Back to GOVBRM

Legal

Privacy policy

Last updated 13 September 2026.

GOVBRM is a personal project run by one person as a sole trader, not a registered company. This page sets out plainly what is and is not collected about you: this website, the AI Demand Toolkit, the free course and GOVBRM Academy's certificates, the Value Orchestration Workbook, and the GOVBRM Newsletter.

This website (govbrm.com)

This site is a set of static pages. It does not use cookies, does not run any analytics or advertising script, and does not track you across visits. The only code that runs is the site's own, needed to display the page and, on the toolkit, to save your own answers on your own device (see below).

The site is hosted on GitHub Pages. Like any web host, GitHub's servers process standard technical data to serve the pages, typically including your IP address, browser type and the pages requested. This happens at the hosting level, not through anything GOVBRM adds, and is covered by GitHub's own Privacy Statement.

The AI Demand Toolkit

Nothing you type into the toolkit is sent anywhere. Your answers are saved only in your own browser's local storage, on your own device.

The toolkit's autosave, export and import features work entirely on your device. Exporting creates a file you choose where to save; importing reads a file you choose to load. At no point does GOVBRM, or anyone else, receive a copy of what you write in the toolkit.

The free course

The course on this site is unlocked with an access code sent to newsletter subscribers. The code check runs in your browser: the course text is stored on the site in encrypted form and is decrypted on your device with the code you enter. The code, and your answers to the knowledge checks, are kept only in your browser's local storage, and nothing about your progress is sent anywhere.

Certificates, badges and the verification page

When you pass the final knowledge check of a free micro-course, you can generate a certificate by typing your name. The certificate is drawn in your browser, on your device. The name you type is used only to draw it and to compute the credential ID printed on it; it is not sent to GOVBRM or to anyone else, and the Academy keeps no record of foundation learners. The last certificate you generated is remembered in your browser's local storage so you can download it again, and clearing your browser data removes it. The Add to LinkedIn profile button takes you to LinkedIn with the credential details in the link; what LinkedIn does with them is covered by LinkedIn's own privacy policy.

The verification page reads a small published registry file for practitioner credentials and, for foundation certificates, checks the name and date you enter against the credential ID. Those entries are processed in your browser and are not sent anywhere. Practitioner credential holders are listed in the public registry by name only if they choose to be; anyone can ask for their name to be withheld or an entry corrected by messaging the GOVBRM LinkedIn page.

The Value Orchestration Workbook

Like the toolkit, the workbook saves what you type only in your own browser's local storage. Export creates a file you choose where to save; import reads a file you choose to load; printing uses your own browser's print function. Nothing you write in it reaches GOVBRM.

Live courses and cohorts

If the Academy runs a live cohort you join, the details needed to run it (your name, email address, organisation, attendance and assessment outcome) are held for the purpose of delivering the programme and issuing the credential, and the credential ID, credential, issue date and, with your consent, your name are entered in the public registry. Booking and payment arrangements, and the platform used for the live sessions, are set out when a cohort is announced, and their operators' privacy policies apply alongside this page.

The GOVBRM Newsletter

The newsletter is published on Substack. If you subscribe, Substack collects and stores your email address and handles sending, unsubscribing and related communications as the data processor and, for its own platform purposes, a data controller in its own right. Substack's handling of subscriber data is set out in its own Privacy Policy and Terms of Use, which apply alongside this page. GOVBRM does not operate a separate mailing list or sign-up form outside Substack, and does not sell, rent or share subscriber data with anyone. If you take out a paid subscription, Substack and its payment processor, Stripe, take the payment and hold the payment details under their own terms; GOVBRM never sees your card details.

What is not collected

Your rights

Under UK data protection law you have the right to ask what personal data is held about you, to have it corrected or deleted, and to object to or restrict how it is used. In practice, for this project that mostly means your Substack subscription, which Substack lets you manage directly (unsubscribe link in every email, or your Substack account settings). For anything else, or a question this page does not answer, message the GOVBRM LinkedIn page. You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time.

Changes to this policy

If GOVBRM adds its own sign-up form, changes how payments are taken, or otherwise changes how data is handled, this page will be updated first and the date at the top will change. Continuing to use the site after an update means you accept the current version.