Your information

Privacy Policy

This policy explains how CXO Retreats Ltd collects, uses, protects and shares personal information when you use our website, contact us, apply for membership or participate in our retreat community.

Last updated · 22 July 2026

Data controller

CXO Retreats Ltd

CXO Retreats Ltd determines how and why the personal information described in this policy is used.

Your control

Your choices matter

You can update your preferences, unsubscribe from marketing or exercise your data-protection rights at any time.

Section 01

Who we are

CXO Retreats Ltd operates the CXO Retreats website, membership community, retreat programme, content, interviews, podcasts and related activities.

For the purposes of UK data-protection law, CXO Retreats Ltd is the data controller for the personal information described in this policy.

You can contact us about privacy or the use of your information at privacy@cxoretreats.com .

Section 02

Information we collect

The information we collect depends on how you interact with CXO Retreats. It may include:

Identity and contact information

  • Name and preferred form of address
  • Work email address and telephone number
  • Country or region
  • LinkedIn profile or other professional profile

Professional information

  • Employer, job title and leadership function
  • Areas of responsibility and seniority
  • Professional interests and leadership priorities
  • Information supplied as part of a retreat or membership application

Retreat and membership information

  • Retreat and community preferences
  • Application responses and selection notes
  • Attendance, communication and participation records
  • Feedback and information you choose to share with us
  • Dietary, accessibility or other participation requirements

Communications and marketing information

  • Your communication and content preferences
  • Records of emails, enquiries and conversations
  • Marketing consent, unsubscribe and objection records
  • Interaction with emails, forms and website content

Technical information

  • IP address, browser, device and operating-system information
  • Pages visited, referral source and website interaction
  • Cookie identifiers and similar tracking information
  • Website security and diagnostic information

We normally collect information directly from you. We may also receive professional information from your employer, a colleague, an event or retreat partner, professional networking platforms or publicly available business sources.

Section 03

How we use your information

We may use personal information to:

  • Respond to enquiries and registration requests
  • Review retreat and membership applications
  • Assess suitability and maintain balanced leadership communities
  • Arrange retreat attendance, accommodation and participation
  • Manage Membership and provide member content
  • Arrange pre-retreat introductions with Retreat Partners
  • Send operational information about retreats and community activity
  • Share relevant retreat, membership, interview and podcast updates
  • Conduct interviews, record content and manage contributor participation
  • Improve our website, forms, content and services
  • Protect the website, community and participants from misuse or fraud
  • Maintain records and comply with legal, tax and regulatory obligations
  • Establish, exercise or defend legal claims

We do not sell personal information.

Section 04

Our lawful bases

UK data-protection law requires us to have a lawful basis for using personal information. Depending on the circumstances, we rely on:

Consent

We may rely on consent for marketing communications, optional cookies, recorded content, or certain sensitive information. You can withdraw consent at any time.

Contract and steps before a contract

We use information when necessary to respond to an application, provide membership, confirm retreat participation or deliver an agreed service.

Legitimate interests

We may use information where reasonably necessary to operate and develop CXO Retreats, manage professional relationships, review applications, protect the community, improve our services and communicate with relevant business contacts.

When relying on legitimate interests, we consider the purpose, necessity and potential effect on your rights and interests.

Legal obligations

We use information where necessary to meet legal, accounting, tax, regulatory or law-enforcement requirements.

Special-category information

Information about health, disability, religious dietary requirements or mental health may constitute special-category data. Where needed to support safe and appropriate participation, we will normally process this information with your explicit consent or another lawful condition permitted by data-protection law.

Section 05

Marketing and community communications

We may send relevant information about retreat editions, Membership, Retreat Insights, interviews, podcasts, community activity and partnership opportunities.

Depending on the circumstances, we rely on consent or legitimate interests for business-to-business communications. We also comply with the Privacy and Electronic Communications Regulations where they apply.

Every marketing email will provide an unsubscribe option. You can also object or change your preferences by emailing privacy@cxoretreats.com .

Your right to object to direct marketing

You have an absolute right to object to the use of your personal information for direct marketing. If you object, we will stop using your information for that purpose.

We may retain a minimal suppression record after you unsubscribe so we can respect your preference and avoid contacting you again.

Section 06

Who we share information with

We share personal information only where necessary and appropriate. Recipients may include:

  • Website, hosting and technical-support providers
  • Customer relationship and form providers, including HubSpot
  • Email, communications and document providers
  • Retreat venues, accommodation and travel providers
  • Event, wellbeing and programme suppliers
  • Professional advisers, accountants, insurers and legal advisers
  • Regulators, courts, law enforcement or public authorities where required
  • A purchaser, investor or adviser involved in a business sale or restructuring

Retreat Partners

Confirmed retreat participants may be introduced to a small number of relevant Retreat Partners before the retreat. Information necessary to arrange those introductions may be shared with the relevant partner after participants have been informed and where we have an appropriate lawful basis.

Retreat Partners are not permitted to receive unrestricted participant data, and we do not sell attendee or member contact information.

Where another organisation processes personal information on our behalf, we require appropriate contractual and security protections.

Section 07

International data transfers

Some service providers may process or access personal information outside the United Kingdom.

Where information is transferred internationally, we use an appropriate legal mechanism, such as:

  • A UK adequacy regulation
  • The UK International Data Transfer Agreement
  • The UK Addendum to approved standard contractual clauses
  • Another lawful safeguard permitted under UK data-protection law

You can contact us for further information about the safeguards used for a particular transfer.

Section 08

How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting and reporting requirements.

Our typical retention approach is:

  • General enquiries and unconfirmed applications: normally up to 24 months after the last meaningful interaction
  • Membership records: for the duration of Membership and normally up to 24 months afterwards
  • Retreat participation and contractual records: normally up to seven years where required for legal, tax or accounting purposes
  • Dietary, accessibility and health-related requirements: deleted or anonymised when no longer needed after the relevant retreat, unless a longer period is legally necessary
  • Marketing information: until you unsubscribe, object or the information is no longer relevant, subject to periodic review
  • Suppression records: retained as necessary to ensure we continue to respect an unsubscribe or objection
  • Technical and security records: retained according to operational, security and legal requirements

We may retain information for longer where necessary to resolve a dispute, investigate an incident, meet a legal requirement or establish, exercise or defend a legal claim.

Section 09

Cookies and website tracking

Our website may use cookies, pixels and similar technologies to operate securely, remember preferences, understand website use and measure the performance of our content and forms.

Essential technologies

Some technologies are necessary for website security, functionality, form submission, load balancing and preference management.

Analytics and marketing technologies

With consent where required, we may use analytics and marketing technologies, including HubSpot tracking, to understand visits, form journeys, content engagement and communications.

Non-essential technologies should not be activated until the required consent has been obtained. You can manage your choices through the website’s cookie controls.

A more detailed Cookie Policy may be introduced as additional analytics or marketing technologies are added to the website.

Section 10

How we protect information

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include access controls, password protection, encryption where appropriate, secure hosting, software updates, backups, processor agreements and limiting access to people who require the information for their role.

No internet or storage system can be guaranteed completely secure. If a personal-data breach creates a risk requiring notification, we will notify the appropriate regulator and affected individuals as required by law.

Section 11

Your data-protection rights

Depending on the circumstances and lawful basis, you may have the right to:

  • Request access to your personal information
  • Ask us to correct inaccurate or incomplete information
  • Request deletion of your information
  • Ask us to restrict how information is used
  • Object to processing based on legitimate interests
  • Object at any time to direct marketing
  • Receive certain information in a portable format
  • Withdraw consent where processing relies on consent
  • Challenge certain decisions made solely through automated processing

These rights are not absolute and may be subject to legal conditions or exemptions.

To exercise a right, email privacy@cxoretreats.com . We may need to confirm your identity before fulfilling a request.

We do not currently make decisions producing legal or similarly significant effects using solely automated processing.

Section 12

Questions and complaints

Please contact us first if you have a concern about how we have used your information. We will try to resolve it promptly.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.

Visit ico.org.uk/make-a-complaint or telephone the ICO on 0303 123 1113.

Section 13

Changes to this policy

We may update this policy when our services, technology, suppliers or legal obligations change.

The latest version will be published on this page with a revised update date. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected individuals.

Section 14

Contact us

For privacy questions, preference changes or data-protection requests, contact:

CXO Retreats Ltd
Email: privacy@cxoretreats.com