
Data Privacy Statement
Competence Development Network LLP · 1103 – 11871 Horseshoe Way, Richmond, BC V7A 5H5, Canada · BC Registry LL03276
Effective date: 4 September 2026 · Replaces the version of 2 January 2026
Competence Development Network LLP ("CDN", "we", "us") provides organisational development, leadership training, coaching and learning design for client organisations. We are established in British Columbia, Canada, and deliver our services internationally, including in the European Union.
This statement explains what we do with personal data. It applies under the General Data Protection Regulation (GDPR) to everyone in the European Union, and under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation in Canada. Where the two differ, we apply the stricter rule.
The controller is Competence Development Network LLP at the address above. For anything concerning privacy, write to [email protected].
Because we have no establishment in the Union, we have appointed a representative under Article 27 GDPR. You may contact the representative on all questions concerning the processing of your personal data, in addition to contacting us directly:
Prighter Germany GmbH, c/o Luther Rechtsanwaltsgesellschaft mbH, Heidestraße 40, 10557 Berlin, Germany
Our representative also maintains a page where you can send us a privacy request directly: https://app.prighter.com/portal/cdnllp
Supervisory authorities may address the representative in the same way.
People at client organisations: name, job title, business contact details, correspondence, and notes from meetings and calls.
Participants in our programmes and coaching clients: name, business email address, the group they belong to, attendance, scheduling, and what they write in the closed programme area described in section 6.
Trainers and coaches in our network: name, contact details, professional background, engagement dates, invoicing and payment data. For the trainers whose profiles we publish: photograph, career history and qualifications.
Website visitors: access data such as IP address, time, page requested and browser, together with aggregate usage statistics.
People who write to us: name, email address, organisation, and the content of the message.
Applicants to the network: CV, contact details, qualifications.
Some coaching work touches sensitive matters. Anything a participant chooses to share in a coaching conversation stays in that conversation, as described in section 5. We do not ask for health data.
Where we rely on legitimate interests, that interest is running a professional services business and delivering what a client has engaged us to do. You may object at any time, as described in section 9.
Providing your data is not a statutory requirement. It is necessary to enter into or perform a contract with us: without contact details we cannot deliver a programme, answer an enquiry or issue an invoice.
We work with service providers who process personal data on our behalf under a contract that binds them to our instructions. We do not sell personal data, and we do not share it for anyone else's marketing.
Beyond these, we disclose personal data to co-facilitators and subcontractors involved in delivering an engagement, all bound by confidentiality; to our banks and payment providers, who act as controllers in their own right; to our accountants and legal advisers; and where the law requires it.
What a client organisation receives depends on the format of the work.
Participants of some programmes have access to a closed area on this website.
Signing in works without a password. You enter your work email address and receive a one-time link, valid for twenty minutes and usable once. The link sets a signed session cookie that keeps you signed in for sixty days. This cookie is necessary for the service and is not used for any other purpose.
Some programmes include an AI coach for the months between modules. It states that it is an AI system. Your conversations with it belong to you: nobody else reads them, not your programme lead, not your employer, not the HR team. There is no administrative view and no export. The coach keeps a small set of notes so that it remembers what you were working on; you can see those notes and delete any of them, a single conversation, or everything, at any time. The coach assesses nobody and reports nothing to your employer, and we ask participants not to use the real names of colleagues. Conversations run through a model operated by Anthropic on our instructions.
Your access and your conversations remain until the programme area closes, which is the end of your programme plus two months. After that date the sign-in link no longer works and your address and conversations are deleted. If you want your data removed earlier, tell us and we will do it; you will lose access at that point.
We are established in Canada, and several of our service providers are in the United States. Personal data of people in the European Union is therefore transferred outside the EU.
Ask us and we will tell you which safeguard applies to a particular transfer, and give you a copy of it.
We delete or securely destroy personal data once these periods end, unless a legal obligation requires us to keep it longer.
Under the GDPR you have the right to obtain confirmation whether we process your data and to receive a copy of it; to have inaccurate data corrected; to have data erased; to have processing restricted; to receive your data in a machine-readable format and to have it transmitted to another organisation; to object to processing based on our legitimate interests; and to withdraw a consent you gave, without affecting what was lawful before.
Under PIPEDA, individuals in Canada have rights of access and correction, and the right to withdraw consent.
To exercise them, write to [email protected], use the request page at https://app.prighter.com/portal/cdnllp, or write to the representative named in section 2. We will acknowledge within five working days and answer within one month. We do not charge for this.
In the European Union you may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. In Canada you may complain to the Office of the Privacy Commissioner of Canada.
We do not use advertising or tracking cookies, and there is no cookie banner because there is nothing to consent to.
Reach measurement on our public pages runs without cookies. It counts page views and does not follow individual visitors across sites.
One cookie is set in the closed programme area, and only after you sign in: a signed session cookie that keeps you signed in for sixty days. Signing out removes it.
You can delete cookies in your browser at any time. Deleting the session cookie signs you out of the closed area.
We do not make decisions about people by automated means that produce legal effects or similarly significant effects. The AI coach described in section 6 gives no assessment of any participant and feeds nothing into any decision about them.
We protect personal data with measures appropriate to the risk: encrypted transmission, encrypted storage on our devices, access limited to those who need it, multi-factor authentication on administrative accounts, confidentiality undertakings with everyone who works on an engagement, and regular backups. No system is absolutely secure, and we say so rather than promise otherwise.
If a breach puts your rights at risk, we will inform you and the competent supervisory authority within the periods the law sets.
Our services are for adults. We do not knowingly collect data from anyone under 18. Where a programme involves young people in an educational setting, consent is obtained through the institution.
Our pages link to services we do not operate. This statement covers only what we do. Once you follow such a link, the other provider's statement applies.
We update this statement when our processing changes. The current version is always the one published here, with its effective date at the top.