top of page

Privacy Policy

Ology Learning Ltd – Privacy Policy

Date: June 2026

1. Introduction

Ology Learning Limited respects your privacy and is committed to protecting personal data.

This privacy policy explains how we collect, use, store, share and protect personal data when you use our websites, products, platforms and services.

This policy applies to:

  • ologylearning.co.uk

  • plurio.co.uk

  • Content-Ology

  • Deliver-Ology

  • our related sales, marketing, support, customer administration and business activities.

 

This privacy policy aims to give you information on how Ology Learning Limited collects and processes your personal data through your use of our website/s, our platform and our app, including any data you may provide through our websites or app when you register to use our website(s) or app, request services, tender for services, provide feedback (including ratings), contact us for any reason or when you report to us a problem with our website(s) or app.

Our website/s and app are not intended for children and we do not knowingly collect data relating to children.

It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.

2. Who we are

Ology Learning Limited is a company registered in England and Wales.

Legal entity: Ology Learning Limited
Company number: 16256712
ICO registration number: ZB957075
Email: info@ologylearning.co.uk
Postal address: 13 Main Street, Stathern, LE14 4HW

 

In this policy, “Ology Learning”, “we”, “us” and “our” means Ology Learning Limited.

We have appointed a data privacy manager who is responsible for overseeing questions about this privacy policy and how we handle personal data.

If you have any questions about this policy, or if you wish to exercise your legal rights, please contact us at:

Email: info@ologylearning.co.uk
Post: Data Privacy Manager, Ology Learning Limited, 13 Main Street, Stathern, LE14 4HW

 

You also have the right to make a complaint to the Information Commissioner’s Office, the UK regulator for data protection matters. We would appreciate the opportunity to deal with your concerns first, so please contact us in the first instance.

3. Important information about our role

Depending on the circumstances, Ology Learning may act as either a controller or a processor.

3.1 When we are controller

We are usually the controller for personal data we collect and use for our own business purposes.

This includes personal data used for:

  • website enquiries;

  • sales and marketing;

  • prospecting and business development;

  • customer account management;

  • contracts and billing;

  • finance and accounting;

  • supplier management;

  • service administration;

  • customer support;

  • product improvement;

  • security monitoring;

  • legal, tax and regulatory compliance.

When we are controller, we decide why and how personal data is used.

3.2 When we are processor

Where a customer uses Plurio to manage data about its employees, workers, managers, learners, applicants, contractors, volunteers, apprentices or other individuals, the customer will usually be the controller and Ology Learning will usually be the processor.

This means the customer decides:

  • what personal data is entered into Plurio;

  • why it is processed;

  • who has access to it;

  • which modules and features are used;

  • how long the data is retained;

  • how individuals are informed about the processing;

  • what lawful basis applies.

 

Where we act as processor, we process personal data on the customer’s instructions and in accordance with our contract and data processing agreement.

If you use Plurio through your employer or another organisation, you should also read that organisation’s own privacy notice. They are normally responsible for explaining how they use your personal data.

4. Data protection law

This policy is designed to reflect applicable UK data protection law, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations where relevant.

Under data protection law, personal data must be:

  • used lawfully, fairly and transparently;

  • collected for clear and legitimate purposes;

  • limited to what is necessary;

  • accurate and kept up to date;

  • kept only for as long as necessary;

  • protected appropriately.

 

We aim to handle personal data in line with these principles.

 

5. Personal data we collect

Personal data means information about an individual from which that person can be identified. It does not include data where identity has been removed and the individual can no longer be identified.

The personal data we collect depends on how you interact with us and which products or services are being used.

 

6. Website, sales and business contact data

When you visit our websites, contact us, request information, book a meeting, subscribe to updates or communicate with us, we may collect and use the following types of personal data.

6.1 Identity Data

This may include:

  • first name;

  • last name;

  • title;

  • job title;

  • employer or organisation;

  • username or similar identifier.

 

6.2 Contact Data

This may include:

  • work email address;

  • telephone number;

  • business address;

  • billing contact details;

  • communication details.

 

6.3 Business Data

This may include:

  • organisation name;

  • organisation size;

  • sector;

  • business needs;

  • products or services of interest;

  • contract details;

  • purchasing requirements;

  • role or decision-making responsibilities.

 

6.4 Financial and Transaction Data

This may include:

  • invoice details;

  • payment status;

  • purchase history;

  • contract value;

  • accounting records;

  • finance contact details.

 

Where online payments are enabled, payment details may be processed by an external payment provider. We do not intend to store full card numbers, expiry dates or security codes on our own systems.

 

6.5 Marketing and Communications Data

This may include:

  • marketing preferences;

  • email preferences;

  • newsletter subscriptions;

  • event registrations;

  • campaign engagement;

  • unsubscribe records;

  • correspondence with us;

  • feedback and survey responses.

 

6.6 Technical Data

This may include:

  • IP address;

  • browser type and version;

  • device type;

  • operating system;

  • time zone;

  • pages visited;

  • referral source;

  • login data;

  • website usage;

  • cookie preferences;

  • other technical information about the device or connection used to access our websites or services.

 

6.7 Support and Enquiry Data

This may include:

  • enquiries submitted through our websites;

  • support requests;

  • messages sent to us;

  • issue reports;

  • feedback;

  • call or meeting notes;

  • customer service history.

 

7. Plurio platform data

Plurio is a business platform that may include learning management, HR management, compliance management, time and attendance, reporting, AI-enabled support and related features.

The personal data processed in Plurio depends on the features a customer chooses to use and the information that the customer or its users choose to enter.

Where this data is entered into Plurio by or on behalf of a customer, the customer will usually be the controller and Ology Learning will usually be the processor.

Plurio platform data may include the following categories.

7.1 User Account Data

This may include:

  • name;

  • work email address;

  • username;

  • role;

  • department;

  • manager;

  • permissions;

  • account status;

  • login activity;

  • authentication information;

  • user group membership;

  • notification preferences.

 

7.2 Employment and HR Data

This may include:

  • employee profile information;

  • job role;

  • department;

  • employment status;

  • start date;

  • leaving date;

  • manager relationship;

  • organisation chart information;

  • onboarding records;

  • offboarding records;

  • flexible working records;

  • equipment records;

  • custom fields created by the customer;

  • internal notes and records added by the customer.

 

7.3 Learning and Development Data

This may include:

  • course enrolments;

  • learning plans;

  • course progress;

  • assessment attempts and results;

  • certificates;

  • CPD records;

  • external training records;

  • skills and competencies;

  • learning targets;

  • manager approvals;

  • learning analytics;

  • feedback on learning.

 

7.4 Compliance Data

This may include:

  • compliance requirements;

  • compliance status;

  • role-based requirements;

  • action plans;

  • incident records;

  • escalation records;

  • evidence uploaded by the customer or user;

  • policy acknowledgements;

  • audit records.

 

7.5 Time, Attendance and Absence Data

This may include:

  • time entries;

  • timesheets;

  • clock-in and clock-out information;

  • shift schedules;

  • overtime requests;

  • time off in lieu records;

  • project time;

  • leave requests;

  • leave balances;

  • holiday records;

  • sickness absence records;

  • return-to-work records;

  • phased return records;

  • occupational health referral records, where entered by the customer.

 

7.6 Performance and Development Data

This may include:

  • goals;

  • performance reviews;

  • review cycles;

  • feedback;

  • one-to-one meeting records;

  • development plans;

  • performance improvement plans;

  • disciplinary records;

  • capability records;

  • calibration information;

  • manager notes entered by the customer.

 

7.7 Compensation, Benefits and Expense Data

Where the customer chooses to use these features, this may include:

  • salary records;

  • salary bands;

  • bonuses;

  • benefits;

  • payroll export data;

  • expense claims;

  • expense receipts;

  • project-related expense information;

  • approval records.

 

7.8 Recruitment Data

Where the customer uses recruitment features, this may include:

  • applicant details;

  • CVs;

  • application forms;

  • vacancy applications;

  • interview notes;

  • recruitment status;

  • recruitment communications;

  • selection records;

  • supporting documents uploaded by the applicant or customer.

 

7.9 Document and Signature Data

This may include:

  • employee documents;

  • company policies;

  • document templates;

  • document versions;

  • uploaded files;

  • acknowledgement records;

  • e-signature request records;

  • typed signature details;

  • timestamps;

  • IP address;

  • user ID;

  • email address;

  • document audit trail;

  • signature status.

 

Plurio does not currently require a drawn signature for the signature process unless this is introduced in future.

 

7.10 Engagement, Survey and Feedback Data

Where these features are used, this may include:

  • survey responses;

  • feedback;

  • engagement records;

  • recognition;

  • badges;

  • points;

  • comments;

  • participation history.

 

7.11 Audit, Security and System Data

This may include:

  • access logs;

  • role changes;

  • permission changes;

  • admin actions;

  • support interactions;

  • system logs;

  • error references;

  • audit history;

  • account activity;

  • security event records.

 

7.12 AI Interaction Data

Where AI-enabled features are used, this may include:

  • prompts;

  • questions;

  • uploaded or selected context;

  • generated responses;

  • feedback on AI outputs;

  • usage history;

  • support interactions.

 

Customers and users should avoid entering unnecessary sensitive personal data into AI-enabled features unless this is required for the relevant task and permitted by the customer’s own policies.

 

8. Special category data

Special category data is more sensitive personal data that receives additional protection under data protection law. It can include information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sex life or sexual orientation.

Plurio may allow customers to input special category data if they choose to use certain features or upload certain documents.

 

This may include:

  • sickness absence information;

  • medical information;

  • occupational health information;

  • wellbeing information;

  • disability information;

  • equality, diversity or demographic information;

  • information included in HR notes, documents, incidents, investigations or uploaded files.

 

We do not usually decide to collect this information for our own purposes. Where this information is processed in Plurio, it is normally processed because the customer has chosen to input it and has determined the lawful basis and additional condition for processing it.

 

Where we process special category data as processor, we process it on the customer’s instructions and in accordance with our contract and data processing agreement.

 

Where we process special category data as controller, we will only do so where we have a lawful basis and an additional condition under data protection law.

9. Criminal offence data

Criminal offence data includes personal data relating to criminal convictions, offences, allegations, proceedings or related security measures.

Plurio may allow customers to input criminal offence data or related safeguarding/compliance information if they choose to use certain features or upload certain documents.

 

This may include:

  • DBS check information;

  • criminal record check status;

  • safeguarding records;

  • investigation records;

  • disciplinary records;

  • incident records;

  • documents uploaded by the customer that contain criminal offence information.

 

We do not usually decide to collect this information for our own purposes. Where criminal offence data is processed in Plurio, it is normally processed because the customer has chosen to input it and is responsible for identifying the relevant lawful basis, condition and safeguards.

 

Where we process criminal offence data as processor, we process it on the customer’s instructions and in accordance with our contract and data processing agreement.

 

Where we process criminal offence data as controller, we will only do so where permitted by law.

 

10. Children and young people

Our websites, products and services are aimed at business customers and are not intended for direct consumer use by children.

However, customers may use Plurio to manage data relating to young workers, apprentices, work experience students, volunteers or other individuals under 18 where this is appropriate for their organisation.

Where this happens, the customer is normally responsible for ensuring that the data is collected and used lawfully and that appropriate privacy information is provided to the individual and, where required, their parent or guardian.

11. Aggregated and anonymised data

We may collect and use aggregated data, such as statistical or usage information.

Aggregated data may be derived from personal data but is not personal data if it does not directly or indirectly identify an individual.

For example, we may use aggregated usage data to understand how many users access a feature or complete a workflow.

If we combine aggregated data with personal data so that an individual can be identified, we will treat the combined data as personal data and use it in accordance with this policy.

We may also anonymise personal data so that it can no longer be associated with an individual. We may use anonymised data for research, analytics, product improvement, benchmarking and reporting.

12. If you fail to provide personal data

Where we need to collect personal data by law, or under a contract we have with you or a customer, and the required personal data is not provided, we may not be able to provide the relevant product or service.

For example, we may need certain identity, contact, account or billing information to set up an account, issue an invoice, provide support or deliver contracted services.

Where this applies, we will explain the issue where appropriate.

13. How we collect personal data

We collect personal data in different ways.

13.1 Directly from you

You may give us personal data when you:

  • visit our websites;

  • complete a form;

  • request a demo, trial or proposal;

  • subscribe to updates;

  • contact us by email, phone, Teams or another channel;

  • book a meeting;

  • enter into a contract with us;

  • use Plurio or another service;

  • upload information or documents;

  • submit support requests;

  • give us feedback;

  • attend a meeting, webinar or event.

 

13.2 From customers

Where a customer uses Plurio, the customer may provide or create personal data about its employees, managers, learners, applicants, workers, contractors, volunteers, apprentices or other individuals.

13.3 From users of Plurio

Users may provide personal data when they complete learning, update their profile, submit requests, upload documents, complete forms, respond to surveys, use AI features or interact with the platform.

 

13.4 Automatically

We may automatically collect technical, security and usage data when you use our websites, emails or platform.

 

This may include data collected through:

  • cookies;

  • analytics;

  • log files;

  • system monitoring;

  • audit logs;

  • security tools;

  • email tracking technologies, where permitted.

 

13.5 From third parties and public sources

We may receive personal data from:

  • business contact databases and prospecting tools;

  • publicly available company websites;

  • public professional profiles;

  • customer referrals;

  • partners and resellers;

  • analytics providers;

  • payment, accounting and administration providers;

  • communication tools;

  • suppliers and service providers.

 

14. How we use personal data

We will only use personal data where the law allows us to.

 

Most commonly, we use personal data:

  • to perform a contract;

  • to take steps before entering into a contract;

  • where it is necessary for our legitimate interests and those interests are not overridden by individual rights;

  • to comply with a legal obligation;

  • where consent has been given;

  • where another lawful basis applies.

 

Where we process personal data as processor for a customer, the customer is responsible for identifying the lawful basis for its processing.

 

15. Purposes and lawful bases

The table below explains the main ways we use personal data where we act as controller.

 

 

 

We may process personal data for more than one lawful basis depending on the specific purpose.

 

16. Legitimate interests

Where we rely on legitimate interests, we consider and balance our interests against the rights and freedoms of the individuals concerned.

Our legitimate interests may include:

  • running and growing our business;

  • responding to enquiries;

  • promoting our products and services to relevant business contacts;

  • managing customer relationships;

  • providing secure and reliable services;

  • preventing misuse, fraud or security incidents;

  • improving our products and services;

  • understanding how our websites and platform are used;

  • maintaining appropriate business records;

  • protecting our legal and commercial position.

 

You can object to processing based on legitimate interests in certain circumstances. You can also object to direct marketing at any time.

 

17. Marketing

We may use business contact details to send relevant information about our products and services, including Plurio, Content-ology, Deliver-ology, updates, events, resources and related services.

 

We primarily use business contact details and company email addresses for B2B marketing.

 

We may contact you if:

  • you have requested information from us;

  • you have purchased or used our services;

  • you work for an organisation that may reasonably be interested in our products or services;

  • you have engaged with our content, events or communications;

  • we otherwise have a lawful basis to contact you.

 

For B2B marketing, we may rely on legitimate interests where the communication is relevant, proportionate and directed to a business contact in a professional context.

 

Where consent is required, we will ask for consent.

 

We will not sell your personal data.

 

We will not share your personal data with third parties for their own marketing purposes unless we have your consent or another lawful basis to do so.

 

17.1 Opting out of marketing

You can ask us to stop sending marketing communications at any time by:

  • using the unsubscribe link in our emails;

  • adjusting your preferences where a preference centre is provided;

  • contacting us at info@ologylearning.co.uk.

 

If you opt out of marketing, we may still send non-marketing service messages, such as important account, security, legal, contractual or product administration notices.

 

We may also keep a suppression record to make sure we do not send you further marketing.

 

18. Cookies and similar technologies

Our websites use cookies and similar technologies.

Some cookies are strictly necessary for our websites to work. Others may support analytics, performance, preferences, marketing or advertising.

We use the Wix consent banner to help manage cookie choices on our websites.

Where required by law, we will ask for consent before placing non-essential cookies or similar technologies on your device.

You can change your cookie preferences through the consent banner or through your browser settings.

Blocking some cookies may affect how our websites work.

This privacy policy does not contain our full cookie table. Please see our separate Cookie Policy for further details about the cookies and similar technologies we use.

19. Advertising and analytics

We may use analytics tools to understand how our websites and services are used.

We may also use advertising and retargeting technologies, including through platforms such as Google, LinkedIn or Meta, where enabled.

Where these technologies involve non-essential cookies or similar tracking technologies, they will be controlled through our cookie consent tools and explained in our Cookie Policy.

20. AI-enabled features

Plurio may include AI-enabled features, including AI support, AI content assistance, AI insights, AI compliance support, AI coaching or AI recommendations.

Where AI features are used, information submitted into those features may be processed to generate a response or complete the requested action.

We currently use Lovable AI in connection with AI-enabled functionality and/or platform development activity.

We do not use customer personal data submitted to Plurio to train third-party foundation models.

Customers and users should not submit unnecessary sensitive personal data into AI-enabled features unless it is required for the task and permitted by the customer’s own policies.

AI-generated outputs may be imperfect or incomplete. Customers and users are responsible for reviewing outputs before relying on them, particularly where they relate to HR, compliance, legal, employment, safety, health or other sensitive decisions.

 

Where AI features process customer-controlled personal data, Ology Learning usually acts as processor and processes that data on the customer’s instructions.

21. Authentication and account security

Plurio currently supports email and password authentication.

Single sign-on may be added in future. If we add single sign-on or third-party authentication, we will update this policy where required to explain what authentication data is used and how it is processed.

We use appropriate technical and organisational measures designed to protect personal data. These may include access controls, authentication controls, role-based permissions, customer-level access restrictions, logging, audit records, backup processes and operational security procedures.

We do not publish full details of our security architecture in this policy, as doing so could create security risks. Further security information may be made available to customers under appropriate commercial or confidentiality arrangements.

22. Sharing personal data

We may share personal data where necessary for the purposes described in this policy.

This may include sharing personal data with:

  • website hosting and platform providers;

  • database, storage, authentication and infrastructure providers;

  • email and communication providers;

  • CRM, sales and marketing tools;

  • analytics and advertising providers, where enabled;

  • payment, finance and accounting providers;

  • AI and product development providers;

  • meeting, webinar and scheduling tools;

  • document, project management and collaboration tools;

  • professional advisers, including accountants, lawyers, insurers, auditors and banks;

  • HMRC, regulators, public authorities, courts or law enforcement where required;

  • customers, where information relates to their account, users or platform data;

  • partners and resellers, where relevant to the customer relationship;

  • a buyer, investor or successor organisation if our business is sold, merged, reorganised or transferred.

 

We require service providers to protect personal data and to use it only for authorised purposes.

 

We do not allow our service providers to use personal data for their own purposes unless they are acting as an independent controller and have a lawful basis to do so.

23. Subprocessors

Where we act as processor for customer-controlled personal data, we may use subprocessors to help provide Plurio and related services.

Subprocessors may provide services such as hosting, infrastructure, authentication, database storage, email delivery, logging, backup, support, AI-enabled functionality and operational tooling.

Before engaging subprocessors, we take steps designed to satisfy ourselves that they can protect personal data appropriately. We also require subprocessors to enter into appropriate contractual commitments where required.

Our current provider and subprocessor schedule is set out at the end of this policy.

The schedule may be updated from time to time as our products, services and suppliers change.

24. International transfers

Some of our providers may process personal data outside the United Kingdom.

This may include providers based in, or using infrastructure in, the United States, European Economic Area or other countries.

 

Where personal data is transferred internationally, we will take steps designed to ensure that it receives an appropriate level of protection.

These steps may include:

  • relying on UK adequacy regulations;

  • using the UK International Data Transfer Agreement;

  • using the UK Addendum to the EU Standard Contractual Clauses;

  • entering into supplier data processing agreements;

  • carrying out transfer risk assessments where required;

  • applying appropriate technical and organisational safeguards.

 

You can contact us if you would like further information about the safeguards used for a particular transfer.

25. Data security

We have put in place appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  • access controls;

  • authentication controls;

  • role-based permissions;

  • logging and audit records;

  • backup processes;

  • staff and supplier confidentiality obligations;

  • operational security procedures;

  • system monitoring and issue investigation.

 

Access to personal data is limited to people and providers who have a business need to access it.

No system can be guaranteed to be completely secure. If we become aware of a personal data breach, we will take appropriate steps to investigate, reduce harm and notify affected parties and regulators where required by law.

26. Data retention

We keep personal data only for as long as reasonably necessary for the purposes for which it was collected.

This includes legal, tax, accounting, contractual, security, support, reporting and operational requirements.

The retention period depends on the type of data, the reason we hold it, the sensitivity of the data, legal requirements and whether the data is needed for complaints, disputes, audit, evidence or legal claims.

26.1 Business, finance and contract records

We normally retain customer, supplier, contract, finance and accounting records for up to 6 years after the end of the relevant financial year or customer relationship, unless a longer period is required or justified.

26.2 Website enquiry and sales records

We retain enquiry, prospect and sales records for as long as needed to respond to the enquiry, manage the business relationship, maintain appropriate sales records and comply with legal obligations.

Where a prospect does not become a customer, we may retain limited records for a reasonable period for business administration, suppression, audit and marketing preference purposes.

26.3 Marketing records

We keep marketing records for as long as needed for marketing, preference management and suppression.

If you opt out, we may keep a suppression record to make sure we do not contact you again for marketing.

26.4 Support records

We keep support records for as long as needed to provide support, investigate issues, maintain service quality, protect our legal position and improve our products.

26.5 Plurio customer data

For personal data processed in Plurio on behalf of a customer, retention is normally controlled by the customer through the platform, the customer contract and any agreed data retention settings.

When a customer contract ends, we will delete or return customer data in accordance with the contract and data processing agreement.

Live customer data will normally be deleted promptly following contract end, subject to any agreed export period, legal requirements, audit/evidence retention and backup expiry.

26.6 Backups

File storage backups are retained for a limited period for accident recovery purposes.

At the time of this policy, Plurio file storage backups are intended to be retained for up to 30 days.

Database backups are managed at platform/infrastructure level by our hosting provider and are retained according to the applicable hosting plan and backup arrangements.

Backup data is not used for live processing and is deleted or overwritten through normal backup rotation.

26.7 Audit, security and evidence records

Some audit, compliance, acknowledgement, security, evidence or legal records may need to be retained for longer where necessary for:

  • accountability;

  • legal claims;

  • regulatory compliance;

  • contractual compliance;

  • audit history;

  • security investigation;

  • fraud prevention;

  • evidential purposes.

 

Where a customer controls the data, the customer is responsible for setting and applying its own retention decisions, subject to the technical functionality available in Plurio and the terms agreed with us.

26.8 Anonymisation

In some circumstances, we may anonymise personal data so that it can no longer identify an individual. We may use anonymised data indefinitely without further notice.

27. Your legal rights

Under data protection law, you may have the following rights in relation to your personal data.

27.1 Right of access

You may request a copy of the personal data we hold about you.

27.2 Right to correction

You may ask us to correct incomplete or inaccurate personal data.

27.3 Right to erasure

You may ask us to delete personal data where there is no good reason for us continuing to process it.

This right is not absolute. We may need to retain certain data for legal, regulatory, contractual, security, audit or legitimate business reasons.

27.4 Right to object

You may object to processing where we rely on legitimate interests.

You can object to direct marketing at any time.

27.5 Right to restriction

You may ask us to restrict processing of your personal data in certain circumstances.

27.6 Right to data portability

You may ask us to provide certain personal data to you or a third party in a structured, commonly used and machine-readable format.

This right only applies in certain circumstances.

27.7 Right to withdraw consent

Where we rely on consent, you may withdraw consent at any time.

This will not affect the lawfulness of processing carried out before consent was withdrawn.

27.8 Rights relating to automated decision-making

You may have rights in relation to certain types of automated decision-making that have legal or similarly significant effects.

 

We do not intend to use AI-enabled features to make final legally significant employment, HR, compliance or similar decisions about individuals without appropriate human review.

28. How to exercise your rights

To exercise your rights, please contact us at:

Email: info@ologylearning.co.uk
Post: Data Privacy Manager, Ology Learning Limited, 13 Main Street, Stathern, LE14 4HW

 

You will not usually have to pay a fee to exercise your rights.

However, we may charge a reasonable fee or refuse to comply if a request is clearly unfounded, repetitive or excessive.

We may need to request information from you to confirm your identity and ensure that personal data is not disclosed to someone who is not entitled to receive it.

We aim to respond to legitimate requests within one month.

If your request is complex, or if you have made several requests, it may take longer. In that case, we will let you know and keep you updated.

29. Requests relating to Plurio customer data

If your personal data is processed in Plurio by your employer or another customer organisation, that organisation will usually be the controller.

In those circumstances, we may need to refer your request to the customer or act on the customer’s instructions.

We may not be able to respond directly to a request about customer-controlled platform data unless the customer authorises us to do so or the law requires it.

30. Keeping your data up to date

It is important that the personal data we hold about you is accurate and current.

Please tell us if your personal data changes during your relationship with us.

Where you use Plurio through a customer organisation, you may also need to update your details through that organisation or within the platform, depending on the settings applied by the customer.

31. Third-party links

Our websites and platform may include links to third-party websites, plug-ins, applications or services.

Clicking on those links or enabling those connections may allow third parties to collect or share data about you.

We do not control third-party websites or services and are not responsible for their privacy practices.

When you leave our websites or platform, we encourage you to read the privacy policy of every website or service you visit.

32. Business reorganisation

We may share or transfer personal data as part of any actual or proposed sale, merger, acquisition, restructuring, investment, financing, transfer of assets or similar business transaction.

Where this happens, we will take steps designed to ensure that personal data remains protected in accordance with data protection law.

33. Financial transactions

Where payments are handled by an external payment provider, that provider may process payment information as an independent controller or processor depending on the circumstances.

We do not intend to store full payment card numbers, expiry dates or security codes on our own systems.

You should review the relevant payment provider’s privacy information where online payments are used.

34. Changes to this privacy policy

We keep this privacy policy under regular review.

We may update it from time to time to reflect changes in our services, technology, suppliers, legal obligations or business practices.

The latest version will be made available on our websites.

Where changes are significant, we may take additional steps to notify customers or users.

35. Glossary

Personal data - Personal data means information relating to an identified or identifiable living individual.

Controller - A controller decides why and how personal data is processed.

Processor - A processor processes personal data on behalf of a controller and on the controller’s instructions.

Lawful basis - A lawful basis is the legal reason for processing personal data under data protection law.

Legitimate interests - Legitimate interests means the interests of our business, a customer or a third party in carrying out and managing activities, provided those interests are not overridden by individual rights and freedoms.

Performance of contract - This means processing personal data where necessary to perform a contract or take steps before entering into a contract.

Legal obligation - This means processing personal data where necessary to comply with a legal obligation.

Consent - Consent means a freely given, specific, informed and unambiguous indication of an individual’s wishes.

Special category data - Special category data is more sensitive personal data that receives extra protection under data protection law, such as health data or certain equality and diversity information.

Criminal offence data - Criminal offence data means personal data relating to criminal convictions, offences, allegations, proceedings or related security measures.

36. Provider and subprocessor schedule

The table below lists the main providers we use or may use to deliver our websites, products, services and business operations.

 

Some providers may act as processors, subprocessors or independent controllers depending on the service provided and the circumstances.

This schedule may be updated from time to time.

​​​​​​​​​​​​​​​​

37. Contact us

If you have any questions about this privacy policy or how we handle personal data, please contact:

Ology Learning Limited
13 Main Street
Stathern
LE14 4HW

Email: info@ologylearning.co.uk

bottom of page