Let's Pass
Privacy Policy
1. Who we are
This policy explains how Let's Pass ("we", "us", "our") collects, uses, shares, and protects personal data, in accordance with UK GDPR and the Data Protection Act 2018.
Data controller: Lorraine Gibson, Director, Let's Pass.
2. What data we collect
- Parent/guardian contact information: name, address, email, phone number.
- Student information: name, age, year group, subjects studied, and academic progress, used to place students in the right group and tailor tuition.
- Payment information: processed by Stripe on our behalf — Let's Pass does not store full card details itself.
- Communications: messages sent via WhatsApp and notes logged on a student's TutorBird record, and correspondence by email.
- Session recordings: online sessions are recorded to Let's Pass's central Zoom cloud storage. The recording link is shared with every student and parent in that group (not only anyone who was absent) for 2 weeks, then automatically deleted. See the Online Safety Policy for full detail.
- Marketing preferences: for anyone signed up to the weekly newsletter or who has downloaded a freebie from the website, via FunnelSketchers.
- Tutor information: qualifications, DBS and vetting records, references, and CV, collected and held under the Safer Recruitment Policy — this is personal data too, and this policy applies to it in the same way.
3. How we collect it
Directly from parents and students at enquiry and sign-up, through the website, phone, WhatsApp, or email; through session delivery and progress monitoring; and from tutors during recruitment.
4. Legal basis for processing
- Performance of a contract: processing necessary to deliver tuition under our agreement with a parent or guardian, or with a tutor under their engagement with Let's Pass.
- Legitimate interests: for example, using session and progress data to improve teaching, or contacting existing families about renewing a place, where this doesn't override the family's own interests or rights.
- Legal obligation: for example, safeguarding record-keeping, or HMRC financial record requirements.
- Consent: for marketing communications to anyone who isn't already an enrolled family — for example, newsletter sign-ups or freebie downloads — which can be withdrawn at any time.
5. Children's data
Most of the personal data we hold relates to students under 18. Because a child cannot enter into a contract, our contract is with the parent or guardian, and we rely on performance of that contract (and our legitimate interest in delivering effective tuition) as the basis for processing a student's data, rather than the student's own consent.
Where we need to process anything that counts as special category data about a student — for example, a disclosed SEN diagnosis or health information relevant to tuition — we ask the parent or guardian for explicit consent to hold and use it, and store it under the additional safeguards set out in section 9.
6. How we use it
- To deliver tuition and fulfil our agreement with parents/guardians and tutors.
- To communicate about sessions, scheduling, progress, and feedback.
- To monitor and report on student progress.
- To meet legal and safeguarding obligations, including record-keeping set out in the Safeguarding Policy and Safer Recruitment Policy.
- To send marketing communications (newsletter, promotions) only where consent has been given, or to existing families about their ongoing tuition.
7. Sharing of information
- Tutors: student information is shared with the tutor(s) delivering that student's sessions.
- Parents/guardians: student progress and updates are shared with the relevant parent or guardian.
- Schools: only where a parent/guardian has given written consent to share information with a student's school, or where a school has directly contracted Let's Pass to deliver tuition to their students.
- Havering Council: where a student is placed with Let's Pass through AP commissioning, relevant information may be shared with the Council under the terms of that commissioning arrangement, once confirmed.
- Service providers: TutorBird, Stripe, and FunnelSketchers process data on our behalf to run scheduling, payments, and marketing respectively.
Some of these providers are based outside the UK, so your data may be processed in Canada, the US, or the EU. Where this happens, appropriate safeguards are in place to protect it to UK GDPR standards:
- TutorBird (scheduling): operated by Port 443 Inc., based in Canada. Data may be processed in Canada and/or the United States.
- Stripe (payments): processes data in the United States. Transfers rely on Standard Contractual Clauses and Stripe's certification under the EU-US Data Privacy Framework, including the UK Extension.
- FunnelSketchers (CRM and marketing): runs on GoHighLevel, based in the United States. Transfers rely on Standard Contractual Clauses.
- Regulatory or safeguarding authorities: where required by law, or under the referral routes set out in the Safeguarding Policy.
We do not sell or rent personal information to third parties for marketing purposes.
8. Data retention
- While a family is enrolled: for as long as tuition continues.
- After a student leaves: general records are kept for a reasonable period to handle any follow-up queries, then deleted; financial records are kept for 6 years to meet HMRC requirements.
- Safeguarding-relevant records: kept for longer where a concern has been recorded, generally until the student turns 25, in line with the Safeguarding Policy.
- Marketing data: kept until you unsubscribe or ask us to delete it.
- Session recordings: kept for 2 weeks, then automatically deleted — see the Online Safety Policy.
9. Special category and children's data — additional safeguards
Special category data, and data relating to children and vulnerable adults, is subject to extra safeguards beyond our standard data security measures:
- Reviewed at least every three months to check it's stored appropriately and securely.
- Access is limited to who genuinely needs it, for the purpose of delivering tuition or meeting a legal/safeguarding duty.
- Use is restricted to what's reasonably necessary for that purpose.
10. Your rights
Under UK GDPR, you have the right to: access your personal data; request correction of inaccurate data; request erasure in certain circumstances; request restriction of processing; receive your data in a portable format; object to processing (including for marketing); and withdraw consent at any time where processing relies on it. You also have the right to complain to the Information Commissioner's Office (ICO) if you're unhappy with how we've handled your data — see section 14 for how. To exercise any of these, contact us using the details in section 13.
11. Data security
We use appropriate technical measures to protect personal data, including access controls, secure passwords, and, where available through our service providers, encryption and two-factor authentication. No method of transmission or storage is 100% secure, and we can't guarantee absolute security, but we take reasonable steps to minimise risk.
If a data breach occurs, we will assess and mitigate it promptly, establish what data was affected, inform affected individuals in clear language where there's a risk to them, and take steps to prevent further harm — for example, recommending a password change where relevant.
12. Changes to this policy
We may update this policy from time to time. The current version is always available on request, and any material changes will be communicated to enrolled families.
If you have any questions about this policy, or want to exercise your data rights, contact:
Let's Pass, 36 Little Gaynes Lane, Upminster, RM14 2JJ
Email: lorraine@letspassgcsemaths.co.uk
Phone: 07538 957492
14. How to complain
If you're unhappy with how we've collected, used, or protected your (or your child's) personal data, we'd like the chance to put it right first. Contact us using the details above and we'll respond promptly, following our Complaints Procedure.
If you're not satisfied with our response, or would prefer to raise it directly, you can complain to the Information Commissioner's Office (ICO), the UK's independent regulator for data protection:
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Last updated: 9 September 2026