brisk-paige
  • Home
  • Programmes
  • Our Story
  • Get Started

GDPR Compliance

Last Updated: May 14, 2026

Our Commitment to Data Protection

brisk-paige is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page outlines how we comply with these regulations and your rights under them.

Legal Basis for Processing

We process personal data under the following legal bases:

  • Consent: When you provide explicit consent for specific processing activities
  • Contract: When processing is necessary to fulfill our contractual obligations to provide educational services
  • Legitimate Interests: When we have legitimate business interests that do not override your rights
  • Legal Obligation: When required to comply with legal requirements

Your Rights Under GDPR

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will provide this information within one month of your request.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to our processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time.

Data Protection Measures

We implement appropriate technical and organizational measures to ensure data security:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Staff training on data protection practices
  • Incident response and breach notification procedures
  • Data minimization and storage limitation principles

Data Processing Activities

We process personal data for the following purposes:

  • Administering educational programmes and services
  • Processing enrolments and managing payments
  • Communicating with participants and their families
  • Improving our services and website functionality
  • Complying with legal and regulatory requirements
  • Protecting against fraud and ensuring security

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Participant records: 6 years after programme completion
  • Financial records: 7 years as required by law
  • Marketing consents: Until consent is withdrawn
  • Website analytics: 26 months

International Data Transfers

We primarily store and process data within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

Children's Data

Given the nature of our services, we process data about children and teenagers. We:

  • Obtain parental consent before processing children's data
  • Only collect data necessary for providing educational services
  • Apply enhanced security measures for children's data
  • Provide clear information to parents about data processing

Data Breach Notification

In the event of a data breach that poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and affected individuals without undue delay.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: [email protected]
Subject Line: GDPR Request

We will respond to your request within one month. In complex cases, this may be extended by a further two months, and we will inform you of any extension.

Complaints

If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113

Updates to This Policy

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of any material changes through our website or by email.

Contact Information

For any questions about our GDPR compliance or data protection practices:

Email: [email protected]
Address: Liverpool, United Kingdom

Quick Links

  • Home
  • About Us
  • Programmes
  • Contact

Legal

  • Privacy Policy
  • GDPR Compliance
  • Cookies Policy
  • Terms of Use

Contact

  • Liverpool, United Kingdom
  • [email protected]

© 2026 brisk-paige. All rights reserved.

We use cookies to improve your experience on our site. By continuing to browse, you agree to our use of cookies. Learn more