Advertising Content

Last updated: September 2024

Our Commitment to Data Protection

Fern Loop is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we fulfil our obligations and how you can exercise your rights.

Data Controller Information

For the purposes of data protection law, Fern Loop acts as the data controller for personal information collected through our website and services.

Contact details:
Fern Loop
47 Kensington Gardens Square
London, W2 4BQ
United Kingdom
Email: [email protected]

Lawful Bases for Processing

We process personal data under the following lawful bases:

Contract

When you enrol in a course, we process your data to fulfil our contractual obligations to you. This includes processing payments, providing course access, and delivering educational content.

Legitimate Interests

We may process your data when it is in our legitimate interests to do so, provided those interests do not override your fundamental rights and freedoms. This includes fraud prevention, improving our services, and internal administrative purposes.

Consent

For marketing communications and certain types of cookies, we obtain your consent before processing. You may withdraw this consent at any time.

Legal Obligation

We may process your data when required to comply with legal obligations, such as tax reporting or responding to lawful requests from public authorities.

Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving your request, free of charge in most cases.

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to your request within one month.

Right to Erasure

You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when processing is unlawful. Certain exceptions apply, such as when data must be retained for legal compliance.

Right to Restriction of Processing

You may request that we restrict the processing of your data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you do not want us to delete it.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used format, and to transmit it to another controller.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making processes.

How to Exercise Your Rights

To exercise any of your rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond within one month, though this may be extended by two months for complex requests.

Data Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

When we transfer personal data outside the United Kingdom, we ensure appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other legally approved mechanisms.

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) when introducing new technologies or processing activities that are likely to result in high risk to individuals' rights and freedoms.

Record Keeping

We maintain records of our processing activities as required under UK GDPR Article 30. These records include the purposes of processing, categories of data subjects and personal data, recipients, international transfers, retention periods, and security measures.

Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: www.ico.org.uk

We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.

Updates to This Information

We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.