Data Processing Terms.
Last updated: 16 September 2026
These Data Processing Terms apply where a school, college, academy, business or other organisation buys course enrolments and chooses which learners to enrol, and we process learner personal data on that organisation’s behalf. They set out our obligations as a data processor under the Data Protection (Bailiwick of Guernsey) Law, 2017.
How these terms apply. They are between the organisation that buys enrolments and manages its learners (the “Customer”, acting as data controller) and Lisia Digital Limited, a company registered in Guernsey (company number 68545), trading as British Sign (“we”/“us”, acting as data processor). They form part of our organisational Terms & Conditions, which the Customer accepts when it buys enrolments, so they apply automatically to every organisational booking – no separate signature is needed. A Customer whose procurement or data-protection procedures require a separately signed copy can request one (see section 8).
1. What the words mean
“Controller”, “processor”, “personal data”, “data subject”, “processing” and “personal data breach” have the meanings given in the Data Protection (Bailiwick of Guernsey) Law, 2017 (the “Law”). “Learner Personal Data” means the personal data we process on the Customer’s behalf to provide the course, as described in Schedule 1. “Sub-processor” means another processor we engage to help provide the service.
2. Our roles
For the Learner Personal Data we process to provide the course, learner accounts, progress tracking and enrolment-management services, the Customer is the controller and we are the processor. We process that data only to provide those services to the Customer and its learners, and as set out in these terms.
3. Processing we carry out as a controller in our own right
These terms do not apply to processing where we, rather than the Customer, decide the purpose and the means – for that processing we are a controller in our own right, and it is governed by our Privacy Policy, not by these terms. It includes:
- our customer and billing records, and the related legal and accounting obligations;
- security, fraud prevention and technical-security logs;
- administering and responding to support enquiries;
- the general administration needed to run British Sign; and
- the minimum certificate record we keep so a certificate issued in a learner’s name can be verified.
4. Our obligations as processor
Where we act as the Customer’s processor, we will:
- Act only on documented instructions. Process the Learner Personal Data only on the Customer’s documented instructions – which include these terms, the organisational Terms & Conditions, and the Customer’s use of the enrolment dashboard – unless we are required to process it by law, in which case we will tell the Customer first unless the law prevents us. We will tell the Customer if, in our opinion, an instruction would breach the Law.
- Keep it confidential. Ensure that the people we authorise to process the data are bound by an appropriate duty of confidentiality and only access the data where they need it for their work.
- Keep it secure. Put in place appropriate technical and organisational measures to protect the data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking account of the risks. Our current measures are described in section 5.
- Use sub-processors responsibly. Engage sub-processors only as described in section 6.
- Help with learners’ rights. Taking account of the nature of the processing, help the Customer respond to requests from learners exercising their rights under the Law (such as access, correction, deletion, restriction, objection or a portable copy).
- Help with breaches and compliance. Help the Customer meet its own duties on security, on notifying and dealing with personal data breaches, and on any assessment of the processing or consultation with the Authority that it needs to carry out. We will tell the Customer without undue delay after we become aware of a personal data breach affecting the Learner Personal Data, with the information the Customer reasonably needs to meet its own obligations.
- Keep records and allow audits. Keep the records of our processing that the Law requires, make available to the Customer the information it reasonably needs to show that we are meeting these terms, and allow for and contribute to a reasonable audit or inspection on reasonable notice – subject to appropriate confidentiality and without compromising the security of other customers’ data.
- Return or delete the data. Each learner’s initial course access lasts two years from that learner’s first login. On the Customer’s instruction, given by contacting us at support@british-sign.co.uk, we will delete or return the Learner Personal Data we hold for a learner on the Customer’s behalf, unless the law requires us to keep it. The one exception is the minimum certificate record described in section 3, which we keep as a controller in our own right.
5. Security measures
Our current technical and organisational measures include HTTPS encryption across the website and learner platform, two-factor authentication on administrative access to hosting, strictly limited administrative access to learner data, regular software and security updates, security monitoring, and daily backups. We may change these measures over time, provided the level of protection is not reduced.
6. Sub-processors
The Customer gives us general authorisation to engage sub-processors to help provide the service. When we do, we put terms in place with each sub-processor that require an equivalent standard of data protection to these terms, and we remain responsible to the Customer for what our sub-processors do.
If we intend to add or replace a sub-processor that processes Learner Personal Data, we will give the Customer reasonable prior notice so that it has the opportunity to object. If the Customer reasonably objects on data-protection grounds and we cannot offer a suitable alternative, either party may end the affected enrolments as set out in the organisational Terms & Conditions.
Our current sub-processors of Learner Personal Data are listed in Schedule 2.
7. The Customer’s responsibilities
As controller, the Customer is responsible for:
- having a lawful basis under the Law to enrol its learners and to give us their details;
- giving learners the information they are entitled to about how their personal data is used;
- giving us instructions that comply with the Law; and
- keeping the learner details it provides accurate and up to date.
8. General
These terms form part of the organisational Terms & Conditions and are governed by the law of the Bailiwick of Guernsey. If there is any conflict between these terms and the rest of those Terms & Conditions on the processing of Learner Personal Data, these terms take precedence. They apply as standard to every organisational booking; a Customer that needs a separately signed copy for its records can email support@british-sign.co.uk.
Schedule 1 – Details of the processing
Schedule 2 – Sub-processors
These sub-processors process Learner Personal Data to help us provide the service:
Revolut (card payments and billing) and Google Analytics (public-website analytics, which is not used in the learner course area) are not sub-processors of Learner Personal Data: they relate to our own processing as a controller, not to the course we provide on the Customer’s behalf. How we use them is explained in our Privacy Policy.
Where a sub-processor processes personal data outside the Bailiwick of Guernsey or the UK, we do so only on the basis of a transfer safeguard permitted under the Data Protection (Bailiwick of Guernsey) Law, 2017 – for instance a transfer to a place recognised as offering an adequate level of protection, or the Guernsey Addendum to the European Union standard contractual clauses. Schedule 2 shows where each sub-processor processes personal data.
