SJ & CO Privacy Notice

SJ & CO Education Services Group Ltd

Version: 1.0 Effective from: 10 June 2026 Last reviewed: 10 June 2026 Next review: June 2027 (annual)

1. Who we are

SJ & CO Education Services Group Ltd (“SJ & CO”, “we”, “our”, “us”) is the data controller for the personal information described in this notice. We are registered in England and Wales (company number 16479080) and with the Information Commissioner’s Office (registration C1943802).

Registered office: 8 Southview, Comeytrowe Road, Trull, Taunton, Somerset, TA3 7NF.

Contact for data protection matters: Sam James, Director, sam@sjandco.uk.

SJ & CO is not required to appoint a Data Protection Officer under UK GDPR Article 37. Data protection queries are handled directly by the Director using the contact details above.

This notice tells you what personal information we hold about you, why we hold it, what we do with it, how long we keep it, and what your rights are. It is written so you can find the section that applies to you.

2. Who this notice is for

SJ & CO is an education consultancy running four service streams plus a small set of supporting activities. Different sections of this notice apply depending on which interaction with us you have. Pick the section that fits you:

  • Section A: Mentees and their families (the mentorship service)

  • Section B: Parents and clients of our tuition introduction service

  • Section C: Tutors registered on our tuition introduction list

  • Section D: Parental advisory clients

  • Section E: Schools engaging us for workshops or talks

  • Section F: Anyone who has contacted us with an enquiry

  • Section G: Visitors to our website

  • Section H: Recipients of any marketing communications

Following the sections that apply to you, Sections I to M cover information that applies across all our interactions: international transfers, your rights under UK GDPR, cookies on our website, how we keep this notice up to date, and how to get in touch.

Section A: Mentees and their families (the SJ & CO mentorship service)

This section applies if you are receiving mentorship from Sam James, or if you are the parent or guardian of a mentee.

The mentorship service involves more processing of personal data, and more sensitive data, than our other streams. The detail is here because we believe families should be able to see clearly what we do with the information they share.

A.1 What personal data we collect

For each mentee, we hold:

  • The mentee’s name, contact details, home address;

  • Date of birth, year group, school, and any relevant educational or personal context disclosed during onboarding or sessions;

  • The parent or guardian’s name and contact details (where the mentee is under 18, or where an adult mentee has nominated a contactable parent/guardian);

  • An audio recording of each mentorship session;

  • A written transcript of each session, generated from the audio recording;

  • A written internal analytical note (the “operational note”) and a written client-facing session summary, produced from the transcript;

  • A planning brief for the next session;

  • Communications between Sam, the mentee and the family between sessions (email, WhatsApp, text, phone);

  • Records of fees raised and payments received.

Session content routinely includes special category data within UK GDPR Article 9 (information about physical or mental health, family circumstances, sexuality, religion or political opinion where mentioned by the mentee). Voice recordings are treated precautionarily as biometric data within Article 9.

A.2 Why we collect it and the lawful basis

The processing of mentees’ personal data is for the following purposes, on the following bases:

  • To deliver the mentorship service under the Mentorship Client Agreement (sessions, written summaries, between-session contact). Lawful basis: performance of the contract under Article 6(1)(b).

  • To record sessions as audio, transcribe them, and produce the operational note and session summary. Lawful basis: explicit consent captured in the Mentorship Client Agreement under Article 6(1)(a). For special category content, explicit consent under Article 9(2)(a).

  • To process session content via the Anthropic Claude API for pseudonymisation, note generation, summary generation, planning, and reflection. Lawful basis as above.

  • To build, where the family has separately opted in, an abstracted corpus of session analyses (see Section A.5 below). Lawful basis: explicit consent under Article 6(1)(a) and Article 9(2)(a).

  • To meet safeguarding obligations, including responding to disclosures and making referrals to statutory authorities where required. Lawful basis: substantial public interest under Article 9(2)(g), as set out in our Safeguarding Policy.

  • To raise invoices and collect payment. Lawful basis: performance of the contract under Article 6(1)(b); legal obligation for record-keeping under Article 6(1)(c).

Children’s consent: under UK GDPR, the age of digital consent is 13. For mentees under 13, parental consent is required. For mentees aged 13 to 17, the mentee themselves can consent in principle, but for the special category processing the mentorship service routinely involves, we treat parental consent (or co-consent) as the safer baseline and seek both. The Mentorship Client Agreement captures this in writing.

A.3 Who we share it with

By default, only the mentee and the family. Specifically:

  • The mentee themselves, the session summary after each session.

  • The mentee’s parents or guardians (where the mentee is under 18, or where the information sharing arrangement agreed at onboarding provides for it), the same session summary as a password-protected PDF.

  • Service providers we use to operate the pipeline: Anthropic (Claude API), Google Workspace (Gmail), and communications platforms (WhatsApp, Apple Messages). The Anthropic relationship is described in more detail in Section A.4 below. We also use Dropbox Sign for the electronic signature of your Mentorship Client Agreement.

  • Statutory authorities (police, local authority children’s services, NHS mental health services, the mentee’s school) only where Sam reasonably concludes that a safeguarding referral is required. In such a case Sam will, where it is safe and appropriate, inform the mentee and the parent or guardian before any referral is made.

We do not share session content with any other family, with any other mentor, with any unrelated third party, or for any marketing or research purpose.

A.4 How we use Anthropic’s Claude API

The mentorship pipeline uses the Anthropic Claude API for several processing steps: pseudonymising the transcript, generating the operational note, generating the session summary, generating reflection questions, and producing the planning brief. This means session content is transferred from Sam’s Mac in the United Kingdom to Anthropic’s infrastructure in the United States for the duration of each API call.

The transfer is covered by Anthropic’s Data Processing Agreement, which is incorporated into Anthropic’s Commercial Terms of Service. Anthropic’s terms include the UK International Data Transfer Addendum and the EU Standard Contractual Clauses as the lawful mechanism for the UK-to-US transfer.

Anthropic retains API content in its logs for up to 30 days for the purposes of safety and abuse detection. Zero Data Retention is not available at SJ & CO’s current Anthropic plan tier. By default, API content is not used to train Anthropic’s models and SJ & CO has not opted in to any training arrangement.

A Transfer Impact Assessment for the Anthropic transfer is held on file by SJ & CO. It is available to families on request.

A.5 The optional corpus

In addition to the session summary and the operational note, SJ & CO produces, for families who have separately opted in, an abstracted analysis of each session. Over time the set of these analyses forms a private “corpus” stored in Sam’s vault, retained for potential future use in training Sam’s continued mentoring practice or to inform future processes developed by SJ & CO.

The corpus is opt-in. Families who do not opt in to the corpus receive the mentorship service identically; no analysis is produced for them and nothing relating to their sessions enters the corpus.

The abstracted analysis is written so that a future mentor could learn from the process without being able to identify the individuals or specifics involved. It does not contain quoted dialogue from the session beyond short technical terms, specific scenarios that could identify the session, client codes, real names, partial names, place names, or specific ages, dates or durations. These restrictions are enforced by an automated check before any analysis is added to the corpus; anything that fails the check is quarantined and reviewed rather than added.

Consent to the corpus use is forward-only: only sessions delivered on or after the date of consent are eligible. Earlier sessions are not retrospectively analysed.

Consent can be withdrawn at any time by writing to sam@sjandco.uk. From the point of withdrawal, no further corpus analyses are produced. Withdrawal can also include a request to erase past corpus analyses produced for the mentee under Article 17 UK GDPR; Sam will action that erasure manually.

The corpus is retained until Sam has decided that no further training or process-development use of it is intended, at which point the source corpus material is deleted.

At the date of this notice, no third party has any access to the corpus. Any future arrangement to share it with an external developer is subject to a written Data Processing Agreement and a non-disclosure agreement put in place before access is granted.

A.6 Pseudonymisation, encryption and access

We use a “coded world / named world” separation in the pipeline. Stored operational artefacts use placeholders for the mentee’s name and for any third party mentioned in the session (a client code such as “M001” rather than the mentee’s name, “[PERSON_A]” rather than a real name). A single “Client Mapping” file held on Sam’s Mac pairs each code with the real-world identity; that mapping is the only file in the system that links the pseudonymised content back to a named person. It is the most carefully protected file in the pipeline.

Sam’s Mac is encrypted at rest using FileVault, auto-locks within minutes of inactivity, and is enrolled in Find My Mac. The vault is not synced to any cloud service. Sam is the sole operator; there are no employees, contractors or family members with access. Session summaries are delivered to families as AES-256 password-protected PDFs, with the password shared via a separate channel.

A.7 How long we keep it

  • Inbox audio (M4A) and working WAV — Retention: Deleted at the end of session processing (operator-confirmed)

  • Raw transcript and pseudonymised transcript — Retention: Deleted after the operational note and session summary are produced (operator-run cleanup)

  • Operational notes, session summaries, planning briefs — Retention: 6 years from end of engagement

  • Client Mapping — Retention: While the client is active, plus 6 years (mirrors the operational records)

  • Corpus analyses (where applicable) — Retention: Until SJ & CO decides no further training or process-development use is intended, then deleted

  • Financial records — Retention: 6 years from end of relevant accounting period (HMRC requirement)

  • Audio retained after a safeguarding disclosure — Retention: Held separately from standard pipeline records, retained only for as long as necessary for the safeguarding purpose

A.8 The information sharing arrangement

The Mentorship Client Agreement records that, at the start of each engagement, Sam, the mentee, and (where the mentee is under 18) the parent or guardian discuss and agree what information from sessions is routinely shared with the parent or guardian, what is shared on request, and what stays between Sam and the mentee. This conversation is led by the mentee alongside the parent. Sam shares information from sessions in line with that agreement, varying it only with the mentee’s knowledge or where a safeguarding referral is required.

When a mentee passes their 18th birthday during the engagement, the arrangement lapses and is renegotiated, this time led by the now-adult mentee. From that point the default position is that no information from sessions is shared with the parent or guardian unless the mentee specifically agrees to it.

Section B: Parents and clients of the SJ & CO tuition introduction service

This section applies if you are the parent or guardian arranging private tuition for your child through SJ & CO Tuition.

B.1 What personal data we collect

When you contact us about tuition we collect: your name, contact details (email, mobile, home address), your child’s first name, year group, school, subject needs, exam boards, target outcomes, and any disclosed learning context, family situation, or special educational needs that are relevant to identifying a suitable tutor match.

B.2 Why we collect it and the lawful basis

  • To facilitate the introduction of a suitable tutor. Lawful basis: performance of the SJ & CO Tuition Client Agreement under Article 6(1)(b); legitimate interests in operating the service under Article 6(1)(f).

  • To raise invoices and collect payment for the introduction fee and the introductory session fee. Lawful basis: performance of the contract under Article 6(1)(b); legal obligation for record-keeping under Article 6(1)(c).

Where a family discloses a special category of personal data (most commonly information relating to a child’s health or special educational needs) for the purpose of informing the tutor match, we process that data on the basis of explicit consent under Article 9(2)(a).

B.3 Who we share it with

  • The selected tutor, the limited information necessary for the introduction and the first session.

  • Service providers we use to operate our processes: Google Workspace (Gmail, Drive), Dropbox Sign (electronic signature of your Tuition Client Registration Agreement), FreshBooks (invoicing), Stripe (card payments). Communications between us may also flow through WhatsApp or Apple Messages.

We do not share your data with any other tutor agency or with any third party for marketing.

B.4 How long we keep your data

  • While the client relationship is active, and then archived for 6 years after the last introduction, to align with the contractual limitation period.

  • Operational communications not load-bearing for contractual or safeguarding purposes: 12 months.

Section C: Tutors on the SJ & CO tuition register

This section applies if you have registered as a tutor on the SJ & CO tuition introduction list.

C.1 What personal data we collect

When you complete the tutor registration form we collect: title, full legal name, date of birth, personal email, mobile telephone number, home address, current school (name and address), role, education and career history, subject specialism, levels taught, exam boards, any examining experience, tutoring format, location and travel radius, availability, hourly rate, experience with SEND, EAL or learning differences, a recent professional photograph, your school-issued Enhanced DBS certificate (uploaded file), DBS reference number and issue date, your DBS Update Service registration status and (where applicable) subscription reference, your declarations about safeguarding (familiarity with Keeping Children Safe in Education, training currency, no prohibitions, no pending investigations, good standing with your employer), your personal interests statement, and your approach-to-tutoring statement for the Tutor Profile.

At identity verification we see your photo identification on a short video call. We do not retain a copy; we record the date of the call and the document type sighted.

When you are introduced to a family we record the date of the introduction, the live DBS Update Service check result against your subscription reference, and the live Teaching Regulation Agency prohibition check result. We do not share your DBS certificate, its reference number, or any other detail beyond the Tutor Profile elements with families.

C.2 Why we collect it and the lawful basis

We collect and use your personal data for the following purposes:

  • To maintain our tutor register, to facilitate introductions, and to administer the Tutor Registration Agreement. Lawful basis: performance of a contract (the Tutor Registration Agreement) under UK GDPR Article 6(1)(b); legal obligation in relation to safeguarding under Article 6(1)(c); and where applicable our legitimate interests in operating an introduction agency under Article 6(1)(f).

  • To verify your identity and your safeguarding suitability, in particular through the two-stage DBS verification standard (inspection of the school-issued Enhanced DBS at registration, then commissioning of a fresh SJ & CO Enhanced DBS through uCheck), the DBS Update Service subscription you maintain following registration, and the per-introduction Update Service and Teaching Regulation Agency prohibition checks. Lawful basis: legal obligation in relation to safeguarding under Article 6(1)(c); performance of the Tutor Registration Agreement under Article 6(1)(b).

  • To share your name, photograph, professional background and subject specialisms with prospective clients in your Tutor Profile. Lawful basis: performance of the Tutor Registration Agreement under Article 6(1)(b). Sharing your photograph and the profile elements is intrinsic to the introduction service the Agreement provides; it is a contractual undertaking under clause 4.3 of the Tutor Registration Agreement (v4.0), not consent.

For DBS data specifically (which counts as criminal offence data under Article 10 UK GDPR), we rely on Schedule 1 Part 2 Paragraph 18 of the Data Protection Act 2018 (Substantial public interest: safeguarding of children and of individuals at risk). This is the basis recorded in our internal Master Appropriate Policy Document.

C.3 Who we share it with

We share your data with:

  • Prospective clients (parents and guardians), only the elements that appear in your Tutor Profile under clause 4.5 of the Tutor Registration Agreement: name, photograph, subjects, levels, exam boards, school, role, qualifications summary, approach quote, interests, format, location, availability, rate, and the fact that an Enhanced DBS is in place. We never share the DBS certificate, the DBS reference number, your home address, your date of birth, or any other detail beyond the Tutor Profile elements with clients.

  • uCheck, our umbrella body, for the purpose of commissioning the SJ & CO-commissioned Enhanced DBS check. uCheck is the controller for the DBS application itself.

  • The Disclosure and Barring Service, when we use the Update Service to confirm your live safeguarding status against your subscription reference.

  • The Teaching Regulation Agency, via the GOV.UK Teacher Services public register, to confirm that you are not subject to a teaching prohibition.

  • Service providers we use to operate our processes: Tally (online intake form, EU-hosted), Make (workflow automation for form intake and the signed-contract step, EU-hosted), Google Workspace (storage, master sheet, email, and the scheduled automation that runs the register; data region set to Europe), eSignatures.io (electronic signature, US-hosted), Canva Pro (Tutor Profile generation, Australia / US-hosted), FreshBooks (invoicing to Clients), Stripe (card payments from Clients). Each is bound by a written data processing agreement under UK GDPR Article 28.

We do not sell your data and we do not share it for any marketing purpose.

C.4 How long we keep your data

The full schedule sits in our internal Data Retention Schedule. In summary:

  • Tutor profile and contact data (form responses, profile, communications): the period of your registration plus 12 months.

  • Signed Tutor Registration Agreement and supporting evidence: 6 years from the end of your registration, in line with the limitation period under the Limitation Act 1980.

  • DBS certificate file: deleted within 30 days of upload. We keep only the reference number and the issue date.

  • DBS reference number, Update Service code, TRA check dates and outcomes: the period of your registration plus 6 years (limitation period).

  • Introduction Log entries: 6 years from the date of each introduction.

Section D: Parental advisory clients

This section applies if you have engaged SJ & CO for our parental advisory service.

D.1 What personal data we collect

The parent or guardian’s name and contact details, family circumstances as disclosed, the child being discussed (first name, age, school, year group), the presenting issue, any disclosed health, special educational needs, behavioural or wellbeing context, and any school correspondence the parent shares.

D.2 Why we collect it and the lawful basis

  • To advise the parent or guardian on educational matters in line with the Advisory Client Agreement. Lawful basis: performance of the contract under Article 6(1)(b).

  • To process special category data where the engagement touches on the child’s health, SEN or related context. Lawful basis: explicit consent under Article 9(2)(a), captured at the start of the engagement.

  • To raise invoices and collect payment. Lawful basis: performance of the contract under Article 6(1)(b); legal obligation for record-keeping under Article 6(1)(c).

D.3 Who we share it with

By default, no one. Where the parent expressly instructs Sam to contact or write to the child’s school on their behalf, Sam will do so by express written consent and only as instructed.

Service providers as for other streams: Google Workspace, Dropbox Sign (electronic signature of your Advisory Client Agreement), communications platforms, FreshBooks, Stripe.

D.4 How long we keep it

Engagement notes: 6 years from the end of the engagement. General correspondence not load-bearing for contractual or safeguarding purposes: 12 months.

Section E: Schools engaging us for workshops or talks

This section applies if your school has engaged SJ & CO to deliver a workshop or talk.

E.1 What personal data we collect

  • The school’s name, address, and the named contact (typically a head teacher, head of pastoral or similar);

  • The named contact’s email and phone;

  • The scope and outcomes of the workshop or talk and any agreed materials;

  • Attendee numbers and any feedback or evaluation data captured.

We do not collect or hold pupil-level personal data through the delivery of workshops or talks. Should a future format ever require pupil data, that processing would be agreed and disclosed separately and would not be covered by this section as it stands.

E.2 Why we collect it and the lawful basis

  • To deliver the workshop or talk under our agreement with the school. Lawful basis: performance of the contract under Article 6(1)(b); legitimate interests in operating the service under Article 6(1)(f).

  • To raise invoices and collect payment. Lawful basis as above plus legal obligation under Article 6(1)(c).

E.3 Who we share it with

By default, no one. Service providers as for other streams: Google Workspace, Dropbox Sign (electronic signature of the Schools Workshop and Talks Agreement), Canva (for materials), FreshBooks, Stripe.

E.4 How long we keep it

Engagement records: 6 years from delivery. General correspondence: 12 months.

Section F: Anyone who has contacted us with an enquiry

This section applies if you have contacted SJ & CO with an enquiry but have not (yet) engaged us for a service.

F.1 What personal data we collect

Your name, contact details, and the content of your enquiry (which may include family or pastoral context).

F.2 Why we collect it and the lawful basis

  • To respond to your enquiry and triage it to the relevant service stream. Lawful basis: steps taken at your request prior to entering a contract under Article 6(1)(b); legitimate interests in responding to enquiries under Article 6(1)(f).

F.3 Who we share it with

No one.

F.4 How long we keep it

If your enquiry does not lead to an engagement, 12 months from the last contact, then deleted. If it does lead to an engagement, the data folds into the relevant stream’s record (Sections A to E above).

Section G: Visitors to our website

This section applies to visitors to www.sjandco.uk.

G.1 What we collect

The SJ & CO website runs on Squarespace. Squarespace processes basic server-log data (IP address, browser type, time of access) as part of operating the site.

The site sets three cookies, confirmed by live audit on 3 June 2026:

  • crumb — Squarespace’s CSRF protection cookie, set on every visit. This is strictly necessary to operate the site and does not require your consent.

  • ss_cvr and ss_cvt — Squarespace’s first-party visitor analytics cookies, used by Squarespace to give us basic aggregate visitor statistics. These are non-essential and are set only if you accept them via the Squarespace cookie banner that appears for UK and EU visitors on first arrival.

We do not embed third-party analytics tools, advertising tools, or social media trackers on the site. We do not use Google Analytics, Facebook Pixel, Hotjar, or any similar service.

Full detail about each cookie, the consent mechanism, how to change your preference, and how to control cookies in your browser is set out in our Cookie Policy.

Where you submit a contact form on the website, that submission is treated under Section F above.

G.2 Lawful basis

Strictly necessary site operation (the crumb cookie): legitimate interests under Article 6(1)(f).

Non-essential analytics (ss_cvr and ss_cvt): your consent under Article 6(1)(a), recorded through the Squarespace cookie banner.

G.3 Retention

Squarespace’s standard server-log retention applies to log data. Cookie durations are set out in the Cookie Policy. Contact form submissions are handled under Section F.

Section H: Recipients of marketing communications

At the date of this notice, SJ & CO does not operate a marketing mailing list and does not send marketing communications. If a mailing tool is adopted in future (for example to support the September 2026 mentee acquisition push), this section will be updated to record the controller’s processing under that tool, and any prospective subscriber will be asked to opt in on a clear, separate basis. Soft opt-in for existing customers may apply where compatible with PECR Regulation 22.

Section I: International transfers

Several of the service providers we use to operate our processes are based outside the United Kingdom. We rely on the following safeguards to ensure your data is protected to the same standard as if it remained in the UK.

  • Google Workspace (Gmail, Drive, Sheets, Calendar) — Country: Europe (data at rest); United States (Google is US-incorporated); Lawful transfer mechanism: UK International Data Transfer Addendum with EU Standard Contractual Clauses, retained because not all services (including the scheduled Apps Script automation) or support access are pinned to the Europe region; Activities: All streams

  • Anthropic (Claude API) — Country: United States; Lawful transfer mechanism: UK IDTA / SCCs, per Anthropic’s Commercial Terms of Service. Subject to a Transfer Impact Assessment held on file; Activities: Mentorship (Section A)

  • Canva — Country: Australia and United States; Lawful transfer mechanism: UK adequacy regulations for Australia; UK IDTA with SCCs for US processing; Activities: Tutor profiles, schools workshop materials

  • eSignatures.io — Country: United States; Lawful transfer mechanism: UK IDTA with SCCs; Activities: Tutor Registration Agreement (Section C)

  • Dropbox Sign (Dropbox International Unlimited Company, Ireland) — Country: United States; Lawful transfer mechanism: UK Extension to the EU-US Data Privacy Framework, backed by Standard Contractual Clauses (DPA on file); Activities: Electronic signature of client and school engagement agreements (Sections A, B, D and E)

  • Tally — Country: European Union; Lawful transfer mechanism: UK adequacy regulations; Activities: Tutor onboarding form (Section C)

  • Make — Country: European Union; Lawful transfer mechanism: UK adequacy regulations; Activities: Tutor pipeline automation (Section C)

  • uCheck — Country: United Kingdom; Lawful transfer mechanism: No international transfer; Activities: Tutor DBS commissioning (Section C)

  • FreshBooks — Country: United States; Lawful transfer mechanism: UK IDTA with SCCs; Activities: Invoicing across streams

  • Stripe — Country: United States; Lawful transfer mechanism: UK IDTA with SCCs; Activities: Card payment processing across streams

  • Squarespace — Country: United States; Lawful transfer mechanism: UK IDTA with SCCs; Activities: Website hosting (Section G)

  • Synology C2 Backup — Country: Germany (Frankfurt region); Lawful transfer mechanism: UK adequacy regulations for the EEA. Backups are encrypted on the controller’s Mac before upload using a personal key held only by the controller; Synology stores only the encrypted blobs and cannot read the contents; Activities: Off-site backup of the controller’s working device (cross-stream)

  • WhatsApp (Meta) — Country: United States; Lawful transfer mechanism: Meta’s standard transfer mechanism; Activities: Communications

  • Apple Messages — Country: United States and elsewhere; Lawful transfer mechanism: Apple’s standard transfer mechanism; Activities: Communications

We do not transfer your data to any other country.

Section J: Your rights under UK GDPR

You have the following rights in respect of personal data we hold about you:

  • The right to access a copy of the personal data we hold about you (Article 15);

  • The right to rectification of inaccurate or incomplete data (Article 16);

  • The right to erasure, subject to exceptions including where we need to retain data to defend a legal claim (Article 17);

  • The right to restrict processing in certain circumstances (Article 18);

  • The right to data portability (Article 20);

  • The right to object to processing based on our legitimate interests (Article 21);

  • The right to withdraw any consent you have given at any time (Article 7(3)). Withdrawal does not affect the lawfulness of processing before withdrawal.

Where the data subject is a mentee under 18, these rights are exercised by the parent or guardian on the mentee’s behalf, subject to any safeguarding considerations and the best interests of the child. From the mentee’s 18th birthday onwards, the now-adult mentee exercises these rights directly.

To exercise any of these rights, write to sam@sjandco.uk. We will respond within one month of receipt of a clear request.

You also have the right to complain to the Information Commissioner’s Office (ICO) if you believe we have mishandled your data. The ICO can be reached at ico.org.uk or 0303 123 1113.

Section K: Automated decision-making

We do not use automated decision-making (including profiling) that produces legal or similarly significant effects on you.

The use of the Anthropic Claude API for the mentorship session pipeline (Section A.4) is not automated decision-making in the Article 22 sense: the AI is used as an assistive tool in the production of written records, with manual review of every output by Sam, and no decisions affecting the mentee are made automatically.

Section L: Case studies and testimonials

We do not include any client’s story, name, or identifying details in marketing material, case studies, or testimonials without seeking that client’s specific consent at the time we wish to do so. For our school clients (Section E), provision for case-study consent is built into the Schools Client Agreement.

Section M: Changes to this notice, and how to contact us

We will review this notice at least annually and update it as our processes change. The current version is always available on request and on our website.

Material changes are communicated by email to clients we are actively engaged with at the time, and through an updated dated version published on the SJ & CO website.

For any question about this notice, or about the data we hold about you:

Sam James, Director SJ & CO Education Services Group Ltd Email: sam@sjandco.uk Telephone: 0730 926 3852