This document sets out the types of Personal Data (meaning information about an individual from which that individual can be personally identified) we handle, the purposes of handling those Personal Data and any recipients of it.
For the purposes of data protection laws the Company is the data controller.
We evaluate the relevant sites which we provide links to but HfL does not give approval or endorsement of those websites and we are not responsible for their content. As such, links to other websites are not covered by this policy and individuals are advised to check the privacy policies of those other sites for their terms and conditions.
1. Our details
We are: Herts for Learning Limited
Address: Robertson House, Six Hills Way, Stevenage, SG1 2FQ
Information Commissioner's Office Registration Number: ZA154308
Our Data Protection Officer is: Lynette Dexter, Company Secretary
Email address for the Data Protection Officer: email@example.com
2. Why we collect personal data
We collect and hold personal information relating to our users. We may also receive information from other bodies linked to pupils' education, development and welfare.
We may share Personal Data with other agencies as necessary under our legal duties or otherwise in accordance with our duties/obligations as a Company.
The Personal Data we are provided with or collect from the Grid is provided to us on a voluntary basis.
Below sets out the reasons why we collect and process Personal Data, as well as the legal basis on which we carry out this processing:
- to support pupils’ learning: we will process Personal Data to help every child achieve his or her potential in all areas of learning and to promote excellence in teaching and learning environment.
- to assess the quality of our services: we will process Personal Data so that we may reflect on our own practices to help us improve and provide the highest quality service that we can to all users.
- to provide information to improve our website: we will process information for system administration and to provide statistics which we use for evaluation of the site.
3. Legal basis for processing personal data
The lawful basis for us to collect/process this Personal Data is by reason of necessity for the performance of a contract to which the Data Subject is party, or in order to take steps at the request of the Data Subject prior to entering into a contract.
We also process Personal Data where processing is necessary for the purposes of legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject.
We do not process any special categories of Personal Data except where necessary for reasons of substantial public interest in complying with legal obligations including under the Equality Act 2010 or where necessary to protect the vital interests of the Data Subject or of another natural person and where safeguards are in place to ensure that this Personal Data is kept secure. For the avoidance of doubt where special categories of Personal Data are collected it shall not be used for the purposes of automated decision making and/or profiling.
Special categories of data means Personal Data revealing:
- racial or ethnic origin;
- political opinions; religious or philosophical beliefs or trade union membership;
- genetic or biometric data that uniquely identifies you;
- data concerning your health, sex life or sexual orientation; or
- data relating to criminal convictions or offences or related security measures.
Further Personal Data including special categories of Personal Data may be collected and/or processed where consent has been given. If consent is the only legal basis for processing and has been given then this may be revoked in which case the Personal Data will no longer collected/processed.
The cookie is used to make the link between you and the information you have provided to the website. The creation of a cookie on your computer does not give the website any access to other information such as your email address.
Where the Grid links to external/third party websites or other Hertfordshire County Council websites/HCC systems which may set cookies, we have no control over these. Certain of our pages may contain links to Twitter, Facebook and Survey Monkey. These web sites set cookies as part of their processes which we cannot control.
A list of the cookies we use on the site is below:
Contensis functional or necessary cookies
Cookies set or used by web controls
|[ID of Control]_Favourites||Stores favourites which have been selected by the us||When the user clears cookies|
|CMSFontSizeCookie||Stores your current font size selection||12 months|
|CMSStylesheetCookie||Stores the user's current stylesheet selection||12 months|
|.ASPXAUTH||Used to determine if a user is authenticated||12 months|
Cookies set or used by Contensis authentication.
These cookies are set once you login to a Contensis site
|ContensisCMSUsername||Stores information to re-authenticate a user when they have selected Save Password when logging in||When the user exits the browser|
|ContensisDisplayName||Stores a user's display name in the format as specified in Contensis global settings||When the user exits the browser|
|ContensisLastUserName||Stores a users' username - this is set when a user logs in for the first time||25 years or until the user clears the cookie|
Session cookies used by the published site
Session cookies are used for remembering user selections during their visit to the website. A typical scenario may be to remember information entered in a form when navigating to different pages.
|csession||Randomly generated session ID||When the user exits the browser|
|ASP.NET_SessionId||Randomly generated session ID||When the user exits the browser|
Other functional cookies
|We use Tawk to provide an online live chat facility on our website. This system is provided by Tawk.to||__tawkuuid||This cookie is used to collect information about how the visitor interacts with the live chat function on the website.||Expires: 179 days|
|TawkConnectionTime||Allows the website to recoqnise the visitor, in order to optimize the chat-box functionality.||Expires: Session cookie|
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited.
|_utma||Identifies unique visitors. Each unique browser that visits a page on the site is provided with a unique ID via the __utma cookie. In this way, subsequent visits to the website via the same browser are recorded as belonging to the same (unique) visitor.||2 years from set/update|
|_utmb||This cookie is used to establish and continue a user session with the site. Each time a user visits a different page on the site, this cookie is updated to expire in 30 minutes, thus continuing a single session for as long as user activity continues within 30-minute intervals||30 minutes/On closure of browser|
|_utmc||Determines whether or not to establish a new session for the user||Expires on exit from browser|
|_utmv||Determines how to classify the user for custom segmentation reports in Google Analytics.||2 years from set/update|
|_utmz||When visitors reach the website via a search engine result, a direct link, or an ad that links to your page, Google Analytics stores the type of referral information in this cookie||6 months|
Advice on how you can control cookies
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit:
To opt out of being tracked by Google Analytics across all websites visit: http://tools.google.com/dlpage/gaoptout
For more information about Google search preferences: http://support.google.com/websearch/bin/answer.py?hl=en&answer=35892
To find out how to delete your Google search history visit: http://support.google.com/websearch/bin/answer.py?hl=en&answer=465
Or to turn off Google search personalisation: http://support.google.com/accounts/bin/answer.py?hl=en&answer=54048
5. Categories of personal data we collect about you
Herts for Learning does not collect or store any personal information about individuals who browse this website other than where you voluntarily choose to give your personal information via email or online forms used to enquire about or apply for a service.
We may collect the following types of Personal Data (please note this list does not include every type of Personal Data and may be updated from time to time):
- name and contact details;
- user's IP address and session information (such as the duration of the visit, type of browser being used and broad demographic information);
- information received in connection with any complaint
6. Who will have access to your Personal Data
Personal Data will be accessible by members of HfL staff. Where necessary, directors will also have access to Personal Data. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We will not share personal information about our users with third parties without consent unless we are required to do so by law or our policies. We will disclose Personal Data to third parties:
- if we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation;
- in order to enforce any agreements with you;
- in order to perform contracts with third party suppliers for purposes listed in Section 2.
- to protect the rights, property, or safety of HfL, pupils or others. This includes exchanging information with other organisations for the purposes of child welfare.
This may include our Local Authority (Hertfordshire County Council), the Department for Education (DfE), the Police and other organisations where necessary.
Certain data collection obligations are placed on us by the DfE. To find out more about the data collection requirements placed on us by the DfE (for example; via the school census) visit: www.gov.uk/education/data-collection-and-censuses-for-schools.
7. How Personal Data will be processed
Personal Data may be processed in a variety of ways; this will include but is not limited to:
- maintaining written records;
- sending by e-mail;
- adding to spreadsheets, word documents or similar for the purposes of assessing Personal Data;
- for educational software use (this could be for the purposes of helping children learn, discipline, reports and other educational purposes).
The information provided by users via email or online forms will be acted upon according to the content of the communication. For example, responding to enquiries or getting in touch with you when necessary.
8. Where we store Personal Data and how we keep Personal Data secure
We are committed to ensuring that the data you provide is handled securely and have put in place suitable physical, electronic and managerial processes to safeguard your information.
Electronic copies of Personal Data are kept securely and information will only be processed where we are satisfied that it is reasonably secure.
All information you provide to us is stored on secure servers. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website, you are responsible for keeping this password confidential. You must not share your password with anyone.
In particular, this site has security measures in place to protect the loss, misuse and alteration of the information under our control. All instances of unauthorised attempted access to our site are logged and investigated. Where necessary, HfL will inform law enforcement agencies or other relevant organisations regarding misconduct.
At HfL we respect the privacy of email accounts and we store your email addresses securely. Your details will not be passed to ANY organisation beyond HfL without your explicit permission.
9. Retention periods
We will only retain Personal Data processed by us for as long as is considered necessary for the purpose for which it was originally collected. As a general rule, Personal Data will be kept in accordance with guidance from the IRMS. Personal data may be held for longer period where extended retention periods are required by law and/or in order to establish, exercise or defend our legal rights.
Once the retention period concludes Personal Data is securely and safely destroyed / deleted.
10. Your data rights
The General Data Protection Regulation and associated law gives you rights in relation to Personal Data held about you. These are:
- Right to be informed: you have the right to be informed about the collection and use of your data. This policy contains information in relation to the collection of your Personal Data, however, if we collect additional data for other purposes, we will inform you about this.
- Right of Access: if your Personal Data is held by HFL, you are entitled to access your Personal Data (unless an exception applies) by submitting a written request. We will aim to respond to that request within one month. If responding to your request will take longer than a month, or we consider that an exception applies, then we will let you know. You are entitled to access the Personal Data described in Section 11.
- Right of Rectification: you have the right to require us to rectify any inaccurate Personal Data we hold about you. You also have the right to have incomplete Personal Data we hold about you completed. If you have any concerns about the accuracy of Personal Data that we hold then please contact us.
- Right to Restriction: you have the right to restrict the manner in which we can process Personal Data where:
- the accuracy of the Personal Data is being contested by you;
- the processing of your Personal Data is unlawful, but you do not want the relevant Personal Data to be erased; or
- we no longer need to process your Personal Data for the agreed purposes, but you want to preserve your Personal Data for the establishment, exercise or defence of legal claims.
Where any exercise by you of your right to restriction determines that our processing of particular Personal Data are to be restricted, we will then only process the relevant Personal Data in accordance with your consent and, in addition, for storage purposes and for the purpose of legal claims.
- Right to Erasure: you have the right to require we erase your Personal Data which we are processing where one of the following grounds applies:
- the processing is no longer necessary in relation to the purposes for which your Personal Data were collected or otherwise processed;
- our processing of your Personal Data is based on your consent, you have subsequently withdrawn that consent and there is no other legal ground we can use to process your Personal Data;
- the Personal Data have been unlawfully processed; and
- the erasure is required for compliance with a law to which we are subject.
- Right to Data Portability: you have the right to receive your Personal Data in a format that can be transferred. We will normally supply Personal Data in the form of e-mails or other mainstream software files. If you want to receive your Personal Data which you have provided to us in a structured, commonly used and machine-readable format, please contact us via the details in Section 1 of this Notice.
- Right to Object: you have the right to object to the processing of your Personal Data where one of the following grounds apply:
- the processing is based on legitimate interests or the performance of a task in the public interest;
- the processing is for direct marketing; or
- the processing is for the purposes of scientific/ historical research and statistics.
You can find out more about the way these rights work from the website of the Information Commissioner's Office (ICO).
11. Subject Access Request (requesting your Personal Data)
You are entitled to request details of Personal Data that we hold about you and you can access that Personal Data by making a Subject Access Request (SAR).
A SAR is a written or verbal request for personal information (known as personal data) held about you by an organisation. Data protection legislation gives individuals the right to know what information is held about them. However, this right is subject to certain exemptions as set out in the Data Protection Act 2018.
To submit a SAR to HfL we recommend that you email a written request to our Data Protection Officer at firstname.lastname@example.org. To help us respond quickly and effectively to your request, please include information regarding your relationship with us, along with a comprehensive list of what personal data you want to access and any details, relevant dates, or search criteria that will help us identify the information that you want.
12. Making a complaint
If you are unhappy with the way we have dealt with any of your data protection concerns, you can make a complaint to the Information Commissioners Office (ICO), the supervisory authority for data protection issues in England and Wales. We would recommend that you complain to us in the first instance, but if you wish to contact the ICO you can do so using the details below. The ICO is a wholly independent regulator established in order to enforce data protection law.
ICO Concerns website: www.ico.org.uk/concerns
ICO Helpline: 0303 123 1113
ICO Postal Address:
Information Commissioner's Office
Cheshire SK9 5AF
Any changes we make to this notice in the future will be posted on our website and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes.
By using this website you are accepting the terms and conditions of use contained within this policy. If this policy is not acceptable to you, please do not use this website.