GDPR Compliance Statement
Last updated: 1 September 2026
Our Commitment to Data Protection
We are committed to protecting the personal data of individuals in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection legislation.
Data Controller Information
For the purposes of data protection legislation, we are the data controller responsible for your personal information.
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by GDPR:
- Consent: When you voluntarily submit forms or contact us, you provide explicit consent for processing
- Contract: Processing necessary for application processing and programme enrollment
- Legitimate Interests: Processing necessary for our business operations and service improvement
Data Subject Rights
Under GDPR, you have comprehensive rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data held by us. We will provide this information within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent.
Right to Restrict Processing
You can request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object
You can object to processing of your personal data where we are relying on legitimate interests as the legal basis.
Rights Related to Automated Decision Making
We do not use automated decision-making or profiling in our processing of personal data.
Exercising Your Rights
To exercise any of your rights under GDPR, please submit a written request to:
We will respond to your request within one month. In complex cases, this period may be extended by two further months, and we will inform you of any such extension.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
International Data Transfers
We do not transfer personal data outside the United Kingdom or European Economic Area.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Application data: 2 years from submission
- Email correspondence: 1 year from last contact
- Cookie data: As specified in our Cookie Policy
Children's Data
Our services are intended for individuals aged 18 and over. We do not knowingly collect personal data from individuals under 18.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
ICO Contact:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Policy Updates
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised date.
Contact for Data Protection Matters
For any questions about GDPR compliance or our data protection practices, please contact: