GDPR Compliance
Last updated: May 14, 2026
Our Commitment to GDPR
FinanceFirst Manchester complies fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are committed to protecting personal data and respecting the rights of individuals whose information we process.
Data Controller Information
FinanceFirst Manchester is the data controller responsible for personal data collected through our services and website.
Organisation: FinanceFirst Manchester
Address: Unit 14, Northern Quarter Business Centre, 47 Lever Street, Manchester M1 1FN, United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contractual Necessity: To deliver the educational programmes you've enrolled in
- Legitimate Interest: To improve our services and communicate relevant programme information
- Consent: For optional communications and website analytics where explicit permission is obtained
- Legal Obligation: To comply with safeguarding requirements and legal record-keeping duties
Your GDPR Rights
Under GDPR, you have comprehensive rights regarding your personal data:
Right to Access
You can request a copy of all personal data we hold about you and your child. We will provide this information within one month of your request in a clear, accessible format.
Right to Rectification
If personal information is inaccurate or incomplete, you can request corrections. We will update records promptly and notify any third parties where necessary.
Right to Erasure
You can request deletion of personal data in certain circumstances. Note that we may be required to retain some information for legal or safeguarding purposes even after programme completion.
Right to Restrict Processing
You can request that we limit how we use your data while disputes are resolved or accuracy is verified.
Right to Data Portability
You can obtain your personal data in a structured, commonly used format and transfer it to another service provider where technically feasible.
Right to Object
You can object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling in our services. All enrolment and programme decisions involve human review.
How to Exercise Your Rights
To exercise any GDPR rights, contact us via:
- Email: [email protected]
- Post: Data Protection, FinanceFirst Manchester, Unit 14, Northern Quarter Business Centre, 47 Lever Street, Manchester M1 1FN
We will respond within one month. If your request is complex, we may extend this by two months and will inform you of the delay and reasons.
Data Sharing and Transfers
We do not transfer personal data outside the United Kingdom. Data is stored on secure UK-based servers with reputable providers who maintain GDPR compliance.
Personal data is never sold or shared with third parties for marketing purposes. Limited information may be shared only when:
- Required by law or legal process
- Necessary for safeguarding purposes with appropriate authorities
- With your explicit consent for specific purposes
Data Retention
We retain personal data only as long as necessary for the purposes collected:
- Enrolment and attendance records: 3 years after programme completion
- Financial records: 6 years to comply with accounting requirements
- Safeguarding-related information: As required by relevant legislation and guidance
- Marketing consent: Until consent is withdrawn or 2 years of inactivity
Data Security Measures
We implement appropriate technical and organisational measures to protect personal data:
- Encryption of data in transit and at rest
- Access controls limiting data access to authorised personnel only
- Regular security audits and vulnerability assessments
- Staff training on data protection and security practices
- Incident response procedures for potential data breaches
Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you and the Information Commissioner's Office (ICO) within 72 hours where required by law. Notification will include the nature of the breach, likely consequences, and measures taken to address it.
Children's Data
We recognise that children's data requires special protection. Enrolment requires parental or guardian consent for participants under 18. We only collect information essential for programme delivery and safeguarding. Children's data is subject to the same security measures and GDPR rights as adult data.
Complaints
If you believe we have not handled your personal data appropriately or have concerns about our GDPR compliance, please contact us first so we can address the issue.
You also have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
Updates to GDPR Practices
We review our GDPR compliance regularly and update our practices as regulations evolve. Significant changes will be communicated via email to enrolled families and posted on this page.