Effective Date: June 24, 2026

POLICY 1: DATA PROTECTION & GDPR COMPLIANCE

1. Purpose

As an operational advisory firm interacting with UK Children’s Homes, Renka Group frequently handles sensitive operational metrics, staffing information, and high-level compliance data. This policy ensures full alignment with the UK GDPR and the Data Protection Act 2018.

2. Scope of Data Collected

  • Prospect Data: Names, corporate emails, and phone numbers of Registered Managers (RMs) and Responsible Individuals (RIs) collected via public directories (CQC/Ofsted data) for email outreach.

  • Diagnostic Data: Internal compliance answers, Annex A metrics, and risk tracking inputted by clients into our Typeform portal.

  • Financial Data: Corporate payment card details processed via our payment gateway (Stripe). Note: Renka Group staff never see or store raw credit card numbers.

3. Operational Procedures for Data Handling

  • The Typeform Safe-Vault: All responses submitted through the 120-question Master Internal Audit Framework are automatically encrypted. Client data must never be downloaded onto personal local devices or public computers.

  • Automated Deletion Cycle: To protect client confidentiality, raw diagnostic entries on Typeform are set to automatically archive or delete 90 days after the final RAG Compliance Report has been issued to the client.

  • Zero Regulatory Leakage: Under no circumstances will any staff member of Renka Group share, report, or leak a client’s diagnostic failures, compliance gaps, or internal vulnerabilities to Ofsted, local authorities, or competing care providers.

POLICY 2: CLIENT INTAKE & INVOICING PROCEDURE

1. Purpose

To maintain Julie’s strict boundary of a zero-stress, automated workflow, this procedure outlines the exact path a lead must take before any consulting, diagnostic unlocking, or advisory calls occur.

2. The Step-by-Step Intake Sequence

  1. The Outreach Phase: Spencer’s automated Instantly systems route prospects to book a free 15-minute Triage Call via an online calendar link (e.g., Calendly/TidyCal).

  2. The Discovery Call: Julie or Spencer conducts the 15-minute call using the peer-to-peer authority framework.

  3. The Checkout Trigger: If the prospect agrees to the £297 Assessment, they are directed to the Renka Group website checkout page.

  4. Payment Gatekeeper: The client inputs card details via the Stripe integration.

  5. The Automated Hand-off (Zapier Webhook): * Trigger: Stripe records a successful £297 transaction.

    • Action 1: An automated VAT invoice is sent to the client's email.

    • Action 2: A unique, single-use Typeform link is generated and emailed to the client alongside instructions.

  6. The Boundary Guard: No staff member of Renka Group is authorized to manually send out the 120-question framework link or book a follow-up review call until Stripe confirms the funds are fully cleared. No manual credit accounts or "pay-later" terms are permitted.

POLICY 3: INTELLECTUAL PROPERTY & BRAND PROTECTION

1. Purpose

The core financial asset of Renka Group is the logic-driven 120-Question Master Internal Audit Framework. This policy outlines the strict internal and external boundaries required to protect this proprietary material from piracy or unauthorized duplication.

2. Internal Protections

  • Software Access Boundaries: Access to the back-end editing portals of Typeform, Zapier, and the website host is strictly limited to the founders (Spencer and Julie).

  • Template Security: Raw copies of the 120 questions in Word or Excel formats must never be sent to prospects or clients. The framework must only be experienced dynamically through the live Typeform link.

3. External Enforcement Procedures

  • Watermarked Deliverables: Every RAG report and Compliance Action Plan PDF automatically generated for a client must carry a clear copyright notice: “© 2026 Renka Group. All Rights Reserved. Unauthorized duplication or redistribution strictly prohibited.”

  • The Consultant/Visitor Restriction: If an independent Regulation 44 Visitor or external consultant is found to be copying, mirroring, or using Renka Group's 120-question architecture within their own practices, the company will immediately issue a formal Cease & Desist order via legal counsel, backed by the terms agreed to at checkout.

POLICY 4: INFRASTRUCTURE & DISASTER RECOVERY

1. Purpose

Because Julie is operating the system from Thailand and Spencer is managing the corporate structure from the UK, the business relies entirely on its digital tech-stack. This policy outlines how to manage sudden software or communications failures without breaking client trust.

2. The Tech-Stack Core Components

  • Outreach Engine:Instantly.ai + 4 unique secondary domains.

  • Diagnostic Engine: Typeform.

  • Financial Engine: Stripe.

  • Automation Bridge: Zapier.

3. Contingency Procedures (When System Gaps Occur)

  • Typeform Outage: In the highly unlikely event that Typeform goes offline, Julie will pause scheduled intake emails via Instantly. If a client has already paid their £297, an automated email template will be deployed stating: "Our secure diagnostic servers are currently undergoing a scheduled security optimization. Your unique audit access portal will activate within 12 hours."

  • Domain Burn Protocol: If one of the 4 outreach domains experiences a sudden drop in deliverability or is flagged for spam, Spencer will immediately mark that domain as inactive inside Instantly, replace it with a pre-warmed backup domain, and adjust daily sending volumes down to a safe limit (e.g., 25 emails per domain per day) to preserve network integrity.

  • Communication Sync: A mandatory, brief 15-minute operational sync will occur between Spencer and Julie via a secure channel once per week to review Stripe sales volume, assess tech-stack expenses, and verify system performance against the £1,500/week baseline target.