Skip to main content
Our sites: Leadership Development Private Label Assessments for Consultancies
About Envisia Learning

Information Security & Data Protection

Your leaders' feedback is sensitive. We treat it like the strategic asset it is. Envisia Learning takes data security and data protection as seriously as you do. The quality, reliability, and security of our platform directly impact the success of your assessment and leadership development programmes.

Data Protection & GDPR Compliance

At Envisia Learning, we take the privacy and security of your personal data very seriously. We are fully committed to complying with the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the Data (Use and Access) Act 2025 (DUAA) which amends UK GDPR, and all other applicable data protection laws worldwide.

Our Commitment to You

  • We only collect and process personal data when we have a lawful basis to do so (e.g., contract performance, legitimate interests, or explicit consent).
  • We implement industry-leading technical and organisational measures to keep your data safe and confidential.
  • We provide transparent information about how we use your data and honour your rights under the GDPR, UK GDPR, DUAA, and other applicable privacy laws.

Our Data Processing Locations

Envisia Learning operates as a UK-registered company (Envisia Learning Ltd) with web servers hosted in the UK, as well as a US entity (Envisia Learning Inc). We primarily process personal data in the United Kingdom. Where data processing involves the European Economic Area (EEA) or relates to EU residents, we ensure full compliance with EU GDPR requirements.

International Data Transfers

While our core processing occurs in the UK, we may transfer personal data outside the UK or EEA (e.g., to secure sub-processors in the United States or other locations) as part of our global operations. In all such cases, we ensure appropriate safeguards are in place in line with UK GDPR (as amended by the DUAA) and EU GDPR requirements, including:

  • UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses
  • EU Standard Contractual Clauses (SCCs) for EU GDPR compliance
  • Binding Corporate Rules or other equivalent mechanisms
ISO 27001 Certificate
Certified Since 2010

ISO/IEC 27001

We have been certified in ISO 27001, a security management system that brings information security, availability, and integrity into management control.

We are proud to have implemented the rigorous set of physical, logical, process, and management controls defined by ISO 27001. We are constantly reviewing and updating our procedures and practices, and are externally audited annually by Alcumus ISOQAR, a UKAS accredited auditor. Adhering to the ISO 27001 demonstrates our commitment to delivering high quality services and web-based applications to our clients and partners. We have held ISO 27001 certification since August 2010.

Scope

  • Secure Data Storage
  • Software Development
  • Controlled Information Handling and Data Protection
  • Management of third-party services and suppliers
  • Systems access control measures to protect all internal and customer data

Questions about security?

We're happy to discuss our information security management system and provide documentation for your IS or procurement teams.

Contact Us