Privacy Policy and Data Storage Terms
Effective Date: 14/11/2024
Reinvigoration Ltd ("we," "our," "us") is committed to protecting the privacy and security of personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy outlines how we collect, store, use, and protect your data when you interact with our services, including training, e-learning, and consultancy.
1. Data Controller
Reinvigoration Ltd is the data controller responsible for processing your personal data. For inquiries, please contact us at:
- Address: sbarc | spark, Maindy Rd, Cardiff, CF24 4HQ
- Email: info@reinvigoration.com
2. What Data We Collect
We may collect and process the following types of personal data:
- Personal Identifiable Information (PII):
- Name
- Email address
- Phone number
- Job title
- Company/organisation details
- Usage Data:
- Interaction history with our e-learning platforms or services
- IP address, browser type, and device information
- Special Category Data:
- Information you provide voluntarily (e.g., accessibility requirements)
- Information you provide voluntarily (e.g., accessibility requirements)
- Financial Data:
- Payment information (for billing purposes)
3. Purpose of Data Collection
We collect your data for the following purposes:
- To deliver our training, e-learning, and consultancy services.
- To manage client relationships and respond to inquiries.
- To improve and customise our offerings.
- To comply with legal obligations.
4. How We Store Your Data
Your data is stored on secure servers located in the United Kingdom or with trusted third-party providers compliant with UK GDPR standards. Measures in place to secure your data include:
- Encryption of data at rest and in transit.
- Firewalls and access controls.
- Regular security audits and vulnerability assessments.
5. Retention Period
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. After this period, data will be securely deleted or anonymised.
6. Third-Party Data Processors
We may share data with trusted third parties who process data on our behalf, such as:
- Learning Management System (LMS) providers
- Payment processors
- IT service providers
- All third parties are subject to strict contractual obligations to ensure data security and compliance with UK GDPR.
7. Your Data Protection Rights
Under UK GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: Request to limit data processing in certain circumstances.
- Right to Data Portability: Request transfer of your data to another organisation.
- Right to Object: Object to processing of your data based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time (if consent is the basis for processing).
To exercise these rights, contact us at info@reinvigoration.com
8. E-Learning Data Collection and Compliance
When delivering e-learning services, Reinvigoration Ltd complies with additional specific requirements under UK GDPR and other applicable standards to protect the personal data of learners and ensure a secure, transparent, and compliant learning environment. This includes:
a. Types of Data Collected in E-Learning Platforms:- User registration details (e.g., name, email, job title, and company).
- Course progress and completion records.
- Assessment results and feedback.
- Learning preferences or settings customised by the user.
- Interaction logs (e.g., time spent on modules, activity history).
- To personalise the learning experience.
- To track and report progress to learners and their organisations (where applicable).
- To enhance course content based on anonymised usage data.
- To issue certificates and record achievements.
We do not knowingly collect data from individuals under 18 without explicit consent from a parent or guardian. If such data is inadvertently collected, it will be promptly deleted upon identification.
d. Data Storage and Security for E-Learning Platforms:- Personal data is encrypted both in transit (e.g., HTTPS) and at rest.
- Secure user authentication methods (e.g., strong passwords, two-factor authentication).
- Regular updates to platform software to address vulnerabilities.
- Separation of data to ensure organisation-specific data remains private.
Our e-learning platforms may integrate with third-party tools for functionalities such as video hosting, assessments, or reporting. These tools are vetted to ensure compliance with UK GDPR, and data processing agreements are in place with these providers.
f. Data Sharing and Reporting:- For organisational clients, learner progress and performance data may be shared with authorised representatives within the organisation (e.g., managers or HR).
- Learners are informed of this sharing during registration.
- Learning records (e.g., course progress, completion) are retained for up to [Insert Duration, e.g., "5 years"] unless otherwise requested by the individual or client organisation.
- After this period, data is securely deleted or anonymised.
Learners using our e-learning platforms have the right to:
- Access their progress and completion data.
- Request deletion of their account and associated data.
- Update personal information used in the platform.
9. Data Breaches
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay.
10. International Data Transfers
If we transfer your data outside the UK, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government.
- Standard Contractual Clauses (SCCs).
Our website and e-learning platforms use cookies to improve user experience and analyse site usage. You can manage cookie preferences via your browser settings.
12. Changes to This Policy
We may update this policy periodically. Any changes will be communicated via email or our website. Please review this policy regularly to stay informed.
13. Contact Us
If you have questions or concerns about our data storage practices, please contact us at:
- Email: info@reinvigoration.com
- Website: www.reinvigoration.com
This policy ensures that Reinvigoration Ltd complies with UK GDPR, the Data Protection Act 2018, and industry best practices for data storage and privacy.