| Title: | Creatio Privacy Protection Policy |
|---|---|
| Version & Status: | 14.0 |
| Date of Issue: | 22nd September 2026 |
| Author: | Rose Ahmed |
This Privacy Protection Policy explains the principles and arrangements that Creatio Limited (“Creatio”) follows when collecting, using, storing, sharing and protecting personal data. It supports our compliance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable data-protection legislation. Client contracts contain appropriate data-processing provisions and we have data-processing agreements in place with sub-processors where required by Article 28 of the UK GDPR.
The Privacy Protection Policy applies to all staff, contractors, partners, clients and third parties who process personal data on behalf of Creatio Limited (“Creatio”) and is published on our corporate website and in the footer of each of the creatiogreen websites.
Looking after the personal information you share with Creatio is very important to us, and we want you to be:
Creatio is registered with the Information Commissioner’s Office (ICO) and is committed to following its guidelines to safeguard the data we hold in any way we can, in an endeavour to prevent any PII breaches affecting our staff, contractors and clients. Our ICO registration can be found at https://ico.org.uk/ESDWebPages/Entry/Z185906X.
We apply the following strict rules in the use of personal data, and we ensure the information we hold is:
Creatio considers data protection by design and by default when developing or materially changing its services, introducing new technology, engaging a new sub-processor or integration, or changing how personal data is collected, used, shared or retained.
DPIA screening is completed when new or materially changed processing involving personal data is considered, in accordance with the ROPA and DPIA Assessment Procedure. Where the screening indicates that the processing is likely to result in a high risk to individuals’ rights and freedoms, a full Data Protection Impact Assessment is completed before the processing begins. The assessment records the proposed processing, its necessity and proportionality, the risks to individuals and the measures adopted to reduce those risks. Assessments and screening decisions are retained and reviewed when the processing or associated risks materially change.
Records of Processing Activities and Data Protection Impact Assessments
Creatio maintains a Record of Processing Activities (ROPA) covering the personal-data processing it undertakes as controller and processor. The ROPA records the nature and purpose of the processing, the categories of individuals and personal data involved, Creatio’s role, recipients and sub-processors, international transfers, retention arrangements and relevant technical and organisational security measures.
A ROPA record must be created or updated when Creatio introduces or materially changes a service, feature, integration, supplier, sub-processor, client requirement or other activity involving personal data. Existing ROPA records are reviewed at least annually and whenever there is a material change to the processing.
DPIA screening is completed as part of the ROPA review. Where the screening identifies that processing is likely to result in a high risk to individuals, Creatio will complete and approve a separate Data Protection Impact Assessment before the processing begins.
The DPIA process considers the nature, scope, context and purposes of the processing, its necessity and proportionality, the risks to individuals and the measures required to reduce those risks. Where Creatio acts as processor, it will support the relevant client in meeting its responsibilities and will assess Creatio’s own technical, contractual, security and operational arrangements.
The Head of Corporate Governance coordinates the ROPA and DPIA records. Relevant Account Managers and Heads of Department are responsible for identifying proposed or changed processing and initiating a review in accordance with the ROPA and DPIA Assessment Procedure.
Creatio provides a software solution – primarily to various education companies - which is called creatiogreen (each client calls their version of the software solution by a specific name) – and we generally act as the data processor and the relevant client acts as the data controller.
The creatiogreen software solution is delivered under a contractual agreement with each client and the client is responsible and leads on the configuration of the software to meet their business operations and needs and therefore decides the data they collect and which we then hold on their behalf. The data collected by each client is done so in accordance with their data needs and they process it in accordance with their own specific data processing policies and arrangements.
Therefore, if you have any queries about the data collected on a version of the creatiogreen software then please contact the client directly or contact Creatio (contact details are at the end of this policy) and we will provide you with their contact details where relevant.
Each client, as controller, is responsible for determining the purposes and lawful basis for its processing and for providing appropriate privacy information to individuals. Creatio remains responsible for meeting its own legal, contractual and security obligations as a processor.
The law states organisations must have one or more of these reasons for collecting personal data and these are:
In relation to Creatio and the data we collect and hold for our business purposes, our main reason for collecting personal information is to provide and improve the services, products, and experiences that our staff and clients expect from us.
The following table provides an indication of the typical data sets we hold for staff, contractors, clients, partners, and third parties and which are likely to contain personal data.
| Main client data sets we collect | Our reason for collecting this information (legal basis) | Creatio and Client’s possible use of the data – note this is a high-level summary of typical reasons we see/are aware of and you should contact each client for specific details on the way they may use the data they collect via the creatiogreen software |
|---|---|---|
| User details – entered in creatiogreen as part of setting up or maintaining a User Account. As a minimum this contains first name, last name, and email address per User. Some clients may configure their version of the creatiogreen software to hold photos, CVs, certificate details and other personal details per User type such as home address. |
Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details. Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client. |
As with most software solutions a User must be registered before they can use and access the system. Each client can configure the fields and therefore the data they collect per User type and for assigning the relevant access rights in accordance with their business arrangements. Also, each client can add a clear ‘consent’-related statement/field which Users should accept and agree to when creating a user account – again, whether this field is included and its wording are decided by each client. A User would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked Creatio to interface or exchange data with under their contract with Creatio. |
| Customer/organisation details – including contacts, staff, email addresses, finance including bank card details and other business premises (e.g. sites). Some clients may configure their version of the creatiogreen software to hold photos, CVs, certificate details and other personal details per record type. |
Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details. Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client. |
The creatiogreen software can be configured to capture details for our clients in relation to their customers and their associated organisations and companies – including their key contacts, staff details and other venues. All these record types have the potential to contain personal details. Each client can configure the fields and therefore the data they collect per record type and add a clear ‘consent’ statement/field which users should accept and agree to upon creating a user account – again, the inclusion or not of this field and its wording is decided by each client. You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us. |
| Learner details – including name, age, gender and possibly home and contact details and national learner number identifier details. Also details of the qualifications they have achieved/been registered against and details of the grades/outcomes of their education activities. Some clients may configure their version of the creatiogreen software to hold photos and other personal details. |
Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details. Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client. |
The creatiogreen software supports various education bodies and depending on the modules they use within the software it can capture details of learners registered with our clients in relation to the qualifications and products they offer. Each client can configure the fields associated with learners and add a clear ‘consent’ statement/field in relation to learner records – again, whether this field is included and its wording are decided by each client. You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us. |
| Information that may be provided when completing a business process outlined by our clients and which is supported by the creatiogreen software – such as giving information or details when completing a client’s online form or log in the software solution. This may also include additional files you may upload when addressing requirements outlined by the client in the Form(s). Or comments Users may make in the Form(s) or pass in relation to information exchanged with the client organisation. This may include information or comments provided in relation to other staff, colleagues, Users or learners at your organisation – such as comments in relation to grading information or performance. |
Creatio processes this information on the documented instructions of the relevant client under our contractual data-processing arrangements. The client, as data controller, determines the applicable lawful basis. Please refer to the client’s privacy notice for details. Creatio does not use the data collected by our clients other than as part of the service we provide under our contractual agreement with each client. |
In relation to information entered in the creatiogreen software via forms or onscreen fields there are various reports in the system that will extract this data for the client – for Users they have authorised with such access rights. Equally clients can configure forms to automatically update a customer’s profile at the end of a transaction (e.g. automated processing). You would need to contact the relevant client to obtain the reason they collect the information they do, what they may do with the data once collected, and how it is used with third-party systems they have asked us to interface or exchange data with under their agreement with us, as well as to understand any automated decision-making processes they use with the data held in the system. |
We collect personal information that you share with us when you are employed by Creatio or you contact us or interact with us through our website, social media, email, phone, in person at meetings, and events, or other similar interactions. For example, you will provide information to us when you contact us and/or our staff, invite us to tender for a contract, place an order, complete a survey, competition, or questionnaire, update your preferences and account information, connect with us through our websites.
| Additional main data sets we collect | Our reason for collecting this information (legal basis) | Creatio’s possible use of the data – note this is a high-level summary of typical reasons we see/are aware of |
|---|---|---|
| Staff details – personal details in relation to our staff including date of birth, personal contacts, home address and personal email addresses, finance including bank account and payroll details and identification documentation (such as passports and driving licenses) This may include details that have been provided for HR and payroll arrangements and documentation and details provided to carry out DBS checks. |
We process staff information where necessary to perform employment contracts, comply with our legal obligations and pursue our legitimate interests in managing the business, staff and workplace. Where we process health or other special-category information, we also identify an applicable Article 9 condition. Criminal-offence information, including information used for DBS checks, is processed only where permitted by law and subject to appropriate safeguards. |
We use the data for internal and external HR and payroll arrangements, emergencies and DBS security checks for employed staff. Data is only retained for as reasonably necessary in line with GDPR legislation. |
| Head office Closed - circuit television (CCTV) Footage – records identifiable people | We collect for our legitimate business interests to prevent crime, help support staff and public safety, and our secure premises and assets and providing valuable evidence in the case of incidents / investigations. Creatio does not use this data to monitor staff behaviour and attendance to the office. |
We have CCTV installed at our offices and have signs to inform staff and visitors of these arrangements. We only use this data in the event to safeguard staff and visitors or to help investigations of incidents and data is only monitored by our Managing Director in the event of an incident and retained for no longer than is necessary and is only provided to the necessary authorities upon request to help with investigations. |
| Creatio corporate website and social media – data collected including (IP) address, browser software you use, the device you use, your operating system, the date and time of access, the internet address of the website from which you link through to our website, information on how you use our website and the activities you undertook, crash data if an error occurred. | We use cookies and similar technologies in accordance with PECR and applicable data-protection legislation. Cookies that are strictly necessary for the operation and security of the service may be used without consent where permitted by law. For other cookies, we obtain consent or rely on an applicable statutory exception. Where an exception requires us to provide a means of objecting, users are given a clear and simple way to do so. | We may interact with you on social media. You may use social media to contact us about our creatiogreen software and services. The information we collect from social media and online sites sometimes includes personal information that has been put online and is publicly available. We make sure any information we use is done so in accordance with the arrangements in this policy and either properly credited to its source or is made anonymous. These online and social media sites typically have their own privacy policies explaining how they use and share personal information. |
| Prospective Client Data – data collected including names, job titles, organisations, business email addresses, telephone numbers and information provided through website enquiries, emails, meetings, demonstrations, tenders, referrals and other sales enquiries. | To respond to enquiries, prepare tenders and proposals, discuss potential services and pursue Creatio’s legitimate business interests. Where someone asks us to take steps before entering into a contract, we may also process their information for that purpose. | To respond to enquiries, communicate with prospective clients, prepare tenders and proposals, arrange demonstrations and meetings and manage potential business opportunities. We may also provide relevant business updates where permitted by data protection and electronic marketing rules. |
| creatiogreen software analytical data collected - including (IP) address, browser software you use, the date and time of access, the internet address of the website from which you link through to our creatiogreen software, information on how you use our creatiogreen software and the activities you undertook, crash data if an error occurred. | We collect data and review data from our creatiogreen software to better understand the conditions in which our creatiogreen software is used/accessed and for investigation purposes in the event of any Cyber Security incidents which may have originated from a client or their customers or Creatio. | To help us deliver on our contract obligations with our clients and optimise the network security and performance, and deal with fixing bugs/defects in the software we provide. Review the usage of various parts of the software to inform future enhancements and upgrades to the software and service. Prevent, detect, or investigate fraudulent activity or inappropriate and offensive use or behaviour and to identify violations of service policies. Support – where required by law or where we believe it is necessary to protect our legal rights, interests, and the interests of others - use information about you in connection with legal claims, compliance, regulatory, and audit functions. |
| Transform client helpdesk data collected – including User’s first name, surname, and contact details. | We collect for our legitimate business reasons to support the delivery of our services and respond to queries/requests. And to notify clients about enhancements to our services, such as our regular software updates. |
Contact users to carry out KIT meetings, clarify change requirements or assist with bugs/ defects that have been reported. Contact Users to undertake customer satisfaction surveys or invite them to provide product reviews or to inform market research activities. |
If you share details of other people with us (for example, your staff/colleagues), then you will need to check with that person that they are happy for you to share their personal information with us, and for us to use it in accordance with this privacy policy.
The creatiogreen system and company corporate website(s) use cookies to collect and store certain information. These typically involve pieces of information or code that a website transfers to or accesses from your computer hard drive or mobile device to store and sometimes track information about you. Cookies allow us to create a unique device ID to enable you to be remembered when using that computer or device to interact with websites and online services and can be used to distinguish Users and manage a range of features and content, including storing searches and presenting personalised content to improve your experience.
It is important to note that most cookies we use expire when you close your browser or log out of the system. Others are used to remember you when you return to our system and will last for longer. We use these cookies on the basis that they are necessary for the performance of a contract with our clients, or because using them is in our legitimate interests (where we have considered that these are not overridden by your rights), and, in some cases, where required by law, where you have consented to their use.
We use the following types of cookies:
Most web browsers automatically accept cookies, but if you prefer, you can change your browser to prevent these cookies. The effect of disabling cookies depends on which cookies you disable but, in general, our creatiogreen system will not operate properly if all cookies are switched off.
We may share your personal information with companies that support our clients if the clients require us to interface or exchange data with them in accordance with the scope of the contractual agreement with Creatio to meet their business needs or data portability arrangements. You should therefore contact the client direct to understand the data they have requested to be shared and what they may do with this data (also note it is our client’s responsibility to make it clear in their consent text and/or privacy policies how data you provide is used across different systems they use for their business purposes). Examples of other organisations/systems with whom such data may be shared:
In relation to data Creatio holds for its own business purposes we do not share this with external parties except for:
All the data captured on:
Where personal data is transferred outside the UK, we ensure that an appropriate UK data-transfer safeguard or other lawful transfer mechanism is in place, where required.
Where Creatio processes personal data through creatiogreen on behalf of a client, the information is retained in accordance with the client’s documented instructions, the applicable contract and agreed retention arrangements. On termination, personal data is returned or securely deleted in accordance with those arrangements, subject to any legal requirement or agreed backup-retention period.
However, there may be times when we hold the data for slightly longer if we need this information to establish, bring or defend legal claims (note that in such circumstances we anticipate using not personal data itself, but the details around the total number of users, customers, transactions, and types of transactions undertaken in creatiogreen software and system).
Staff information is retained in accordance with Creatio’s Data Retention Policy or Schedule, taking account of relevant employment, tax, pension, insurance and legal requirements.
For users of our website(s), we keep the details you provide only to respond to your online enquiry and, if this does not lead to a new contract, we delete the details within 7 years or earlier if you contact us to remove the personal data we hold.
In addition to the right to be informed (set out in this policy), under UK GDPR you have certain rights as outlined below. The rights apply where the relevant legal conditions apply.
In exercising any of these rights, it is important to note that if the data is processed:
In relation to the data we hold for Creatio for our own business purposes and activities, you can contact us direct if you wish to remove your consent or opt out of marketing communications at any time by clicking the unsubscribe options or contacting us (our contact details are at the end of this policy).
The security of your personal information is important to us, and we implement a range of measures to protect your data as best we can. However, as you are aware, no method of transmission over the internet, or method of electronic storage, is 100% secure, and users may not robustly protect their passwords or may use unsecured networks. Therefore, we cannot guarantee its absolute security. If you have any questions about security, please contact us (details at the end of this policy).
Some of the controls we have in place include:
These controls are designed to minimise the risk of unauthorised access, accidental loss, or misuse of your personal data.
In the event of a data breach:
Staff and contractors must report suspected incidents immediately via our internal arrangements.
Clients should report suspected incidents affecting their creatiogreen system via Transform (helpdesk), info@creatio.org.uk or by contacting their Creatio Account Manager by telephone.
We will take steps to contain and investigate the incident, identify root cause, apply remediation, and document decisions and actions. We incorporate lessons learned into our processes.
We encourage you to contact us first before making any formal complaint and we will seek to resolve any issues or concerns you may have. Our contact details are below.
You have the right to make a formal complaint with the data protection regulator in the UK - the Information Commissioner's Office (ICO) (www.ico.org.uk).
We review the policy annually and revise it as and when necessary, in response to feedback, changes in our practices or changes to relevant legislation. If we make changes to this notice, we will publish the latest version on our company websites, our client-facing helpdesk service (called Transform), and in the footer of each version of the creatiogreen solution we provide to clients.
If you have any queries about this privacy policy or about the use of your personal data or want to exercise your privacy rights, please contact us at info@creatio.org.uk or by posting to Creatio Ltd, Phoenix Wharf, Eel Pie Island, Twickenham, TW1 3DY.