LAST UPDATED · FEBRUARY 2026
Privacy Policy
1. Introduction
ACE Portfolios ("we", "our", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform.
2. Data We Collect
- Account Information: Name, email address, phone number, date of birth, and role within your organisation.
- Portfolio Data: Evidence files, assessment records, qualification progress, and IQA/EQA activity logs.
- Usage Data: Login timestamps, IP addresses, device information, and browser metadata for security and audit purposes.
- Communication Data: In-app messages, support tickets, and contact log records.
3. How We Use Your Data
- To provide and maintain the portfolio management service.
- To authenticate your identity and enforce multi-factor authentication.
- To generate assessment reports and track qualification progress.
- To send notifications about portfolio activity, deadlines, and system updates.
- To maintain audit trails for regulatory compliance.
- To detect and prevent security threats and unauthorised access.
4. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract: Processing necessary to provide the services agreed with your organisation.
- Legitimate Interest: Security monitoring, fraud prevention, and service improvement.
- Legal Obligation: Maintaining audit trails as required by awarding body regulations.
5. Data Retention
Portfolio data and evidence files are retained for a minimum of 3 years after qualification completion, in line with awarding body requirements. Account data is retained for 12 months after account closure. Audit logs are retained indefinitely for compliance purposes.
6. Data Security
We implement robust security measures including:
- Encryption in transit using modern TLS, including TLS 1.3 for supported connections.
- AES-256 encryption for data at rest.
- Multi-factor authentication (TOTP/SMS) for all accounts.
- Row-level security policies ensuring data isolation between organisations.
- Layered edge, application and database security controls that are reviewed regularly.
7. Your Rights
Under GDPR and the UK Data Protection Act 2018, you have the right to:
- Access your personal data.
- Request correction of inaccurate data.
- Request deletion of your data (subject to retention requirements).
- Object to processing of your data.
- Request data portability.
- Lodge a complaint with the ICO (Information Commissioner's Office).
8. Contact Us
For any privacy-related enquiries or to exercise your rights, contact us at:
privacy@aceportfolios.co.uk
