionate and balance our interests against the rights and reasonable expectations of the people concerned.

8. When information is required

Certain information is necessary for us to enter into or perform a contract, administer a course, meet an accreditation requirement or comply with the law.

Where required information is not provided, we may be unable to:

·        respond fully to an enquiry;

·        provide a quotation;

·        enter into or perform acontract;

·        register you for training;

·        provide an adjustment;

·        process payment;

·        issue or verify a certificate;or

·        report professional-developmentactivity.

We will explain where particular information is mandatory.

9. Course recordings, photographs and testimonials

We will tell participants in advance where a training session, webinar or eventmay be recorded or photographed.

Where appropriate, we will provide a non-recorded participation option or obtainconsent. We will not use a learner’s image, recorded contribution or testimonial for promotional purposes without an appropriate lawful basis andany consent required by law.

Consent may be withdrawn for future use, although withdrawal will not affect processing that was lawful before consent was withdrawn.

10. Cookies and similar technologies

Our website uses cookies and similar storage or access technologies.

Some technologies are necessary for security, network communication or a service requested by the visitor. Other technologies may be used for analytics, functionality or marketing.

Where consent is legally required, a non-essential technology will not be activated until the visitor has made an appropriate choice.

Further information about the technologies used, their providers, purposes and duration should be provided in our separate Cookie Policy and cookie-preference tool.

11. Who we share information with

We may share personal information with the following categories of recipient wherenecessary:

·        corporate clients, employersand organisations sponsoring training;

·        trainers, consultants,associates and subcontractors involved in service delivery;

·        professional, certification and accreditation organisations, including PMI and GPM where applicable;

·        website-hosting, form-management, email, cloud-storage, booking, learning-management, video-conferencing and IT-support providers;

·        payment processors, banks andfraud-prevention providers;

·        accountants, auditors,insurers, solicitors and other professional advisers;

·        recruitment providers, referees and background-check providers;

·        regulators, courts, government bodies and law-enforcement authorities;

·        parties involved in a proposed or completed business sale, merger, restructuring or investment; and

·        other recipients where you haveasked us to make a disclosure or have consented to it.

Service providers acting on our behalf are required to process information only for authorised purposes and to protect it appropriately.

We do notsell personal information.

12. International transfers

Some of ourservice providers, professional partners, certification bodies, trainers or clients may be located outside the United Kingdom. Personal information may therefore be accessed or processed in another country.

Where UK data protection rules on international transfers apply, we will use an appropriate transfer mechanism. Depending on the destination and circumstances, this may include:

·        UK adequacy regulations;

·        the UK International Data Transfer Agreement;

·        the UK Addendum to the European Commission’s Standard Contractual Clauses; or

·        another transfer mechanism permitted by UK law.

Where required,we will assess whether the transfer provides a standard of protection that is not materially lower than the protection provided under UK data protection law and implement additional safeguards where appropriate.

You may contact us for further information about the safeguards relevant to your information.

13. How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, contractual, accreditation, accounting and dispute-resolution requirements.

Our usual retention periods are:

·        Enquiries and prospective-client information: up to 24 months after the last meaningful contact, unless a relationship continues or a longerperiod is justified.

·        Client contracts,consultancy records and important correspondence: normally six years after the end of the client relationship or completion of the relevant service.

·        Training registration,attendance, assessment, completion and certificate records: normally six years after the course, or longer where required by an accreditation, verification or professional-development scheme.

·        Financial, invoice and taxrecords: normally six years from the end of the relevant company financial year, or longer where required by law or an ongoing enquiry.

·        Marketing information: until you unsubscribe, withdraw consent or object, subject toperiodic review. Minimal suppression information may be retained for as long asnecessary to respect an opt-out.

·        Website security logs: normally no longer than 12 months unless needed to investigate asecurity incident.

·        Cookie and analyticsinformation: for the periods stated in our Cookie Policy or cookie-preference tool.

·        Unsuccessful job applicants: normally six months after the recruitment process. With the applicant’s agreement, limited information may be retained for up to 12 months for suitable future roles.

·        Data protection requests andcomplaints: normally three years after closure, or longer where needed for an actual or anticipated legal claim.

·        Employee and contractorrecords: in accordance with our internal employment-record retention schedule and any separate workforce privacy notice.

We may retain information for longer where litigation, a regulatory investigation, a tax enquiry or another legal requirement makes this necessary.

At the end of the applicable period, information will be securely deleted, anonymised orplaced beyond routine use.

14. Information security

We use appropriate technical and organisational measures designed to protect personal informationfrom accidental or unlawful loss, alteration, destruction, unauthorised accessor disclosure.

Measures may include:

·        access restrictions based on job responsibilities;

·        password and account-security controls;

·        multi-factor authentication where available;

·        secure cloud and storage services;

·        encryption where appropriate;

·        backups and business-continuity measures;

·        confidentiality obligations;

·        supplier due diligence and contracts;

·        data-minimisation practices;and

·        procedures for identifying and responding to personal-data breaches.

No electronic systemcan be guaranteed to be completely secure. We regularly review the measures appropriate to the nature and risk of our processing.

15. Automated decision-making

We do not currently make decisions about customers, learners or applicants solely by automated means where the decision would have a legal or similarly significant effect on the person.

If this changes, we will provide appropriate information about the logic involved, the significance and expected consequences of the processing, and the available safeguards and rights.

16. Children and young people

Our website and services are generally intended for business professionals and adult learners.

Where we knowingly provide training or another service to a person under 18, we will take appropriate steps to provide suitable privacy information, minimise the information collected and obtain parental, guardian or organisational authorisation where required.

17. Your data protection rights

Depending on the circumstances and the lawful basis used, you may have the right to:

·        request access to your personal information;

·        request correction of inaccurate or incomplete information;

·        request erasure of your information;

·        request restriction of processing;

·        object to processing based on legitimate interests;

·        object at any time to direct marketing;

·        receive information you provided in a structured, commonly used and machine-readable format and have it transmitted to another controller where the right to data portability applies;

·        withdraw consent at any timewhere processing is based on consent; and

·        challenge certain decisions made solely through automated processing.

These rights are not absolute, and an exemption or another legal requirement may sometimesapply.

To exercise a right, contact hello@nproject.co.uk. You may make a request verbally or in writing, although written requests can help us understand what you require.

We may request information reasonably necessary to verify your identity or clarify the information covered by your request.

We will normally respond without undue delay and within one calendar month. The response period may be paused where legally permitted while we await information reasonably required to identify you or clarify the request. Where a request is complex or you have submitted multiple requests, the period may be extended by up to a further two months. We will tell you if an extension applies.

We will not normally charge a fee. A reasonable fee may be charged, or a request may be refused, only where permitted by law, including where a request is manifestlyunfounded or excessive.

Withdrawing consent will not affect the lawfulness of processing carried out before the withdrawal.

18. Data protection complaints

You have the right to complain to us if you believe that we have not handled your personal information in accordance with data protection law.

Please send your complaint to:

Email: hello@nproject.co.uk
Suggested subject line: Data Protection Complaint

Please include enough information for us to understand:

·        who you are;

·        what processing or information concerns you;

·        what you believe went wrong;and

·        what outcome you are seeking.

We will acknowledge a data protection complaint within 30 days of receiving it.

We will take appropriate steps to investigate and respond, keep you reasonably informed where an investigation remains ongoing and communicate the outcome without undue delay.

You also have the right to make a complaint to the UK supervisory authority:

InformationCommissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

You do not have to pay to make a complaint to the Information Commissioner’s Office.

We would appreciate the opportunity to address your concern directly, but your right to contact the Information Commissioner’s Office is not affected.

19. Links and third-partyservices

Our website may contain links to websites and services operated by other organisations, including booking, mapping, professional-body and social-media services.

Those organisations may collect personal information as independent controllers.Their own privacy notices and terms will apply. We are not responsible for theprivacy practices of an external website or service that we do not control.

20. Changes to this Privacy Policy

We may update this Privacy Policy where our services, systems, suppliers or legal obligations change.

The current version will be published on our website with the date of the latest update. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected people.

21. Contact us

For questions about this Privacy Policy, our use of personal information, your data protection rights ora data protection complaint, contact:

NProject:

‍3rd Floor,

207 Regent Street,

London,

England,

W1B 3HH

‍
Email: hello@nproject.co.uk

‍