1. Purpose and scope
Mavera Group Ltd, trading as Level Up Education, is committed to responsible handling of personal information. This policy explains our organisation-wide approach to data protection and confidentiality. It applies to personal information relating to students, prospective students, parents or guardians, staff, contractors, institutional contacts, website visitors and other people who interact with us.
We seek to comply with the UK General Data Protection Regulation, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations where applicable, and relevant guidance from the Information Commissioner's Office.
2. Data-protection principles
We require personal information to be:
- processed lawfully, fairly and transparently, with clear information provided to the people concerned;
- collected for specified purposes and not used in an incompatible way;
- adequate, relevant and limited to what is necessary;
- accurate and kept up to date where appropriate;
- kept no longer than necessary for the relevant purpose;
- protected by appropriate security against unauthorised access, loss, destruction or damage;
- supported by records and controls that allow us to demonstrate accountability.
3. Roles and responsibilities
Management is responsible for ensuring proportionate data-protection measures are in place and reviewed. Anyone handling personal information for us is expected to:
- access information only when required for authorised work;
- keep passwords, devices and records secure;
- follow approved methods for sharing and disposing of information;
- maintain confidentiality during and after their engagement;
- report mistakes, suspicious activity and possible breaches promptly;
- complete appropriate data-protection and security awareness training.
We remain responsible for deciding the purpose and means of processing when acting as controller. Where another organisation instructs us to process information on its behalf, responsibilities must be recorded in an appropriate written agreement.
4. Lawful, fair and transparent processing
Before collecting personal information, we identify the purpose, the lawful basis and the minimum information required. Where special category or criminal-offence information is involved, an additional lawful condition must also be identified and documented.
Privacy information must be clear, accessible and provided at an appropriate time. Personal information must not be used for a new, incompatible purpose without reviewing the legal basis and updating the information given to the individual.
5. Data minimisation and website forms
We collect only information reasonably needed for an enquiry, agreed service, application, legal duty or legitimate operational purpose. Public website forms do not request document uploads. Passport copies, identity documents, transcripts, certificates, financial evidence and other sensitive records must not be submitted through those forms.
If detailed application records are required later, we will explain what is needed and provide an appropriate method for supplying them. Duplicate, excessive and obsolete records should be removed.
6. Accuracy
Reasonable steps must be taken to keep information accurate where it is used to make decisions or provide guidance. People should be given a clear route to correct inaccurate or incomplete information. Where a correction is disputed, the disagreement and any restriction on use should be recorded where appropriate.
7. Confidentiality and access control
Access to student and business records is limited to authorised people with a genuine need to know. Confidential information must not be discussed, copied, downloaded or shared for personal purposes or with unauthorised recipients.
We use proportionate controls such as account authentication, access permissions, secure devices and communications, software updates, backups where appropriate, and secure disposal. Sensitive information should not be sent through unapproved channels.
8. Children and special-category information
Additional care is required where information concerns a student under 18, accessibility or health needs, ethnicity, religion or other special-category matters. Such information is collected only where necessary and lawful, access is restricted, and a parent or guardian is involved where appropriate.
9. Sharing, processors and international transfers
Personal information is shared only where necessary, lawful and consistent with the privacy information provided. Before using a service provider that handles personal information for us, we consider the nature of the information, the provider's role, security, location and contractual protections.
A processor must act only on documented instructions, maintain confidentiality, provide appropriate security and assist with rights requests and incidents where required. International transfers must use a lawful transfer mechanism and any necessary supplementary safeguards.
10. Retention and secure disposal
Records are retained according to their purpose, legal requirements, limitation periods and operational need. They must be reviewed and securely deleted, destroyed or anonymised when no longer required. Our public-facing retention approach is explained in the Privacy Policy.
11. Individual rights requests
Requests for access, correction, erasure, restriction, portability, objection or withdrawal of consent must be sent promptly to the person responsible for handling data-protection matters. We verify identity proportionately, keep a record of the request and respond within the applicable legal time limit, normally one calendar month.
No person should alter, conceal or delete information in order to avoid responding to a rights request or complaint.
12. Data-protection complaints
Anyone may raise a complaint by emailing [email protected]. We will:
- provide a clear route for making the complaint;
- acknowledge receipt within 30 days;
- make appropriate enquiries and investigate proportionately;
- keep the complainant informed where necessary;
- communicate the outcome without unjustifiable delay;
- retain an appropriate record of the complaint and response.
A person who remains dissatisfied can complain to the Information Commissioner's Office.
13. Personal data breaches
A suspected loss, unauthorised disclosure, accidental transmission, compromised account or other personal-data incident must be reported immediately. We will record and assess the incident, contain it where possible, preserve relevant evidence and take remedial action.
Where legally required, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. Where a breach is likely to create a high risk to an individual, we will also notify the affected person without undue delay.
14. Risk assessment, training and review
Privacy and security risks should be considered when introducing a new service, provider or way of using information. A data protection impact assessment will be completed where processing is likely to create a high risk to individuals.
This policy is reviewed at least annually and sooner where legislation, guidance, technology, services or risks materially change.
Data-protection contact
Email: [email protected]
Phone: +44 7388 913388
Post: Mavera Group Ltd, Unit 3 Dulcia Works, Herbert Street, London, England, E13 8BE

