Privacy Notice

Last updated: 4th August 2026

Registered name: Geostrategy Limited (T/A Council on Geostrategy).

We are the controller of your personal data. For more information on controllers and their responsibilities please see our guidance on data protection principles, definitions, and key terms.

This privacy notice tells you what to expect us to do with your personal information.

1.0 Contact details

  • Post: Council on Geostrategy, Alliance House, 12 Caxton Street, London, SW1H 0QS, United Kingdom
  • Telephone: 0044 (0) 20 3915 5625
  • Email: [email protected]

2.0 What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details
  • Addresses
  • Gender
  • Occupation
  • Payment details (including card or bank information for transfers and direct debits)
  • Transaction data (including details about payments to and from you and details of products and services you have purchased)
  • Usage data (including information about how you interact with and use our website, products and services)
  • Health information (such as medical records or health conditions)
  • Information relating to compliments or complaints
  • Video recordings
  • Audio recordings (e.g., calls)
  • Records of meetings and decisions
  • Account access information
  • Website user information

We also collect or use the following special category information to provide and improve products and services for clients. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information for the operation of client or customer accounts:

  • Names and contact details
  • Addresses
  • Purchase or service history
  • Account information, including registration details
  • Information used for security purposes
  • Marketing preferences
  • Technical data, including information about browser and operating systems

We also collect or use the following special category information for the operation of client or customer accounts. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Profile information
  • Marketing preferences
  • Purchase or account history
  • Website and app user journey information
  • IP addresses

We collect or use the following personal information for scientific or historical research purposes, for statistical purposes or for archiving in the public interest:

  • Names and contact details
  • Addresses
  • Purchase or client account history
  • Website and app user journey information
  • IP addresses
  • Political opinions

We collect or use the following personal information to comply with legal requirements:

  • Name
  • Contact information
  • Identification documents
  • Client account information
  • Health and safety information
  • Any other personal information required to comply with legal obligations

We also collect or use the following special category information to comply with legal requirements. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information for recruitment purposes:

  • Contact details (eg name, address, telephone number or personal email address)
  • National Insurance number
  • Copies of passports or other photo ID
  • Employment history (eg job application, employment references or secondary employment)
  • Education history (eg qualifications)
  • Right to work information
  • Security clearance details (eg basic checks and higher security clearance)

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details
  • Addresses
  • Payment details
  • Account information
  • Purchase or service history
  • Customer or client accounts and records
  • Information relating to health and safety (including incident investigation details and reports and accident book records)
  • Correspondence

3.0 Lawful bases and data protection rights

Under UK data protection law, we must have a ‘lawful basis’ for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website. Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

If you make a request, we must respond to you without undue delay and in any event within one month. To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

4.0 Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we are collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • We process personal information (such as contact details, event attendance, and feedback) to manage and deliver our policy research, events, and membership services, and to evaluate and improve the quality of our work. This processing is necessary to coordinate event logistics, tailor research outputs to relevant stakeholders, and understand participant needs. Without this data, we could not effectively deliver our core services or refine our policy work. The primary benefit is providing stakeholders and members with relevant, high-quality research and well-managed policy events. Privacy risks are minimal as we collect standard, professional contact and administrative data, maintain strict security measures, limit data retention, and respect individual opt-outs. As participants reasonably expect a non-profit think tank to process professional data for these administrative and operational improvements, the benefits outweigh the minimal impact on individual privacy rights.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we are collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • We process personal information associated with user accounts to administer memberships, manage user profiles, authenticate account access, and maintain the security of our website and databases. This processing is necessary to provide users with secure, reliable access to their membership benefits, account settings, and event activity logs, and to protect our platform from unauthorised access or misuse. The primary benefit to individuals is a seamless, secure account experience where they can manage their details and access member resources. The benefit to our organisation is maintaining accurate member records and ensuring platform security. Privacy risks are minimal, as processing is limited to standard account data, access logs, and preferences – all of which users reasonably expect when creating an account, and which are protected by strict access controls and security measures.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent – we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Legitimate interests – we are collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • We process professional contact details to send targeted policy updates, research publications, and event invitations to existing members, business contacts, and relevant industry stakeholders. This processing is necessary to engage key audiences with our research, promote informed public debate, and fulfil our core mission as a policy think tank. The primary benefit to recipients is receiving timely, relevant analysis, policy insights, and networking opportunities directly aligned with their professional work. The benefit to our organisation is building an active, informed network of supporters and policy partners. The impact on individual privacy is low, as we primarily process professional contact details, ensure communications are contextually relevant, and provide an easy, clear opt-out or unsubscribe mechanism in every email.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information to comply with legal requirements:

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

Our lawful bases for collecting or using personal information for recruitment purposes are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we are collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • We process personal information (such as curriculum vitaes, cover letters, work history, and candidate contact details) to evaluate applicant suitability, manage the application and interview process, and communicate with job candidates. This processing is necessary to assess qualifications, arrange interviews, make informed hiring decisions, and maintain administrative records of our recruitment process. The primary benefit to applicants is receiving fair and structured consideration for job opportunities. The benefit to our organisation is recruiting qualified personnel to support our policy research and operational goals. Privacy risks are minimal as we only process data relevant to employment applications, restrict access strictly to hiring personnel, store records securely, and retain candidate data only for as long as necessary to complete the hiring process and fulfil record-keeping requirements.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we are collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
    • We process personal information (such as contact details, correspondence history, and details relevant to queries or disputes) to address inquiries, investigate complaints, resolve issues, and defend against potential legal claims. This processing is necessary to communicate effectively with individuals, address concerns raised about our services, uphold quality standards, and maintain accurate administrative records for dispute resolution or legal defence. The primary benefit to individuals is receiving timely, accurate responses and fair resolutions to their complaints or inquiries. The benefit to our organisation is maintaining quality standards, managing public relations, and protecting our legal position. Privacy risks are minimal because individuals voluntarily supply this information to receive assistance. We limit processing strictly to what is relevant to the matter, restrict access to appropriate staff, store details securely, and retain records in line with statutory limitation periods.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

5.0 Where we get personal information from

  • Directly from you
  • CCTV footage or other recordings
  • Publicly available sources
  • Previous employment
  • Suppliers and service providers
  • Third parties:
    • We occasionally receive personal information (e.g., participant registration lists for joint events) from partner organisations and co-hosts, such as government organisations, academic institutions, think tanks, and corporate sponsors, as well as third-party ticketing or event management platforms.

6.0 How long we keep information

Data categoryRetention
Subscribers (Active)Duration of active subscription
Subscribers (Lapsed and Former)2 years for potential re-engagement
Members (Active)Duration of active membership contract
Members (Lapsed and Former)2 years post-membership expiration
Associate fellowsDuration of fellowship plus 1 year post-departure
Standard event attendees2 years from event conclusion
Dietary and accessibility logsMax. 1 month post-event conclusion
Identifiable research data3 years post-project completion
Anonymised research data5 years (subject to regular review)
Employee personnel files6 years after worker termination
Payroll and tax records6 years from end of relevant tax year
Unsuccessful job applicants6 months from application close

For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.

7.0 Who we share information with

7.1 Data processors

7.1.1 Cloud hosting and information technology infrastructure providers (UK, EU, US)

This data processor does the following activities for us: Host our website, manage information technology infrastructure, and provide secure cloud storage.

7.1.2 CRM and database platforms (UK, EU, US)

This data processor does the following activities for us: Store and manage member records, event participant contact lists, and organisational contact history.

7.1.3 Email and marketing platforms (UK, EU, US)

This data processor does the following activities for us: Distribute newsletters, research papers, policy briefings, and event invitations.

7.1.4 Virtual event and video conferencing platforms (UK, US)

This data processor does the following activities for us: Process registrations and host live webinars, digital panel discussions, and virtual meetings.

7.1.5 Financial accounting and payment gateways (UK, EU, US, New Zealand)

This data processor does the following activities for us: Manage employee salaries, pensions, tax records, financial accounting, and receive payments.

8.0 Others we share personal information with

  • Professional or legal advisors
  • External auditors
  • Organisations we are legally obliged to share personal information with
  • Publicly on our website, social media or other marketing and information media
  • Suppliers and service providers
  • Third parties:
    • We occasionally share personal information (e.g., participant registration lists for joint events) with partner organisations and co-hosts, such as government organisations, academic institutions, think tanks, and corporate sponsors, as well as third-party ticketing or event management platforms.

9.0 Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Organisation name: Cloud storage and communications providers (i.e., Google Workspace, Microsoft 365)

Category of recipient: Information Technology – cloud storage, document management, productivity software, and corporate email hosting

Country the personal information is sent to: United States and European Economic Area (EEA)

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

Organisation name: Web publishing, marketing and social management platforms (i.e., WordPress, Substack, Canva, Social Champ)

Category of recipient: Digital media and marketing technology – website content management, digital newsletters, graphic design, and social media scheduling software

Country the personal information is sent to: United States and Australia

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

Organisation name: Financial accounting and payment gateways (i.e., Xero, Dext, Stripe, GoCardless)

Category of recipient: Financial technology – cloud accounting software, invoice processing, online payment gateways, and direct debit handling

Country the personal information is sent to: New Zealand, United States, and European Economic Area (EEA)

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

Where necessary, our data processors will share personal information outside of the UK. When doing so, they comply with the UK GDPR, making sure appropriate safeguards are in place.

For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Organisation name: Cloud storage and communications providers (i.e., Google Workspace, Microsoft 365)

Category of recipient: Information Technology – cloud storage, document management, productivity software, and corporate email hosting

Country the personal information is sent to: United States and European Economic Area (EEA)

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

Organisation name: Web publishing, marketing and social management platforms (i.e., WordPress, Substack, Canva, Social Champ)

Category of recipient: Digital media and marketing technology – website content management, digital newsletters, graphic design, and social media scheduling software

Country the personal information is sent to: United States and Australia

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

Organisation name: Financial accounting and payment gateways (i.e., Xero, Dext, Stripe, GoCardless)

Category of recipient: Financial technology – cloud accounting software, invoice processing, online payment gateways, and direct debit handling

Country the personal information is sent to: New Zealand, United States, and European Economic Area (EEA)

How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)

10.0 How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us:

Email: [email protected]

If you remain unhappy with how we have used your data after raising a complaint with us, you can also complain to the Information Commissioner’s Office (ICO). 

The ICO’s address is:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint