SystemShift Logo
SystemShiftLeadership development platform

Data Handling Policy

SystemShift Leadership Development Platform

GDPR Compliant

Version1.0
Issue Date01 June 2026
Review DateAnnually or upon material change
Document OwnerData Protection Officer
ClassificationInternal / Participant-facing

1. Introduction and Scope

This Data Handling Policy (“Policy”) sets out how SystemShift Ltd (“we”, “us”, “the Organisation”) collects, uses, stores, shares, and protects personal data in connection with our Learning Management System (“LMS”) and the four bespoke training programmes delivered through it.

This Policy is issued in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) and reflects the principles of the EU GDPR where applicable. It applies to all staff, trainers, administrators, and third-party processors who handle personal data as part of LMS operations.

The LMS delivers the following four training programmes:

  • Programme 1: Leading Strategic Change: The Step Up, Step Back Approach
  • Programme 2: How to develop your Strategy and set up your Organisation to Deliver
  • Programme 3: How to get More out of your People
  • Programme 4: How to have ‘Difficult’ Conversations More Effectively

The LMS also has two public-facing portals:

  • The “L&D Manager” portal, used by the individual responsible for managing participants within an organisation (“L&D manager portal”).
  • The “Participant” portal, used by those who are enrolled on one or more of SystemShift's four training programmes to complete their programme (“participant portal”).

2. Data Controller Details

For the purposes of the UK GDPR, SystemShift Ltd is the Data Controller in respect of all personal data processed through the LMS.

FieldDetail
OrganisationSystemShift LTD
Registered Address6th Floor Kings House, 9-10 Haymarket, London, United Kingdom, SW1Y 4BP
ICO Registration NumberZC171745
Data Protection Officer (DPO)Elsbeth Johnson, Managing Director
DPO Contact EmailEnquiries@SystemShift.com

Where a client organisation procures licences to SystemShift's programmes and is granted access to the LMS, that organisation may act as a joint controller or separate controller for certain processing activities. A Data Processing Agreement (“DPA”) will be entered into with all such organisations.

3. Personal Data We Collect

3.1 Account Registration Data

When participants or L&D managers register for and use the LMS, we collect the following personal data directly from them:

Data ElementData SubjectSourcePurpose
Full NameParticipant / L&D ManagerAccount registrationIdentity and programme administration
Job Role / TitleParticipant / L&D ManagerAccount registrationAllocating appropriate training programmes
Work Email AddressParticipant / L&D ManagerAccount registrationAuthentication, notifications, correspondence
Password (hashed)Participant / L&D ManagerAccount creationSecure authentication
Organisation / DepartmentParticipant / L&D ManagerAccount registrationCohort management and reporting

3.2 Calendar Integration Data

Calendar integration is a requirement of onboarding to the SystemShift LMS platform. Where participant or L&D Manager users connect their Microsoft Outlook or Google Calendar accounts to the LMS, we access the following calendar data via secure OAuth 2.0 authorisation:

  • Calendar event titles and descriptions (to schedule and surface training sessions)
  • Meeting availability and free/busy status (to recommend optimal scheduling)
  • Event dates and times (to create and update LMS-generated calendar entries)

Important – Scope of Calendar Access

We access only the minimum calendar data necessary for scheduling purposes. We do not read, store, or process personal or confidential content from calendar events unrelated to LMS training activities.

Calendar integration is a requirement of onboarding and access to the programme and is not optional. If a participant does not wish to connect their calendar, they will not be able to access any training programme.

Calendar access tokens are revocable by the participant at any time through their Microsoft or Google account settings. Participants should contact their L&D manager to understand how revoking their tokens will impact progress through their programme.

3.3 Programme Participation Data

While delivering the four training programmes, we collect the following data generated by participant activity:

  • Written responses to course questions, exercises, and reflective activities
  • Module and session progress and timestamps
  • Feedback and evaluation responses
  • Certificates of completion

We may, from time to time, wish to publish quotes based on participant feedback. We will not do this without the explicit consent of the participant.

3.4 Technical and Log Data

Our systems automatically collect limited technical data when participants access the LMS:

  • IP address and browser/device type (for security and audit purposes)
  • Login timestamps and session durations
  • System error and access logs

4. Lawful Basis for Processing

We rely on the following lawful bases under Article 6 UK GDPR for each category of processing:

Processing ActivityLawful Basis
Account registration and authenticationContract (Art. 6(1)(b)) – necessary to provide access to the LMS
Programme delivery and progress trackingContract (Art. 6(1)(b)) – necessary to deliver the agreed training
Written responses to course questionsContract (Art. 6(1)(b)) – integral to programme delivery; Legitimate Interests (Art. 6(1)(f)) – improving programme quality
Calendar integrationConsent (Art. 6(1)(a)) – participants expressly authorise access via OAuth
Management reporting and oversightLegitimate Interests (Art. 6(1)(f)) – lawful employer oversight of training; balanced against participant privacy
Security logging and fraud preventionLegal Obligation (Art. 6(1)(c)) / Legitimate Interests (Art. 6(1)(f))
Compliance with legal obligationsLegal Obligation (Art. 6(1)(c))

Where we rely on Legitimate Interests, a Legitimate Interests Assessment (LIA) has been carried out and is available upon request from the DPO.

5. Special Category and Sensitive Data

The LMS is not designed to collect special category personal data as defined by Article 9 UK GDPR (e.g. health data, race/ethnicity, political opinions, religious beliefs).

However, participants should be aware that written responses submitted to course questions are free-form in nature. Participants are advised not to include sensitive personal information about themselves or third parties in their course responses beyond what is required to answer the questions set.

If a participant inadvertently discloses special category data within a course response, such data will be handled with heightened care and restricted access controls, and the participant will be notified.

6. How We Use Personal Data

We use the personal data collected through the LMS for the following purposes:

  • Registering and managing participant and L&D manager accounts
  • Authenticating users and maintaining platform security
  • Delivering the four training programmes and tracking progress
  • Scheduling and sending programme-related calendar invitations and reminders
  • Providing L&D managers with progress reports on their team members' participation and completion
  • Generating anonymised aggregate analytics to evaluate and improve programme effectiveness
  • Complying with legal and regulatory obligations
  • Responding to data subject rights requests

We will not use personal data for automated decision-making or profiling that produces legal or similarly significant effects without explicit consent.

7. Data Sharing and Recipients

7.1 Internal Access

Access to personal data within the Organisation is restricted on a strict need-to-know basis:

RoleAccess Scope
Programme AdministratorsAccount management, scheduling, and reporting
Training Facilitators / CoachesProgramme delivery; access to participant responses relevant to their programme only
IT / Platform TeamSystem maintenance and security; no routine access to content data
Data Protection OfficerCompliance oversight, rights request handling
Senior ManagementAnonymised aggregate programme reports only

7.2 Third-Party Processors

We engage the following categories of third-party data processors who act under our written instructions and are bound by a Data Processing Agreement:

  • LMS Platform Provider – hosting and software infrastructure
  • Cloud hosting and storage provider (e.g. AWS / Azure / GCP)
  • Microsoft and Google – solely in connection with calendar integration (OAuth access governed by their respective privacy policies and terms)
  • Email delivery provider – for system notifications
  • Analytics provider – receives only anonymised or aggregated data

A register of all third-party processors is maintained by the DPO and is reviewed annually. All processors are assessed for adequacy of their technical and organisational security measures prior to engagement.

7.3 Disclosure to Client Organisations

Where the LMS is deployed on behalf of a client organisation, we may share participant progress and completion data with designated managers or HR administrators within that organisation. The extent of such sharing is governed by the Data Processing Agreement between us and the client and participants are informed of this sharing at registration.

7.4 Legal Disclosure

We may disclose personal data to law enforcement, regulatory authorities, or courts where required by law, or where necessary to protect the rights, property, or safety of the Organisation, its participants, or others.

8. International Data Transfers

We endeavour to process and store all personal data within the UK or European Economic Area (EEA). Where any transfer to a third country outside the UK/EEA is necessary (for example, through the use of global cloud infrastructure), we ensure that an appropriate safeguard is in place, including:

  • An adequacy decision by the UK Secretary of State or European Commission
  • UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs) where applicable

Details of any international transfers and the safeguards applied are available from the DPO upon request.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following retention periods apply:

Data CategoryRetention PeriodRationale
Account data (name, role, email)Duration of active enrolment + 2 yearsLegitimate interests; post-programme support
Programme completion records and certificates6 years from completion dateLegal obligation; potential employment/audit reference
Written course responses2 years from programme completionProgramme quality assurance; dispute resolution
Management reports3 years from issue dateLegitimate interests; HR audit trail
Calendar integration tokensUntil revoked by participant or account deletionConsent-based; revocable at any time
Security and access logs12 monthsSecurity monitoring; incident investigation
Technical log data90 days (rolling)System stability and fraud prevention

At the end of the applicable retention period, data is securely deleted or anonymised in accordance with our Data Destruction Procedure.

10. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration, including:

10.1 Technical Controls

  • One-Time Password is used for all participant and L&D manager accounts.
  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using industry-standard AES-256
  • OAuth 2.0 protocol for calendar integrations (no passwords stored for Microsoft or Google)
  • Secure access controls and role-based permissions limiting access to personal data
  • Regular automated security patching and vulnerability scanning
  • Penetration testing conducted at least annually

10.2 Organisational Controls

  • Data protection and information security training for all staff with access to the LMS
  • Data protection impact assessments (DPIAs) conducted for high-risk processing activities
  • Confidentiality obligations for all staff and processors
  • An incident response and breach notification procedure
  • Regular audits of access controls and data holdings

11. Data Subject Rights

As a data subject, participants and managers have the following rights under the UK GDPR, which can be exercised free of charge:

RightDescription
Right of Access (SAR)Request a copy of the personal data we hold about you and information about how it is used.
Right to RectificationRequest correction of inaccurate or incomplete personal data.
Right to Erasure ('Right to be Forgotten')Request deletion of your personal data where there is no overriding legal basis for retention.
Right to Restrict ProcessingRequest that we limit how we use your data in certain circumstances.
Right to Data PortabilityReceive your data in a structured, commonly used, machine-readable format (applies to consent or contract-based processing).
Right to ObjectObject to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw ConsentWhere processing is based on consent (e.g. calendar integration), withdraw consent at any time without affecting prior processing.
Rights re Automated DecisionsNot be subject to solely automated decisions that produce significant effects, without human review.

To exercise any of these rights, please contact the DPO at Enquiries@SystemShift.com. We will respond within one calendar month of receiving a valid request. We may request proof of identity before processing a rights request.

If you are dissatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk or by telephone on 0303 123 1113.

12. Consent and Withdrawal

Where we rely on consent as the lawful basis for processing (currently limited to calendar integration), participants are informed at the point of connection of exactly what data will be accessed and for what purpose.

Consent is obtained separately from acceptance of general terms and conditions and is granular – participants can connect their calendar without accepting any unrelated data use.

Participants may withdraw consent for calendar integration at any time by:

  • Disconnecting the integration within their LMS account settings, or
  • Revoking access directly through their Microsoft or Google account settings

Withdrawal of consent will not affect the lawfulness of any processing that took place prior to withdrawal, nor will it affect participation in any training programme.

13. Data Protection Impact Assessment

We have conducted a Data Protection Impact Assessment (DPIA) covering the LMS and its core processing activities, including the collection of written participant responses and integration with third-party calendar services. The DPIA is reviewed annually and following any material change to the system or processing activities.

Copies of DPIAs are maintained by the DPO. Participants or client organisations may request a summary upon reasonable request.

14. Children's Data

The LMS is intended solely for use by adults (individuals aged 18 years or over) in a professional capacity. We do not knowingly collect or process personal data relating to children. If we become aware that a child has registered for the LMS, we will promptly delete their account and associated personal data.

15. Cookies and Tracking Technologies

The LMS uses cookies and similar technologies to maintain session authentication, remember user preferences, and support platform security. A separate Cookie Policy is available within the LMS interface. Non-essential cookies require prior consent, which may be managed through the cookie preference centre.

16. Changes to This Policy

We review this Policy at least annually and following any significant change to our processing activities, applicable law, or ICO guidance. Material changes will be communicated to participants and client organisations by email and via a notice on the LMS platform. The version history below records all substantive amendments.

VersionDateApproved BySummary of Changes
1.029 April 2026Data Protection OfficerInitial issue

17. Contact and Further Information

If you have any questions about this Policy, how we handle your personal data, or wish to exercise your data subject rights, please contact:

Data Protection Officer Contact

Name: Elsbeth Johnson

Role: Data Protection Officer

Email: Enquiries@SystemShift.com

For complaints about the handling of your personal data, you may also contact the UK Information Commissioner's Office:

  • Website: www.ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF