Introduction
Privacy Policy
The Governance Forum | tgf.global | admin@tgf.global | ICO Reg: ZB876299
Version 2.0 | July 2026 | Next review: July 2027
This Privacy Policy explains what personal data The Governance Forum collects, why we collect it, how we use it, and your rights. It applies to visitors to our website, delegates and clients of our programmes, contacts who attend our events, and anyone who communicates with us.
This policy has been updated to reflect our use of artificial intelligence tools and AI-powered meeting transcription, in line with UK GDPR, the EU AI Act (Articles 4 and 50), and our AI Transparency Framework™.
1. Who We Are
The Governance Forum (TGF) is a governance training and advisory organisation based in the United Kingdom, with offices in Birmingham, London, and Dubai. We deliver governance education programmes including the Effective Board Member (EBM) programme and AI Wake-Up Call workshops, and provide consultancy and advisory services to public, private, and voluntary sector organisations.
The Governance Forum is the data controller for personal data processed under this policy.
- Email: admin@tgf.global
- Website: tgf.global
- Offices: Birmingham UK | London UK | Dubai UAE
- ICO Registration Number: ZB876299
2. What Personal Data We Collect
Website Visitors
- IP address and browser/device information (via cookies and analytics)
- Contact form submissions (name, email address, message)
Delegates and Programme Participants
- Name, job title, organisation, and contact details
- Registration and booking information
- Attendance records and participation data
- Feedback and evaluation responses
- Payment and invoicing information
Clients and Partner Organisations
- Contact names, email addresses, and telephone numbers
- Correspondence and communication records
- Contract and service delivery information
- Invoice and payment records
Meeting Participants
- Audio content, transcripts, and AI-generated notes — where Granola or Otter AI is active (see Section 7)
- Name and contact details provided in advance of meetings
Marketing and Communications Contacts
- Name and email address (where you have subscribed or consented to marketing)
- Communication preferences and engagement history
We do not collect special category personal data (e.g. health information, ethnicity, political opinions) unless you voluntarily provide it. We do not use AI tools to process special category data.
3. How We Collect Your Personal Data
- Directly from you — when you register for a programme, purchase a service, complete a contact form, or correspond with us
- From your organisation — where your employer provides your details for programme delivery or service coordination
- Automatically — via cookies and analytics when you visit our website
- From meeting participation — where you attend a TGF-hosted meeting using AI transcription tools (see Section 7)
- From publicly available sources — such as LinkedIn or organisation websites, where we conduct outreach for legitimate business purposes
4. Why We Use Your Personal Data — Lawful Bases
| Lawful Basis | When We Rely on It | Examples |
|---|---|---|
| Contractual necessity (Article 6(1)(b)) | Processing is necessary to deliver a service you have requested or agreed to | Registering you for a programme; processing payment; sending booking confirmation |
| Legitimate interests (Article 6(1)(f)) | Processing is necessary for our legitimate interests, where not overridden by your rights | Using AI tools for operational drafting and research (no personal data); maintaining client records; responding to enquiries |
| Consent (Article 6(1)(a)) | You have given clear, specific consent | Sending marketing emails; meeting recording via Granola/Otter AI; non-essential cookies |
| Legal obligation (Article 6(1)(c)) | Processing is required by law | Financial and tax record-keeping (HMRC); responding to regulatory requests |
Where we rely on legitimate interests, you have the right to object. See Section 9 for details.
5. How We Use Your Personal Data
Delivering Programmes and Services
Processing registrations, bookings, and payments; communicating with delegates before, during, and after programmes; issuing certificates and materials; coordinating with client organisations.
Business Administration
Maintaining client and contact records; invoicing and accounting; responding to enquiries; managing supplier and partner relationships.
Marketing and Communications (with consent)
Sending you information about TGF programmes and services where you have consented. You can withdraw consent and unsubscribe at any time by emailing admin@tgf.global or using the unsubscribe link in our emails.
Improving Our Services
Analysing feedback to improve our programmes; reviewing anonymised website usage data to improve our website.
Legal and Compliance
Meeting our legal obligations under UK law including HMRC requirements; defending or pursuing legal claims where necessary.
6. Artificial Intelligence — How We Use AI Tools
The Governance Forum uses AI tools to support our operational efficiency, research, and content creation. The following tools are currently in use:
| Tool | Provider | Purpose | Personal Data Processed |
|---|---|---|---|
| Claude | Anthropic (US) | Research, drafting, programme content | None — we do not enter personal data |
| ChatGPT | OpenAI (US) | Research, content drafting, ideation | None — we do not enter personal data |
| Google Gemini | Google (US) | Research, summarisation, drafting | None — we do not enter personal data |
| NotebookLM | Google (US) | Document analysis, research synthesis | Programme documents only (non-personal) |
| Microsoft Copilot | Microsoft (US) | Productivity, drafting, M365 integration | Non-personal business documents |
| Granola | Granola Inc. (US) | AI meeting note-taking and summaries | Meeting audio and spoken content (see Section 7) |
| Otter AI | AISense Inc. (US) | Real-time transcription, notes, action items | Meeting audio and spoken content (see Section 7) |
| Manus | Monica (CN/US) | Research, task automation | Non-personal text queries only |
| GitHub Copilot | GitHub/Microsoft (US) | Technical development assistance | Code only — no personal data |
| Microsoft Codex | OpenAI (US) | Code generation, technical automation | Code and technical prompts — no personal data |
| Vercel v0 | Vercel (US) | Frontend development, deployment | Technical/development content only |
| N8N (AI nodes) | N8N GmbH (DE) | Workflow automation with AI integrations | Workflow data only — no personal data |
Our AI Data Protection Commitments
- We do not enter personal data about clients, delegates, or third parties into AI tools without appropriate safeguards and a lawful basis.
- All AI-assisted content is reviewed and approved by a qualified human before use — we operate a human-in-the-loop principle at all times.
- We apply data minimisation: only the minimum information needed for the task is shared.
- We do not use AI to make automated decisions that significantly affect individuals without human review (UK GDPR Article 22).
- We do not process special category personal data through AI tools.
AI Transparency Framework™
TGF applies the AI Transparency Index™ to all AI-assisted work, classifying outputs from AI-0 (human only) through to AI-5 (AI-autonomous). This framework was developed by Karl George MBE / The Governance Forum. For more information: governanceai.io.
7. Meeting Recording and Transcription
AI MEETING RECORDING NOTICE
Some TGF-hosted meetings use AI-powered note-taking and transcription tools — Granola and/or Otter AI. These tools may capture and process spoken content to generate transcripts, notes, and summaries. You will be notified in advance (in your meeting invitation) and verbally at the start of any meeting where these tools are active. You have the right to opt out — simply advise the meeting host.
What Data Is Processed
- Audio content from the meeting
- AI-generated transcripts and structured meeting notes
- Summaries, action items, and key points extracted by the AI tool
Lawful Basis
Consent (Article 6(1)(a)), obtained through advance notice in meeting invitations and verbal confirmation at the start of each meeting.
Data Processors
- Granola — Granola Inc. (US). Privacy policy: granola.so/privacy
- Otter AI — AISense Inc. (US). Privacy policy: otter.ai/privacy-policy
Retention
Meeting notes and transcripts are retained for a maximum of 12 months, or deleted when the operational purpose has been fulfilled, whichever is sooner. You may request deletion at any time by contacting admin@tgf.global.
8. Sharing Your Personal Data
We do not sell, rent, or trade your personal data. We share it only in the following circumstances:
Service Providers (Data Processors)
| Category | Provider | Purpose |
|---|---|---|
| AI tools (operations) | Anthropic, OpenAI, Google, Microsoft | Research, drafting, productivity — no personal data shared |
| Meeting transcription | Granola Inc., AISense/Otter AI | Meeting notes and transcription (see Section 7) |
| Website hosting | Hostinger | Hosting tgf.global |
| Business banking | Revolut Ltd (UK) | TGF business bank account; receipt of all programme and service payments |
| Email and productivity | Google Workspace / Microsoft 365 | Email, calendar, document management |
| Workflow automation | N8N GmbH (DE) | Internal operational workflow automation |
Legal and Regulatory Disclosure
We may disclose personal data to law enforcement, regulatory bodies (such as the ICO), or courts where required by law. We will notify you where we are legally permitted to do so.
International Transfers
Several of our service providers are based in the United States. Where we transfer personal data outside the UK, appropriate safeguards are in place, including the UK-US Data Bridge (where applicable) and Standard Contractual Clauses (SCCs) incorporated into provider data processing terms.
9. How Long We Keep Your Data
| Data Category | Retention Period |
|---|---|
| Client and delegate records | 7 years from end of engagement |
| Financial and invoice records | 7 years (HMRC requirement) |
| Programme attendance and feedback | 5 years |
| Marketing contact records | Until consent withdrawn or 3 years of inactivity, whichever is sooner |
| Meeting notes and transcripts | 12 months or until purpose fulfilled, whichever is sooner |
| Website enquiry / contact form | 3 years from last contact |
| Website analytics data | 26 months |
| Correspondence and emails | 7 years for business records |
When data is no longer required, it is securely deleted or anonymised.
10. Your Rights Under UK GDPR
You have the following rights. To exercise any right, contact admin@tgf.global. We will respond within one month, free of charge.
| Your Right | What It Means |
|---|---|
| Right to be informed | To know how your personal data is being used — this Privacy Policy fulfils that obligation. |
| Right of access | To request a copy of the personal data we hold about you (a Subject Access Request). |
| Right to rectification | To ask us to correct inaccurate or incomplete data about you. |
| Right to erasure | To ask us to delete your personal data where there is no compelling reason to keep it. |
| Right to restrict processing | To ask us to pause processing your data in certain circumstances. |
| Right to data portability | To receive your personal data in a structured, machine-readable format where processing is based on consent or contract. |
| Right to object | To object to processing based on legitimate interests or for direct marketing. For marketing, we will always stop immediately. |
| Rights re: automated decisions | Not to be subject to a decision based solely on automated processing. TGF does not make automated decisions about individuals. |
11. Cookies
Our website uses cookies to improve your browsing experience and understand how the site is used.
| Type | Purpose | Basis |
|---|---|---|
| Essential | Enable basic website functions. Cannot be disabled. | Legitimate interests |
| Analytics | Understand how visitors use our site. Data is anonymised where possible. | Consent |
| Marketing / Preferences | Remember your preferences and, with consent, personalise your experience. | Consent |
You can manage or disable non-essential cookies through your browser settings. Disabling some cookies may affect website functionality.
12. Security
We take appropriate technical and organisational measures to protect your personal data, including multi-factor authentication (MFA) on all TGF accounts, encrypted communications, access controls, software firewalls, and automatic security updates. In the event of a personal data breach likely to result in risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay.
13. Children
Our services are intended for adults and professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data about a child, contact admin@tgf.global and we will delete it promptly.
14. Changes to This Policy
We may update this policy periodically to reflect changes in our practices or legal requirements. Material changes will be reflected in an updated version number and effective date. We recommend reviewing this page periodically.
15. How to Complain
If you have concerns about how we use your personal data, please contact us first at admin@tgf.global.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
16. Contact Us
For any questions about this policy or to exercise your data rights:
- Email: admin@tgf.global — subject line: Data Rights Request
- Website: tgf.global
The Governance Forum | Privacy Policy Version 2.0 | July 2026 | ICO Registration ZB876299
