Privacy policy
Last updated 24 August 2026. This policy explains how C&G Education (“we”) uses personal data in C&G Nest. It should be read with our UK GDPR statement, which sets out lawful bases and your rights in more detail.
1. Who we are
C&G Education is the data controller for personal data processed in C&G Nest. We are a UK alternative provision supporting children and young people, including those with SEND and SEMH needs. Contact details are at the end of this page.
2. Whose data we process
- Students on our programmes (including children and young people aged 15–25).
- Parents, carers, and other emergency or professional contacts.
- Staff, contractors, and applicants (HR, safer recruitment, payroll, training).
- Users of the admin panel, staff portal, and family portal (account and security data).
3. What we collect
Depending on your relationship with us, this may include:
- identity and contact details (name, date of birth, address, email, telephone);
- education records (sessions, plans, logs, attendance, targets, destinations, documents);
- special category data such as SEND, health, and wellbeing information where needed to support the student;
- safeguarding concerns and related notes, visible only to authorised safeguarding roles;
- staff employment data, including DBS, training, right-to-work, and (for finance roles) bank details;
- account data: sign-in email, password hash, optional authenticator-app configuration, and security logs;
- essential cookies needed to keep you signed in and protect forms — see our cookie policy .
4. Why we use it
We use personal data to deliver education, keep students safe, employ and pay staff, meet our legal duties (including Keeping Children Safe in Education), and operate this platform securely. We do not sell personal data. We do not use it for advertising.
5. Sharing
We share information only where necessary: with authorised C&G Education staff; with parents and carers through the family portal (limited, non-safeguarding information about their own child); with local authorities, schools, or safeguarding partners where the law or a student’s placement requires it; and with processors who host or support the platform under written contracts (including Google Cloud in the UK).
6. Automated tools
Staff may use optional AI drafting helpers (for example session-log drafts). Inputs are anonymised before they leave our systems, staff must review every draft, and no decision about a student is made solely by automated means. See our safe AI usage policy.
7. How long we keep data
We keep records for as long as the education, employment, or safeguarding purpose continues, and then for the retention period in C&G Education’s retention schedule and applicable law. Safeguarding and education records are often kept longer than ordinary correspondence. When a retention period ends, we delete or irreversibly anonymise the data.
8. Security
Access is role-based. Family accounts cannot reach staff or admin areas. Staff cannot see safeguarding records they are not authorised to see. The platform is hosted in the UK (London), uses encrypted connections, and stores sensitive files on a private disk. No system is perfect; report suspected misuse to office@cgeducation.co.uk and, if a child is at risk, follow safeguarding procedures.
9. Your rights
Under UK GDPR you can ask to access, correct, delete, or restrict your data, object to certain processing, and (where processing is based on consent or contract and is automated) request portability. Parents and carers may exercise rights on behalf of a child where they have the legal authority to do so. Some rights are limited where we must keep records for education, safeguarding, or employment law. See the UK GDPR statement for the full list and how to complain to the ICO.
How to contact us
For privacy questions, subject-access requests, or to exercise your UK GDPR rights, email office@cgeducation.co.uk.
You can also complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.