top of page

Privacy Policy

Bearing Safety & Security Limited

Last updated: 30 July 2026 · v1.0

Review date: 30 July 2027

1. Who we are

Bearing Safety & Security Limited ("Bearing", "we", "us") is the data controller for the personal information described in this policy.

We are registered with the Information Commissioner's Office as a data controller.

We trade as "Bearing". Our programme is UK Ready.

 

Our Data Protection Lead is Tom Frearson. Data protection questions, requests and complaints go to contact@bearinguk.com, marked for his attention.

2. What this policy covers

This policy explains what personal information we collect, why we hold it, how long we keep it, who we share it with, and what rights you have.

It applies to:

  • Parents and other purchasers who book a place on UK Ready

  • Students who attend the programme, including students under 18

  • Staff and contacts at universities, colleges and education agents

  • People who contact us, subscribe to updates, or visit bearinguk.com

Cookies and similar technologies are covered in our separate Cookie Policy.

We handle personal information under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

3. The information we collect

3.1 Enquiry and booking information

Name, email address, telephone number, country of residence, relationship to the student, billing address, and payment confirmation details. We do not see or store full card numbers. Payments are processed by Stripe.

3.2 Student information

Full name, date of birth, nationality, first language, institution and course, arrival date in the UK, UK and home address, email address, telephone number, and the name and contact details of a parent, guardian or emergency contact.

3.3 Health information

Medical conditions, allergies, medication, injuries, disabilities, accessibility requirements, and dietary needs. We collect this before the practical day because the programme includes physical content and hands-on emergency first aid, and because we need to respond correctly if a student becomes unwell.

Health information is special category data. We handle it under the additional conditions set out in section 5.

3.4 Learning and completion records

Module progress, knowledge check results, attendance, the personal safety plan a student submits, facilitator notes on completion, certificate records, and the completion report issued to the purchasing parent.

3.5 Safeguarding records

Concerns raised, disclosures made, actions taken, and referrals made. These records may include health information and information relating to alleged criminal offences. They are held separately from general programme records, with restricted access.

3.6 Images

Photographs and video from delivery days, where consent has been given. Consent is optional, is never a condition of attending, and can be withdrawn.

3.7 Feedback and evaluation

Pre- and post-programme knowledge and confidence responses, and general feedback. Where results are shared with a partner institution, they are aggregated and anonymised.

3.8 Institutional and agent contacts

Name, job title, employer, work email address, work telephone number, and correspondence.

3.9 Website and technical information

IP address, device and browser type, pages visited, and referral source. See our Cookie Policy.

4. Where we get it from

Most information comes directly from the parent or purchaser at booking, and from the student when they complete Phase 1.

​We also receive information from:

  • Partner universities, colleges and education agents, where they arrange a cohort

  • The student's parent, guardian or emergency contact

  • Our facilitators, in the course of delivery

  • Our website and course platform, automatically

5. Why we use it, and our lawful basis

What we use it for

Lawful basis                  

Taking a booking, taking payment, and delivering the programme                                                                                                                                                                  

Enrolling a student on the online platform and tracking progress

Keeping students safe on the practical day, including first aid response

Safeguarding children and adults at risk, including recording and referring concerns                                                                                                                          

Issuing certificates and completion reports

Working with a partner institution or agent on a cohort                                             

Evaluating and improving the programme              

Marketing to institutions and agents

Sending updates to parents and enquirers

Photography and video

Accounting, tax and insurance records

Website security and fraud prevention                                           

Contract with the purchaser. Legitimate interests, where the student is not the purchaser — so that the programme booked for them can be delivered

Contract. Legitimate interests                                                        

Legal obligation (health and safety). Vital interests, in a medical emergency

Legal obligation. Substantial public interest — safeguarding of children and of individuals at risk (Data Protection Act 2018, Schedule 1, Part 2)

Contract. Legitimate interests                             

Legitimate interests — running the programme we have been asked to deliver

Legitimate interests. Anonymised wherever possible

Legitimate interests                                            

Consent                                                          

Consent                            

Legal obligation. Legitimate interests

Legitimate interests. Recognised legitimate interests, where relevant

Health information. We rely on explicit consent, given at booking, to hold and use health information for programme delivery. Where a student cannot give or confirm consent and there is a risk to life or health, we rely on vital interests. Where health information forms part of a safeguarding record, we rely on the safeguarding condition above.

Legitimate interests. Where we rely on legitimate interests, we have assessed the impact on the individual and are satisfied our interests do not override their rights. You can ask us for a summary of that assessment.

6. Children and young people

Most UK Ready students are adults. A minority arrive at 16 or 17. Where a student is under 18, we treat their information with a higher standard of protection.

  • A place is booked and paid for by a parent, guardian or institution — not by the student

  • We ask for written parental or guardian consent before a student under 18 attends, covering health information, emergency treatment, and the practical content of the day

  • We collect the minimum information needed to deliver the programme safely

  • We do not send marketing to anyone under 18

  • We do not use children's information for profiling or advertising

  • Completion reports for a student under 18 are issued to the purchasing parent or guardian

  • Where a safeguarding concern arises, we may need to share information without consent. Safeguarding comes first. See section 7 and our Safeguarding Policy

We design our services in line with the ICO's Age Appropriate Design Code and the children's higher protection duties under the Data (Use and Access) Act 2025.

A student aged 16 or 17 has their own rights over their information under section 11. Where a request is made by a parent, we will consider the student's own wishes and best interests.

7. Who we share it with

We do not sell personal information. We share it only where it is necessary.

 

Service providers acting on our instructions:

  • Wix — website hosting and enquiry forms

  • Inform — online course platform, module delivery and progress records

  • Stripe — payment processing

  • Google Workspace — email, documents and file storage

  • A customer relationship and email marketing provider, used to manage enquiries and mailing lists

Each is bound by a written contract requiring them to protect the information and to use it only as we instruct. We update this policy when we change provider.

Others we may share with:

  • Our facilitators — the operational information needed to deliver a cohort safely, including relevant health information

  • Partner institutions and education agents — attendance and completion confirmation for students they have placed on a cohort, and anonymised, aggregated evaluation results

  • Emergency services and the NHS — where there is a medical emergency

  • Safeguarding partners — local authority children's services, the Local Authority Designated Officer, the police, and the safeguarding lead at a partner institution, where a concern requires it

  • Insurers, auditors and professional advisers — where required

  • Accreditation bodies — anonymised records only, for quality assurance

We will also disclose information where we are required to by law.

8. Transfers outside the UK

Some of our providers store or process information outside the UK, including in the United States and Israel.

Where information goes to a country covered by UK adequacy regulations, the transfer is made on that basis. Where it does not, we rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

Student and parent information is not transferred outside the UK for any purpose other than the operation of the services listed in section 7.

9. How long we keep it

Record                 

Retention period

Enquiries that do not lead to a booking

Booking, contract and programme delivery records                                  

Health information collected for a cohort                                                                                              

Accident, incident and first aid records                                                                                          

Learning records, certificates and completion reports

Safeguarding records                                                                                                                     

Records relating to an allegation of abuse                                                                                                           

Financial and tax records                                             

Images used with consent                                           

Marketing contacts                                                                         

Website analytics

12 months                                                                  

6 years from the end of the financial year in which the cohort ran

Deleted 3 months after the practical day, unless it forms part of an incident or safeguarding record

3 years from the date of the record; for a student under 18, 3 years from their 18th birthday

6 years                                                                       

Until the individual's 25th birthday, or 6 years from the date of the record, whichever is later

75 years from the date of the record, in line with national retention guidance for records of this type

6 years from the end of the relevant accounting period

Until consent is withdrawn, and no more than 3 years

Until consent is withdrawn, or 24 months without engagement

Up to 26 months

When a retention period ends, we delete the information securely or anonymise it so it can no longer identify anyone.

10. How we protect it

  • Access is restricted to those who need it to do their job

  • Accounts are protected by multi-factor authentication

  • Devices are encrypted and password protected

  • Safeguarding records are held separately, with access limited to the Designated Safeguarding Lead and any appointed deputy

  • Paper records taken on a delivery day are transferred to secure storage and destroyed once no longer needed

  • Facilitators are trained on confidentiality and data handling at induction

  • We keep a record of personal data breaches and report qualifying breaches to the ICO within 72 hours

11. Your rights

You have the right to:

  • Be told how we use your information

  • Get a copy of the information we hold about you

  • Have inaccurate information corrected

  • Have information erased, in certain circumstances

  • Restrict how we use your information, in certain circumstances

  • Object to processing based on legitimate interests

  • Receive information you gave us in a portable format, in certain circumstances

  • Withdraw consent at any time, where we rely on consent

To exercise any of these, email contact@bearinguk.com. We will respond within one month. If a request is complex, we may extend that by up to two further months, and we will tell you if we do.

There are limits. We cannot delete records we are required to keep by law, and we may not be able to delete a safeguarding record on request.

Automated decisions. We do not make decisions about you by automated means, and we do not use your information for profiling.

12. How to complain

If you think we have handled your information incorrectly, tell us first. Email contact@bearinguk.com with "Data protection complaint" in the subject line, or write to us at the registered office above.

We will acknowledge your complaint within 30 days, investigate it without undue delay, and tell you the outcome.

You also have the right to complain directly to the Information Commissioner's Office at any time:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

0303 123 1113 · ico.org.uk

13. Changes to this policy

We review this policy at least annually, and whenever our services or the law change. The date at the top shows when it was last updated. Where a change is significant, we will tell affected individuals directly.

Bearing Safety & Security Limited · Company number 17354268 · 124 City Road, London EC1V 2NX

Privacy Policy · Know your bearing

bottom of page