Privacy & Cookie Policy
For Learning Cog and My360Goals
UK GDPR • Data Protection Act 2018 • PECR • Data (Use and Access) Act 2025
| Version | 3.0 |
|---|---|
| Effective date | 5 August 2026 |
| Next scheduled review | August 2027 |
Learning Cog Limited Trading as Learning Cog and My360Goals www.learningcog.com | www.my360goals.com Privacy enquiries: info@learningcog.com
Privacy at a glance
| Who controls your information? Learning Cog Limited is normally the controller for information collected through its websites, enquiries and direct client relationships. When a client organisation supplies participant information for a My360Goals or Learning Cog programme, the client may be the controller and Learning Cog Limited may act as its processor. Section 3 explains this distinction. |
|---|
- We collect only the information needed to provide learning, coaching, assessment and 360-degree feedback services, manage accounts and contracts, operate our websites, communicate with users and meet legal obligations.
- Personal information is hosted and stored within the European Economic Area (EEA). Access from, or onward disclosure to, another country is not permitted unless it has first been reviewed and documented under the UK GDPR transfer rules.
- We do not sell personal information.
- Non-essential cookies and similar technologies are not used until the user has made an appropriate choice, except where a statutory exemption applies.
- You may have rights to access, correct, erase, restrict or object to the use of your information, and to complain to the Information Commissioner’s Office (ICO).
1. Introduction and scope
This privacy and cookie policy explains how Learning Cog Limited (“Learning Cog”, “we”, “us” or “our”) handles personal information in connection with the Learning Cog and My360Goals businesses, their websites and associated services. It is intended for website visitors, prospective and current clients, programme participants, respondents, suppliers, professional contacts and other individuals whose information we process.
This policy applies to www.learningcog.com, www.my360goals.com, related online platforms operated by us, and services delivered under the Learning Cog or My360Goals names. A client-specific notice or contract may provide additional information. Where there is a conflict, the notice that most specifically describes the relevant processing should be read alongside this policy.
We process personal information under the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), as amended, and relevant provisions of the Data (Use and Access) Act 2025. This policy is a transparency notice and does not create contractual rights beyond those provided by law.
2. Who we are and how to contact us
Learning Cog Limited operates the Learning Cog and My360Goals businesses.
| Legal entity | Learning Cog Limited |
|---|---|
| Registered address | The Offices, 57 Newtown Road, Hove, BN3 7BA, United Kingdom |
| Operational address | Sussex Innovation Hub, Science Park Square, Brighton, BN1 9SB, United Kingdom |
| Websites | www.learningcog.com and www.my360goals.com |
| Privacy contact Data Protection Officer | Managing Director — info@learningcog.com Richard Hayden, Managing Director |
3. Our role: controller or processor
3.1 When we are a controller
We are a controller when we decide why and how personal information is used. This normally includes information about website visitors, enquiries, client contacts, suppliers, our own marketing activities, billing and administration, and information we use to manage and secure our services.
3.2 When we act for a client
For some learning, coaching, assessment and 360-degree feedback programmes, a client organisation selects the participants and respondents, decides the purpose of the programme and instructs us how to administer it. In that situation, the client is normally the controller and we act as its processor. The client is responsible for identifying a lawful basis, providing appropriate privacy information and responding to rights requests, while we process information only on documented instructions and under a data-processing agreement.
3.3 Independent decisions
Even where we act as a processor for core programme data, we may be a separate controller for limited processing necessary to protect our systems, maintain audit records, comply with law, establish or defend legal claims, administer contracts and manage our business. We will not reuse client programme data for unrelated purposes.
4. The information we collect
Depending on how you interact with us, we may process the following categories of personal information:
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Name, job title, employer, postal address, email address, telephone number, username or participant identifier. | You, your employer or programme sponsor. |
| Account and service | Account credentials, organisation, programme allocation, enrolment status, support history and preferences. | You, a client administrator or our systems. |
| Assessment and feedback | Questionnaire responses, ratings, written feedback, goals, reflections, reports, coaching notes and participation records. | You, respondents, coaches, facilitators or a client organisation. |
| Contract and financial | Purchase information, invoices, payment status, tax and accounting records. We generally receive payment confirmation rather than full card details. | You, your organisation or a payment provider. |
| Communications | Emails, enquiry forms, meeting notes, complaints, requests and customer-support correspondence. | You and people communicating with us. |
| Technical and usage | IP address, device and browser information, timestamps, security logs, pages viewed, referring pages and interactions with our services. | Your device, server logs and permitted technologies. |
| Marketing preferences | Consent records, subscription status, topics of interest and suppression records. | You and our communication systems. |
| Professional and supplier | Business contact details, role, organisation, contractual correspondence and due-diligence information. | You, your organisation and public professional sources. |
| Recruitment | Application, CV, employment history, qualifications, interview notes and right-to-work information where relevant. | Applicants, referees and recruitment providers. |
5. How information is collected
- Directly from you, including through forms, questionnaires, surveys, assessments, emails, calls, meetings, account creation and use of our services.
- From a client, employer or programme sponsor that asks us to provide a service involving you.
- From respondents who provide feedback about a participant in a 360-degree or similar programme.
- Automatically from websites, platforms and systems through server logs, strictly necessary technologies and other technologies used with an appropriate legal basis or consent.
- From service providers, such as payment, identity, communications, hosting and support providers.
- From publicly available professional sources where it is reasonable and lawful to do so.
Where information is required by law or contract, or is necessary to enter into a contract, we will explain this where appropriate. If required information is not provided, we may be unable to create an account, deliver the programme, process a transaction or respond fully to a request.
6. Purposes and lawful bases
We must have a lawful basis before processing personal information. The basis depends on the purpose and our role. The principal purposes and bases are summarised below and described in more detail in Appendix 1.
- Contract: to take steps requested before entering into a contract and to perform a contract with you.
- Legitimate interests: to operate and improve a responsible learning and technology business, provide client services, maintain security, manage relationships and protect legal rights, provided those interests are not overridden by your rights and interests.
- Legal obligation: to comply with tax, accounting, employment, regulatory, court and other legal requirements.
- Consent: for activities where consent is required or is the most appropriate basis, including certain marketing and non-essential storage/access technologies. Consent can be withdrawn at any time.
- Vital interests: in rare cases, where processing is necessary to protect someone’s life.
Where a client is the controller, the client determines the lawful basis for the programme data. We process that data under the client’s documented instructions and our contract with the client.
7. My360Goals and 360-degree feedback
7.1 Programme administration
My360Goals may be used to invite participants and respondents, collect ratings and comments, generate reports, support coaching or development conversations, record goals and administer related learning activities. Invitation and reminder communications are service messages rather than marketing where they are necessary to administer a programme.
7.2 Confidentiality and respondent information
The confidentiality model for a programme may vary. Some feedback may be attributed, while other feedback may be grouped or presented without naming the respondent. The relevant client or programme materials should explain the model before responses are submitted. We do not promise anonymity where the design, number of respondents, wording of comments or surrounding circumstances could allow an individual to be inferred.
7.3 Access to reports
Access is limited according to the programme configuration and client instructions. Reports may be available to the participant, nominated coach or facilitator, authorised client administrators and other people identified in the programme arrangements. We recommend that clients apply role-based access and share reports only with people who need them for the stated development purpose.
7.4 Appropriate use
Unless the client has established a separate lawful and fair basis and has clearly informed affected individuals, 360-degree feedback designed for development should not be repurposed for unrelated disciplinary, dismissal or high-impact automated employment decisions. Free-text comments should be professional, relevant and proportionate and should not include unnecessary sensitive information about any person.
8. Special category and sensitive information
Special category information includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric identification data, health information, and information about sex life or sexual orientation. Criminal-offence information is subject to separate safeguards.
Our standard services are not designed to require special category or criminal-offence information. However, free-text feedback, accessibility requests, coaching discussions or recruitment activity could occasionally include it. We ask users not to submit unnecessary special category or criminal-offence information. Where such information is genuinely required, the relevant controller must identify both an Article 6 lawful basis and an additional condition under the UK GDPR and Data Protection Act 2018, apply appropriate safeguards and provide any additional notice required.
9. Cookies and storage/access technologies
9.1 What these technologies are
Cookies are small files stored on a device. Similar storage and access technologies may include pixels, scripts, tags, local storage, software development kits, link decoration and device-fingerprinting techniques. PECR can apply whenever information is stored on, or accessed from, a user’s device, whether or not the information is personal data. Where personal information is processed, the UK GDPR also applies.
9.2 Our approach
- We provide clear information about the technologies used and their purposes.
- We may use technologies without consent where a statutory exemption applies, including technologies that are strictly necessary to provide a service requested by the user, support security or carry a communication.
- We obtain an appropriate affirmative choice before using non-essential technologies unless another specific statutory exemption applies.
- Rejecting non-essential technologies must be as easy as accepting them, and users must be able to revisit their choices.
- Non-essential technologies must not be set before the relevant choice is made.
- We keep our technology inventory, purposes, providers, durations and consent records under review.
9.3 Cookie categories
The categories we may use are described below. The live cookie-preference tool and Appendix 2 should identify the technologies actually deployed at the time of use.
| Category | Purpose | Consent | Typical duration |
|---|---|---|---|
| Strictly necessary | Security, authentication, session management, load balancing, consent preference and delivery of a service requested by the user. | Not normally required where the statutory exemption applies. | Session or the shortest period necessary. |
| Functional | Remembering optional preferences or enhanced features that are not strictly necessary. | Usually required unless a specific exemption applies. | Set according to the feature and reviewed regularly. |
| Analytics/performance | Understanding use of the websites or services, measuring performance and improving design. | Required unless a valid statutory exemption applies to the specific use. | Limited and documented in the live schedule. |
| Advertising/marketing | Measuring campaigns, profiling interests or delivering targeted advertising. | Required before use. | Limited and documented in the live schedule. |
9.4 Managing choices
You can use the cookie-preference control presented on the relevant website to accept, reject or change optional categories. Browser settings may also allow you to block or delete technologies, but blocking strictly necessary technologies may prevent parts of a service from working. Withdrawing consent does not make earlier processing unlawful, but it should stop future non-essential use covered by that consent.
10. Direct marketing
We may send information about Learning Cog or My360Goals services to business contacts where permitted by the UK GDPR and PECR. We will obtain consent where it is required. In limited circumstances, the “soft opt-in” may allow marketing about our own similar services to an individual customer where the statutory conditions are satisfied and a clear opt-out was offered when the details were collected and in every message.
You can opt out at any time by using the unsubscribe mechanism in a message or contacting info@learningcog.com. We may retain a minimal suppression record to ensure that we respect the opt-out. Service, security, billing and programme-administration messages are not marketing and may still be sent where necessary.
Our marketing system and the My360Goals data storage system and users of the My360Goals system do not enter the marketing system.
11. Sharing information
We do not sell personal information. We may disclose information only where necessary and lawful, including to:
- client organisations, programme sponsors, authorised administrators, coaches and facilitators according to the relevant programme arrangements;
- hosting, platform, IT support, communications, email, survey, analytics and security providers;
- payment, banking, accounting, audit, insurance and professional-advisory providers;
- public authorities, regulators, law-enforcement bodies, courts or other parties where disclosure is required or permitted by law;
- a prospective buyer, investor or successor in connection with a genuine corporate transaction, subject to confidentiality and data-protection safeguards; and
- other parties with your direction or consent.
Service providers that process information for us are subject to written terms addressing confidentiality, security, permitted processing, assistance with rights and incidents, deletion or return, and audit obligations. They may engage approved sub-processors only under appropriate controls.
12. Storage and international transfers
12.1 EEA storage commitment
Learning Cog Limited’s stated operating requirement is that personal information is stored and processed within the European Economic Area (EEA). Our supplier selection, contracts and technical configurations should reflect that requirement. For this policy, the EEA comprises the EU member states together with Iceland, Liechtenstein and Norway.
12.2 UK access and data flows
Learning Cog Limited is established in the United Kingdom. Information may therefore be accessed and managed by authorised personnel in the UK in order to provide the services, even where the hosting infrastructure is in the EEA. The UK recognises the EEA under its adequacy regulations, and the European Commission renewed the UK adequacy decisions in December 2025. These arrangements allow relevant UK–EEA data flows without separate contractual transfer safeguards while the applicable adequacy decisions remain in force.
12.3 No unreviewed onward transfers
We do not authorise a supplier to store, access or onward-transfer personal information outside the UK and EEA unless the proposed transfer has first been assessed, documented and approved. If this position changes, we will update this policy and use a lawful transfer mechanism, which may include UK adequacy regulations, approved safeguards and a documented data-protection test or transfer risk assessment, or a narrowly applicable statutory exception.
13. Retention and deletion
We retain personal information only for as long as necessary for the purpose for which it was collected, taking account of contract terms, client instructions, participant expectations, security needs, statutory requirements, limitation periods and the need to establish, exercise or defend legal claims. Information is then securely deleted, anonymised or returned as appropriate.
| Record type | Indicative approach | Key factors |
|---|---|---|
| Enquiries and sales correspondence | Retained for a reasonable follow-up period, then deleted or moved to an appropriate business-contact record. | Nature of enquiry, relationship and limitation periods. |
| Client contracts, invoices and accounting records | Retained for the applicable accounting, tax and legal period. | Statutory retention and claims. |
| Programme accounts, responses and reports | Retained according to the client contract and documented retention configuration, then deleted or returned. | Client instructions, participant expectations, programme purpose and backup cycles. |
| Support and security logs | Retained for a proportionate period needed to investigate issues and protect services. | Security risk and operational necessity. |
| Marketing records | Kept while relevant and lawful; suppression records may be retained to respect opt-outs. | Consent, legitimate interests and PECR. |
| Recruitment records | Unsuccessful application records are retained for a limited period unless longer retention is agreed; successful records move into the personnel file. | Employment law, equality monitoring and claims. |
14. Security
We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:
- role-based access, least-privilege permissions and periodic access review;
- authentication controls and, where appropriate, multi-factor authentication;
- encryption in transit and at rest where appropriate to the risk;
- secure development, patching, malware protection, logging and vulnerability management;
- backups, resilience, incident-response and recovery arrangements;
- supplier due diligence and contractual security requirements;
- confidentiality obligations, staff training and documented policies; and
- data minimisation, retention controls and secure disposal.
No internet transmission or storage system can be guaranteed to be completely secure. Users are responsible for keeping passwords and authentication details confidential and should notify us promptly of suspected compromise. We assess personal-data breaches and notify the ICO and affected individuals where the legal thresholds are met.
15. Your data-protection rights
Subject to the conditions and exemptions in law, you may have the following rights:
| Right | What it means |
|---|---|
| To be informed | To receive clear information about how personal information is used. |
| Access | To obtain confirmation of processing and a copy of your personal information, together with related information. |
| Rectification | To have inaccurate information corrected and incomplete information completed. |
| Erasure | To ask for deletion in circumstances where there is no overriding reason to retain the information. |
| Restriction | To ask us to limit processing in specified circumstances. |
| Objection | To object to processing based on legitimate interests or public task, and to object at any time to direct marketing. |
| Data portability | To receive certain information you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller. |
| Withdraw consent | To withdraw consent at any time where consent is the basis for processing. |
| Automated decisions | To safeguards relating to certain solely automated decisions with legal or similarly significant effects. |
| Complain | To raise a concern with us and lodge a complaint with the ICO. |
15.1 Making a request
Contact info@learningcog.com and describe the right you wish to exercise. We may ask for information necessary to confirm identity, locate the records and understand the request. We will not request more identification information than is proportionate. We normally respond within one month, although the period may be extended where the law allows for complex or multiple requests. We will explain any extension, refusal or permitted fee.
15.2 Requests concerning client-controlled programme data
Where we process programme data solely for a client, we may refer your request to the client or assist the client in responding. This is because the client determines the purposes and means of that processing. We will tell you where this applies, unless prohibited by law or the client is already handling the request.
16. Automated decision-making and profiling
Our standard services may calculate scores, aggregate questionnaire responses or generate reports using rules selected for the relevant programme. These functions support interpretation and discussion; they are not intended to make solely automated decisions that produce legal or similarly significant effects on individuals.
If we or a client proposes to use personal information for a solely automated decision with such an effect, the responsible controller must identify a lawful basis, provide meaningful information about the logic and likely consequences, and implement the safeguards required by law, including human involvement where applicable. This policy will be updated if our own use materially changes.
17. Children and young people
Our websites and standard business services are directed to organisations and adults and are not intended for children. We do not knowingly invite a child to create a standard My360Goals account or submit feedback without an appropriate programme arrangement, lawful basis and safeguards established by the responsible controller. If we learn that information about a child has been collected inappropriately, we will investigate and delete or otherwise address it as required.
18. Recruitment and business contacts
18.1 Recruitment
We use applicant information to administer recruitment, assess suitability, communicate with applicants, take pre-contract steps, meet legal obligations and protect our legitimate interests in selecting staff and maintaining recruitment records. Additional information may be provided during a recruitment process, particularly where special category, criminal-record or right-to-work information is required.
18.2 Client, supplier and professional contacts
We process professional contact information to manage relationships, deliver and receive services, maintain records, conduct due diligence, communicate about relevant work and protect legal rights. The usual bases are contract, legitimate interests and legal obligation.
19. Links and third-party services
Our websites or communications may link to websites, platforms or services controlled by other organisations. Their privacy practices are governed by their own notices, and we are not responsible for their independent processing. Users should review the relevant notice before providing information. Where a third-party service is embedded in our website, we will assess whether it uses storage/access technologies or receives personal information and configure consent and contractual controls as required.
20. Complaints
Please contact us first at info@learningcog.com so that we can investigate and try to resolve your concern. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. The ICO can be contacted through its official website at ico.org.uk. Its postal address is Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Current contact methods should be checked on the ICO website.
21. Changes to this policy
We may update this policy to reflect changes in law, regulatory guidance, technology, suppliers or our services. The latest version will be published on the relevant website with an updated effective date.
Appendix 1 – Lawful-basis schedule
| Purpose | Information | Likely basis when we are controller | Notes |
|---|---|---|---|
| Responding to enquiries and proposals | Identity, contact and communications | Legitimate interests; contract/pre-contract steps | To respond, scope work and maintain appropriate records. |
| Creating accounts and delivering services | Identity, account, programme and technical information | Contract; legitimate interests | Where a client controls programme data, we act on its instructions. |
| Administering 360 feedback and reports | Participant, respondent, assessment and feedback information | Contract and/or legitimate interests; client-determined basis where we are processor | Confidentiality and access depend on programme design. |
| Billing, accounting and tax | Contract, transaction and financial records | Contract; legal obligation; legitimate interests | Full payment-card details should normally be handled by the payment provider. |
| Customer support and service improvement | Account, communications, technical and usage information | Contract; legitimate interests | Improvement should use minimised or aggregated information where practical. |
| Security, fraud prevention and incident response | Technical, authentication, audit and communications information | Legitimate interests; legal obligation | Necessary to protect users, services and legal rights. |
| Direct marketing | Contact and preference information | Consent or legitimate interests, subject to PECR | Every message provides an opt-out; suppression records may be retained. |
| Cookies and similar technologies | Device, preference and usage information | Consent, or legitimate interests/contract where a PECR exemption applies | The PECR rule and UK GDPR basis must both be considered. |
| Legal claims and compliance | Relevant records across categories | Legal obligation; legitimate interests | Includes responding to regulators, courts and professional advisers. |
| Recruitment | Application, contact, assessment and right-to-work information | Pre-contract steps; legitimate interests; legal obligation | Additional conditions are needed for special category or criminal-offence information. |
| Corporate transactions | Relevant business, contract and relationship records | Legitimate interests; legal obligation | Subject to confidentiality, minimisation and due diligence controls. |
Appendix 2 – Cookie and storage/access technology schedule
| Name | Provider | Category | Purpose | Consent/exemption |
|---|---|---|---|---|
| Supabase | My360Goals | Strictly necessary | Session security or authentication. | Strictly necessary exemption, if confirmed. |
| Users Own Device | Consent management provider | Strictly necessary | Stores the user’s cookie choices. | Strictly necessary exemption, if confirmed. |
| Microsoft | Email system | Functional | Optional preference or feature. | Consent unless a specific exemption applies. |
| Google Analytics | My360Goals.com / Learningcog.com | Analytics/performance | Measures use and performance. | Consent unless a specific statutory exemption applies. |
| ZohoCRM | ZOHO | Advertising/marketing | Campaign measurement or targeted advertising. | Consent required before use. |
| AWS | My360Goals | Functional | Production of PDF reports and storage to allow access in system. | Consent unless a specific exemption applies. |
| SupaBase | My360Goals | Strictly necessary | Candidate and participant information including scoring across questionnaires. | Consent unless a specific exemption applies. |
Appendix 3 – Legal and guidance references
This policy was updated with reference to the following UK legal and regulatory materials current at 5 August 2026:
- UK General Data Protection Regulation and Data Protection Act 2018: Core data-protection principles, lawful bases, transparency, rights, security, processor obligations and international-transfer rules.
- Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended: Rules for electronic marketing and storage/access technologies, including cookies.
- Data (Use and Access) Act 2025: Amendments affecting UK data-protection and PECR rules; all provisions affecting those regimes were reported by the ICO as in force by 2026.
- ICO guidance on storage and access technologies, published April 2026: Current guidance on cookies, pixels, scripts, tags, fingerprinting and related technologies.
- ICO international-transfer guidance, updated January 2026: Current guidance on adequacy, restricted transfers and the data-protection test/transfer risk assessment.
- ICO guidance on purpose limitation, updated March 2026: Current guidance on specified purposes, compatible reuse and the 2025 Act amendments.
- European Commission renewed UK adequacy decisions, adopted 19 December 2025: Recognition allowing covered personal information to flow from the EEA to the UK through 27 December 2031, subject to ongoing monitoring.
Official resources:
- Information Commissioner’s Office — UK GDPR guidance
- Information Commissioner’s Office — storage and access technologies
- Information Commissioner’s Office — international transfers
- UK legislation
