Springpod Data Protection Policy

Edited

1. Purpose

We need to process certain information about natural living persons. These include students, suppliers, business contacts, employees, and other natural persons with whom the organisation has a relationship or holds personal information.

This Policy describes how we must process personal data to meet our data protection standards and ensures

that we follow the law.

This data protection policy ensures the company:

  • Follows the data protection laws and follows good practices and codes of conduct.

  • Protects the rights of natural living persons whose data we control and process.

  • Is transparent about how we control and processes a natural living person's data.

  • Protects itself from the risks of a regulatory infringement or breach.

  • Protects its proprietary information.


2. Scope

This version-controlled document is applicable to all entities operating under the Springpod brand, including Springpod Holdings Ltd, Springpod Inc., and The Education Hub Group Ltd trading as Springpod. It encompasses all employees, contractors, consultants, temporary staff, and any third parties engaged in activities on behalf of these entities.

The provisions within this document are binding across all operational jurisdictions and apply to all business functions, processes, and systems managed or overseen by the entities. This ensures a consistent and unified approach to governance, compliance, and operational excellence throughout the organisation.


3. Risk Appetite

We have no appetite for infringement of data protection regulations and non-compliance leading to a breach.

We also have no appetite for detrimental impact to users or third parties caused by non-compliant personal data processing.


4. Policy Statement

4.1. The Data Protection Law

In the United Kingdom, the following instruments govern the protection of personal information:

  • The Data Protection Act of 2018

  • The Data Protection (Charges and Information) Regulations 2018

  • The Privacy in Electronic Communication Regulation (PECR) 2003

  • The UK General Data Protection Regulation (UK GDPR)

  • The Data (Use and Access) Act (DUAA 2025)

These regulations, viewed in conjunction with guidance from the UK's Information Commissioner's Office (ICO) and the European Data Protection Board (EDPB) and any precedents set by enforcement actions, describe how we must collect, handle, store, and erase personal information. The rules apply regardless of whether we store data electronically, on paper or other materials.

Personal information must be collected and used fairly, stored safely and not shared unlawfully.

The UK GDPR sets out six data protection principles. Personal data shall be:

  • Processed lawfully, fairly and in a transparent manner concerning individuals

  • Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be inconsistent with the original purposes

  • Adequate, relevant, and limited to what is necessary for the purposes for which they are processed

  • Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay

  • Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is to be processed; personal data may be stored for more extended periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to the implementation of the appropriate technical and organisational measures required by the GDPR to safeguard the rights and freedoms of individuals

  • Processed in a manner that ensures proper security of the personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organisational measures.

  • The company is also responsible for, and must be able to demonstrate, compliance with these principles.

This is the accountability principle in Article 5(2) of the UK GDPR.

4.2. Individuals' Rights

The regulations state that data subjects have the following rights:

  • The right to be informed

  • The right of access

  • The right to rectification

  • The right to erasure

  • The right to restrict processing

  • The right to data portability

  • The right to object

  • Rights concerning automated decision making and profiling,

  • The right to complain about data protection matters

4.3. Data protection risks

This Policy helps to protect the company from data security risks, including:

  • Breaches of confidentiality. For instance, information is being given out inappropriately.

  • Not offering a choice. For instance, all individuals should be free to choose how the company uses data relating to them.

  • Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.

  • Damage to business operations through the disclosure of proprietary information.

4.4. Training

All staff will receive training on this Policy, supporting policies and company procedures. In addition, new joiners will receive training as part of the induction process, and refresher training will be delivered at least every year or whenever there is a substantial change in the law or the company policy and procedure.

4.5. Fair and transparent processing

We will ensure that any processing of personal data has a documented legal basis. All parties who handle personal data will be aware of the conditions for processing. The conditions for processing will be made available to data subjects in the form of a privacy notice.

4.6. Privacy Notices

To ensure fair, lawful, and transparent processing, a privacy notice shall be made available to data subjects on our website at www.springpod.com/privacy-policy. The privacy notice will let them know how we intend to use and protect their data and will include the following detail:

  • The purposes of processing data.

  • The information that is to be held.

  • The lawful basis for processing data.

  • The length of time that the data will be kept.

  • The measures that are taken to protect all data held.

  • The third parties that can access this data.

  • The contact details of the Data Protection Officer (DPO).

  • Information for Data Subjects about their rights and how to exercise them.

4.7. Accuracy

The company shall ensure that any personal data processed is accurate and up to date.

We are responsible for taking reasonable steps to ensure that any personal data the company holds is correct and up to date.

4.8. Adequacy and relevance

The company shall ensure that any personal data collected is used only for the purpose for which it was obtained. Personal data obtained for one purpose shall not be used for any unconnected purpose unless the individual concerned has been informed, and there is a lawful basis for the added processing.

4.9. Data retention

The company will not keep personal data for any longer than is necessary. What is needed will depend on each case's circumstances, considering why the personal data was obtained but should be decided according to the company's data retention guidelines. The company's retention Register has the information on how long each asset should be kept. This retention does not affect the subject's right to erasure.

4.10.Data Security

The company shall keep sensitive data secure against loss, misuse, or unauthorised disclosure. Where other organisations process personal data as a service on behalf of the company, there must be contractual clauses to provide the same level of data protection. The information security policy shall be implemented and enforced using supporting policies and procedures, training, and technologies to ensure consistent information protection throughout the company.

4.11. Privacy by design and default

The company shall follow the principle of privacy by design and default. This is an approach to culture and projects that promote privacy and data protection compliance from the start and keep focus daily.

Privacy settings will be set to the most private by default.

4.12.Data protection impact assessments (DPIA)

When relevant, the DPO will undertake Data Privacy Impact Assessments to advise the company on managing compliance risk.

Where personal processing information is likely to result in a risk to the data subjects' rights and freedoms, a data protection impact assessment shall be conducted, and the results shall be implemented and incorporated into the project. Records of all DPIAs shall be kept, and the assessment shall be conducted according to the Data Protection Impact Assessment Procedure.

4.13.Storing Data

All data controlled by the company must be kept securely. For example, when data is stored on printed paper, it should be held securely where unauthorised personnel cannot access it.

Printed data should be shredded when it is no longer needed.

Data stored on a computer should be protected as outlined in the Information Security Policy. In addition, data stored on CDs or memory sticks must follow the guidelines in the Removable Media Policy.

Data should be regularly backed up in line with the company's continuity and disaster recovery plans.

All devices that store sensitive data must be approved and protected by security software and strong firewalls.

4.14.Transferring data internationally

The company follows strict restrictions on transferring data internationally.

No data can be transferred without first following the International Data Transfer Procedure. You can get further support on this from the DPO.

This procedure ensures that data does not get transferred unless there are proper and approved security measures in place to protect the data, such as adequacy regulations made by the UK government, the International Data Transfer Agreement or Addendum issued by the ICO, or binding corporate rules.

4.15.Data Subject rights

The company shall abide by the data subject's rights laid out in both the DPA and GDPR, including as amended by DUAA 2025. The DPO shall manage any request from an individual, and a response issued within a month.

4.15.1. Consent

Where the company uses consent as the legal basis for processing data, there must be a record of the data subject's active consent.

Consent should be gathered in the manner outlined in the Consent Management Procedure.

The data subject has the right to withdraw this consent at any time.

This right does not affect any of the other rights.

Special category personal data requires a condition under Article 9 of the UK GDPR in addition to a lawful basis under Article 6. Where the company is the controller, the condition relied on shall be identified, approved by the DPO and recorded in the data register before the processing begins, together with appropriate safeguards.

Where the company acts solely as a processor, it processes under the controller's documented lawful instructions and does not determine the controller's lawful basis or Article 9 condition. Where a client controller processes special category information for equality monitoring, the applicable condition is ordinarily Article 9(2)(g) of the UK GDPR together with paragraph 8 of Part 2 of Schedule 1 to the Data Protection Act 2018, concerning equality of opportunity or treatment. That condition does not extend to measures or decisions about a particular data subject.

Where explicit consent is the condition relied on, the consent shall be recorded and shall clearly identify the data concerned, why it is being processed and to whom it will be disclosed. Explicit consent is not the default condition and shall not be assumed.

Where the data subject is under the age of 13 years old, the company shall obtain authorisation from the subject's legal guardian.

4.15.2. The right to be informed

Data subjects have the right to be informed about how their data is processed. To enable this right, the company provides the required information using a mixture of inform statements, inform with object statements informed consent requests. Where information is mainly static, it will be made available in our Privacy Notice.

4.15.3. The right of access

Data subjects are entitled, subject to certain exceptions, to request access to information held about them.

These requests shall be passed to the DPO to manage.

A response must be made to the data subject within one month.

SPR25.6 – Springpod Data Protection Policy v1.6 30.07.26 Page 4 of 8The requests must be recorded and monitored, and the process from the Data Subject Access Request Procedure should be followed.

4.15.4. The right to data portability

Upon request, a data subject should have the right to receive a copy of their data in a structured format or send that information to another Data Controller.

These requests should be processed within one month if there is no undue burden and it does not compromise other individuals' privacy.

This must be done for free.

When managing these requests, a response must be made to the data subject within one month.

The requests must be recorded and checked, and the process from the Data Portability Procedure should be followed.

4.15.5. The right to rectification

Data subjects can ask that personal information held on them is corrected if it is not correct.

These requests shall be passed to the DPO to manage.

When managing these requests, a response must be made to the data subject within one month.

The requests must be recorded and checked, and the process from the Subject Rectification Request Procedure should be followed.

4.15.6. The right to erasure

Data subjects may ask that any information held on them be erased or removed. Any third parties who process or use that data must also follow the request.

An erasure request can only be refused if an exemption applies.

These requests shall be passed to the DPO to manage.

When managing these requests, a response must be made to the data subject within one month.

The requests must be recorded and checked, and the process from the Subject Erasure Request Procedure should be followed.

4.15.7. The right to restrict processing

Data subjects can request a restriction of processing on their data when they do not wish for their data to be erased but do not want the data processed.

These requests shall be passed to the DPO to handle.

When managing these requests, a response must be made to the data subject within one month.

The requests must be recorded and checked, and the process from the Restricting Processing Procedure should be followed.

4.15.8. The right to object

Data subjects can object to processing if they suspect that their data is being processed illegally. Following an objection, the data controller must investigate the claim and communicate the results to the data subject.

These requests shall be passed to the DPO to manage.

When managing these requests, a response must be made to the data subject within one month.

The requests must be recorded and checked, and the process from the Objection Request Procedure should be followed.

4.15.9. Rights concerning automated decision making and profiling

Data subjects have the right to be informed if they are subject to automated decision making and the possible consequences this automated decision making could have on them.

To follow this right, the company supplies the required information in its privacy notice and collects and documents the proper consent as said in the Consent Procedure.

The right to complain about data protection matters

Based on the developments brought by the DUAA 2025, data subjects have an explicit right to complain to data controllers about data protection matters, including about how the above requests were handled. These complaints are submitted prior to a complaint to the ICO, which gives the data controller the possibility to investigate and remedy the problem before regulatory intervention. An internal complaint process must be in place.

4.16.Data audit and Register

Regular Data audits to manage and mitigate risks will inform the data register.

This has information on what data is held, where it is stored, how it is used, who is responsible and any further regulations or retention timescales that may be relevant.

4.17.Reporting breaches

All members of staff must report actual or potential data protection compliance failures.

This allows us to:

  • Investigate the failure and take remedial steps if necessary

  • Maintain a register of compliance failures

  • Notify the Supervisory Authority [SA] of any material compliance failures either in their own right or as part of a pattern of failures.

4.18.Consequences of not complying

Where an employee has been found to have violated the company policies or procedures, the following actions may be taken:

  • Written Warning – An official warning that any further infractions will lead to further action.

  • Removal of privileges – The staff member will be forbidden from performing certain actions, accessing certain systems, or using certain devices.

  • Corrective action – The staff member shall take action so that no further infractions occur, for example, training.

  • Termination of employment – The member of staff shall no longer work for the company.

  • Civil action – A claim of legal recompense may be made against the staff member.

  • Legal action – The company will pass details of the infraction to the authorities to press charges.

4.19.Contracted Third Parties

Where a contracted third party has been found to have violated the contractual obligations relating to data protection, the following actions may be taken:

  • Written Warning – An official warning that any further infractions will lead to further action

  • Removal of privileges – The contracted third party will be forbidden from performing certain actions, accessing certain systems, or using certain devices.

  • Corrective action – The contracted third party shall take steps so that no further infractions occur, for example, training.

  • Security Audit – An audit of the contracted third party's systems to ensure that they still meet their obligations.

  • Termination of contract – The contracted third party shall no longer be contracted to work for the company.

  • Civil action – A claim of legal recompense may be made against the contracted third party.

  • Legal action – The company will pass details of the infraction to the authorities to press charges.

4.20. Compliance

Compliance with this Policy will be audited through various methods, including periodic training, video monitoring, business reports, internal and external audits, and feedback to the policy owner.

An employee found to have violated this Policy may be subject to disciplinary action, up to and including termination of employment.

4.21.Exceptions

Any exception to the Policy must be approved by the Data Protection Officer (DPO) in advance either by consultation or by delegated authority following the risk management framework.

4.22. Controller and processor roles

The company is the controller for the personal data needed to create, host, secure, maintain and administer Springpod accounts, and for specifically identified Springpod platform purposes such as authenticating users, maintaining platform functionality, providing account support, protecting the platform and its users, and preventing misuse.

Where a client commissions a programme, that client is the controller for the delivery of its programme and for its equality monitoring. The company acts as that client's processor for that processing.

The company may hold controller and processor roles at the same time for different processing activities. The role that applies is determined by the purpose of the processing, not merely by which system stores the information. Client-controlled data remains processor activity when the company hosts it on the platform.

When acting as a processor, the company shall follow the client's documented instructions and shall apply appropriate security, access control, data minimisation and assistance measures in accordance with the applicable data processing agreement.

No joint controller relationship is created by these arrangements.

Special category personal data requires both an Article 6 lawful basis and an Article 9 condition. Where the company acts as processor, the client as controller determines and documents both.


5. Roles and Responsibilities

5.1. The first line of defence (everyone) is responsible for:

  • Ensuring their day-to-day business activity complies with all relevant regulations.

  • Ensuring their business area is compliant with this Policy.

  • Reporting any actual or perceived breaches.

5.2. The Second line of defence (the management) is responsible for:

  • Oversight of policy implementation.

  • Acting as an independent, effective challenger of the first line.

5.3. The third line of defence (Risk & Compliance Officer) is responsible for:

  • Assuring that the Policy meets all regulatory requirements and that the Policy is being complied with effectively.

  • Reviewing and approving this Policy.

  • Developing and supplying training on this Policy and associated standards, tools, methodologies, and programmes.

  • Supplying advice and guidance to staff implementing the Policy.

5.4. The MD and COO are responsible for:

Approval of this Policy


6. Document Review

This document will be reviewed at least annually or as needed if significant changes occur in the business structure, responsibilities, or regulatory framework.


7. Related Documents

  • Privacy Notice

  • Information Security Policy

  • Third-Party Management Policy

  • Business Continuity Policy

  • Removable media policy

  • International Data Transfer procedure

  • Risk Management Framework

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.