Independent construction quality learning Professionally reviewed · Structured · Searchable
Privacy and confidentiality

Protecting professional participants and responsible learning.

This pilot information explains how contributor and reviewer applications, professional verification, submission evidence, review records and approved public lessons are intended to be handled.

Collection Relevant information for defined purposes
Access Role-controlled platform records
Separation Source submissions and public lessons
Publication Approved anonymised learning only

Status and controller details

This is pilot privacy information describing the platform’s intended operation. It is not a substitute for the final privacy notice approved by the organisation legally responsible for NCQLE.

The final notice must identify the data controller, provide its postal and registration details, name any data-protection contact where applicable and explain the lawful basis for each processing purpose.

Information collected

Depending on how the platform is used, NCQLE may hold:

  • name, email address, telephone number, organisation, enquiry details, requested account type and account-security information;
  • organisation, role, professional-body and membership information;
  • submission drafts, project context and proposed lessons;
  • supporting documents, photographs and other evidence;
  • anonymisation records, reviewer assignments, reviews and decisions;
  • service-email delivery records including recipient, subject, notification type and hosting-server outcome;
  • workflow notes, communications and an audit history of platform actions.

How information is obtained

Most information is provided directly when a person sends an enquiry, registers, updates a profile, submits a lesson, uploads evidence, completes a professional review or otherwise communicates with the Exchange.

A contributor may also provide information concerning another person or organisation. Contributors should only provide such information where it is necessary and they are permitted to do so.

Why information is used

Information is intended to be used to:

  • create and secure user accounts;
  • receive and respond to general enquiries;
  • assess contributor and expert reviewer applications and manage authorised roles;
  • receive, store and administer confidential lesson submissions;
  • undertake triage, anonymisation and multidisciplinary review;
  • send account and lesson service notifications, communicate decisions and request clarification;
  • protect the integrity, security and auditability of the Exchange;
  • prepare and publish approved transferable learning.

The final policy must assign and document the appropriate lawful basis for each purpose rather than assuming one basis applies to every activity.

Confidential and published records

The identifiable source submission is held as a separate record from the anonymised lesson prepared for professional review and publication. A contribution is not automatically placed in the public library.

Only the approved public record should contain the context, conclusion, recommended action, evidence rating and limitations required for transferable professional learning.

Access and disclosure

Platform access is intended to be controlled by role:

  • contributors can access their own submission records;
  • reviewers can access material assigned to them for professional review;
  • authorised administrators can manage verification, anonymisation, review and publication;
  • public visitors can access approved published lessons only.

The final notice must identify relevant service providers, processors and other recipient categories, and explain the circumstances in which information may be disclosed to an appropriate authority or reporting body.

Security, retention and deletion

The platform uses account authentication, role-based access and workflow records to restrict and audit access. These controls reduce risk but cannot provide an absolute guarantee of security.

Retention periods must be approved for accounts, unsuccessful verification records, withdrawn submissions, original evidence, review records, published lessons, system logs and backup copies. The final notice must explain those periods or the criteria used to determine them.

Essential cookies and session information

The secure account area uses essential session information to maintain sign-in state, protect forms and route authorised users to the correct workspace. The final cookie information should identify the cookies actually deployed, their purposes and their duration.

Your rights, questions and complaints

Depending on the circumstances, individuals may have rights relating to access, correction, deletion, restriction, objection and portability of their personal information.

Questions or requests should be sent to info@ncqle.org. The final notice must identify the data controller and provide a complete internal complaint route.

People in the UK can also obtain information about their data-protection rights or raise a concern with the Information Commissioner’s Office.