Privacy Policy

INSTITUTE OF SALES PROFESSIONALS

Last updated: 28/05/2026

 

Who We Are

The Institute of Sales Professionals (ISP) is the UK and global professional membership body for salespeople and sales leaders. Our mission is to promote and advance excellence in professional sales. Our website address is: https://the-isp.org.

ISP is a Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This means we are responsible for deciding how and why we process your personal data, and for ensuring that we do so lawfully and transparently.

 

What Personal Data We Collect and Why

Members and Prospective Members

When you apply for membership, register for an event, or make an enquiry, we may collect the following:

  • Full name
  • Job title and employer
  • Email address
  • Phone number
  • Postal address
  • Payment information (processed securely via our payment provider)
  • Professional background and qualifications relevant to membership

 

Contact Forms and Enquiries

When you complete a contact form on our website, we collect the information you provide (name, email address, phone number, and your message). We also collect your IP address for security purposes and to identify the general geographic location of enquiries, as ISP is a UK-based organisation.

If you tick the consent checkbox on our contact form, you give us permission to retain your details for future relevant communications. If you do not tick this box, your details will be deleted from our records after 30 days.

 

Event Registration

When you register for an ISP event, we collect the information needed to process your registration, communicate event details, and (where applicable) issue CPD records. This may include your name, organisation, contact details, and dietary or access requirements.

Website and Cookies

When you visit our website, we may collect standard technical information including your IP address, browser type, and pages visited. We use cookies to improve your experience on our site. A cookie is a small text file placed on your device. We use the following types of cookies:

  • Session cookies: temporary cookies that expire when you close your browser
  • Login cookies: if you log in to our site, these persist for up to two weeks if you select Remember Me, or are removed when you log out
  • Preference cookies: to remember your display settings (last for one year)

Embedded content from third-party websites (such as videos) may set their own cookies and track your interaction with that content. We recommend reviewing the privacy policies of those third parties.

 

Lawful Basis for Processing Your Personal Data

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:

  • Performance of a contract: where processing is necessary to deliver membership services, process event registrations, or fulfil other contractual obligations to you
  • Legitimate interests: where we have a legitimate business reason to process your data that is not overridden by your rights and interests. Examples include follow-up communications after events, relationship development, and relevant professional content
  • Consent: where you have given us clear, specific agreement to process your data for a defined purpose, such as receiving marketing communications
  • Legal obligation: where we are required to process your data to comply with a legal requirement

 

Where we rely on legitimate interests, we carry out a balancing test to ensure our interests do not override your rights. You have the right to object to processing based on legitimate interests at any time (see Your Rights below).

 

How We Use Your Personal Data

We use your personal data for the following purposes:

  • Processing and managing your membership application and ongoing membership
  • Communicating with you about your membership, events, and ISP services
  • Processing event registrations and issuing CPD records
  • Sending follow-up communications after events you have attended, including resources and information about similar ISP events
  • Sending marketing communications where we have a lawful basis to do so
  • Improving our website and services
  • Complying with our legal and regulatory obligations

 

Marketing Communications

ISP may contact you with information about events, membership benefits, and professional development opportunities that are relevant to your role. We will only do this where we have a lawful basis, which may include:

  • Your consent, where you have opted in to marketing communications
  • Legitimate interests or soft opt-in, where you have previously engaged with ISP through membership or event registration and we are contacting you about similar services
  • Business-to-business communications where the content is relevant to your professional role

 

Every marketing communication we send includes a clear and easy way to unsubscribe. You can opt out at anytime and we will stop sending marketing communications promptly.

 

How Long We Retain Your Data

We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our general retention periods are:

  • Membership records: retained for the duration of your membership and for 6 years after your membership ends, in line with our legal obligations
  • Event registrations: retained for 3 years after the event, to support CPD records and follow-up communications
  • Contact form enquiries (with consent): retained for up to 3 years from last contact
  • Contact form enquiries (without consent): deleted after 30 days
  • Financial records: retained for 7 years in line with HMRC requirements

 

Who We Share Your Data With

We do not sell your personal data to third parties. We may share your data with:

  • Service providers who process data on our behalf (e.g. our email platform, event management system, payment processor, and website host). These third parties are bound by data processing agreements and may only use your data on our instructions
  • Regulatory or law enforcement bodies where we are legally required to do so

 

Where we use third-party service providers based outside the UK, we ensure that appropriate safeguards are in place to protect your data, in line with UK GDPR requirements for international transfers.

 

Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access: you can request a copy of the personal data we hold about you
  • Right to rectification: you can ask us to correct inaccurate or incomplete data
  • Right to erasure: you can ask us to delete your personal data in certain circumstances
  • Right to restrict processing: you can ask us to limit how we use your data
  • Right to data portability: you can request your data in a structured, machine-readable format
  • Right to object: you can object to processing based on legitimate interests or for direct marketing purposes
  • Rights related to automated decision-making: you have rights in relation to any automated decisions made about you

 

To exercise any of these rights, please contact our Data Protection Officer (see below). We will respond to your request within one calendar month.

 

How We Protect Your Data

We take the security of your personal data seriously. We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or alteration. These measures include secure servers, encryption, access controls, and staff training.

 

Contact Us and Your Right to Complain

Data Protection Officer

Our Data Protection Officer (DPO) is our Head of Operations. If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about how we handle your personal data, please contact:

 

Data Protection Officer

Institute of Sales Professionals

Email: Helen.weidner@the-isp.org

Website: https://the-isp.org

 

Right to Lodge a Complaint

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

 

 

Information Commissioner's Office (ICO)

Website: www.ico.org.uk

Helpline: 0303 123 1113

 

We would always appreciate the opportunity to address your concerns before you contact the ICO, so please do get in touch with us in the first instance.

 

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The last updated date at the top of this document will always show when the most recent changes were made. We encourage you to review this policy periodically.

 

Institute of Sales Professionals  |  Privacy Policy  |  Last updated: 28/05/2026