Privacy Policy

1. Policy Statement

York Forks Ltd is committed to protecting the privacy and security of all personal data it collects, processes, and stores in the course of business operations.
We comply fully with the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 to ensure that all personal data is handled lawfully, fairly, and transparently.

This policy sets out how York Forks Ltd manages personal data for employees, learners, clients, and suppliers to ensure compliance with data protection legislation and to promote a culture of privacy and accountability.



2. Purpose

The purpose of this policy is to:

Define York Forks Ltd commitment to protecting personal data.

Ensure compliance with all relevant data protection laws and regulations.

Inform individuals how their personal data is collected, used, stored, and shared.

Set out responsibilities for managing data securely and lawfully.



3. Scope

This policy applies to:

All employees, trainers, contractors, and representatives of York Forks Ltd.

All personal data processed by the company, whether in digital or paper format.

All learners, clients, and suppliers whose personal information may be held by York Forks Ltd.



4. Data Protection Principles

York Forks Ltd adheres to the following six principles of data protection under the UK GDPR. Personal data must be:

1. Processed lawfully, fairly, and transparently.


2. Collected for specified, explicit, and legitimate purposes and not used for other purposes.


3. Adequate, relevant, and limited to what is necessary.


4. Accurate and kept up to date where necessary.


5. Stored no longer than necessary for the purpose it was collected.


6. Processed securely to prevent unauthorised access, loss, or damage.


5. Lawful Basis for Processing

York Forks Ltd will process personal data under one or more of the following lawful bases:

Contract: when data processing is necessary to deliver training or provide a service.

Legal obligation: to comply with employment or health and safety legislation.

Legitimate interests: for operational purposes, such as maintaining training records.

Consent: when individuals have given explicit permission for a specific purpose (e.g. marketing or image use).



6. Types of Personal Data Collected

York Forks Ltd may collect and process the following personal information:

Learners: name, contact details, date of birth, national insurance number, training records, and certification results.

Employees and contractors: employment details, payroll information, emergency contacts, qualifications, and performance records.

Clients and suppliers: business contact details, correspondence, and invoicing information.


Sensitive data (such as health information or disability details) will only be processed where necessary and with the individual’s explicit consent.



7. Data Storage and Security

Personal data is stored securely in password-protected digital systems and locked filing cabinets.

Access to data is limited to authorised personnel who require it for legitimate business purposes.

All staff are trained in data protection awareness and must handle data responsibly.

Electronic data is backed up regularly and protected by secure networks and antivirus software.

Paper records are disposed of securely using shredding or confidential waste disposal.



8. Data Retention

York Forks Ltd retains personal data only for as long as necessary to fulfil its intended purpose and to comply with legal and accreditation requirements.
Typical retention periods include:

Training records and certificates: up to 6 years.

Employee records: 6 years after leaving employment.

Financial and invoicing data: 6 years (in line with HMRC requirements).


After this period, data is securely deleted or destroyed.



9. Data Sharing

Personal data may be shared with:

Accrediting bodies or regulatory authorities (e.g. RTITB, ITSSAR) for certification purposes.

Service providers or partners where necessary to deliver training.

Legal or government bodies when required by law.


York Forks Ltd will never sell personal data to third parties.



10. Individual Rights

Under the UK GDPR, individuals have the following rights regarding their personal data:

The right to access their data.

The right to rectification of inaccurate information.

The right to erasure (“right to be forgotten”).

The right to restrict or object to processing.

The right to data portability.


All requests should be made in writing to the Data Protection Officer at York Forks Ltd. The company will respond within 30 days.



11. Data Breaches

In the event of a data breach, York Forks Ltd will:

Take immediate steps to contain and investigate the breach.

Notify the Information Commissioner’s Office (ICO) within 72 hours if the breach poses a risk to individuals’ rights or freedoms.

Inform affected individuals if there is a high risk of harm.

Record all breaches, regardless of severity, in a Data Breach Log.




12. Responsibilities

Management:

Ensure compliance with this policy and data protection legislation.

Provide staff training and allocate resources for secure data handling.


Employees and Trainers:

Handle personal data responsibly and in accordance with this policy.

Report any data breaches or security concerns immediately.


Data Protection Officer (DPO):
Andrew Davis – Operations Director
Email: andrew@yorkforks.co.uk
Responsible for overseeing data protection compliance and responding to data subject requests.


13. Review and updates

This policy will be reviewed annually or sooner if required by changes in legislation or business operations.
Any updates will be communicated to all employees and published in the company’s policy manual.

Policy Review Date: ……07/09/2025

Approved By: Carley Davis – Managing Director

Next Review Due: ………06/09/2026