The policy owner is the Cenit College UK Board of Directors.
Cenit College UK is committed to safeguarding the rights and freedoms of individuals in connection with personal data, and in doing so complying with relevant data protection laws. The purpose of this policy is to set out the conditions that must be satisfied by Cenit College UK in relation to the obtaining, handling, processing, storage, transportation and destruction of personal information. It applies to data collected and stored for all employees, learners, and other stakeholders. Furthermore, this policy ensures that the organisation complies with the requirements of the relevant UK legislation, namely the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
This policy is applicable to processing activities in relation to personal and sensitive data carried out by Cenit College UK in the normal course of its business.
Specifically, this policy is applicable to:
This Policy should be read in conjunction with
This policy is designed to inform employees about their obligation to protect the privacy of individuals and the security of their personal information and how Cenit College UK will handle personal data that it collects in the normal course of business.
Data: information which is stored electronically, on a computer, or in a certain paper based filing system
Data subjects: living individuals about whom Cenit College UK holds data
Controllers: are the organisations which determine the purposes for which and the manner in which personal is collected and processed (DfE are the Data Controller for all Bootcamp programmes)
Processors: include any person who processes personal data on behalf of a controller – (Cenit College UK act as processors for the DfE on Bootcamp programmes)
Sensitive or Special category data: includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition or sexual life, or about the commission of, or proceedings for, any offence committed or alleged to have been committed by that person, the disposal of such proceedings or the sentence of any court in such proceedings. This data can only processed under strict conditions and will usually require the express consent of the person concerned.
The Board of Directors are responsible for approving this policy and ensuring organisation wide compliance.
Financial Controller is responsible for maintaining all financial records.
All employees (full, part time, contracted) are responsible for ensuring compliance in their respective roles and duties and upon circulation of this policy reading and understanding its components.
The Data Protection Manager (we are not obligated to appoint a Data Protection Office by law) has the following responsibilities in accordance with article 69 of the UK GDPR and 37 of the UK DPA.
Cenit College UK processes and stores data in relation to the following.
This policy and associated procedures, controls and measures ensure that all Cenit College UK employees and contractors are fully aware of their Data Privacy commitments. Furthermore, it ensures they should carry out their duties in accordance with applicable legislation and should any issue arise the data protection manager is instantly informed, so any corrective action is taken immediately.
All personal data enquires should be made to the Cenit College UK Data Protection Manager at the following email address: dataprotection@cenitcollege.co.uk
If a data subject is not satisfied with the information provided by Cenit College UK, they are entitled to make a complaint to the Information Commissioner’s Office.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK95AF
Helpline: 03031231113
Under current legislation, data subjects have increased rights and data controllers are required to notify data subjects of their rights. Individuals have the right to:
Where processing is based on consent, Cenit College UK will demonstrate that the data subject has consented to processing of his or her personal data, when asking permission to process their personal data. Where consent is given by the data subject (for example, the use of personal data for marketing purposes) Cenit College UK will maintain records evidencing this consent. Such consent must be clearly presented, understood, unambiguous, separate from any terms and conditions and freely given. This should be given in a positive form without pre-ticked boxes.
Such consent can be withdrawn at any time by the data subject. However, the withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
Cenit College UK will ensure that the following protocols are implemented regarding consent.
Marketing: the clearest way Cenit College UK obtains consent is via tick an opt-in box confirming the data subject is happy to receive marketing emails. Communications will inform data subjects that they can withdraw their consent. Clear records on what a person has consented to shall be maintained.
In the course of its business activities, any Cenit College UK employee or contractor processing personal data must comply with the seven data protection principles. The initial six provide that data must be:
The right of access gives individuals the right to obtain a copy of their data. It helps data subjects understand what data is being collected about them, and whether it is lawful. An individual can make a data subject access request in writing or verbally, including on social media. A request is valid if it is clear that an individual is asking for their own personal data, they do not need to refer to legislation or use specific wording.
Any member of staff who received a request must forward it to the Data Protection Manager immediately. This is because Cenit College UK must comply with the request without undue delay and in most cases within one month of receiving the request. There is provision to extend for further subject to certain conditions. Other factors to take into account include:
Cenit College UK may also withhold personal information that is requested to the extent that it is permitted to do so by legislation.
It is the responsibility of all employees to ensure that personal data is collected, used, processed, stored, transferred and shared only in accordance with this Policy. If you become aware of any actual or suspected personal data breach or compromise, any breach of this policy or complaint by a client of an actual breach, regardless of severity, the Data Protection Manager must be informed immediately. All actual and potential data breaches must be raised, investigated and handled in an urgent and confidential manner.
All staff must attend data protection training at least annually.
The QA Manager will monitor this policy as part of their annual QA audit to ensure the effectiveness of this policy.
The Data Protection Manager (DPM), in conjunction with the Board of Directors, will monitor and approve this policy on an ongoing basis using the following mechanisms.
Cookie | Duration | Description |
---|---|---|
__stripe_mid | Stripe sets this cookie to process payments. | |
__stripe_sid | Stripe sets this cookie to process payments. | |
cookielawinfo-checkbox-advertisement | Set by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Advertisement". | |
cookielawinfo-checkbox-analytics | Set by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Analytics". | |
cookielawinfo-checkbox-functional | Set by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Functional". | |
cookielawinfo-checkbox-necessary | Set by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Necessary" category. | |
cookielawinfo-checkbox-others | Set by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Others". | |
cookielawinfo-checkbox-performance | Set by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Performance". | |
CookieLawInfoConsent | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. | |
m | Stripe sets this cookie for fraud prevention purposes. It identifies the device used to access the website, allowing the website to be formatted accordingly. | |
PHPSESSID | This cookie is native to PHP applications. The cookie stores and identifies a user's unique session ID to manage user sessions on the website. The cookie is a session cookie and will be deleted when all the browser windows are closed. | |
rc::a | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. | |
rc::c | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
Cookie | Duration | Description |
---|---|---|
_fbp | Facebook sets this cookie to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising after visiting the website. | |
_ga | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. | |
_ga_* | Google Analytics sets this cookie to store and count page views. | |
_gat_UA-* | Google Analytics sets this cookie for user behaviour tracking.n | |
_gcl_au | Google Tag Manager sets the cookie to experiment advertisement efficiency of websites using their services. | |
_gid | Google Analytics sets this cookie to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously. | |
last_pys_landing_page | PixelYourSite plugin sets this cookie to manages the analytical services. | |
last_pysTrafficSource | PixelYourSite plugin sets this cookie to manage the analytical services. | |
pbid | PixelYourSite plugin sets this cookie to manage the analytical services. | |
pys_first_visit | PixelYourSite plugin sets this cookie to manage the analytical services. | |
pys_landing_page | PixelYourSite plugin sets this cookie to manages the analytical services. | |
pys_session_limit | PixelYourSite plugin sets this cookie to manage the analytical services. | |
pys_start_session | PixelYourSite plugin sets this cookie to manage the analytical services. | |
pysTrafficSource | PixelYourSite plugin sets this cookie to manage the analytical services. | |
vuid | Vimeo installs this cookie to collect tracking information by setting a unique ID to embed videos on the website. |
Cookie | Duration | Description |
---|---|---|
__cf_bm | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. | |
_cfuvid | Calendly sets this cookie to track users across sessions to optimize user experience by maintaining session consistency and providing personalized services | |
li_gc | Linkedin set this cookie for storing visitor's consent regarding using cookies for non-essential purposes. | |
lidc | LinkedIn sets the lidc cookie to facilitate data center selection. | |
wcml_client_currency | Description is currently not available. | |
wcml_client_currency_language | Description is currently not available. | |
wp-wpml_current_language | WordPress multilingual plugin sets this cookie to store the current language/language settings. | |
wpEmojiSettingsSupports | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly. |
Cookie | Duration | Description |
---|---|---|
bcookie | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser IDs. | |
NID | Google sets the cookie for advertising purposes; to limit the number of times the user sees an ad, to unwanted mute ads, and to measure the effectiveness of ads. |