Data processing terms
The UK GDPR Article 28 processor terms that apply to every Journey workspace.
Version 2026-10. Last updated: 6 October 2026
These are the data processing terms for every Journey provider workspace. They set out the processor terms required by Article 28 of the UK GDPR. The provider accepts them once, when its workspace is created, and they apply to Journey Core and Journey Advanced alike.
Who these terms are between
The processor is Tech Geek UK Ltd, which operates Journey. It is a company registered in England and Wales (company number 09834597), registered office Rourke House, Kingsbury Crescent, Watermans Business Park, Staines-upon-Thames, TW18 3BA. ICO registration ZA511007. The controller is the training provider (“you”) whose workspace holds the apprenticeship records. Contact is by email only: privacy@journeyapp.co.uk.
When these terms apply
You accept these terms when an authorised person creates your workspace, and they apply for as long as Journey processes personal data for you. A signed agreement can add to them. Where it covers the same point, the signed agreement prevails, but nothing in it reduces the protections below. Each version has a label, shown at the top of this page, and Journey records which version your workspace accepted. If we change these terms, we will give you at least 30 days’ notice by email and in the app, unless the change is required by law.
1. Documented instructions
We process your personal data only on your documented instructions. Those instructions are these terms, the signed agreement if there is one, and the way your authorised users configure and use Journey. This includes transfers outside the UK. If the law requires us to process data in another way, we will tell you first unless the law forbids it. If we think an instruction breaks data protection law, we will tell you straight away.
2. Confidentiality
Everyone at Journey who can access your personal data is bound by a duty of confidentiality, through their contract or a statutory duty. Access is limited to the people who need it to run, support or secure the service.
3. Security
We take the technical and organisational measures required by Article 32 of the UK GDPR. They include encryption in transit and at rest, tenant isolation using server-derived workspace context, role-based access control, multi-factor sign-in for staff, audit logging of significant actions, virus scanning of uploads, backups, and tested incident response. Tech Geek UK Ltd’s information security management system is certified to ISO/IEC 27001:2022. The certificate covers the company’s management system. The full measures are described on our security page and in our due-diligence pack.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours. We will give you the information you need to meet your own reporting duties, and keep you updated as we learn more.
4. Sub-processors
You give general authorisation for us to use the sub-processors listed on our sub-processors page. Before we add or replace a sub-processor, we will give you at least 30 days’ notice by email to your workspace administrators and on that page. You may object on reasonable data protection grounds within that period. We will then work with you in good faith to resolve it. If we cannot, you may end the affected service without penalty, and we will refund any fees you have paid for the period after it ends.
Each sub-processor is bound by a written contract with data protection obligations at least as protective as these terms. We remain responsible to you for how our sub-processors handle your data.
5. Help with data-subject rights
Journey gives you tools to answer requests from apprentices, employers and staff, including a per-apprentice data export. If someone sends a request to us directly, we will pass it to you promptly and will not answer it ourselves unless you ask us to. Where the tools are not enough, we will help you respond to requests to access, correct, delete, restrict, move or object to the use of personal data.
6. Help with your other duties
Taking into account what we know about the processing, we will help you meet your duties under Articles 32 to 36 of the UK GDPR. That covers security, breach notification to the ICO and to the people affected, data protection impact assessments, and any prior consultation with the ICO.
7. Delete or return at the end
When the service ends, you can export your workspace data for 30 days. At the end of that period we delete your personal data, unless you ask us in writing to return it instead or the law requires us to keep it. Deletion from backups follows within a further 35 days, as backups expire. Records you must keep under DWP funding rules are your responsibility to export and keep before deletion. We will confirm deletion in writing if you ask.
8. Audits and information
We will give you the information you need to show that these terms are being met. This includes our security documentation, our ISO/IEC 27001:2022 certificate and answers to reasonable due-diligence questions. You, or an independent auditor you appoint who is bound by confidentiality, may audit our compliance once a year on 30 days’ written notice, or at any time after a personal data breach or at the request of a regulator. Audits take place during working hours and in a way that protects other customers’ data.
9. International transfers
Your workspace data is held in the UK. Some sub-processors are based in the United States or handle data there, as shown on the sub-processors page. We only make those transfers with one of the safeguards UK law allows. Where the supplier is certified to the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge), the transfer relies on the UK’s adequacy regulations for that framework. Otherwise it relies on the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, in the supplier’s data processing terms, together with a transfer risk assessment. The sub-processors page shows which safeguard each supplier uses. If a supplier’s certification lapses, we rely on the contractual clauses in its terms or stop the transfer.
10. No AI training on your data
Journey never uses customer data to train its own AI models or anyone else’s. We only use AI suppliers whose terms do not allow them to train their models on the data Journey sends them. Journey’s AI features process your data only to produce the draft, answer or summary your users ask for.
Annex: details of the processing
Subject matter and purpose: providing Journey, an apprenticeship management platform, so that you can manage apprentices, employers, off-the-job training, evidence, progress reviews, end-point assessment, funding and ILR returns, together with support, security and service diagnostics.
Duration: for as long as your workspace is active, then the export and deletion periods in section 7.
Nature of the processing: collection, storage, organisation, retrieval, analysis, AI-assisted drafting, transmission, export and deletion.
Data subjects: apprentices, employer contacts, your staff and other users you invite.
Personal data: names and contact details; learner identifiers and ILR fields; employer and programme details; off-the-job hours; evidence and uploaded files; review notes and assessment outcomes; meeting transcripts where you connect Google Meet or Microsoft Teams; sign-in and audit records; and support messages.
Special category data: only where you choose to record it, for example disability, learning difficulty or health information used to plan reasonable adjustments, or equality and diversity data required for the ILR.
Contact
Contact is by email only. For anything about these terms, email privacy@journeyapp.co.uk.
Related pages.
See what changes
when it all connects.
Bring your learners’ journey, your team’s questions and your next ambition.