The UK General Data Protection Regulation (UK GDPR) provides you with significant rights regarding your personal data. This page explains what those rights are and how we ensure compliance with data protection law.

Our Commitment

At zeal-study, we're committed to protecting your personal data and respecting your privacy. We process personal data fairly, lawfully, and transparently, collecting only what we need for specific purposes and keeping it secure.

We regularly review our data practices to ensure ongoing compliance with the UK GDPR and the Data Protection Act 2018.

Data Controller

zeal-study is the data controller for personal information collected through this website and our educational services. This means we determine how and why your data is processed.

Contact details:
Email: [email protected]
Address: Unit 14, Charter Square, Sheffield, S1 2HB

Your Rights Under UK GDPR

The UK GDPR grants you several rights regarding your personal data. We're committed to upholding each of these:

Right to Be Informed

You have the right to know how your data is collected and used. Our Privacy Policy provides this information in clear, accessible language. We'll always tell you what data we collect, why we collect it, and what we do with it.

Right of Access

You can request a copy of all personal data we hold about you. This is sometimes called a "subject access request." We'll respond within 30 days and provide the data in a commonly used electronic format.

Right to Rectification

If any information we hold about you is inaccurate or incomplete, you have the right to have it corrected. Let us know, and we'll update our records promptly.

Right to Erasure

Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as when the data is no longer needed for its original purpose or you withdraw consent. Some data may need to be retained for legal or regulatory reasons.

Right to Restrict Processing

In certain situations, you can ask us to limit how we use your data while we verify its accuracy or consider your objection to processing.

Right to Data Portability

Where processing is based on consent or contract, you can request your data in a structured, machine-readable format to transfer to another service provider.

Right to Object

You can object to processing based on legitimate interests at any time. We'll stop processing unless we can demonstrate compelling legitimate grounds that override your rights.

Rights Related to Automated Decision-Making

You have rights regarding automated decisions that significantly affect you. Currently, we don't use automated decision-making processes that would engage these rights.

How We Protect Your Data

We implement appropriate technical and organisational measures to protect personal data:

  • Access controls: Only authorised personnel can access personal data, and only for legitimate purposes
  • Encryption: Data transmitted via our website uses SSL/TLS encryption
  • Secure storage: Personal data is stored in secure systems with appropriate safeguards
  • Staff training: Our team receives regular training on data protection requirements
  • Third-party vetting: We carefully select and monitor any third parties who process data on our behalf
  • Data minimisation: We only collect and retain data that's necessary for specified purposes

Lawful Bases for Processing

We only process personal data when we have a valid legal basis. The bases we rely on include:

  • Consent: Where you've given clear consent for specific purposes
  • Contract: Where processing is necessary to deliver our services to you
  • Legitimate interests: Where processing serves our legitimate business interests without overriding your rights
  • Legal obligation: Where we must process data to comply with the law

Data Retention

We don't keep personal data longer than necessary. Retention periods vary depending on the type of data and purpose:

  • Enquiry records: 2 years from last contact
  • Programme participant records: 6 years from programme completion
  • Financial records: 7 years (legal requirement)
  • Website analytics: 26 months

After these periods, data is securely deleted or anonymised.

International Transfers

Your data is primarily processed within the UK. Where we use service providers based outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.

Exercising Your Rights

To exercise any of your rights, contact us at [email protected]. Please include:

  • Your name and contact details
  • Which right you wish to exercise
  • Any information that helps us identify the data in question

We may need to verify your identity before processing your request. We'll respond within 30 days. If we need more time due to complexity, we'll let you know within the initial 30-day period.

Complaints

We take data protection concerns seriously. If you're unhappy with how we've handled your data:

  1. Contact us first at [email protected] so we can try to resolve the issue
  2. If you're not satisfied with our response, you can complain to the Information Commissioner's Office (ICO)

ICO contact details:
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Updates

We review our data protection practices regularly. This page will be updated to reflect any changes. Material changes will be communicated through our website.

Further Information

For detailed information about how we handle personal data, please see our Privacy Policy and Cookies Policy.