We protect personal data in compliance with UK GDPR, ensuring secure storage, fair processing, and clear retention policies.
1. Introduction
Alliance First Aid Training Academy Ltd ("Alliance Academy") is committed to protecting the privacy and security of personal data. This policy outlines how we collect, store, process, and retain data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Scope
This policy applies to all employees, contractors, learners, and any third parties handling personal data on behalf of Alliance Academy.
3. Data Collection and Processing
We collect and process personal data only where it is necessary for:
- Enrolling learners in training courses.
- Managing assessments and certifications.
- Complying with regulatory and awarding body requirements (e.g., Qualsafe Awards).
- Communicating with learners and clients.
- Business operations, including financial and administrative functions.
4. Lawful Basis for Processing
Personal data is processed under one or more of the following lawful bases:
- Consent – When individuals provide explicit permission.
- Contractual Obligation – When data is necessary for a contract.
- Legal Obligation – When compliance with the law is required.
- Legitimate Interests – When processing is necessary for legitimate business purposes, provided it does not override individuals’ rights.
5. Data Storage and Security
- Personal data is stored securely using appropriate technical and organisational measures.
- Access to data is restricted to authorised personnel only.
- Digital records are protected using encryption, firewalls, and secure access controls.
- Physical records are stored securely and disposed of properly when no longer needed.
6. Data Retention
We retain personal data only as long as necessary for legal, regulatory, and business purposes:
- Learner records – Retained for at least 3 years after course completion, as required by Qualsafe Awards.
- Financial records – Retained for 6 years in accordance with HMRC regulations.
- Employee records – Retained for up to 6 years after employment ends.
- Marketing data – Retained until an individual opts out.
- Data is securely deleted or anonymised once the retention period expires.
7. Data Sharing and Third Parties
We do not sell or share personal data with third parties except where:
- Required by law or regulatory bodies (e.g., Qualsafe Awards, HMRC).
- Necessary to fulfil contractual obligations (e.g., certification bodies, payment processors).
- Explicit consent has been provided.
8. Individual Rights
Under UK GDPR, individuals have the right to:
- Access their personal data.
- Request corrections to inaccurate data.
- Request data deletion (subject to legal retention requirements).
- Restrict or object to processing.
- Request data portability.
- Lodge complaints with the Information Commissioner’s Office (ICO).
9. Data Breach Reporting
In the event of a data breach:
- Incidents are assessed and documented.
- If necessary, affected individuals and the ICO will be notified within 72 hours.
10. Policy Review and Updates
This policy is reviewed annually or in response to legislative changes to ensure continued compliance.
Date: 02/02/2025
Updates to this page
-
Initial commit to new website.