PapayaLearner Journey

Last updated 23 September 2026

Privacy policy

Papaya Learner Journey is a competency and training record service for employers. This policy explains what personal data is processed, who decides why, and the rights people have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The English text is the version that applies.

Who we are

Bidlow Ltd provides Papaya Learner Journey. The service is hosted at papayalearner.bidlow.co.uk. In this policy, “we” means Bidlow Ltd as the provider of the service. “Customer” means the employer or other organisation that has an account. “You” means a person whose personal data is processed — usually an employee or a manager using the service on the customer’s instructions.

Product
Papaya Learner Journey
Provider
Bidlow Ltd
Service
https://papayalearner.bidlow.co.uk
Provider website
https://bidlow.co.uk
Company number
16374082
Registered office
27 Roxburgh Road, Stamford, Lincolnshire, England, PE9 2XE
Privacy contact
support@bidlow.co.uk
Data protection officer
No DPO is appointed

The privacy contact is support@bidlow.co.uk. No DPO is appointed.

Controller and processor

For personal data about the customer’s workforce that is entered into the service, the customer is the controller. The customer decides which employees are recorded, what competency statements apply, and what evidence is uploaded. Bidlow Ltd is the processor: we host and maintain the service and handle that data on the customer’s instructions.

Bidlow Ltd is an independent controller for a narrow set of its own business data: the customer’s account administration (who may sign in as a manager), security logs, this website’s strictly necessary cookies, and the commercial relationship with the customer. Those activities are described below and are not a substitute for the customer’s own privacy notice to its staff.

A signed data processing agreement sets the Article 28 terms between the customer and Bidlow Ltd. This page is not that agreement. How to request the current template is on the retention and data processing page.

Personal data we process

Depending on how the customer uses the service, that includes:

  • Identity and work details: name, employee reference, area or department, role, and employment status.
  • Account details: email address, a hashed password, language preference, and sign-in history needed to keep the account secure.
  • Competency records: knowledge, skill, and behaviour statements, scores, knowledge-check answers, manager and employee sign-off, and the dates of those events.
  • Evidence the customer or employee uploads: documents, photos, and similar files attached to an assessment.
  • Training and audit records: assigned training, audit responses, and related notes.
  • Technical data: session cookies, the organisation a platform administrator is working in, and a short-lived copy of an assessment saved on the device if it was submitted while offline.

The service is built for competency and training records. It does not ask for special category data (such as health, trade-union membership, or biometrics). Customers should not upload that kind of data in evidence files or notes unless they have their own lawful basis and have agreed it with Bidlow Ltd. Please do not put it in a support email either.

Why we process it

  • To provide the service the customer has asked for: assessments, progress, documents, and audit records.
  • To keep accounts secure, including ending a session when someone leaves or a password is reset.
  • To remember the language a person chose, so the product can be read on a multilingual site.
  • To translate competency text or a document when a customer uses those optional text features.
  • To draft a training-video script from a competency statement when a manager uses that feature. The video itself is then rendered as slides. Realistic video generation is not part of the service we offer.
  • To meet legal duties that apply to us, and to help the customer meet duties that apply to them, such as keeping evidence of training.

We do not sell personal data. We do not use it for advertising.

Lawful bases

Where the customer is controller, the customer chooses the lawful basis for its workforce data. For training and competency records that is commonly a legal obligation (health and safety, and customer or retailer audit standards) or the customer’s legitimate interests in running a competent shift. Employment-contract necessity may also apply. The customer must say which basis it relies on in its own staff privacy notice.

Where Bidlow Ltd is controller, we rely on legitimate interests (securing and running the service) and, for the commercial relationship with the customer, contract. We do not rely on consent for the strictly necessary cookies described in the cookie policy. Consent is not required for those cookies under the Privacy and Electronic Communications Regulations.

Who we share it with

We use these sub-processors to run the service. They may handle personal data only so we can provide it:

  • Microsoft Azure — application hosting, the PostgreSQL database, and file storage for evidence and documents.
  • xAI — optional text features only: drafting a training-video script, translating competency text, and translating or summarising a document. The text the customer submits is sent for that purpose. xAI is not used to render the training video.
  • Hugging Face — illustrations for slide-based training videos, when a manager has approved a script and the render step runs. The script text is sent so an image can be produced.

We also share personal data if the law requires it, or with professional advisers who are bound to confidentiality. We do not share a customer’s workforce data with another customer. A platform administrator at Bidlow Ltd can open a customer account to support it; that access is limited to people who operate the service.

The signed data processing agreement, when issued, is the place that lists sub-processors as a contractual schedule. This page describes the ones the product uses today. If that list changes, we will update this page and the date at the top.

Where personal data is processed

The database and file storage are in Microsoft Azure, UK South. The web application currently runs in Azure, West Europe, on the hosting plan in use today. West Europe is in the EEA. Transfers from the UK to the EEA are covered by the UK’s adequacy regulations for the EU.

xAI and Hugging Face may process the text sent to those features outside the UK. Where that happens, the transfer tool is the UK International Data Transfer Agreement (or the Addendum to the EU clauses), unless an adequacy regulation applies. The signed data processing agreement will name the locations that apply to a particular customer. Hosting regions can change; this page will be updated when they do, and the agreement prevails if the two differ.

How long we keep it

Training and assessment records are kept for the length of employment and for at least six years after the person leaves. That period is how the product is built: an employee with scores, sign-off, or uploaded evidence cannot be hard-deleted, and marking them as resigned or dismissed keeps the record and starts the six-year clock. The full summary, including accounts, cookies, and backups, is on the data retention page.

The customer remains responsible for its own retention schedule where the law requires a longer or different period. The six-year floor is the product default so that health and safety training can still be shown to an inspector. It is not a promise that every category of data is kept for six years.

Your rights

Under UK GDPR you may ask to access your personal data, correct it, erase it, restrict it, or object to processing based on legitimate interests. You may also ask for portability where the processing is based on contract or consent and is carried out by automated means. These rights are not absolute. In particular, a request to erase training records can be refused while the retention period above still applies, because the customer needs those records to show that training took place.

If you are an employee, contact your employer first. They are the controller and can see and correct your record. If you contact Bidlow Ltd, we will help the customer respond, and we will not use that request as a reason to delete records the retention rules require us to keep.

You can complain to the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113). We would like the chance to put something right first, but you do not have to contact us before you contact the ICO.

Security

Passwords are stored as hashes. Sessions expire after a period of inactivity and are checked against the account so that a person who has left, or whose password has been reset, does not keep access. Access inside the product is limited by role: an employee sees their own journey, and a manager sees the people in their organisation. Evidence files are stored through the service’s storage layer, not on a page the public can browse.

No online service can promise that a breach is impossible. If we become aware of a personal-data breach that affects a customer’s workforce, we will tell the customer without undue delay so they can meet their own duties to the ICO and to their staff.

Children

The service is for employers and their workforce. It is not directed at children, and customers must not use it to keep records about children.

Changes to this policy

We will post any change on this page and update the date at the top. If a change materially affects a customer’s workforce, we will also tell the customer’s account contacts. The customer is responsible for telling its own staff.

How to contact us

Write to support@bidlow.co.uk, the privacy contact shown in the company details at the top of this page. For questions about a particular employee’s record, the customer (the employer) is the right first stop. The terms of use are at /terms.

Privacy policy — Papaya Learner Journey