Icon Image

Privacy Policy

Last updated: July 2026

 


1. Who we are

CX Council ("we", "us", "our") operates the website at www.cxcouncil.org. We are a peer network for customer experience leaders.

 

For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR, CX Council is the data controller of personal data collected through this website.

 

If you have questions about this policy or how we handle your data, please contact us at:

 

Email: [privacy@cxcouncil.org]

 


2. What data we collect and why

Membership applications

When you apply for membership through our website, we collect your name, job title, company, email address, and any other information you provide in the application form. We use this to assess your application, manage your membership, and communicate with you about CX Council activities.

 

Legal basis: Legitimate interests (assessing and fulfilling membership requests); contract performance (once membership is granted).

Event registrations

When you register for events such as strategy lunches, masterclasses, or online expert sessions, we collect your name, email address, company, and dietary or accessibility requirements where relevant. We use this to organise and run the event and to keep you informed about it.

 

Legal basis: Contract performance; legitimate interests.

Contact and enquiries

When you contact us through the website or by email, we collect your name, email address, and the content of your message. We use this to respond to your enquiry.

 

Legal basis: Legitimate interests.

Website analytics and cookies

We use cookies and similar technologies to understand how visitors use our website and to improve it. This may include data about pages visited, time spent on site, and the device or browser used.

 

Legal basis: Consent (where required by applicable law). You can manage your cookie preferences at any time via the cookie banner on our website.

 


3. Who we share your data with

We do not sell your personal data. We may share it with:

 

HubSpot — we use HubSpot as our CRM and marketing platform to manage contacts, membership applications, and event communications. HubSpot acts as a data processor on our behalf and processes data in accordance with GDPR. For more information, see HubSpot's Privacy Policy.

 

Service providers — we work with a small number of trusted third-party providers (such as event platforms and email tools) who process data strictly on our behalf and under data processing agreements.

 

Legal requirements — we may disclose your data if required to do so by law or in response to a valid legal request.

 


4. International data transfers

Some of our service providers, including HubSpot, may process your data outside the European Economic Area (EEA) or the UK. Where this occurs, we ensure appropriate safeguards are in place, such as the EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), to protect your data to the same standard as within the EEA and UK.

 


5. How long we keep your data

We keep your personal data only as long as necessary for the purposes described in this policy:

 

  • Membership data is kept for the duration of your membership and for up to 3 years afterwards for legitimate business purposes.
  • Event registration data is kept for up to 2 years after the event.
  • Enquiry data is kept for up to 2 years after the enquiry is resolved.
  • Cookie and analytics data is subject to the retention periods of the tools we use (typically 13–26 months).

 


6. Your rights

Depending on where you are based, you have the following rights over your personal data:

 

Under GDPR (EU) and UK GDPR:

 

  • The right to access the personal data we hold about you
  • The right to correct inaccurate or incomplete data
  • The right to have your data deleted ("right to be forgotten"), where applicable
  • The right to restrict or object to processing
  • The right to data portability
  • The right to withdraw consent at any time, where processing is based on consent
  • The right to lodge a complaint with a supervisory authority

 

If you are based in the Netherlands, you may lodge a complaint with the Autoriteit Persoonsgegevens (AP) at www.autoriteitpersoonsgegevens.nl.

 

If you are based in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.

 

To exercise any of your rights, please contact us at [privacy@cxcouncil.org]. We will respond within one month of receiving your request.

 


7. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include access controls, encrypted data transmission (HTTPS), and regular security reviews.

 


8. Children

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us so we can delete it.

 


9. Changes to this policy

We may update this privacy policy from time to time. When we do, we will update the "last updated" date at the top of this page. Where changes are significant, we will notify members directly by email.

 


10. Contact us

For any questions, requests, or concerns about your personal data, please contact:

 

Email: [privacy@cxcouncil.org]

 


 

This privacy policy applies to personal data processed through www.cxcouncil.org and related CX Council communications and events.

 

Shape Image One
Shape Image One