Home › Data Protection
Data Protection
Accredo processes personal and institutional data under UK GDPR: application and inspection data to deliver accreditation, contact data to respond and inform, retained only as long as the purpose requires, never sold, and subject to access, correction, and erasure rights.
What we collect and why
| Data | Purpose | Basis |
|---|---|---|
| Registration and application details | Delivering the accreditation service | Contract |
| Inspection evidence, incl. staff qualifications | Assessment against the standards | Contract / legitimate interest |
| Contact-form and email correspondence | Responding to you | Legitimate interest |
| Newsletter subscription | Sending the newsletter | Consent — withdraw any time |
Retention and security
Accreditation records are retained for the life of the accreditation relationship plus six years; enquiry correspondence for two years; newsletter data until you unsubscribe. Data is stored on access-controlled systems, transferred over encrypted connections, and never sold or shared for marketing.
Your rights
You may request access to, correction of, or erasure of your personal data, and object to or restrict processing, by writing to [email protected]. Complaints may also be raised with the UK Information Commissioner's Office (ICO).
Policy owner: Accredo leadership team. Questions to [email protected]. This page is reviewed annually.