Data Protection Policy

How Freedom Property Academy meets its obligations under UK GDPR, the Data Protection Act 2018, and PECR. This internal governance document should be read alongside our public Privacy Policy.

Last Updated: July 2026Version 2.4
15
Policy Sections
72hrs
Breach Notification
UK GDPR
& DPA 2018 Aligned
Annual
Policy Review

This is an internal governance document. It sets out how Freedom Property Academy ("the Academy") meets its obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 ("DUAA"). It applies to anyone who processes personal data on the Academy's behalf.

Purpose and Scope

This policy applies to all personal data processed in connection with the Programme, the Platform Software, and the Academy's marketing activities, regardless of the format in which it is held.

Data Protection Principles

The Academy processes personal data in line with the following principles under Article 5 UK GDPR:

  • Lawfulness, fairness, and transparency
  • Purpose limitation — data is only used for the purpose(s) it was collected for, or a compatible purpose
  • Data minimisation — only the data genuinely needed is collected
  • Accuracy — data is kept accurate and up to date
  • Storage limitation — data is not kept longer than necessary
  • Integrity and confidentiality — appropriate security is maintained
  • Accountability — the Academy can demonstrate compliance with the above

Roles and Responsibilities

  • The Academy is the data controller for personal data processed in connection with the Programme
  • [Andrei / insert name and role] is responsible for data protection matters, including data subject requests, complaints, maintaining this policy, and acting as the main point of contact with the ICO where necessary
  • Having assessed the nature, scale, and purpose of its processing, the Academy has determined it is not currently required to appoint a formal Data Protection Officer under Article 37 UK GDPR — this will be revisited if processing changes materially

Lawful Basis for Processing

  • Before processing personal data for a new purpose, the responsible person identifies and documents an appropriate lawful basis under Article 6 UK GDPR (and, for special category data, an Article 9 condition)
  • The Academy's current lawful bases for its main processing activities are set out in its Privacy Policy
  • Where the Academy relies on legitimate interests, it carries out and documents a balancing test, save where processing falls within a DUAA "recognised legitimate interest" category (which must still be necessary and proportionate)

Special Category Data

The Academy does not, as a matter of course, seek to collect special category data (e.g. health data, or data about racial or ethnic origin, religious belief, or similar). Where a Client volunteers such data — for example, to explain a delay in meeting a Programme requirement on health grounds — it is used only for that purpose, access is restricted internally, and it is deleted once no longer needed.

Data Subject Rights Procedures

On receiving a request from an individual to exercise a data protection right, the Academy will:

  • Verify the requester's identity before disclosing any data
  • Carry out a reasonable and proportionate search for the relevant data
  • Respond within one calendar month of receipt, extendable by a further two months for complex or numerous requests (informing the individual of any extension within the first month)
  • Where reasonably necessary to clarify what the requester is seeking, pause ("stop the clock") on the response period until that clarification is received

Handling Complaints

In line with section 164A of the Data Protection Act 2018 (in force from 19 June 2026), the Academy:

  • Provides an accessible, electronic means for individuals to submit data protection complaints, via info@freedompropertyacademy.com
  • Maintains a log of all complaints received
  • Acknowledges each complaint within 30 days of receipt
  • Responds substantively without undue delay, keeping the complainant updated on progress

Individuals who remain unsatisfied after raising a complaint with the Academy may also refer the matter to the ICO.

Consent Management

Where the Academy relies on consent (for example, to record sessions, or to use a Client's image, video, or testimonial in marketing), it keeps a record of when and how consent was given, makes withdrawing consent as easy as giving it, and stops the relevant processing promptly on withdrawal, without affecting the lawfulness of processing carried out before that point.

Data Security

The Academy maintains appropriate technical and organisational measures, including:

  • Access controls and strong, unique passwords for internal systems and the Platform Software
  • Restricting access to personal data to those who need it to perform their role
  • Using reputable, secure third-party providers for the Online Portal, CRM, PMS, Guestalizer, Infinit Invoice, Infinit Doc, the bookings platform, and the deals marketplace
  • Keeping software and systems up to date
  • Providing data protection awareness to anyone working on behalf of the Academy

Third-Party Processors

The Academy only engages third-party processors (including providers of the Platform Software) who can provide sufficient guarantees of appropriate technical and organisational security measures, and enters into a written data processing agreement with each, covering the requirements of Article 28 UK GDPR.

International Transfers

Where a processor stores or transfers personal data outside the UK, the Academy ensures an appropriate transfer mechanism is in place, such as an adequacy finding, the UK International Data Transfer Agreement, or standard contractual clauses.

Automated Decision-Making and Profiling

The Academy does not currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals. If this changes, the Academy will assess the requirements of Articles 22A to 22D UK GDPR (introduced by the DUAA) before doing so, and will put in place appropriate safeguards, including the ability for individuals to obtain human review of significant decisions.

Cookies and Direct Marketing

The Academy complies with PECR when using cookies and sending electronic marketing.

  • Strictly necessary and low-risk analytics/functionality cookies may be used without consent, in line with the exemptions introduced by the DUAA
  • Cookies used for advertising or cross-site tracking (including social media advertising pixels) are only used with prior consent
  • Electronic marketing is only sent with consent (or another valid basis under PECR), and every marketing communication provides a clear way to opt out

Children's Data

The Programme is directed at adults and is not a service likely to be accessed by children. The Academy does not knowingly collect personal data from children.

Training and Awareness

Anyone working on behalf of the Academy who handles personal data is made aware of this policy and given appropriate guidance on their data protection responsibilities before doing so.

Data Retention & Disposal

Personal data is retained only as long as necessary.

5 categories
Data CategoryRetention PeriodDisposal Method
Client contracts and financial records6 years after the relationship endsSecure deletion / confidential disposal
CRM / Programme records (contact and progress data)Duration of membership plus 2 yearsSecure deletion
Meeting and webinar recordings12 months, unless needed for a specific ongoing purposeSecure deletion
Marketing images, video, and testimonialsWhile in active marketing use, or until consent is withdrawnRemoved from marketing use; source files deleted where feasible
Website / cookie dataAs set out in the cookie banner/settingsAutomatic expiry per cookie settings

Data Breach Management

  • Any suspected personal data breach must be reported immediately to the person responsible for data protection matters.
  • The Academy assesses the risk posed by a breach without undue delay, and notifies the ICO within 72 hours of becoming aware of it where the breach is likely to result in a risk to individuals' rights and freedoms.
  • Where a breach is likely to result in a high risk to individuals, the Academy also notifies the affected individuals without undue delay.
  • All breaches, whether or not notifiable, are recorded in an internal breach log, including the facts, effects, and remedial action taken.

Review of This Policy

This policy is reviewed at least annually, and whenever there is a material change in the law or in the Academy's processing activities.

Questions About This Policy?

Data protection complaints and queries can be raised via info@freedompropertyacademy.com We acknowledge complaints within 30 days and respond without undue delay.