Lighthouse Mentoring
Privacy Policy
Version 1.0 · Last updated 3 September 2026
0. The short version
This bit is for everyone, and it is meant to be easy to read. The full detail is below it.
Lighthouse Mentoring runs the mentoring sessions you book here. To make a booking we need your name, your email address, your date of birth and a time. There are other questions too — about what you want to talk about — and you can leave those blank without it stopping your booking. We use what you tell us to set up your session, send you the joining details, and get the right mentor ready for you.
Your mentor also writes notes about your sessions. You can ask to see those notes, and we will show you, unless part of them is about someone else or showing them would put someone at risk — and we will tell you if we have held anything back.
One important thing: what you say in a session is private, but it is not completely secret. If a mentor thinks you or someone else might get seriously hurt, they have to tell someone who can help. They will try to tell you first.
We do not sell your information to anyone, and we do not use it for advertising.
If you want your information deleted, or you are unhappy about how we have handled it, write to us at info@lighthousementoring.org or use the complaint form at https://www.lighthousementoring.org/contact/, and a real person will reply.
1. Who is responsible for your information
Lighthouse Mentoring is the data controller. That means Lighthouse Mentoring decides what personal data is collected here and why, and is answerable to you for it.
Lighthouse Mentoring is a trading name of LIGHTHOUSE MENTORING, RESEARCH & EDUCATION, Company number 16127538, registered at 17314 Legend Brook Ct, Tomball, TX 77375-1065, USA. You can contact us at info@lighthousementoring.org or at that address.
Lighthouse Mentoring's Data Protection Officer can be reached at info@lighthousementoring.org.
Lighthouse Mentoring runs its booking, scheduling and mentoring records on software supplied by Puntoria. For everything to do with your sessions, Puntoria is a data processor: it stores and moves your information on Lighthouse Mentoring's instructions, under a written contract, and does not use it for its own purposes.
There is one exception, and we would rather say it plainly than bury it. Puntoria also measures how its own booking software performs across all the organisations that use it. For that limited purpose it decides things for itself and acts as a controller in its own right, not as Lighthouse Mentoring's processor. Section 11 explains what that involves and how to say no. If you have an account that shows your bookings across more than one organisation, Puntoria is the controller for that account too, and its own privacy notice covers it.
This service is provided from the United Kingdom and this policy is written to the law of England and Wales.
What this policy covers. The booking pages for Lighthouse Mentoring, the emails you get about a session, and the pages those emails link to — for joining your session, managing your booking, giving feedback, or correcting a detail — as well as your account area if you have one.
2. What we collect, why, and on what legal basis
"You" below means the person attending the session. Where an adult books on behalf of a young person, some of this is provided by that adult — see section 2A.
| What we hold | Why we hold it | Lawful basis |
|---|---|---|
| Your name | To identify your booking, address you correctly, and put your name on the calendar invitation | Contract (Art 6(1)(b)) |
| Your email address, and a tidied-up copy of it used to recognise you as the same person across bookings | To confirm your booking, send joining details, reminders, changes and feedback requests, and to keep your bookings together | Contract |
| Your date of birth | To check you are 18 or over, which we require in order to offer you a session. A booking form that gives a date under 18 is refused | Legitimate interests — offering sessions only to adults |
| Your gender | So the mentoring team can take account of it when matching you with a mentor, and so staff can find and group the people they work with. You have to answer it to book: the form offers male and female, has no other answer, and will not let you continue until you choose one | Legitimate interests — matching you with a mentor, and keeping a record of the people Lighthouse Mentoring works with |
| Your phone number, if a mentor's intake question asks for it | So the mentor or organiser can reach you about the session | Contract |
| Your time zone and language | To show session times correctly to you and send communications in the right language | Contract |
| What you want to ask, and topics you want to discuss | So your mentor can prepare for your session | Contract |
| Your answers to a mentor's own intake questions | Same as above — these questions are written by the mentoring team, not by the software | Contract |
| Any message you add when booking, rescheduling or cancelling, including a cancellation reason | To act on your request and understand why plans change | Contract; legitimate interests — running the service |
| Whether you attended or did not turn up | To follow up sensibly, and to manage repeated no-shows fairly | Legitimate interests — running the service |
| Notes your mentor or the organising team write about you: private session notes, the main concerns raised, what you said in response, resources given to you, and suggested areas to improve | To give you continuity between sessions and let a new mentor pick up where the last one left off | Legitimate interests — delivering mentoring properly |
| A summary record of you as someone Lighthouse Mentoring works with: your contact details, your profile picture if you have an account, and how many sessions you have had | So staff can see who they are working with without opening every booking | Legitimate interests — running the service |
| Your feedback: a rating out of five, a rating of your host, and any comment you write | To improve sessions and to supervise mentors | Legitimate interests — quality and safeguarding |
| A moderation record: your standing (good, watchlisted or blocked), the reason, and a timeline of related events | To keep sessions safe for attendees and mentors, and to enforce the Terms | Legitimate interests — safety and enforcing our Terms; where a specific safeguarding concern is involved, recognised legitimate interests (section 4) |
| Your booking reference, the private links we email you, and a combined search string of your name, email and session title used by staff to find your session | To let you manage your booking without an account, and to let staff find the right record | Contract; legitimate interests |
| Account and sign-in records. Most sessions require an account, so this usually applies to you | To sign you in securely and show you your bookings | Contract |
| How you arrived: if you followed a campaign or referral link, the campaign details attached to that link | To understand which of our programmes reach people | Legitimate interests — understanding our own reach |
| When you opened the joining link for a session, and when you used it to go through to the room. Your mentor and Lighthouse Mentoring's staff can see both, on the session's own record, while the session is running | So the person waiting for you knows whether to keep waiting. It records that the link was used, not that you were in the room | Legitimate interests — running the sessions you booked |
| Technical data created automatically when you visit: your IP address, your browser and device type, the pages you looked at on the booking form, and identifiers stored in your browser | To keep the site running and secure, and to see where the booking form is confusing so we can fix it | Legitimate interests — security and running the service; section 11 covers the parts that need your agreement |
What you have to give us. Your name, your email address, your date of birth and a chosen time are needed to make a booking at all — without them we cannot arrange a session. Your gender is required as well: the question offers male and female and nothing else, and the form will not let you past it unanswered, so if you are not willing to answer it you cannot book here. We would rather tell you that than call it optional. Everything else is optional, and leaving it out will not stop you booking, though your mentor may be less well prepared.
Sensitive information. The free-text boxes are yours to fill as you wish, and people sometimes mention health, wellbeing, beliefs or other sensitive things. Please share only what your mentor actually needs — you are never required to. Where information of that kind is necessary to run or prepare for your session, we rely on Article 9(2)(a) UK GDPR (explicit consent), and we ask for that consent separately rather than assuming it from whatever you happen to type. Where a safeguarding concern arises and we cannot ask you first without increasing the risk to you or to someone else, we rely instead on Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018 (safeguarding of children and of individuals at risk). We keep the policy document that paragraph requires, and you can ask us for a copy.
Who can see this inside Lighthouse Mentoring. It is worth being clear that telling your mentor is, in practice, telling the organisation. Your contact details and session history are visible to Lighthouse Mentoring's staff, and staff can search for you by name or email. The notes your mentor writes, the concerns recorded and any moderation flag are visible to staff and to other hosts who may work with you. Your mentor is not a separate confidant from the organisation that employs them.
We do not sell your data, share it with advertisers, or use it to build a marketing profile of you.
2A. Where someone else gives us your details
Sometimes we get your details from someone other than you:
- a mentor or a member of staff who invites you to book — in that case we hold your name and email address, and any note that person wrote about why they were inviting you;
- a mentor who writes down questions to raise with you before you have booked anything;
- a parent, carer, teacher or support worker who books on your behalf — in that case they give us the details in section 2 about you.
We will tell you that we hold it the first time we contact you, and you have all the same rights over it as over anything you gave us yourself — including the right to know who gave it to us.
People are also sometimes mentioned by name inside a session or in something you write. We do not go looking for those people to notify them, because tracing everyone named in a conversation would take disproportionate effort. If you are someone who has been mentioned and you want to know what is held, write to us.
3. Checking that you are 18 or over
Sessions here are for adults. You need to be 18 or over to book, and the booking form asks for your date of birth to check that.
A form that says you are under 18 is refused. The check runs on our own servers, not just in your browser, so a booking cannot get past it: no session is booked and no session record is created. Something is already held by then, though, and we would rather say so. Most sessions here need an account, so you will have signed in before the form asks your date of birth — with a one-time code sent to your email address, or with Google — and that leaves an account holding your email address, your name and the answer you gave to the gender question. The date of birth itself is not kept when it puts you under 18. You can delete that account yourself from your account page, or write to info@lighthousementoring.org and we will delete it for you.
How we check your age. We take the date of birth you type at face value. We do not ask for ID documents. If we later find that someone under 18 has booked, we will cancel the session and delete what we hold about them, and we will write to the email address on the booking to say we have done so.
4. The lawful bases we rely on
Contract (Art 6(1)(b)). Most of what we hold exists because you asked us to arrange a mentoring session. Without a name, an email address and a time, there is no session.
Legitimate interests (Art 6(1)(f)). We rely on this for matching you with a mentor, continuity of mentoring, quality and supervision, keeping sessions safe, preventing abuse of the booking system, keeping a record of the people Lighthouse Mentoring works with, security, and understanding how the booking form performs. In each case we have weighed our interest against your rights and concluded the processing is what you would reasonably expect from a mentoring organisation. You can object at any time (section 9), and we will stop unless we have compelling grounds not to.
Recognised legitimate interests (Art 6(1)(ea) and Annex 1 UK GDPR, inserted by the Data (Use and Access) Act 2025). In the narrow case where we are processing because we have reasonable cause to believe a child or an adult at risk needs protecting from harm or neglect, that is a recognised legitimate interest and no balancing test is required. We do not use this basis for ordinary record-keeping, for no-shows, or for moderation decisions that are not about protecting someone from harm — those rest on ordinary legitimate interests, and you can object to them.
Consent (Art 6(1)(a), and Art 9(2)(a) for sensitive details). We rely on consent for sensitive details where we have asked for them specifically. You can withdraw consent at any time; withdrawal does not undo what was lawfully done before you withdrew. We do not rely on consent for the gender question: it has to be answered before a booking can be made, and a question you are not free to refuse is not one you have consented to. We rely on legitimate interests for it, as section 2 sets out.
Legal obligation (Art 6(1)(c)). Where a specific law requires us to keep or disclose something — for example a court order, or a statutory safeguarding duty where one applies to Lighthouse Mentoring. We will tell you which law we are relying on if you ask.
5. Artificial intelligence
We use Anthropic's Claude models for a small number of clearly bounded jobs:
- helping staff search their own session records in plain language;
- reading what you wrote when booking and telling staff whether the request reads as ready to confirm, or whether to ask you for more detail, point you to a session that fits better, or turn it down;
- reading what you wrote when booking, together with how your earlier sessions with Lighthouse Mentoring went, to suggest which reason best fits a session staff are about to call off;
- drafting the messages staff send you, the questions your mentor prepares for your session, and a first pass at your mentor's notes on it, for a person to edit;
- writing the summary paragraph in the periodic report Lighthouse Mentoring can subscribe to.
What is sent. For a job about your session, what can go to Anthropic is your first name, the session title, the time it is booked for, and what you wrote when booking — and, for the first draft of your mentor's write-up, your full name. If you have sat with Lighthouse Mentoring before, the dates and titles of those sessions go with it, along with what you wrote then, the questions your mentor prepared, and their note on what came up. The free-text box is the part to think about: as section 2 says, people sometimes put health, wellbeing, beliefs or other sensitive things in it, and it goes across in your own words. The first read of a new request is sent your answer and the session title, but not your name. Staff also send the words they type into search, the questions they ask about their own reports, whatever they type as the reason a session cannot go ahead, and the figures behind a periodic report, which can carry the name on the next session in the diary. Under our contract with Anthropic, none of it is used to train their models. Like most providers, they keep it briefly for security and abuse-prevention purposes before deleting it.
No solely automated decisions about you. Under Articles 22A to 22D UK GDPR we do not make decisions that produce legal effects for you, or similarly significantly affect you, by automated means alone. AI output here is always a draft or a summary that a person reads, judges and can override. No model decides whether to accept a booking, how to handle a cancellation, or whether to restrict someone's access — a person at Lighthouse Mentoring does, apart from the few automatic steps set out in the next paragraph. Where content is sensitive, such as health or wellbeing, the law is stricter still, and we do not let automated output drive a decision about you at all.
Some steps do happen automatically, and you should know which. A request nobody has answered is cancelled once the session it asks for is within two hours of starting, or once any window Lighthouse Mentoring has set for answering runs out, and we email you when that happens. Times too close to now are not offered. Requests from an email address, or a whole domain, that Lighthouse Mentoring has blocked are refused without a person looking, and the page shows a general error rather than announcing the block. Where Lighthouse Mentoring has turned it on, a request can be confirmed the moment it arrives instead of waiting for review; a request from someone who has never booked there before is still held for a person to look at, unless that exception is switched off as well. None of these produces a legal or similarly significant effect on you, and a person will always look again if you ask.
If you believe an automated output has affected you unfairly, tell us at info@lighthousementoring.org. You are entitled to an explanation, to a human review, and to challenge the outcome.
6. Who we share your information with
We share your information only with the service providers we need to run the service, and only what they need. Each acts under a written contract. We do not sell your data and we do not share it for anyone else's marketing.
| Provider | What it receives | Where it is processed |
|---|---|---|
| Convex | Everything described in section 2 — it is the database and application backend | European Union (eu-west-1) |
| Vercel | Hosting for this website; request data such as your IP address and browser | United States (global edge network) |
| Nylas | Your name and email address, to create the calendar invitation for your session | European Union |
| Your mentor's calendar provider (Google Workspace) | Your name and email address, as the attendee on the invitation in your mentor's own work calendar | United States and elsewhere, per that provider |
| Google, if you sign in with your own Google account | Your sign-in itself. The sign-in asks Google for permission to read the events in your own Google calendar and for a refresh token that keeps that permission working while you are away; if you agree, Google issues both and we store them on your account record. The booking site does not currently ask Google for those events, and you can remove the permission from your Google account at any time | United States and elsewhere, per Google |
| The video service for your session, where your session is held on video (the joining link is in your confirmation email) | Where the session is on Google Meet, your name and email address, because the invitation carries you as a guest — and whatever you say and show during the session. Where Lighthouse Mentoring has set a joining link of its own instead, we send that provider nothing; you go to it yourself. A session held by phone or in person has no video service at all | Per that provider's own privacy notice |
| Resend | Your email address, the content of the emails we send you, and Lighthouse Mentoring's reply-to address | United States |
| Sentry (Functional Software, Inc.) | Error and performance data from the booking site: the error itself, the page or request path you were on — and for a personal link, such as a feedback or session link, that path contains the link's token — the pages you moved through and what you clicked just before it, anything the page wrote to the browser console, your browser, and the timing of page loads. On our servers it also receives the log lines we write at warning and error level. We do not turn on its option to attach personal details such as your IP address | European Union (Sentry's EU region) |
| Anthropic | Session write-up text, cancellation and decline reasons, and staff search queries — see section 5. Drafting also sends the free-text answer you gave when booking, your first name — your full name where a mentor drafts the write-up of your session — the session title, and the time of your session in your own time zone. Where you have sat with Lighthouse Mentoring before, it sends the titles and dates of those earlier sessions, what you wrote when you booked them, and your mentor's written outcome for each | United States |
| PostHog | Analytics about how the booking form is used — see section 11. It is engaged by Puntoria for its own purposes, not by Lighthouse Mentoring | European Union (PostHog's EU cloud) |
Sign-in and session handling runs on Better Auth, which is software running inside our own backend rather than a separate company receiving your data.
A gift link is not a recipient either. Where Lighthouse Mentoring invites you to give something after you book, the button opens that provider's own page in a new tab — Donorbox, PayPal, Open Collective, Ko-fi, Stripe, JustGiving, or wherever Lighthouse Mentoring has pointed it. Where the provider supports it, the link carries the amount you picked, its currency, and a mark that it is a one-off, and nothing else; it is set not to tell the provider which page you came from, and none of what you told us travels with you. What you then give the provider is between you and them, under their own privacy notice.
We will also disclose information:
- where there is a safeguarding concern — which may mean telling a parent, carer or guardian, a school, local authority children's services, the police, or a health professional;
- where the law requires it, including a court order;
- to establish or defend legal claims;
- where Lighthouse Mentoring reports to a funder or commissioner, in which case it will tell you what is reported and in what form.
7. Sending information outside the UK
Some of the providers above hold your information in the United States — Vercel, Resend and Anthropic — and Google, on the rows where it appears, holds it there and elsewhere. When your information goes to any of them, we make sure one of these is in place:
- the recipient is certified under the UK Extension to the EU–US Data Privacy Framework, which the UK Government has found provides adequate protection; or
- we use the Information Commissioner's standard transfer terms — the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, in whatever form is current — together with an assessment that the protection you get is not materially lower than under UK law.
Not all of it goes there. Convex, which holds everything in section 2, runs in the European Union — its eu-west-1 region. Nylas runs in its EU region, PostHog on its EU cloud, and Sentry in its EU region. Those four take in and hold what they process for us in the EU, which the UK treats as offering adequate protection. Where a provider's staff outside the EU can reach that data in support of the service, the safeguards above apply to that access too.
You can ask us which mechanism applies to a particular provider and ask for a copy of it, and we will send you one. Write to info@lighthousementoring.org.
8. How long we keep things
We keep personal data only as long as it is useful for the purpose it was collected for, or as long as the law requires.
These periods take effect from 1 November 2026, and we are being straight with you about that. Until then, records are kept until they are deleted at your request or on Lighthouse Mentoring's instruction — so if you want yours removed sooner, ask, and we will do it. From that date the following happens automatically.
| We keep | For |
|---|---|
| What you tell your mentor when you book, and the notes your mentor writes about your sessions | 2 years after your last session |
| Your name and contact details | 2 years after your last session, then removed from your record |
| A basic record that a session happened — when, how long, which mentor, no names and no notes | 6 years |
| A record that we have blocked someone from booking | 6 years, with the written reasons removed after 2 years |
| Invitations that were never taken up, and pre-session questions | 90 days |
| The permission you gave Google, if you signed in with it, and the tokens that keep it working | Until you delete your account, or withdraw the permission from your Google account |
Some of our providers keep their own records — delivery logs for the emails we send, and the analytics described in section 11. Those periods are set by the provider; we ask for the shortest their service allows, and if you ask us we will tell you what applies today.
Where Lighthouse Mentoring's own safeguarding policy requires child-protection material to be kept for longer than the periods above, it will be, and Lighthouse Mentoring will tell you the period that applies if you ask.
What "deleted" actually means here. We do not delete the fact that a session happened. We remove your name, email address, phone number, date of birth and gender from your record, and we take your name and email out of the staff search index so you can no longer be found by them. What stays is the session itself: when it was, how long, with which mentor.
We also erase what was written — what you told us when you booked, the notes your mentor made, and any feedback comment — because those may still mention you by name, and a record that names you is still a record about you. Until 1 November 2026 that erasure runs when you ask us; from that date it also runs automatically on the schedule above. What survives is the bare shape of the appointment, kept because it is also your mentor's own record of their working time.
9. Your rights
Under UK GDPR you have the right to:
- Get a copy of your data (a subject access request), including the notes your mentor has written about you. We may hold back another person's information (Schedule 2, Part 3, paragraph 16 of the Data Protection Act 2018), or material where releasing it would be likely to cause serious harm to someone's physical or mental health (Schedule 3, Part 2). We will tell you if we have held anything back and why.
- Correct anything inaccurate.
- Ask us to delete your data. See section 8 for exactly what deletion means. If you have an account, you can also delete it yourself from your account area — tell us as well if you want your records at Lighthouse Mentoring erased, because deleting an account and erasing a mentoring record are not the same thing.
- Restrict what we do with your data — for example while we check its accuracy, or while we consider an objection you have made.
- Object to processing based on legitimate interests. You can object to direct marketing at any time and we must stop, no questions asked. For analytics, use the control in section 11.
- Portability — where we hold something because you gave it to us, and we process it by consent or under our contract with you, you can have it in a machine-readable format, and we can send it straight to another organisation where that is technically possible.
- Withdraw consent at any time, for anything you agreed to.
- Ask for human review of any decision you believe was made about you by automated means (section 5).
- Complain — to us, and then to the Information Commissioner's Office. Section 10 explains how.
One thing we may refuse. If Lighthouse Mentoring has blocked you from booking, we keep a minimal record of that decision — your email address, the fact of the block and its date — even if you ask us to erase everything else, and even after we have deleted the reasons. We do that under Article 17(3) UK GDPR, because the record is needed to keep sessions safe and to defend the decision if it is challenged. If we refuse an erasure request on this ground we will tell you so, in writing, and tell you how to challenge it.
How to make a request. Write to info@lighthousementoring.org. It is free, unless a request is clearly unfounded or excessive, in which case we may charge a reasonable fee or refuse it — and if we do, we will explain why and tell you how to challenge that. You do not need to use any particular form of words.
How long we take. We respond within one month. If your request is complex, or you have made several, we may extend by up to two further months and will tell you within the first month if we do. Where we genuinely need you to clarify what you are asking for — for example, which sessions you mean — the one-month clock pauses from the day we ask until the day you reply (Article 12A UK GDPR). If we need to check who you are before handing over your information, the clock pauses while we wait for that too. We will only ask where we really cannot proceed without the answer.
10. Complaints
Complain to us first. Since 19 June 2026, section 164A of the Data Protection Act 2018 gives you the right to complain directly to us about how we have handled your personal data, and obliges us to deal with it properly.
How to complain. Use the complaint form at https://www.lighthousementoring.org/contact/ — it takes a minute and you do not need an account. You can also write to info@lighthousementoring.org, or to us at 17314 Legend Brook Ct, Tomball, TX 77375-1065, USA, or ask us to send you a paper form. If none of those works for you, tell us and we will agree another way. If you need help making a complaint — including because you are a young person — someone else can make it for you.
We will:
- acknowledge your complaint within 30 days of receiving it;
- take appropriate steps to investigate it; and
- tell you the outcome without undue delay.
Then the ICO. If you are not satisfied with our response, or we do not respond, you can complain to the Information Commissioner's Office, the UK's supervisory authority. The ICO will normally expect you to have complained to us first and to have given us a reasonable time to answer, so please start with us.
Complaining to the ICO does not affect any other legal remedy you have.
11A. How we protect your information
Your information is held in access-controlled systems, encrypted in transit and at rest by our providers. Access inside Lighthouse Mentoring is limited to staff and hosts who need it for their work, and the links we email you are treated as credentials — see below. Our providers are contracted to tell us without undue delay if they suffer a personal data breach, and if a breach affects you and is likely to result in a high risk to your rights and freedoms, we will tell you.
Links we email you. Some emails contain a private link — to join your session, manage your booking, give feedback, or correct a detail. The link is the credential: anyone who has it can do those things. Do not forward it or post it anywhere public. Links that manage a booking stop working after the session. If you think someone else has one of your links, tell us and we will cancel it.
12. Changes to this policy
We will update this policy when what we do changes, or when the law does. The version number and date at the top always reflect the current version, and the current version is always on this page.
If a change materially affects you — a new category of data, a new recipient, a different retention period, or a new reliance on consent — we will tell you by email before it takes effect where we still hold a working address for you, and we will post the change here in any event.
We keep the previous versions of this policy, and you can ask us for one at info@lighthousementoring.org.