Data Protection & GDPR Policy
What personal data we hold across acadame.co.uk and acadame-online.com, why we hold it, how long we keep it, and the rights you have over it.
Policy statement
Acadame Ltd is committed to the privacy, security and lawful processing of personal data, in compliance with the UK GDPR, the Data Protection Act 2018 and current UK data protection law. This policy sets out our principles, responsibilities and procedures for protecting personal data.
It forms part of our Integrated Management System and supports compliance with ISO 9001 (documented information, risk, customer requirements), ISO 14001 (regulated compliance and responsible communication) and ISO 45001 (secure handling of worker information). All processing is lawful, fair, transparent and secure across every part of the business, including our digital platforms and public-facing websites.
1Policy and scope
This policy applies to all personal data processed by Acadame Ltd, including:
- Candidate data from training courses and qualifications
- Employee data, including payroll and HR records
- Data processed by external contractors, such as freelance trainers and third-party training providers
- Data shared with stakeholders, including awarding bodies, regulators and certification bodies
- Data collected for marketing, including campaigns through Google Ads, Facebook and Mailchimp
- Data stored and managed in our IT systems
It covers every processing activity, from collection and storage through use, sharing, transfer and disposal, whether electronic or on paper.
2Our two websites
This policy applies to all personal data collected through both of our sites:
- acadame.co.uk, our corporate and booking site
- acadame-online.com, our eLearning platform
That includes contact forms, registration forms, learning platform data, course purchases, analytics tools, cookies, tracking pixels, AI chat interactions and any embedded third-party processor integrated into either site. All staff, contractors and third-party partners must comply with this policy alongside the Confidentiality Policy, the Acceptable Use Policy, the Complaints Policy and the Safeguarding & Prevent Policy.
3The principles we work to
- Lawful processing. Personal data is processed only on lawful grounds: consent, contractual necessity, legal obligation, legitimate interests, or vital interests such as a safeguarding situation
- Transparency. Clear information about processing is given through the privacy and cookie notices published on acadame.co.uk and acadame-online.com
- Data minimisation. We collect only what is necessary for the stated purpose
- Accuracy. Data is kept accurate and up to date
- Security. Measures are in place to prevent unauthorised access or loss
- Retention. Data is kept only as long as legal, operational or regulatory requirements demand
- Accountability. We maintain documentation demonstrating compliance, including impact assessments, breach records, training records and procedural controls under the IMS
4Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection.
Requests are acknowledged within 24 hours and answered within the statutory timeframe. We verify identity before releasing any personal data. A request involving assessment data may need coordination with the awarding body, and erasure may not apply where a legal or awarding body retention obligation overrides the request.
5How long we keep things
- Course paperwork: the validity of the qualification plus two years
- Qualifications valid for life: five years
- Employee and contractor data: six years
- Financial records: seven years
- Marketing data: two years after the last engagement
- System logs and backups: one year, in line with the system provider's requirements
- acadame-online.com accounts: for the duration of course access plus the required audit and certification retention period
Retention may be extended where litigation, an investigation or an appeal is ongoing.
6Security
We use layered security:
- Physical security at our premises
- Technical controls across our systems
- Role-based access control
- Multi-factor authentication, password policies and encryption
- Senior Leadership Team access limited to what oversight requires
- A rule that personal devices may not store personal data unless authorised and protected
Both websites use HTTPS, firewall protection, routine updates, vulnerability reviews, encrypted form submissions and GDPR-compliant secure hosting. Cookie consent banners are displayed and managed in line with PECR and UK GDPR.
7If there is a breach
Every breach must be reported immediately to the Head of Centre, who is also our Data Protection Officer. We will:
- Document the breach
- Notify the ICO within 72 hours where that is required
- Notify the individuals affected where the risk is high
- Notify awarding bodies such as CITB, NEBOSH and IOSH where relevant
- Complete a post-breach review
8Data protection impact assessments
A DPIA is required for high-risk processing, which for us means:
- CCTV with audio
- AI chat interactions
- Website analytics and tracking tools
- Learning platform processing and online assessment
- Special category data
- Pearson VUE and CITB ITC integrations
9Training and awareness
Staff receive GDPR induction, annual refresher training, role-specific training and updated guidance whenever the law changes. Training is monitored under the IMS competence framework.
10AI and emerging technology
We require AI systems to be transparent to users, audited for bias, overseen by humans and secured against breach.
AI systems, including the site chat assistant, must not store unnecessary personal data or make automated decisions affecting certification, assessment outcomes, safeguarding referrals or disciplinary action. AI use on our websites is covered by the published privacy and cookie notices.
11Third-party processors
We hold GDPR-aligned processing agreements with:
- Arlo, for training management and CRM
- WordPress, for the website
- Moodle, for the eLearning platform at acadame-online.com
- Stripe, for payments where applicable
- Google, for Analytics and Ads
- Meta, for Facebook and Instagram advertising
- Tidio, for the chat assistant
- Mailchimp, for email marketing
- HubSpot, for lead management
Transfers outside the UK follow adequacy regulations or contractual safeguards.
12Review
This policy is reviewed annually, after any incident, and whenever the law or our systems change. It is also reviewed as part of the IMS Management Review (ISO 9001 clause 9.3).
13Who to contact
Martin Blakemore is our Head of Centre and Data Protection Officer. Email martin@acadame.co.uk with any data protection question or to exercise your rights.
Our ICO registration number is ZA801226. If you are not satisfied with how we have handled your personal data you can complain to the Information Commissioner's Office.
The regulator
If you are not satisfied with how we have handled your personal data, you can raise it with the Information Commissioner's Office.
Document control
- Registered name
- Acadame Ltd
- Trading names
- Acadame Training Solutions, Acadame
- Registered number
- 12921273
- Registered address
- Trent House, 234 Victoria Road, Fenton, Stoke-on-Trent ST4 2LW
- UKPRN
- 10087409
- ICO registration
- ZA801226
- Telephone
- 0330 124 2165
- hello@acadame.co.uk