Privacy
Policy
Privacy Policy – codevelo.org
Last updated: July 2026
1. Who We Are
Codevelo (JPBC Holdings (UK) Ltd) is the data controller for personal data described in this policy.
- Registered office: 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London W1T 6EB
- Data Protection contact: dpo@codevelo.org
- ICO Registration Number: ZB377606
2. Scope
This policy covers all websites, learning platforms, tools and services operated by Codevelo, whatever domain or subdomain they’re hosted on. It applies wherever you interact with Codevelo online — browsing our website, taking part in a CPD programme, or receiving a reflection report as a school leader. We provide services primarily to adults working in education. We do not knowingly collect personal data directly from children. Where our work touches on children indirectly — for example where a staff member’s professional reflection references a pupil — safeguarding responsibility remains with the commissioning school or trust.
3. What We Collect and Why
What | Why | Lawful basis |
Contact details (name, email, organisation, role) from enquiries, bookings and CPD enrolment | Respond to you, deliver training and CPD, manage the relationship | Contract / legitimate interests |
Marketing preferences and communication history | Send relevant updates where you’ve opted in, or as permitted for professional B2B contacts | Consent / legitimate interests |
CPD engagement content (course activity, reflections, assessments) | Deliver and support the learning programme; generate anonymised, aggregated reflection reporting for school leadership | Contract / legitimate interests |
Website and platform usage data (device, IP, analytics) | Keep our systems secure and understand how our services are used | Consent (analytics) / legitimate interests (security) |
Payment information | Process payment for services (handled by our payment provider — we don’t store full card details) | Contract |
Financial and contractual records | Meet our legal and audit obligations | Legal obligation |
4. AI-Assisted Reflection Reporting
As part of some CPD programmes, anonymised content you contribute is processed using AI to generate a summarised reflection report for your school’s leadership. No names or identifying details are included in this process. This reporting reflects overall themes and engagement, not individual performance, and is not used to make any automated decision about you.
5. Who We Share Data With
We use a small number of named service providers to deliver our services, each acting under a written data protection agreement and only processing data on our instructions:
- GoHighLevel — CRM, enquiries, bookings and communications
- Stripe — payment processing
- Our learning platform hosting provider — delivery of CPD courses and content
- Cloudflare and Anthropic — secure hosting and AI-assisted synthesis of anonymised reflection reporting
None of these providers may use your data for their own purposes, and we don’t sell personal data or use it for advertising or profiling. Where a provider is based outside the UK (some of the above are US-based), we rely on an appropriate legal safeguard for that transfer — either the UK’s International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an equivalent UK-recognised adequacy mechanism.
Where Codevelo processes CPD engagement data on behalf of a school under a signed agreement, the school remains the data controller for that data and Codevelo acts as processor, on the terms of that agreement.
6. How Long We Keep Data
Data type | Retention |
Enquiry, booking and marketing contact data | 24 months from last engagement, then reviewed and deleted |
CPD engagement content and reflection reports | 2 years from generation, then deleted |
Contractual and financial records | As required by UK tax and audit law |
A school or individual may request earlier deletion of their data at any time — see Section 7.
7. Your Rights
Under UK GDPR, you have the right to access your personal data, request correction of inaccurate data, request erasure where applicable, restrict or object to processing, withdraw consent at any time, request data portability where relevant, and lodge a complaint with the Information Commissioner’s Office (ICO). To exercise any of these rights, contact dpo@codevelo.org.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including multi-factor authentication on administrative access, encrypted transmission, role-based access controls, anonymisation at source for CPD reflection content, and regular system updates.
9. Changes to This Policy
We review this policy regularly and update it when our services change. The current version is always available at codevelo.org/privacy-policy.