top of page

GDPR Policy

The General Data Protection Regulation (GDPR), effective from 25th May 2018, requires all businesses to issue a privacy notice outlining how personal data is collected, used, and protected.

This policy explains our data handling practices, both online and in person. It is available on our website or upon request. Please review it carefully. Any updates will be reflected on our website.

1. Introduction

Inclusion at Heart is committed to protecting the privacy and security of personal information belonging to students, parents/carers and other individuals who use our services. This policy explains how Inclusion at Heart collects, uses, stores, protects and disposes of personal information when providing tutoring and support services, both online and face-to-face.

This policy is intended to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as applicable to our services. This policy is available on the Inclusion at Heart website and upon request. Any significant updates will be reflected in the current version of this policy.

2. Data Controller

Sara Lewis, Founder and Tutor of Inclusion at Heart, is the Data Controller responsible for determining how and why personal information is processed and for ensuring that appropriate measures are in place to protect it.

Contact: inclusionatheartbristol@gmail.com

3. What Personal Data We Collect

We only collect information that is necessary and relevant for providing our services, managing our business and meeting our legal and safeguarding responsibilities.

 

Information is provided directly by parents/carers, students, schools or other professionals involved in a student's education.

This may include:

Personal and contact information

  • Name

  • Date of birth or age

  • School year

  • School attended

  • Home address

  • Telephone numbers

  • Email addresses

  • Parent/carer details

  • Emergency contact details

Educational information

  • Academic attainment and working levels

  • Educational history

  • Learning needs

  • SEND information

  • EHCP information

  • Learning objectives and targets

  • Session notes

  • Lesson plans

  • Progress records

  • Marked work

  • Assessment information

  • Information provided by schools or other professionals

Health and additional needs information

Where necessary to provide appropriate educational support or safeguard a student, we may collect relevant information relating to:

  • Medical needs

  • Disabilities

  • Special educational needs

  • Communication needs

  • Accessibility requirements

  • Mental or physical health information

  • Other relevant information relating to a student's wellbeing or safety

Some of this information may constitute special category data under UK GDPR and will only be collected and processed where there is an appropriate lawful basis and additional legal condition for doing so.

Administrative and financial information

  • Session dates and times

  • Attendance records

  • Invoice records

  • Payment information

  • Payment history

  • Correspondence relating to bookings and services

Online learning information

Where applicable, we may process information associated with online tuition platforms, such as:

  • Google Meet

  • Zoom

  • Microsoft Teams

  • Other agreed educational platforms

This may include account names, email addresses, login details or information generated through use of the platform.

We do not request or store unnecessary passwords for students or parents.

4. How We Collect Personal Data

Personal information may be collected through:

  • Website contact forms

  • Registration forms

  • Tuition agreements

  • Emails

  • Telephone conversations

  • Text messages

  • WhatsApp or other agreed messaging platforms

  • Online learning platforms

  • Face-to-face meetings

  • Information provided by schools or other professionals

  • Academic work and assessments

  • Invoices and payment records 

​​

Where information is provided by a school, parent/carer or another professional, Inclusion at Heart will use the information only where it is relevant and necessary for the services being provided.

 

5. Why We Use Personal Data

Personal information is processed only where necessary for legitimate and clearly defined purposes.

These purposes include:

  • Providing tutoring and educational support

  • Planning and delivering lessons

  • Understanding a student's educational and support needs

  • Monitoring and recording progress

  • Communicating with students and parents/carers

  • Managing bookings and attendance

  • Preparing invoices and managing payments

  • Maintaining appropriate educational records

  • Meeting legal and tax obligations

  • Safeguarding children, young people and vulnerable adults

  • Responding to safeguarding concerns

  • Managing complaints or concerns

  • Maintaining appropriate business records

  • Improving the quality and effectiveness of our services

  • Communicating marketing information where appropriate consent has been provided

We will not collect or use personal information for purposes that are incompatible with the purpose for which it was originally collected unless there is a lawful basis for doing so.

6. Lawful Basis for Processing

UK GDPR requires organisations to identify an appropriate lawful basis for processing personal information. Where processing is necessary to provide the tutoring services requested and to manage the agreement with a parent/carer or client.

This may include:

  • Booking and scheduling sessions

  • Delivering tuition

  • Communicating about sessions

  • Maintaining relevant tutoring records

  • Managing invoices, contracts  and payments

Legal obligation

Where processing is necessary for Inclusion at Heart to comply with a legal obligation.

This may include:

  • Maintaining financial and tax records

  • Responding to lawful requests from authorities

  • Meeting relevant safeguarding or legal requirements

Legitimate interests

Where processing is necessary for legitimate business or educational purposes and those interests are not overridden by the individual's rights and freedoms.

Vital interests

Where processing is necessary to protect someone's life or prevent serious harm, where applicable.

Consent

Consent may be used for specific activities where consent is the appropriate lawful basis, such as certain forms of marketing or photography/social media use.Consent can be withdrawn at any time.

The withdrawal of consent does not affect processing that was lawfully carried out before consent was withdrawn.

Different processing activities may therefore have different lawful bases.

A single blanket consent is not relied upon as the legal basis for all processing.

7. Children's Personal Data

Inclusion at Heart works with children and young people and recognises that children's personal information requires particular care and protection.

Children have data protection rights in their own right. Depending on their age, maturity and understanding, a child may be able to exercise their rights independently. Parents/carers may also exercise rights on behalf of a child in appropriate circumstances.

We will:

  • Collect only information that is necessary and proportionate

  • Explain data use in an age-appropriate way where appropriate

  • Take additional care when processing children's information

  • Maintain appropriate security measures

  • Consider the child's best interests when dealing with data protection requests

  • Ensure safeguarding concerns are not compromised by inappropriate deletion or disclosure of information

8. Special Category Data

Information relating to health, disability and certain SEND or medical information may constitute special category data under UK GDPR.

Inclusion at Heart will only process such information where it is necessary and where an appropriate Article 6 lawful basis and Article 9 condition apply.

This information may be necessary to:

  • Adapt teaching and learning

  • Meet accessibility needs

  • Understand educational needs

  • Support a student's wellbeing

  • Safeguard a student

  • Communicate appropriately with parents/carers or relevant professionals

Special category information will receive additional protection and will only be accessed or shared where necessary.

The ICO confirms that special category data requires both a lawful basis under Article 6 and an additional condition under Article 9.

9. Sharing Personal Data

Personal information will not be sold or shared for unrelated commercial purposes.

Information may be shared where necessary and lawful with:

  • Parents/carers

  • Schools

  • Local authorities

  • Other educational professionals

  • Relevant safeguarding professionals

  • Health or social care professionals where appropriate

  • HMRC or other statutory authorities where legally required

  • Police or emergency services where necessary

  • Professional service providers who process information on our behalf

Information may be shared without consent where this is necessary to protect a child, young person or vulnerable adult, or where there is a legal obligation or other lawful basis to do so.

Safeguarding

Where a safeguarding concern exists, information may need to be shared with children's social care, the police or other safeguarding professionals.

 

Data protection law does not prevent appropriate information sharing for safeguarding purposes. Safeguarding concerns will be prioritised where necessary to protect an individual from harm.

10. Data Processors and Online Platforms

Inclusion at Heart may use third-party services to deliver its services and manage business administration.

These may include, where applicable:

  • Google Meet

  • Zoom

  • Microsoft Teams

  • Email providers

  • Accounting/invoicing software

  • Website providers

  • Payment providers

Where third-party organisations process personal data on behalf of Inclusion at Heart, appropriate arrangements will be considered to ensure that personal information is processed securely and appropriately.

The privacy policies and terms of the relevant platforms may also apply when those platforms are used.

11. Data Security and Storage

Inclusion at Heart takes reasonable and appropriate technical and organisational measures to protect personal information against:

  • Unauthorised access

  • Loss

  • Accidental destruction

  • Unauthorised disclosure

  • Alteration

  • Misuse

Security measures include:

  • Paper records stored securely in a locked cabinet

  • Electronic information stored using appropriate secure systems

  • Password-protected computers and devices

  • Passcode-protected mobile devices

  • Appropriate account passwords and security measures

  • Restricting access to personal information to those who need it

  • Avoiding leaving personal information unattended or visible to others

  • Secure disposal of paper records

  • Permanent deletion or anonymisation of digital information when no longer required

12. Data Minimisation

Inclusion at Heart follows the principle of data minimisation.

Only information that is necessary, relevant, proportionate, accurate and required for a defined purpse will be collected and retained. 

We will not routinely collect information simply because it may be useful in the future.

13. Accuracy

We will take reasonable steps to ensure that personal information held by Inclusion at Heart is accurate and, where necessary, kept up to date.

Parents/carers and students can request that inaccurate or incomplete information is corrected.

 

14. Data Retention

Personal data will not be retained for longer than is necessary for the purpose for which it was collected, unless there is a legal or safeguarding reason to retain it.

Our standard retention periods are:

General client/tutoring records

Personal tutoring records will normally be retained for 2 years after tuition ends.

Financial records

Financial and tax records will normally be retained for 7 years, or for the period required by applicable tax and accounting requirements.

Safeguarding records

Safeguarding records may need to be retained for longer than general tutoring records where necessary to meet safeguarding, legal or accountability requirements.

Where a safeguarding matter is ongoing, records will not be deleted simply because the standard client retention period has expired.

Retention periods will be reviewed periodically.

15. Secure Disposal

When personal information is no longer required:

  • Paper records will be securely shredded or otherwise securely destroyed.

  • Digital records will be permanently deleted where appropriate.

  • Information held on devices or platforms will be removed where appropriate.

  • Contact information will be removed from business systems when no longer required.

Where information must be retained for legal, financial or safeguarding reasons, it will be securely stored for the required period before disposal.

16. Your Data Protection Rights

Individuals have a number of rights under UK data protection law.

Depending on the circumstances, these include the right to:

  • Be informed about how personal data is used

  • Request access to personal data

  • Request correction of inaccurate information

  • Request erasure of personal data

  • Request restriction of processing

  • Object to certain processing

  • Request data portability in applicable circumstances

  • Withdraw consent where processing is based on consent

These rights are not absolute and may be subject to legal exemptions or circumstances where Inclusion at Heart has a lawful reason to retain or continue processing information.

For example, the right to erasure does not mean that all information must automatically be deleted immediately. Information may need to be retained where there is a legal obligation or safeguarding reason to do so.

17. Subject Access Requests

Individuals have the right to request a copy of the personal information Inclusion at Heart holds about them.

This is known as a Subject Access Request (SAR).

Requests should be made to:

inclusionatheartbristol@gmail.com

Inclusion at Heart will respond in accordance with applicable data protection requirements. The ICO states that organisations will generally have one month to respond to a valid Subject Access Request.

Where a request concerns a child's information, consideration will be given to the child's age, maturity, understanding and best interests.

 

18. Safeguarding and Data Protection

Data protection and safeguarding responsibilities will be considered together.

Inclusion at Heart will not delete, withhold or refuse to record necessary safeguarding information simply because it contains personal or sensitive information. Where information needs to be shared to protect a child, young person or adult at risk, appropriate safeguarding information may be shared with the relevant authorities.

Any decision to share safeguarding information will be recorded where appropriate.

19. Data Breaches

A personal data breach may include:

  • Sending personal information to the wrong person

  • Losing a device containing personal information

  • Unauthorised access to an account

  • Accidental disclosure of confidential information

  • Loss or theft of paper records

  • A cyberattack

  • Unauthorised access to online platforms

If a breach occurs, Inclusion at Heart will:

  1. Identify and contain the breach as quickly as possible.

  2. Establish what information has been affected.

  3. Assess the potential risk to individuals.

  4. Record the breach and actions taken.

  5. Take steps to prevent further harm.

  6. Consider whether the breach must be reported to the ICO.

  7. Inform affected individuals where legally required or appropriate.

Where a breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Not every breach requires notification to the ICO, but all breaches should be appropriately assessed and recorded.

Where a breach presents a high risk to an individual's rights and freedoms, affected individuals will also be informed where required.

20. Marketing and Communications

Inclusion at Heart will only send marketing communications where there is an appropriate lawful basis to do so.

Where consent is required, individuals will be asked to actively opt in.

Marketing communications may include:

  • Business updates

  • Newsletters

  • New service announcements

  • Educational information

  • Promotional offers

Individuals can unsubscribe from marketing communications at any time.

Unsubscribing from marketing communications will not affect essential communications relating to existing tuition services.

21. Photography, Student Work and Social Media

Inclusion at Heart may occasionally wish to share examples of students' work or activities for educational, promotional or social media purposes.

Students' faces or full names will not be shared.

Where photography, student work or other identifiable material is intended for use on the Inclusion at Heart website or social media, a separate consent process will be used. Consent for photography/social media use is separate from consent or other lawful bases used to provide tutoring services.

Parents/carers may withdraw consent for future use at any time.

Where a student is able to exercise their own data protection rights, their views and rights will also be considered.

 

22. Confidentiality

Inclusion at Heart will treat personal information as confidential and will only access or share information where there is a legitimate reason to do so.

However, confidentiality cannot be guaranteed where information needs to be shared to:

  • Safeguard a child or vulnerable adult

  • Prevent serious harm

  • Comply with a legal obligation

  • Respond to a lawful request from an appropriate authority

This is particularly important where a student discloses a safeguarding concern.

23. Complaints and Concerns

If you have concerns about how Inclusion at Heart handles your personal information, please contact:

Sara Lewis
Inclusion at Heart
Email: inclusionatheartbristol@gmail.com

We will aim to resolve concerns directly.

Individuals also have the right to complain to the Information Commissioner's Office (ICO) if they believe their personal information has not been handled appropriately.

24. Information Commissioner's Office

Inclusion at Heart is registered with the Information Commissioner's Office.

ICO Registration Number: ZB971415

The ICO is the UK's independent supervisory authority for data protection.

25. Policy Review

This policy will be reviewed at least annually and sooner where there are significant changes to:

  • Data protection legislation

  • ICO guidance

  • The services provided by Inclusion at Heart

  • The types of personal information collected

  • The technology or platforms used by Inclusion at Heart

  • Safeguarding requirements

Policy Owner: Sara Lewis
Policy Updated: September 2026
Next Review: September 2027

bottom of page