Privacy Policy
Effective date: January 1, 2026
This Privacy Policy explains how Heidi M. Higginbottom, operating as Heidi M. Higginbottom Consulting ("we," "us," or "our"), collects, uses, and protects your personal data. It applies to visitors to this website, workshop registrants, newsletter subscribers, and consulting and facilitation clients.
1. Data Controller
The data controller responsible for your personal data is:
Heidi M. Higginbottom
Heidi M. Higginbottom Consulting
Washington State, United States
hello@heidihigginbottom.com
We are based in the United States and serve clients globally, including in the European Union, United Kingdom, Canada, and Australia. Where applicable data protection law governs our processing of your personal data — including the UK and EU General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988 — we handle that data in accordance with the relevant requirements as set out in this policy.
2. What data do we collect?
We collect the following personal data depending on how you interact with us:
Contact and identity information: name and email address when you use our contact form or enquire about services.
Booking information: name, email address, job title, organisation, and any information provided on a workshop intake form when you register for a session.
Billing information: name, company name, and email address for the purposes of issuing invoices. Payment details are processed securely by our payment processor and are not stored by us.
Newsletter subscription: name and email address, when you explicitly opt in to receive our newsletter.
Client engagement information: information shared with us in the course of a consulting or facilitation engagement, handled with strict confidentiality.
3. How do we use your data?
Responding to enquiries and administering bookings.
Delivering workshops and consulting or facilitation services.
Sending session confirmations, joining details, and relevant reminders.
Issuing invoices and maintaining financial records.
Sending our newsletter, where you have given explicit consent.
Improving how we work and understanding our clients' needs.
4. Legal basis for data processing
For individuals located in the EU or UK, we process your personal data on the following legal grounds under GDPR:
Contractual necessity: to deliver the workshop or service you have booked or engaged us for.
Consent: when you subscribe to our newsletter or provide optional information. You may withdraw consent at any time without affecting prior processing.
Legal obligation: to meet tax, accounting, or other legal requirements.
Legitimate interests: to respond to enquiries and maintain records of client communications, where these interests are not overridden by your rights.
For individuals located in Canada, we process personal data in accordance with PIPEDA, relying on consent and contractual necessity as our primary grounds. For individuals in Australia, we comply with the Australian Privacy Principles under the Privacy Act 1988. For individuals in the United States and other jurisdictions, we apply the same principles of transparency and data minimisation as a matter of practice.
5. How long do we keep your data?
Booking and contact data: up to 2 years after our last interaction, unless an ongoing client relationship exists.
Financial and invoicing records: up to 7 years, or as required by applicable law.
Newsletter subscriber data: until you unsubscribe. We periodically remove inactive subscribers.
Client engagement data: typically 3 years after project completion, unless a longer period is agreed or necessary for professional practice purposes, or a shorter period is requested.
You may request deletion of your data at any time (see Your Rights below), subject to any legal retention obligations.
6. Sharing your data
We do not sell or rent your personal data. We may share it with trusted service providers where necessary to deliver our services, including:
Booking and scheduling: Acuity Scheduling (operated by Squarespace), to manage workshop registrations.
Payments and invoicing: Stripe and Wise, to process payments and issue invoices.
Email communications: Google Workspace and Squarespace Email Campaigns, for direct client correspondence and newsletters respectively.
Video conferencing: Zoom or Google Meet, to deliver virtual sessions.
Website hosting: Squarespace.
All providers are required to handle your data securely and in accordance with applicable data protection law. We do not share your data with third parties for their own marketing purposes.
7. International data transfers
We are based in the United States. If you are located in the EU, UK, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the US by us and the third-party providers listed in Section 6. Each of those providers maintains appropriate safeguards for international transfers, including Standard Contractual Clauses where applicable. Details of their data processing agreements are available on request, or directly from each provider's website.
8. Your rights
Depending on where you are located, you may have the following rights regarding your personal data:
Access the personal data we hold about you.
Rectify any inaccurate or incomplete data.
Request erasure of your data, subject to legal retention obligations.
Restrict or object to certain processing, including for marketing purposes.
Data portability — receive your data in a structured, commonly used format.
Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at hello@heidihigginbottom.com. We will respond within 30 days and may need to verify your identity before fulfilling a request.
If you are based in the UK and are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).
If you are based in the EU, you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred. A full list of EU supervisory authorities is available at edpb.europa.eu.
If you are based in Canada, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca). If you are based in Australia, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
9. Cookies
This website is hosted on Squarespace, which may set functional cookies necessary for the site to operate. We do not use advertising cookies or third-party tracking beyond those set by Squarespace as part of their platform. You can manage cookie preferences through your browser settings or any cookie consent tool active on this site.
10. Data security and breach notification
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure, including using reputable, established platforms for all data processing activities.
In the event of a data breach that affects your personal data, we will notify you and any relevant regulatory authorities as required by applicable law. For individuals located in Washington State, we comply with Washington's data breach notification law (RCW 19.255.010), which requires notification within 30 days of discovering a breach. If a breach affects more than 500 Washington residents, we will also notify the Washington State Attorney General's Office.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify active clients and subscribers by email where appropriate. The effective date at the top of this page will always reflect the most recent version.
12. Contact
We are always happy to answer questions about how we handle your data. Please get in touch:
Heidi M. Higginbottom
Heidi M. Higginbottom Consulting
Washington State, United States
hello@heidihigginbottom.com
This policy is intended to comply with the UK and EU General Data Protection Regulation (GDPR), Canada's PIPEDA, Australia's Privacy Act 1988, Washington State data breach notification law (RCW 19.255.010), and broadly equivalent data protection laws in other jurisdictions. It does not constitute legal advice. Last reviewed: June 29, 2026.

