Skip to content
Journey
PlatformJourney AIMerituraPricingResources
Book a walkthrough
Journey/LEGAL & PRIVACY
LEGAL & PRIVACY

Data processing terms

The UK GDPR Article 28 processor terms that apply to every Journey workspace.

Version 2026-10. Last updated: 6 October 2026

These are the data processing terms for every Journey provider workspace. They set out the processor terms required by Article 28 of the UK GDPR. The provider accepts them once, when its workspace is created, and they apply to Journey Core and Journey Advanced alike.

Who these terms are between

The processor is Tech Geek UK Ltd, which operates Journey. It is a company registered in England and Wales (company number 09834597), registered office Rourke House, Kingsbury Crescent, Watermans Business Park, Staines-upon-Thames, TW18 3BA. ICO registration ZA511007. The controller is the training provider (“you”) whose workspace holds the apprenticeship records. Contact is by email only: privacy@journeyapp.co.uk.

When these terms apply

You accept these terms when an authorised person creates your workspace, and they apply for as long as Journey processes personal data for you. A signed agreement can add to them. Where it covers the same point, the signed agreement prevails, but nothing in it reduces the protections below. Each version has a label, shown at the top of this page, and Journey records which version your workspace accepted. If we change these terms, we will give you at least 30 days’ notice by email and in the app, unless the change is required by law.

1. Documented instructions

We process your personal data only on your documented instructions. Those instructions are these terms, the signed agreement if there is one, and the way your authorised users configure and use Journey. This includes transfers outside the UK. If the law requires us to process data in another way, we will tell you first unless the law forbids it. If we think an instruction breaks data protection law, we will tell you straight away.

2. Confidentiality

Everyone at Journey who can access your personal data is bound by a duty of confidentiality, through their contract or a statutory duty. Access is limited to the people who need it to run, support or secure the service.

3. Security

We take the technical and organisational measures required by Article 32 of the UK GDPR. They include encryption in transit and at rest, tenant isolation using server-derived workspace context, role-based access control, multi-factor sign-in for staff, audit logging of significant actions, virus scanning of uploads, backups, and tested incident response. Tech Geek UK Ltd’s information security management system is certified to ISO/IEC 27001:2022. The certificate covers the company’s management system. The full measures are described on our security page and in our due-diligence pack.

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours. We will give you the information you need to meet your own reporting duties, and keep you updated as we learn more.

4. Sub-processors

You give general authorisation for us to use the sub-processors listed on our sub-processors page. Before we add or replace a sub-processor, we will give you at least 30 days’ notice by email to your workspace administrators and on that page. You may object on reasonable data protection grounds within that period. We will then work with you in good faith to resolve it. If we cannot, you may end the affected service without penalty, and we will refund any fees you have paid for the period after it ends.

Each sub-processor is bound by a written contract with data protection obligations at least as protective as these terms. We remain responsible to you for how our sub-processors handle your data.

5. Help with data-subject rights

Journey gives you tools to answer requests from apprentices, employers and staff, including a per-apprentice data export. If someone sends a request to us directly, we will pass it to you promptly and will not answer it ourselves unless you ask us to. Where the tools are not enough, we will help you respond to requests to access, correct, delete, restrict, move or object to the use of personal data.

6. Help with your other duties

Taking into account what we know about the processing, we will help you meet your duties under Articles 32 to 36 of the UK GDPR. That covers security, breach notification to the ICO and to the people affected, data protection impact assessments, and any prior consultation with the ICO.

7. Delete or return at the end

When the service ends, you can export your workspace data for 30 days. At the end of that period we delete your personal data, unless you ask us in writing to return it instead or the law requires us to keep it. Deletion from backups follows within a further 35 days, as backups expire. Records you must keep under DWP funding rules are your responsibility to export and keep before deletion. We will confirm deletion in writing if you ask.

8. Audits and information

We will give you the information you need to show that these terms are being met. This includes our security documentation, our ISO/IEC 27001:2022 certificate and answers to reasonable due-diligence questions. You, or an independent auditor you appoint who is bound by confidentiality, may audit our compliance once a year on 30 days’ written notice, or at any time after a personal data breach or at the request of a regulator. Audits take place during working hours and in a way that protects other customers’ data.

9. International transfers

Your workspace data is held in the UK. Some sub-processors are based in the United States or handle data there, as shown on the sub-processors page. We only make those transfers with one of the safeguards UK law allows. Where the supplier is certified to the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge), the transfer relies on the UK’s adequacy regulations for that framework. Otherwise it relies on the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, in the supplier’s data processing terms, together with a transfer risk assessment. The sub-processors page shows which safeguard each supplier uses. If a supplier’s certification lapses, we rely on the contractual clauses in its terms or stop the transfer.

10. No AI training on your data

Journey never uses customer data to train its own AI models or anyone else’s. We only use AI suppliers whose terms do not allow them to train their models on the data Journey sends them. Journey’s AI features process your data only to produce the draft, answer or summary your users ask for.

Annex: details of the processing

Subject matter and purpose: providing Journey, an apprenticeship management platform, so that you can manage apprentices, employers, off-the-job training, evidence, progress reviews, end-point assessment, funding and ILR returns, together with support, security and service diagnostics.

Duration: for as long as your workspace is active, then the export and deletion periods in section 7.

Nature of the processing: collection, storage, organisation, retrieval, analysis, AI-assisted drafting, transmission, export and deletion.

Data subjects: apprentices, employer contacts, your staff and other users you invite.

Personal data: names and contact details; learner identifiers and ILR fields; employer and programme details; off-the-job hours; evidence and uploaded files; review notes and assessment outcomes; meeting transcripts where you connect Google Meet or Microsoft Teams; sign-in and audit records; and support messages.

Special category data: only where you choose to record it, for example disability, learning difficulty or health information used to plan reasonable adjustments, or equality and diversity data required for the ILR.

Contact

Contact is by email only. For anything about these terms, email privacy@journeyapp.co.uk.

On this page
  1. Who these terms are between
  2. When these terms apply
  3. 1. Documented instructions
  4. 2. Confidentiality
  5. 3. Security
  6. 4. Sub-processors
  7. 5. Help with data-subject rights
  8. 6. Help with your other duties
  9. 7. Delete or return at the end
  10. 8. Audits and information
  11. 9. International transfers
  12. 10. No AI training on your data
  13. Annex: details of the processing
  14. Contact
Questions about this document? Contact the team.
Keep reading

Related pages.

Trust

Security

Access controls, tenant isolation, audit history and governed AI.

Trust

Responsible AI

How Journey uses AI: answers cite records, people decide.

Legal

Data processing

Controller and processor roles, sub-processors and retention.

Related policies.

Sub-processorsPrivacy policyTerms of service

See what changes
when it all connects.

Bring your learners’ journey, your team’s questions and your next ambition.

Book a walkthrough Apply for Core access Explore Core & Advanced
JourneyEvery learner.
A clear next step.

Platform

OverviewAll featuresJourney AIMIS & deliveryDelivery softwareePortfolio & OTJFunding & ILRGateway & EPAMeritura connectionAssessment operations

Managed services

All managed servicesCurriculum & contentCompliance & ILRAssessment & IQATutor talent poolEmployer growthMarketing & recruitment

Your team

Training providersCollegesIndependent providersEmployer-providersEmployersApprenticesEmployer portalLearner portalData & integrations

Explore

Journey CoreJourney AdvancedPricingBuyer’s guideCompare platformsResourcesOTJ calculatorILR calendarGlossary

Alternatives

Aptem alternativeOneFile alternativeBud alternativeSmart Assessor alternativePICS alternativeMaytas alternativeHow we compareTotal cost of ownershipApprenticeship management system

Trust & company

About JourneyMeet the founderContactSecurityAssuredResponsible AISafeguarding & PreventAccessibilitySubprocessorsData processing

Start your journey

Book a walkthrough Apply for Core accessSign in to Journey Meet Meritura

TechGeek UK certifications

A product of Tech Geek UK Ltd. Covered by the company’s certified management systems.

Citation combined ISO 9001:2015 and ISO/IEC 27001:2022 certification mark

ISO 9001:2015 and ISO/IEC 27001:2022
Certificate 523362026

Citation ISO/IEC 42001:2023 certification mark

ISO/IEC 42001:2023
Certificate 523352026

Cyber Essentials Certified mark

Cyber Essentials Certified

These marks relate to Tech Geek UK Ltd’s management systems and do not certify or endorse Journey as a separate product.

© 2026 Journey
PrivacyTermsCookiesAcceptable useModern slaveryDelete account

Journey is independent and is not affiliated with DWP, DfE or Ofsted. Illustrative learner records and guided AI responses in website demonstrations.

Journey is a product of Tech Geek UK Ltd, company 09834597, ICO registration ZA511007. Registered office: Rourke House, Kingsbury Crescent, Watermans Business Park, Staines-upon-Thames, TW18 3BA.