How we handle and protect your personal data.
Last updated and effective: 10 September 2026
In the course of our work we receive confidential business information from our clients, which may contain personal data. We also collect personal data through our website, our engagements, our research, our events and our correspondence.
This notice sets out the personal data we handle, why we handle it, who has access to it, how long we keep it, and the measures and processes by which we protect it. Personal data means information about an identified or identifiable individual. It does not cover information that cannot be attributed to an identifiable individual.
Confidential business information we receive from a client is governed by our engagement terms with that client, and we retain it only for as long as we need it for the purposes for which it was given. Where it contains personal data, this notice applies to that personal data.
We comply with the laws to which we are subject. We collect and use personal data only where we have a legal basis to do so. Where we deal with another business, including a social media platform, a service provider or a client's own systems, we act in accordance with the terms on which that business makes its services available to us.
If you work for one of our clients, we receive some of your personal data from your employer, and our use of that data is governed by our agreement with them. Information you give us directly and in confidence is treated differently, and that is set out in full below.
If you apply to work with us, or you work with us as an employee or contractor, we may give you a separate notice covering that relationship. Where we do, it applies in addition to this one.
You are not required to give us your personal data. Where you choose not to, we may be unable to provide our services properly or to respond to you.
By using our website or dealing with us, you confirm that you have read and understood this notice. If any part of it is unclear, contact us before proceeding.
The Startup Blacksmith is the trading name of Delphi Returns Ltd, a company incorporated in the British Virgin Islands with company number 2118540, whose registered office is at Mandar House, 3rd Floor, Suite 301, P.O. Box 3159, Road Town, Tortola VG1110, British Virgin Islands.
Where we collect and use your personal data as described in this notice, we do so as the party that determines how it is collected, used, protected, disclosed and disposed of, and we are responsible for it.
Where we hold personal data on behalf of a client, that client determines the purposes and we act on their instructions. Where you are one of their people and you want to exercise a right over that data, we will pass your request to them and help them answer it.
Directly from you. When you contact us, when you engage us, when you take part in an interview, questionnaire, session or workshop we run, when you take part in research we conduct, when you subscribe to something we send, when you register for an event, when you post publicly to us or respond to a survey, when you supply services to us, and when you apply to work with us.
From our clients. Where a client engages us, they give us the names, contact details and roles of the people who will take part, and they give us business material that may contain personal data. The client is responsible for having a lawful basis for giving it to us.
From your systems, where a client has given us access. In the course of an engagement we are given access to a client's own tools and records. Those contain personal data about the people who use them.
From people who introduce you to us, and from publicly available sources such as company websites and professional profiles.
From social media platforms. Where you contact us, mention us or post to our accounts, we see what the platform shows us. The platform is responsible for its own handling of your data and its notice governs that rather than ours.
From public posts on social platforms. We read and analyse posts that are already public on platforms such as X, LinkedIn, Telegram and Discord, including posts that have nothing to do with us. We do this through each platform's official interface. Section 3 describes the purpose in full, together with the limits we apply.
Automatically, when you visit our website. Our hosting provider records ordinary request information generated by your browser, which may include IP address, the date and time of the request, the page requested, the referring page and the browser identifier. This is generated by any website and is used to serve pages and to keep the site secure. We do not use analytics, advertising, profiling or session recording technologies, and we do not use cookies for those purposes.
Sensitive personal data. We may collect sensitive personal data directly from you, for instance when you take part in a survey or in user research and give us demographic or other personal details, or when you tell us what you need so that we can accommodate you at a session or an event. We use sensitive personal data only with your consent unless another legal basis exists, an example being a public health requirement. Where we use it for research, analysis and statistical purposes, we use it to produce findings drawn from anonymised datasets.
Combining data. We may combine personal data we receive directly from you with personal data we receive from a client or from another third party, to the extent that all such collection and use is consistent with this notice and with the purposes and access described in section 3. When we combine anonymised data with personal data, we treat the combined information as personal data.
The blocks below set out each purpose, the data used for it, the legal basis where one is required, and who has access.
Where our basis is legitimate interest, we assess whether the use is adequate, proportionate and legitimate before relying on it. Where our basis is consent and you withdraw it, we may be unable to provide part of the service, and withdrawal does not affect anything done before it.
Responding to you, and business development
Delivering an engagement
Recording sessions
User research
Engaging suppliers and advisers
Our people, and people who apply to work with us
Running our business
Keeping our systems and our premises secure
Improving how we work
Marketing
Naming a client in our marketing
Newsletters and alerts
Events, talks and recorded media
Public posts, comments and surveys
Social media
Public social media research and monitoring
The limits we apply. Our output is aggregate. What we produce is a finding about a market, a topic, a client or our own content, rather than a record about a person. Posts we have taken in are kept only for as long as the analysis takes and in any event no longer than twelve months, after which what survives is the aggregate finding. You can object at any time by contacting us at privacy@startupblacksmith.com and, subject to verification of your identity, we will exclude your handle from future collection.
Legal compliance and legal claims
We do not use automated decision-making that produces legal effects or similarly significant effects on you.
Some of what we collect is expressly designated confidential to you. Where we designate material in that way at the point we collect it, which covers our confidential questionnaires and the confidential parts of interviews and sessions, the following applies.
Your employer has agreed to this in writing. Our engagement terms with each client contain a matching provision, by which the client acknowledges that this material is given to us in confidence by the individual rather than by the company, agrees that it is not theirs to receive in identifiable form, and accepts that it is not theirs to waive. That holds notwithstanding that they are our counterparty and you are their personnel, and it survives the engagement ending.
Your rights over material designated in this way. We will confirm to you what we hold, and we will delete it on request, and we will not release it to your employer.
What this section does not cover. Information you gave us on your employer's behalf rather than in confidence, and material your employer provided to us directly, are part of the engagement and belong to the client. They are held in confidence as between us and the client, and are used and disclosed as described elsewhere in this notice.
The line is drawn by the setting rather than by the stage of our dealings. Anything you say to us with your employer present is theirs to hear, and this section does not apply to it. That includes any session your employer attends, whether it takes place before we are engaged or during an engagement. Anything you tell us privately and in confidence is covered by this section, whenever you tell us.
We do not sell personal data.
We do not disclose personal data to advertising networks, data brokers or data enrichment services.
We do not build persistent profiles of individuals, and we do not use personal data for profiling that produces legal or similarly significant effects.
We do not acquire, use, or allow others to use anonymous data with the intent of identifying or reidentifying individuals. When we receive anonymous data, or transform personal data we have collected into anonymous data, we make the following commitments.
We do not use client material or anything given to us in confidence to train any artificial intelligence model. Artificial intelligence does not determine the professional judgements we deliver.
We do not carry anything identifiable between engagements. What we take forward is methodology, generalised so that no trace of a client or an individual remains in it.
We do not name a client, use their marks or publish a case study about them without their prior explicit written consent. Engaging us is not itself permission to refer to the engagement.
Access inside our firm is restricted by name to the people performing the relevant engagement. Access to material covered by section 4 is narrower still.
Outside our firm, we give access to the following categories of recipient.
Each is engaged on terms requiring them to process personal data only on our instructions and to maintain appropriate security. On request we will identify the specific providers within a category, limited to the categories to which the person asking is actually exposed.
Additional recipients. We also disclose personal data:
We and our service providers operate in a number of jurisdictions, so your personal data may be transferred to and processed in countries other than the one in which it was collected, and those countries may have different data protection laws.
Where a transfer is subject to a legal transfer requirement, we put an appropriate safeguard in place, which may include standard contractual clauses or an equivalent mechanism recognised by the applicable law. We will tell you which mechanism applies on request.
We protect and safeguard your personal data in accordance with applicable law, our own security policies and this notice. We use generally accepted standards of administrative, technical and physical security to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorised access and destruction, in consideration of the risks associated with the personal data and its processing, and we require the same standard of protection from our service providers. Access to personal data is restricted by name to the people performing the relevant engagement, and those people are required to treat it as confidential. Despite these precautions, no organisation can guarantee that unauthorised access will never occur.
If a breach affects you, we will tell the affected client without undue delay, and where required the affected individual and the relevant authority, and we will give the information reasonably needed to understand and respond to it.
We keep personal data only for as long as it is needed for the purposes described in this notice, or for longer where the law requires it.
Enquiries that do not lead to an engagement are deleted within twelve months, unless retention is necessary for a legal claim.
Public posts we have taken in for research are deleted once that analysis is finished, and in any event within twelve months. What survives is the aggregate finding, which identifies nobody.
Engagement material. Working material is deleted as the engagement proceeds and when it is no longer needed for the work in hand. At the end of an engagement, everything received from or about the client, including working copies and derived analysis, is compiled into a single encrypted archive, given to the client, and deleted from our systems. We confirm that deletion in writing.
Backups. Client material is excluded from our backup systems, so that deletion is effective and no residual copy survives in backup.
Third party holders. Where a service provider holds client material, deletion propagates through that provider's own systems on the terms they publish, which may allow a limited period for complete removal.
Business records. Contractual, financial and tax records are kept for the periods the law requires.
If you ask us to delete your personal data, we will comply with applicable law and will make reasonable attempts to delete all instances of it, subject to our right to keep a copy for the purposes described above. For requests for access, correction or deletion, and in particular where the processing is based on your consent, please refer to section 11 of this notice.
Our services are directed to businesses and not to children. We do not intentionally use our website, our services or our research to collect or hold personal data from children, and we do not knowingly collect personal data from anyone under the age of 16.
Individuals under the age of 16 should not provide us with personal data, and should not post to us in a public space or on a social platform expecting us to read it. If we learn that we hold personal data provided by someone under the age of 16, we will delete it. If you believe we hold personal data about a child, contact us at privacy@startupblacksmith.com and we will delete it.
Where the law that applies to you sets a higher age, or requires the consent of a parent or guardian above that age, we apply that requirement instead.
Subject to the data privacy laws in your jurisdiction, including the exceptions in them, you may have the following rights in relation to the personal data we hold about you:
Please note that applicable laws include exceptions which may prevent us from giving access to your personal data or otherwise fully complying with a request. Where we believe an exception applies, we will respond to the extent we are able to and explain the basis for not complying wholly or partly with the request.
How to make a request. Email privacy@startupblacksmith.com.
What happens next. We acknowledge your request within ten business days. We may ask for information reasonably needed to confirm who you are before we act, and we may decline where we cannot confirm it. We respond within thirty business days, or sooner where the law requires, and where we need longer we will tell you why. There is no charge, except where the law allows one for a request that is manifestly unfounded or excessive.
Someone acting for you. You may appoint someone to make a request on your behalf. We will ask you to confirm your own identity and ask them for written evidence of their authority.
Where the data belongs to a client engagement, we will pass your request to that client and help them respond.
If you are not satisfied, tell us and we will look at it again. You may also complain to the data protection authority in your jurisdiction.
Our website may link to sites operated by other people. We do not control them and we are not responsible for their content or their privacy practices. Their own notice governs your use of their site.
We are not established in the European Union or the United Kingdom. We do not target our services to those territories, we do not track visitors, and we do not monitor the behaviour of individuals in them.
Where an engagement involves personal data relating to individuals in the European Union or the United Kingdom, we apply the standards in this notice to that data, and we will enter into a data processing agreement with a client on request.
Where the Personal Data Protection Act B.E. 2562 (2019) of Thailand applies to our processing, we comply with it.
Nothing in this section limits any right available to you under the law that applies to you.
We may change this notice as our business or the law changes. The current version and its date appear at the top of this page. Where a change is material, we will tell clients and anyone with a matter open with us directly, as well as publishing it here.
We welcome questions, comments and feedback on this notice and on how we handle personal data.
Start with a no cost preliminary analysis.