Privacy Policy
Last updated: 24 February 2026
1. Who We Are
Teckollab Ltd (“Teckollab”, “we”, “us”, “our”) is a company registered in England & Wales (Companies House number: 14390643). Our registered office is at [INSERT REGISTERED ADDRESS]. We are registered with the Information Commissioner's Office (ICO registration number: [INSERT ICO NO.]).
We operate Coheart, a cohort learning management platform for training providers and employers, available at coheart.io and app.coheart.io. Coheart is a product of Teckollab Ltd.
For questions about this policy, contact us at privacy@coheart.io.
2. Our Role: Data Controller and Data Processor
Under UK GDPR, the same organisation can act as a data controller (deciding the purpose and means of processing) or a data processor (processing data on behalf of a controller), depending on the context. Coheart acts in both capacities:
- Controller — for data we collect about visitors to coheart.io (analytics, enquiries) and for our own business operations (billing, staff, supplier relationships). We determine the purposes and means of this processing and this policy governs it.
- Processor — for personal data that your organisation (the controller) uploads to or generates within the Coheart platform, including learner profiles, assessment records, attendance data, and ILR outcomes. In this context, your organisation instructs us; we process that data only on your behalf and in accordance with our Data Processing Agreement (“DPA”).
If your organisation is using Coheart and has questions about how learner personal data is handled under the DPA, please contact your organisation's administrator or request a copy of the DPA at privacy@coheart.io.
3. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, hashed password, role within your organisation.
- Profile data: job title, phone number (optional), profile photo (optional).
- Usage data: session attendance, assessment submissions, resource interactions, login timestamps.
- Communications: messages sent via the platform, announcements, and discussion posts.
- Technical data: IP address, browser type, and device information collected automatically for security and fraud-prevention purposes.
- ILR outcome data: Individualised Learner Record data as required for funder and statutory reporting obligations. This may include special category data (such as disability or employment status) where provided by the learner's organisation for reporting purposes.
Local storage. The Coheart application (app.coheart.io) stores your session authentication token in your browser's localStorage rather than in a cookie. This token contains no personal data — it is an opaque reference to a server-side session. See our Cookie Policy for full details of what is and is not stored in your browser.
4. How We Use Your Data
We use your personal data to:
- Provide and improve the Coheart platform and its features.
- Manage your account and authenticate your sessions.
- Enable facilitators to deliver cohort programmes and track learner progress.
- Generate certificates, reports, and ILR exports for funding compliance.
- Send service-related communications (e.g., session reminders, notifications, password resets) via Mailchimp Transactional — see Section 7.
- Detect and prevent fraud, abuse, and security incidents.
- Identify learners who may be at risk of disengagement, using automated scoring of platform activity — see Section 10 (Automated Processing).
5. Legal Basis for Processing
We rely on the following legal bases under UK GDPR:
- Contract: processing necessary to perform our agreement with your organisation (account management, session delivery, certificate generation, reporting).
- Legitimate interests: platform security, fraud prevention, and service improvement — where our interests are not overridden by your rights.
- Legal obligation: ILR reporting, HMRC record-keeping, and other statutory requirements.
- Special category data (Schedule 1, DPA 2018): where ILR outcome data includes disability or employment information, we rely on Schedule 1, paragraph 1 (employment, social security, and social protection) of the Data Protection Act 2018.
6. Data Retention
We retain personal data for as long as your organisation's contract with us is active. Following contract termination or account closure, we retain data for a further 7 years to satisfy our legal obligations under the Companies Act 2006 and HMRC record-keeping requirements (6 years from the end of the relevant financial year). After this period, personal data is securely and permanently deleted, except where a longer retention period is required by law.
Learner ILR outcome records are retained in anonymised form indefinitely to satisfy funder audit and regulatory requirements. Anonymisation is irreversible — once anonymised, the records can no longer be attributed to an individual.
You may request deletion of your personal data at any time (see Section 11 — Your Rights); a 30-day grace period applies before permanent deletion to allow for recovery in case of accidental requests.
Transactional email records held in our systems — including the recipient email address and email content — are automatically and permanently deleted after 90 days.
7. Data Sharing and Sub-Processors
We do not sell your personal data. We share data only with trusted sub-processors required to provide the service:
- Microsoft Azure — hosting and storage (UK South region, London). Primary data residency for all platform data.
- Zoom Video Communications, Inc. — live session hosting. Zoom's servers process audio/video during live sessions.
- Mux, Inc. — pre-recorded video content delivery.
- Mailchimp Transactional (Mandrill) — The Rocket Science Group LLC — transactional email delivery (see below).
All sub-processors are bound by Data Processing Agreements and are required to process data only on our instructions.
Mailchimp and transactional email. When we send you a transactional email — such as a password reset link, account invitation, session reminder, or certificate notification — your email address and the rendered content of that email are transmitted to Mailchimp Transactional (Mandrill), operated by The Rocket Science Group LLC. This is necessary to deliver the message to your inbox. Email open tracking and click tracking are disabled: Coheart does not instruct Mailchimp to track whether you open or click any email we send. Our own email delivery records are purged after 90 days (see Section 6).
International data transfers. The Rocket Science Group LLC is headquartered in Atlanta, Georgia, USA. Transmitting your email address to Mailchimp constitutes a transfer of personal data outside the UK. We rely on Standard Contractual Clauses with the UK Addendum approved by the ICO to ensure appropriate safeguards. You may obtain a copy of these safeguards by contacting privacy@coheart.io. All other personal data remains stored in the UK (Azure UK South). Zoom and Mux may process data in the USA under their own SCCs and/or adequacy arrangements.
8. Cookies and Local Storage
The coheart.io marketing website uses no analytics or tracking cookies. We use Plausible Analytics, a fully cookieless tool. The Coheart application (app.coheart.io) uses browser localStorage — not cookies — to store your session token.
For a full explanation of what is stored in your browser and why, see our Cookie Policy.
9. Security and Data Breaches
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction, including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption for all data at rest (Azure Storage Service Encryption).
- Role-based access control (RBAC) — staff and systems access only the data necessary for their function.
- SHA-256 hashed session tokens — plaintext credentials are never stored.
- Annual third-party penetration testing.
Personal data breaches. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to individuals, we will also notify affected data subjects without undue delay (Article 34). If Coheart is acting as a data processor on behalf of your organisation, we will notify your organisation of any breach affecting your learner data without undue delay so that you can fulfil your own notification obligations.
To report a security concern, contact security@coheart.io.
10. Automated Processing
Coheart's platform includes an at-risk detection system that automatically calculates an engagement score for each learner based on platform activity signals including: session attendance, resource interactions, assessment completion, login frequency, and recency of activity. Learners whose score falls below defined thresholds are flagged to facilitators and organisation administrators.
This automated scoring is used solely to support human decision-making — it does not produce legally binding or similarly significant decisions about individuals without human review. Facilitators and administrators retain full discretion over any interventions or actions taken.
If you believe your at-risk status has been incorrectly calculated, you may contact your facilitator or exercise your rights under Section 11 below.
11. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access (Article 15): request a copy of the data we hold about you.
- Rectification (Article 16): correct inaccurate or incomplete data.
- Erasure (Article 17): request deletion of your personal data (“right to be forgotten”), subject to our legal retention obligations.
- Restriction (Article 18): restrict how we process your data in certain circumstances.
- Portability (Article 20): receive your data in a structured, machine-readable format.
- Object (Article 21): object to processing based on legitimate interests.
- Automated decision-making (Article 22): not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- Complaint (Article 77): lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have processed your data unlawfully (see Section 12).
To exercise any of these rights, contact privacy@coheart.io. We will respond within 30 days. We may ask you to verify your identity before processing your request.
Note for learners: if your personal data on the Coheart platform was provided by your training organisation, you may need to direct some requests (e.g., rectification or erasure) to that organisation as the data controller.
12. Data Protection Officer and Complaints
Our Data Protection Officer (DPO) can be contacted at dpo@coheart.io.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time. The ICO is the UK's supervisory authority for data protection matters:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We ask that you contact us first at privacy@coheart.io so that we have the opportunity to resolve your concern before you escalate to the ICO.
13. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or via an in-app notification at least 14 days before changes take effect. The date at the top of this page reflects when the policy was last updated.