Who is responsible for what
Data-protection law splits responsibility between the organisation that decides why information is used (the controller) and the organisation that handles it on their instructions (the processor). Which one we are depends on what you have bought.
| Situation | You are | We are |
|---|---|---|
| You buy training and give us a list of staff to enrol | Controller | Processor, acting on your instructions |
| Your staff sign up individually with their own money | Not involved | Controller, dealing with them directly |
| You ask us to report on your team’s progress | Controller | Processor |
| We invoice you and keep our accounts | Controller of your contact details | Controller of ours |
The rest of this page deals with the first case: we are your processor.
What we process for you
- Who they are — name, work email address, job role, and the site or practice they work at.
- What they did — which courses they were enrolled on, what they completed, when, and how they scored on any assessment.
- What they said — answers to any reflective or diagnostic question that forms part of the training, and course feedback.
- Technical records — sign-in times and IP address, kept for security.
We do not need and do not ask for home addresses, dates of birth, GDC or registration numbers, health information, or anything else about your staff. If you send it to us anyway, we will ask you to stop and delete what you sent.
What we will and will not do with it
We will use it to deliver the training, give your staff access, report progress to you, and support them when they get stuck. That is the whole list.
We will not:
- market our other services to your staff on the basis of an enrolment you paid for — if they want our newsletter they can subscribe themselves;
- use their data for our own purposes, including product development, in a form that identifies them;
- sell it, share it with anyone outside the suppliers listed below, or use it for advertising; or
- make an automated decision about anyone that has a legal or similarly significant effect.
We may use completion and outcome data in aggregate and anonymised form — “84% of learners finished within six weeks” — where no individual and no client organisation can be identified.
What you are responsible for
As the controller, you need to have told your staff what is happening, and to have a lawful basis for it. Most employers rely on legitimate interests or the employment contract for mandatory training rather than consent, because consent from an employee is rarely freely given.
You are also responsible for the accuracy of the list you send us, for telling us promptly when someone leaves, and for passing on any request one of your staff makes about their own data.
We will help you answer those requests. We will not answer them for you, because they are yours to answer.
Who else touches it
We use a small number of sub-processors to run the service. We stay responsible for what they do.
- Hosting — the servers and database running the platform.
- Email delivery — enrolment and support emails.
- Backup storage — encrypted copies for disaster recovery.
Named suppliers and their locations to be confirmed in the signed agreement. We will tell you before we add or change a sub-processor, and you can object.
Where it is held
We aim to keep learner data in the UK or the EEA. Where a supplier processes it elsewhere, the transfer relies on an adequacy decision, the UK International Data Transfer Addendum, or Standard Contractual Clauses. If your organisation requires UK-only or EEA-only processing, tell us before you buy — it is a reasonable requirement and we would rather know up front than fail it later.
Keeping it safe
- Encrypted in transit, over TLS.
- Access limited to the people who need it to do their job, and reviewed when someone’s role changes.
- Encrypted backups, held separately from the live system and not reachable from the public internet.
- Software kept patched, with automated backups taken daily.
- Staff and contractors under written confidentiality obligations.
We are not currently certified to ISO 27001 or Cyber Essentials. If your procurement requires a certification, tell us which one and we will tell you honestly where we stand. We would rather lose a tender than claim a certificate we do not hold.
If something goes wrong
If there is a personal data breach affecting your people, we will tell you without undue delay and in any event within 24 hours of becoming aware of it — sooner than the law requires of us, because you are the one on a 72-hour clock with the regulator, not us.
We will tell you what happened, who is affected, what the likely consequences are, and what we are doing. We will keep telling you as we learn more, rather than waiting until we have a complete picture.
How long we keep it
For as long as the contract runs, plus whatever period you specify. Our default, if you do not specify one, is 12 months after the contract ends, so that a learner can still get a copy of their completion record.
When the period is up, we delete it or return it, whichever you choose. Backups roll off on their own cycle and we will tell you what that cycle is.
Checking up on us
You can ask for the information you need to satisfy yourself we are doing what this page says, and we will provide it. For a larger engagement we will agree audit rights in the signed agreement, including reasonable notice and frequency.
Putting this on a proper footing
Email info@cejexperts.com. Tell us roughly how many people, whether you need reporting, and whether your procurement has data requirements we should know about. We will come back with an agreement rather than a brochure.
See also: Privacy Notice, Refunds and Cancellations, and For Organisations.