Privacy
Last updated: 4 October 2026
This policy explains how TACT handles personal information when you visit this website, contact us or discuss working with us. Where a coaching or learning engagement involves additional information, we provide the relevant confidentiality agreement and any additional privacy information when the work is arranged.
Who is responsible for your information?
TACT is a trading name of RoleCoach OÜ, the controller for website and business-enquiry information. RoleCoach OÜ is registered in Estonia, registry code 17347179, with its registered office at Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia. For privacy questions or rights requests, email mail@tact.coach.
The laws that apply
Our approach is governed by the EU General Data Protection Regulation and relevant Estonian law. UK data-protection requirements apply where our activities fall within their scope. Where Saudi Arabia’s Personal Data Protection Law (PDPL), its Implementing Regulation and its rules on transfers outside the Kingdom apply, we also apply those requirements.
Other GCC countries have their own legal frameworks. The requirements relevant to an engagement depend on the country, the information and the processing involved. This policy does not remove any rights or protections provided by applicable local law. Additional local information will be supplied where required.
What we collect and where it comes from
- Website visits: Cloudflare, our hosting and security provider, processes technical information such as IP addresses, browser and device information, requested pages and security events to deliver and protect the website.
- Enquiries: your name, contact details, role, organisation and the message or attachments you send us. Email links open your email application; this website has no enquiry submission form.
- Business discussions: correspondence, proposals and information needed to discuss or arrange services. A colleague or organisational sponsor may supply business contact details when arranging work with us.
We ask only for information relevant to the purpose. Please do not include sensitive personal information, confidential participant details or coaching records in an initial enquiry. Providing enquiry information is voluntary, but without sufficient contact details we may be unable to respond or arrange services.
How and why information is used
We use enquiry and business information to answer questions, discuss requirements, prepare proposals, arrange services and maintain the relevant business records. Technical information supports website delivery, security and fault resolution. We may also retain information necessary to meet legal duties or deal with a dispute.
Under GDPR, the relevant lawful basis is:
- Legitimate interests: handling ordinary business enquiries and maintaining a secure website, subject to balancing those interests against your rights.
- Contract: taking steps at your request before entering a contract, or performing a contract with you. Where a contract is with your organisation, ordinary business-contact processing may instead rely on legitimate interests.
- Legal obligation: information required for applicable accounting, tax or other legal duties.
- Consent: uses for which consent is required, including optional marketing where applicable. An enquiry does not subscribe you to marketing.
For information subject to Saudi PDPL, a GDPR lawful basis alone is not sufficient. The applicable PDPL basis must also be met. Consent is used where required; contract, legal or legitimate-interest provisions are used only where their conditions apply. Legitimate interests do not provide a basis for processing sensitive personal data under Saudi PDPL. Such information requires a separate lawful assessment and appropriate safeguards before collection.
Cookies and analytics
This website does not include advertising trackers, visitor analytics or embedded third-party media. TACT does not add tracking cookies. Depending on the security features used, Cloudflare may set essential security cookies. Its cookie information explains those cookies. If optional tracking is introduced, this policy and the relevant consent arrangements will be updated before it is used.
Who may receive information?
Information is available to people who need it to handle an enquiry or the agreed work, and to service providers supporting those activities. The website uses Cloudflare Pages; our business email uses Google services. Providers may process information within their service arrangements. Where relevant, information may also be provided to professional advisers or authorities where required or otherwise lawfully permitted. We do not sell personal information.
For coaching and learning work, the agreement identifies any authorised reporting to a sponsor. Contacting TACT does not authorise unrestricted sharing of personal or confidential information with an employer.
International processing and access
RoleCoach OÜ is based in Estonia and TACT works internationally, including from Saudi Arabia and the UK. Access from those locations and the use of Cloudflare and Google may involve processing outside the country where information was collected, including outside the EEA and Saudi Arabia.
Transfers must meet the law applicable to the information. Under GDPR, this may require an adequacy decision or appropriate safeguards, such as approved standard contractual clauses, with any necessary assessment and supplementary measures. Saudi transfers must separately satisfy the PDPL and the Regulation on Personal Data Transfer outside the Kingdom, including applicable safeguards and risk-assessment requirements. Provider GDPR terms alone do not establish Saudi transfer compliance.
To ask which destinations, recipients and safeguards apply to your information, or request information about relevant safeguards, email mail@tact.coach. Additional details will be provided where the processing requires them.
Retention and protection
Enquiry correspondence is retained while the enquiry and related business discussions remain active, then only where a continuing, documented business or legal reason requires it. If an enquiry leads to work, the retention criteria also include the engagement’s duration, contractual requirements, applicable accounting obligations and relevant limitation periods. Information must be deleted or anonymised when it is no longer required, unless lawful retention is necessary. Hosting providers retain technical information under their applicable service policies.
Personal information must be protected by access controls, appropriate account and device security, and confidentiality arrangements proportionate to the information. Any breach is assessed and reported to the relevant authority and affected individuals where the applicable legal thresholds and deadlines require it.
Your rights and how to exercise them
Under GDPR, subject to applicable conditions, you may request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. You may object to direct marketing at any time. Where consent is the basis, you may withdraw it without affecting processing lawfully undertaken beforehand.
Under Saudi PDPL, applicable rights include knowing how your information is collected and used, access and obtaining a copy in a readable format, correction or updating, requesting destruction when the conditions apply, and withdrawing consent. Rights may be limited by lawful retention requirements or other statutory exceptions.
Send requests to mail@tact.coach. We may need proportionate information to verify your identity. Requests are handled within the applicable statutory period: ordinarily one month under GDPR and 30 days under Saudi implementing rules. Where a lawful extension is necessary, you will be told why and when to expect a response. Requests are normally free; any permitted refusal or charge will be explained.
This website and its enquiry process do not use solely automated decision-making with legal or similarly significant effects.
Complaints
You can raise a privacy concern with us using the contact details above. You can also complain directly to the relevant supervisory authority, including the Estonian Data Protection Inspectorate, the UK Information Commissioner’s Office where applicable, or SDAIA’s National Data Governance Platform for Saudi PDPL matters. Other local complaint routes apply where the relevant country’s law applies.
Policy changes and external websites
We update this page when relevant services, processing or legal requirements change. The date above identifies the current version. External websites have their own privacy policies; links to them do not replace this TACT policy.
