Privacy Policy

MB Partners

MBP: Privacy Policy

Last updated: 1/8/2026

Who are we?

MBP is a B Corp™ certified sports marketing agency connecting brands, rights holders, and talent through commercial expertise and authentic relationships.

Founded by former Formula One driver Mark Blundell, we combine first-hand motorsport experience with commercial expertise and business performance at the highest level, creating partnerships that deliver measurable impact.

Using sport as the conduit, we maximise marketing opportunities for business growth. Our insider access, global reach, and bespoke delivery connect brands with the power of motorsport and beyond, to drive lasting commercial success.

Operating across key international markets, we give partners access to the people, platforms, and opportunities that drive both global and local business growth.

As a certified B Corp™, recognised by B Lab, MBP meets high standards of social and environmental performance, transparency, and accountability, reflecting our belief that strong commercial results and responsible business should go hand in hand.

Data controller

The data controller responsible for your personal data is:

MB Partners Limited 

Registered office: Kindred House, 17 Hartfield Road, London, United Kingdom, SW19 3SE

Company registration number: 06945477

Privacy contact: office@wearembp.com

Third party links

Our website may include links to third-party websites of our partners and to social media sites. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their security or their management of your personal data. We encourage you to visit their privacy policies to understand how your personal data may be collected and used.

How do we get your information?

We collect information about you from the following sources:

  • Directly from you
  • From your employer when you are nominated to attend an event
  • From completing our guest registration form
  • From your employer when you are nominated to participate in the Partner Agreement
  • From our other MBP Partners
  • From our website when you visit, or when you open our emails (see Cookies section below)

What personal data we process and why

Information related to your employment

We collect and use the following information to carry out the contract we have with you directly or with your employer:

  • Name
  • Business email address
  • Business contact telephone numbers (landline or mobile)
  • Job title 

Personal information we may use to make accommodations for events

  • Dietary requirements
  • Company
  • Job title
  • Gender
  • Partner company
  • Date of birth
  • Jacket size
  • Address
  • Golf handicap
  • Medical conditions
  • Accessibility requirements
  • Whether you have held a valid driver's licence for the past 12 months

We may use this information to:

  • Perform analysis to identify appropriate potential business contacts from within our MBP partner group
  • Provide your contact details to other members of our MBP partner group to facilitate introductions
  • Compile event delegate nominations and arrange invitations
  • Coordinate and manage events
  • Coordinate and provide you with discounts, offers and events from other members of MBP's partner group
  • Contact you pre/post event to provide arrival instructions, key event information, and to collect feedback

Where we analyse your data to identify potential business contacts or match you with partner opportunities, this involves a limited form of profiling. This does not produce decisions with legal or similarly significant effects on you, and you can object to it at any time (see 'Your right to object to processing' below).

Information relating to your health and other special category data

We may need to collect information about any health conditions, your access requirements and dietary needs when you attend our events. This information may be passed to our venue locations and catering partners to help us ensure your wellbeing and to meet your specific needs. We will only process this information with your explicit consent.

Information related to events

We may need to collect information such as your driving licence details or passport information in order to ensure you are entitled to participate in event activities, or to arrange travel and accommodation related to events.

Information related to surveys

We conduct surveys for the purposes of reviewing our services in order to improve our delivery. The data collected from surveys is managed by Serve First CX Limited and Google — you can read Serve First's and Google’s privacy notice on their respective websites. The data is only available to a small number of our team who are responsible for running or administering the particular survey.

Most survey questions require quantitative responses (for example, agree/disagree); however, some free-text boxes are included. We would advise you not to share identifiable information about yourself in these boxes if you wish to remain anonymous. When appropriate, we will also provide additional privacy information regarding specific surveys.

Cookies and similar technologies

Lawful basis for processing your personal data

Depending on the processing activity, we rely on the following lawful bases for processing your personal data under UK GDPR:

  • Article 6(1)(b) — processing necessary for the performance of a contract
  • Article 6(1)(f) — our legitimate interests
  • Article 6(1)(c) — compliance with our legal obligations
  • Article 6(1)(d) — to protect your vital interests or those of another person

Where we are processing your personal data for the purpose of event management and you do not provide the required data to us, we will be unable to complete your registration and confirm your attendance.

Special category data

Where the information we process is special category data — for example, information relating to access requirements or food allergies — the additional bases we rely on are:

  • Article 9(1)(a) — where you have provided your explicit consent to the processing
  • Article 9(2)(c) — to protect your vital interests where you are incapable of giving consent

How long we keep your personal data

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for — for example, satisfying legal, accounting, event guest management, or reporting requirements.

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.

In some circumstances we may anonymise your personal data (so it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Data sharing

We may share your information with third parties in certain circumstances:

  • When we are legally obliged to do so, for example under a court order
  • With government agencies such as HMRC, regulators or other authorities who require reporting of processing activities in certain circumstances
  • With our legal advisors, insurance companies, bankers and auditors who provide us with services
  • With organisations we may consider entering into commercial transactions with, for example mergers, acquisitions, or the sale of parts of our business
  • With clubs, associations and other organisations for business and/or professional purposes, for example to manage professional memberships
  • With relevant suppliers such as event locations and catering partners

Our service providers

  • Productive.io — our project management platform. Handles data through secure cloud storage, automated CSV/Excel imports, and API access, and states it maintains GDPR compliance.
  • Webflow — our website platform. Handles data through built-in storage, native form collection, and the Webflow CMS, with external tools used for more complex data needs.
  • Xero — our accounting and financial management software. Uses cloud storage, automated document capture, and secure API integrations, and states it maintains regulatory compliance appropriate to financial data.
  • Mailchimp — used to send marketing email communications and manage press releases. States it applies TLS 1.2+ encryption and password hashing, and participates in the EU–U.S. Data Privacy Framework alongside Standard Contractual Clauses for international transfers.
  • Airtable — used for guest management registration forms and to store data submitted via those forms.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We have contracts in place with our service providers (data processors) which restrict processing to what we instruct, require an appropriate level of security, and prevent them from using your personal data for their own purposes.

Use of Claude (Anthropic AI)

We use Claude, an AI assistant provided by Anthropic, PBC ("Anthropic"), in our day-to-day workflows, including automating tasks, summarising content, and responding to requests. Claude connects to the following third-party services on our behalf: Gmail, Google Drive, Slack, and Airtable.

When Claude is used with these connected services, relevant data from them (such as emails, files, messages, or records) may be shared with Anthropic to complete the requested task. According to Anthropic's published policies at the time of writing, this data is used only to generate a response or complete the task, and is not used to train Anthropic's underlying AI models. We recommend reviewing Anthropic's current privacy and data usage policy at anthropic.com for the most up-to-date position, as third-party practices may change.

Transfers of personal data

Some of our service providers are based outside the United Kingdom or the European Economic Area (EEA), so their processing of your personal data will involve a transfer to a 'third country'.

Whenever we transfer your personal data to a third country, we ensure an appropriate level of protection through one of the following safeguards:

  • Adequacy: the UK Government or European Commission has deemed the destination country to provide an adequate level of data protection (for example, transfers to the United States under the UK–US Data Bridge / EU–U.S. Data Privacy Framework, where the receiving organisation is certified)
  • Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum, approved by the relevant regulators, which contractually bind the receiving party to UK/EU-equivalent data protection standards

Please contact us using the details above if you want further information on the specific mechanism used for a particular transfer.

Your rights in relation to our processing

As an individual, you have certain rights regarding our processing of your personal data, including a right to lodge a complaint about our processing with the Information Commissioner's Office (ico.org.uk), which is responsible for oversight and enforcement of data protection law in the UK.

You are not required to pay any charge for exercising your rights. We may refuse to comply with a request, or charge a reasonable fee, if the request is clearly unfounded, repetitive, or excessive.

We may need to request specific information from you to confirm your identity before acting on a rights request — this is a security measure to ensure personal data is not disclosed to anyone without the right to receive it.

We have one month to respond to you, except where the request is complex, in which case we may extend this by a further two months.

To exercise any of your rights, contact privacy@wearembp.com (or jo@wearembp.com), including details of the right you wish to exercise. If your request concerns erasure, correction, restriction or objection, please provide details of the information concerned. If your request is for access to your data, it would help (though is not required) if you could describe the information you wish to receive.

Your right of access

You have the right to ask us for copies of your personal information. This right always applies, though some exemptions mean you may not always receive all the information we process.

Your right to rectification

You have the right to ask us to rectify information you think is inaccurate, or to complete information you think is incomplete. This right always applies.

Your right to erasure

You have the right to ask us to erase your personal information in certain circumstances (the 'right to be forgotten'), including where you have successfully exercised your right to object, where we may have processed your data unlawfully, or where erasure is required to comply with local law. We may not always be able to comply for specific legal reasons, which we will explain to you at the time.

Your right to restriction of processing

You have the right to ask us to restrict the processing of your information in certain circumstances.

Your right to object to processing

You have the right to object to processing carried out on the basis of legitimate interest if you feel it impacts your fundamental rights and freedoms. We do not have to stop processing if we (or a partner) have strong and legitimate grounds to continue. You also have the right to object where we process your data for direct marketing purposes; any marketing content we send will include an option to unsubscribe.

Your right to data portability

This applies only to information you have given us. You have the right to ask that we transfer that information to another organisation, or provide it to you directly, where we process it based on your consent or a contract, and the processing is automated.

Children's data

Some of our events involve children — for example, family or educational activities linked to our motorsport programmes. Where this is the case, we collect a limited amount of data about the child: their first and last name, and any dietary information needed to keep them safe and looked after at the event.

This data is provided to us directly by a parent or guardian, or by the child's school on the family's behalf. We do not collect this data directly from a child, and we do not collect any special category data beyond dietary information (for example, we do not collect health, medical or other sensitive details about children beyond what is needed for catering and allergy safety).

  • Lawful basis: we process this data with the consent of the parent, guardian or school providing it, and/or because it is necessary to protect the child's vital interests (Article 6(1)(a)/(d), and Article 9(2)(a) where dietary information reveals a health condition, such as an allergy).
  • Data minimisation: we only collect name and dietary/allergy information for this purpose — we do not collect addresses, dates of birth, photographs, or other identifying details about children unless a parent, guardian or school provides these voluntarily for a specific, disclosed purpose.
  • Retention: children's data is kept only for as long as needed to plan and run the event, plus a short period for safety follow-up, then deleted.
  • Sharing: dietary information may be shared with our catering and venue partners solely to accommodate allergies and dietary needs, on the same confidentiality terms as our other suppliers.

A parent, guardian or school providing a child's data on their behalf can exercise any of the rights described above (access, rectification, erasure, etc.) for that child by contacting us using the details above.

Automated decision-making

We do not use your personal data for any processing that produces legal or similarly significant effects on you without human involvement. Some limited profiling is used to identify relevant business contacts within our partner network, as described above, and you can object to this at any time.

Further information

CCTV

We operate CCTV in our offices for the purpose of crime prevention and the security of our employees and visitors.

Your image may be captured on CCTV equipment when you attend events we have arranged. We do not own the CCTV systems at third-party event locations; please refer to the relevant venue's privacy policy for information about how your image data is processed there.

Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to employees, agents, contractors and other third parties who have a business need to know. They may only access data on our instructions and are subject to contractual confidentiality obligations.

Review of this policy

This policy was last updated on [insert actual date]. Any changes we make to the way we process your personal data will be reflected in updates to this policy. In the event of significant changes, or one-off processing events, we will take action to inform you directly.