Privacy Policy

At Care Staff Academy, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy outlines how we collect, use, store, and protect your personal information in compliance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

1. What Is Personal Data?

Personal data refers to any information that relates to an identified or identifiable living individual. This includes names, contact details, email addresses, training records, and any other data that can directly or indirectly identify you.

2. Who Are We?

Care Staff Academy is the data controller responsible for the collection and use of your personal information. We ensure that your data is processed lawfully, transparently, and for a specific purpose.

Data Controller: Care Staff Academy

Email: admin@carestaffacademy.com

Phone: 03300589277

Address: Basement Suite, 42–44 Bishopsgate, London, England, EC2N 4AH

3. How We Collect and Use Your Personal Data

We only collect personal information that is necessary to deliver our services. This includes when you:

  • Register or book onto training courses
  • Contact us via phone, email, or web forms
  • Participate in assessments or online modules
  • Sign up for newsletters or marketing updates

We use your personal data for:

  • Processing bookings and training course registrations
  • Issuing training certificates and maintaining qualification records
  • Identifying and communicating with you
  • Responding to enquiries or complaints
  • Sending relevant updates, policy changes, or course information
  • Informing you of offers or new training programmes (with consent)
  • Meeting legal, accreditation, and regulatory obligations

4. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contractual necessity – to deliver services you have requested
  • Legitimate interest – for internal administration, course updates, or service improvements
  • Legal obligation – for regulatory compliance and audit requirements
  • Consent – for optional marketing or communications (can be withdrawn at any time)

5. Data Sharing and Third Parties

We do not sell or trade your personal information. We may share your data only with trusted third parties who assist in delivering our services, such as:

  • Online training platforms
  • Certification bodies
  • Email service providers (e.g. Mailchimp)
  • Payment processors (e.g. Stripe, WorldPay)
  • Accrediting organisations (e.g. CPD Certification Services)
  • Delivery partners (e.g. Royal Mail, DPD)

Note: All third parties are bound by confidentiality and data protection agreements.

6. Your Data Rights

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion when data is no longer required
  • Restriction: Limit how we use your data
  • Data portability: Receive your data in a structured, machine-readable format
  • Objection: Object to data processing based on legitimate interest
  • Withdraw consent: At any time, where processing is based on consent
  • Complaint: Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, email us at: admin@carestaffacademy.com

7. Cookies

We use cookies to enhance your user experience, such as:

  • Remembering your login or session preferences
  • Tracking course progress or purchases
  • Analysing site traffic (anonymously)

You can manage or disable cookies through your browser settings. For more details, refer to our Cookie Policy.

8. Data Retention

We retain your personal data only for as long as necessary:

  • For training and certification records – up to 7 years, unless required longer for legal or audit reasons
  • For marketing – until you unsubscribe
  • For customer enquiries – up to 12 months after resolution

9. Data Security

We implement appropriate technical and organisational measures to protect your data from unauthorised access, loss, or misuse. These include:

  • Secure servers and encryption
  • Role-based access controls
  • Regular data reviews and audits

10. External Links

Our website may contain links to external websites. We are not responsible for the privacy policies or practices of these third-party sites. Please review their policies before submitting personal data.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in legal or operational requirements. The latest version will always be available on our website.

12. Contact Us

If you have any questions, concerns, or requests related to this policy or your personal data, please contact:

Care Staff Academy

Email: admin@carestaffacademy.com

Phone: 03300589277

Address: Basement Suite, 42–44 Bishopsgate, London, England, EC2N 4AH