Privacy Notice

How we handle and protect your personal data.

Last updated and effective: 10 September 2026

In the course of our work we receive confidential business information from our clients, which may contain personal data. We also collect personal data through our website, our engagements, our research, our events and our correspondence.

This notice sets out the personal data we handle, why we handle it, who has access to it, how long we keep it, and the measures and processes by which we protect it. Personal data means information about an identified or identifiable individual. It does not cover information that cannot be attributed to an identifiable individual.

Confidential business information we receive from a client is governed by our engagement terms with that client, and we retain it only for as long as we need it for the purposes for which it was given. Where it contains personal data, this notice applies to that personal data.

We comply with the laws to which we are subject. We collect and use personal data only where we have a legal basis to do so. Where we deal with another business, including a social media platform, a service provider or a client's own systems, we act in accordance with the terms on which that business makes its services available to us.

If you work for one of our clients, we receive some of your personal data from your employer, and our use of that data is governed by our agreement with them. Information you give us directly and in confidence is treated differently, and that is set out in full below.

If you apply to work with us, or you work with us as an employee or contractor, we may give you a separate notice covering that relationship. Where we do, it applies in addition to this one.

You are not required to give us your personal data. Where you choose not to, we may be unable to provide our services properly or to respond to you.

By using our website or dealing with us, you confirm that you have read and understood this notice. If any part of it is unclear, contact us before proceeding.


1. Who is responsible for your personal data

The Startup Blacksmith is the trading name of Delphi Returns Ltd, a company incorporated in the British Virgin Islands with company number 2118540, whose registered office is at Mandar House, 3rd Floor, Suite 301, P.O. Box 3159, Road Town, Tortola VG1110, British Virgin Islands.

Where we collect and use your personal data as described in this notice, we do so as the party that determines how it is collected, used, protected, disclosed and disposed of, and we are responsible for it.

Where we hold personal data on behalf of a client, that client determines the purposes and we act on their instructions. Where you are one of their people and you want to exercise a right over that data, we will pass your request to them and help them answer it.


2. How do we collect your personal data

Directly from you. When you contact us, when you engage us, when you take part in an interview, questionnaire, session or workshop we run, when you take part in research we conduct, when you subscribe to something we send, when you register for an event, when you post publicly to us or respond to a survey, when you supply services to us, and when you apply to work with us.

From our clients. Where a client engages us, they give us the names, contact details and roles of the people who will take part, and they give us business material that may contain personal data. The client is responsible for having a lawful basis for giving it to us.

From your systems, where a client has given us access. In the course of an engagement we are given access to a client's own tools and records. Those contain personal data about the people who use them.

From people who introduce you to us, and from publicly available sources such as company websites and professional profiles.

From social media platforms. Where you contact us, mention us or post to our accounts, we see what the platform shows us. The platform is responsible for its own handling of your data and its notice governs that rather than ours.

From public posts on social platforms. We read and analyse posts that are already public on platforms such as X, LinkedIn, Telegram and Discord, including posts that have nothing to do with us. We do this through each platform's official interface. Section 3 describes the purpose in full, together with the limits we apply.

Automatically, when you visit our website. Our hosting provider records ordinary request information generated by your browser, which may include IP address, the date and time of the request, the page requested, the referring page and the browser identifier. This is generated by any website and is used to serve pages and to keep the site secure. We do not use analytics, advertising, profiling or session recording technologies, and we do not use cookies for those purposes.

Sensitive personal data. We may collect sensitive personal data directly from you, for instance when you take part in a survey or in user research and give us demographic or other personal details, or when you tell us what you need so that we can accommodate you at a session or an event. We use sensitive personal data only with your consent unless another legal basis exists, an example being a public health requirement. Where we use it for research, analysis and statistical purposes, we use it to produce findings drawn from anonymised datasets.

Combining data. We may combine personal data we receive directly from you with personal data we receive from a client or from another third party, to the extent that all such collection and use is consistent with this notice and with the purposes and access described in section 3. When we combine anonymised data with personal data, we treat the combined information as personal data.


3. Why and how do we use your personal data

The blocks below set out each purpose, the data used for it, the legal basis where one is required, and who has access.

Where our basis is legitimate interest, we assess whether the use is adequate, proportionate and legitimate before relying on it. Where our basis is consent and you withdraw it, we may be unable to provide part of the service, and withdrawal does not affect anything done before it.

Responding to you, and business development

  • Purpose: To answer an enquiry, to have a conversation about whether we can help, and to keep a record of our dealings with prospective clients and counterparties.
  • Categories of personal data: Name, employer, role, email address or messaging handle, and anything you choose to tell us.
  • Legal basis for use: Legitimate interest for the provision of our services and running our business.
  • Who has access: Us, and the service providers described in section 6.

Delivering an engagement

  • Purpose: To carry out the research, analysis and preparation an engagement requires, to run the sessions and the workshop, and to prepare and deliver what the client receives.
  • Categories of personal data: Names, roles and contact details of the people taking part. Their views, observations and recollections about the business. Personal data appearing incidentally in the business material and system access a client provides.
  • Legal basis for use: Legitimate interest for the provision of our services and running our business. Where you are the individual we contract with, performance of that contract.
  • Who has access: The people running that engagement, by name. The client, subject to section 4. The service providers described in section 6.

Recording sessions

  • Purpose: To record a session, a meeting or a call so that it can be analysed, summarised and acted on afterwards rather than from memory.
  • Categories of personal data: Voice, image where video is used, and what you say.
  • Legal basis for use: Where you take part as a client or as personnel of a client, the agreement of the client under our engagement terms with them. Otherwise your consent, given before the recording starts, either in writing or verbally and noted by us at the time.
  • Who has access: The people running that engagement, and the recording and transcription provider described in section 6.

User research

  • Purpose: To interview a client's users and prospective users, to run recorded sessions of people using a product, and to report what we find.
  • Categories of personal data: Contact details, what you told us, recordings where you consented, and the details needed to pay you for your time.
  • Legal basis for use: Your consent to take part. Legitimate interest for the provision of our services in analysing and reporting what we learn.
  • Who has access: The people running that engagement, and the client in aggregate form. Where a direct quotation is used, it is used without your name.

Engaging suppliers and advisers

  • Purpose: To engage, instruct, manage and pay our suppliers, service providers, contractors and professional advisers.
  • Categories of personal data: Name, role, contact details, contractual and payment details.
  • Legal basis for use: Performance of a contract where you are the party we contract with. Otherwise legitimate interest in running our business.
  • Who has access: Us, and our accounting and payment providers.

Our people, and people who apply to work with us

  • Purpose: To assess an application, to enter into and manage an employment or contractor relationship, to pay people, and to meet our obligations as an employer or engager.
  • Categories of personal data: Contact details, work history, information given during an application or interview, and the contractual, payment and tax details the relationship requires.
  • Legal basis for use: Steps taken at your request before entering into a contract, and performance of that contract once made. Compliance with legal obligations. Legitimate interest in assessing whether someone is right for the work.
  • Who has access: Us, our professional advisers, and our accounting and payment providers. Where we engage you, we may give you a fuller notice covering the relationship.

Running our business

  • Purpose: Invoicing, payment, accounting, tax, insurance, and keeping proper business records.
  • Categories of personal data: Name, employer, role, contact details, and the details of what was agreed and paid.
  • Legal basis for use: Legitimate interest in running our business, and compliance with legal obligations.
  • Who has access: Us, our accounting and financial providers, and our professional advisers.

Keeping our systems and our premises secure

  • Purpose: To maintain the security, integrity and availability of our systems and information, to keep the room where a workshop is held secure, and to prevent, detect and investigate misuse or unlawful activity.
  • Categories of personal data: Access and request records, and any data implicated in an incident.
  • Legal basis for use: Legitimate interest in protecting our business and the information entrusted to us.
  • Who has access: Us, and where necessary our professional advisers and the relevant authorities.

Improving how we work

  • Purpose: To develop our methodology and our materials.
  • Categories of personal data: None, by design. Anything we learn from an engagement is generalised so that it identifies neither the client nor any individual before it is carried forward.
  • Legal basis for use: Legitimate interest for the provision of our services and running our business.
  • Who has access: Us.

Marketing

  • Purpose: To tell people about what we do, and to keep in touch with people who have shown an interest in it.
  • Categories of personal data: Name, employer, role, email address or messaging handle.
  • Legal basis for use: Legitimate interest for the provision of our services and running our business, and your consent where the law requires it. You can object at any time by contacting us at privacy@startupblacksmith.com and, subject to verification of your identity, we will cease doing so.
  • Who has access: Us.

Naming a client in our marketing

  • Purpose: To describe an engagement we have run, whether by naming the client, using their marks, quoting someone who worked on it, or publishing a case study.
  • Categories of personal data: The name, role and words of the individuals involved, and the identity of the client itself.
  • Legal basis for use: The client's prior explicit written consent, given for the specific use. Where an individual is named or quoted, their own explicit written consent as well. Consent can be withdrawn, and we will stop using the material going forward.
  • Who has access: Us, and whoever the published material reaches.

Newsletters and alerts

  • Purpose: To send you what you signed up for, and to administer your subscription.
  • Categories of personal data: Name, employer, role, email address, and your subscription and delivery preferences.
  • Legal basis for use: Your consent, given when you subscribe. Every message carries an unsubscribe link and unsubscribing takes effect immediately.
  • Who has access: Us, and the mailing provider described in section 6.

Events, talks and recorded media

  • Purpose: To register you for an event, talk, webinar or recording, to run it, to accommodate you properly, and to produce and publish any recording of it.
  • Categories of personal data: Name, employer, role, contact details, and where you tell us, dietary requirements or an accessibility need. Where an event is recorded, your voice and image.
  • Legal basis for use: Legitimate interest in running the event and dealing with your registration. Your consent for any recording in which you appear, and for the use of a dietary or accessibility detail, which we use only to accommodate you and then discard.
  • Who has access: Us, the venue and the providers necessary to run the event, and where a recording is published, whoever it reaches.

Public posts, comments and surveys

  • Purpose: To run any public discussion space, comment facility or survey we operate, and to read and respond to what people post to us in public.
  • Categories of personal data: What you choose to write, together with whatever identity you post under.
  • Legal basis for use: Your consent, given by choosing to post or to respond. Anything you post in a public space is public, we cannot control who reads or copies it, and you should not put anything confidential there.
  • Who has access: Anyone who can see the space you posted in.

Social media

  • Purpose: To run our own accounts, to respond to people who contact us or mention us there, and to reach an audience through the platform's own tools.
  • Categories of personal data: Your handle, your profile as the platform displays it, and what you send or post to us.
  • Legal basis for use: Legitimate interest in maintaining a public presence and replying to people who approach us.
  • Who has access: Us, and the platform, which sets its own terms. We are not responsible for how a platform handles your data, and its privacy notice governs that rather than ours.

Public social media research and monitoring

  • Purpose: To understand the market we work in and the conversations happening in it, to research competitors, to assess how our own content performs and improve it, to find public discussions worth taking part in, and to identify people and organisations we may approach about our services.
  • Categories of personal data: The post itself, the handle or profile name it was published under, and the public information the platform attaches to it such as timing and engagement. Where a post contains personal data about its author or about someone else, we receive that too.
  • Legal basis for use: Legitimate interest in understanding our market and in reaching the people our services are for. We assess that interest against yours before relying on it, and apply the limits set out below.
  • Who has access: Us, and the content and monitoring providers described in section 6.

The limits we apply. Our output is aggregate. What we produce is a finding about a market, a topic, a client or our own content, rather than a record about a person. Posts we have taken in are kept only for as long as the analysis takes and in any event no longer than twelve months, after which what survives is the aggregate finding. You can object at any time by contacting us at privacy@startupblacksmith.com and, subject to verification of your identity, we will exclude your handle from future collection.

Legal compliance and legal claims

  • Purpose: To comply with applicable law, to respond to lawful requests and legal process, and to establish, exercise or defend legal claims.
  • Categories of personal data: Whatever the specific requirement calls for.
  • Legal basis for use: Compliance with legal obligations, and legitimate interest in defending our position.
  • Who has access: Us, our professional advisers, and the relevant authorities or courts.

We do not use automated decision-making that produces legal effects or similarly significant effects on you.


4. Information you give us in confidence

Some of what we collect is expressly designated confidential to you. Where we designate material in that way at the point we collect it, which covers our confidential questionnaires and the confidential parts of interviews and sessions, the following applies.

  • It is not disclosed to your employer, to anyone who works for them, or to anyone else, in a form that identifies you or from which you could reasonably be identified.
  • It is reported only in aggregated or de-identified form, and it is not attributed to any individual.
  • Where a matter you raised has to be reported, it is reported as a general pattern rather than as a position held by a person.
  • We do not ask anyone to assess, rate or comment on the performance of a named colleague.

Your employer has agreed to this in writing. Our engagement terms with each client contain a matching provision, by which the client acknowledges that this material is given to us in confidence by the individual rather than by the company, agrees that it is not theirs to receive in identifiable form, and accepts that it is not theirs to waive. That holds notwithstanding that they are our counterparty and you are their personnel, and it survives the engagement ending.

Your rights over material designated in this way. We will confirm to you what we hold, and we will delete it on request, and we will not release it to your employer.

What this section does not cover. Information you gave us on your employer's behalf rather than in confidence, and material your employer provided to us directly, are part of the engagement and belong to the client. They are held in confidence as between us and the client, and are used and disclosed as described elsewhere in this notice.

The line is drawn by the setting rather than by the stage of our dealings. Anything you say to us with your employer present is theirs to hear, and this section does not apply to it. That includes any session your employer attends, whether it takes place before we are engaged or during an engagement. Anything you tell us privately and in confidence is covered by this section, whenever you tell us.


5. What we do not do

We do not sell personal data.

We do not disclose personal data to advertising networks, data brokers or data enrichment services.

We do not build persistent profiles of individuals, and we do not use personal data for profiling that produces legal or similarly significant effects.

We do not acquire, use, or allow others to use anonymous data with the intent of identifying or reidentifying individuals. When we receive anonymous data, or transform personal data we have collected into anonymous data, we make the following commitments.

  • We will maintain anonymous data in anonymised form.
  • Except to the extent necessary to confirm that personal data has been transformed into anonymous data, we will not attempt to identify or reidentify specific individuals within an anonymised dataset, or otherwise use anonymous data to attempt to associate specific individuals with individual characteristics, and we will not permit any entity or individual acting on our behalf to do so.

We do not use client material or anything given to us in confidence to train any artificial intelligence model. Artificial intelligence does not determine the professional judgements we deliver.

We do not carry anything identifiable between engagements. What we take forward is methodology, generalised so that no trace of a client or an individual remains in it.

We do not name a client, use their marks or publish a case study about them without their prior explicit written consent. Engaging us is not itself permission to refer to the engagement.


6. Who has access to your personal data

Access inside our firm is restricted by name to the people performing the relevant engagement. Access to material covered by section 4 is narrower still.

Outside our firm, we give access to the following categories of recipient.

  • Productivity and storage providers, for documents, collaboration and email.
  • Our website host, which generates the server records described in section 2.
  • A recording and transcription provider, where a session is recorded with consent.
  • A collaboration and whiteboarding provider, for session materials.
  • External contractors engaged for a specific engagement, where specialist work is required.
  • A mailing provider, where you have subscribed to something we send.
  • A content, publishing and social monitoring platform, for the research described in section 3.
  • Social media platforms, in respect of our own accounts and what you send us there.
  • Artificial intelligence providers, on the terms described in section 5.
  • Electronic signature, accounting, payment, legal and insurance providers.

Each is engaged on terms requiring them to process personal data only on our instructions and to maintain appropriate security. On request we will identify the specific providers within a category, limited to the categories to which the person asking is actually exposed.

Additional recipients. We also disclose personal data:

  • To the relevant client, subject to section 4;
  • To our professional advisers, where reasonably necessary;
  • To legal and regulatory authorities, to comply with applicable law, to respond to lawful requests and legal process, to establish, exercise or defend legal claims, and to protect the rights, property or safety of any person;
  • To a successor or acquiring business, in connection with a reorganisation, merger, sale, financing or transfer of our business, and in insolvency, in each case subject to the recipient being bound by obligations no less protective than these; and
  • To anyone else with your consent, or at your direction.

7. International transfers

We and our service providers operate in a number of jurisdictions, so your personal data may be transferred to and processed in countries other than the one in which it was collected, and those countries may have different data protection laws.

Where a transfer is subject to a legal transfer requirement, we put an appropriate safeguard in place, which may include standard contractual clauses or an equivalent mechanism recognised by the applicable law. We will tell you which mechanism applies on request.


8. Security

We protect and safeguard your personal data in accordance with applicable law, our own security policies and this notice. We use generally accepted standards of administrative, technical and physical security to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorised access and destruction, in consideration of the risks associated with the personal data and its processing, and we require the same standard of protection from our service providers. Access to personal data is restricted by name to the people performing the relevant engagement, and those people are required to treat it as confidential. Despite these precautions, no organisation can guarantee that unauthorised access will never occur.

If a breach affects you, we will tell the affected client without undue delay, and where required the affected individual and the relevant authority, and we will give the information reasonably needed to understand and respond to it.


9. How long do we keep your personal data

We keep personal data only for as long as it is needed for the purposes described in this notice, or for longer where the law requires it.

Enquiries that do not lead to an engagement are deleted within twelve months, unless retention is necessary for a legal claim.

Public posts we have taken in for research are deleted once that analysis is finished, and in any event within twelve months. What survives is the aggregate finding, which identifies nobody.

Engagement material. Working material is deleted as the engagement proceeds and when it is no longer needed for the work in hand. At the end of an engagement, everything received from or about the client, including working copies and derived analysis, is compiled into a single encrypted archive, given to the client, and deleted from our systems. We confirm that deletion in writing.

Backups. Client material is excluded from our backup systems, so that deletion is effective and no residual copy survives in backup.

Third party holders. Where a service provider holds client material, deletion propagates through that provider's own systems on the terms they publish, which may allow a limited period for complete removal.

Business records. Contractual, financial and tax records are kept for the periods the law requires.

If you ask us to delete your personal data, we will comply with applicable law and will make reasonable attempts to delete all instances of it, subject to our right to keep a copy for the purposes described above. For requests for access, correction or deletion, and in particular where the processing is based on your consent, please refer to section 11 of this notice.


10. Data collection from children

Our services are directed to businesses and not to children. We do not intentionally use our website, our services or our research to collect or hold personal data from children, and we do not knowingly collect personal data from anyone under the age of 16.

Individuals under the age of 16 should not provide us with personal data, and should not post to us in a public space or on a social platform expecting us to read it. If we learn that we hold personal data provided by someone under the age of 16, we will delete it. If you believe we hold personal data about a child, contact us at privacy@startupblacksmith.com and we will delete it.

Where the law that applies to you sets a higher age, or requires the consent of a parent or guardian above that age, we apply that requirement instead.


11. Your rights, and how to exercise them

Subject to the data privacy laws in your jurisdiction, including the exceptions in them, you may have the following rights in relation to the personal data we hold about you:

  • Right to request information about the personal data we hold about you, including how we use it, who has access to it and the terms on which third parties have access to it;
  • Right to request a copy of the personal data we hold about you;
  • Right to request that we correct or otherwise amend your personal data where it is not correct, complete, timely or accurate for the purposes for which we are using it;
  • Right to request deletion of your personal data;
  • Right to request that we cease processing, or restrict or limit our processing of, your personal data;
  • Right to object to processing based on our legitimate interest, including for marketing;
  • Right to request portability of your personal data, so that you receive a copy in a structured, commonly used and machine-readable format and can transmit it to another controller;
  • Right to withdraw a consent you gave, including consent to recording, where consent is the basis of our processing, without affecting anything done before you withdrew it; and
  • Right not to be discriminated against for exercising your rights in relation to your personal data.

Please note that applicable laws include exceptions which may prevent us from giving access to your personal data or otherwise fully complying with a request. Where we believe an exception applies, we will respond to the extent we are able to and explain the basis for not complying wholly or partly with the request.

How to make a request. Email privacy@startupblacksmith.com.

What happens next. We acknowledge your request within ten business days. We may ask for information reasonably needed to confirm who you are before we act, and we may decline where we cannot confirm it. We respond within thirty business days, or sooner where the law requires, and where we need longer we will tell you why. There is no charge, except where the law allows one for a request that is manifestly unfounded or excessive.

Someone acting for you. You may appoint someone to make a request on your behalf. We will ask you to confirm your own identity and ask them for written evidence of their authority.

Where the data belongs to a client engagement, we will pass your request to that client and help them respond.

If you are not satisfied, tell us and we will look at it again. You may also complain to the data protection authority in your jurisdiction.


12. Third party websites

Our website may link to sites operated by other people. We do not control them and we are not responsible for their content or their privacy practices. Their own notice governs your use of their site.


13. Which data protection laws apply

We are not established in the European Union or the United Kingdom. We do not target our services to those territories, we do not track visitors, and we do not monitor the behaviour of individuals in them.

Where an engagement involves personal data relating to individuals in the European Union or the United Kingdom, we apply the standards in this notice to that data, and we will enter into a data processing agreement with a client on request.

Where the Personal Data Protection Act B.E. 2562 (2019) of Thailand applies to our processing, we comply with it.

Nothing in this section limits any right available to you under the law that applies to you.


14. Changes to this notice

We may change this notice as our business or the law changes. The current version and its date appear at the top of this page. Where a change is material, we will tell clients and anyone with a matter open with us directly, as well as publishing it here.


15. Contact us

We welcome questions, comments and feedback on this notice and on how we handle personal data.


Ready to break through?

Start with a no cost preliminary analysis.