PRIVACY POLICY

  1. Introduction

Welcome to Nottinghamshire Work Experience Hub, a work experience application management system operated by Nottinghamshire Health Informatics Service ("Nottinghamshire Work Experience Hub", "we", "us", or "our"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our services.

Nottinghamshire Work Experience Hub is designed to facilitate the work experience application process by managing applications and automating workflows involving applicants, placement supervisors, and parents/guardians (where applicable). This policy outlines how we process personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

 

  1. Data Controller and Contact Information

Nottinghamshire Health Informatics Service, an organisation hosted by Sherwood Forest Hospitals NHS Foundation in England, with a registered office at Nottinghamshire Health Informatics Service – TB3, King’s Mill Hospital, Mansfield Road, Sutton-in-Ashfield NG17 4JL.

If you have any questions about this policy or our data processing practices, you can contact us at:

  1. What Personal Data We Collect

We collect and process different types of personal data depending on your role in the work experience application process. The data fields are determined by the organisation that is hosting the placement on the Nottinghamshire Work Experience Hub. All the fields on the application form and subsequent stages are items of personal data we collect.

We may also collect technical data such as IP addresses, browser type, and usage data when you interact with our website and services.

 

  1. How We Use Your Data

We process personal data to:

  • Facilitate the application process for work experience placements;
  • Communicate with applicants, parents/guardians, and placement supervisors;
  • Verify eligibility and consent where required;
  • Manage and track application progress;
  • Improve and enhance our services;
  • Respond to inquiries and provide customer support.

We do not use personal data for automated decision-making or profiling without human intervention.

 

  1. Legal Basis for Processing

We process personal data under the following lawful bases:

  • Contractual Necessity: To fulfil our agreement with applicants, schools, and placement providers.
  • Legitimate Interests: To operate and improve our service efficiently while ensuring necessary safeguards.
  • Legal Obligation: To comply with legal and regulatory requirements, including safeguarding obligations.
  • Consent: Where applicable, such as when processing certain parental/guardian approvals.

  1. Data Sharing and Disclosure

We only share personal data when necessary to facilitate the work experience application process. This includes:

  • Placement Supervisors: To enable them to review and process applications.
  • Schools/Educational Institutions: Where applicable, to coordinate work experience placements.
  • Parents/Guardians: When required for applicants under 18.
  • Service Providers: We may use third-party IT providers to host and secure our platform, all of whom are subject to data protection obligations.
  • Legal Authorities: If required by law, regulatory authorities, or safeguarding obligations.

We do not sell or rent personal data to third parties.

 

  1. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this policy. This includes:

  • Active application records are retained for the duration of the work experience process.
  • Personal data may be archived for legal and compliance purposes for up to 7 years.
  • After the retention period, personal data will be securely deleted or anonymised.


  1. Data Security

We implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, or misuse. These include:

  • Encryption of data in transit and at rest;
  • Secure access controls;
  • Regular security audits and monitoring;
  • Data minimisation and anonymisation where feasible.


  1. Your Rights Under Data Protection Law

Under UK GDPR, individuals have rights regarding their personal data, including:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion of personal data where it is no longer necessary.
  • Right to Restrict Processing: Request limited processing under certain conditions.
  • Right to Data Portability: Receive a copy of your data in a commonly used format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at sfh-tr.nhiscommunications@nhs.net. We may require verification before processing requests.

 

  1. International Data Transfers

We exclusively process all data within the UK.

 

  1. Updates to This Policy

We may update this Privacy Policy to reflect changes in regulations or our practices. Any significant changes will be communicated through our website or direct notification where appropriate.

Last Updated: 1st August 2025

 

  1. Complaints and Contact Information

If you have concerns about our data practices, please contact us first at sfh-tr.nhiscommunications@nhs.net.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

 

  1. Acceptance of This Policy

By using Nottinghamshire Work Experience Hub, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any terms, please discontinue use of our services.

For further details or queries, contact us at sfh-tr.nhiscommunications@nhs.net