Privacy Policy

THE WHOLE GROUP PRIVACY NOTICE 

Last updated: 05 / 08 / 25

  1. INTRODUCTION

The Whole Group (“TWG”, “we”, “us” or “our”) provides business workflow management tools for deployment on the ServiceNow platform, together with related consultancy services (the “Services”).

This privacy notice sets out how we collect, store, process, transfer, share and use data that identifies or is associated with you ("personal information") when you visit our website at www.thewholegroup.com (the “Site”) or use our Services. 

When we provide our Services, most of the personal information we collect is processed on behalf of our enterprise clients. Please refer to our clients’ privacy policies for information about how this personal information is use. This privacy notice only sets out how we use the personal information we collect for our own purposes (i.e. as a “controller” or equivalent term under applicable law).

If you have any questions about this privacy notice or how we use your personal information, please contact us using the details in the “Contact Us” paragraph below. 

If you are in the United Kingdom (“UK”), European Economic Area (“EEA”) [or Switzerland], please also refer to the Additional European Privacy Disclosures for further information about the identity of the controller of your personal information, the lawful basis we rely on for processing and the personal information rights made available to individuals located in those jurisdictions under applicable law. 

  1. Contact Us

If you have any questions, comments and requests regarding this privacy notice or how we use your personal information, please contact product-support@thewholegroup.com   

  1. PERSONAL INFORMATION WE COLLECT ABOUT YOU AND HOW WE USE IT

Information you provide when you use the Site or contact us about our Services

We collect the following personal information that you submit directly to us when you use the Site or contact us in relation to the Services. This can include information you provide to us when you make a request on the Site, correspond with us by phone, e-mail or otherwise, subscribe for our marketing communications, or use some other features of the Site:

  • Contact information, including your name, email address, phone number, your employer and job role. We use this information to contact you in relation to the Site or the Services, to respond to your comments or queries and to send you marketing materials. 

  • Your chat, comments and other correspondence. We use this information to respond to your comments and queries. 

  • Your marketing communications preferences. We use this information to manage how we send you marketing, and to comply with our legal obligations. 

Information you provide when you sign up to our Services as a customer admin

When you sign up to our Services on behalf of a customer, or if a customer designates you as an admin user on their account, we collect the following personal information: 

  • Contact and professional information, such as your first name, last name, email address, telephone number, the name of the customer on whose behalf you communicate with us in respect of the use of the Services, and your role at that customer. We use this information to communicate with you about the relevant customer’s use of the Services, such as sending service-related communications, notices and invoices, as well as to send marketing materials.

  • Your marketing communications preferences. We use this information to manage how we send you marketing, and to comply with our legal obligations.

Information you provide when you are granted access to the Services by a customer

We use most of the information we receive about you when a customer grants you access to our Services on behalf of the relevant customer and on their instructions (i.e. to provide you with access to the Services in accordance with the agreement between the customer and us). We do, however, also collect and use the following for our own purposes:

  • Comments, questions and feedback that you submit to us about your use of the Services. We mostly use this to provide support services to the customer, but we also use this information to identify ways in which we can improve our Services, such as identifying errors and potential new features and functionalities. 

Information we collect automatically

Like all online services, we also collect certain personal information about you automatically when you use the Site to understand how the Site is used and how we can improve it, as well as to tailor the adverts you see online to your interests, such as:

  • Your approximate location. We do not collect your precise geolocation; however, your IP address may provide us with an approximate location. We may use this information for security purposes, to ensure our Site is secure for you, our other users and ourselves, and to personalise how our Site is presented to you.

  • Information about how you access and use the Site, including the time you access the Site and how long you access it for, the approximate location that you access the Site, the site from which you came and the site to which you are going when you leave the Site, the pages you visit, the links you click, your interactions on the Site and other actions you take on the Site. We use this information to present the Site to you, to ensure our Site is secure for you, our other users and ourselves, to personalise how our Site is presented to you and to monitor the Site for improvement purposes. 

  • Information about your device. We also collect information about the tablet, smartphone or other electronic device you use to connect to the Site. This information can include details about the type of device, unique device identifying numbers, operating systems, browsers and applications connected to the Site through the device, your mobile network, your IP address and your device's telephone number (if it has one). We use this information to present the Site to you, to ensure our Site is secure for you, our other users and ourselves, to personalise how our Site is presented to you and to monitor the Site for improvement purposes. 

  • Analytics information, which we collect via third-party analytics tools. We use this information to help us measure traffic and usage trends for the services, monitor the performance of the Site and to understand more about the demographics of our users in order to identify ways in which we can improve the Site.

We (and our third-party partners and service providers) use different technologies to collect information, including cookies, embedded scripts, mobile SDKs, location-identifying technologies and web beacons. For reference, cookies are small data files stored on your hard drive or in device memory that help us improve our Services and your experience, see which areas and features of our Services are popular, and count visits and web beacons (also known as “pixel tags” or “clear GIFs”) are electronic images that may be used in our Services or emails and help deliver cookies, count visits, and understand usage and campaign effectiveness. For more information about cookies and how to disable them, see our [Cookie Policy].

Information we collect from third parties

We may also obtain information about you from other sources. For example, we may collect information about you from third parties, including but not limited to mailing list providers and publicly available sources. We may also obtain information about you from social media platforms, marketing partners, and other third parties. We may use this information to supplement the information that you provide us and/or the information we collect from you. We use this information to inform our marketing outreach strategy and to personalise the information we send to you. 

Other uses of personal information 

We may also use all of the above information for the following purposes:

  • To respond to requests from law enforcement, and any court orders we receive; and 

  • To comply with our legal obligations, resolve any disputes that we may have with any of our users, and enforce our agreements with third parties. 

We may combine information we collect from you directly with information we collect automatically to help us identify specific use of, or errors that you experience in, and allow us to provide more tailored support in relation to the Services.

If you are in the UK, EEA [or Switzerland], please refer to the Additional European Privacy Disclosures, for further information about the lawful bases we rely on to process your personal information. 

  1. HOW LONG WE KEEP YOUR PERSONAL INFORMATION

We will store the personal information we collect for no longer than necessary for the purposes set out and in accordance with our legal obligations and legitimate business interests. 

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and the applicable legal requirements. 

Once retention of the personal information is no longer reasonably necessary for the purposes outlined above, we will either delete or deidentify the personal information or, if that is not possible (for example, because personal information has been stored in backup archives), we will securely store the personal information and isolate it from further active processing until deletion or deidentification is possible. 

  1. RECIPIENTS

As required in accordance with how we use your personal information, we may share your personal information with the following:

  • Affiliates. We may share your personal information with affiliated legal entities within our family of companies.

  • Service providers, such as providers of web hosting or other technical services such as analytic services or communication services.

  • Advisors, such as legal advisors or accountants.

  • Purchasers and third parties in connection with a business transaction, such as in connection with a transaction, such as a merger, sale of assets or shares, reorganisation, financing, change of control or acquisition of all or a portion of our business.

  • Law enforcement, regulators and other parties for legal reasons. We may share your personal information with third parties as required by law or if we reasonably believe that such action is necessary to (i) comply with the law and the reasonable requests of law enforcement; (ii) detect and investigate illegal activities and breaches of agreements; and / or (iii) exercise or protect the rights, property or personal safety of The Whole Group, its users or others.

  • Third party ad networks and advertising partners, such as advertising agencies and exchanges that use personal information to serve adverts to you based on your browsing history when you browse the internet.

If you are in the UK, EEA [or Switzerland], please refer to the Additional European Privacy Disclosures, for further information about the disclosures of your personal information to recipients. 

  1. MARKETING AND COMMUNICATIONS 

From time to time we may contact you with information about our products and services, including sending you marketing messages and asking for your feedback on our products and services. 

Our marketing messages will generally be sent by [email and text messages]. For some marketing messages, we may use personal information we collect about you to help us determine the most relevant marketing information to share with you. 

If you wish to withdraw your consent or opt-out of our marketing communications, you can click on the unsubscribe link in the footer of our marketing emails or by contacting us at product-support@thewholegroup.com  We make every effort to promptly process all unsubscribe requests. You may not opt-out of service-related communications (e.g., account verification, transactional communications, changes/updates to the features of the Site or Service, technical and security notices).

  1. STORING AND TRANSFERRING YOUR PERSONAL INFORMATION

Security. We implement appropriate technical and organisational measures to protect your personal information against accidental or unlawful destruction, loss, change or damage. All personal information we collect will be stored on our secure servers. We will never send you unsolicited emails or contact you by phone requesting your ID, password, credit or debit card information or national identification numbers. 

International Transfers of your personal information. The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third-party service providers have operations. 

We will take appropriate steps to ensure that your personal information is treated securely and in accordance with applicable law and this privacy notice regardless of where it is processed.

If you wish to enquire further about the safeguards we use, please contact us using the details set out at the end of this privacy notice. 

If you are in the UK, EEA [or Switzerland], please refer to the Additional European Privacy Disclosures, for further information about the international transfer safeguards we have in place. 

  1. LINKS TO THIRD PARTY SITES

The Site and the Services may, from time to time, contain links to and from third party websites, including those of other users, our partner networks, advertisers, partner merchants, news publications, social media platforms, retailers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. Please check the individual policies before you submit any information to those websites.

  1. OUR POLICY TOWARDS CHILDREN

The Site and Services are not directed at persons under 18 and we do not knowingly collect personal information from children under 18. If you become aware that your child has provided us with personal information, without your consent, either directly or by other means, then please contact us using the details below so that we can take steps to delete such information and terminate any account your child has created with us.

  1. CHANGES TO THIS POLICY

We may update this privacy notice from time to time and so you should review this page periodically. When we change this privacy notice in a material way, we will update the "last modified" date at the top of this privacy notice. Changes to this privacy notice are effective when they are posted on this page.

  1. NOTICE TO YOU

If we need to provide you with information about something, whether for legal, marketing or other business-related purposes, we will select what we believe is the best way to get in contact with you. We will usually do this through email or by placing a notice on the Site. 

ADDITIONAL EEA, UK [AND SWISS] DISCLOSURES

These disclosures provide additional information about our personal information processing practices relating to individuals in the EEA, UK [and Switzerland]. 

  1. Who is responsible for your personal information

The Whole Group, Inc (“TWG US”) and The Whole Group Limited (“TWG UK”), act as joint controllers of the personal information you provide or that we collect when you use the Site or contact us about our Services. This means that TWG US and TWG UK jointly determine and are responsible for how your personal information is used.

When we provide our Services to our enterprise clients, the relevant client will be the controller of most of the personal information that we collect. This means that the relevant client determines and is responsible for how that personal information is used. Each of TWG US and TWG UK will process that personal information primarily as processors on behalf of the relevant client, meaning that we have each contractually committed to processing that personal information only on the instructions of the relevant client.

TWG US and TWG UK do, however, also collect and use certain personal information in connection with the operation of the Services for our own purposes, as further described in the section headed “Personal information we collect about you and how we use it”. When we do so, TWG US and TWG UK act as independent or joint controllers, as further set out in the paragraph headed “How we share your personal information: joint controllers” below, meaning that we independently or jointly determine and are responsible for how your personal information is used.  

Information about when TWG US and TWG UK act as joint controllers and how we have allocated responsibility between us in relation to personal information can be found in the paragraph headed “How we share your personal information: joint controllers” below. You can contact us in relation to any questions or requests relating to your personal information that is processed jointly between TWG US and TWG UK. You can also assert your rights against any of the joint controllers, who will then ensure that your rights are also enforced against the other joint controllers. 

  1. Personal information we collect about you and how we use it

We rely on the following lawful bases when we process your personal information as described in the privacy notice:

Information you provide when you use the Site or contact us about our Services

How we use personal information

Categories of personal information

Lawful basis we rely on

Respond to your comments and queries in relation to the Services.

Contact information



Chat, comments and other correspondence

The processing is necessary for our legitimate interests, namely communicating with prospective customers.

Send you marketing communications in accordance with your preferences

Contact information



Marketing communications preferences

Where permitted under applicable law, the processing is necessary for our legitimate interests, namely promoting our products and services to prospective customers. 



Where required under applicable law, we rely on your consent.

Comply with your marketing communications preferences

Contact information



Marketing communications preferences

The processing is necessary for compliance with a legal obligation to which we are subject.

Information you provide when you sign up to our Services as a customer admin

How we use personal information

Categories of personal information

Lawful basis we rely on

Communicate in relation to the customer’s use of the Services and otherwise administer the relationship between us and the customer.

Contact and professional information



The processing is necessary for our legitimate interests, namely sending service-related communications to customers.

Send you marketing communications in accordance with your preferences

Contact and professional information



Marketing communications preferences

Where permitted under applicable law, the processing is necessary for our legitimate interests, namely promoting our products and services to prospective customers. 



Where required under applicable law, we rely on your consent.

Comply with your marketing communications preferences

Contact and professional information



Marketing communications preferences

The processing is necessary for compliance with a legal obligation to which we are subject.

Information you provide when you are granted access to the Services by a customer

How we use personal information

Categories of personal information

Lawful basis we rely on

Identify ways in which we can improve the Services, such as identifying errors and potential new features and functionalities.

Comments, questions and feedback.

The processing is necessary for our legitimate interests, namely informing our product development and improvement.

Information we collect automatically

How we use personal information

Categories of personal information

Lawful basis we rely on

Ensure the security and integrity of our Site.

Approximate location.



Information about how you access and use the Site.



Information about your device.

The processing is necessary for our legitimate interests, namely ensuring the security and integrity of our Site.

Personalise the way the Site is presented to you.

Approximate location



Information about how you access and use the Site.



Information about your device.

Your consent.

Monitor the performance of the Site and Services to identify errors and ways in which we can improve them.

Information about how you access and use the Site.



Information about your device.



Analytics information.

Your consent.

Measure traffic and usage trends to understand how our Site is used.

Analytics information.

Your consent.

  1. Our use of cookies

We typically collect information about how you use the Site and the device you use to access the Site through a variety of tracking technologies, including cookies and similar tracking technologies. For more detailed information about the cookies we use, please see [our [Cookie Notice] / [Section X below]].

Other than cookies and similar technologies that are required to operate the Site or ensure its security, if you visit our Site from the EEA, UK [or Switzerland] we will only use cookies and similar technologies if you give us your consent to do so. You can change your consent preferences at any time by [***].

  1. How we share your personal information 

Joint controllers

TWG US and TWG UK share the information processed as described in this privacy notice in connection with providing centralised administration, shared IT resources and intragroup services. Where permitted under applicable law, the lawful basis we rely on for these transfers is that it is necessary for our legitimate interests, namely administering, providing and receiving centralised intragroup services. Where required, however, we will only transfer your personal information where we have your consent to do so. 

TWG US and TWG UK as joint or independent controllers as follows:

Processing

Categories of personal information

Joint or independent controllers

Respond to your comments and queries in relation to the Services.

Contact information (Site users)



Chat, comments and other correspondence (Site users)


TWG US and TWG UK act as joint controllers

Send you marketing communications in accordance with your preferences.

Contact information (Site users)



Marketing preferences (Site users)


TWG US and TWG UK act as joint controllers

Contact and professional information (customer admins)



Marketing preferences (customer admins)


TWG US and TWG UK act as independent controllers

Comply with your marketing communications preferences.

Contact information (Site users)



Marketing preferences (Site users)


TWG US and TWG UK act as joint controllers

Contact and professional information (customer admins)



Marketing preferences (customer admins)


TWG US and TWG UK act as independent controllers

Communicate in relation to the customer’s use of the Services and administer the relationship with the Customer.

Contact and professional information (customer admins)

TWG US and TWG UK act as independent controllers

Identify ways in which we can improve the Site and Services.

Comments, questions and feedback



Information about how you access and use the Site.



Information about your device (Site users)



Analytics information (Site users)


TWG US and TWG UK act as joint controllers

Ensure the integrity of our Site.

Approximate location.



Information about how you access and use the Site.



Information about your device.


TWG US and TWG UK act as joint controllers

Personalise the way the Site is presented to you.

Approximate location



Information about how you access and use the Site.



Information about your device.


TWG US and TWG UK act as joint controllers

Measure traffic and usage trends to understand how our Site is used.

Analytics information.

TWG US and TWG UK act as joint controllers

TWG US and TWG UK have allocated responsibility for complying with applicable data protection law between them as follows:

  • Information about how we use your personal information: TWG US and TWG UK are jointly required to ensure that the information contained in our privacy policy, including these Additional European Privacy Disclosures, is provided to you before they allow us to collect personal information about you. 

  • Lawfulness and consent: TWG US and TWG UK are jointly responsible for identifying the lawful basis relied on for the processing of your personal information. TWG UK is responsible for obtaining or procuring your consent to the processing of your personal information. 

  • Your rights: TWG UK is the primary contact point for your exercise of your rights. You can exercise your rights as set out in the “Your rights in respect of your personal information” section below in respect of both TWG UK and TWG US. 

  • Security: each of TWG US and TWG UK entities maintain safeguards to ensure that the personal information we process as joint controllers is kept secure.

  • Transfers: each of TWG US and TWG UK have implemented their own safeguards for the transfers of your personal information we undertake, including transfers to recipients outside of the jurisdiction you are in.

How we otherwise share personal information

Recipient

Why we share it and how they will use it

Lawful basis 

Service providers, such as providers of web hosting or other technical services such as analytic services or communication services.

Depending on the nature of the services, we may share all of the above personal information with third-party vendors and other service providers perform services for us or on our behalf.

These service providers will use your personal information as processors on our instructions.

Advisors, such as legal advisors or accountants.

Depending on the nature of the services, we may share all of the above personal information with these advisors, who will use your personal information to provide advisory services to us.

The lawful basis we rely on for these transfers is that the processing is necessary for our legitimate interests, namely obtaining legal, accounting and other professional advice.

Purchasers and third parties in connection with a business transaction. Your personal information may be disclosed to third parties in connection with a transaction, such as a merger, sale of assets or shares, reorganisation, financing, change of control or acquisition of all or a portion of our business.

We may share all of the above personal information with these recipients, who will use your personal information to review and assess a potential transaction to purchase our business or assets.


The lawful basis we rely on for these transfers is that they are necessary for our and the purchaser's legitimate interests, namely to conduct due diligence on our business and assets in connection with a potential acquisition.

Law enforcement, regulators and other parties for legal reasons. We may share your personal information with third parties as required by law or if we reasonably believe that such action is necessary to (i) comply with the law and the reasonable requests of law enforcement; (ii) detect and investigate illegal activities and breaches of agreements; and / or (iii) exercise or protect the rights, property or personal safety of The Whole Group, its users or others.

We may share all of the above personal information with these recipients, which will use your personal information in the performance of their regulatory or law enforcement role, or to advise us in connection with a potential claim or regulatory enforcement action.

The lawful basis we rely on for sharing personal information with these recipients is that the processing is either necessary to comply with a legal obligation to which we are subject or, where there is no applicable legal obligation to share this data, that the sharing is necessary for our legitimate interests, namely enforcing our rights or complying with requests from regulatory authorities.

  1. International Transfers

    1. Your personal information may be processed outside of the UK, EEA [or Switzerland], including in the U.S. We will ensure that these international transfers of your personal information are made pursuant to appropriate safeguards, such as: 

      1. ensuring that the personal information is only transferred to countries recognised by the UK Secretary of State, European Commission [or Swiss Federal Council] (as applicable) as offering an equivalent level of protection as compared to the level of protection in the country you are located (and “Adequacy Decision”); or 

      2. the transfer is to a third party who uses appropriate safeguards in respect of the processing in question, included but not limited to the UK or EU standard contractual clauses [including as amended to given effect to Swiss Law], which are recognised as offering adequate protection for the rights and freedoms of data subject, as adopted by the UK Secretary of State, the European Commission [or Swiss Federal Council] (as applicable).

    2. We may transfer your personal information to, or store your personal information in, the following countries:

Country

Appropriate Safeguard 

United States of America

Standard Contractual Clauses adopted by the European Commission / regulation of the UK Secretary of State [/ the Swiss Federal Council].

Sharing with recipients certified to the EU-U.S. Data Privacy Framework [the Swiss-U.S. Data Privacy Framework] and the UK Extension.

United Kingdom 

Adequacy Decision (if you are located in the EEA [or Switzerland])

EEA

Adequacy Decision (if you are located in the UK [or Switzerland])

  1. If you wish to enquire further about the safeguards we use, please contact us using the details set out at the end of this privacy notice. 

  1. Your Rights in Respect of Your Personal Information 

    1. If you are resident in the UK, EEA [or Switzerland], in accordance with applicable privacy law you have the following rights in respect of your personal information that we hold:

      1. Right of access. You have the right to obtain:

        1. confirmation of whether, and where, we are processing your personal information;

        2. information about the categories of personal information we are processing, the purposes for which we process your personal information and information as to how we determine applicable retention periods;

        3. information about the categories of recipients with whom we may share your personal information; and

        4. a copy of the personal information we hold about you.

      2. Right of portability. You have the right, in certain circumstances, to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal information to another person.

      3. Right to rectification. You have the right to obtain rectification of any inaccurate or incomplete personal information we hold about you without undue delay. 

      4. Right to erasure. You have the right, in some circumstances, to require us to erase your personal information without undue delay if the continued processing of that personal information is not justified. 

      5. Right to restriction. You have the right, in some circumstances, to require us to limit the purposes for which we process your personal information if the continued processing of the personal information in this way is not justified, such as where the accuracy of the personal information is contested by you.

      6. Right to withdraw consent. Where we rely on your consent for processing your personal information, you have the right to withdraw your consent. Withdrawal of your consent will not affect the lawfulness of the processing of your personal information before you withdrew your consent.

    2. You have a right to object to any processing based on our legitimate interests. There may, depending on the particular circumstances, be compelling reasons for continuing to process your personal information despite your objection, and we will assess and inform you if that is the case.  You can object to marketing activities for any reason. 

    3. If you wish to exercise one of these rights, please contact us using the contact details at the top of this privacy notice. 

    4. We will not charge you a fee for complying with your request to exercise one of these rights, other than where the request is manifestly unfounded or excessive (such as if you submit a number of repeated requests), in which case we may charge you a reasonable fee to cover our administrative costs. 

    5. You also have the right to lodge a complaint to your national data protection authority. If you are in the UK, your local data protection authority is the Information Commissioner's Office, which can be contacted using the details at https://ico.org.uk/global/contact-us/. If you are in the EEA, further information about how to contact your local data protection authority is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. [If you are in Switzerland, your local data protection authority is the Federal Data Protection and Information Commissioner, which can be contacted you using the details at https://www.edoeb.admin.ch/en/contact-2.