Data Protection Policy
Introduction
At Runway Global Ltd, we are committed to ensuring the security and confidentiality of all participant data collected and processed during our learning and development activities. This data protection policy outlines our approach to handling personal data in compliance with the UK Data Protection Act 2018 and the General Data Protection Regulation (GDPR).
Principles of Data Protection
We adhere to the following principles when processing personal data:
- Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and in a transparent manner, ensuring individuals are informed about the processing of their data.
- Purpose Limitation: We only collect and process personal data for specified, explicit, and legitimate purposes and do not process data in a manner incompatible with those purposes.
- Data Minimisation: We ensure that personal data processed is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
- Accuracy: We take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. We also rectify or erase inaccurate or incomplete data without delay.
- Storage Limitation: We store personal data for no longer than is necessary for the purposes for which it is processed.
- Integrity and Confidentiality: We implement appropriate technical and organisational measures to ensure the security of personal data and protect it against unauthorised or unlawful processing and accidental loss, destruction, or damage.
Types of Personal Data We Collect
We may collect the following types of personal data during our learning and development/training activities:
- Contact Information: Names, addresses, email addresses, and phone numbers of individuals participating in our programmes or engaging with our services.
- Demographic Information: Age, gender, occupation, and other demographic details, where relevant to our training programmes.
- Payment Information: Bank details or payment card information for processing payments related to our services.
- Training Data: Information related to attendance, performance, assessments, and feedback collected during training sessions or programmes.
Use of Personal Data
We use personal data for the following purposes:
- To communicate with participants regarding our training programmes, schedules, and updates.
- To facilitate the delivery of training services, including registration, attendance tracking, and assessment.
- To process payments and manage financial transactions related to our programmes or services.
- To improve the quality and effectiveness of our training programmes based on participant feedback and performance data.
Sharing of Personal Data
We may share personal data with third-party service providers, subcontractors, or partners involved in the delivery of our training programmes or related services. We ensure that any third parties processing personal data on our behalf comply with data protection laws and maintain appropriate security measures. We do not sell or rent delegate information to third parties.
Data Subject Rights
Participants have the following rights regarding their personal data:
- Right to Access: The right to request access to their personal data and information about how we process it.
- Right to Rectification: The right to request correction of inaccurate or incomplete personal data.
- Right to Erasure: The right to request erasure of personal data under certain circumstances.
- Right to Restriction of Processing: The right to request restriction of processing of personal data under certain circumstances.
- Right to Data Portability: The right to receive personal data in a structured, commonly used, and machine-readable format.
- Right to Object: The right to object to the processing of personal data under certain circumstances, including direct marketing.
- Rights in Relation to Automated Decision Making and Profiling: The right to object to automated decision making and profiling.
Data Security Measures
We implement appropriate technical and organisational measures to ensure the security of personal data, including:
- Secure Data Storage: We store personal data securely using encryption and access controls.
- Access Controls: Access to personal data is restricted to authorised personnel on a need-to-know basis.
- Data Backup: We regularly perform personal data backups to prevent data loss.
Data Breach Management
In the event of a personal data breach, we will:
- Assess the severity and impact of the breach.
- Notify the relevant supervisory authority within 72 hours, where applicable.
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
Policy Review and Updates
We review this data protection policy regularly to ensure compliance with UK data protection law and any changes in our data processing activities.
Contact Information
For any questions, concerns, or requests regarding our data protection practices, please contact us at hello@jackiehandy.com