Legs raised and keep warm

Medi-K Privacy Policy

Book a course trending_flat

Medi-K Privacy Policy

Introduction

Medi-K Performance Ltd, (“Medi-K”) has created this document to demonstrate its commitment to data privacy and its alignment to the requirements of the Data Protection Act 1998 and, in substitution from 25 May 2018, the General Data Protection Regulation 2018 (“GDPR”) in respect of handling and processing personal data.

Data received from freelance trainers

We will collect and process data that is provided to us by trainers. Personal data may be included in the data you provide about learners, tutors, assessors and contacts. It is important that contractual arrangements with those individuals clearly set out how you will use their data and with whom it could potentially be shared. We require all our trainers to comply with the GDPR. By adding individuals’ personal data to Medi-K systems, or by sending personal data via email or by other methods to Medi-K, you give consent to us processing the data and you confirm that you have obtained the appropriate consent from the relevant individuals for the personal data to be processed by Medi-K.

Medi-K will retain and use this data to perform the contract between us whilst you remain a Medi-K trainer and further will use it where it is in Medi-K’s legitimate interest, for example fraud prevention.

We collect trainer contact personal data as a Data Controller and uses it for the purpose of trainer applications, Once the application has been successful this data will be held securely on our systems for the duration of the freelance contract. We will review incomplete trainer applications annually and delete those over 12 months old.

Learners' Data

You may provide us with personal data about learners when you add learner details to courses, work-based learning awards or exams. The personal data is usually limited to the details required for us to undertake the basic functions of a training company and the certification process. These details will include a learner’s name, date of birth, gender, email and qualification awarded. In line with our regulatory requirements and requirements to deliver future services such as certificate re-prints and the confirmation of awards, this basic learner-level data will be held by Medi-K indefinitely.

Information processed as part of a learner’s qualification, such as physical exam papers, will be held for a maximum of 6 months. Learners may also contact Medi-K to request certificate replacements. In these circumstances, a record of a learner’s address is taken so that the certificate can be sent. This is held on file for a maximum of 6 months before it is destroyed or deleted.

Tutors, assessors and internal quality assurance (IQA) staff

Tutors, assessors and quality assurance staff provide Medi-K with information about their experience and qualifications that confirm their ability to teach Medi-K courses. As such, Medi-K may hold a substantial set of personal details about a tutor, assessor and other staff. These may include:

This data is required for regulatory purposes to ensure that we meet the necessary conditions of the Awarding Body. We collect this information in the capacity of a Data Controller.

End-Point Assessment

Medi-K will process personal data for the performance of End point Assessment. It collects this personal data in the capacity of a Data Controller. Trainers will provide Medi-K with data for the processing of assessments for learners; it is the responsibility of the trainer to ensure that learners are aware and have consented to their data being share with Medi-K. Medi-K may share this data with Awarding Organisations and Regulators. We have carried out a comprehensive review of their activities in relation to GDPR via questionnaires and agreements are in place which will be reviewed annually.

Data sharing

Other than as set out in the next paragraph and even where we collect personal data in the capacity of a Data Controller, we will never distribute or share personal data that is held on our system with any third parties other than Medi-K’s employees, consultants and sub-contractors.

We may share personal data with regulatory bodies in respect of:

Medi-K has a course finder function that is available to the public and allows users to search for publicly available courses. The address of this website is http://www.medi-k.co.uk/course-calendar/. The contact details of the course host contact will be displayed on the website if the host provides this information.

We are also required to provide data to RM Results for DfE under the legal basis contained within Section 537A of the Education Act 1996 and Regulation 6 (d) of the Education (Individual Pupil Information) (Prescribed Persons) (England) Registrations 2009, and section 47 of the Statistics and Registration Service Act 2007 and the Statistics and Registration Service Act 2007 (Disclosure of Pupil Information) (England) Regulations 2009. The DfE and RM Results ensure that the Data is processed in line with the replacement Data Protection Act 2018 and GDPR.

Marketing

Medi-K maintains a marketing database that contains the basic details of individuals who have consented to Medi-K sending information about products, qualifications, events or services, as well as general news about the Medi-K companies, to them, via email. Each marketing email that is sent provides you with the ability to unsubscribe from receiving marketing emails at any time. Alternatively, you can opt-out by sending a request specifying your new choice to kay@medi-k.co.uk .

We will at times contact you by email with important updates that you must be made aware of as a previous attendee on a Medi-K course. These updates are mandatory and for regulatory reasons you are unable to unsubscribe from these. We will also on occasion send you communications which we believe will be of legitimate interest to you regarding new products and qualifications, which you will be able to unsubscribe to should you wish.

External Consultants, EQS, SMEs, End-Point Assessors, Exam Markers, Suppliers

Medi-K engage the services of external freelance trainers and suppliers for various purposes within the company.

It is necessary to obtain and retain personal data for the fulfilment of contracts. We collect this personal data in the capacity of a Data Controller. Data including but not limited to: names, addresses, contact details, professional qualifications, identification documents, bank details – will be held on Medi-K Systems and Finance Software.

Contracts are reviewed annually, and inactive partnerships deleted from systems. It is necessary to share bank details with our bankers to make payments for services, Medi-K will always make sure that the details are only processed using secure banking systems. Medi-K will never share this information elsewhere, outside of the company unless required to do so by a regulatory or legal authority.

Website use – tracking and monitoring

Users of Medi-K website should refer to the privacy section of Medi-K terms and conditions, which are located at the following address: http://www.medi-k.co.uk/terms-of-use This provides details on how information that is collected on the website is managed by Medi-K. Our websites and online systems use cookies to distinguish you from other users of our website. For detailed information on the cookies we use please refer to the terms and conditions on the website. We may automatically collect the following information when you visit our website:

Employees

Medi-K will only process and hold staff data for the legitimate purpose of employment. Personal data including name, address, contact details, NI number, date of birth, bank details, employment history, medical history, next of kin contact details is stored and processed on the Medi-K HR drive and Sage payroll system and will be held for the duration of the employment. On leaving the company all data will be removed from systems and personnel files and be archived for a period of 3 years before being securely destroyed. PAYE information will be held on Sage 50 payroll for 6 years after as required by HMRC.

CV’s and interview notes will be held for 6 months after the recruitment of a role before being securely destroyed or deleted. Data for successful candidates will be stored with employment data.

Prospective CV’s will be considered on receipt, shared with internal departments and destroyed should no suitable vacancies be available. Medi-K does not store prospective CV’s. References will be requested from former employers as part of employment terms. Factual references for former staff will only be provided on request from future employers, Medi-K will only state dates of employment and final role. On receipt of financial reference requests, HR staff will seek consent before providing information.

Personal data will be shared with relevant agencies for the appropriate performance of pensions schemes, tax affairs, benefit schemes, insurances, fleet management, illness cover. Staff participation in such services will indicate consent to share required data for the performance of the service.

Security

Medi-K’s online systems have security measures in place to help protect against the loss or misuse of any data under our control.

When the websites are accessed by users, data traffic is encrypted using up to date secure socket layer (SSL) technology so that it can only be accessed by the end user. All sensitive information on the website, such as passwords, are encrypted by a proprietary encryption system. All personal data can only be accessed by the relevant end users by way of unique user names and passwords that must be entered when a user logs in to the systems. Medi-K are PCI DSS (Payment Card Information Data Security Standard) compliant. Credit card information is never stored on Medi-K’s systems and is only used to authorise the specific transaction through Medi-K’s card payment authority (paypal) and then removed. Where credit card data is held (for speed of future payments), this is only held by Paypal. Under no circumstances will your credit card information be passed to any third party.

Where we store data

All data in Medi-K’s systems is stored on a secure set of servers hosted by our hosting provider. The servers reside in the United Kingdom. Data is frequently backed up and stored in the provider’s backup / disaster recovery facility, which is also in the UK. This is in a secure server hosting facility with the necessary environmental, physical and technical controls in place to ensure unapproved access is prevented. Medi-K's email data is stored with Microsoft located in EU data-centres and follows Microsoft standard security and backup processes.

Destruction of physical data

In line with our regulatory requirements, Medi-K has a set of processes for issue and incident management, including data breaches. These processes include the required notifications to be sent to the Information Commissioners Office and to customers. This is reviewed annually and may be subject to change.

Data breach incidents

In line with our regulatory requirements, Medi-K has a set of processes for issue and incident management, including data breaches. These processes include the required notifications to be sent to the Information Commissioners Office and to customers. This is reviewed annually and may be subject to change.

The General Data Protection Regulation 2018

Medi-K has adapted its policies and procedures to ensure it is compliant with the GDPR. This document has been produced to represent our current status and will be reviewed annually and updated as processes are developed.

Under GDPR, individuals have certain rights when it comes to the control of personal data:

The right to be informed. Each individual has the right to be given information about how their data is being processed and why. Medi-K have provided this policy to show how we handle your data.

The right of access. Medi-K have a duty to comply with the requirements of Subject Access Requests (SAR)

The right to rectification. The GDPR includes a right for individuals to have inaccurate personal data rectified or completed if it is incomplete.

The right to be forgotten. You have the right to ask Medi-K to remove your data.

The right to restrict processing. You may restrict processing for a legitimate reason, we would still have the right to hold that information.

The right to data portability. You may be able to obtain the information we hold about you and use it for your own purposes. Conditions apply.

Should you wish to exercise any of your rights above, please email kay@medi-k.co.uk stating the following information:

Name
Contact details
Relationship to Subject
Full details of information relating to your request
Reason for request and the right being exercised.

You will be asked to verify your identity if you are the subject alternatively you will be asked to provide consent from the subject if you are a representative. Should we require further information we will contact you. Your request will be dealt within one month of receipt of your request. Under the GDPR you have further rights in relation to automated decision making and profiling. Medi-K currently only use automated profiling for the purpose of Functional Skills and e Learning requirements, the purpose of this profiling is to determine appropriate skills levels. Should any further automated processes be implemented, the policy will be reviewed and updated.

Cookies

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website. It also allows us to improve our website.

A 'Cookie' is a small piece of information that we store on your computer. Our system will issue cookies to your computer when you access the site. We use the following cookies

  1. Strictly necessary cookies; These are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website.
  2. Analytical/performance cookies; These allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
  3. Functional Cookies; These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

Name Purpose
ASP.NET_SessionId Stores server-side, user-specific data relating to a current browsing session.
_utma These are first party cookies for Google analytics and track how many times a visitor has been to the site.
_utmb / _utmc b - c are a pair and work together to calculate how long a visit takes - b takes a time stamp of when a user enters a site - c takes a time stamp of when the user leaves - b expires at the end of the session - c waits 30mins and then expires.
_utmb / _utmc Keeps track of where the visitor came from - what search engine used - what link the user clicked - what key word the user used and where they are in the world.
Additional Cookies – used when registered trainers log to the websites
UserID Stores a unique identifier to allow the site to remember a user's identity.
CartId Stores a unique identifier to allow the site to remember purchase details.
RoleID Stores a unique identifier of the current logged in user's role to ensure that the correct information is presented to them.
TrainerID Stores a unique identifier to allow the site to remember a trainer's identity.
TrainerNumber Stores the trainer's registration number to allow the site to remember a trainer's identity.
TutorNumber Stores the tutor's registration number to allow the site to remember a tutor's identity.
InternalVerifierNumber Stores the Internal Verifier registration number to allow the site to remember an Internal Verifier's identity.
TutorID Stores the unique identifier to allow the site to remember a trainer's identity.
RoleOption Stores the designated role of the current logged in user to ensure that the correct information is presented to them.
LastProductsViewed Stores details of the last products viewed by the user to allow relevant information to be presented.
   

This website uses tracking software to monitor its visitors to better understand how they use it. This software is provided by Google Analytics which uses cookies to track visitor usage. The software will save a cookie to your computer’s hard drive in order to track and monitor your engagement and usage of the website, but will not store, save or collect personal information.

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including “strictly necessary” cookies) you may not be able to access all or parts of our website.

You can remove cookies from your computer at any time by going into the settings in your browser and deleting the browsing history and cookies stored. The exact location of this setting will depend on your browser of choice.