Legal

Data Processing for Organisations

What happens to your team's information when your practice or trust buys training from us.

Last reviewed 23 August 2026

What this page is: a plain-English description of how we handle your team’s data, published so you can see our position before you talk to us. It is not the contract. If your organisation needs a signed data processing agreement — and most NHS trusts, universities and larger groups do — email info@cejexperts.com and we will put one in front of you. Details marked like this are being confirmed.

Who is responsible for what

Data-protection law splits responsibility between the organisation that decides why information is used (the controller) and the organisation that handles it on their instructions (the processor). Which one we are depends on what you have bought.

Situation You are We are
You buy training and give us a list of staff to enrol Controller Processor, acting on your instructions
Your staff sign up individually with their own money Not involved Controller, dealing with them directly
You ask us to report on your team’s progress Controller Processor
We invoice you and keep our accounts Controller of your contact details Controller of ours

The rest of this page deals with the first case: we are your processor.

What we process for you

  • Who they are — name, work email address, job role, and the site or practice they work at.
  • What they did — which courses they were enrolled on, what they completed, when, and how they scored on any assessment.
  • What they said — answers to any reflective or diagnostic question that forms part of the training, and course feedback.
  • Technical records — sign-in times and IP address, kept for security.

We do not need and do not ask for home addresses, dates of birth, GDC or registration numbers, health information, or anything else about your staff. If you send it to us anyway, we will ask you to stop and delete what you sent.

What we will and will not do with it

We will use it to deliver the training, give your staff access, report progress to you, and support them when they get stuck. That is the whole list.

We will not:

  • market our other services to your staff on the basis of an enrolment you paid for — if they want our newsletter they can subscribe themselves;
  • use their data for our own purposes, including product development, in a form that identifies them;
  • sell it, share it with anyone outside the suppliers listed below, or use it for advertising; or
  • make an automated decision about anyone that has a legal or similarly significant effect.

We may use completion and outcome data in aggregate and anonymised form — “84% of learners finished within six weeks” — where no individual and no client organisation can be identified.

What you are responsible for

As the controller, you need to have told your staff what is happening, and to have a lawful basis for it. Most employers rely on legitimate interests or the employment contract for mandatory training rather than consent, because consent from an employee is rarely freely given.

You are also responsible for the accuracy of the list you send us, for telling us promptly when someone leaves, and for passing on any request one of your staff makes about their own data.

We will help you answer those requests. We will not answer them for you, because they are yours to answer.

Who else touches it

We use a small number of sub-processors to run the service. We stay responsible for what they do.

  • Hosting — the servers and database running the platform.
  • Email delivery — enrolment and support emails.
  • Backup storage — encrypted copies for disaster recovery.

Named suppliers and their locations to be confirmed in the signed agreement. We will tell you before we add or change a sub-processor, and you can object.

Where it is held

We aim to keep learner data in the UK or the EEA. Where a supplier processes it elsewhere, the transfer relies on an adequacy decision, the UK International Data Transfer Addendum, or Standard Contractual Clauses. If your organisation requires UK-only or EEA-only processing, tell us before you buy — it is a reasonable requirement and we would rather know up front than fail it later.

Keeping it safe

  • Encrypted in transit, over TLS.
  • Access limited to the people who need it to do their job, and reviewed when someone’s role changes.
  • Encrypted backups, held separately from the live system and not reachable from the public internet.
  • Software kept patched, with automated backups taken daily.
  • Staff and contractors under written confidentiality obligations.

We are not currently certified to ISO 27001 or Cyber Essentials. If your procurement requires a certification, tell us which one and we will tell you honestly where we stand. We would rather lose a tender than claim a certificate we do not hold.

If something goes wrong

If there is a personal data breach affecting your people, we will tell you without undue delay and in any event within 24 hours of becoming aware of it — sooner than the law requires of us, because you are the one on a 72-hour clock with the regulator, not us.

We will tell you what happened, who is affected, what the likely consequences are, and what we are doing. We will keep telling you as we learn more, rather than waiting until we have a complete picture.

How long we keep it

For as long as the contract runs, plus whatever period you specify. Our default, if you do not specify one, is 12 months after the contract ends, so that a learner can still get a copy of their completion record.

When the period is up, we delete it or return it, whichever you choose. Backups roll off on their own cycle and we will tell you what that cycle is.

Checking up on us

You can ask for the information you need to satisfy yourself we are doing what this page says, and we will provide it. For a larger engagement we will agree audit rights in the signed agreement, including reasonable notice and frequency.

Putting this on a proper footing

Email info@cejexperts.com. Tell us roughly how many people, whether you need reporting, and whether your procurement has data requirements we should know about. We will come back with an agreement rather than a brochure.

See also: Privacy Notice, Refunds and Cancellations, and For Organisations.

Still not clear?

Ask us in your own words.

Legal writing has a way of answering everything except the thing you actually wanted to know.

info@cejexperts.com