Privacy Policy
Please Read Our Privacy Policy
This notice applies across all websites that we own and operate and all services we provide, including our online learning zone and any other apps or services we may offer (for example, events or training). For the purpose of this notice, we’ll just call them our ‘services’.
When we say ‘personal data’ we mean identifiable information about you, like your name, email, address, telephone number, bank account details, payment information, support queries, portfolio, formative and assignment submissions, community comments and so on. If you can’t be identified (for example, when personal data has been aggregated and anonymised) then this notice doesn’t apply. Check out our terms of use for more information on how we treat your other data.
You can read the whole notice below.
Last updated: July 2026. Next review date: July 2027
This Privacy Policy explains how AheadHR Selection and Assessment Limited (‘AheadHR’, ‘we’, ‘our’ or ‘us’) collects, uses, shares, stores and protects personal data. It has been prepared to reflect the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), the Data (Use and Access) Act 2025 and current Information Commissioner’s Office (ICO) guidance.
1. About AheadHR
AheadHR Selection and Assessment Limited (Company No. 07534454) is the data controller for the personal data described in this policy unless stated otherwise. Insert your registered office address before publication. Privacy queries should be sent to info@aheadhr.co.uk.
2. Scope
This policy applies to learners, prospective learners, employers, sponsors, website visitors, coaches, contractors, suppliers, applicants and anyone else whose personal information we process.
3. Data protection principles
We process personal data lawfully, fairly and transparently; collect only what is necessary; keep information accurate; retain it only as long as required; protect it using appropriate security measures; and demonstrate accountability for our decisions.
4. Categories of personal data
Identity data, contact data, employment details, education history, CVs, payment information, learner records, assignment submissions, attendance, assessment feedback, accessibility and reasonable adjustment information, communications, technical information, IP addresses, cookies, marketing preferences and records needed to meet legal or regulatory obligations.
5. Sources of personal data
Information is collected directly from individuals, sponsoring employers, the CIPD where appropriate, publicly available sources, service providers acting on our behalf and through normal use of our website and learning platform.
6. Lawful bases
Processing is carried out under one or more lawful bases including performance of a contract, compliance with legal obligations, legitimate interests, consent and, where applicable, substantial public interest or employment law obligations for special category information.
7. How we use personal data
To assess suitability for study; enrol learners; register with awarding bodies; deliver training; assess work; provide coaching; issue certificates; administer payments; provide support; improve our services; manage complaints; recruit staff and associates; comply with legal obligations; protect systems; prevent fraud; and communicate with learners and customers.
8. AI-assisted technologies
We may use AI-assisted tools to improve administrative efficiency, draft communications, support customer service, analyse trends, assist content creation and improve learner experience. AI tools are subject to human oversight. We do not make decisions producing legal or similarly significant effects solely through automated processing.
9. Marketing
Marketing is carried out only where permitted under PECR and the UK GDPR. Individuals can unsubscribe or withdraw consent at any time.
10. Cookies
We use essential cookies to operate our services. Non-essential analytics or marketing cookies are used only with consent where required. Our Cookie Policy explains the cookies used and how preferences may be changed.
11. Sharing personal data
We share information only where necessary with awarding bodies including the CIPD, cloud hosting providers, learning management system providers, Microsoft 365, payment processors, video conferencing providers, CRM providers, accountants, auditors, insurers, legal advisers, regulators, public authorities and trusted suppliers acting under written contracts.
12. International transfers
If personal data is transferred outside the UK, we use UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses or another lawful safeguard.
13. Security
We apply technical and organisational measures including encryption where appropriate, role-based access controls, password policies, multi-factor authentication where available, secure hosting, endpoint protection, monitoring, regular backups, supplier due diligence, confidentiality agreements, staff training and secure disposal of information.
14. Retention schedule
Personal data is retained only while required. Learner and assessment records are retained in accordance with contractual, legal and awarding body requirements. Finance records are retained for statutory tax and accounting periods. Recruitment information is retained for a limited period unless longer retention is required. Marketing data is retained until consent is withdrawn or no longer required. Information is securely deleted or anonymised when retention periods expire.
15. Special category data
Where health information, disability information, reasonable adjustments or equality information is processed, we do so only where necessary and permitted by law, applying additional safeguards.
16. Children’s information
Our services are primarily intended for adults. If we knowingly collect information relating to younger individuals, appropriate consent and safeguarding requirements will be followed.
17. Your rights
You have rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and rights relating to automated decision making where applicable. Requests should be sent to info@aheadhr.co.uk and will normally be answered within one month.
18. Data breaches
We maintain documented procedures for reporting, investigating and managing personal data breaches. Where required, breaches are reported to the ICO and affected individuals.
19. Governance
AheadHR maintains internal policies covering information security, acceptable use, data retention, incident management, AI use, staff confidentiality and supplier management. Staff receive appropriate training and access to personal data is limited according to role.
20. Complaints
If you are dissatisfied with how we process your information please contact info@aheadhr.co.uk. If you remain unhappy you may complain to the Information Commissioner’s Office.
21. Changes
We review this policy regularly and publish updated versions when legal, operational or regulatory changes require them.
Data Protection Contact Details
You may contact our Data Protection Officer via info@aheadhr.co.uk
Appendix A – Processing Activities
|
Activity |
Personal data |
Purpose |
Lawful basis |
|
Enquiries |
Contact details |
Respond to enquiries |
Legitimate interests |
|
Course enrolment |
Identity/contact |
Deliver services |
Contract |
|
Assessment |
Assignments/results |
Qualification |
Contract |
|
CIPD registration |
Identity/results |
Awarding Body |
Contract/Legal obligation |
|
Payments |
Billing |
Finance |
Legal obligation |
|
Marketing |
Email/preferences |
Updates |
Consent/Legitimate interests |
|
Recruitment |
CV/application |
Recruitment |
Legitimate interests |
Appendix B – Processor Register
We maintain an internal register naming processors used by AheadHR (for example Microsoft 365, Absorb LMS, Moodle, Stripe, Zoom, Hubspot, GoDaddy, Google, Xero) together with the processing purpose, location, transfer safeguard and contract review date.
Appendix C – Annual Governance Checklist
- Review this policy annually.
- Review processor contracts.
- Review retention schedule.
- Review security controls and MFA.
- Review AI usage.
- Test data breach procedure.
- Review staff training records.
- Review cookie compliance.
- Review international transfers.
- Review Records of Processing Activities.
How to contact us
We’re always keen to hear from you. If you’re curious about what personal data we hold about you or you have a question or feedback for us on this notice, our websites or services, please get in touch.
We prefer to communicate with you by email – this ensures that you’re put in contact with the right person, in the right location, and in accordance with any regulatory time frames.
Our email is info@aheadhr.co.uk.
Get in touch to request an information pack and arrange your FREE no obligation discussion. We look forward to helping you to choose the best programme for your needs.
