Privacy Policy
Effective from date: 11/04/2019
Revision: 7
Review responsibility: Project Director
Signature: Paul Wright
Effective Date: 11 April 2019
Last Reviewed: 20 July 2026
Next Review Due: 20 July 2027
This policy / procedure may be revised at an earlier date if necessary.
Any form of reproduction, dissemination, copying, disclosure, modification, distribution and/or publication of this material is strictly prohibited.
Introduction
The Company, TrAC is a not-for-profit organisation which employs and provides shared apprentices to our contractor partners for fixed durations, and, for the purposes of specific funding streams, we also enable work experience opportunities.
This privacy statement provides guidance and information in relation to the processing of personal data. We are regulated by the EU General Data Protection Regulation which is effective from 25th May 2018. ‘Personal Data’ for the purposes of the Regulation, means any information from which a person can be identified, i.e. name, e-mail address, home address and telephone number. ‘The Business’ is defined as Moore Networking Ltd and TrAC Ltd, located at Building 262b Scottow Enterprise Park, Badersfield, Norfolk NR10 5FB.
Moore Networking Ltd is the contract holder to manage TrAC, a not-for-profit FlexiJob Apprenticeship Agency. Moore Networking Ltd Employees manage all elements of TrAC and its Employees. These include (but are not limited to):
- Apprenticeship Development Managers
- Apprenticeship Mentors
- Operations Manager
- HR
- Business Develop Manager/Co-Ordinator
- Project Manager
- Director
This statement describes how we process in the lawful and relevant business activities of the business. The Business is committed to protecting the privacy of all contacts. We will endeavour to ensure that all information provided by you and held by The Business is kept private and confidential and will only be used in order that The Business can provide the services requested by an individual.
1. Uses and Disclosure of Personal Information
The Business (Moore Networking Ltd) will only share details of data internally (within The Business) and among its Employees and appointed representatives. We may also need to share your data with our delivery partners; for example, we may share data with employers, applicants, training providers, referral agencies or funders when you authorise us to do so. Where this is deemed necessary explicit consent will be requested from you prior to the release of any data we hold.
When we process personal data about you, we do so with your consent and/or as necessary to provide the products you use, operate our business, meet our contractual and legal obligations, protect the security of our systems and our customers, or fulfil other legitimate interests. People we collect data on are known as ‘Data Subjects’.
If you register on the Website as an applicant and provide us with personal data, we will process such personal data on the basis that it is necessary to do so to perform the contract you enter into with us.
If you register on the website or via one of our referral partners, we will process your personal data on the basis set out below as it is in our legitimate interests to do so following your registration.
If you are an employee of TrAC, data is captured and stored in accordance with the requirements of the standard practices of The Business, HR law and HMRC requirements. It is subject to the same rights and protocols as external data subjects.
Personal data will not be transferred to a third country or international organisation. Personal information will only be held for as long as necessary in order to comply with legal obligations and the data sets will be individually assessed against specific legal bases defined as:
- Consent: you have given clear consent for us to process your personal data for a specific purpose.
- Contract: the processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
- Legal obligation: the processing is necessary for us to comply with the law (not including contractual obligations).
- Vital interests: the processing is necessary to protect someone’s life.
- Public task: the processing is necessary for us to perform a task in the public interest or for our official functions, and the task or function has a clear basis in law
- Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect your personal data which overrides those legitimate interests.
You must inform us of any changes to personal information so that the Business can keep data up to date.
We collect data for two basic purposes: to operate our business and provide the services we offer, (you provide some of this data directly, such as when you create an applicant account,) and to send communications, including promotional communications. We get some of it by recording how you interact with our services by, for example, using technologies like cookies and we also obtain data from third parties you have engaged with for services.
Communications. We use data we collect to communicate with you and personalise our communications with you. For example, we may contact you by phone or email or other means to complete our applicant and placement process or inform or update you about a vacancy/candidate.
Social media. The Business promotes The Business and its activities through our website and the use of social media platforms (currently Facebook, Twitter, Instagram and LinkedIn). This may be a generic picture to denote organisational services, as a news item or to highlight a positive outcome for one of our employees or host companies. Where posting will identify an individual, we will seek explicit consent for this purpose and the data/graphics will be stored in accordance with the security information contained in this privacy statement.
Business Operations. We use data to develop aggregate analysis and business intelligence that enable us to operate, protect, make informed decisions and report on the performance of our business.
Data Retention. We retain data for as long as necessary to provide the services and fulfil the transactions you have requested, or for other essential purposes such as complying with our legal obligations, resolving disputes and enforcing our agreements. Because these needs can vary for different data types in the context of different products, actual retention periods can vary significantly. The criteria used to determine the retention periods include:
- How long is the personal data needed to provide the services and operate our business? This includes such things as maintaining and improving the performance of those services, keeping our systems secure and maintaining appropriate business and financial records. This is the general rule that establishes the baseline for most data retention periods.
- Is the personal data of a sensitive type? If so, a shortened retention time would generally be appropriate.
- Have you provided consent for an extended retention period? If so, we will retain data in accordance with your consent.
- Are we subject to a legal, contractual or similar obligation to retain the data? Examples can include mandatory data retention for audit, government orders to preserve data relevant to an investigation or data that must be retained for the purposes of litigation.
Finally, we will access, transfer, disclose and preserve personal data, including your online content (such as the content of your emails) when we have a good faith belief that doing so is necessary to:
- comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies;
- protect our customers, for example to prevent spam or attempts to defraud, or to help prevent the loss of life or serious injury of anyone;
- operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks; or
- protect the rights or property of the business, including enforcing the terms governing the use of the services
2. CONSENT
We share your personal data with your consent as necessary to complete our business processes or provide any information you have requested. We will ask you to give consent (opt in) as part of our standard business practice at the outset of our business relationship.
We will request your consent (opt-in) as part of our standard business practice at the outset of our business relationship.
3. TALENT POOL, CANDIDATE INTRODUCTIONS AND EMPLOYER SHARING
As part of our recruitment, apprenticeship and work experience services, we may maintain a Talent Pool of applicants and candidates on our website. The Talent Pool is used to introduce suitable individuals to employer partners for the purpose of identifying suitable opportunities.
What we share and who we share it with
Where an applicant has provided consent, we may share a limited profile with employer partners. The profile may include:
- First name
- Local area and city
- Field of interest
- Driving licence status
- Age or age range
- Nationality
- Gender
- Qualifications
- Work experience
- Career aspirations
- Hobbies and interests
The Talent Pool will be publicly accessible on our website and may also be shared with approved employer partners for the purpose of identifying suitable opportunities. Employer partners are organisations that are in contact with us and are interested in recruiting an apprentice or work experience candidate.
Contact details
We do not share an applicant’s direct contact details with employers at the Talent Pool stage unless the applicant agrees to progress further or provides additional consent for contact. Where appropriate, initial contact and introductions may be made via TrAC staff.
How we contact applicants
After registration, a member of TrAC staff may contact an applicant using the contact details provided, including by email and telephone, to discuss their registration details and next steps. This contact supports our recruitment, onboarding and placement process.
Lawful basis for processing
We process personal data for the Talent Pool and candidate introduction activities on the following lawful bases:
- Consent, where an applicant has actively opted in to their profile being shared with approved employer partners
- Contract, or steps taken at the request of the applicant before entering a contract, where processing is necessary to progress an application or placement
- Legitimate interests, where appropriate, to operate our services and match candidates to suitable opportunities, provided those interests are not overridden by the applicant’s rights and freedoms
Where we rely on consent for Talent Pool visibility and employer sharing, an applicant may withdraw this consent at any time.
Data minimisation and relevance
We aim to share only information that is relevant and proportionate to identifying suitable opportunities. We periodically review the information displayed in the Talent Pool and may reduce the level of detail shared where appropriate.
Withdrawal of consent and removal from the Talent Pool
Applicants can withdraw consent for inclusion in the Talent Pool at any time. If consent is withdrawn, the applicant’s profile will be removed from employer visibility. This does not affect the lawfulness of processing carried out before consent was withdrawn.
Equality and monitoring information
We may collect information such as age, nationality and gender for monitoring and reporting purposes. This information helps us to understand access to opportunities and improve fairness. We do not use this information to make automated decisions about individuals.
Record keeping and audit
We keep records of consent and other processing activities where required. We may also maintain access controls and logs to support the security of the Talent Pool and to demonstrate compliance.
4. SECURITY
GDPR requires personal data to be processed in a manner that ensures its security. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
The Business will take the necessary steps to protect personal data and will only store information securely in accordance with the data protection and privacy and electronic communications guidance for the type of data held.
We are committed to protecting the security of your personal data. We use a variety of security technologies and procedures to help protect your personal data from unauthorised access, use or disclosure. For example, we store the personal data you provide on computer systems that have limited access and are in controlled facilities. When we transmit highly confidential data over the Internet, we protect it through the use of encryption.
5. YOUR RIGHTS
Anyone has the right to find out what data the Business holds about them and request to have it amended, restricted or erased if applicable. In certain circumstances we can refuse the right and, where this is applicable, will be detailed in our response.
Your rights include:
- The right to be informed of information we hold, why we hold it and how we use it .
- The right of access to that information
- The right to rectification of incorrect data,
- The right to erase data (also known as the right to be forgotten)
- The right to restrict processing of your personal data
- The right to data portability, which only applies:
- to personal data an individual has provided to a controller;
- where the processing is based on your consent or for the performance of a contract; and
- when processing is carried out by automated means.
- The right to object to the use of your data
- Rights in relation to automated decision making and profiling.
6. WITHDRAWAL OF CONSENT
If the processing of personal data is based on your consent, you have a right to withdraw consent at any time for future processing and you can object to the processing of your personal data.
You can withdraw consent or request a copy of information held about you. Your request may be requested verbally or in writing and we will reply within one month of your request.
Our designated Data Protection Manager is
Madeline Buxton madeline@tracweb.co.uk or telephone 01603 737739
You also have a right to lodge a complaint with a data protection authority if you’re unhappy with our response. A request for personal information is free unless the request is deemed 'manifestly unfounded or excessive'. We reserve the right to charge a reasonable fee for multiple requests.
If you need any advice you should contact the Information Commissioner’s Office (ICO).
ICO helpline Telephone: 0303 123 1113
https://www.gov.uk/data-protection/make-a-complaint
This document is stored on our website and can be found via the home page. We will update this privacy statement when necessary to reflect updates and changes in our services. When we make changes to this statement, we will revise the 'last updated' date at the top of the statement and highlight the changes in the document. If there are material changes to the statement or in how we will use your personal data, we will notify you either by prominently posting a notice of such changes before they take effect or by directly sending you a notification. We encourage you to periodically review this privacy statement to learn how we are protecting your information.
7. COMMUNICATION / ROLL OUT OF THE POLICY
Policy Owner: Project Manager
Implementation: This policy applies to all Employees of TrAC Ltd. Launch of the policy will be via a briefing to apprentice management teams which will then be cascaded through to all those responsible for carrying out a management function.
Communication: This policy will be made available to all Employees of TrAC Ltd during induction and electronically thereafter. Printed copies will be available on request.
Review of the policy: The content of this policy will be reviewed on a regular basis not exceeding one year (maximum) from the previous revision date.
Audit: An effective auditing and review process shall be implemented for monitoring the ongoing use of and compliance to this policy.