Confidentiality Statement 

This policy contains information confidential and proprietary to The Right Track Consultancy Ltd. This document contains information that is confidential or otherwise protected from disclosure and shall not be disclosed without prior approval. 

Document version control 

The document owner is Helen Russell.

Date Current Version  Comment  Next review date  Author Status
19/02/2024 1 Policy created  KA HR/KA Approved

Document history control 

Date Version  Comment  Author Approver Status 
19/02/2024 1 Policy created  KA HR/KA Approved

Contacts 

Company Contact 
The Right Track Consultancy Ltd info@therighttrackconsutling.com

Definitions

The definition of the Data Controller, Data Processor, Data, Personal Data, Processing is in accordance with the Data Protection Act 2018 and the EU General Data Protection Regulation up to 31st December 2020, thereafter the UK GDPR. 

Client, You or Your” means the business or entity, an authorised person on behalf of the business ordering the Services from Us.

“Data Protection Act 2018” means the data protection laws in the UK, including amendments The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (effective on exit day) (“DPPEC”). 

“EU GDPR” means The General Data Protection Regulation (EU) 2016/679 ( GDPR) is a regulation in EU law on data protection and privacy for all individual citizens of the European Union (EU) and the European Economic Area (EEA). Where a UK business is providing service to an EEA Customer a UK business will need to comply with the UK GDPR and where applicable EU GDPR.  

“UK GDPR” means the Regulation (EU) 2016/679  as per the definition in the updated Data Protection Act 2018. Thereafter, from the 31st December 2020, data protection to be governed by the UK GDPR and Data protection Act 2018. Where a UK  business is providing service to an EEA Customer a UK business will need to comply with UK GDPR and EU GDPR.  

“ICO” means the information commissioner’s office. 

“Services” including but limited to any of the following:- 

a) Business apprentice scheme consultancy 

b) Education sector apprentice scheme consultancy 

c) Early careers consultancy 

d) Apprentice levy consultancy 

e) Stakeholder engagement consultancy 

f)  Recommendations 

g) Training 

  1. Introduction

This privacy policy governs the use of The Right Track Consultancy LTD, (“Our,We,Us”) website (http://www.therighttrackconsutling.com), and sets out the basis in the way We collect or provided by You any Personal Data, the way in which We process Your  (“You, Your”) Personal Data. By using Our website or any associated mobile application (Apps) You agree and accept the terms of this privacy policy in conjunction with the terms and conditions.  If You do not agree with this then do not use Our Website or any associated mobile application(s).

  1. The information We may hold about You
    1. What Personal Data do we collect?

For most of the business apprentice scheme consultancy and early careers consultancy support Services required We may collect Personal Data as per the table in 2.2 below.  

  1. Why do we collect this information?

We use the Personal Data for purposes listed below for Our Clients related to the Services:-

Subject  Role Purpose and type of activities Lawful basis for processing Special Category purpose  (DPA 2018) Personal Data 
Business apprentice scheme (stakeholder/ recommendation/ training) We collect or determines, Data Controller. To provide apprentice support .    Performance of a contract Not applicable Surname, first name, address, postcode, phone number, email, IP address bank details, payee reference. 
Apprentice levy  We process on behalf of provider . To provide  levy account support  Performance of a contract Not applicable In addition to any of the business details above plus government gateway login or user name, payee reference, company ID
Early careers scheme education (stakeholder/ recommendation/ training) We collect or determines, Data Controller or process on behalf of provider. To provide early carers support  Performance of a contract Under 18 Surname, first name, date of birth, ECHP plan for a student Subset of the above.
Deal with regulatory or legal queries Data Controller To contact legal or regulatory authority under a legal obligation. Legal obligation Not applicable Subset of the above.
Website responses Data Controller To respond to enquiries with Our website or contact on social media.  Legitimate interest/ Performance of a contract 

Not applicable  Subset of the above.
Marketing (business)and advertising including online or mail. Data Controller To provide blogs, newsletters, email campaign, social media.  Consent (unless opted out) Not applicable Subset of the above.
Reviews  Data Controller For Customer to publish reviews. Direct marketing/ Consent Not applicable Subset of the above.
  1. How is this information collected?

We may collect Your details from contact us form, direct emails enquiries or as part of Our Services.  Any Website tracking information related to device specific, collecting information about e.g. web analytics etc if applicable.  

  1. Use of the information collected?

The Personal Data is used to contact You via email or other means about Our service provision as per 2.2 above and to identify You when You engage with Us. Our partners who are instructed by Us on Our behalf in delivering any part of service to You in 2.2 above. For marketing Our services to You except where You have withdrawn or opted out to receive any marketing from Us.  

Any third party which We use for Data Processing will only process for example the email, until such time either the Personal Data is deleted on exit of a contract or a right which is exercised e.g. right to erase or withdraw of consent. 

  1. Cookies, web analytics traffic 

A Website may have number of small scripts running in the background to capture web traffic data or retain session information about You. Our Website may use the listed cookies below:- 

Type Company  Use 
Google Analytics  Google Web analytics online service which tracks and reports website traffic. 
Google Maps  Google  is a web mapping service developed by Google.
Social media pixels (Linkedin) Linkedin Online social media in relation to lead generation with inMail, messaging, posts, marketing campaigns. 
Google AdWords remarketing  Google  is a form of online advertising that enables sites to show targeted ads to users who have already visited their website.
Company Cookie Name Expiration Time Cookies use
Linkedin __utma,utmv 2 years from the creation time Uses a unique ID to make sure that any advertising you see from us on LinkedIn is relevant and personalised.
Google  Google Map Api Session To request user IP address marketing and tracking
UserSetting Session User’s internet browser colour and location preferences

You may be able to disable some cookies on Our Website under their browser settings and it may affect the way a Website operates. You can find further information about cookies at www.allaboutcookies.org

  1. Third parties 

We work with a few trusted third parties delivering any of the services mentioned above in section 2, who sign up to or adopt similar level of privacy as The Right Track Consultancy Ltd privacy policy concerning how they handle Personal Data.  You may obtain a list of third parties who process Your specific data by request to info@therighttrackconsutling.com

Type Company  Use for Us
Email marketing  Mail Chimp Online email marketing tool for marketing. 
Reviews – Google My Business  Google my business  Online reviews related to Services.  
Google maps  (Google API)  Google maps  Providing location information by way of a map. Any zoom in and zoom out uses the API to resize the map.
Web hosting  DP Marketing communications  Online hosting of website and domain Services. 
Marketing  DP Marketing communications Creation, publishing online, print marketing material or marketing campaigns or referrals. 
  1. Marketing  

We may contact You from time to time and send You details of services that We provide which may be of interest to You. We may share Your information with other third parties to contact You about services which may be of interest to You with in house marketing. Any external marketing lists used shall be subject to approved consents where applicable. If You do not wish to receive such requests in the future, please contact Us to withdraw.  

  1. Your rights

As a Client, You have several rights in relation to Personal Data some are listed below. Where applicable We will respond to the above requests within thirty (30) days or notify as to who should be responding.

  1. Subject access requests

If You wish to submit a subject access request, on the information We may hold about You then please  email info@therighttrackconsutling.com Where We are acting as the Data Controller of the Personal Data We will respond. However, where We are acting as the Data Processor or a third party We will pass Your request onto the relevant Data Controller to respond directly. There is no charge of this except where such request is excessive it may be chargeable.

  1. Inaccurate Personal Data

Where We collect or use the Personal Data and which You believe is incorrect the please contact Us with a request to amend the Personal Data. 

  1. Request to withdraw, erase and portability of Personal Data

If You wish to submit a request in relation to withdrawing consent, erase or port Your Personal Data We may hold on You then please contact Us.

The ICO guidelines provide that some rights may not apply right to object (excluded under contact, legitimate interest or public tasks), erase (excluded under legal obligation or public tasks), portability (excluded under legal obligation, vital interest, public tasks, legitimate interests).  

  1. Retention of Personal Data 

We will retain records no longer than they are required in accordance with Our retention policy or as up to 36 months if You withdraw/erase earlier then the Personal Data will be deleted exceptions for example legal etc reasons held for longer. On exit of a service for example Website hosting with database, We will delete the Personal Data collected.  

  1. Personal Data outside the EEA 

If any of website design or hosting services are provided outside of the EEA and Personal Data may be transferred by Us in order to provide You service to You in 2.2 above. Where We transfer any Personal Data outside the European Economic Area (EEA) this will be subject to either model agreements or binding corporate rules to ensure that higher level of data privacy are applied. 

  1. Links to other websites 

Our Website may contain other website links or content for interest. On entering the other website, We will have no control once You exit Our Website.  We exclude all responsibility and liability for any Personal Data which You may submit. If You are not sure about entering Personal Data on these other websites, please review their privacy policy. 

  1. Disclosure of information 

We reserve the right to disclose collected Personal Data or any other supporting information in response of a court order, legal action, where consent is given, acquisition, regulator body where such disclosure is required law or regulation.  

  1. Contacting Us 

If You have any questions in relation to this privacy policy please contact the regarding data privacy at info@therighttrackconsutling.com