Skip to content
Journey
PlatformJourney AIMerituraPricingResources
Book a walkthrough
Journey/LEGAL & PRIVACY
LEGAL & PRIVACY

Privacy policy

Last updated: 27 August 2026 · Terms of service · Sub-processors

The public marketing website loads Google Analytics only after you accept analytics. It does not enable session recording. Review copies load neither analytics nor session recording. The application diagnostics described below apply to the signed-in service where configured; optional analytics require the applicable consent.

Journey ("we", "us") provides software for UK apprenticeship training providers to manage learners, employers, evidence, off-the-job training, reviews, and end-point assessment. This page explains what personal data we process and how we look after it. It is written to be readable; legal terms are linked where relevant.

Who we are

Journey is operated by Tech Geek UK Ltd, a company registered in England and Wales (company number 09834597), registered office Rourke House, Kingsbury Crescent, Watermans Business Park, Staines-upon-Thames, TW18 3BA. Tech Geek UK Ltd is the data controller for this website, for enquiry and application forms and for marketing analytics. ICO registration ZA511007. Contact: privacy@journeyapp.co.uk (email only).

Controller and processor roles

For an approved provider workspace, the provider is the controller of apprentice, employer and staff records. Tech Geek UK Ltd acts as processor for those records under the written agreement. It processes them only on the provider's documented instructions. Please do not send learner or special-category data through public enquiry forms.

What we collect

  • Account data: name, email, organisation, role.
  • Apprentice records: learner identifiers, employer affiliation, programme, progress, off-the-job hours, evidence uploads, review notes, EPA outcomes, ILR-relevant fields.
  • Operational data: audit log of significant actions (who did what and when), AI usage metering, billing status, support tickets, and service diagnostics. Diagnostics can include the authenticated user ID, name and email, tenant, role, entitlement, route, workflow, release, request/session correlation, error, performance and bounded replay context.
  • Cookies: a strictly-necessary session cookie to keep you signed in; optional analytics cookies only after consent via the banner.

Service diagnostics

Journey uses Sentry for operational error, performance and replay diagnostics needed to secure and maintain the service. With your analytics consent, PostHog records product analytics and session replay so authorised Journey operators can reproduce failures and understand workflow friction. These services are not used for advertising or automated decisions.

Normal account, tenant and workflow context is retained when it is needed to investigate an incident. Journey excludes credentials, authentication and session tokens, API keys, payment-card data, raw signature strokes and document/upload bytes. Typed fields and explicitly sensitive interface areas are masked or blocked from replay.

Lawful basis

The applicable written agreement identifies the controller's lawful basis and Journey's processing instructions for an approved workspace. For a public product enquiry, we use the details supplied to respond to the request and progress a requested evaluation.

How long we keep it

Retention for an approved provider workspace is agreed in writing and may be affected by statutory or funding-rule requirements. We retain public enquiry details only as long as needed to respond, follow up appropriately and meet any applicable legal obligation. Diagnostic and replay retention is configured separately and kept proportionate to incident investigation; the dedicated PostHog EU project retains new session recordings for no more than 30 days on its current plan.

Where it lives

Approved production processing services are listed in our current sub-processor register. Journey does not sell personal data. The sub-processor register shows where each supplier processes data and the safeguard used for any transfer outside the UK, and our data processing terms explain how those transfers are protected.

AI features

Journey Advanced has distinct AI workflows. Programme-bound evidence and feedback assistance processes the authorised content needed for that request. Conversational Journey AI retrieves permitted record facts using application-controlled tools and may send the context needed to generate an answer through the configured AI service. Neither workflow gives a model unrestricted database access or authority to make regulated decisions. Journey never uses customer data to train its own AI models or anyone else’s. We only use AI suppliers whose terms do not allow them to train their models on the data Journey sends them. Data categories, model routing, retention, safeguards and provider approvals must be confirmed for each enabled workflow in the signed data-processing arrangements. Controls documented for one workflow must not be assumed to cover another. Do not place credentials, payment data or unnecessary sensitive learner information in a question. See Responsible AI and the sub-processor register for the relevant scope.

Your rights (UK GDPR)

  • Access: request a copy of your data.
  • Rectification: correct anything inaccurate.
  • Erasure: ask us to delete your data subject to retention obligations.
  • Portability: per-apprentice data can be exported as a JSON bundle from the apprentice page (Subject Access Request).
  • Objection / restriction: ask us to stop or limit a particular use.

For an active provider workspace, contact your provider's data protection lead. That route can also be used to challenge an AI draft/suggestion, correct the underlying source record or ask to restrict further AI processing. For a public enquiry, email privacy@journeyapp.co.uk and identify the email address used for the enquiry.

Contact

Contact is by email only. Email privacy@journeyapp.co.uk with a data protection question or a rights request. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

On this page
  1. Who we are
  2. Controller and processor roles
  3. What we collect
  4. Service diagnostics
  5. Lawful basis
  6. How long we keep it
  7. Where it lives
  8. AI features
  9. Your rights (UK GDPR)
  10. Contact
Questions about this document? Contact the team.
Keep reading

Related pages.

Legal

Privacy policy

What we collect, why, and your rights under UK GDPR.

Trust

Security

Documented product controls and access management.

Company

Contact

Email the team for company, procurement or security questions.

Related policies.

Cookie policyTerms of serviceAcceptable use policyData processing information

See what changes
when it all connects.

Bring your learners’ journey, your team’s questions and your next ambition.

Book a walkthrough Apply for Core access Explore Core & Advanced
JourneyEvery learner.
A clear next step.

Platform

OverviewAll featuresJourney AIMIS & deliveryDelivery softwareePortfolio & OTJFunding & ILRGateway & EPAMeritura connectionAssessment operations

Managed services

All managed servicesCurriculum & contentCompliance & ILRAssessment & IQATutor talent poolEmployer growthMarketing & recruitment

Your team

Training providersCollegesIndependent providersEmployer-providersEmployersApprenticesEmployer portalLearner portalData & integrations

Explore

Journey CoreJourney AdvancedPricingBuyer’s guideCompare platformsResourcesOTJ calculatorILR calendarGlossary

Alternatives

Aptem alternativeOneFile alternativeBud alternativeSmart Assessor alternativePICS alternativeMaytas alternativeHow we compareTotal cost of ownershipApprenticeship management system

Trust & company

About JourneyMeet the founderContactSecurityAssuredResponsible AISafeguarding & PreventAccessibilitySubprocessorsData processing

Start your journey

Book a walkthrough Apply for Core accessSign in to Journey Meet Meritura

TechGeek UK certifications

A product of Tech Geek UK Ltd. Covered by the company’s certified management systems.

Citation combined ISO 9001:2015 and ISO/IEC 27001:2022 certification mark

ISO 9001:2015 and ISO/IEC 27001:2022
Certificate 523362026

Citation ISO/IEC 42001:2023 certification mark

ISO/IEC 42001:2023
Certificate 523352026

Cyber Essentials Certified mark

Cyber Essentials Certified

These marks relate to Tech Geek UK Ltd’s management systems and do not certify or endorse Journey as a separate product.

© 2026 Journey
PrivacyTermsCookiesAcceptable useModern slaveryDelete account

Journey is independent and is not affiliated with DWP, DfE or Ofsted. Illustrative learner records and guided AI responses in website demonstrations.

Journey is a product of Tech Geek UK Ltd, company 09834597, ICO registration ZA511007. Registered office: Rourke House, Kingsbury Crescent, Watermans Business Park, Staines-upon-Thames, TW18 3BA.