Skip to content

Privacy policy

DRAFT. This document was prepared from public ICO template guidance and has not been reviewed by a lawyer. It must receive legal review before being treated as published policy.

Who we are

ABMS is an operations platform for training providers. This deployment is operated by BrightOak Consultancy Limited (“we”, “us”), the data controller for the personal data described below. Contact: admin@brightoak.uk.

What personal data we process today

Staff accounts. Name, work email address, role, and authentication data (password hashes and two-factor authentication enrolment, held by our authentication provider). Lawful basis: legitimate interests in operating and securing an internal business system.

Business contacts. Names, roles, work email addresses and phone numbers of people at client and partner organisations who arrange training business with us. Lawful basis: legitimate interests in managing business relationships.

Trainers. For the people who deliver our training — employees, self-employed associates and trainers supplied through partners — we process names, contact details, home location (used to plan travel to training venues), engagement terms including day and per-course rates, IR35 assessment status for associates, qualification and exam-institute accreditation records with renewal dates, and compliance-check facts. Lawful bases: performance of the engagement contract and legitimate interests in scheduling qualified, compliant trainers.

Criminal-record (DBS) check status. For trainers we record that a DBS check exists, when it was verified and when it expires — the fact of the check only. We do not store DBS certificates or their contents in this system. This is criminal offence data under Article 10 UK GDPR; [THE ARTICLE 10 CONDITION AND APPROPRIATE POLICY DOCUMENT TO BE CONFIRMED BY LEGAL REVIEW before this draft is published].

Audit records. Actions taken in the system are recorded against the staff account that took them, for accountability and security. These records are append-only. Where an audited change involves personal data (for example a trainer’s rate), the audit record contains the before and after values; access to the audit log is restricted more tightly than access to the records themselves.

Course delegates

Delegates. For the people attending training we process names, contact details, bookings (including which organisation pays for each place), per-session attendance, exam results and certificates of attendance. Lawful bases: performance of the training arrangement and legitimate interests in running and invoicing courses. A delegate can request erasure: we anonymise the person in place while the underlying booking records — which are financial records — are retained.

Dietary and accessibility requirements. Where a delegate chooses to tell us, we record dietary requirements and accessibility requirements so that venues, catering and materials can be arranged for the events they attend. This can be special category data under UK GDPR (dietary needs can reveal religion or health; accessibility needs can reveal disability). We process it on the basis of Article 9(2)(a) explicit consent: providing it is entirely optional, it is used solely to arrange the delivery of the events the delegate attends, and consent can be withdrawn at any time — on request we delete these details immediately, without affecting the booking. This paragraph is subject to confirmation at legal review, as is the rest of this draft.

Where data is stored and who processes it

Data is stored in a dedicated Postgres database hosted by Supabase in the AWS eu-west-1 region (Ireland). The application is hosted by Vercel with functions pinned to the London region. Error monitoring is provided by Sentry when enabled. These providers act as processors; [DATA PROCESSING AGREEMENTS AND INTERNATIONAL TRANSFER MECHANISMS TO BE CONFIRMED BY LEGAL REVIEW].

Retention

Dietary and accessibility requirements are deleted 30 days after the last event they supported has been delivered, and immediately on request at any time.

[RETENTION PERIODS FOR OTHER DATA TO BE SET BY LEGAL REVIEW.] Audit records are append-only by design and record only the fact that personal-data fields changed, never their contents; the retention approach for them must be decided as part of that review.

Your rights

Under UK GDPR you can ask us for access to, correction of, or erasure of your personal data, ask us to restrict or object to processing, and ask for data portability where it applies — including withdrawal of consent for dietary and accessibility requirements, which we act on immediately. Contact admin@brightoak.uk. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

Last updated: 28 August 2026 (draft). This page is versioned in the project repository; substantive changes are recorded there.