Privacy Notice

Privacy policy

EBP South Privacy Notice 

EBP South is committed to protecting your personal information and being transparent about how we collect, use and store it. This Privacy Notice explains how we process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

EBP South is the Data Controller for the personal data we process. 

Data Protection Officer (DPO): CEO
Contact: Sammy Ward 

If you have any questions about this Privacy Notice or how your data is handled, please contact the DPO.

2. What Personal Data We Collect

We may collect and process the following types of personal data depending on your relationship with us: 

a) Personal Data

  • Name 
  • Email address 
  • Telephone number 
  • Postal address 
  • Date of birth 
  • School, employer or organisation details 
  • Photographs, videos and digital media (where consent has been provided)

b) Special Category (Sensitive) Data

Where necessary and with appropriate safeguards, we may process: 

  • Health information 
  • Equality and diversity data (e.g. ethnicity, religion, disability)

c) Staff and Volunteer Data

  • Employment records 
  • Payroll and pension information 
  • Training and safeguarding records

3. How We Collect Your Data

We collect personal data when you: 

  • Complete paper or online forms 
  • Register for events, work experience or services 
  • Communicate with us by email, phone or post 
  • Visit and submit information through our website or social media 
  • Sign up to mailing lists or HubSpot communications 

4. Careers Footprints and Action Plans

Careers Practitioners contracted to work in schools will provide action plans/footprints to the contracted school and the young person. 

EBP South acts as a Data Processor for this information and will not retain the data once it has been provided to the school. The school acts as the Data Controller and is responsible for storing and processing the data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. EBP South shall not retain this data beyond the point at which it has been used for its intended and appropriate purpose.

5. Why We Use Your Data and Our Lawful Basis

We process personal data for the following purposes: 

Purpose  Lawful Basis 
Delivering careers guidance, work experience and related services  Public task / Contract 
Safeguarding children and young people  Legal obligation / Vital interests 
Managing events and employer engagement  Legitimate interests 
Staff administration and payroll  Legal obligation / Contract 
Marketing and communications  Consent 
Monitoring equality and inclusion  Legal obligation 

Where we rely on consent, you may withdraw it at any time. 

6. Who We Share Your Data With

We may share your information with trusted third parties where necessary, including: 

  • Local authorities 
  • Funding bodies 
  • Delivery partners and voluntary organisations 
  • IT and systems providers acting as Data Processors 

These include: 

  • Collsys (Work Experience Software) 
  • Microsoft SharePoint and OneDrive (supported by Aerial Direct IT) 
  • HubSpot 
  • Breathe HR 
  • Xero 
  • BrightPay 
  • Website hosting via Krystal Hosting (managed by Design Image) 
  • Auditors (Morris Crocker) 
  • Accountants (Xebra Accounting) 

All third parties are required to keep your data secure and use it only for agreed purposes.

7. Data Retention

We retain personal data in line with statutory requirements: 

  • 6 years under the Limitation Act 1980 
  • Until age 21 for children and young people (if longer than 6 years) 
  • Staff and contractor data retained in line with employment law 

When data is no longer required, it is securely destroyed.

8. Data Security

We take appropriate technical and organisational measures to protect your personal data, including: 

  • Secure office premises 
  • Access-controlled IT systems 
  • Password protection and encryption 
  • Staff training and supervision 
  • Secure disposal and shredding

9. International Transfers

We do not transfer personal data outside the UK or European Economic Area (EEA) unless appropriate safeguards are in place. 

10. Cookies and Website Analytics

Cookies are small text files that are placed on your computer, tablet or mobile device when you visit a website. They are widely used to make websites work efficiently, improve user experience, and provide information to website owners. 

When you visit www.ebpsouth.co.uk, we may collect limited information through cookies and similar technologies. This may include: 

  • IP address 
  • Browser type and version 
  • Device information 
  • Pages visited and time spent on the site 
  • Referring website addresses 

These cookies do not identify you personally unless you choose to submit personal data via a form on the website. 

We use the following categories of cookies: 

a) Strictly Necessary Cookies

These cookies are essential to enable core functionality such as website security and form submissions. The website cannot function properly without them. 

b) Analytics and Performance Cookies

These cookies help us understand how visitors interact with our website by collecting information anonymously. This allows us to improve site performance and usability. 

c) Marketing and Communications Cookies

Where applicable, cookies associated with HubSpot and Google may be used to: 

  • Track engagement with website content 
  • Support email marketing and communications (where consent has been provided) 
  • Link website activity with HubSpot CRM records where a user has voluntarily submitted their details 

Some cookies on our website are set by trusted third-party services, including: 

  • HubSpot (marketing and analytics) 
  • Website hosting via Krystal Hosting (technical performance and security) 
  • Google 

These providers act as Data Processors and are required to handle data securely and in accordance with UK GDPR. 

Lawful Basis for Using Cookies 

  • Strictly necessary cookies are used on the basis of legitimate interests 
  • Analytics and marketing cookies are used on the basis of consent 

You will be asked to provide consent for non-essential cookies when you first visit our website via a cookie banner or preference tool. 

Managing Your Cookie Preferences 

You can control or delete cookies at any time by: 

Changing your browser settings to block or delete cookies 

Please note that disabling certain cookies may affect website functionality. 

11. Your Rights Under UK GDPR

You have the right to: 

  • Be informed about how your data is used 
  • Access the personal data we hold about you 
  • Request correction of inaccurate data 
  • Request erasure (“right to be forgotten”) where applicable 
  • Restrict or object to processing 
  • Withdraw consent at any time 
  • Object to direct marketing 
  • Lodge a complaint with the Information Commissioner’s Office (ICO) 

ICO Contact:
www.ico.org.uk 

12. How to Exercise Your Rights

Requests should be made in writing where possible and sent to the Data Protection Officer.
We may ask for proof of identity before responding. 

We will respond within one month, unless an extension is permitted under UK GDPR. 

13. Marketing and Communications

You can ask us to stop contacting you for marketing purposes at any time by: 

  • Using the unsubscribe link in emails 
  • Contacting the DPO 

Your service-related communications may continue where necessary. 

14. Data Breaches

EBP South has procedures in place to manage data breaches. If a breach poses a risk to your rights and freedoms, we will inform you and the ICO where required. 

15. Changes to This Privacy Notice

This Privacy Notice is reviewed annually in conjunction with our Data Protection Policy and may be updated to reflect changes in the law or our practices. 

Last review: May 2026
Next review: May 2027 

FacebookLinkedInX (Twitter)YouTube