Skip to content

Legal

Privacy Policy

How we collect, use and protect personal information.

Version 4.0 · Effective 1 September 2026 · Next review August 2027

Download this policy as a PDF from our policies page

Document control

Document title
Privacy Policy
Organisation
Fylde AP & Education Services Ltd (Company No. 15495677)
Registered office
10a Tithebarn Street, Poulton-le-Fylde, FY6 7BX
ICO registration
ZB652173
Data Protection Lead
Rachel Swarbrick — rachel@fyldeap.co.uk
Version
4.0
Effective date
1 September 2026
Last updated
30 August 2026
Next review
August 2027
Supersedes
Privacy Policy v3.1 (interim, 29 August 2026)
Change log
v4.0 is issued on completion of the systems migration. Sections 1.1, 2.4, 6, 7, 9, 10, 11 and 17 have been updated. Section numbering is unchanged from v3.1, except that section 10 is now titled “Where your information is held”.
Related documents
Cookie Policy; Pupil Privacy Notice; Safeguarding and Child Protection Policy; Accidents and Medical Policy; Information Handling Schedule

1. Introduction

Your privacy is important to us. It is our policy to respect your privacy and to comply with any applicable law and regulation regarding any personal information we may collect about you. Fylde AP & Education Services Ltd (formerly Rachel S Tutoring Ltd) is a company registered in England and Wales, company number 15495677, with its registered office at 10a Tithebarn Street, Poulton-le-Fylde, FY6 7BX. We are registered with the Information Commissioner’s Office, registration number ZB652173. Rachel Swarbrick is our Data Protection Lead and can be contacted at rachel@fyldeap.co.uk. We provide tuition and alternative provision to children and young people, and we also act as an employment business introducing self-employed tutors to clients. We are the data controller for the personal information we collect and hold. Where we introduce a self-employed tutor to you, that tutor is a separate data controller for the information they hold about your child, and is responsible for their own registration with the Information Commissioner’s Office and their own privacy policy. Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address and date of birth), your devices, payment details, and information about how you use a website or online service. Our website does not collect personal information directly. Enquiries reach us by email or telephone, and referral information is provided to us outside the website — by parents and carers, or by schools and local authorities commissioning provision. We also use secure online forms to collect registration and medical information; these are described in section 2.4 and are opened from a link we send you rather than completed on our website. This policy describes the information we hold as an education provider and employment business, however it reaches us. The only information collected through the website itself is anonymous analytics data, as described in our Cookie Policy.

1.1 Our systems

Our systems are consolidated onto Microsoft 365, so that our email, file storage and collaboration all sit on a single platform with security and access controls suited to holding information about children. Files are held in SharePoint, video sessions and meetings are delivered through Microsoft Teams, and our forms are Microsoft Forms on our own tenant. Our client, tuition, pupil and safeguarding records are held in TutorCruncher, which holds basic pupil information, scheduling and safeguarding records. Our IT is managed for us by Simultech IT, a Microsoft partner, who administer our Microsoft 365 tenant and SharePoint, manage our devices and endpoint security, monitor our systems, and provide our backup. They act as our data processor and are described in sections 9 and 11.

2. Information We Collect

Information we collect falls into one of two categories: “voluntarily provided” information and “automatically collected” information. “Voluntarily provided” information refers to any information you knowingly and actively provide us — for example when you contact us with an enquiry, complete one of our forms, or share information about a pupil’s needs so that we can provide suitable support. It also includes information provided to us by a school or local authority commissioning provision for a pupil, and information provided by tutors and staff during recruitment. “Automatically collected” information refers to any information automatically sent by your devices in the course of accessing our website. Our website does not collect personal information directly, and automatically collected information is limited to the technical and analytics data described below and in our Cookie Policy. Because we work with children and young people, some of the information we hold is about a pupil rather than about the person providing it. Where a parent, carer, school or local authority gives us information about a child, we hold and use that information in the same way as any other personal information described in this policy, and the child has the same rights over it.

2.1 Log data

When you visit our website, our servers and our website provider may automatically log standard data provided by your web browser. This may include your device’s Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit. We have enabled IP anonymisation in our analytics, and we do not use this information to identify individual visitors. If you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This may include technical details about your device and what you were trying to do when the error happened. While this information may not be personally identifying by itself, it may be possible to combine it with other data to identify individual persons. We do not attempt to do so. We use this information only to keep the website working properly and secure, and to understand in general terms how the site is used.

2.2 Device data

When you visit our website, we may automatically collect data about your device, such as:

  • Device type
  • Operating system and browser
  • Approximate location (city or region), derived from your IP address

Our analytics show approximate location only — we do not collect precise or GPS location data, and we do not track your device across other websites. Analytics cookies are only set if you agree to them. If you decline them through our cookie banner, this data is not collected. See our Cookie Policy for more detail.

2.3 Personal information

We may ask for personal information — for example, when you contact us with an enquiry, register for provision, or are referred to us by a school or local authority. This may include one or more of the following. About parents, carers and other adults:

  • Name
  • Email address
  • Phone or mobile number
  • Home or mailing address
  • Relationship to the pupil

About pupils:

  • Name and date of birth
  • Home address
  • School, year group and attendance history
  • Special educational needs, EHCP status and any support plans
  • Learning needs, prior attainment, reports and progress records
  • Medical, dietary or accessibility information relevant to providing sessions safely
  • Emergency contact details
  • Safeguarding information, where relevant

About tutors and staff:

  • Name, address and contact details
  • Proof of identity and right to work in the UK
  • Qualifications, references and employment history
  • DBS certificate details
  • Self-employment details, such as a UTR or company registration number, and insurance details

We only ask for information we reasonably need in order to provide safe and suitable provision, to meet our safeguarding and legal duties, and to run our business.

2.4 Information collected through our forms

Much of the information described above reaches us through our forms, and through referral information provided to us by schools and local authorities.

  • Parent/Carer Form and Pupil Information — completed by a parent or carer when a pupil starts with

us.

  • Medical Information— completed by a parent or carer where a medical condition, allergy or

medication is declared, either at registration or at any later point in the year.

  • Consent Forms – these are for trips (such as park or café), food tasting, Medication Administration or

other necessary consent we may need to obtain These forms are Microsoft Forms, provided on our own Microsoft 365 tenant. They include a signature field, and allow you to provide supporting documents such as an EHCP, a care plan or a photograph of a medication label. Responses are held in the United Kingdom, and signatures and supporting documents are held on the same basis as the rest of the form and are covered by the security and retention arrangements in sections 6 and 7. Accidents, injuries and medical incidents are recorded separately, on a paper Accident Report Form and in our Accident Book, as set out in our Accidents and Medical Policy. A copy of the completed form is given to the parent or carer and the master copy is held securely at our registered office. Paper versions of the registration and medical forms are available for anyone who would prefer to complete a document, and for use where there is no internet connection. Information given on paper is treated in exactly the same way as information given online: it is transferred into the pupil’s record as soon as practicable, signed originals we need to keep are held securely at our registered office with access restricted to those who need it, and anything we do not need to keep is destroyed by secure shredding once the information has been recorded. Paper forms are not left in vehicles, taken home, or stored at a tutor’s own address. Where information reaches us from a school or local authority commissioning provision, it comes as part of the referral rather than through our forms, and is held in the same way.

3. Sensitive Information

“Sensitive information” or “special category data” is a subset of personal information given a higher level of protection under the UK GDPR. Examples include information relating to racial or ethnic origin, political opinions, religion, trade union membership, philosophical beliefs, sexual orientation, sexual practices or sex life, health information, or biometric information. Information about criminal offences and convictions is given similar protection. The types of sensitive information we may hold include:

  • Health information, including medical conditions, allergies and medication relevant to providing

sessions safely, most of which reaches us through the Medical Information and Consent form

  • Special educational needs, disability and EHCP information
  • Safeguarding and child protection information, including information about welfare concerns and,

where relevant, a pupil’s status as a child looked after or subject to a child protection plan

  • Racial or ethnic origin, where this is recorded on a referral from a school or local authority
  • Criminal records information, in the form of DBS checks carried out on tutors and staff as part of

recruitment. We do not collect criminal records information about clients or pupils. We do not rely on consent to process most of this information. Consent is not an appropriate basis where we hold information in order to meet a legal duty, and asking for consent we could not act on would be misleading. Instead we process special category and criminal offence data under:

  • Article 9(2)(b) UK GDPR and Schedule 1 Part 1 of the Data Protection Act 2018 — obligations in the

field of employment and social protection, for tutor and staff vetting

  • Article 9(2)(g) UK GDPR and Schedule 1 Part 2 of the Data Protection Act 2018 — safeguarding of

children and individuals at risk, and other reasons of substantial public interest

  • Article 9(2)(c) UK GDPR — protecting someone’s vital interests, in an emergency

Where we do rely on your consent — for example, to record optional information that is not necessary for us to provide provision — we will ask for it clearly and you can withdraw it at any time. We hold an appropriate policy document covering our processing of special category and criminal offence data, as required by the Data Protection Act 2018, and it is available on request.

4. How We Use Personal Information

We may collect, hold, use and disclose information for the following purposes:

  • To provide tuition and alternative provision, and to introduce tutors to clients
  • To communicate with parents, carers, schools and local authorities about provision
  • To meet our safeguarding and child protection responsibilities
  • To recruit and vet tutors and staff
  • For internal record keeping and administration, including invoicing
  • To understand in general terms how our website is used, and to improve it
  • To comply with our legal obligations and resolve any disputes
  • For security and fraud prevention

We only collect and use personal information where we have a lawful basis for doing so, and we collect only what is reasonably necessary.

5. Lawful Bases for Processing

Our lawful bases depend on the services concerned and how they are used. We never direct marketing at any person under 18 years of age.

5.1 Consent

Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time; however this will not affect any use of your information that has already taken place. We rely on consent in relatively few circumstances.

5.2 Performance of a contract

Where you have entered into a contract with us, or in order to take preparatory steps prior to entering into a contract. For example, if you contact us with an enquiry, we may require your name and contact details in order to respond.

5.3 Legal obligation

In some cases we have a legal obligation to use or keep your personal information. This includes our safeguarding and child protection duties, our obligations as an employment business, and financial record- keeping requirements. For example, we are required to keep financial records for a period of six years.

5.4 Legitimate interests

Where we assess it is necessary for our legitimate interests, such as providing, operating, improving and communicating our services, understanding our audience, operating efficiently, and protecting our legal rights and interests.

5.5 Vital interests

In an emergency, where processing is necessary to protect someone’s life or physical safety.

6. Security of Your Personal Information

When we collect and process personal information, and while we retain it, we protect it using appropriate technical and organisational measures to prevent loss, theft, unauthorised access, disclosure, copying, use or modification. These include encrypted cloud storage on company-controlled accounts, multi-factor authentication on every account, and access restricted on a need-to-know basis. Records are not stored on personal devices, local drives or personal email accounts.

6.1 Pupil and safeguarding records

Our client information and scheduling, including safeguarding and child protection records, are held in TutorCruncher. Access to the platform is role-based and every user has their own account. Tutors have individual accounts and can see only the pupils assigned to them. A tutor can raise a safeguarding concern through the platform, and is expected to. Access to safeguarding records is restricted to the Designated Safeguarding Lead and the Deputy Designated Safeguarding Lead. Accident reports are the deliberate exception to records being separated by pupil, and are kept together in a single chronological record, because reviewing them side by side is what allows patterns to be spotted and any reporting duty under RIDDOR to be met.

6.2 Sharing documents with tutors

  • Where a tutor needs a document in order to deliver a session safely and effectively — for example a

support plan, a risk assessment or a set of targets — we share it from our own SharePoint file storage using a link issued to that named individual.

  • The link is specific to that tutor. It is not published, not made openly available, and not forwarded.
  • Multi-factor authentication is required before the document will open, so access depends on the tutor

verifying their own identity, not on possession of the link.

  • Every pupil document carries a sensitivity label — for example Confidential or Highly Confidential. The

label stays attached to the file and controls what can be done with it, including if it is copied or moved out of SharePoint.

  • Links are withdrawn when the assignment ends.
  • We do not send pupil documents as email attachments, and never to a personal email account.

Tutors work with these documents inside our Microsoft 365 environment. Documents are not downloaded, saved or copied to personal devices or personal storage, and personal devices are used only to access our environment, never to hold pupil information. The conditions that apply are set out in the Information Handling Schedule, which every tutor and member of staff signs at induction — see section 11.1. A Bring Your Own Device policy is being prepared with our IT provider and will sit alongside that agreement.

6.3 Correspondence

Pupils are referred to by initials in routine email and messaging with tutors, rather than by name. Pupil documents are not sent by email at all; they are made available on SharePoint by the route described above. Safeguarding concerns are not raised or discussed by email or through shared documents. They are reported through TutorCruncher and to the Designated Safeguarding Lead, by the route set out in our Safeguarding and Child Protection Policy.

6.4 IT management and support

Our Microsoft 365 tenant, our devices and our security are managed for us by Simultech IT, a Microsoft partner. Their service includes administration of Microsoft 365 and SharePoint, mobile device management, endpoint protection, real-time device and security monitoring, cloud backup of our Microsoft 365 data, user onboarding and offboarding, and security awareness training for our people. Simultech IT act only on our instructions and under a written contract, and are named as our data processor in section 11. Their access is limited to what is needed to administer and support our systems.

7. How Long We Keep Your Personal Information

We keep personal information only for as long as we need it. How long that is depends on what the information is and why we hold it. Some records must be kept for set periods to meet safeguarding, employment and financial obligations. Our retention periods are:

  • Enquiries — up to 12 months from your last contact with us, unless you go on to become a client
  • Pupil records (attendance, progress, reports, correspondence) — for the duration of the provision and

for a reasonable period afterwards, then securely destroyed or anonymised

  • Child protection and safeguarding records — until the individual’s 25th birthday, after which they are

reviewed and securely destroyed unless there is a continuing reason to retain them

  • Records relating to allegations of child sexual abuse — retained indefinitely, in line with Home Office

instructions arising from the Independent Inquiry into Child Sexual Abuse

  • Accident and incident records involving children — until the child reaches 21, or 25 where the record

is safeguarding-related

  • Allegations against adults working with children — substantiated allegations are kept on the

individual’s file until normal retirement age or for 10 years, whichever is longer. Allegations found to be malicious or unsubstantiated are removed.

  • Tutor and staff records — for six years after the engagement ends. We record only the DBS certificate

number, issue date and outcome, not a copy of the certificate itself.

  • Financial records — six years, to comply with HMRC requirements
  • Form responses — moved into the pupil’s record and deleted from Microsoft Forms once saved, so

that the form platform does not become a second copy of the record

  • Material supplied to tutors — returned or securely deleted at the end of the assignment, under the

Information Handling Schedule described in section 11.1 The retention periods above are ours and apply to the records themselves, wherever they are held. Where we hold records on a third-party platform and stop using that platform, we export any record we are required to keep into our own storage before the account is closed, so that the retention periods above continue to be met. Where a pupil is or has been a child looked after, the statutory case record is held by the responsible local authority until the 75th anniversary of the pupil’s date of birth. We hold our own provision and safeguarding records under the periods set out above, and share information with the local authority and Virtual School as required. Where a local authority or school commissioning provision sets its own retention requirements as a condition of contract, we follow those requirements where they are longer than our own. When information is no longer required, we delete it or make it anonymous by removing all details that identify an individual. We may retain information for longer where necessary to comply with a legal, accounting or reporting obligation, or to establish, exercise or defend legal claims.

8. Children’s Privacy

Our website is aimed at parents, carers, schools and local authorities rather than at children, and children are not expected to use it directly. We do not use cookies to profile or track children, and we do not send marketing to anyone under 18. However, because we provide tuition and alternative provision, we do hold personal information about children and young people — including children under 13. That information is provided to us by parents and carers, or by schools and local authorities commissioning provision, and is described in the sections above. It is held and used only for the purposes set out in this policy. Children have the same rights over their information as adults. Depending on their age and understanding, a young person may exercise those rights themselves rather than through a parent or carer. As a general guide, we will normally consider a young person of 13 or over capable of making their own request, though we assess this individually, and we will always act in the child’s best interests.

9. Disclosure of Personal Information to Third Parties

We may disclose personal information to:

  • Self-employed tutors introduced to you, to the extent needed to deliver sessions safely and effectively
  • Our employees and contractors, on a need-to-know basis
  • Schools and local authorities commissioning provision, including reporting on attendance, progress

and safeguarding for funded placements

  • Statutory safeguarding partners — including children’s social care, the Local Authority Designated

Officer (LADO), health services and the police — where there is a safeguarding or child protection concern. We may also make referrals to the Disclosure and Barring Service or Teaching Regulation Agency where a legal duty to do so arises.

  • Third-party service providers, including IT and data storage providers, hosting providers and analytics

providers

  • Our professional advisers, including our accountant and insurers
  • Courts, tribunals, regulatory authorities and law enforcement, as required by law, or in order to

establish, exercise or defend our legal rights

  • An entity that buys, or to which we transfer, all or substantially all of our assets and business

Where we share information for safeguarding purposes, we do so proportionately and securely, and only what is necessary. We do not require your consent to share information where there is a safeguarding concern, and in some circumstances telling you first could place a child at greater risk. Wherever it is safe and appropriate to do so, we will explain what we are sharing and why. Where a school or local authority has commissioned a placement, sharing attendance, progress and safeguarding information with them is necessary in order to deliver the placement at all. We do that under the lawful bases set out in section 5 rather than by asking you to agree to it. We tell you that it happens and you can raise an objection with us, but it is not something we are able to offer as optional. We do not sell personal information, and we do not share it with advertisers or data brokers. The third parties we currently use are:

  • Microsoft Corporation — email, file storage (SharePoint), collaboration and video sessions (Teams),

and our forms (Microsoft Forms). Our tenant is configured for United Kingdom data residency.

  • TutorCruncher Ltd — client, tuition, pupil and safeguarding records. TutorCruncher is a UK company

and acts as our data processor.

  • Simultech IT — our managed IT provider and a Microsoft partner, who administer and support our

Microsoft 365 tenant, devices and security, as described in section 6.4.

  • Bitwarden — the password manager we use to issue access passcodes to tutors and to hold our own

credentials securely.

  • Google Analytics — website analytics only, set only where you agree to analytics cookies. No pupil or

client information is held there.

10. Where Your Information Is Held

Our Microsoft 365 system is set to keep our data in the United Kingdom, so our emails and our SharePoint files are stored here. Responses to our online forms are held within the European Union, which UK law treats as offering equivalent protection. TutorCruncher, our tuition management system, is a UK company. Some of the suppliers it uses store data outside the UK, including in the United States. TutorCruncher has contracts in place that meet UK data protection requirements for those transfers, and a list of its suppliers is published in its privacy policy and available from us on request. If any provider we use holds information outside the UK, we check before we start using them that the arrangement meets UK data protection rules.

11. Data Controller and Data Processor

The UK GDPR distinguishes between organisations that decide how and why personal information is used (“data controllers”) and organisations that handle personal information on behalf of others (“data processors”). Fylde AP & Education Services Ltd is the data controller for the personal information described in this policy. This applies both to provision we deliver ourselves and to information you give us when we act as an employment business introducing tutors. Our data processors act only on our instructions and under a written contract. They are Microsoft Corporation, which hosts our email, file storage, collaboration and forms; TutorCruncher Ltd, which holds our client, tuition, pupil and safeguarding records; Simultech IT, which administers and supports those systems for us; and Bitwarden, which holds credentials and access passcodes. None of them decides how the information is used, and none uses it for its own purposes. Where we deliver provision commissioned by a school or local authority, that body is also a data controller in its own right. We each hold our own records and each have our own responsibilities under data protection law. The commissioning body remains responsible for the statutory record it holds about the pupil.

11.1 Self-employed tutors

Where we introduce a self-employed tutor to you, that tutor is a separate data controller for the information they hold and create in the course of delivering sessions, such as their own session notes and correspondence. Tutors are required to be registered with the Information Commissioner’s Office where necessary, to hold their own privacy policy, and to comply with data protection law. They are not our data processors, and we are not responsible for how they meet their own obligations. We do, however, set binding conditions on the information we disclose to them. Every tutor signs our Information Handling Schedule at induction, as a condition of engagement and as part of our tutor terms. It governs how they may access, use, store, share and dispose of the information we provide, how they must report any loss or unauthorised disclosure, and what they must do with our material when an assignment ends. A copy is available on request. A tutor may keep their own records where they are legally required to, for example for tax or insurance purposes, or where they have made a safeguarding record. They do so as a controller in their own right and under their own registration, and it does not entitle them to keep a copy of our records.

11.2 Our employees

Our employees are not separate data controllers. They act under our authority and on our instructions, and we remain the data controller for everything they do with personal information in the course of their work. We are responsible for how they handle it. Employees sign the same Information Handling Schedule at induction and are bound by the same handling rules as tutors. For employees these obligations also come through their contract of employment and our Staff Policy, and a failure to follow them is a disciplinary matter. Records created by an employee in the course of their work belong to us and remain with us when their employment ends.

12. Your Rights

Under the UK GDPR you have the following rights.

12.1 Right to be informed

You have the right to be told how your information is collected, used, shared and stored. This policy is how we meet that duty.

12.2 Right of access

You may request a copy of the personal information we hold about you by making a Data Subject Access Request. The statutory deadline for responding is one calendar month from our receipt of your request, which may be extended by up to two further months where the request is complex or where we have received a number of requests from you.

12.3 Right to rectification

If personal information is inaccurate, out of date or incomplete, you have the right to have it corrected, updated or completed. This right applies to your own personal information; you cannot seek the rectification of another person’s information.

12.4 Right to erasure

In certain circumstances you can ask for your personal information to be erased. This is a qualified right, not an absolute one. It may apply where the information is no longer necessary for the purpose it was collected for, where consent was the lawful basis and has been withdrawn, where you have objected to processing based on legitimate interests and we have no overriding grounds to refuse, where information is processed for direct marketing and you object, or where legislation requires the information to be destroyed. Some records cannot be erased on request. Safeguarding and child protection records, and records we are required to keep by law, are retained for the periods set out in this policy regardless of a request for erasure.

12.5 Right to restrict processing

You may request that we restrict processing if you are concerned about the accuracy of your information, believe it has been unlawfully processed, need us to keep it solely for a legal claim, or where we are considering your objection to processing based on legitimate interests.

12.6 Right to object

You have the right to object to processing based on our legitimate interests or on public interest. Where you do, we must demonstrate compelling legitimate grounds which override your interests, rights and freedoms in order to continue.

12.7 Right to data portability

You have the right to obtain certain personal information in an accessible, machine-readable format, and to ask us to transfer it to another organisation. This right applies only to information you have given us directly in electronic form, and onward transfer is available only where technically feasible.

12.8 Non-discrimination

We will not treat you less favourably for exercising any of your rights over your personal information.

13. Data Breaches

Upon discovery of a data breach we will investigate the incident, assess it against ICO guidance, and report it to the Information Commissioner’s Office within 72 hours where the reporting threshold is met. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify those affected without undue delay, and take remedial action. Tutors and staff are required to report any loss or unauthorised disclosure of information to us within 24 hours of becoming aware of it, so that we can meet these deadlines. The same requirement applies to our IT provider under their contract with us.

14. Cookies

We use cookies to keep our website working and, with your agreement, to understand how it is used. Please refer to our Cookie Policy for full details of the cookies we use and how to change your preferences.

15. Business Transfers

If we or our assets are acquired, or in the unlikely event that we cease trading or enter insolvency, personal information may be transferred to the party acquiring us or to a successor provider. Any party receiving personal information in these circumstances would be required to continue to handle it in accordance with this policy and with data protection law. Where a transfer would affect provision for a pupil, we would notify parents and carers, and the commissioning school or local authority, and would work with them to ensure continuity of provision and the safe transfer or return of records. Safeguarding and child protection records would be transferred or returned in line with statutory guidance and any requirements set by the relevant local authority, rather than treated simply as a business asset.

16. Limits of This Policy

Our website may link to external sites that are not operated by us. We have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

17. Changes to This Policy

We may change this privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. We review it at least annually. If we decide to change this policy, we will post the changes at the same link by which you are accessing it. The version number and date on the cover page show when it was last updated. This version, 4.0, is issued on completion of the change of systems described in the interim version 3.1. Our information is now held on a single platform, in the United Kingdom, as described in section 1.1. If required by law, we will seek your permission, or give you the opportunity to opt in or opt out, in relation to any new uses of your personal information.

18. Complaints and Contact

If you have any questions or concerns about this policy or about how we handle your information, or if you wish to exercise any of your rights, please contact: Rachel Swarbrick, Director and Data Protection Lead Fylde AP & Education Services Ltd 10a Tithebarn Street, Poulton-le-Fylde, FY6 7BX rachel@fyldeap.co.uk We would appreciate the chance to deal with your concerns before you approach the regulator, so please contact us in the first instance. We will promptly investigate any complaint and respond in writing, setting out the outcome of our investigation and the steps we will take. You also have the right at any time to lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority for data protection: Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 | Website: www.ico.org.uk

Cookies

Full details of the cookies we use, and how to change your preferences, are in our Cookie Policy.