Skip to Content

  • ​
  • ​

​

PRIVACY POLICY

Version: 3.1
Effective date: September 2026

This Privacy Policy (the “Privacy Policy”) explains how The Investor Ladder Limited, a private limited company incorporated and registered in England and Wales under company number 10289755, whose registered office is at Suite 3, Bignell Park Barns, Chesterton, Bicester, OX26 1TD, United Kingdom, and whose VAT registration number is GB335770882 (the “Company”), collects, uses, stores, shares, transfers and protects personal data in connection with our websites, applications, digital platforms, Events, competitions, memberships, communications, products and services.

The Company trades under the names Climb Group, ClimbGroup, Climb UK, ClimbUK, Climb Dubai, ClimbDubai, Investor Ladder and such other brands as it may publish from time to time. References in this Privacy Policy to “Climb Group”, “we”, “us” and “our” mean the Company alone as controller, unless we identify another entity in writing for a particular activity. Those trading names are styles of the Company only and do not designate separate legal entities as controllers under this Privacy Policy.

This Privacy Policy applies when you access or use any website, affiliated domain, mobile application, Event platform, customer portal, communication channel or other service we operate, or otherwise interact with us, including when you register for Events, enter competitions or surveys, submit enquiries, communicate with us, subscribe to our services, or provide personal information in any other way.

We process personal data lawfully, fairly and transparently under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and other applicable data protection legislation. Ticket acceptance alone is not the sole lawful basis for every processing activity; the lawful bases are described in this Privacy Policy.

Canonical copies are published at https://www.climb-group.com/privacy and https://www.climb-uk.com/privacy (or such successor URLs as we publish). This Privacy Policy works together with our Terms of Service and product-specific conditions (for example the ClimbUK Speakers and Hosts Conditions).

Who We Are


The controller of personal data described in this Privacy Policy is The Investor Ladder Limited (details above). Climb Group operates professional networking, knowledge-sharing, educational and community platforms and Events for participants in industry, entrepreneurship, innovation, investment communities and related commercial ecosystems. Through Events, meetings, roundtables and digital Platforms we facilitate professional introductions and discussions.

Subject to any separate written engagement under different terms, those activities are provided as networking and community services of the Company and are not, of themselves, the provision of regulated investment advice, personal recommendations on particular investments, or a brokerage service. Nothing in this Privacy Policy is a statement that the Company holds Financial Conduct Authority authorisation for a particular regulated activity.

Data Collection


We collect personal data directly from you when you use our services, register for Events, create an account, purchase products or services, participate in competitions, complete surveys, communicate with us, engage with our communities, or otherwise interact with Climb Group.

We may also receive personal data indirectly from organisers, employers, colleagues, exhibitors, sponsors, Event partners, referral partners, publicly available sources, integrated systems, or third parties acting on your behalf.

The categories of personal data and the purposes of processing are described throughout this Privacy Policy, including in the “How We Use Your Personal Data” section.

Accounts and User Portals


Where you register for Events, purchase products or services, submit applications, participate in programmes, or otherwise engage with Climb Group, we may create an account or portal profile for you. This may occur automatically, including where an initial purchase or registration was completed as a guest.

These accounts allow users to access tickets, bookings, invoices, communications, preferences, networking services, Event information and related functionality.

We use account information to provide services, maintain security, prevent unauthorised access, administer our platforms and support customer service.

How We Use Your Personal Data


Activity Personal data used Purpose Lawful basis
Account creation and management Name, email address, company details, login information To create and manage your account, provide access to services and maintain account security Contract, Legitimate Interests
Event registration and attendance Contact details, company information, Event preferences, attendance records To administer Events, provide tickets, facilitate participation and support Event operations Contract, Legitimate Interests
Networking and introductions Name, company, job title, biography, networking preferences To facilitate introductions, networking opportunities and professional connections Legitimate Interests, Consent where applicable
Customer support and helpdesk Communications, support requests, account information, correspondence records To provide support, resolve issues and improve customer service Contract, Legitimate Interests
AI-assisted processing Information in enquiries, communications, support requests, registrations and account records To assist staff with administration, support, reporting, analytics and operational activities Legitimate Interests, Contract
Communications and notifications Email address, telephone number, messaging identifiers To send service updates, Event information, reminders and operational communications Contract, Legitimate Interests
Marketing and newsletters Contact details, communication preferences, engagement data To promote services, Events and opportunities where permitted by law Consent, Legitimate Interests
Website analytics and performance IP address, device information, browser information, usage data, cookie identifiers To understand website usage, improve performance, troubleshoot issues and measure effectiveness Consent, Legitimate Interests
Affiliate and referral programmes Referral identifiers, tracking information, transaction records To administer affiliate programmes, attribute referrals and calculate commissions Contract, Legitimate Interests
Competitions, awards, grants and campaigns Application information, eligibility information, contact details To administer competitions and provide related benefits Contract, Consent, Legitimate Interests
Recruitment and Event staffing Contact details, availability information, experience details To recruit and manage temporary staff, contractors and Event personnel Contract, Legitimate Interests
Accessibility arrangements, carers and communication support Ticket details, assistant name, brief need statement, limited health or disability information you supply, badge matching To deliver requested accessibility adjustments, free carer or assistant places, and professional communication support Contract, Legitimate Interests; special category under Article 9 / DPA Schedule 1 or explicit consent as applicable
Speakers and Hosts Profile Content (biography, headshot, professional links, session materials), contact details, production Recordings To operate the programme, publish profiles, coordinate Sessions and produce Event media under the Speakers and Hosts Conditions Contract, Legitimate Interests
Cloakroom, bag holding, lost property and found devices Claim tags, Ticket or Account references, contact details, ownership evidence, item descriptions, limited device-identification data To operate temporary Facility deposit and reclaim, manage lost property, and assess security risk on found devices Contract, Legitimate Interests
Badge scans and Commercial Client leads Registration and scan data as described at the activity To fulfil sponsorship packages, attendee interest and related Event services (third parties often process as independent controllers for their own follow-up) Legitimate Interests, Consent where required
Security, fraud prevention and compliance Technical information, account activity, communication records To protect services, investigate incidents, prevent misuse and meet legal obligations Legal Obligation, Legitimate Interests

The lawful basis for a particular activity may vary depending on the services used and your relationship with Climb Group. Where we rely on Legitimate Interests, we consider the impact on your rights and freedoms and assess that the processing is necessary, proportionate and consistent with reasonable expectations.

Further information about specific activities, retention periods, recipients and third-party providers may be given at the point of collection or on request.

Analytics, Tracking and Similar Technologies


In addition to cookies, Climb Group uses analytics, monitoring, attribution and diagnostic technologies to understand how our websites, applications, platforms, Events and services are used and to improve performance, functionality, security and effectiveness.

These technologies may include website and application analytics; marketing and advertising attribution; conversion tracking; session replay and user-interaction analysis; heatmaps and engagement measurement; error logging and performance monitoring; referral, affiliate and campaign attribution; UTM and link tracking; and Event and platform usage analytics.

They may operate across our websites, mobile applications, client portals, Event platforms, communications, digital services and other systems operated by or on behalf of Climb Group.

Depending on the service, they may collect device and browser information, IP address, approximate location, pages viewed, links clicked, time spent, session information, referral and campaign attribution data, and interactions with our websites, applications, emails, advertisements, Events and services.

Where required by law, non-essential analytics, advertising, behavioural analysis, affiliate attribution, session replay, heatmap and marketing tracking technologies operate only after you have given the appropriate consent through our cookie and tracking preference controls.

We implement reasonable measures to minimise unnecessary collection and may apply masking, filtering, anonymisation, pseudonymisation, exclusion rules or other controls where appropriate.

You may manage preferences at any time through the Cookie Preferences controls on our websites.

Cookie Preferences


Our websites use cookies and similar technologies to improve functionality, measure performance, remember preferences, support security and enhance user experience.

Non-essential cookies and similar tracking technologies are deployed only where you have given the appropriate consent. You may withdraw or amend consent at any time using Cookie Preferences on our websites.

We may re-display preference prompts from time to time so that your choices remain current.

Our cookie and consent processes are designed to comply with applicable UK and European privacy and electronic communications rules, including ICO guidance and the Privacy and Electronic Communications Regulations (PECR). Where required by law, non-essential cookies, analytics, behavioural monitoring, affiliate attribution, advertising tracking, session replay and similar tools operate only after the appropriate consent has been obtained.

Further detail is in the “Analytics, Tracking and Similar Technologies” section of this Privacy Policy.

Artificial Intelligence and Automated Processing


Climb Group uses artificial intelligence (“AI”), machine learning, automation tools and AI-assisted software to support customer service, administration, communications, Event management, marketing, analytics, reporting, security and other operational activities (including features that may be presented as ClimbGroup AI or equivalent product names).

These technologies may process personal data in information you provide, including correspondence, enquiries, registrations, support requests, account information, Event participation records, survey responses, website interactions, communications and other information collected through our services.

AI-assisted technologies may be used to categorise, prioritise, route, summarise and analyse enquiries and communications; assist with helpdesk, live chat, email and response generation; support Event management, networking, attendee services and operational planning; produce summaries, reports, insights and business intelligence; search and process information in systems authorised for our use; assist staff with administrative tasks; and monitor, secure and improve our services.

Where appropriate, AI systems may interact with authorised systems, databases, platforms, applications, storage, communication systems and business tools through controlled authentication, permissions, integrations, APIs, automation frameworks or similar technologies.

AI systems used by Climb Group are intended to assist our staff and operational processes. Human review, oversight, intervention or approval may be applied depending on the nature of the activity, request, decision or outcome. We do not use solely automated decision-making that produces legal or similarly significant effects on individuals unless permitted by law and disclosed separately where required.

We take reasonable steps so that AI providers and technology suppliers implement appropriate technical and organisational safeguards. Where technically and contractually available, we configure providers not to use Climb Group customer data for foundation-model training or similar purposes, and require them to process personal data only for authorised purposes.

Some AI-assisted services are provided by third-party technology providers. Depending on the provider and service, personal data may be processed, stored, transferred, accessed, analysed or backed up in the United Kingdom, the European Economic Area and other jurisdictions under the safeguards described in this Privacy Policy.

Please do not provide special category personal data (for example information relating to health, ethnicity, religious beliefs, sexual orientation, trade union membership, genetic data, biometric data or criminal convictions) through AI-assisted communication channels unless that information is necessary for us to provide a requested service, fulfil a legal obligation, protect safety or comply with applicable law.

If you do not wish your information to be processed using AI systems operated by or on behalf of Climb Group, contact [email protected] to discuss whether alternative communication methods may be available. Communications may still pass through third-party platforms that use their own automated security, filtering, routing, monitoring or processing technologies outside our direct control.

Event Participation, Networking and Media


Climb Group operates physical Events, virtual Events, webinars, live streams, networking platforms, websites, applications, communities, competitions, social channels and other engagement activities. References to “Events” in this Privacy Policy are not limited to in-person attendance.

Where networking, directories, introductions, sponsorship fulfilment or related Event services require it, certain personal information may be shared with other attendees, participants, exhibitors, sponsors, partners or stakeholders. Depending on the activity, this may include your name, company affiliation, job title, professional biography, profile information, contact details, networking preferences and other information you choose to provide through registration, applications, directories, Event platforms, mobile applications, meeting booking systems, websites, communities or other services. Visibility and sharing follow the controls you use on our Platforms where those controls are offered. Once contact details leave our systems to a recipient, that recipient is responsible for subsequent use under applicable law.

Sponsors, exhibitors and other Commercial Clients may, at certain Events or in sponsored zones, scan badges, QR codes or similar credentials, or receive registration or lead data for their own business purposes. Where they determine the purposes and means of subsequent processing for their own organisation (for example follow-up sales contact) they act as independent controllers. We describe such sharing at the relevant point of collection or scanning where practicable, and in any data schedule under a Client Agreement. After data is lawfully received by an independent controller, their privacy notice and practices govern later use. We may still process the same data as controller for our own Event operations, analytics and compliance.

Climb Group activities may be photographed, filmed, live streamed, recorded, screen captured or otherwise documented. Media may include your image, likeness, voice, comments, contributions, profile information, presentations, messages or participation. Content may be used in photographs, video and audio recordings, Event reports, promotional materials, social media, editorial content, live streams, training materials, archives, educational content and other marketing, reporting, promotional or commercial materials produced by or on behalf of Climb Group. Official crowd, atmosphere and wide shots of public Event spaces are a normal part of documenting and promoting large Events. Session and stage recordings and livestreams are likewise a normal part of many main Events and may later be incorporated into paid courses or media products unless Event-specific conditions state otherwise.

The lawful bases for media processing are not created merely by a person reading this Privacy Policy or by Ticket acceptance alone. In general, processing of general audience, atmosphere and wide-shot imagery, and of stage and Session production where you form part of a public professional audience or programme, relies on our legitimate interests in documenting, promoting, reporting on and commercially developing Events and content, balanced against your rights and expectations. For featured interviews, microphone stand-ups, testimonials, case studies or materials where an individual is intended to be the primary focus, we seek participation or another clear permission where required and appropriate (verbally, electronically, in writing, through recorded participation or another suitable method) and may retain evidence of that permission. For live online or hybrid Events, platform controls (for example camera or microphone off) help limit capture of your image and voice in interactive segments; programme stage streams of facilitators may continue if you remain connected for audio-only. Where we offer badge, lanyard or digital indicators requesting reduced featured photography, we use them as an operational aid without guaranteeing exclusion from all crowd or atmosphere images.

If you do not wish to appear in featured session or livestream material as an ordinary attendee, request opt-out through the helpdesk at least one calendar month before the Event where recording is intended, and we will take reasonable steps to accommodate that request operationally. Persons under eighteen (where attendance has been approved as described below) require appropriate parental or guardian permission for featured interviews. Persons who consider themselves vulnerable should notify us in advance so that reasonable arrangements can be discussed.

Speakers and Hosts are subject to the ClimbUK Speakers and Hosts Conditions (or successor schedule) as well as this Privacy Policy. Profile Content you supply for publication (biography, headshot, professional links, session titles and abstracts) is processed to operate the programme, Platforms, Packs, signage and marketing, typically under contract (your confirmed engagement) and legitimate interests. Contact details of co-Speakers or Hosts may be shared between confirmed contributors for Session coordination only; recipients must not use those details for unsolicited marketing or share them more widely without a lawful basis. By participating as a Speaker or Host you grant production and marketing licences for Recordings of your Session performance as described in those Conditions and our Terms of Service. The ordinary one-month featured opt-out pathway for attendees does not apply to Session performance capture of Speakers or Hosts except as those Conditions and this Privacy Policy expressly allow. Your data-protection rights remain unaffected. We may still operate reduced-featured photography indicators for your off-stage movement as an ordinary attendee where reasonably practicable.

Media may be captured by Climb Group, its partners, sponsors, exhibitors, media organisations, journalists, content creators, attendees and other third parties. Climb Group may receive, acquire, licence, commission or otherwise obtain copies of such content for promotional, editorial, reporting, archival or commercial purposes where rights allow. Climb Group cannot control, modify, remove or otherwise take responsibility for content independently captured, published, distributed or shared by third parties who are not acting on our behalf.

Individuals may withdraw permission for future use of identifiable featured content by contacting the relevant Event team, [email protected] for ClimbUK Events, [email protected] for other Climb Group activities, or [email protected]. Withdrawal will apply to future use where reasonably practicable. It may not be possible to remove or retract content that has already been published, distributed, licensed, broadcast, archived, shared with partners, reproduced by third parties, included within historical Event materials, or otherwise entered the public domain.

Climb Group primarily provides services to businesses, professionals, entrepreneurs, investors, Event participants and organisational representatives. Our Events are designed primarily for adults aged eighteen and over. In limited circumstances a person under eighteen may be permitted to attend only with our prior written approval and an appropriate Ticket arrangement under our Terms of Service, and then only under continuous supervision of a parent or legal guardian who remains responsible for the child’s welfare. Account registration on some Platforms may start at sixteen where law permits. We do not operate services directed at children, and we do not knowingly market to children. Where we process personal data relating to a supervised minor (including Ticket and registration details, entry records, safeguarding information, or featured media subject to parental permission), we do so only as needed for that attendance, safety, legal compliance and the media purposes described above, under contract, legitimate interests and, where required for featured media of a child, appropriate parental or guardian consent or another suitable lawful basis. Parents or guardians who book or accompany a minor should supply accurate contact data for operational and safeguarding communication.

Facilities Access, Sensitive Attributes, Accessibility and Incident Reports


Climb Group does not seek, solicit or require disclosure of sensitive personal attributes as a condition of ordinary Event attendance, Platform use, hospitality class or facilities access. That includes, without creating a closed list, sex assigned at birth, gender history and detailed surgical or medical transition information; sexual orientation, gender identity and transgender status; religious or philosophical belief; political opinion; sexual health or sexually transmitted infection status (including HIV); and detailed disability or health diagnosis, except limited information you choose to provide so that we can deliver an accessibility arrangement you have requested. We do not process sexual-health or STI status for access decisions. We do not use registration or accessibility data to police which toilet block you may enter by reference to sex assigned at birth, and we do not require disabled people to prove medical eligibility at an accessible toilet door as a condition of using accessible facilities. Ticketing and registration forms must not invent mandatory fields for those purposes. This does not prevent ordinary Ticket, accreditation, bag or age checks, limited assistance-animal questions permitted under equality practice, or proportionate accessibility processing where you have requested an arrangement. Operational standards on facilities, non-interrogation and inclusive facilities design are set out further in our Terms of Service; this Privacy Policy describes how related personal data is (and is not) processed.

If you contact us for an accessibility arrangement, free carer or personal-assistant place, or professional communication support (for example British Sign Language interpretation or speech-to-text), we may process limited identity and need information you supply solely to deliver that arrangement. For a free carer or assistant place we typically hold the paid guest’s Ticket details, the assistant’s name, a short statement that the assistant is needed for disability-related support at the Event, and entry badge matching so that free access is used only by the named assistant. For interpreter or communication-support booking we hold only the information needed to arrange a suitable practitioner and coverage plan. We do not routinely require full medical dossiers, diagnostic letters or invasive detail of impairment. Where information about health or disability is processed so that an arrangement can be delivered, it may be special category personal data under the UK GDPR. We process it only as necessary for the stated accessibility purpose, under the Article 6 bases of contract and/or legitimate interests as applicable to the Booking relationship, and under an appropriate Article 9 / Data Protection Act 2018 Schedule 1 condition for that purpose (or, where we expressly seek it and the activity so requires, your explicit consent). We treat such information as confidential, restrict access to persons who need it operationally, and do not use it for marketing profiles. Where the status of an assistance animal is not already clear, authorised staff may ask only the limited questions permitted for service providers under Equality Act practice (whether the animal is required because of disability, and what task or work it has been trained to perform) without demanding medical evidence as a routine condition of entry.

If you report harassment, discrimination, misconduct or a safeguarding concern, we may process personal data in your report - and, where you choose to include it, special category data - to investigate, take protective measures, keep incident records, and where appropriate work with venues, independent investigators or competent authorities. We ask you to share only what is necessary. The lawful bases are typically legitimate interests (safe Events and Platforms, investigation of misconduct) and, where applicable, legal obligation or establishing, exercising or defending legal claims, with special-category conditions as needed. Your rights remain as stated later in this Privacy Policy, subject to legal exceptions including the need to preserve evidence of serious misconduct.

We may retain limited accessibility-arrangement notes for the Event and a short operational closure period after the Event ends (typically of the order of ninety days unless a claim, complaint or longer operational need remains open). Incident investigation files are retained as needed for limitation periods, legal claims, regulatory requirements and safety, consistent with our retention practices for security and compliance records. Do not use AI-assisted helpdesk channels for special category detail that is not necessary; the Artificial Intelligence section asks that special category data not be submitted through those channels unless needed for a requested service, safety or legal compliance.

Cloakrooms, Bag Holding, Lost Property and Found Devices


At some Events we, the venue operator, security contractors or another contractor may operate a cloakroom, temporary bag-holding counter, left-bag room or similar Facility. Deposit is voluntary. Use of a Facility may involve processing of limited personal data such as your name, Ticket or badge reference, a claim token or tag number, contact details where you provide them for reclaim, and descriptions of deposited items needed for logistics and security. That processing is so we (or the Facility operator) can accept, hold and return items, refuse unsuitable items, and investigate disputed reclaim. Lawful bases are typically contract (where deposit forms part of a service relationship with us) and legitimate interests in Event operations, safety and property logistics. Where a Facility is operated wholly or partly by a venue or independent left-luggage provider, that operator may process data under its own privacy notice in addition to this Privacy Policy.

Items left unattended, found on the Event estate, or not collected from a Facility by the published reclaim deadline may be treated as lost property. To manage reclaim we may process descriptions of items, your Ticket or Account details, evidence of ownership you supply, correspondence about reclaim and limited internal notes. After the Event, reclaim requests are typically directed to [email protected] (or such other channel as we publish for that Event). We aim to hold ordinary non-perishable lost property only for a limited operational period (commonly up to fourteen days after the last public day of the relevant Event unless we publish a different period or safety requires otherwise), after which unclaimed items may be disposed of as described in our Terms of Service, so far as the law permits.

Devices, storage media and documents may contain personal data of you or of other people. You remain responsible for locking devices, encrypting storage, and not depositing materials that contain other people’s personal data except where strictly necessary and adequately protected. For safety, reclaim or disposal we may power a device or open packaging solely so far as reasonably needed to identify an owner or assess a security risk. Staff are not authorised to browse personal content out of curiosity. This processing relies on legitimate interests in reuniting owners with property and managing security risk, and (where applicable) legal obligation. Retention of reclaim correspondence and ownership evidence follows our operational and claims-related practices; we do not keep device contents as a standing archive once reclaim or disposal is complete, save for residual logs needed for security, fraud prevention or legal claims.

Competitions, Prize Draws and Promotional Campaigns


From time to time Climb Group may operate competitions, prize draws, awards programmes, grants, sponsorship initiatives or similar promotional activities.

Where you participate, we may share relevant personal data with competition sponsors, judges, delivery partners, funding partners or organisations directly involved in administering the competition.

Data shared will be limited to information reasonably required for operation, assessment, delivery, administration or fulfilment of the competition or associated benefits. This may include application materials, supporting information, contact details, eligibility information and other information reasonably required for that purpose.

Additional competition-specific terms and conditions may apply and take precedence where they conflict with this Privacy Policy on pure competition process. Sharing will be carried out in accordance with UK GDPR and other applicable data protection legislation.

Data Sharing


We do not sell personal data to third parties under any circumstances.

We may share personal data with Event partners during and shortly after Events where relevant to your participation and the delivery of Event-related services.

We may share personal data with member organisations, sponsors, exhibitors, competition partners, service providers or other third parties where necessary to provide services, facilitate networking, administer Events, fulfil contractual obligations, comply with legal obligations, or where you have requested or consented to such sharing.

Where registration, badge, QR or lead data is shared with sponsors, exhibitors or similar Commercial Clients so that they can run their own follow-up or hospitality activities, those organisations typically act as independent controllers once they receive the data for their own purposes. We require confidentiality and purpose limitation in our commercial arrangements where appropriate, but each independent controller remains responsible for transparency to you and for the lawfulness of their later processing. Lead-generation scans and sponsored-zone sharing may also be described on site or in the Event app at the point of engagement. Processor suppliers (venue technology, cloud, email, payment and similar providers acting only on our documented instructions) remain processors as set out below and are not recharacterised as independent controllers by mere technical hosting.

We may share personal data with technology providers, cloud providers, communication platforms, analytics providers, payment processors, artificial intelligence providers, Event technology providers and other service providers acting as data processors on our behalf. These providers assist us in delivering our services and may process personal data solely for authorised purposes under appropriate contractual, confidentiality, security and data protection obligations.

We may also share anonymised, aggregated, statistical or non-identifiable information for research, reporting, analytics, marketing, operational or business purposes.

All data sharing is carried out under appropriate lawful bases and with safeguards designed to protect personal data.

Data Retention


We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to provide services, comply with legal obligations, resolve disputes, enforce agreements, maintain security and protect our legitimate business interests.

Retention periods vary depending on the nature of the information, the services used, legal requirements, operational requirements and the relationship between the individual and Climb Group.

Typical retention practices:

Data category Typical retention period
Membership, customer, account and client records Up to 7 years after the relationship ends
Event registrations, bookings, attendance records, tickets, orders and invoices Up to 7 years
Initial enquiries and prospective customer information Up to 2 years after the last meaningful interaction
Correspondence, support requests, helpdesk records, SMS, WhatsApp and communication history Up to 2 years after the last meaningful interaction
Marketing preferences, suppression lists, unsubscribe and opt-out records Retained as long as necessary to honour communication preferences and prevent unwanted communications
Competition, award, grant and promotional campaign records Up to 3 years after completion of the activity unless a longer period is required
Networking, introductions, attendee directory information, badge scans, meeting requests and Event engagement records Up to 7 years
Accessibility arrangements, carer places and communication-support booking notes Typically for the Event plus a short operational closure period (commonly of the order of 90 days) unless a claim or longer operational need remains open
Cloakroom tags, lost-property reclaim correspondence and ownership evidence Limited operational reclaim window (commonly up to 14 days after the Event for physical holds) plus residual correspondence logs as needed for security and claims
Website analytics, tracking, attribution, session replay, heatmaps, diagnostic and behavioural analytics Typically between 30 days and 26 months depending on the service and configuration
Affiliate, referral, attribution, campaign tracking and UTM records Retained as long as necessary to administer the programme, calculate commissions, validate referrals and resolve disputes
Security logs, access logs, audit logs, fraud prevention, monitoring and error logs Typically between 90 days and 7 years depending on the purpose and legal requirements
Event photography, recordings, livestreams, promotional content, testimonials, interviews, media assets and historical Event archives Retained for as long as Climb Group reasonably considers the content valuable for business, promotional, historical, archival, legal, educational, reporting or operational purposes
Recruitment, staffing, contractor, volunteer and Event personnel information Up to 2 years after the recruitment or engagement process concludes unless a longer period is required
AI interaction records, AI-generated summaries, AI-assisted support records, operational reports, analytics outputs and associated audit information Retained in accordance with the underlying system, service, communication or record to which they relate
Financial records, accounting, tax, payment information, refunds, invoices and transaction records Up to 7 years or longer where required by law
Forum posts, community content, comments, user-generated content and platform contributions Retained until deleted by the user, removed by Climb Group, or no longer required for operational purposes

Where multiple periods apply, we retain information for the longer applicable period. We may retain information for longer where required by law, necessary to establish, exercise or defend legal claims, required for regulatory purposes, necessary to prevent fraud or abuse, or otherwise permitted by applicable law.

Where personal data is no longer required, we delete, anonymise, aggregate, suppress, archive or otherwise securely dispose of it in accordance with our retention practices.

Data Security and International Transfers


Climb Group operates primarily in the United Kingdom and the European Economic Area.

To provide our services we use technology providers, communications platforms, cloud services, payment providers, analytics platforms, Event systems and other third-party providers. Depending on the provider, configuration and services, personal data may be stored, processed, accessed, transferred or backed up in countries outside the United Kingdom or European Economic Area.

Where personal data is transferred internationally, Climb Group takes reasonable steps to ensure appropriate safeguards under applicable data protection law. These may include adequacy regulations, International Data Transfer Agreements (IDTAs), the UK Addendum to the European Commission’s Standard Contractual Clauses, contractual protections, or other lawful transfer mechanisms recognised under applicable law.

Climb Group is committed to protecting personal data and implementing appropriate technical, organisational, physical and administrative measures against unauthorised access, disclosure, alteration, loss, misuse or destruction.

Access to personal data is restricted to authorised personnel and approved service providers who require access to perform their duties.

Security measures may include access controls, authentication, multi-factor authentication, encryption, monitoring and audit logging, backup and recovery, incident response, staff training, device management, security reviews, vulnerability management and supplier due diligence.

No method of transmission over the internet, electronic storage or security control can be guaranteed to be completely secure. We cannot guarantee absolute security of personal data, though we work continuously to maintain and improve appropriate safeguards.

External Links


Our websites may contain links to external websites. We do not control those sites and are not responsible for the protection and privacy of information you provide while visiting them. Review the privacy policies of external sites you visit.

Your Rights


Subject to applicable data protection law, you have the following rights in relation to your personal data:

  • the right to be informed about how your personal data is collected, used, shared, stored and protected;
  • the right of access to personal data we hold about you and to obtain a copy of that information;
  • the right to request that inaccurate, incomplete or outdated personal data is corrected or updated;
  • the right to request erasure of your personal data in certain circumstances;
  • the right to request that we restrict processing in certain circumstances;
  • the right to receive certain personal data in a structured, commonly used and machine-readable format and, where technically feasible, to request transfer to another organisation;
  • the right to object to processing based on Legitimate Interests;
  • the absolute right to object at any time to processing of your personal data for direct marketing;
  • the right to withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal;
  • the right not to be subject to solely automated decision-making or profiling that produces legal or similarly significant effects, except where permitted by applicable law.

To exercise these rights, contact [email protected].

We will normally respond within one calendar month. Where permitted by law, this period may be extended for particularly complex or numerous requests.

If you request deletion of personal data required for us to provide a service, maintain an account, fulfil a contract, comply with legal obligations, exercise legal rights, prevent fraud, maintain security or protect legitimate business interests, we may be unable to continue providing some or all services. Certain information may continue to be retained where required or permitted by law.

Where we rely on Legitimate Interests, you may object to that processing. We will consider objections carefully and cease processing unless we have compelling legitimate grounds to continue, another lawful basis applies, or processing is necessary for the establishment, exercise or defence of legal claims.

If you are dissatisfied with how we handle your personal data, you may lodge a complaint with the Information Commissioner’s Office (ICO) or seek an appropriate legal remedy.

Marketing Preferences


Where permitted by law, Climb Group may send you information relating to Events, services, opportunities, surveys, newsletters and other activities that may be relevant to you.

You may manage communication preferences at any time by:

  • using the unsubscribe link in marketing communications;
  • updating preferences in your account dashboard;
  • contacting us through live chat; or
  • emailing [email protected].

We maintain suppression records where necessary so that individuals who opt out do not receive future marketing communications.

Service-related communications may still be sent where necessary to provide a requested service, fulfil a contractual obligation or comply with legal requirements. Notices about material updates to this Privacy Policy may also be sent where necessary for transparency or legal compliance, even if you have opted out of marketing.

Contact


The Investor Ladder Limited trading as Climb Group, ClimbGroup, Climb UK, ClimbUK, Climb Dubai, ClimbDubai and Investor Ladder

Company number: 10289755

VAT: GB335770882

Registered office: Suite 3, Bignell Park Barns, Chesterton, Bicester, OX26 1TD, United Kingdom

General queries: [email protected]

Data protection: [email protected]

ClimbUK media preferences and certain media withdrawals: [email protected]

Policy Updates


We may amend, update or otherwise revise this Privacy Policy from time to time so that it remains accurate and reflects our processing, technology and legal obligations. When we do so we will publish the revised Privacy Policy on our website (or within the relevant Platform) with a stated effective date and, for material revisions, a short summary of the principal changes. We may retain previous versions, or excerpts of them, for transparency, accountability or dispute purposes and may make them available alongside the then-current version, but we do not guarantee that every historic draft will remain publicly accessible indefinitely.

Where a change is material to how we process personal data - for example a substantial new purpose, a change of principal lawful basis for a significant processing activity, new categories of recipient or international transfer that are not already described fairly, or a significant change to the rights or choices we describe - we will take such additional steps as are reasonable and appropriate to bring the change to the attention of affected individuals. Those steps may include prominent website notice, in-service messaging, email to accounts for which we hold a current address, or direct communication when you next engage with us. Where processing depends on consent, we will not rely on continued silence alone to treat that consent as covering a purpose incompatible with the purpose for which consent was originally given, and where consent must be refreshed under the UK GDPR or PECR we will seek it in a manner consistent with those regimes.

Processing of personal data is governed by this Privacy Policy as published at the relevant time and by applicable data protection law. Continued access to or use of our services after an update does not of itself create a contractual acceptance mechanism for commercial terms, nor replace any UK GDPR requirement for a lawful basis, for consent where required, or for fair information about material changes. You are encouraged to review this Privacy Policy periodically.

A high-level version history appears below. Summaries are for navigation only and are not a complete statement of all drafting amendments.

Version 

Effective Date 

Summary of Changes 

Downloadable File

3.1

September 2026

Aligned Privacy as the transparency instrument with Climb Group Terms of Service (attendance equality, accessibility, personal property, media) and Speakers and Hosts Conditions. Adds facilities and sensitive-attribute non-collection, limited accessibility health processing, cloakroom and lost-property device handling, speaker and host profiles and Session capture carve-outs, independent-controller exhibitor lead language, full company identity, and supervised-minors wording. Clarifies media lawful bases.

PRIVACY POLICY_2026_09.pdf

3.0 

July 2026 

Comprehensive modernisation of the Privacy Policy. Enhanced transparency regarding how personal data is collected, used, shared, retained, and protected. Expanded information relating to events, networking, media, analytics, tracking technologies, artificial intelligence, user accounts, competitions, international transfers, security measures, individual rights, retention practices, and communication preferences. Introduced additional transparency and version history information. 


PRIVACY POLICY_2026.pdf

2.0 

November 2025 

Significant revision of the Privacy Policy. Improved structure, refreshed branding, expanded event and membership-related provisions, enhanced data sharing and retention information, introduced dedicated sections covering cookies, security, marketing preferences, and policy updates, and brought the policy into closer alignment with evolving business operations. 


PRIVACY POLICY_2025.pdf

1.0 

February 2023 

Initial publication of the ClimbUK Privacy Policy, building upon previous privacy and data protection practices operated through The Investor Ladder Limited and associated event brands. 

 


PRIVACY_POLICY_2023.pdf

 

This Privacy Policy is a transparency notice of the Company under United Kingdom data protection law. It does not constitute legal advice to third parties. Questions about interpretation for staff should be referred to the directors or appointed counsel.