Privacy & Safeguarding
VETTA EDUCATION – PRIVACY POLICY
Last updated: 25‑08‑2026
1. Who we are and what this policy covers
1.1 This policy explains how Vetta Growth Ltd, trading as Vetta Education, a company registered in England and Wales (company number 17326100, registered office 66 Paul Street, London, EC2A 4NA) (Vetta, we, us, our), collects, uses, shares, and protects personal data when you use www.vettaeducation.com (the Site), download our free resources, or purchase our Interview Handbook, Diagnostic, or Mentorship services (the Services).
1.2 We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1.3 Vetta is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO) as a data controller and pay the annual data protection fee. Our ICO registration number is ZC223428.
1.4 We are not required to appoint a Data Protection Officer under Article 37 UK GDPR and have not done so. Our data protection contact is our founder, reachable at hello@vettaeducation.com (subject line Data Protection).
1.5 In this policy, Customer means the person who purchases Services (usually a parent or guardian), and Student means the person who receives them (aged 16 or over). You means whichever of them the context requires; where the difference matters, we say so.
1.6 This policy should be read alongside our Terms of Use at www.vettaeducation.com/terms, which govern purchases, set out our service complaints process, and are governed by the law of England and Wales.
2. Children and young people: our approach
2.1 Our Services are aimed at applicants who are typically 16 or 17, and our Site is likely to be accessed by under 18s. We have therefore designed the Site and our data practices to conform to the ICO’s Age Appropriate Design Code (the Children’s Code), and we have carried out a Data Protection Impact Assessment (DPIA) covering the Site and the Services, which we keep under review and update when our processing changes.
2.2 In line with the Children’s Code, we apply the following by design and by default:
(a) High privacy by default – settings are privacy protective by default. Non essential cookies and similar technologies are off unless you turn them on or we can rely on a specific statutory exception, and geolocation is not collected at all.
(b) Data minimisation – we collect only the data listed in section 3, and only when needed for the purpose you have asked us to fulfil.
(c) No advertising or profiling using children’s data – we do not use anyone’s data, and in particular no Student’s data, for targeted advertising, behavioural profiling, or automated decision making with legal or similarly significant effects.
(d) No nudge techniques – we do not use design tricks to push anyone into giving more data, weakening privacy settings, or staying engaged longer than they intend.
(e) Transparency – we have written this policy in clear language so that a 16 year old can understand it, and we surface short, just in time notices at the points where data is actually collected (for example, at booking and before recorded Sessions).
(f) Data is never sold – we do not sell personal data, and we do not share Student data with third parties for marketing or commercial purposes.
2.3 Where the Student is under 18, the Customer is our primary contact for contractual and billing matters. Information a Student shares during a Session is handled as described in sections 7 and 8.
3. What personal data we collect
3.1 We may collect the following categories of personal data from the Site and Services:
(a) Contact details
Examples: email address, full name (for example, the Ask Dr Farooq form may ask for full name), and, if you choose, a phone number.
When collected: free resource downloads, newsletter sign up, Ask Dr Farooq or other enquiry forms, purchases.
(b) Application context (optional)
Examples: year group, course type (for example medicine), school name if you choose to give it, whether you are a parent, student or school contact.
When collected: free resource downloads, Mentorship enquiry form, Ask Dr Farooq form where you choose to provide this information.
(c) Purchase and billing information
Examples: name, email, billing address if requested, transaction history.
When collected: purchases of the Interview Handbook and Diagnostic, and Mentorship payments, processed by Stripe (section 9).
(d) Booking information
Examples: preferred Session times, time zone, calendar details, any notes you add for scheduling.
When collected: booking Sessions via Calendly or our chosen scheduling tool (section 9).
(e) Session content
Examples: audio recordings of Diagnostic and Mentorship Sessions, written notes made during Sessions, materials the Student shares for feedback (for example draft answers or practice statements).
When collected: during delivery of the Diagnostic and Mentorship.
(f) Correspondence
Examples: emails and messages to hello@vettaeducation.com, messages submitted through Ask Dr Farooq and similar forms, and any replies.
When collected: any direct contact with us.
(g) Technical data
Examples: IP address, browser type, general location at country or region level, pages visited, time spent on pages, and aggregate usage patterns.
When collected: automatically, via cookies and similar technologies (section 11).
3.2 We do not collect payment card details ourselves. Card details are collected and processed directly by Stripe (section 9).
3.3 We do not intentionally collect special category data (such as detailed health information), but a Student may volunteer it during a Session (for example, mentioning a health condition or work experience in a clinical setting). Section 5 explains the conditions we rely on when this happens, and section 8 covers information about other people.
3.4 Where a school shares our free School Pack materials with pupils, no pupil data passes to us. We collect data from pupils only if they separately visit the Site, download a resource, or a purchase is made for them.
3.5 We do not collect precise or approximate geolocation data.
4. What happens if you do not provide data
4.1 Contact and payment information requested at purchase is necessary to deliver the Services and to meet our legal and accounting obligations. Without it, we cannot process the purchase, deliver the Handbook, book a Diagnostic, or enrol a Student on the Mentorship.
4.2 Application context (year group, course type, school) is always optional. Declining to provide it never affects your ability to buy or use the Services; it only helps us tailor free resources and communications.
4.3 When you contact us through the Ask Dr Farooq form or by email, you are free to provide as much or as little information as you wish. However, if you do not provide enough detail about your question, it may limit the usefulness of our response.
5. How we use personal data, and our lawful bases
5.1 We use personal data for the following purposes and on the following legal bases under UK GDPR:
(a) Delivering the Interview Handbook, Diagnostic, or Mentorship you purchased, including scheduling and personalised materials.
Lawful basis: Article 6(1)(b) – performance of a contract.
(b) Processing payments via Stripe, keeping accounting records, and preventing fraud.
Lawful basis: Article 6(1)(b) – performance of a contract, and Article 6(1)(c) – legal obligation (tax and accounting law).
(c) Responding to Mentorship enquiries, Ask Dr Farooq messages, and managing capacity and waiting lists.
Lawful basis: Article 6(1)(b) – steps at your request before entering a contract, and Article 6(1)(f) – our legitimate interests in managing enquiries and capacity.
(d) Making and retaining routine audio recordings of Sessions, for safeguarding readiness and to resolve any dispute about what was said or agreed.
Lawful basis: Article 6(1)(f) – our legitimate interests, supported by a documented legitimate interests assessment that specifically weighs the fact that Students may be under 18. Where a recording incidentally captures special category data, we rely on Article 9(2)(f) – establishment, exercise, or defence of legal claims.
(e) Retaining, escalating, or sharing a recording or related record because an actual safeguarding concern has arisen.
Lawful basis: Article 6(1)(c) – legal obligation, and Article 6(1)(d) – vital interests, together with Article 9(2)(g) and DPA 2018 Schedule 1, Part 2, paragraph 18 (safeguarding of children and individuals at risk), applied in line with our internal safeguarding policy.
(f) Sending you a free resource you requested (for example, the Pre‑Interview Applicant Guide or Parent Guide).
Lawful basis: Article 6(1)(b) – performance of a contract for the resource you asked for.
(g) Sending marketing emails, including our newsletter The Medicine Application Briefing.
Lawful basis: Article 6(1)(a) – consent, or Article 6(1)(f) – legitimate interests where the PECR soft opt in applies (see section 6).
(h) Improving the Site and understanding how it is used (aggregate analytics only).
Lawful basis: Article 6(1)(f) – our legitimate interests, applied with heightened care because our audience includes under 18s, and subject to the cookie rules in section 11.
(i) Complying with legal and regulatory obligations (including responding to the ICO, HMRC, courts, or safeguarding authorities).
Lawful basis: Article 6(1)(c) – legal obligation.
5.2 Where we rely on legitimate interests, we have carried out and documented a balancing assessment, and you have the right to object (section 15).
5.3 We do not carry out automated decision making or profiling that produces legal or similarly significant effects about anyone, and we will not do so in relation to Students in any event.
6. Marketing and the PECR rules
6.1 We send marketing emails only where:
(a) you have given clear, specific consent (for example, ticking an unticked newsletter box); or
(b) the PECR soft opt in applies – we obtained your email address in the course of a sale or negotiations for a sale of our Services, we are marketing only our own similar Services, and you were given a clear and simple way to opt out both when we collected your address and in every message since.
6.2 Downloading a free resource by itself is not a sale. Where we offer marketing alongside a free resource download, we rely on consent via an unticked opt in box, not the soft opt in, unless the download forms part of genuine negotiations for a paid Service.
6.3 Every marketing email contains a working unsubscribe link. You can also opt out at any time by emailing hello@vettaeducation.com. Opting out is free, takes effect promptly, and never affects any Service you have purchased.
6.4 Newsletter content that is general and informational (for example, application tips and admissions news) may be sent to a Customer or a Student, depending on who signed up. Promotional content about our paid Services, including pricing and enrolment for the Mentorship, is sent only to Customers (parents or guardians), consistent with our parent led approach and the Children’s Code.
6.5 Where we rely on the soft opt in, we ask you to reconfirm your interest approximately every 18 months rather than relying on it indefinitely.
6.6 We never use Student Session content, recordings, or safeguarding information for marketing.
7. Session recordings and safeguarding
7.1 Because the Services involve one to one video contact between our founder and Students who may be under 18, all Diagnostic and Mentorship Sessions are audio recorded as a matter of routine, for safeguarding readiness and dispute resolution only. You are told this at booking and reminded before your first Session. The lawful bases are set out in section 5.
7.2 Recordings are stored securely with access limited to our founder. They are never used for marketing, promotional material, or training content, and are never shared for commercial purposes. Any different use would require your separate, explicit, written consent, which you are free to refuse without any effect on the Services.
7.3 Recordings and related Session notes are retained for 12 months from the date of the Session, then securely deleted. Where a recording, note, or correspondence relates to an actual safeguarding concern, it is instead retained for as long as reasonably necessary in line with recognised safeguarding record keeping practice, which may be significantly longer.
7.4 If we have a genuine safeguarding concern about a Student, we may share relevant information with the Student’s parent or guardian, their school, or the appropriate authorities (such as children’s social care or the police), without consent where we reasonably believe this is necessary to protect the Student or another person from harm. This relies on the safeguarding condition identified in section 5.
7.5 Session content is otherwise treated as confidential, as set out in our Terms of Use.
8. Information about other people shared during Sessions
8.1 Students often discuss real experiences from work placements, volunteering, or shadowing, which may involve third parties such as patients.
8.2 Students should not name or otherwise identify real patients or other third parties during Sessions, consistent with the confidentiality principles taught in our own materials. If identifiable third party information is nonetheless shared, we treat it with the same confidentiality and security as your own data, do not use it for any purpose beyond the Session in which it arose, and delete it on the same schedule as the Session recording.
9. Who we share personal data with
9.1 We share personal data only with the following categories of recipient, and only as necessary:
(a) Stripe Payments UK Ltd and Stripe Inc
Role: payment processing
What they process: payment card details (collected directly by Stripe; we never see full card numbers), name, email, transaction data.
(b) Calendly LLC (or an equivalent scheduling provider notified in advance)
Role: Session scheduling
What they process: name, email, chosen Session times and related scheduling data.
(c) Our email service provider (currently MailerLite, or any replacement we notify in advance)
Role: email delivery and mailing lists
What they process: name, email address, newsletter preferences and delivery data.
(d) Video platform providers (currently Zoom, Microsoft Teams and Google Meet, or their UK or EEA equivalents notified in advance)
Role: video Sessions
What they process: meeting metadata and Session audio and video during the call.
(e) Professional advisers (for example accountant, solicitor, insurer)
Role: running our business
What they process: only what is necessary for the relevant advice or claim.
(f) Regulators and authorities (for example ICO, HMRC, police, children’s social care, courts and similar bodies)
Role: legal compliance and safeguarding
What they process: only where legally required or necessary to protect someone from harm, as described in section 7.4.
9.2 Each service provider acts under contract terms that meet UK GDPR Article 28 requirements. We do not sell personal data, and we do not share Student Session content with anyone for marketing or commercial purposes.
10. International transfers
10.1 Stripe, Calendly, our email provider and our video platforms are based outside the UK or may process personal data in the United States or other countries outside the UK.
10.2 Where personal data is transferred outside the UK, we rely on one of the following safeguards recognised under UK law:
(a) the UK Extension to the EU‑US Data Privacy Framework (the UK‑US Data Bridge), where the recipient is certified under it; or
(b) the ICO’s International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment.
10.3 You can ask us which safeguard applies to a particular provider, and for a copy of the relevant safeguard where applicable, using the contact details in section 17.
11. Cookies and similar technologies
11.1 We keep cookie and tracking technology use to a minimum, reflecting our young audience and the Children’s Code.
11.2 We may use:
(a) Strictly necessary cookies and similar technologies
Used only to make the Site work (for example, security, load balancing and page delivery). These do not require consent and cannot be switched off in our systems.
(b) Analytics tools
If we use analytics, we will either:
ask for your opt in consent before setting analytics cookies or similar technologies; or
where a particular tool clearly falls within a specific statutory exception (for example limited statistics used only by us to improve the Site under the Data (Use and Access) Act 2025), we will tell you what we are using, how it is limited, and provide a simple, free opt out.
Given our audience, our default position is to seek opt in consent before setting analytics cookies or similar technologies, unless a specific statutory exception clearly applies.
(c) Advertising and marketing cookies
We do not use advertising cookies or similar technologies for behavioural advertising, cross site tracking or profiling.
11.3 On first visit, the Site shows a cookie banner with clear information and, where consent is required, equally prominent accept and reject options, nothing pre ticked, and no nudging. You can change your choice at any time via the Cookie settings link in the Site footer.
11.4 Our separate Cookie Notice at www.vettaeducation.com/cookies lists each cookie or similar technology in use, who sets it, its purpose, whether it is strictly necessary or analytics, and how long it lasts.
12. How long we keep personal data
12.1 We keep personal data only for as long as necessary for the purposes set out in this policy, and to meet legal and regulatory requirements. In particular:
(a) Free resource and newsletter data (email, name, optional year group) – until you unsubscribe or ask us to delete it, or after 24 months of inactivity, whichever is sooner.
(b) Purchase and billing records – six years from the end of the relevant financial year, to meet accounting and tax obligations.
(c) Session recordings and Session notes – 12 months from the Session, unless linked to an actual safeguarding concern (section 7.3).
(d) Enquiry and general correspondence – up to three years from last contact, unless needed longer to resolve a dispute, or it relates to a safeguarding concern (section 7.3).
(e) Marketing consent and opt out records – duration of the marketing relationship plus three years, to evidence PECR and UK GDPR compliance.
12.2 When a retention period ends, digital records are permanently deleted from our systems and we instruct our processors to do the same. Any hard copy records are destroyed by confidential shredding.
13. How we keep data secure
13.1 We apply technical and organisational measures proportionate to our size and the sensitivity of the data, including:
using reputable, security vetted providers (Stripe, Calendly, mainstream video and email platforms) rather than building our own systems
encryption in transit
access to Session recordings and safeguarding records restricted to the founder
two factor authentication on business accounts
prompt deletion at the end of retention periods.
13.2 No system is completely secure. Section 14 explains what we do if something goes wrong.
14. Personal data breaches
14.1 If a personal data breach occurs, we will assess it promptly and keep a record of it. Where the breach is likely to result in a risk to people’s rights and freedoms, we will notify the ICO without undue delay and within 72 hours of becoming aware of it.
14.2 Where the breach is likely to result in a high risk to you or the Student, we will also tell you directly, without undue delay, explaining what happened and what we are doing about it.
15. Your rights
15.1 Under UK GDPR you have the right to:
(a) access the personal data we hold about you (a subject access request)
(b) rectification of inaccurate or incomplete data
(c) erasure of your data, in certain circumstances
(d) restriction of processing, in certain circumstances
(e) object to processing based on legitimate interests (including our routine recording of Sessions), and to object at any time to direct marketing, which we will always stop
(f) data portability – receive data you provided to us in a structured, commonly used, machine readable format, and have it transmitted to another provider where technically feasible
(g) withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal.
15.2 Where the Student is under 18, the Student may exercise these rights themselves if they have sufficient understanding (which we will normally assume at 16 and over), and the Customer may exercise them on the Student’s behalf where that is in the Student’s best interests. In each case we may need to verify identity and authority first.
15.3 To exercise any right, contact hello@vettaeducation.com. Exercising your rights is free. We will respond within one month of receiving your request (extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why).
16. Complaints
16.1 If you are unhappy with how we have handled personal data, you have the right to complain to us. We have a data protection complaints procedure, as required by the Data (Use and Access) Act 2025: email hello@vettaeducation.com with the subject line Data Protection Complaint, or use any complaint form on the Site. We will acknowledge your complaint within 30 days and respond substantively without undue delay, telling you the outcome and what we have done.
16.2 You also have the right to complain at any time to the Information Commissioner’s Office: ico.org.uk, 0303 123 1113, or Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concerns first, but you do not have to come to us before going to the ICO.
17. Contact us
17.1 Questions about this policy or our data practices: hello@vettaeducation.com (subject line Data Protection), or by post to Vetta Growth Ltd, 66 Paul Street, London, EC2A 4NA.
18. Changes to this policy
18.1 We may update this policy from time to time, for example to reflect changes to the Services, our providers, or the law. Material changes will be notified by email to people whose data we hold, or by prominent notice on the Site, at least 30 days before they take effect. The Last updated date at the top shows the current version. Previous versions are available on request.
VETTA EDUCATION – PRIVACY POLICY
Last updated: 25‑08‑2026
1. Who we are and what this policy covers
1.1 This policy explains how Vetta Growth Ltd, trading as Vetta Education, a company registered in England and Wales (company number 17326100, registered office 66 Paul Street, London, EC2A 4NA) (Vetta, we, us, our), collects, uses, shares, and protects personal data when you use www.vettaeducation.com (the Site), download our free resources, or purchase our Interview Handbook, Diagnostic, or Mentorship services (the Services).
1.2 We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1.3 Vetta is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO) as a data controller and pay the annual data protection fee. Our ICO registration number is ZC223428.
1.4 We are not required to appoint a Data Protection Officer under Article 37 UK GDPR and have not done so. Our data protection contact is our founder, reachable at hello@vettaeducation.com (subject line Data Protection).
1.5 In this policy, Customer means the person who purchases Services (usually a parent or guardian), and Student means the person who receives them (aged 16 or over). You means whichever of them the context requires; where the difference matters, we say so.
1.6 This policy should be read alongside our Terms of Use at www.vettaeducation.com/terms, which govern purchases, set out our service complaints process, and are governed by the law of England and Wales.
2. Children and young people: our approach
2.1 Our Services are aimed at applicants who are typically 16 or 17, and our Site is likely to be accessed by under 18s. We have therefore designed the Site and our data practices to conform to the ICO’s Age Appropriate Design Code (the Children’s Code), and we have carried out a Data Protection Impact Assessment (DPIA) covering the Site and the Services, which we keep under review and update when our processing changes.
2.2 In line with the Children’s Code, we apply the following by design and by default:
(a) High privacy by default – settings are privacy protective by default. Non essential cookies and similar technologies are off unless you turn them on or we can rely on a specific statutory exception, and geolocation is not collected at all.
(b) Data minimisation – we collect only the data listed in section 3, and only when needed for the purpose you have asked us to fulfil.
(c) No advertising or profiling using children’s data – we do not use anyone’s data, and in particular no Student’s data, for targeted advertising, behavioural profiling, or automated decision making with legal or similarly significant effects.
(d) No nudge techniques – we do not use design tricks to push anyone into giving more data, weakening privacy settings, or staying engaged longer than they intend.
(e) Transparency – we have written this policy in clear language so that a 16 year old can understand it, and we surface short, just in time notices at the points where data is actually collected (for example, at booking and before recorded Sessions).
(f) Data is never sold – we do not sell personal data, and we do not share Student data with third parties for marketing or commercial purposes.
2.3 Where the Student is under 18, the Customer is our primary contact for contractual and billing matters. Information a Student shares during a Session is handled as described in sections 7 and 8.
3. What personal data we collect
3.1 We may collect the following categories of personal data from the Site and Services:
(a) Contact details
Examples: email address, full name (for example, the Ask Dr Farooq form may ask for full name), and, if you choose, a phone number.
When collected: free resource downloads, newsletter sign up, Ask Dr Farooq or other enquiry forms, purchases.
(b) Application context (optional)
Examples: year group, course type (for example medicine), school name if you choose to give it, whether you are a parent, student or school contact.
When collected: free resource downloads, Mentorship enquiry form, Ask Dr Farooq form where you choose to provide this information.
(c) Purchase and billing information
Examples: name, email, billing address if requested, transaction history.
When collected: purchases of the Interview Handbook and Diagnostic, and Mentorship payments, processed by Stripe (section 9).
(d) Booking information
Examples: preferred Session times, time zone, calendar details, any notes you add for scheduling.
When collected: booking Sessions via Calendly or our chosen scheduling tool (section 9).
(e) Session content
Examples: audio recordings of Diagnostic and Mentorship Sessions, written notes made during Sessions, materials the Student shares for feedback (for example draft answers or practice statements).
When collected: during delivery of the Diagnostic and Mentorship.
(f) Correspondence
Examples: emails and messages to hello@vettaeducation.com, messages submitted through Ask Dr Farooq and similar forms, and any replies.
When collected: any direct contact with us.
(g) Technical data
Examples: IP address, browser type, general location at country or region level, pages visited, time spent on pages, and aggregate usage patterns.
When collected: automatically, via cookies and similar technologies (section 11).
3.2 We do not collect payment card details ourselves. Card details are collected and processed directly by Stripe (section 9).
3.3 We do not intentionally collect special category data (such as detailed health information), but a Student may volunteer it during a Session (for example, mentioning a health condition or work experience in a clinical setting). Section 5 explains the conditions we rely on when this happens, and section 8 covers information about other people.
3.4 Where a school shares our free School Pack materials with pupils, no pupil data passes to us. We collect data from pupils only if they separately visit the Site, download a resource, or a purchase is made for them.
3.5 We do not collect precise or approximate geolocation data.
4. What happens if you do not provide data
4.1 Contact and payment information requested at purchase is necessary to deliver the Services and to meet our legal and accounting obligations. Without it, we cannot process the purchase, deliver the Handbook, book a Diagnostic, or enrol a Student on the Mentorship.
4.2 Application context (year group, course type, school) is always optional. Declining to provide it never affects your ability to buy or use the Services; it only helps us tailor free resources and communications.
4.3 When you contact us through the Ask Dr Farooq form or by email, you are free to provide as much or as little information as you wish. However, if you do not provide enough detail about your question, it may limit the usefulness of our response.
5. How we use personal data, and our lawful bases
5.1 We use personal data for the following purposes and on the following legal bases under UK GDPR:
(a) Delivering the Interview Handbook, Diagnostic, or Mentorship you purchased, including scheduling and personalised materials.
Lawful basis: Article 6(1)(b) – performance of a contract.
(b) Processing payments via Stripe, keeping accounting records, and preventing fraud.
Lawful basis: Article 6(1)(b) – performance of a contract, and Article 6(1)(c) – legal obligation (tax and accounting law).
(c) Responding to Mentorship enquiries, Ask Dr Farooq messages, and managing capacity and waiting lists.
Lawful basis: Article 6(1)(b) – steps at your request before entering a contract, and Article 6(1)(f) – our legitimate interests in managing enquiries and capacity.
(d) Making and retaining routine audio recordings of Sessions, for safeguarding readiness and to resolve any dispute about what was said or agreed.
Lawful basis: Article 6(1)(f) – our legitimate interests, supported by a documented legitimate interests assessment that specifically weighs the fact that Students may be under 18. Where a recording incidentally captures special category data, we rely on Article 9(2)(f) – establishment, exercise, or defence of legal claims.
(e) Retaining, escalating, or sharing a recording or related record because an actual safeguarding concern has arisen.
Lawful basis: Article 6(1)(c) – legal obligation, and Article 6(1)(d) – vital interests, together with Article 9(2)(g) and DPA 2018 Schedule 1, Part 2, paragraph 18 (safeguarding of children and individuals at risk), applied in line with our internal safeguarding policy.
(f) Sending you a free resource you requested (for example, the Pre‑Interview Applicant Guide or Parent Guide).
Lawful basis: Article 6(1)(b) – performance of a contract for the resource you asked for.
(g) Sending marketing emails, including our newsletter The Medicine Application Briefing.
Lawful basis: Article 6(1)(a) – consent, or Article 6(1)(f) – legitimate interests where the PECR soft opt in applies (see section 6).
(h) Improving the Site and understanding how it is used (aggregate analytics only).
Lawful basis: Article 6(1)(f) – our legitimate interests, applied with heightened care because our audience includes under 18s, and subject to the cookie rules in section 11.
(i) Complying with legal and regulatory obligations (including responding to the ICO, HMRC, courts, or safeguarding authorities).
Lawful basis: Article 6(1)(c) – legal obligation.
5.2 Where we rely on legitimate interests, we have carried out and documented a balancing assessment, and you have the right to object (section 15).
5.3 We do not carry out automated decision making or profiling that produces legal or similarly significant effects about anyone, and we will not do so in relation to Students in any event.
6. Marketing and the PECR rules
6.1 We send marketing emails only where:
(a) you have given clear, specific consent (for example, ticking an unticked newsletter box); or
(b) the PECR soft opt in applies – we obtained your email address in the course of a sale or negotiations for a sale of our Services, we are marketing only our own similar Services, and you were given a clear and simple way to opt out both when we collected your address and in every message since.
6.2 Downloading a free resource by itself is not a sale. Where we offer marketing alongside a free resource download, we rely on consent via an unticked opt in box, not the soft opt in, unless the download forms part of genuine negotiations for a paid Service.
6.3 Every marketing email contains a working unsubscribe link. You can also opt out at any time by emailing hello@vettaeducation.com. Opting out is free, takes effect promptly, and never affects any Service you have purchased.
6.4 Newsletter content that is general and informational (for example, application tips and admissions news) may be sent to a Customer or a Student, depending on who signed up. Promotional content about our paid Services, including pricing and enrolment for the Mentorship, is sent only to Customers (parents or guardians), consistent with our parent led approach and the Children’s Code.
6.5 Where we rely on the soft opt in, we ask you to reconfirm your interest approximately every 18 months rather than relying on it indefinitely.
6.6 We never use Student Session content, recordings, or safeguarding information for marketing.
7. Session recordings and safeguarding
7.1 Because the Services involve one to one video contact between our founder and Students who may be under 18, all Diagnostic and Mentorship Sessions are audio recorded as a matter of routine, for safeguarding readiness and dispute resolution only. You are told this at booking and reminded before your first Session. The lawful bases are set out in section 5.
7.2 Recordings are stored securely with access limited to our founder. They are never used for marketing, promotional material, or training content, and are never shared for commercial purposes. Any different use would require your separate, explicit, written consent, which you are free to refuse without any effect on the Services.
7.3 Recordings and related Session notes are retained for 12 months from the date of the Session, then securely deleted. Where a recording, note, or correspondence relates to an actual safeguarding concern, it is instead retained for as long as reasonably necessary in line with recognised safeguarding record keeping practice, which may be significantly longer.
7.4 If we have a genuine safeguarding concern about a Student, we may share relevant information with the Student’s parent or guardian, their school, or the appropriate authorities (such as children’s social care or the police), without consent where we reasonably believe this is necessary to protect the Student or another person from harm. This relies on the safeguarding condition identified in section 5.
7.5 Session content is otherwise treated as confidential, as set out in our Terms of Use.
8. Information about other people shared during Sessions
8.1 Students often discuss real experiences from work placements, volunteering, or shadowing, which may involve third parties such as patients.
8.2 Students should not name or otherwise identify real patients or other third parties during Sessions, consistent with the confidentiality principles taught in our own materials. If identifiable third party information is nonetheless shared, we treat it with the same confidentiality and security as your own data, do not use it for any purpose beyond the Session in which it arose, and delete it on the same schedule as the Session recording.
9. Who we share personal data with
9.1 We share personal data only with the following categories of recipient, and only as necessary:
(a) Stripe Payments UK Ltd and Stripe Inc
Role: payment processing
What they process: payment card details (collected directly by Stripe; we never see full card numbers), name, email, transaction data.
(b) Calendly LLC (or an equivalent scheduling provider notified in advance)
Role: Session scheduling
What they process: name, email, chosen Session times and related scheduling data.
(c) Our email service provider (currently MailerLite, or any replacement we notify in advance)
Role: email delivery and mailing lists
What they process: name, email address, newsletter preferences and delivery data.
(d) Video platform providers (currently Zoom, Microsoft Teams and Google Meet, or their UK or EEA equivalents notified in advance)
Role: video Sessions
What they process: meeting metadata and Session audio and video during the call.
(e) Professional advisers (for example accountant, solicitor, insurer)
Role: running our business
What they process: only what is necessary for the relevant advice or claim.
(f) Regulators and authorities (for example ICO, HMRC, police, children’s social care, courts and similar bodies)
Role: legal compliance and safeguarding
What they process: only where legally required or necessary to protect someone from harm, as described in section 7.4.
9.2 Each service provider acts under contract terms that meet UK GDPR Article 28 requirements. We do not sell personal data, and we do not share Student Session content with anyone for marketing or commercial purposes.
10. International transfers
10.1 Stripe, Calendly, our email provider and our video platforms are based outside the UK or may process personal data in the United States or other countries outside the UK.
10.2 Where personal data is transferred outside the UK, we rely on one of the following safeguards recognised under UK law:
(a) the UK Extension to the EU‑US Data Privacy Framework (the UK‑US Data Bridge), where the recipient is certified under it; or
(b) the ICO’s International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment.
10.3 You can ask us which safeguard applies to a particular provider, and for a copy of the relevant safeguard where applicable, using the contact details in section 17.
11. Cookies and similar technologies
11.1 We keep cookie and tracking technology use to a minimum, reflecting our young audience and the Children’s Code.
11.2 We may use:
(a) Strictly necessary cookies and similar technologies
Used only to make the Site work (for example, security, load balancing and page delivery). These do not require consent and cannot be switched off in our systems.
(b) Analytics tools
If we use analytics, we will either:
ask for your opt in consent before setting analytics cookies or similar technologies; or
where a particular tool clearly falls within a specific statutory exception (for example limited statistics used only by us to improve the Site under the Data (Use and Access) Act 2025), we will tell you what we are using, how it is limited, and provide a simple, free opt out.
Given our audience, our default position is to seek opt in consent before setting analytics cookies or similar technologies, unless a specific statutory exception clearly applies.
(c) Advertising and marketing cookies
We do not use advertising cookies or similar technologies for behavioural advertising, cross site tracking or profiling.
11.3 On first visit, the Site shows a cookie banner with clear information and, where consent is required, equally prominent accept and reject options, nothing pre ticked, and no nudging. You can change your choice at any time via the Cookie settings link in the Site footer.
11.4 Our separate Cookie Notice at www.vettaeducation.com/cookies lists each cookie or similar technology in use, who sets it, its purpose, whether it is strictly necessary or analytics, and how long it lasts.
12. How long we keep personal data
12.1 We keep personal data only for as long as necessary for the purposes set out in this policy, and to meet legal and regulatory requirements. In particular:
(a) Free resource and newsletter data (email, name, optional year group) – until you unsubscribe or ask us to delete it, or after 24 months of inactivity, whichever is sooner.
(b) Purchase and billing records – six years from the end of the relevant financial year, to meet accounting and tax obligations.
(c) Session recordings and Session notes – 12 months from the Session, unless linked to an actual safeguarding concern (section 7.3).
(d) Enquiry and general correspondence – up to three years from last contact, unless needed longer to resolve a dispute, or it relates to a safeguarding concern (section 7.3).
(e) Marketing consent and opt out records – duration of the marketing relationship plus three years, to evidence PECR and UK GDPR compliance.
12.2 When a retention period ends, digital records are permanently deleted from our systems and we instruct our processors to do the same. Any hard copy records are destroyed by confidential shredding.
13. How we keep data secure
13.1 We apply technical and organisational measures proportionate to our size and the sensitivity of the data, including:
using reputable, security vetted providers (Stripe, Calendly, mainstream video and email platforms) rather than building our own systems
encryption in transit
access to Session recordings and safeguarding records restricted to the founder
two factor authentication on business accounts
prompt deletion at the end of retention periods.
13.2 No system is completely secure. Section 14 explains what we do if something goes wrong.
14. Personal data breaches
14.1 If a personal data breach occurs, we will assess it promptly and keep a record of it. Where the breach is likely to result in a risk to people’s rights and freedoms, we will notify the ICO without undue delay and within 72 hours of becoming aware of it.
14.2 Where the breach is likely to result in a high risk to you or the Student, we will also tell you directly, without undue delay, explaining what happened and what we are doing about it.
15. Your rights
15.1 Under UK GDPR you have the right to:
(a) access the personal data we hold about you (a subject access request)
(b) rectification of inaccurate or incomplete data
(c) erasure of your data, in certain circumstances
(d) restriction of processing, in certain circumstances
(e) object to processing based on legitimate interests (including our routine recording of Sessions), and to object at any time to direct marketing, which we will always stop
(f) data portability – receive data you provided to us in a structured, commonly used, machine readable format, and have it transmitted to another provider where technically feasible
(g) withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal.
15.2 Where the Student is under 18, the Student may exercise these rights themselves if they have sufficient understanding (which we will normally assume at 16 and over), and the Customer may exercise them on the Student’s behalf where that is in the Student’s best interests. In each case we may need to verify identity and authority first.
15.3 To exercise any right, contact hello@vettaeducation.com. Exercising your rights is free. We will respond within one month of receiving your request (extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why).
16. Complaints
16.1 If you are unhappy with how we have handled personal data, you have the right to complain to us. We have a data protection complaints procedure, as required by the Data (Use and Access) Act 2025: email hello@vettaeducation.com with the subject line Data Protection Complaint, or use any complaint form on the Site. We will acknowledge your complaint within 30 days and respond substantively without undue delay, telling you the outcome and what we have done.
16.2 You also have the right to complain at any time to the Information Commissioner’s Office: ico.org.uk, 0303 123 1113, or Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concerns first, but you do not have to come to us before going to the ICO.
17. Contact us
17.1 Questions about this policy or our data practices: hello@vettaeducation.com (subject line Data Protection), or by post to Vetta Growth Ltd, 66 Paul Street, London, EC2A 4NA.
18. Changes to this policy
18.1 We may update this policy from time to time, for example to reflect changes to the Services, our providers, or the law. Material changes will be notified by email to people whose data we hold, or by prominent notice on the Site, at least 30 days before they take effect. The Last updated date at the top shows the current version. Previous versions are available on request.
Vetta Education is a trading style of Vetta Growth Ltd. Registered in England and Wales. Company No. 17326100. Registered address: 66 Paul Street, London, EC2A 4NA. Led by Dr S Farooq MBChB, BSc (Hons).