Last updated 23 September 2026
Privacy policy
Papaya Learner Journey is a competency and training record service for employers. This policy explains what personal data is processed, who decides why, and the rights people have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The English text is the version that applies.
Who we are
Bidlow Ltd provides Papaya Learner Journey. The service is hosted at papayalearner.bidlow.co.uk. In this policy, “we” means Bidlow Ltd as the provider of the service. “Customer” means the employer or other organisation that has an account. “You” means a person whose personal data is processed — usually an employee or a manager using the service on the customer’s instructions.
- Product
- Papaya Learner Journey
- Provider
- Bidlow Ltd
- Service
- https://papayalearner.bidlow.co.uk
- Provider website
- https://bidlow.co.uk
- Company number
- 16374082
- Registered office
- 27 Roxburgh Road, Stamford, Lincolnshire, England, PE9 2XE
- Privacy contact
- support@bidlow.co.uk
- Data protection officer
- No DPO is appointed
The privacy contact is support@bidlow.co.uk. No DPO is appointed.
Controller and processor
For personal data about the customer’s workforce that is entered into the service, the customer is the controller. The customer decides which employees are recorded, what competency statements apply, and what evidence is uploaded. Bidlow Ltd is the processor: we host and maintain the service and handle that data on the customer’s instructions.
Bidlow Ltd is an independent controller for a narrow set of its own business data: the customer’s account administration (who may sign in as a manager), security logs, this website’s strictly necessary cookies, and the commercial relationship with the customer. Those activities are described below and are not a substitute for the customer’s own privacy notice to its staff.
A signed data processing agreement sets the Article 28 terms between the customer and Bidlow Ltd. This page is not that agreement. How to request the current template is on the retention and data processing page.
Personal data we process
Depending on how the customer uses the service, that includes:
- Identity and work details: name, employee reference, area or department, role, and employment status.
- Account details: email address, a hashed password, language preference, and sign-in history needed to keep the account secure.
- Competency records: knowledge, skill, and behaviour statements, scores, knowledge-check answers, manager and employee sign-off, and the dates of those events.
- Evidence the customer or employee uploads: documents, photos, and similar files attached to an assessment.
- Training and audit records: assigned training, audit responses, and related notes.
- Technical data: session cookies, the organisation a platform administrator is working in, and a short-lived copy of an assessment saved on the device if it was submitted while offline.
The service is built for competency and training records. It does not ask for special category data (such as health, trade-union membership, or biometrics). Customers should not upload that kind of data in evidence files or notes unless they have their own lawful basis and have agreed it with Bidlow Ltd. Please do not put it in a support email either.
Why we process it
- To provide the service the customer has asked for: assessments, progress, documents, and audit records.
- To keep accounts secure, including ending a session when someone leaves or a password is reset.
- To remember the language a person chose, so the product can be read on a multilingual site.
- To translate competency text or a document when a customer uses those optional text features.
- To draft a training-video script from a competency statement when a manager uses that feature. The video itself is then rendered as slides. Realistic video generation is not part of the service we offer.
- To meet legal duties that apply to us, and to help the customer meet duties that apply to them, such as keeping evidence of training.
We do not sell personal data. We do not use it for advertising.
Lawful bases
Where the customer is controller, the customer chooses the lawful basis for its workforce data. For training and competency records that is commonly a legal obligation (health and safety, and customer or retailer audit standards) or the customer’s legitimate interests in running a competent shift. Employment-contract necessity may also apply. The customer must say which basis it relies on in its own staff privacy notice.
Where Bidlow Ltd is controller, we rely on legitimate interests (securing and running the service) and, for the commercial relationship with the customer, contract. We do not rely on consent for the strictly necessary cookies described in the cookie policy. Consent is not required for those cookies under the Privacy and Electronic Communications Regulations.
Where personal data is processed
The database and file storage are in Microsoft Azure, UK South. The web application currently runs in Azure, West Europe, on the hosting plan in use today. West Europe is in the EEA. Transfers from the UK to the EEA are covered by the UK’s adequacy regulations for the EU.
xAI and Hugging Face may process the text sent to those features outside the UK. Where that happens, the transfer tool is the UK International Data Transfer Agreement (or the Addendum to the EU clauses), unless an adequacy regulation applies. The signed data processing agreement will name the locations that apply to a particular customer. Hosting regions can change; this page will be updated when they do, and the agreement prevails if the two differ.
How long we keep it
Training and assessment records are kept for the length of employment and for at least six years after the person leaves. That period is how the product is built: an employee with scores, sign-off, or uploaded evidence cannot be hard-deleted, and marking them as resigned or dismissed keeps the record and starts the six-year clock. The full summary, including accounts, cookies, and backups, is on the data retention page.
The customer remains responsible for its own retention schedule where the law requires a longer or different period. The six-year floor is the product default so that health and safety training can still be shown to an inspector. It is not a promise that every category of data is kept for six years.
Your rights
Under UK GDPR you may ask to access your personal data, correct it, erase it, restrict it, or object to processing based on legitimate interests. You may also ask for portability where the processing is based on contract or consent and is carried out by automated means. These rights are not absolute. In particular, a request to erase training records can be refused while the retention period above still applies, because the customer needs those records to show that training took place.
If you are an employee, contact your employer first. They are the controller and can see and correct your record. If you contact Bidlow Ltd, we will help the customer respond, and we will not use that request as a reason to delete records the retention rules require us to keep.
You can complain to the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113). We would like the chance to put something right first, but you do not have to contact us before you contact the ICO.
Security
Passwords are stored as hashes. Sessions expire after a period of inactivity and are checked against the account so that a person who has left, or whose password has been reset, does not keep access. Access inside the product is limited by role: an employee sees their own journey, and a manager sees the people in their organisation. Evidence files are stored through the service’s storage layer, not on a page the public can browse.
No online service can promise that a breach is impossible. If we become aware of a personal-data breach that affects a customer’s workforce, we will tell the customer without undue delay so they can meet their own duties to the ICO and to their staff.
Children
The service is for employers and their workforce. It is not directed at children, and customers must not use it to keep records about children.
Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects a customer’s workforce, we will also tell the customer’s account contacts. The customer is responsible for telling its own staff.
How to contact us
Write to support@bidlow.co.uk, the privacy contact shown in the company details at the top of this page. For questions about a particular employee’s record, the customer (the employer) is the right first stop. The terms of use are at /terms.
