Privacy Policy
Effective date: 14 August 2026
1. Background
We understand that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone who visits this website, https://livingwithoutlimitsmethod.com ("Our Site"), and only collect and use your personal data as described in this Privacy Policy.
Any personal data we collect will only be used as permitted by law. Please read this Privacy Policy carefully and ensure that you understand it. By continuing to use Our Site or providing personal data to us, you confirm that you have read and understood this policy.
2. About Us
2.1 Our Site is owned and operated by Living Without Limits Method Ltd, a limited company registered in England under company number 17343229.
2.2 Registered address: 29 Abbey Road, Sleaford., Lincolnshire NG34 7XB.
2.3 Contact email: [email protected]
2.4 For the purposes of the Data Protection Legislation, we are the data controller responsible for your personal data.
2.5 We are registered with the Information Commissioner's Office (ICO) under registration number ZB545566.
3. What This Policy Covers
3.1 This Privacy Policy applies to your use of Our Site and to all personal data we collect from you in connection with our products, services, and communications.
3.2 Our Site may contain links to other websites. We have no control over how those websites collect, store, or use your personal data. You should check the privacy policies of any third-party websites before providing personal data to them.
4. What Is Personal Data
4.1 Personal data is defined by the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 (collectively, "the Data Protection Legislation") as "any information relating to an identified or identifiable natural person" - that is, any information about you that enables you to be identified, directly or indirectly.
4.2 Personal data covers obvious information such as your name and contact details, but also less obvious identifiers such as IP addresses, cookie identifiers, location data, and other online identifiers.
4.3 "Special category data" is a sub-set of personal data that is given greater legal protection. It includes information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health information, and information about sex life or sexual orientation. Where we process special category data, we do so only in accordance with the additional requirements of the Data Protection Legislation.
5. What Personal Data We Collect
Depending on how you use Our Site, we may collect and process the following categories of personal data:
5.1 Contact and identity data: name, email address.
5.2 Payment data: billing address and order details. Payment card details are collected and processed securely by our third-party payment processors Stripe and SumUp. We do not store full payment card details on our systems.
5.3 Account data: if you create an account on our site, we collect your username, password (stored securely in encrypted form), and any other information you provide during registration.
5.4 Marketing data: your preferences in receiving marketing communications from us, including consent records.
5.5 Usage data: information collected automatically when you visit Our Site, including IP address, browser type and version, operating system, the pages you visit, the time and duration of your visit, and the website you visited before ours.
5.6 Communications data: the content of any emails or messages you send us, including via Our Site contact forms.
5.7 Special category data: we do not collect or process special category data.
6. How We Collect Your Data
We collect your personal data in the following ways:
6.1 Directly from you. You provide us with personal data when you contact us, sign up to our mailing list, make a purchase, create an account, complete a form, attend an event, or otherwise interact with us.
6.2 Automatically. When you visit Our Site, certain personal data is collected automatically through cookies and similar technologies. See clause 10 for details.
6.3 Through third-party platforms. We use the following third-party platforms which may collect personal data on our behalf: Kajabi (website hosting), Kajabi (email marketing), Stripe (payment processing), Calendly (meeting bookings), Google Analytics (website analytics), Google Meet (video calls). We are responsible for the data we collect; each platform has its own privacy policy governing how it processes data on its own account.
7. Why We Use Your Data and Our Lawful Basis
Under the Data Protection Legislation, we must have a lawful basis for processing your personal data. The lawful bases we rely on are set out below alongside the purposes for which we process your data.
We use your personal data for the following purposes:
7.1 To fulfil your order and provide the products or services you have purchased, including sending order confirmations, delivering digital products, providing access to courses or memberships, and dealing with refund and complaint requests. Lawful basis: performance of a contract (Article 6(1)(b) UK GDPR).
7.2 To respond to your enquiries and provide customer support, including pre-sale enquiries and post-sale support. Lawful basis: performance of a contract where you are an existing customer; legitimate interests where you are a prospective customer (Article 6(1)(f)).
7.3 To send you marketing communications about our products, services, and offers. Lawful basis: your consent (Article 6(1)(a)) where you have opted in to receive marketing; legitimate interests (Article 6(1)(f)) where you are an existing customer being contacted about similar products or services and you have not opted out - the "soft opt-in" under the Privacy and Electronic Communications Regulations 2003 (PECR).
7.4 To manage your account, where you have created one, and to maintain records of your interactions with us. Lawful basis: performance of a contract; legitimate interests.
7.5 To improve Our Site, our products, and our services, including through analytics, user feedback, and review of usage patterns. Lawful basis: legitimate interests.
7.6 To comply with our legal and regulatory obligations, including maintaining records for tax, accounting, and any other statutory purposes. Lawful basis: legal obligation (Article 6(1)(c)).
7.7 To establish, exercise, or defend legal claims. Lawful basis: legitimate interests.
8. Marketing
This section sets out how we handle marketing communications. It applies in addition to clause 7.3.
8.1 We send marketing communications only to people who have opted in (where consent is the lawful basis) or to existing customers about similar products or services where they have not opted out (where legitimate interests is the lawful basis under the soft opt-in rule).
8.2 Every marketing communication we send includes an unsubscribe option. You can withdraw your consent or opt out at any time by clicking the unsubscribe link in any marketing email or by emailing us using the details in clause 17.
8.3 Where you withdraw consent or opt out, we will stop sending you marketing communications. We may continue to send you transactional communications relating to any purchase or account (for example, order confirmations, account notices, or service updates), as these are not marketing communications.
8.4 We comply with the Privacy and Electronic Communications Regulations 2003 (PECR) in relation to marketing by email, SMS, or telephone. PECR sits alongside the Data Protection Legislation and governs the specific rules for electronic marketing.
8.5 We do not buy or rent marketing lists from third parties.
8.6 Our marketing communications are sent through Kajabi. We maintain records of consent and opt-out preferences within this platform.
9. Who We Share Your Data With
We do not sell your personal data to third parties. We will share your personal data only with the following categories of recipients, and only as necessary for the purposes set out in clause 7:
9.1 Payment processors: STRIPE. Required to process payments.
9.2 Email marketing platforms: Kajabi. Required to send marketing and transactional emails.
9.3 Website hosting and analytics: Kajabi. Google Analytics. Required to operate our site.
9.4 Course and membership platforms: Kajabi
9.5 Booking and scheduling tools: Calendly
9.6 Video conferencing tools: Google Meet
9.7 Accounting and bookkeeping tools: Xero
9.8 Customer relationship management (CRM) and project management tools: Kajabi
9.9 Any other third party that processes data on our behalf.
9.10 Each third-party processor is bound by the terms of our agreement with them and their own data protection obligations. Where required by the Data Protection Legislation, we have a Data Processing Agreement in place with each processor under Article 28 of the UK GDPR.
9.11 In limited circumstances, we may also disclose your personal data: (a) to professional advisors (such as our solicitors, accountants, or insurers) who are bound by duties of confidentiality; (b) where we sell, transfer, or merge parts of our business or assets, in which case your personal data may be transferred to the buyer and used in line with this policy; or (c) where we are legally required to do so by court order, regulator, or other lawful authority.
10. Cookies
Cookies are small text files placed on your device when you visit a website. We use cookies on Our Site and you have a legal right to control how non-essential cookies are used.
10.1 We use the following categories of cookies on our site:
- Strictly necessary cookies: required for Our Site to function. Examples: session cookies that keep you logged in, shopping cart cookies, security cookies. These do not require your consent.
- Analytics cookies: help us understand how visitors use Our Site, such as which pages are visited most. Examples: Google Analytics, Hotjar, Wix Analytics.
- Marketing cookies: used to measure the effectiveness of marketing and to deliver targeted advertising. Examples: Facebook Pixel, Google Ads conversion tracking.
- Preference cookies: remember choices you have made on Our Site, such as language or region. Often classed alongside strictly necessary cookies.
10.2 Under the Privacy and Electronic Communications Regulations 2003 (PECR), we must obtain your consent before placing non-essential cookies on your device. We do this through a cookie consent banner that appears when you first visit Our Site.
10.3 You can review and change your cookie preferences at any time through the cookie consent settings on Our Site. You can also control cookies through your browser settings - most browsers allow you to refuse all cookies, accept only certain cookies, or be alerted when a cookie is placed.
10.4 If you refuse non-essential cookies, some features of Our Site may not function correctly.
10.5 Our cookie consent management is provided by a Cookie Consent Banner. A full list of cookies used on Our Site is availablevia the cookie settings on Our Site.
11. International Data Transfers
11.1 Where we transfer your personal data outside the United Kingdom - for example, where one of the third-party platforms listed in clause 9 is based outside the UK - we ensure that appropriate safeguards are in place to protect your data.
11.2 These safeguards include:
- Transferring data only to countries that the UK Government has determined provide an adequate level of data protection (an "adequacy decision"), including the European Economic Area and certain other jurisdictions;
- Where there is no adequacy decision, ensuring that the transfer is governed by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another approved transfer mechanism;
- For transfers to the United States, relying where applicable on the UK-US Data Bridge framework, which provides an adequacy decision for certified US recipients.
11.3 Most of the third-party platforms listed in clause 9 handle these safeguards as part of their own compliance arrangements. You can review each provider's privacy policy for further detail.
12. How Long We Keep Your Data
We keep your personal data only for as long as is necessary for the purpose for which it was collected. The principle is one of the six data protection principles in Article 5 of the UK GDPR ("storage limitation").
Our standard retention periods are:
12.1 Order, transaction, and tax records: 6 years from the end of the financial year in which the transaction occurred, in line with UK HMRC requirements.
12.2 Customer account data, where you have an account on Our Site: for as long as your account remains active, and for up to 2 years after closure, unless we are required to retain it for longer for legal reasons.
12.3 Marketing data: for as long as you remain subscribed to our marketing communications, and for up to 2 years after you unsubscribe, in order to evidence your consent or opt-out.
12.4 Enquiry data, where no relationship has resulted: up to 2 years from the last contact.
12.5 Email and other communications: 3 years from the date of the communication, unless required to be retained for longer.
12.6 Website analytics data: as determined by the analytics provider's retention settings.
12.7 After the relevant retention period ends, we securely delete or anonymise the data, unless we are required to retain it for longer for legal, regulatory, tax, or accounting purposes.
13. How We Store and Protect Your Data
13.1 We store your personal data on secure systems and use appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage.
13.2 Measures we take include:
- Limiting access to your personal data to those staff, contractors, and third parties who need it to perform their role, and ensuring they are bound by appropriate duties of confidentiality; yeah I've got to do more cuttings yeah decided to book a piece on the bottom yeah I think it looks more and then got paint on skirting board page no let's get in board be white be white and then all the framework and doors then can stay white continuous yeah being so I think when you look at that on the stairs that looks better before it off right that is this looks a little bit across there I think that maybe gives it the full Square shape yes a bit more work but in my mind yeah if you think so yeah stuff session but yeah all right yeah
- Using secure, encrypted connections (HTTPS) for the transmission of personal data through Our Site;
- Ensuring that payment information is processed by PCI-DSS compliant third-party payment processors and is not stored on our own systems;
- Keeping software, devices, and systems used to process personal data up to date with security patches;
- Using strong passwords and, where available, two-factor authentication on accounts that hold personal data;
- Maintaining backup and disaster recovery procedures.
13.3 No method of transmission or storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
14. Special Category Data
14.1 Special category data is given greater protection under the Data Protection Legislation. It includes information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health, sex life, and sexual orientation.
14.2 We do not collect or process special category data in connection with our products and services.
14.3 Where we process special category data, we apply additional safeguards including restricted access, secure storage, and clear retention limits.
15. Your Rights
Under the Data Protection Legislation, you have the following rights in relation to your personal data:
15.1 Right to be informed. You have the right to know what personal data we collect about you, why we collect it, and how we use it. This Privacy Policy is the principal means by which we provide that information.
15.2 Right of access. You have the right to ask us for a copy of all the personal data we hold about you. This is sometimes called a "subject access request" and is covered in detail in clause 16.
15.3 Right to rectification. You have the right to ask us to correct any personal data we hold about you that is inaccurate or incomplete.
15.4 Right to erasure. In certain circumstances, you have the right to ask us to delete personal data we hold about you. This is not an absolute right - we may refuse where we have a legal obligation to retain the data (for example, tax records) or where we need the data to establish, exercise, or defend legal claims.
15.5 Right to restrict processing. In certain circumstances, you have the right to ask us to restrict how we use your data - for example, while we investigate whether the data is accurate, or while we consider a request for erasure.
15.6 Right to data portability. Where the processing is based on consent or on a contract, and is carried out by automated means, you have the right to ask us to provide your personal data in a structured, commonly used, machine-readable format. You may also ask us to transmit the data directly to another controller where technically feasible.
15.7 Right to object. You have the right to object to processing based on legitimate interests (including profiling). You have an absolute right to object to processing for direct marketing purposes.
15.8 Right to withdraw consent. Where the lawful basis for our processing is your consent, you have the right to withdraw that consent at any time.
15.9 Rights relating to automated decision-making. You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you. We do not currently carry out such automated decision-making.
15.10 To exercise any of these rights, please contact us using the details in clause 17. We will respond within one month of receiving your request.
15.11 You will not have to pay a fee to exercise any of these rights. However, if your request is manifestly unfounded or excessive - for example, if it is clearly intended to disrupt our business or is a repeat of a recent request - we may charge a reasonable fee or refuse to act on the request.
16. How to Make a Subject Access Request
16.1 To make a subject access request, please contact us using the details in clause 17. You do not need to use a specific form or wording - a clear request asking for your personal data is sufficient.
16.2 Your request should include:
- Confirmation of your identity (we may ask for proof of identity to verify before disclosing data);
- Sufficient detail to enable us to locate the data you are seeking (for example, the relevant date ranges or types of interaction);
- Your preferred format for receiving the data (email, post, or otherwise).
16.3 We will respond to a valid subject access request within one calendar month of receiving it. Where requests are particularly complex or numerous, we may extend this period by up to a further two months, in which case we will inform you within the first month and explain why the extension is necessary.
16.4 We will provide a copy of your personal data free of charge. Where copies of the same data have already been provided, or where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.
16.5 In responding to your request, we may redact personal data relating to third parties or information that is otherwise protected from disclosure.
17. Data Breaches
17.1 A "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
17.2 We take all reasonable steps to prevent personal data breaches. Where a breach does occur, we will:
- Assess the nature and severity of the breach as soon as we become aware of it;
- Where the breach is likely to result in a risk to the rights and freedoms of affected individuals, notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR;
- Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, notify those individuals without undue delay, as required by Article 34 of the UK GDPR;
- Maintain a written record of the breach, including the facts surrounding the breach, its effects, and the remedial action taken, in accordance with our accountability obligations under the UK GDPR.
17.3 If you become aware of, or suspect, a data breach involving your personal data, please contact us immediately using the details in clause 19.
18. Complaints
18.1 If you have any concerns about how we handle your personal data, we would like the opportunity to address them in the first instance. Please contact us using the details in clause 19.
18.2 If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters.
18.3 Contact details for the ICO:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
19. How to Contact Us
To contact us about anything relating to this Privacy Policy or your personal data, please use the following details:
19.1 Email: [email protected]
19.2 Post: Living Without Limits Ltd, 29 Abbey Road, Sleaford. Lincolnshire NG34 7XB
19.3 Please mark any correspondence about data protection clearly so that we can route it to the right person.
20. Changes to This Privacy Policy
20.1 We may update this Privacy Policy from time to time, for example to reflect changes in the law or in our data practices.
20.2 The current version of this policy is the version published on Our Site. Where we make significant changes, we will notify you by email (where you have provided an email address) or by a prominent notice on Our Site.
20.3 The date this policy was last updated is shown at the bottom of this page.
This Privacy Policy was last updated on 14 August 2026.