Security Policy
1. Scope
This policy covers the personal data we process about prospective students, their parents or guardians, and the staff of the educational institutions we work with — whether it reaches us through our website, through an advertising platform, or through correspondence. It applies to all of our personnel and to any contractor acting on our behalf.
2. Governance
- Responsibility for data protection and information security rests with our management, and a named point of contact is reachable atceo@passion-education.com.
- Everyone with access to personal data is bound by confidentiality and is briefed on this policy before access is granted.
- Providers acting on our behalf are engaged under written data processing terms that oblige them to equivalent measures, and are assessed before personal data is entrusted to them.
3. Protecting the data
- Personal data is encrypted in transit and at rest using current industry standards.
- Our public pages, forms and interfaces are served over HTTPS only; unencrypted connections are redirected rather than served.
- Contact details transmitted to advertising platforms for measurement are hashed beforehand. We never transmit a raw email address or telephone number to an advertising platform.
- Credentials for third-party services are held in a secured credential store, are never embedded in the website delivered to your browser, and are rotated when a person’s access ends or a credential may have been exposed.
- Our events are free of charge: we do not collect, transmit or store payment card or bank details.
4. Access control
- Access is granted on the principle of least privilege and only where a role requires it.
- Access is by individual named account; accounts are not shared.
- Strong authentication is required, with multi-factor authentication wherever the system supports it.
- Administrative operations on our records are performed by authorised personnel, never by an unauthenticated interface.
- Access rights are reviewed when a role changes and withdrawn on the day a person leaves.
5. Data minimisation
We ask only for the information an educational institution needs in order to advise a candidate. We do not request identity document scans, financial account details or health data, and we ask that they not be sent to us. We do not use data obtained from a platform for any purpose other than those set out in our Privacy Policy, and we do not sell it.
6. Retention and deletion
Personal data is kept only for the periods stated in ourPrivacy Policy and is then deleted or anonymised. Anyone may request deletion at any time; the procedure and the deadline we hold ourselves to are set out on theData Deletion page. Backup copies are cycled out in the ordinary course and are never used to reinstate a record that has been deleted on request.
7. Resilience and change control
- Data is backed up regularly, and restoration is tested.
- Changes to our systems are reviewed and tested before release.
- Security updates are applied on a regular schedule, and sooner where the severity warrants it.
- Access and application logs are retained so that an incident can be reconstructed, and never contain credentials.
8. Incident response
We maintain a documented procedure for security incidents: contain, assess the scope, remediate, and record. Where a personal data breach is likely to result in a risk to the people concerned, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform those affected without undue delay where the risk to them is high. Where platform data is involved we notify the platform concerned as its terms require.
Report a suspected vulnerability or incident toceo@passion-education.com. We acknowledge within two business days. We will not pursue anyone who reports a vulnerability in good faith and who does not access, alter or retain other people’s data.
9. Personnel and devices
Personal data is worked on only within our authorised systems, on devices with disk encryption, a screen lock and current security updates. It is not copied to personal accounts, personal devices or unauthorised applications.
10. Review
This policy is reviewed at least annually and whenever our processing changes materially. Questions go toceo@passion-education.com.
← passion-education.com · Privacy Policy · Terms of Service · Data Deletion · Legal Information