top of page

Privacy and Cookie Notice

Last updated: September 2026

This notice explains how Edify Collective Ltd collects and uses personal data through our website, platform, applications, learning services, customer support, events, sales and marketing activities. It also explains the choices and rights available to you.

Edify Collective Ltd is a company registered in England and Wales under company number 15905863, with its registered office at 4 Durham Terrace, London, England, W2 5PB. In this notice, “Edify”, “we”, “us” and “our” refer to Edify Collective Ltd.

You can contact us about privacy or data security at learn@edifycollective.com.

 

1. When Edify is a controller and when it is a processor

Edify is the controller when we decide why and how personal data is used. This normally includes data collected through our website, enquiries, direct customer relationships, events, marketing, supplier management and our own service administration and security.

Where an employer or other organisation provides access to the Edify platform and decides why its workforce data is used, that organisation is normally the controller and Edify acts as its processor. We process that data on the organisation’s documented instructions and under a data processing agreement. If you make a request about data we process for your organisation, we may refer the request to that organisation or assist it in responding.

 

2. The personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and work data: name, username, job title, role, department, work location, employer and employee or internal identifier.

  • Contact data: work email address, telephone number and business contact details.

  • Account and authentication data: account status, permissions, login records and authentication information. We do not need your password in readable form.

  • Learning and performance-support data: enrolments, content viewed, questions and prompts submitted, answers, assessment results, completion records, feedback, learning preferences and progress.

  • Task and operational data: tasks assigned or completed, acknowledgements, checklists and other records created through features enabled by your organisation.

  • Content data: documents, policies, product information, messages, comments, images, recordings or other material that you or your organisation upload or create.

  • Support and communications data: correspondence, support requests, meeting notes and records of our relationship with you or your organisation.

  • Technical and usage data: IP address, device and browser type, operating system, approximate location derived from IP address, timestamps, session activity, diagnostic logs, crash data and security events.

  • Marketing and events data: professional interests, event attendance, communication preferences and engagement with our communications.

  • Transaction and business administration data: contracts, invoices, payments and records required for tax, accounting and audit purposes. Edify does not ordinarily need employees’ salary or personal bank details to provide its learning platform.

  • Cookie and similar technology data: information described in the Cookie Notice below.

We ask customers and users not to upload special category data, criminal offence data or information that is not needed for learning or performance support. If a customer instructs us to process such data, the customer must identify a valid legal basis and any additional condition required by law, and appropriate safeguards must be agreed.

 

3. How we obtain personal data

We collect personal data:

  • directly from you when you create an account, use the service, contact us, attend an event or respond to a survey;

  • from your employer or another organisation that provides your access;

  • automatically from your device and use of our website or services;

  • from service providers that support authentication, hosting, analytics, customer support or communications; and

  • from public professional sources, referrals and lawful business data providers when we identify potential business customers.

If we obtain your personal data from another source, we will provide the information required by law within the applicable period, unless an exemption applies.

 

4. Why we use personal data and our lawful bases

We use personal data only where a lawful basis applies.

Providing and administering the service

We use identity, contact, account, learning, task, content, technical and support data to create accounts, provide learning and in-the-flow guidance, deliver enabled features, authenticate users, provide support and communicate service information.

Our lawful basis is performance of a contract where the individual is a party to it. In most workforce deployments, Edify acts as a processor and the customer determines the applicable lawful basis. For our own service administration, we may rely on our legitimate interests in delivering and managing a secure business service.

Personalising learning and guidance

We use learning activity, role, permitted content and interactions to tailor recommendations, retrieve relevant approved information and improve the usefulness of the service.

We rely on our legitimate interests in making the service relevant and effective, or we act on the controller customer’s instructions. We assess those interests against the rights and reasonable expectations of users.

Security, abuse prevention and service reliability

We use account, authentication, technical, usage and content data where necessary to secure accounts and systems, prevent misuse, investigate incidents, troubleshoot faults and maintain service availability.

We rely on our legitimate interests in protecting users, customers, Edify and our systems, and on legal obligations where applicable.

Analytics and product improvement

We use usage, support and learning data to understand service performance, resolve issues and improve features. Wherever reasonably possible, we use aggregated or de-identified information.

We rely on legitimate interests for essential service analytics. We use consent where analytics involve non-essential cookies or similar technologies. When Edify acts as a processor, improvement using customer personal data will be governed by the customer agreement and documented instructions.

Customer relationships, enquiries and events

We use business contact and communications data to respond to enquiries, arrange demonstrations, manage customer and supplier relationships, administer events and follow up on matters you ask us to address.

We rely on steps taken at your request before entering a contract, performance of a contract and our legitimate interests in operating and developing our business.

 

Marketing

We use professional contact details and communication preferences to send relevant business communications where permitted by law. We rely on consent where required. In appropriate business-to-business contexts, we may rely on legitimate interests, subject to the Privacy and Electronic Communications Regulations 2003 and your right to object.

You can opt out at any time by using the unsubscribe link or emailing learn@edifycollective.com. We may retain a minimal suppression record so we respect your choice.

Legal and business administration

We use relevant records to comply with tax, accounting, legal and regulatory requirements, establish or defend legal claims, conduct due diligence and manage a corporate transaction.

We rely on legal obligation and our legitimate interests in managing and protecting our business.

 

5. AI, recommendations and automated decision-making

Edify uses artificial intelligence to help retrieve approved organisational knowledge, generate or adapt learning materials and recommend relevant guidance or learning content. Outputs may be generated from information supplied or approved by a customer and from a user’s role and interactions.

AI-generated output can be incomplete or incorrect. Users should follow their organisation’s policies and exercise human judgement, particularly for safety-critical, legal, financial, health or employment matters.

Edify does not use platform data to make solely automated decisions that produce legal or similarly significant effects about individuals. Employers remain responsible for employment decisions and should not rely solely on Edify scores, recommendations or usage data for disciplinary, dismissal, promotion or other significant decisions.

We do not use identifiable customer content or workforce data to train general-purpose AI models unless the relevant controller has expressly agreed this in writing and an appropriate lawful basis, transparency information and safeguards are in place. Our AI and infrastructure providers may process data only to provide contracted services, subject to contractual and security controls.

You may ask for information about relevant AI processing, object where processing is based on legitimate interests and exercise the rights described below.

 

6. Who receives personal data

We may share personal data with:

  • the organisation that provides or sponsors your access, in accordance with its configuration, policies and agreement with Edify;

  • hosting, cloud infrastructure, authentication, communications, analytics, customer support, security and AI service providers acting under contract;

  • professional advisers, auditors, insurers and financial service providers;

  • regulators, courts, law enforcement or other authorities where disclosure is required or permitted by law;

  • a prospective buyer, investor or successor in connection with a genuine financing, reorganisation, sale or transfer, subject to appropriate confidentiality and data protection safeguards; and

  • other parties where you ask us to do so or give valid consent.

 

We do not sell personal data. We require processors to protect personal data, keep it confidential and use it only for agreed purposes. A current list of material subprocessors and their processing locations is available from learn@edifycollective.com.

Our primary cloud hosting environment is provided by Amazon Web Services in Ireland (European Union). This means the core service data hosted in that environment is stored in the EEA, subject to Edify’s configuration and customer agreement.

 

7. International transfers

Our primary AWS hosting environment is in Ireland. A transfer from the United Kingdom to Ireland is covered by the United Kingdom’s adequacy regulations for the EEA. Some support, communications, AI or other service providers may nevertheless process or access personal data outside the United Kingdom or EEA. Where UK data protection law restricts a transfer, we use a lawful transfer mechanism, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework for eligible certified US recipients, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We carry out a transfer risk assessment and apply supplementary measures where required.

You can contact us for more information about the relevant transfer mechanism and safeguards.

 

8. How we protect personal data

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to risk and include, where appropriate:

  • encryption in transit and at rest;

  • role-based access controls, authentication and least-privilege access;

  • logging, monitoring, vulnerability management and secure development practices;

  • backups, resilience and incident response procedures;

  • supplier security and data protection due diligence; and

  • staff confidentiality obligations and security awareness training.

No service can guarantee absolute security. If you believe personal data or an Edify account has been compromised, contact learn@edifycollective.com promptly. We assess personal data breaches and notify affected controllers, the Information Commissioner’s Office and individuals where the law requires it.

 

9. How long we keep personal data

We retain personal data only for as long as reasonably necessary for the relevant purpose, including contractual, legal, accounting, security and dispute-resolution requirements. The period depends on the nature, sensitivity and volume of the data, the risk of harm, the purpose of processing and any customer instructions.

Unless a customer agreement or legal requirement provides otherwise, our working retention framework is:

  • customer account and contract administration records: for the customer relationship and ordinarily up to six years afterwards where needed for legal, tax or accounting purposes;

  • user accounts, learning, task and content data processed for a customer: for the period set by that customer and deleted or returned in accordance with the customer agreement;

  • sales enquiries and prospective customer records: while the relationship is active and then reviewed periodically, with deletion or suppression when no longer needed;

  • support records: ordinarily up to two years after resolution, unless needed for security, contractual or legal reasons;

  • security and diagnostic logs: for the shortest period needed for security and reliability, according to the applicable system configuration;

  • marketing consent and suppression records: for as long as needed to demonstrate or respect the communication preference; and

  • cookie data: for the lifespan shown in the cookie settings panel or cookie register.

We may retain anonymised information that no longer identifies an individual.

 

10. Your data protection rights

Depending on the circumstances, you may have the right to:

  • be informed about how your personal data is used;

  • request access to your personal data;

  • ask us to correct inaccurate or incomplete data;

  • ask us to erase personal data;

  • ask us to restrict processing;

  • receive personal data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically feasible;

  • object to processing based on legitimate interests, including profiling, and object at any time to direct marketing;

  • withdraw consent at any time, without affecting processing already carried out; and

  • request safeguards and human involvement where the law gives rights in relation to automated decision-making.

These rights are not absolute and exemptions may apply. We may need information to verify your identity. We will normally respond within one month, although the law permits an extension for complex or multiple requests. There is usually no charge, but the law allows a reasonable fee or refusal in limited circumstances.

To exercise a right, email learn@edifycollective.com. If Edify processes the data only for your employer or another organisation, you can also contact that organisation directly.

 

11. Complaints

Please contact us first at learn@edifycollective.com so we can try to resolve your concern.

You also have the right to complain to the UK Information Commissioner’s Office. Current contact and complaint information is available at https://ico.org.uk/make-a-complaint/. You may also have the right to contact the supervisory authority in the country where you live or work.

 

12. Children

Edify’s business services are intended for workplace users and are not directed to children. We do not knowingly offer the service directly to children. A customer must not provide access to anyone under 18 without first agreeing appropriate contractual, transparency, consent and safeguarding arrangements with Edify. If we learn that a child’s data has been collected without appropriate authority, we will take reasonable steps to restrict or delete it.

 

13. Third-party links and services

Our website or service may link to third-party websites or services. Those organisations control their own privacy practices. We encourage you to read their privacy notices before providing personal data.

 

14. Changes to this notice

We may update this notice when our services, processing or legal obligations change. We will post the revised notice with a new date and, where appropriate, provide additional notice of material changes.

 

 

 

Cookie Notice

This Cookie Notice explains how Edify uses cookies and similar technologies on its website, platform and applications. It should be read with the Privacy Notice above.

 

1. What cookies and similar technologies are

Cookies are small text files stored on a browser or device. Similar technologies include local storage, software development kits, pixels and device identifiers. They can recognise a device, maintain a secure session, remember preferences and help us understand how a service is used.

 

2. The categories we use

  • Strictly necessary: authentication, security, load balancing, fraud prevention, network management and features required to provide a service you request. These do not require consent where the legal exemption applies.

  • Functional or preference: remembering choices such as language, accessibility or display preferences. We request consent unless a legal exemption applies.

  • Analytics: measuring visits, feature use, errors and service performance. Where required, these remain off until you consent.

  • Support and collaboration: enabling optional chat, feedback, comments or collaboration features. Consent requirements depend on whether the technology is strictly necessary for a feature you request.

  • Marketing: measuring campaigns, referrals and engagement, or supporting advertising. These remain off until you consent.

The cookie banner or settings panel identifies the cookies and similar technologies currently in use, their providers, purposes and lifespans. That live register forms part of this notice. Edify should update it whenever a technology is added or changed.

 

3. Your choices

You can accept or reject non-essential cookies and make category-level choices through the cookie banner or settings panel. Rejecting non-essential cookies must be as easy as accepting them. Withdrawing consent does not affect use that occurred before withdrawal.

You can also block or delete cookies using your browser settings. Blocking strictly necessary technologies may prevent parts of the website or platform from working.

 

4. Third-party services

Where an enabled third-party service sets or accesses a cookie, that provider may process information under its own privacy terms as well as under its contract with Edify. The current settings panel identifies the relevant provider. We do not permit optional third-party cookies to be set before the required consent has been obtained.

 

5. Contact

For questions about cookies or your choices, email learn@edifycollective.com.

bottom of page