Hold Fast Online – Privacy Policy

Effective Date: September 2026 Version: 1.0

Hold Fast Online (“we”, “our”, “us”), part of Hold Fast Education Ltd, respects your privacy and is committed to protecting your personal data in accordance with UK data protection law.

This Privacy Policy explains how we collect, use, store, and share personal information when you access our online educational services, including live lessons, recorded content, feedback systems, assessments, and communication platforms.

1. Data We Collect

We collect personal data when learners, parents/carers, schools, or commissioning organisations engage with our services.

This may include:

Learner and contact information

  • Name

  • Date of birth (where applicable)

  • Email address

  • Parent/carer contact details

  • School or commissioning organisation details

Educational data

  • Attendance and engagement records

  • Assessment outcomes and progress data

  • Behavioural or safeguarding-related notes (where relevant and necessary)

  • Work submitted through online platforms

Technical and usage data

  • IP address

  • Device information

  • Login data and platform activity

  • Session participation (live and recorded sessions)

Communication data

  • Emails and messages between staff, learners, parents/carers, schools, or commissioners

  • Safeguarding communications where concerns are raised

Financial data (where applicable)

  • Payment and invoicing information (processed securely via third-party providers)

2. How We Use Your Data

We use personal data to:

  • Deliver online education and learning support

  • Provide access to live lessons, resources, and recorded materials

  • Monitor engagement, progress, and attendance

  • Support safeguarding and child protection responsibilities

  • Communicate with learners, parents/carers, schools, and commissioning bodies

  • Process payments and manage enrolments (where applicable)

  • Improve our services and educational delivery

  • Comply with legal, safeguarding, and regulatory obligations

3. Lawful Basis for Processing

Under UK GDPR, we process personal data under the following lawful bases:

  • Contract – to deliver educational services

  • Legal obligation – safeguarding, statutory reporting, and compliance

  • Public task / educational interest – where applicable through commissioning arrangements

  • Legitimate interests – improving services and maintaining secure systems

  • Consent – where specifically required (e.g. marketing communications)

4. Sharing Your Data

We do not sell personal data.

We may share data where necessary with trusted third parties, including:

  • Schools and Alternative Provision settings

  • Local Authorities and commissioning organisations

  • Children’s Social Care and safeguarding partners

  • Online learning platforms and service providers (e.g. video conferencing systems, LMS platforms)

  • Payment processors and administrative service providers

  • Law enforcement or regulatory bodies where legally required

All third-party providers are required to handle data securely and in compliance with UK GDPR.

5. Safeguarding and Child Protection

Where safeguarding concerns arise, we may process and share personal data without consent where it is necessary to protect a child from harm.

This may include sharing information with:

  • Designated Safeguarding Leads (DSL/DDSL)

  • Schools or commissioning organisations

  • Local Authority safeguarding teams

  • Police or emergency services where required

All safeguarding data is handled on a strict need-to-know basis.

6. Online Learning and Session Recording

Hold Fast Online delivers services through live online lessons and digital platforms.

We may:

  • Record live sessions for safeguarding, quality assurance, and training purposes

  • Monitor engagement and participation during sessions

  • Use secure platforms with restricted access controls

Where sessions are recorded, they are stored securely and only accessed by authorised staff.

7. Data Security and Storage

We take appropriate technical and organisational measures to protect personal data, including:

  • Password-protected systems

  • Secure online platforms

  • Restricted staff access based on role

  • Encrypted or secure storage systems where applicable

Data is retained only for as long as necessary for educational, safeguarding, or legal purposes.

8. Data Retention

We retain personal data in line with:

  • statutory safeguarding requirements

  • educational record retention expectations

  • legal and contractual obligations

When data is no longer required, it is securely deleted or anonymised.

9. Your Rights (UK GDPR)

Under data protection law, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request deletion of data (where legally permissible)

  • Restrict or object to processing

  • Withdraw consent (where consent applies)

  • Request data portability

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

ICO website: https://ico.org.uk

10. Children’s Data

Where learners are under 18, data is processed with appropriate safeguarding safeguards in place.

We work in line with statutory safeguarding guidance, and all processing prioritises the welfare and safety of children and young people.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • legislation

  • statutory guidance

  • operational practice

The latest version will always be available on our website.

12. Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please contact:

Email: admin@holdfasteducation.co.uk