Privacy Policy
Version 1 · Last updated 17 April 2026
1. Who we are
PathwaySkills is a Functional Skills assessment and learning platform operated by Pathways+ Limited, a company registered in England and Wales with its registered office at 24 Beaumaris Close, Dudley, England, DY1 3LX.
Pathways+ Limitedis the "data controller" for the personal information we hold about you under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
You can contact our Data Protection Officer by email at help@pathway-skills.com or by post at the registered office address above.
2. The personal data we collect
When you or your training provider use PathwaySkills, we collect:
- Account information — your name, email address or username, hashed password, role (student, teacher, organisation manager), the training-provider organisation you belong to, and optional profile details.
- Learning activity — Initial Assessment and Subject Knowledge Assessment responses, practice-question attempts, topic test scores, mock exam attempts, Personal Learning Plan progress, and timestamps of your activity.
- Course and enrolment data — the courses you are enrolled on, the groups you belong to, and the teachers assigned to you.
- Technical data — IP address, browser, device information, and session cookies necessary to keep you signed in. See section 9 for cookie detail.
- Support correspondence — any messages you send us at help@pathway-skills.comor through the platform's messages feature.
3. How we use your data and our lawful basis
We only process your personal data when we have a lawful basis under UK GDPR Article 6:
- Contract (Article 6(1)(b)) — to provide the PathwaySkills service to you and your training provider, including account creation, assessment delivery, progress tracking, and support.
- Legal obligation (Article 6(1)(c)) — to meet our obligations under education-funding rules where the provider is delivering an apprenticeship (e.g. ESFA record-keeping requirements).
- Legitimate interests (Article 6(1)(f)) — to secure the platform, prevent abuse, and improve our service. We balance these interests against your rights.
- Consent (Article 6(1)(a)) — for non-essential cookies or any optional marketing communications. You can withdraw consent at any time.
4. How long we keep your data
We keep your learning records for as long as you are actively enrolled with your training provider, and then retain them for up to six years after your enrolment ends. This retention period reflects funding-audit requirements for UK apprenticeship and Functional Skills delivery, and the general limitation period for contractual claims under English law.
Technical logs (IP address, security events) are kept for up to 12 months. Support email correspondence is kept for up to 3 years. Backups that include your data are held for up to 35 days after deletion, after which they are overwritten.
If you ask us to delete your account, we tombstone your record immediately so no-one can use your email or username again, and purge the underlying personal data at the next scheduled cleanup cycle unless we are legally required to retain it.
5. Who we share your data with
Your training provider and the teachers assigned to you can see your progress, assessment results, and account details — that is the point of the platform. We do not sell your data. We share personal data with the following categories of processors strictly to run the service:
- Hosting — Vercel Inc. (US/EU region) hosts the application.
- Database — Neon Inc. (EU region) stores the underlying data.
- Email delivery — Resend, Inc. sends transactional emails (password reset, welcome, notifications).
- Error monitoring — Functional Software, Inc. trading as Sentry (opt-in) collects error reports to help us diagnose issues.
- Product analytics — Plausible Insights OÜ (EU-hosted, privacy-friendly). No cookies used; no personal data is sent.
Each processor is bound by a data processing agreement that requires them to protect your data and only use it on our instructions.
6. International data transfers
Most of our processors host your data in the UK or EU. Where a processor (for example, Sentry) processes data in the United States, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses as the safeguard.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you (a "Subject Access Request").
- Rectify inaccurate or incomplete data.
- Have your data erased ("right to be forgotten"), subject to retention obligations in section 4.
- Restrict or object to our processing.
- Receive your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email help@pathway-skills.com. We will respond within one calendar month.
If you are not satisfied with our response you have the right to complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint.
8. Security
Passwords are stored as salted bcrypt hashes; we never see or store the password itself. All traffic is encrypted in transit with TLS. Administrative access to production data is restricted and logged. We review our security measures regularly.
9. Cookies
PathwaySkills uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery (for example, our NextAuth session cookie). These cookies are set automatically because the service cannot function without them.
Non-essential cookies (for example, anonymous usage analytics) are only set with your consent, captured via our cookie banner at first visit. You can change your preferences at any time by clearing the cookie banner setting and reloading the page.
10. Children
PathwaySkills is intended for learners aged 16 and over studying Functional Skills with a registered UK training provider. If you believe a child under 16 has an account set up without parental consent, please contact help@pathway-skills.com and we will investigate.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified to you in-app or by email. The version date at the top of this page always reflects the current edition.