Privacy policy
Last updated: 12 August 2026 · Terms of service · Sub-processors
Journey ("we", "us") provides software for UK apprenticeship training providers to manage learners, employers, evidence, on-the-job training, reviews, and end-point assessment. This page explains what personal data we process and how we look after it. It is written to be readable; legal terms are linked where relevant.
Controller and processor roles
For an approved provider workspace, the contracting entity and the controller/processor roles are identified in the written pilot or commercial agreement. The intended model for provider-held apprentice, employer and staff records is that the provider is the controller and Journey processes data on its documented instructions. Please do not send learner or special-category data through public enquiry forms.
What we collect
- Account data: name, email, organisation, role.
- Apprentice records: learner identifiers, employer affiliation, programme, progress, on-the-job hours, evidence uploads, review notes, EPA outcomes, ILR-relevant fields.
- Operational data: audit log of significant actions (who did what and when), AI usage metering, billing status, support tickets, and service diagnostics. Diagnostics can include the authenticated user ID, name and email, tenant, role, entitlement, route, workflow, release, request/session correlation, error, performance and bounded replay context.
- Cookies: a strictly-necessary session cookie to keep you signed in; optional analytics cookies only after consent via the banner.
Service diagnostics
Journey uses Sentry for operational error, performance and replay diagnostics needed to secure and maintain the service. With your analytics consent, PostHog records product analytics and session replay so authorised Journey operators can reproduce failures and understand workflow friction. These services are not used for advertising or automated decisions.
Normal account, tenant and workflow context is retained when it is needed to investigate an incident. Journey excludes credentials, authentication and session tokens, API keys, payment-card data, raw signature strokes and document/upload bytes. Typed fields and explicitly sensitive interface areas are masked or blocked from replay.
Lawful basis
The applicable written agreement identifies the controller's lawful basis and Journey's processing instructions for an approved workspace. For a public product enquiry, we use the details supplied to respond to the request and progress a requested evaluation.
How long we keep it
Retention for an approved provider workspace is agreed in writing and may be affected by statutory or funding-rule requirements. We retain public enquiry details only as long as needed to respond, follow up appropriately and meet any applicable legal obligation. Diagnostic and replay retention is configured separately and kept proportionate to incident investigation; the dedicated PostHog EU project retains new session recordings for no more than 30 days on its current plan.
Where it lives
Approved production processing services are listed in our current sub-processor register. Journey does not sell personal data. The signed agreement identifies the applicable processing location and transfer safeguards for the provider arrangement.
AI features
Journey Advance AI is governed, tenant-bound and available only after provider, DPIA and release approval. For an authorised request it may process bounded learner-authored workflow content to prepare a draft or K/S suggestion. Pattern-based redaction is applied where direct identifiers are detected but cannot guarantee that all personal data is removed; credentials, payment data, raw signatures and document bytes are excluded. It assists authorised users and does not make regulated decisions or automatically change the underlying record. Availability and the applicable processor are disclosed during provider due diligence.
Your rights (UK GDPR)
- Access: request a copy of your data.
- Rectification: correct anything inaccurate.
- Erasure: ask us to delete your data subject to retention obligations.
- Portability: per-apprentice data can be exported as a JSON bundle from the apprentice page (Subject Access Request).
- Objection / restriction: ask us to stop or limit a particular use.
For an active provider workspace, contact your provider's data protection lead. For a public enquiry, use the Journey contact page and identify the email address used for the enquiry.
Contact
Use the Journey contact page. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.