Freeframe Governance

Work with me

Privacy Policy and Subject Access Request FREEFRAME May 2026

Last Updated: March 2026

Author Angela Jackson@freeframe.co.uk Data Controller on behalf of Freeframe


At Freeframe we respect your privacy and take care of your personal information. This policy explains what data we collect, why we collect it, how we use it, and the choices you have.

We follow the rules set by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 to keep your information safe.

Who Controls Your Data

Freeframe Limited (referred to as “Freeframe,” “we,” “us,” or “our” in this privacy policy) is a community Interest company with registration number :

Freeframe is the Controller of the personal data covered by this privacy policy. This means we are responsible for making sure your personal data is collected, stored, and used safely and lawfully.


1. The Information We Collect

We may collect:

  • Personal details: your name, date of birth,  and contact details including your address, telephone number and email.
  • Payment details: if you pay for our services.
  • Technical details: your IP address, device type, and how you use our website or app.

2. How We Use Your Information

We use your information to:

  • Contract: Data is processed to register attendees, manage assessments as required, and issue certificates.
  • Legitimate Interests: Used for course updates, attendance tracking, and internal marketing.
  • Legal Obligation: Shared with regulators or agencies when required.
  • Consent: Explicit consent is obtained for internal marketing and sensitive data (e.g., dietary needs).
  • Carry out research (using information that doesn’t identify you).

3. Who We Share Your Information With

We do not sell your personal data. We may share it only when:

  • You give permission – for example, if you want us to share results with a third party.
  • The law requires it – for example, if a court or regulator asks us.
  • It’s de-identified – where personal details are removed so the data cannot identify you.

4. Our responsibilities to you

  • Data Minimisation:  We only collect essential training information.
  • Security: We protect data using proper safeguards like encryption.
  • Storage Limitation: We keep data only as long as necessary for verification or legal reasons.
  • Transparency: We clearly explain privacy practices, data collection, and sharing.

5. Keeping Your Data Safe

We use security measures to protect your data, including secure systems and restricted access. While no system is 100% secure, we take steps to reduce risks of loss, misuse, or unauthorised access.


5. Personal Data We Use and How Long We Keep It

Personal data means information that can identify you, like your name, address, date of birth, or payment details.

We only keep your data for as long as we need it.

We may also keep information in a way that does not identify you. This “de-identified” data helps us improve our services and support health research.

  • Why we use your data (legal basis):
    • To carry out a task in the public interest (UK GDPR Article 6(1)(e)
  • Data we collect:
    • Your contact details (such as name, phone number, or email)
  • How long we keep your data:
    • or for audit and service improvement purposes.
  • Tax legislation requires we to maintain financial records including invoices for at least six years.
  • Why we use your data (legal basis):
    • To respond to your enquiry and manage our services, which is part of our legitimate interests (UK GDPR Article 6(1)(f)).
    • We keep this information for 2 years in case you return to us for care, Communicating About Concerns, Queries, or Complaints

If you contact us with a concern, query, or complaint, we may process your information to respond and manage the issue.

  • Data we collect:
    • Your name and contact details
    • Any relevant information you provide.
  • How long we keep your data:
    • We keep this information for 10 years to ensure proper follow-up and accountability
  • Why we use your data (legal basis):
    • To respond to your concern or query, and manage our services (legitimate interests, UK GDPR Article 6(1)(f))
    • To ensure the quality and safety of healthcare services we provide (special category data – Article 9(2)(i))

Quality Assurance, Improvement, Training & Security

We use some of your information to make sure our services are safe, high-quality, and continuously improving. This includes:

Conducting Research

We may use some of your information if you register and participate in research studies. This includes:

  • Your name, contact details, and study ID

We remove any information that could identify you, such as your name, address, or contact details, before using it for research.

Who it applies to: Individuals who register and participate in research

How long we keep your data: Up to 10 years, depending on the type of research

Why we use your data (legal basis):

  • To provide or plan healthcare services (legitimate interests, UK GDPR Article 6(1)(f))
  • For public interest, scientific, or statistical purposes (special category data, UK GDPR Article 9(2)(j))

Our Legitimate Interests

We rely on UK GDPR Article 6(1)(f) – legitimate interests to process your personal data. This means we use your information when it is necessary for our services and does not override your rights. Our main legitimate interests are:

  1. Providing Education or advice to you safely and effectively
  2. Handling complaints and communications appropriately
  3. Maintaining high standards of quality across our service
  4. Conducting research to improve our service.

6. Your Rights under DATA Protection

Under UK law, you have the right to:

  • See a copy of the data we hold about you.
  • Ask us to correct information that isn’t right.

Your Rights – Erasure (Right to Be Forgotten) UK GDPR Article 17

Under UK law, you have the right to request that we delete your personal data, also called the “right to be forgotten.” You can ask us to delete your data if it is no longer needed for the purpose we collected it, if you withdraw your consent and we have no other legal reason to keep it, if you object to our processing and there is no overriding reason for us to keep it, or if the data has been processed unlawfully.

There are some exceptions. We may need to keep certain information to comply with legal obligations, protect public health, or resolve disputes. Certain health records may also need to be kept for professional or regulatory reasons.

To request erasure, contact us.

Your Rights – Rectification

Under UK GDPR Article 16, you have the right to ask us to correct any personal data we hold about you that you believe is inaccurate or incomplete. If you think the information we hold is wrong, you can contact us and request that it be updated or corrected.

Your Rights – Access

Under UK GDPR Article 15, you have the right to request a copy of the personal data we hold about you. This allows you to see what information we have collected and how it is being used.

Your Rights – Restriction

Under UK GDPR Article 18, you have the right to ask us to stop processing your personal data in certain circumstances, while we may still need to keep the data. For example, we might need to retain it to comply with legal obligations or for regulatory reasons.

Your Rights – Data Portability

Under UK GDPR Article 20, you have the right to ask for a copy of your personal data in a format that can be easily transferred to another company or service. This helps you move your information securely between providers if needed.

Your Rights – Objection

Under UK GDPR Article 21, you have the right to object to the processing of your personal data in certain situations. You can object when we are relying on a legal obligation, public duty, or legitimate interests, especially if your data is being used for direct marketing.

Your Rights – Automated Decisions

Under UK GDPR Article 22, you have the right to know if a computer or automated system makes a decision about you without human involvement. For example, if an online system assesses your eligibility for a service, you can ask how the decision was made and request human review if needed.


If you’re not happy with how we use your data, you can complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk


9. Updates to This Policy

We may update this policy from time to time. If the changes are important, we’ll let you know.

10. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: Angela Jackson DATA CONTROLLER

Freeframe Ltd angela.jackson@freeframe.co.uk

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
www.ico.org.uk

Subject access request

Step one: Inform the data protection lead that a subject access request has been made.

Step two: the identity of the person requesting subject access must be confirmed prior to the release of any information. This may include asking for formal identification, however this may not always be proportionate and so it may be that the person requesting information would be able to supply information that only they know. Whoever this is not possible then photo ID may be requested.

Step three: Check the request is valid

If the subject access request has been made by someone other and the person whose data is being requested such as a friend relative or solicitor, then written authority to act on behalf of the person concerned will be required. Or a document showing general power of attorney will be accepted as long as this is in date.

Children: If a child over the edge of 12 asks for their own subject access request in most cases this can be granted. If we are asked about subject access requests about a 12-year-old by their parent or carer, permission will be sought from the child first.

Step four: Set yourself some reminders

The time frame to supply the subject access request information is 1 calendar month. If identification or other information is required, then we will wait for the reply before starting the clock on the one-month time limit.

Any additional information will be asked for as soon as possible.

One calendar month runs from the day that we recieved the subject access request, even if this is not a working day.

If the subject access request due date falls on a weekday or public holiday, we have until the next working day to respond. An example of this would be receiving a request on the 25th of November but responding by the 27th of December due to the public holiday.

It does not matter about the length of the month, so subject access request on 31st of January must be responded to by the 28th of February.

If it’s a very complex request, or if you made a lot of requests, Freeframe can take an extra two calendar months to respond. But we will let you know there will be a delay before the end of the first calendar month.

Step five: We will check with you to understand what it is you are asking.If we’re not certain about the data that you are requesting, we will ask you.

Step six: Search for the relevant information, we will check all the information that we have with regards to you and your care and treatment. This will include all forms of data, telephone contact, text messages emails, clinical questionnaires, assessments, and complaints.

Step seven: Check what you need to redact

Before we give you your information, we will look through it carefully to make sure that it really is your information, and that it does not belong to a number of different people. We will reject any information that doesn’t relate to you directly. This is important because most of the time we must avoid disclosing information about other people.

Step eight: Consider the impact of releasing data about other people

There may be occasions when the personal data we have found includes information that is closely linked to someone else. We will still aim to release the personal data requested. However, we also need to consider that doing so may disclose data about someone else and consider the impact thought this may have.

If we think releasing the information may mean that there would be a negative impact on the other person, then we may consider withholding this piece of information altogether. If we do this, we will make a note of why we withheld this

When responding to a SAR in these situations there can be lots to consider, but we will always contact us ( Information Commissioners Office) if we need help deciding what to do.

Step nine: Preparing your reply

If we receive the subject access request by e-mail, we will reply to you by e-mail unless you have told us otherwise will check with you what format you would like it sent and give it a final quality check prior to sending out the subject access request.

Step ten: Send your reply securely and keep a record of what you’ve sent

As well as your personal data we will send your privacy information. You have a right to know why we hold your data, how we got it, how long we’re planning on keeping it, who we are sharing it with, and how you can ask for it to be changed, including updating addresses or deletion of information, we will make sure we keep dated records of the information we send you as you may need to refer to it again for example if you’re unhappy with the response that you received from us or make another request soon after.

privacy information can be found here.