Privacy and Cookie Policy
The Business Network England Limited
Introduction
The Business Network England Limited (“The Business Network”, “TBN”, “we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy and Cookie Policy explains how we collect, use, share and protect personal data when:
- you contact us;
- you attend our events or use our services; or
- you visit our website or online platforms.
We process personal data in accordance with:
- the UK General Data Protection Regulation (“UK GDPR”);
- the Data Protection Act 2018 (“DPA 2018”);
- the Data (Use and Access) Act 2025 (“DUAA 2025”), which updates aspects of UK GDPR and DPA 2018; and
- the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), as amended.
You should read this policy together with any other privacy information we give you at the point we collect your data (for example, on membership forms, event booking pages or specific consent statements).
Short Version
The Business Network England Limited provides professional, invitation-only business networking events and related services.
We collect personal data to:
- administer membership and event bookings;
- host and manage regional business networking events;
- facilitate professional introductions between members and visitors; and
- manage our business relationships, marketing and operations.
The information we may collect includes:
- contact details;
- membership and event information;
- business and professional details (e.g. role, organisation, sector);
- limited financial data for payments and billing;
- marketing and communication preferences; and
- technical and usage data from our website and systems.
We do not routinely collect special category (sensitive) data. Where we need limited information (for example, dietary or accessibility requirements for events), we only process it where the law allows and, where required, with your explicit consent or another lawful condition.
We do not intentionally provide services directly to children or proactively collect data about anyone under 18. If a person under 18 attends an event, we will only process their information where it is strictly necessary and in line with the wishes or authority of the person making the booking.
We obtain personal data:
- directly from you (for example when you enquire, join as a member or book an event);
- from referrers and other organisations who lawfully introduce you to us; and
- automatically from your use of our website (for example via cookies and analytics tools).
Our website uses cookies. Essential cookies are needed for the site to work. Non-essential cookies (for analytics, preferences and marketing) are only used with your consent. You can manage these at any time via our cookie management tool.
We use your personal data to:
- provide and administer membership and events;
- manage our business, accounts and records;
- improve our events, services and website;
- send you relevant information and updates (where you have not opted out); and
- comply with our legal and regulatory obligations.
Our main lawful bases under UK GDPR are:
- Contract (Article 6(1)(b));
- Legitimate Interests (Article 6(1)(f));
- Consent (Article 6(1)(a)); and
- Legal Obligation (Article 6(1)(c)).
If we process special category data (for example, health information for accessibility or dietary needs), we will rely on the relevant condition in Article 9 UK GDPR and applicable DPA 2018 provisions, typically explicit consent.
We sometimes share personal data with trusted third parties where this is necessary to:
- run and host our events (for example venues, caterers, event platforms);
- facilitate introductions (for example providing attendee lists to other delegates); and
- run our business (for example accountants, IT and cloud service providers, email and CRM platforms).
We keep personal data only for as long as necessary for the purposes described in this policy and to meet legal, regulatory or business-record requirements.
We apply appropriate technical and organisational measures to keep your data secure, in line with UK GDPR, DPA 2018 and DUAA 2025 expectations on risk-based and proportionate security.
You have a range of data protection rights, including access, rectification, erasure, restriction, objection and data portability, subject to legal limits. You can exercise these by contacting our Data Protection Officer (DPO) at dpo@csrb.co.uk.
Full details are set out below.
Privacy and Cookie Policy – In Full
Contents
- Our responsibilities
- Your responsibilities
- Contact details
- The information we collect
- Special category data
- Children’s data
- How we gather your information
- How we use your information
- Lawful bases explained
- Do we share your personal information?
- International transfers
- Links to other websites
- Social media
- Cookies
- How we store your data and keep it secure
- Your rights
- Data retention
- Changes to this Privacy and Cookie Policy
- Questions and complaints
- Our responsibilities
When we process personal data, The Business Network England Limited acts as a data controller for the purposes of UK GDPR and DPA 2018 (as amended by DUAA 2025). This means we decide how and why your personal data is used.
We are registered as a company in England and Wales under number 06799841 and are registered with the Information Commissioner’s Office (ICO) as a data controller under registration number ZA937416.
We are responsible for:
- ensuring we have an appropriate lawful basis for each type of processing;
- providing clear and accessible information about what we do;
- keeping personal data accurate and up to date where necessary;
- only retaining data for as long as needed; and
- keeping personal data secure and confidential.
DUAA 2025 places additional emphasis on risk-based accountability and record-keeping. We maintain proportionate records of our processing activities and decisions.
- Your responsibilities
There is not much you need to do, but we ask that you:
- read this Privacy and Cookie Policy carefully;
- refer to any membership terms, event booking information or contracts you have with us for further detail on specific services; and
- only provide us with personal information about other people (for example, guests or colleagues you register for events) where you are entitled to do so and, where appropriate, have informed them.
If you give us personal information about other individuals, or if others give us your information, we will only use that information for the specific purpose for which it was provided. By submitting information about others, you confirm that you have authority to do so and that they have been informed about this policy where appropriate.
- Contact details
Data Controller:
The Business Network England Limited
Registered office:
The Business Network England Limited
5 Pellew Arcade
Teign Street
Teignmouth
Devon
TQ14 8EB
Email (general enquiries): info@business-network.co.uk
Telephone: 01803 328806
Data Protection Officer (DPO):
We have appointed an independent Data Protection Officer to oversee data protection matters:
CSRB Limited
Email: dpo@csrb.co.uk
- The information we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Contact details – name, job title, role, business name, postal address, email address, telephone number and similar details.
- Membership and event information – membership type, renewal status, branch/region, event bookings, attendance records, dietary or accessibility requirements (where provided), and your preferences relating to introductions and follow-ups.
- Business and professional information – sector, size and nature of your organisation, areas of interest, networking focus, and basic profile information used in our membership directory or “members area”.
- Financial information – limited details such as payment records, invoice references and transaction history relating to membership fees or event bookings. (We do not typically store full card details; where payments are processed via a third-party provider, their privacy information will also apply.)
- Marketing data – your preferences in receiving marketing or event updates from us and your communication preferences.
- Technical and usage data relating to our website –
- URL clickstreams (the path you take through our site);
- pages viewed and content of interest;
- page response times and download errors;
- how long you visit pages and what you do on those pages;
- the number of visits to our site;
- IP address, browser type and version, time zone setting, approximate location and similar information collected through analytics tools.
You are not required by law to provide most of this information. However, if you choose not to provide certain data, we may be unable to:
- administer your membership;
- complete your event booking or accommodate any special requirements; or
- respond to specific enquiries.
- Special category data
We do not seek to routinely collect special category data about you. “Special category data” includes information about:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic data;
- biometric data used for identification;
- health;
- sex life or sexual orientation; and
- criminal convictions or offences (which are also subject to specific rules).
In practice, limited special category data may arise where you voluntarily provide information such as dietary requirements, allergies or accessibility needs in connection with an event.
If and when we process such information, we only do so where:
- it is necessary to protect your vital interests (for example, in an emergency);
- it is necessary to comply with health and safety or equality law; and/or
- you have given explicit consent for us to use it for the stated purpose (for example, to ensure appropriate catering or access).
We do not use special category data for marketing or profiling.
- Children’s data
We do not provide services directly targeted at children and we do not proactively collect personal data from anyone under 18.
In limited circumstances, a member or organiser may ask us to include a younger guest at an event. Where that happens, we:
- only record the minimum details necessary (for example, first name and attendance);
- process that information solely for the relevant event purpose; and
- rely on the authority or consent of the person making the booking.
- How we gather your information
We collect personal information in the following ways:
- Directly from you
For example when you:
- contact us by phone, email, post or via our website;
- enquire about membership or events;
- complete membership forms or event booking forms;
- attend our events or take part in online meetings;
- subscribe to our newsletter or other communications; or
- fill in any form or survey on our website or event platform.
- Indirectly from other sources
For example:
- from existing members or contacts who refer or introduce you to us;
- from organisations that are lawfully entitled to share data with us (for example, a corporate member providing a list of attendees);
- from public business sources (for example company websites or professional networking platforms where you have made your information publicly available);
- from analytics and advertising providers (for example Google Analytics) when you accept relevant cookies on our site; and
- via your use of our website, through cookies and similar technologies (see “Cookies” below).
- How we use your information
Data protection law requires us to have a clear, lawful basis for each purpose for which we use personal data. We use your data for the purposes below:
To provide our services and perform our contract with you
- to process membership applications and renewals;
- to manage your membership and profile;
- to administer and confirm event bookings;
- to communicate with you about meetings, venues and changes; and
- to manage billing and payments.
Lawful basis: Contract (Article 6(1)(b) UK GDPR).
To run our networking events and facilitate introductions
- to prepare attendee lists, name badges and table plans;
- to share limited contact details with other event attendees (for example in a delegate list or follow-up email) where appropriate;
- to make professional introductions between members and visitors; and
- to follow up after events with relevant connections or information.
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) in operating our networking model and supporting business relationships, balanced against your rights and reasonable expectations.
To manage and improve our business and website
- to respond to enquiries and feedback;
- to maintain internal records, accounts and administrative systems;
- to monitor and improve our events, services and website content; and
- to protect our systems against misuse or unauthorised access.
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) in running, developing and safeguarding our business.
Marketing and updates
- to send you information about upcoming events, membership benefits and relevant business content;
- to keep you informed about changes to our services or terms; and
- to manage your marketing preferences and any opt-outs.
Lawful bases:
- Consent (Article 6(1)(a) UK GDPR) where you have opted in; and
- Legitimate interests (Article 6(1)(f)) and PECR soft opt-in rules where you are an existing or recent customer/member and we contact you about similar services, unless you have opted out.
To comply with legal and regulatory obligations
- to meet our obligations under tax, company and data protection law;
- to respond to lawful requests from regulators, law enforcement or courts; and
- to maintain appropriate records demonstrating our compliance, including DUAA 2025’s expectations on proportionate but effective accountability.
Lawful basis: Legal obligation (Article 6(1)(c) UK GDPR).
We will not use your personal data for purposes that are materially different, unrelated or incompatible with those above without informing you and, where required, obtaining your consent.
- Lawful bases explained
For clarity:
- Contract – processing is necessary for a contract you have with us (for example membership or event booking) or to take steps at your request before entering into such a contract.
- Consent – you have clearly agreed to specific processing for a defined purpose. You can withdraw consent at any time by contacting us. This will not affect any processing carried out before you withdrew consent.
- Legitimate Interests – we process your information where it is necessary for our legitimate business interests or those of a third party, and these are not overridden by your interests or fundamental rights. We keep a record of legitimate interest assessments where appropriate and take into account ICO guidance and DUAA 2025’s emphasis on proportionate, risk-based approaches.
- Legal Obligation – processing is necessary for us to comply with a legal obligation (for example tax reporting, company law and data protection requirements).
Under PECR, we only send electronic marketing (such as event mailings and newsletters) where:
- you have given your consent; or
- you are an existing or recent customer/member and we rely on the “soft opt-in” for similar events or services, and you have not opted out.
Every marketing communication we send will include an easy way to unsubscribe.
- Do we share your personal information?
We share personal data where it is necessary, proportionate and lawful to do so. This includes:
- Event venues and service providers
For the purposes of organising and delivering events, we may share information with:
- venues and caterers (for example attendee lists, dietary and accessibility requirements);
- online meeting or event platforms where events are held virtually; and
- speakers or facilitators where attendee information is required (for example job role and organisation for tailored content).
- Other members and attendees
To support effective networking, we may:
- provide delegate lists or post-event follow-up emails including names, business details and contact information; and
- make introductions where we believe there is a mutual professional interest.
We limit these details to what is necessary and give you the ability to opt out of certain uses where appropriate.
- Our professional advisers and service providers
To run our business efficiently, we may share limited personal data with:
- accountants and auditors – for preparing accounts, tax returns and audit work (for example copies of invoices and payment records);
- IT, hosting and cloud service providers – who store or process data for us (for example email, document storage, CRM and event management systems);
- email marketing or CRM platforms – where you receive our communications; and
- other specialist providers – such as secure document disposal companies or cyber-security advisers.
In all cases:
- we only share what is necessary for the specific purpose;
- we have written contracts in place with data processors that reflect UK GDPR, DPA 2018 and DUAA 2025 requirements; and
- we require them to keep your data secure and to act only on our documented instructions.
We will not sell your personal information to third parties.
Other than as set out in this policy, we will only share your data with your informed consent or where we are required or permitted to do so by law.
- International transfers
Our main systems are hosted within the UK or European Economic Area (EEA). Where we use service providers that store or process personal data outside the UK (for example, providers with data centres in other countries):
- we check whether there is an adequacy decision in place; and/or
- we put in place appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses with the UK Addendum, where required; and
- we carry out transfer risk assessments in line with ICO guidance and DUAA 2025’s updated framework for international transfers.
Where we use tools such as Google Analytics or email marketing platforms, information (including IP addresses, truncated where possible) may be processed outside the UK. We configure such tools to limit the personal data collected and rely on contractual safeguards and technical measures implemented by those providers.
- Links to other websites
Our website may contain links to other websites. If you follow a link to any external site, please note that their privacy information will apply, not this policy. We cannot accept responsibility for how those organisations handle your personal data, so we encourage you to read their privacy notices.
- Social media
We may operate pages or profiles on platforms such as:
- Facebook / Meta
- X (Twitter)
If you visit our pages or interact with us on these platforms, your data will also be processed by the platform provider in accordance with their own privacy notices. We recommend you review those notices and your privacy settings on each platform.
- Cookies
What are cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to improve efficiency and to provide information to site owners.
Under PECR (as updated and supported by DUAA 2025), we must:
- obtain your consent for most non-essential cookies; and
- clearly explain what they do.
How and why we use cookies
We use cookies to:
- enable core functions of our website;
- remember choices you make (such as preferences);
- understand how visitors use our site so we can improve it; and
- support marketing and social media integrations, where you consent to this.
Types of cookies we use
- Necessary cookies – essential for the website to function (for example, page navigation and access to secure areas). You cannot switch these off using our cookie tool, but you can block them in your browser (which may affect how the site works).
- Preferences cookies – remember choices you have made (for example language or cookie settings).
- Performance / analytics cookies – help us understand how the site is used, so we can improve performance and the user experience.
- Advertising/marketing cookies – help us show relevant content (for example, where social media pixels are used so that you can see our content on those platforms).
We use both:
- session cookies – which are deleted when you close your browser; and
- persistent cookies – which remain for a set period or until you delete them.
We may also use social media plugins or buttons which set cookies controlled by those platforms.
Managing your cookie settings
You can change your cookie preferences at any time by using our cookie management tool (usually accessible via a “Cookie Settings” or “Privacy & Cookies” link on the site). You can then adjust the available options and save your preferences. You may need to refresh the page for your changes to take effect.
You can also manage cookies through your browser settings. For further guidance, you can visit:
To opt out of Google Analytics across all websites, you can use Google’s browser add-on at:
http://tools.google.com/dlpage/gaoptout
Specific cookies
Details of the individual cookies we use, their providers, purposes and expiry periods are available via the “Manage Cookies” option in our cookie consent mechanism. This information is reviewed and updated periodically.
- How we store your data and keep it secure
We take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, as required by UK GDPR, DPA 2018 and DUAA 2025.
These measures include:
- storing electronic information on secure systems with appropriate access controls and, where appropriate, encryption;
- using secure connections (HTTPS) for our website;
- implementing role-based access so that only authorised staff or contractors can see relevant information;
- maintaining policies and risk assessments for information security and data protection;
- regularly updating and patching systems and security software; and
- ensuring any physical documents are stored securely and disposed of securely when no longer required.
Despite our efforts, no method of transmission or storage is completely secure. You provide personal data at your own risk, but we will act promptly if we become aware of any suspected data breach and, where required, we will notify you and the ICO in line with legal requirements.
- Your rights
You have the following rights under UK data protection law:
- Right to be informed – to be told how we use your personal data. This policy and any supplementary notices are intended to provide that information (Articles 13–14 UK GDPR).
- Right of access – to request a copy of the personal data we hold about you, together with certain information about how and why it is processed (Article 15). DUAA 2025 confirms that we are required to carry out reasonable and proportionate searches when responding to such requests.
- Right to rectification – to ask us to correct inaccurate or incomplete personal data (Article 16).
- Right to erasure (“right to be forgotten”) – to ask us to delete your personal data in certain circumstances (Article 17).
- Right to restrict processing – to ask us to restrict the use of your data in certain circumstances (Article 18).
- Right to data portability – to receive certain personal data in a structured, commonly used and machine-readable format and/or request that we transmit it to another controller where technically feasible (Article 20).
- Right to object –
- to object at any time to processing for direct marketing; and
- to object, on grounds relating to your particular situation, to other processing based on legitimate interests (Article 21).
- Rights relating to automated decision-making and profiling – where relevant (Article 22).
Where we rely on your consent, you can withdraw that consent at any time. This includes unsubscribing from marketing emails using the links provided or by contacting us.
To exercise any of these rights, please contact our DPO at dpo@csrb.co.uk or write to us at the address in the Contact details section.
We may need to request additional information from you to confirm your identity before acting on your request. We will normally respond within one calendar month of receiving a valid request, although DUAA 2025 allows for extended time limits for particularly complex or multiple requests, in which case we will let you know and explain the reasons.
Some rights are subject to legal exemptions or conditions (for example where data is needed for legal claims or where disclosure would adversely affect the rights of others). If we cannot fully comply with your request, we will explain why.
- Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including:
- meeting legal, accounting or reporting requirements;
- defending or establishing legal claims; and
- maintaining appropriate records of membership, events and business activities.
In particular:
- Membership and client records – we typically retain core membership and client account information for up to 6–7 years after the end of the relationship, in line with tax and limitation periods, unless a longer period is required by law or there is an ongoing dispute or legal claim.
- Event records – information relating to specific events (for example attendee lists, dietary requirements and feedback) is usually retained for a shorter period, with sensitive elements removed as soon as they are no longer needed.
If, before the end of a retention period:
- your personal data is no longer required for the relevant purpose;
- we are no longer lawfully entitled to process it; or
- you validly exercise your right to erasure and no exemption applies,
we will remove or anonymise it as soon as reasonably practicable.
If you ask us to stop sending direct marketing, we will keep your details on an internal suppression list to ensure you are not contacted again for marketing purposes.
- Changes to this Privacy and Cookie Policy
This policy was last updated in May 2026.
We may update it from time to time, for example to reflect:
- changes in our services, events or internal processes; or
- changes in applicable laws or ICO guidance, including updates arising from DUAA 2025.
The latest version will always be available on our website. If we make any substantial or material changes, we will, where appropriate, notify you by email or a prominent notice on our website.
- Questions and complaints
If you have any questions about this policy or how we handle personal data, or if you wish to exercise your rights, please contact our Data Protection Officer:
Data Protection Officer
CSRB Limited
Email: dpo@csrb.co.uk
If you are unhappy with how we have used your data, we would encourage you to contact us or our DPO first so we can try to resolve the issue.
You also have the right to lodge a complaint with the UK data protection regulator:
Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Online: https://ico.org.uk/make-a-complaint/
Our Policy on Video Conferencing Communications
Introduction
Business Network is successful through enabling members to meet face to face. As a legacy of coronavirus and COVID-19, video conferencing may, from time to time, be used to enable ‘virtual’ face to face meetings.
Our members, by definition, are people who value face to face interaction and find it is beneficial to their organisation.
Many established video conferencing tools have significant costs of usage which act as a barrier to some members, consequently it is not practical to limit usage to high-cost and proven technologies.
Risk Assessment
We believe we should help our members to remain in touch during the coronavirus crisis. We should aim to do this in a way that most closely resembles the face to face get meetings they usually benefit from.
We assess the risks to our organisation of not embracing video conferencing at this time are great.
We believe that by embracing video conferencing we can continue to help our members benefit from their membership.
We understand the risks posed by using immature technologies, but we also recognise the risks of setting the barriers to access unreachably high.
We also understand the potential risks of users exposing personal data inadvertently when using new technologies.
Risk Treatment
We will encourage members to use video conferencing technologies that suit their circumstances.
We will not use or cease to use video conferencing tools if they are shown to compromise information security or personal data and privacy requirements. We will make efforts to be aware of information in this area as it becomes available and respond with urgency if required.
We will inform our members of the risks posed by exposing information unintentionally and aim to educate them about good practice where appropriate.
Decision
Given the risks posed and the treatments we have implemented, we believe the benefits of using video conferencing technologies more widely outweigh the risks posed.
Consequently we decide to make use of these technologies more widely, while ensuring our risk treatment programme is put in place.
Business Network are unable to vouch for the adequacy of the security provisions of Video Conferencing providers., nevertheless the personal data exposed is small, participants have the right not to engage if they are concerned. We make them aware of the risks before they join the video conference. We believe the residual risks to personal data are outweighed by the benefits of using the service.
There have been some suggestions that Zoom Inc. may be retaining or using personal data in ways that would not be expected. However, Zoom is approved for use by MOD personnel, though not for secure communications. Zoom Inc. are members of the recently struck down Privacy Shield scheme. We are therefore continuing to keep the matter under continual review until the planned new guidance from the Information Commissioner’s Office (ICO) is available.
IMPORTANT – During any Video Conferencing event your name may be available to other participants, and please be aware of the background in any video, including your family.
Refund Policy
Please note that to be eligible for a full refund for your event booking cancellations must be notified 48 hours prior to the lunch i.e. for a lunch on a Wednesday the cancellation would need to be received by us via email by 12.00 noon on the Monday before the lunch. The refund will then be made via Worldpay or by BACs.
Because Benefits of Membership are made available to new Members immediately on receipt of a completed Membership Application Form, refunds of membership payments will not be offered. Hosts may, in certain circumstances, offer extensions to a membership term if they feel it appropriate, however, this is discretionary, and the extension will not exceed three months.
Terms and Conditions
Any Documents & Materials that are made available to download from this website are the copyrighted work of Partners, Mr. R Bennett and Mrs. H Bennett (T/A The Business Network) or have been licensed to us. Reproduction is prohibited other than in accordance with this copyright notice, which forms part of our terms and conditions. Disclosure or dissemination of this material outside of The Business Network would be in violation of copyright laws and is prohibited.
Permission to use Documents (such as Manuals, Tool Kits and Forms) from this website is granted, provided that (1) all copyright notices appears in all copies (2) use of such Documents from this website is for the education and instruction of individual Business Network Members and/or Business Network Hosts and will not be copied or posted on any network computer or broadcast in any media, and (3) no modifications of any Documents are made. Use for any other purpose is expressly prohibited by law and may result in severe civil and criminal penalties. Violators will be prosecuted to the maximum extent possible.
Documents specified above do not include the design or layout of this website or any other Business Network owned, operated, licensed or controlled site. Elements of The Business Network websites are protected by trade dress, trademark, unfair competition, and other laws and may not be copied or imitated in whole or in part. No logo, graphic, sound or image from any Business Network website may be copied or re-transmitted unless expressly permitted in writing by The Partners.
The content of the pages of this website is for your general information and use only. It is subject to change without notice. Neither we nor any third parties provide any warranty or guarantee as to the accuracy, timeliness,
performance, completeness or suitability of the information and materials found or offered on this website for any particular purpose. You acknowledge that such information and materials may contain inaccuracies or errors and we expressly exclude liability for any such inaccuracies or errors to the fullest extent permitted by law. Your use of any information or materials on this website is entirely at your own risk, for which we shall not be liable. It shall be your own responsibility to ensure that any products, services or information available through this website meet your specific requirements.
Your use of this website and any dispute arising out of such use of the website is subject to English Law.