Data Protection Policy.
The rules we follow when handling personal data about learners, customers and visitors to our websites, under UK GDPR.
About this policy
Elearnment Ltd is a company registered in England and Wales (company number 17458288). We provide online training under the Good Food Hygiene brand, at goodfoodhygiene.co.uk, and publish the company website elearnment.co.uk. Elearnment Ltd is the data controller for the personal data collected through both websites and our online courses.
The Good Food Hygiene Privacy Policy tells learners and customers what we collect and why, and the privacy page on elearnment.co.uk covers what that site collects. This policy is the other side of them: the rules everyone who works with us follows when handling that data. The Good Food Hygiene app has its own privacy notice.
We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
ICO registration: Elearnment Ltd is registered with the Information Commissioner’s Office as a data controller. Registration number: ZC248359.
Who this policy applies to
Everyone who handles personal data for Elearnment Ltd, including directors, staff, contractors and anyone providing support on our behalf.
Our data protection principles
We make sure personal data is:
- used lawfully, fairly and in a way people would expect
- collected for a clear purpose and not used for anything unrelated
- limited to what we actually need
- kept accurate and up to date
- kept no longer than necessary
- kept secure
- handled in a way we can show complies with the law
What we hold, and why
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Name, email, password (stored encrypted) | To run your account and courses | Contract |
| Date of birth and gender (individual learners) | So an inspector can match a certificate to the right person | Legitimate interests |
| Course progress, assessment attempts and answers, certificates | To deliver the course, issue and verify certificates, and handle appeals | Contract |
| Business account details and staff training records | To run the business account the employer has bought | Contract |
| Order and payment records | To sell courses and keep financial records | Contract; legal obligation |
| Marketing email opt-in, with the date given | To send marketing emails only to people who asked for them | Consent |
| Analytics and sign-up source cookies (Good Food Hygiene website) | To see which pages and routes help people | Consent |
| Details of a disability or health condition, if a learner shares them | To arrange a reasonable adjustment | Explicit consent |
| Course feedback answers, if a learner chooses to give them | To review and improve our courses | Legitimate interests |
| Reflective practice records, if a learner writes one | So the learner can keep and print their own CPD record | Contract |
| Complaint, appeal, malpractice and safeguarding records | To handle them fairly and keep a record | Legitimate interests; legal obligation |
| Security logs, such as login attempts | To protect accounts and the websites | Legitimate interests |
| Enquiry form details (elearnment.co.uk) | To reply and prepare a walkthrough | Steps taken at your request before a contract |
| Good Bar Management waitlist email and answers (elearnment.co.uk) | To say when there is something to try, and to decide what to build | Consent |
| Readiness check answers, and an email if a copy is asked for (elearnment.co.uk) | To write and send the summary | Steps taken at your request |
We do not sell personal data, and we do not use it for automated decisions with legal effects. Assessments are marked automatically, but anyone can have a result reviewed by a person under our Appeals Policy.
Service providers
We use a small number of providers who process data on our behalf, each under a written agreement:
- Krystal Hosting — hosts both websites and their databases in the UK
- Cloudflare — protects and speeds up the Good Food Hygiene website
- Stripe — takes card payments; we never see or store full card numbers
- Google Analytics — measures use of the Good Food Hygiene website, only for visitors who accept cookies
- Wordfence — security protection for our websites and logins
- Adobe Fonts — supplies the typeface used on elearnment.co.uk, and receives visitors’ IP addresses to do so
Where a provider processes data outside the UK, we rely on UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.
Keeping data secure
- Both websites are served over an encrypted connection (HTTPS) and protected by a security plugin, and the Good Food Hygiene website is also protected by Cloudflare.
- Passwords are stored in encrypted (hashed) form and can never be read back.
- Card payments are handled by Stripe, not by our websites.
- Administrator access is limited to the people who need it for their role.
- Software is kept up to date.
- Learner data is never downloaded to personal devices or sent by ordinary email unless necessary, and then only securely.
How long we keep data
| Data | Kept for |
|---|---|
| Account, course progress and certificate records | While the account is open, so certificates can still be verified |
| Order and financial records | 6 years, as required for tax and company records |
| Complaint, appeal and malpractice records | 3 years from closure |
| Reasonable adjustment details | Until 12 months after course access ends |
| Marketing consent records | While subscribed, and 2 years after unsubscribing, as proof of consent |
| Course feedback answers | While the account is open; shown to us without names |
| Reflective practice records | While the account is open; never shown in our reports or to an employer |
| Safeguarding records | As long as necessary to protect the person, reviewed yearly |
| Enquiries made through elearnment.co.uk | 12 months after our last exchange |
| Good Bar Management waitlist | Until launch plus 6 months, or until you ask us to remove it |
| Readiness check answers | 12 months |
When data reaches the end of its period, it is deleted or anonymised.
Your rights
Everyone we hold data about can ask to access, correct or delete it, restrict or object to how we use it, or have a copy to take elsewhere. Requests go to enquiries@goodfoodhygiene.co.uk. We respond within one month, free of charge, and check the person’s identity first.
Deleting an account also means its certificates can no longer be verified, so we explain that before deleting.
Data breaches
A personal data breach is anything that leads to data being lost, destroyed, changed, disclosed or accessed without permission.
- Anyone who suspects a breach tells the Director immediately.
- We contain it, then assess the risk to the people affected.
- If there is a risk to people’s rights, we report it to the ICO within 72 hours of becoming aware of it.
- If the risk is high, we tell the people affected without delay, and explain what they can do.
- Every breach, including ones not reported, is recorded with what happened and what we changed.
Data protection by design
Before we add a new feature, tool or provider that uses personal data, we check that it is necessary, collects as little as possible, and is covered by the relevant privacy policy. Any new use of data is added to that privacy policy before it starts.
Training
Anyone given access to personal data reads this policy first and confirms they understand it, with a refresher every year.
Responsibility and review
The Director of Elearnment Ltd is responsible for data protection and for this policy. It is reviewed every year, and whenever we start using personal data in a new way.
Questions or concerns can be sent to enquiries@goodfoodhygiene.co.uk. Anyone unhappy with how we handle their data can also complain to the Information Commissioner’s Office at ico.org.uk.