This document is provided for transparency and general information. It should be reviewed by a qualified UK legal professional before being relied upon as final legal advice or a substitute for statutory rights.
Who controls your personal information
Controller details
EncryptEdge Labs Limited, Company No. 15830711, 128 City Road, London, EC1V 2NX, United Kingdom, is the data controller for the processing described here.
Privacy enquiries and rights requests may be sent to [email protected]. The Contact page lists the information that helps us identify a privacy request. We have not appointed a statutory Data Protection Officer. Privacy matters are handled by our designated data-protection contact.
Information we collect
Website visitors
Device and browser data, IP address, page interactions, consent preferences, support-chat messages, and analytics data when optional services are accepted.
Applicants
Identity and contact details, CV or application information, education and experience, assessment responses, interview notes, track preferences, availability, and recruitment communications.
Participants
Account details, enrolment and payment status, attendance, submissions, results, mentor feedback, conduct records, support requests, and completion or credential records.
Payments and credentials
Transaction references, amount, currency, payment status, limited billing information supplied by a provider, and credential-verification details. Full card details should not be submitted through this website.
Please do not provide special-category information unless it is necessary and requested for a specific purpose, such as considering a reasonable adjustment.
Purposes and lawful bases
The applicable basis depends on the purpose and our relationship with you.
| Purpose | Typical basis |
|---|---|
| Applications, assessments, interviews, and onboarding | Steps before contract; legitimate interests |
| Programme delivery, assessment, feedback, support, and credentials | Contract; legitimate interests |
| Payments, accounting, fraud prevention, disputes, and compliance | Contract; legal obligation; legitimate interests |
| Security, service improvement, and misuse prevention | Legitimate interests; legal obligation where applicable |
| Optional analytics, support chat, and marketing | Consent, which may be withdrawn |
We determine and document the appropriate basis before processing. See the ICO guide to lawful bases.
Applicants and programme participants
- Applicant information is used to assess suitability, communicate decisions, prevent duplicate or fraudulent applications, and prepare onboarding.
- Participant information is used to provide platform access, deliver activities, assess work, provide feedback, manage conduct, confirm completion, and handle support or appeals.
- Recruitment records are kept separate from ongoing participant records where practical. An unsuccessful application is not treated as a participant record.
- Testimonials, photographs, or identifiable work are published only with permission or another documented legal basis.
International data transfers
Some providers or support personnel may process information outside the United Kingdom. Before a restricted transfer, we assess the destination and use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum, or another lawful safeguard, together with an appropriate data-protection assessment.
Retention periods
Unsuccessful applications
Normally up to 12 months after the decision, unless a complaint, legal claim, fraud-prevention need, or renewed permission requires longer.
Programme and assessment records
Normally for the programme and up to 6 years afterward where contractual, tax, accounting, complaint, or legal-claim requirements apply.
Credential records
Core verification information may be retained for the useful life of a credential to support authenticity checks, corrections, or revocation.
Support and technical records
Normally up to 24 months, subject to shorter provider settings or longer retention for a security incident or dispute.
Records are deleted, anonymised, or securely archived when no longer required. A legal hold or active dispute may extend a period.
Automated decision-making
We do not currently make recruitment, enrolment, disciplinary, or credential decisions solely by automated means where they would produce legal or similarly significant effects. Tools may assist administration, security, duplicate detection, or scoring, but material decisions should include authorised human review.
If this changes, we will explain the logic and likely consequences and provide a way to request human intervention or challenge the decision. See ICO automated-decision guidance.
Your data-protection rights
Depending on the circumstances and legal basis, you may ask for access, correction, erasure, restriction, portability, or human review; object to certain processing or direct marketing; and withdraw consent. Rights are not absolute, and we may verify identity or apply a lawful exemption.
Security, contact, and ICO complaints
Security and younger users
We use proportionate access, confidentiality, monitoring, backup, and incident-response controls, but no online system is completely secure. The services are not directed to children under 13. Applicants under 18 require the legal capacity and any guardian authorisation applicable to the programme and payment.
Contact [email protected] with a privacy concern or rights request. You may also complain to the Information Commissioner's Office. This does not require you to complain to us first.
