The UK General Data Protection Regulation (UK GDPR) provides you with significant rights regarding your personal data. This page explains what those rights are and how we ensure compliance with data protection law.
Our Commitment
At zeal-study, we're committed to protecting your personal data and respecting your privacy. We process personal data fairly, lawfully, and transparently, collecting only what we need for specific purposes and keeping it secure.
We regularly review our data practices to ensure ongoing compliance with the UK GDPR and the Data Protection Act 2018.
Data Controller
zeal-study is the data controller for personal information collected through this website and our educational services. This means we determine how and why your data is processed.
Contact details:
Email: [email protected]
Address: Unit 14, Charter Square, Sheffield, S1 2HB
Your Rights Under UK GDPR
The UK GDPR grants you several rights regarding your personal data. We're committed to upholding each of these:
Right to Be Informed
You have the right to know how your data is collected and used. Our Privacy Policy provides this information in clear, accessible language. We'll always tell you what data we collect, why we collect it, and what we do with it.
Right of Access
You can request a copy of all personal data we hold about you. This is sometimes called a "subject access request." We'll respond within 30 days and provide the data in a commonly used electronic format.
Right to Rectification
If any information we hold about you is inaccurate or incomplete, you have the right to have it corrected. Let us know, and we'll update our records promptly.
Right to Erasure
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as when the data is no longer needed for its original purpose or you withdraw consent. Some data may need to be retained for legal or regulatory reasons.
Right to Restrict Processing
In certain situations, you can ask us to limit how we use your data while we verify its accuracy or consider your objection to processing.
Right to Data Portability
Where processing is based on consent or contract, you can request your data in a structured, machine-readable format to transfer to another service provider.
Right to Object
You can object to processing based on legitimate interests at any time. We'll stop processing unless we can demonstrate compelling legitimate grounds that override your rights.
Rights Related to Automated Decision-Making
You have rights regarding automated decisions that significantly affect you. Currently, we don't use automated decision-making processes that would engage these rights.
How We Protect Your Data
We implement appropriate technical and organisational measures to protect personal data:
- Access controls: Only authorised personnel can access personal data, and only for legitimate purposes
- Encryption: Data transmitted via our website uses SSL/TLS encryption
- Secure storage: Personal data is stored in secure systems with appropriate safeguards
- Staff training: Our team receives regular training on data protection requirements
- Third-party vetting: We carefully select and monitor any third parties who process data on our behalf
- Data minimisation: We only collect and retain data that's necessary for specified purposes
Lawful Bases for Processing
We only process personal data when we have a valid legal basis. The bases we rely on include:
- Consent: Where you've given clear consent for specific purposes
- Contract: Where processing is necessary to deliver our services to you
- Legitimate interests: Where processing serves our legitimate business interests without overriding your rights
- Legal obligation: Where we must process data to comply with the law
Data Retention
We don't keep personal data longer than necessary. Retention periods vary depending on the type of data and purpose:
- Enquiry records: 2 years from last contact
- Programme participant records: 6 years from programme completion
- Financial records: 7 years (legal requirement)
- Website analytics: 26 months
After these periods, data is securely deleted or anonymised.
International Transfers
Your data is primarily processed within the UK. Where we use service providers based outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Exercising Your Rights
To exercise any of your rights, contact us at [email protected]. Please include:
- Your name and contact details
- Which right you wish to exercise
- Any information that helps us identify the data in question
We may need to verify your identity before processing your request. We'll respond within 30 days. If we need more time due to complexity, we'll let you know within the initial 30-day period.
Complaints
We take data protection concerns seriously. If you're unhappy with how we've handled your data:
- Contact us first at [email protected] so we can try to resolve the issue
- If you're not satisfied with our response, you can complain to the Information Commissioner's Office (ICO)
ICO contact details:
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Updates
We review our data protection practices regularly. This page will be updated to reflect any changes. Material changes will be communicated through our website.
Further Information
For detailed information about how we handle personal data, please see our Privacy Policy and Cookies Policy.