About
Information security and data protection
When you deliver a 360 under your own brand, your client's security review lands on you. This page is written so you can forward it, and we will supply the underlying documentation to a procurement team on request.
ISO/IEC 27001, held since August 2010
ISO 27001 puts information security, availability and integrity under management control. We implemented the physical, logical, process and management controls it defines, and we are audited externally every year by Alcumus ISOQAR, a UKAS accredited auditor.
- Secure data storage
- Software development
- Controlled information handling and data protection
- Management of third-party services and suppliers
- Systems access control across internal and customer data
Data protection
GDPR, UK GDPR and the DUAA
We comply with the EU General Data Protection Regulation, the UK General Data Protection Regulation, the Data (Use and Access) Act 2025 which amends UK GDPR, and the other data protection laws that apply where we operate.
What we commit to
- Personal data is collected and processed only where we have a lawful basis, such as performing a contract, legitimate interests, or explicit consent
- Technical and organisational measures keep that data confidential
- We say plainly how data is used, and we honour the rights people hold under GDPR, UK GDPR and the DUAA
Where processing happens
Envisia Learning Ltd is UK-registered and its web servers are hosted in the UK, which is where personal data is primarily processed. Envisia Learning Inc is the US entity. Where processing touches the EEA or concerns EU residents, EU GDPR requirements apply and we meet them.
International transfers
Core processing sits in the UK. Where data moves outside the UK or EEA, to a sub-processor in the United States for instance, one of these safeguards is in place:
- UK International Data Transfer Agreement, or the addendum to the EU Standard Contractual Clauses
- EU Standard Contractual Clauses
- Binding Corporate Rules or an equivalent mechanism
Client security review to get through?
We'll supply the certificate, the sub-processor list and whatever else their procurement team needs.