Privacy Policy
Introduction
The ESG Institute Limited ("the Company", "we", "us") is committed to protecting the personal data entrusted to us and to using it only in accordance with applicable data‑protection legislation. This Privacy Policy explains how we collect, use, disclose, store and protect personal information in the course of our operations, including training, consultancy, research services and community management. It also sets out the rights available to data subjects.
Legal Framework
The Company is established in the Isle of Man and is therefore subject to the Data Protection Act 2018 (Isle of Man), which gives direct effect to the United Kingdom General Data Protection Regulation (UK GDPR) via the Applied GDPR. Where we process personal data in the European Economic Area or transfer data to the EEA, we comply with the EU GDPR. We also observe relevant sectoral regulations, including the Telecommunications (Security) Act 2021 (IoM) for electronic communications and any guidance issued by the Isle of Man Information Commissioner. The ESG Institute is registered with the Isle of Man Information Commissioner as a data controller, registration number R857425. The public register can be searched at https://icoregister.powerappsportals.com/
Scope
This Policy applies to all personal data processed by the Company relating to clients, programme participants, members, employees, contractors, suppliers, website visitors and any other identifiable individual. It covers processing carried out in any location and by any means, including paper files, electronic systems, CCTV, portable devices and community platforms.
Key Definitions
Personal data means any information relating to an identified or identifiable person. Special category data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade‑union membership, genetic or biometric data, health data and data concerning a person's sex life or sexual orientation. Processing covers any operation performed on personal data, such as collection, storage, alteration, disclosure or destruction.
Principles of Processing
We process personal data lawfully, fairly and transparently; for specified, explicit and legitimate purposes; only to the extent necessary; with accuracy; for no longer than necessary; and with appropriate security. These principles guide our decisions about what data to collect and how to handle it.
Lawful Bases
We rely on one or more of the following bases under Article 6 of the Applied GDPR: performance of a contract with the data subject; compliance with a legal obligation; legitimate interests pursued by the Company or a third party (balanced against the rights of the individual); consent where required; protection of vital interests; or performance of a task carried out in the public interest.
Special category data is processed only where an additional condition in Article 9 applies, such as explicit consent or the fulfilment of employment-law obligations.
For marketing and promotional communications, we rely on consent where required, or on legitimate interest where a professional relationship exists and communications are relevant to the recipient's role or interests.
Collection and Use of Personal Data
We collect personal data directly from individuals (e.g., when they register for a course, sign up to a membership plan, join our global network in Circle.so, request information, apply for employment or sign up to a mailing list) and from third parties such as employers, referees or publicly available sources. The data collected typically includes name, contact details, role, organisation, payment information, course records and community profile information. We use this information to deliver our services, manage relationships, administer the website and community platform, comply with legal duties, improve our offerings and, where permitted, send relevant communications. These communications may include information about our programmes, services, partnerships and opportunities that we believe may be relevant to you. Such communications are sent on the basis of your consent or, where appropriate, our legitimate interest in maintaining an ongoing professional relationship. You may withdraw your consent or opt out at any time by following the unsubscribe instructions provided in our emails or by contacting us directly. We do not sell personal data.
Community Platform (Circle.so) Data Processing
The ESG Institute operates a members community on Circle.so. Circle acts as a data processor on our behalf. The following clarifications apply:
When you join our community, you create a profile and account with Circle.so. Circle acts as a data processor on our behalf under a data processing agreement. Circle collects and processes data about your account activity, including login patterns, posts, comments, interactions and engagement. Circle also collects technical data such as device identifiers, browser information, mouse movements, scrolling, keystrokes and other browsing behavior to improve the platform experience. Circle processes certain profile information you choose to share (name, photo, bio, expertise areas, location). The ESG Institute retains responsibility for how member data is used, but Circle may also process data according to their own terms. For full details of Circle's data handling, please refer to Circle's Privacy Policy at https://circle.so/privacy. If you are located in the European Economic Area, UK or Switzerland, please also review Circle's EU Privacy Policy at https://circle.so/eu-privacy
Member Profile Data & Visibility
When you join our community, you create a member profile. The information you include on your profile (photo, bio, expertise, location, social links) is visible to other community members by default, unless you choose to restrict visibility through your privacy settings. You have full control over what information you display on your profile. The ESG Institute does not share member profile information with external parties without your consent, except where required by law.
Direct Messaging & Communication
"Members may send private messages to each other within Circle.so. Both the ESG Institute and Circle may receive and process the content of messages you send and receive, including the message content and metadata (such as when messages were sent or received). The ESG Institute does not routinely access or monitor private messages, but reserves the right to do so if necessary to enforce community guidelines, investigate complaints, or comply with legal obligations. Circle may access messages as part of their platform operations and security practices. Messages are retained by Circle in accordance with their data retention policies. For questions about how Circle handles message data, please refer to Circle's Privacy Policy at https://circle.so/privacy.
Content Moderation & Member Posts
Posts, comments and content shared in the community are subject to our Community Guidelines. The ESG Institute, through designated staff and community volunteers, reviews and moderates content to ensure compliance with these guidelines. Content that violates our guidelines may be removed, flagged or reported. Moderation actions are taken to maintain a respectful, professional and safe community environment. Members retain ownership of their content but grant the ESG Institute the right to remove or modify content that breaches community standards.
Networking & Data Connections
Members connect with each other within the community, share expertise, and may exchange contact details or form professional relationships. The ESG Institute facilitates these connections but is not responsible for how members use each other's personal data after they have shared it directly. Members are responsible for respecting one another's data and privacy. Any disputes over data use between members should be resolved directly between those individuals.
Cookies & Analytics on Circle.so
Circle.so uses cookies and analytics tools to collect information about member engagement, including pages visited, features used, time spent in the community and interaction patterns. This data helps the ESG Institute understand how members use the platform and improve the community experience. Analytics data is treated confidentially and is not shared with external parties. You can control cookie preferences through your browser settings or Circle's cookie-management tool.
AI and Automated Features
Circle may offer AI-powered features to help community owners and members create and interact with content. These features are provided through Circle and operate using AI models built by trusted third-party providers. Your personal data may be used to generate responses and enhance your community experience. However, your data will not be used to train, fine-tune, or improve external AI models. All data processed by AI features is handled securely and these providers retain it only for the limited period necessary to provide the feature and monitor for misuse. If you have concerns about AI-powered features, please contact us at team@the-esg-institute.org.
Data Sharing and Disclosure
Personal data may be shared with trusted third‑party service providers who perform functions on our behalf, such as IT hosting, payment processing, certification bodies, community platform providers and professional advisers. These parties are bound by confidentiality and data‑processing agreements. We may also disclose data where required by law, to protect vital interests or to establish, exercise or defend legal claims. International transfers outside the Isle of Man and the UK are made only where an adequacy decision exists or appropriate safeguards (such as standard contractual clauses) are in place.
Security Measures
We implement technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Measures include encryption, access controls, secure email, regular penetration testing, staff training and incident‑response procedures. All employees and contractors are required to adhere to the Company's Information‑Security Policy and to report any suspected data breach immediately to the DPO. Circle.so also maintains security measures to protect data processed on the platform.
Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, to satisfy legal, accounting or reporting requirements, or to protect the Company's legitimate interests. Retention periods are documented in the Data‑Retention Schedule. When data is no longer required, it is securely deleted or anonymised. Community member data is retained for as long as your membership is active and for a reasonable period afterward to fulfil contractual and legal obligations.
Data Subject Rights
Under the Applied GDPR, individuals have the right to: access their personal data; rectify inaccuracies; erase data in certain circumstances ("the right to be forgotten"); restrict processing; object to processing based on legitimate interests or direct marketing; and obtain data portability. No decision producing legal or similarly significant effects is made solely by automated means. Requests should be submitted in writing to the DPO, who will respond within one month, subject to extensions permitted by law.
You can object at any time to receiving marketing communications from us, and we will promptly respect your preference.
Community members can also manage privacy settings directly within Circle.so, adjust notification preferences, or request account deletion through their Circle profile settings. For requests related to data processed by Circle.so, you may also contact Circle directly at legal@circle.so.
Cookies and Online Tracking
Our website uses essential cookies to enable core functionality and analytics cookies to understand usage patterns. Where non‑essential cookies are employed, we seek user consent via a cookie banner. Cookie preferences can be adjusted at any time through the browser's settings or the website's cookie‑management tool. Circle.so uses cookies as described in their Privacy Policy.
Data Breaches
A personal‑data breach is any incident that compromises the confidentiality, integrity or availability of personal data. All suspected breaches must be reported to the DPO without delay. Where the breach is likely to result in a risk to individuals' rights and freedoms, the DPO will notify the Isle of Man Information Commissioner within seventy‑two hours and, where required, communicate the breach to affected individuals promptly. This includes breaches affecting data processed on Circle.so. If Circle experiences a data breach affecting your information, Circle will notify affected individuals in accordance with applicable data protection laws and their own breach notification procedures. The ESG Institute will coordinate with Circle to ensure appropriate notification to affected members.
Contact Details
Questions, requests or complaints regarding this Policy or our data‑processing practices should be directed to:
Data Protection Officer
The ESG Institute Limited
21 Keeill Pharick Park
Email: mail@the-esg-institute.org (Subject: Data Protection Enquiry)
Individuals also have the right to lodge a complaint with the Information Commissioner, PO Box 69, Douglas, Isle of Man, IM99 1EQ (www.inforights.im) if they believe their data‑protection rights have been infringed.
Review
This policy is to be reviewed every two years, or earlier if there are significant changes in law or our operations.
Latest update: June 25, 2026.
This Policy is non‑contractual and may be amended at the Company’s discretion.