GDPR Compliance
Your data protection rights under EU regulation
Our Commitment to GDPR
isle-yard is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented policies and procedures to protect personal data under our control, including identification of relevant categories of data, what data needs to be protected, risk assessments, and documentation of processing activities.
Data Controller
isle-yard acts as the Data Controller for personal information collected through our website and services. As the Data Controller, we determine the purposes and means of processing personal data and are responsible for ensuring compliance with data protection legislation.
Contact details:
isle-yard
27 Pemberton Lane
London, EC2A 4NR
United Kingdom
Email: [email protected]
Your Rights as a Data Subject
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request. In certain circumstances, we may charge a reasonable fee or refuse the request if it is manifestly unfounded or excessive.
Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you. If your personal data is incomplete, you have the right to have it completed, including by providing a supplementary statement.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including:
- The data is no longer necessary for the purpose for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, including:
- You contest the accuracy of the data (processing restricted while we verify accuracy)
- The processing is unlawful but you oppose erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing pending verification of our legitimate grounds
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in such automated decision making.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to your request within one month, though this may be extended by two months for complex requests.
Data Processing Activities
We process personal data for the following purposes:
- Providing educational services and course delivery
- Processing enrolments and managing student accounts
- Payment processing and billing
- Customer support and communication
- Website analytics and improvement
- Marketing communications (with consent)
- Legal compliance and fraud prevention
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods include:
- Account information: Duration of account plus 3 years
- Course completion records: Indefinitely for certificate verification
- Payment records: 7 years for tax and legal purposes
- Marketing preferences: Until consent is withdrawn
- Website analytics: 26 months
International Data Transfers
Where we transfer personal data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or adequacy decisions.
Data Security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit and at rest, access controls, and regular security assessments.
Data Breach Procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. The UK supervisory authority is:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Updates to This Information
We may update this GDPR information page from time to time. Any changes will be posted on this page with an updated revision date.