Privacy Policy
Controller: Mary Appleby ("we", "us", "our")
Registered business name: Celerity Education
Email: info@celerity-education.co.uk
Telephone: 0161 383 8603
Data Protection Officer (DPO): [If appointed, insert name and contact details; otherwise state "Not applicable"]
Effective date: 1/11/23
Version: 1.0
1. Scope
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you interact with us, including through our website, services, communications, and in the course of our business operations. It applies to individuals in the United Kingdom and the European Economic Area (EEA), and is intended to comply with the UK GDPR, the EU GDPR (where applicable), and the Data Protection Act 2018.
2. How we collect personal data
We collect personal data directly from you and from other sources:
Direct interactions: when you contact us, make an enquiry, sign a contract, attend meetings or events, or provide information by phone, email, forms, or post.
Website and technology: cookies, analytics, and similar technologies when you visit our website(s). See Cookies & similar technologies below.
Third-party sources: professional advisers, publicly available sources (e.g. Companies House), social media platforms, and service providers who assist us in delivering our services.
3. Categories of personal data we process
Depending on your relationship with us, we may process:
Identification and contact data: name, title, postal address, email, phone number, job title, employer.
Business relationship data: enquiry details, correspondence, meeting notes, contract information, billing and payment details.
Technical and usage data: IP address, device identifiers, browser type, pages viewed, time spent, referral URLs.
Special category data: only where necessary and lawful (e.g., data revealing health information when you choose to share it). We will obtain your explicit consent or rely on another applicable condition under Article 9 UK GDPR before processing such data.
Criminal offence data: processed only in strictly limited circumstances and in accordance with Schedule 1 of the Data Protection Act 2018.
4. Purposes and lawful bases for processing
We use personal data for the following purposes and rely on the indicated lawful bases under Article 6 UK GDPR:
Providing and administering services (including responding to enquiries, preparing proposals, managing projects, and delivering our contractual obligations) — contract; legitimate interests.
Client onboarding, due diligence, and compliance (including identity checks, conflict checks, anti-fraud/AML screening where applicable) — legal obligation; legitimate interests.
Communications and relationship management (updates, administrative messages, and service-related notices) — contract; legitimate interests.
Marketing and events (newsletters, invitations, surveys) — consent where required; otherwise legitimate interests with an unsubscribe option.
Operations, security, and website analytics (troubleshooting, testing, monitoring, preventing abuse, and improving our services) — legitimate interests.
Record-keeping, accounting, and tax — legal obligation.
Where we rely on legitimate interests, we balance our interests with your rights and freedoms and you may object at any time (see Your rights).
If we process special category data, we will rely on one of the conditions in Article 9 UK GDPR (e.g., explicit consent; establishment, exercise or defence of legal claims; substantial public interest with appropriate safeguards).
5. Sharing your personal data
We may share personal data with:
Service providers/Processors: IT hosting, cloud storage, email, CRM, analytics, payment processors, professional advisers, and subcontractors who act on our instructions and are bound by confidentiality and data protection obligations.
Professional partners and counterparties: where necessary to provide our services to you or with your consent.
Authorities and regulators: where required by law or to protect legal rights (e.g., HMRC, courts, supervisory authorities).
Business transfers: in the context of a merger, restructuring, or asset transfer, subject to confidentiality.
We do not sell your personal data.
6. International data transfers
Your data may be transferred to and processed in countries outside the UK/EEA that may not provide the same level of data protection. Where this occurs, we use appropriate safeguards such as:
Adequacy regulations/decisions recognised by the UK or EU; and/or
Standard Contractual Clauses and, where necessary, supplementary measures.
You may contact us for a copy of the relevant safeguards (redactions may apply).
7. Data retention
We keep personal data only for as long as necessary to fulfil the purposes described in this Policy, including to satisfy legal, accounting, or reporting requirements. Typical periods are:
Enquiries (no contract formed): up to [12–24 months] after last contact.
Client and engagement records: [6–7 years] from the end of the engagement or as required by law and professional rules.
Marketing data: until you opt out or withdraw consent, or after a defined inactivity period.
We will securely delete or anonymise data when it is no longer needed.
8. Your rights
Subject to applicable law, you have the right to:
Access your personal data and obtain a copy.
Rectify inaccurate or incomplete data.
Erase your data in certain circumstances.
Restrict our processing in certain circumstances.
Object to processing based on legitimate interests or to direct marketing.
Data portability for data you provided to us, processed by automated means and based on consent or contract.
Withdraw consent at any time, where we rely on consent.
Complain to a supervisory authority (see Complaints).
To exercise these rights, contact us using the details above. We may need to verify your identity before responding.
9. Automated decision-making
We do not conduct solely automated decision-making, including profiling, that produces legal or similarly significant effects on you. If this changes, we will provide meaningful information about the logic involved and the envisaged consequences and your rights.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage. Measures include access controls, encryption in transit and at rest (where appropriate), secure configuration, vendor due diligence, staff training, and incident response procedures.
11. Cookies & similar technologies
We may use cookies and similar technologies on our website to operate the site, remember preferences, and analyse traffic. Where required, we will request your consent via a cookie banner and provide a cookie notice with details of the cookies used and how to manage your preferences.
12. Children’s data
Our services are not directed to children under 13 (or the relevant local age). We do not knowingly collect personal data from children without appropriate consent and safeguards.
13. Third-party links
Our website may include links to third-party sites and services. We are not responsible for their privacy practices. We encourage you to read their privacy policies.
14. Complaints
If you have concerns about our use of your personal data, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://www.ico.org.uk/
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date. Material changes will be notified where appropriate.
Implementation checklist (remove before publishing)
Replace bracketed placeholders (entity name, address, contacts, DPO, retention periods) with your details.
Add your lawful bases tailored to each processing activity.
List your processors/subprocessors and ensure written data processing agreements are in place.
Insert your international transfer mechanisms (SCCs/UK Addendum, adequacy decisions).
Publish/update your cookie notice and consent mechanism if you use non-essential cookies.
Set a version control process and review annually or upon material change.