We accept Apple Pay Google Pay & 3 interest-free instalments via Klarna · 0330 124 2165
Policy POL-009

Data Protection & GDPR Policy

What personal data we hold across acadame.co.uk and acadame-online.com, why we hold it, how long we keep it, and the rights you have over it.

ReferencePOL-009
Version6
EffectiveDecember 2025
Controlled byMartin Blakemore, Head of Centre
ReviewReviewed annually

Policy statement

Acadame Ltd is committed to the privacy, security and lawful processing of personal data, in compliance with the UK GDPR, the Data Protection Act 2018 and current UK data protection law. This policy sets out our principles, responsibilities and procedures for protecting personal data.

It forms part of our Integrated Management System and supports compliance with ISO 9001 (documented information, risk, customer requirements), ISO 14001 (regulated compliance and responsible communication) and ISO 45001 (secure handling of worker information). All processing is lawful, fair, transparent and secure across every part of the business, including our digital platforms and public-facing websites.

1Policy and scope

This policy applies to all personal data processed by Acadame Ltd, including:

  • Candidate data from training courses and qualifications
  • Employee data, including payroll and HR records
  • Data processed by external contractors, such as freelance trainers and third-party training providers
  • Data shared with stakeholders, including awarding bodies, regulators and certification bodies
  • Data collected for marketing, including campaigns through Google Ads, Facebook and Mailchimp
  • Data stored and managed in our IT systems

It covers every processing activity, from collection and storage through use, sharing, transfer and disposal, whether electronic or on paper.

2Our two websites

This policy applies to all personal data collected through both of our sites:

  • acadame.co.uk, our corporate and booking site
  • acadame-online.com, our eLearning platform

That includes contact forms, registration forms, learning platform data, course purchases, analytics tools, cookies, tracking pixels, AI chat interactions and any embedded third-party processor integrated into either site. All staff, contractors and third-party partners must comply with this policy alongside the Confidentiality Policy, the Acceptable Use Policy, the Complaints Policy and the Safeguarding & Prevent Policy.

3The principles we work to

  • Lawful processing. Personal data is processed only on lawful grounds: consent, contractual necessity, legal obligation, legitimate interests, or vital interests such as a safeguarding situation
  • Transparency. Clear information about processing is given through the privacy and cookie notices published on acadame.co.uk and acadame-online.com
  • Data minimisation. We collect only what is necessary for the stated purpose
  • Accuracy. Data is kept accurate and up to date
  • Security. Measures are in place to prevent unauthorised access or loss
  • Retention. Data is kept only as long as legal, operational or regulatory requirements demand
  • Accountability. We maintain documentation demonstrating compliance, including impact assessments, breach records, training records and procedural controls under the IMS

4Your rights

You have the right of access, rectification, erasure, restriction, data portability and objection.

Requests are acknowledged within 24 hours and answered within the statutory timeframe. We verify identity before releasing any personal data. A request involving assessment data may need coordination with the awarding body, and erasure may not apply where a legal or awarding body retention obligation overrides the request.

5How long we keep things

  • Course paperwork: the validity of the qualification plus two years
  • Qualifications valid for life: five years
  • Employee and contractor data: six years
  • Financial records: seven years
  • Marketing data: two years after the last engagement
  • System logs and backups: one year, in line with the system provider's requirements
  • acadame-online.com accounts: for the duration of course access plus the required audit and certification retention period

Retention may be extended where litigation, an investigation or an appeal is ongoing.

6Security

We use layered security:

  • Physical security at our premises
  • Technical controls across our systems
  • Role-based access control
  • Multi-factor authentication, password policies and encryption
  • Senior Leadership Team access limited to what oversight requires
  • A rule that personal devices may not store personal data unless authorised and protected

Both websites use HTTPS, firewall protection, routine updates, vulnerability reviews, encrypted form submissions and GDPR-compliant secure hosting. Cookie consent banners are displayed and managed in line with PECR and UK GDPR.

7If there is a breach

Every breach must be reported immediately to the Head of Centre, who is also our Data Protection Officer. We will:

  • Document the breach
  • Notify the ICO within 72 hours where that is required
  • Notify the individuals affected where the risk is high
  • Notify awarding bodies such as CITB, NEBOSH and IOSH where relevant
  • Complete a post-breach review

8Data protection impact assessments

A DPIA is required for high-risk processing, which for us means:

  • CCTV with audio
  • AI chat interactions
  • Website analytics and tracking tools
  • Learning platform processing and online assessment
  • Special category data
  • Pearson VUE and CITB ITC integrations

9Training and awareness

Staff receive GDPR induction, annual refresher training, role-specific training and updated guidance whenever the law changes. Training is monitored under the IMS competence framework.

10AI and emerging technology

We require AI systems to be transparent to users, audited for bias, overseen by humans and secured against breach.

AI systems, including the site chat assistant, must not store unnecessary personal data or make automated decisions affecting certification, assessment outcomes, safeguarding referrals or disciplinary action. AI use on our websites is covered by the published privacy and cookie notices.

11Third-party processors

We hold GDPR-aligned processing agreements with:

  • Arlo, for training management and CRM
  • WordPress, for the website
  • Moodle, for the eLearning platform at acadame-online.com
  • Stripe, for payments where applicable
  • Google, for Analytics and Ads
  • Meta, for Facebook and Instagram advertising
  • Tidio, for the chat assistant
  • Mailchimp, for email marketing
  • HubSpot, for lead management

Transfers outside the UK follow adequacy regulations or contractual safeguards.

12Review

This policy is reviewed annually, after any incident, and whenever the law or our systems change. It is also reviewed as part of the IMS Management Review (ISO 9001 clause 9.3).

13Who to contact

Martin Blakemore is our Head of Centre and Data Protection Officer. Email martin@acadame.co.uk with any data protection question or to exercise your rights.

Our ICO registration number is ZA801226. If you are not satisfied with how we have handled your personal data you can complain to the Information Commissioner's Office.

The regulator

If you are not satisfied with how we have handled your personal data, you can raise it with the Information Commissioner's Office.

Document control

Registered name
Acadame Ltd
Trading names
Acadame Training Solutions, Acadame
Registered number
12921273
Registered address
Trent House, 234 Victoria Road, Fenton, Stoke-on-Trent ST4 2LW
UKPRN
10087409
ICO registration
ZA801226
Telephone
0330 124 2165
Skip to main content