Legal

Privacy Policy

This privacy notice gives you information about how Hemsley Fraser Group Limited collects and uses your personal data through your access to and use of this website, our learner portals or Digital Hub(s). 

Hemsley Fraser Group Limited is the controller and responsible for your personal data (collectively referred to as, “Hemsley Fraser”, "we", "us" or "our" in this privacy policy).

Hemsley Fraser Group Limited is a learning and development provider predominantly serving the business-to-business market. We are registered in England and Wales No: 02638042.
Our VAT registration number is GB 777 3270 03. Our data protection registration number is Z5610077.

Our registered address is BLOCK Plymouth, 23 Melville Building, Royal William Yard, Plymouth, PL1 3RP

We have appointed a data privacy manager to oversee compliance with this Privacy Policy.  If you have any questions concerning this policy, personal information that we hold on you, how to change your personal information or make a complaint please contact compliance@hemsleyfraser.co.uk

 

1. Overview

Hemsley Fraser is committed to the responsible and lawful handling of personal data in all jurisdictions in which it operates when providing services to clients.

This statement sets out our approach to data protection and privacy compliance and is intended to provide assurance to clients, partners, and procurement stakeholders when evaluating us as a supplier or training partner.

2. Applicable Legal Framework

We operate in compliance with applicable data protection legislation across our global operations, including:

  • The UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 and Data Use and Access Act 2025 in the United Kingdom;
  • The EU General Data Protection Regulation (EU) 2016/679 (EU GDPR) in the European Economic Area; and
  • Other applicable national data protection laws in the jurisdictions in which we deliver services.

Where UK GDPR and EU GDPR both apply, we apply the higher standard.

3. Personal Data We Process

Hemsley Fraser processes a minimal volume of personal data necessary to provide training services to our clients. The personal data we collect and process is limited to:

  • Full name; and
  • Email address.

We do not collect or process sensitive or special category personal data as defined under Article 9 of the UK/EU GDPR. We do not collect financial information, health data, identity documents, or any data beyond that strictly necessary for the purposes described below.

4. Purposes of Processing and Lawful Basis

We process names and email addresses for the following purposes:

Purpose Lawful Basis
Registering and administering participant enrolment on training programmes Performance of a contract (Article 6(1)(b)) or Legitimate interests (Article 6(1)(f))
Communicating with participants regarding scheduled training sessions and materials Performance of a contract (Article 6(1)(b))
Issuing completion records or certificates Performance of a contract (Article 6(1)(b))
Communicating with client contacts regarding programme delivery and administration Legitimate interests (Article 6(1)(f))
Compliance with legal obligations Legal obligation (Article 6(1)(c))

5. Data Minimisation

In accordance with the data minimisation principle under Article 5(1)(c) UK/EU GDPR, we collect only the personal data that is necessary for the specific purpose for which it is collected. Our processing is by design limited to names and email addresses, and we do not request or retain additional personal information unless it is strictly required and a fresh assessment has been conducted.

6. Data Retention

Personal data is retained only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. Our standard retention periods are:

  • Participant enrolment and completion records: 6 years from the date of the relevant training session, to support certification verification requests.
  • Client contact information: for the duration of the contractual relationship and 6 years thereafter, in accordance with our legitimate interests in maintaining business records.

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.

7. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration, in accordance with Article 32 UK/EU GDPR. Given the limited nature of the personal data we process (names and email addresses only), we assess the risk to data subjects to be low. Our security measures are nonetheless calibrated to reflect best practice.

8. International Data Transfers

Hemsley Fraser operates globally. Where personal data is transferred outside the United Kingdom or the European Economic Area, we ensure that appropriate safeguards are in place in accordance with Chapter V of the UK GDPR and EU GDPR respectively, including:

  • Adequacy regulations or decisions;
  • Standard Contractual Clauses (SCCs) approved by the ICO or European Commission as applicable; or
  • Other transfer mechanisms permitted under applicable law.

9. Third-Party Processors

Where we engage third-party service providers who process personal data on our behalf (for example, learning management system providers or email platform providers), we ensure that:

  • Data processing agreements compliant with Article 28 UK/EU GDPR are in place;
  • Processors provide sufficient guarantees of their technical and organisational security measures; and
  • Processors act only on our documented instructions.

10. Data Subject Rights

Hemsley Fraser respects and upholds the rights of data subjects under UK/EU GDPR. Requests may be submitted to compliance@hemsleyfraser.com.

11. Data Breach Management

We maintain internal procedures for identifying, assessing, and responding to personal data breaches in accordance with our obligations under Articles 33 and 34 UK/EU GDPR. In the event of a breach that poses a risk to the rights and freedoms of data subjects, we will notify clients without undue delay.

12. Accountability and Governance

Hemsley Fraser maintains records of processing activities in accordance with Article 30 UK/EU GDPR. Our data protection compliance is overseen by our Data Protection Officer, who can be contacted at compliance@hemsleyfraser.com.

{