Privacy Notice
Last updated: 15 July 2026
This notice explains how 25Thirty Ltd (“25Thirty”, “we”, “us” or “our”) uses personal information in connection with the Bridge Admissions website, sales, customer relationships and the operation of our services.
1. Who we are
25Thirty Ltd is the controller of personal information described in this notice, except where we process information on behalf of a school using Bridge Admissions.
Registered company: 25Thirty Ltd
Privacy contact: privacy@bridgeadmissions.co.uk
Website: https://www.bridgeadmissions.co.uk
When a school enters information about applicants, pupils, parents, guardians, staff or other contacts into Bridge Admissions, the school will normally be the data controller and 25Thirty will act as its data processor. Questions about that information should normally be directed to the relevant school.
2. Information we collect
Depending on how you interact with us, we may collect:
- your name, job title, school or organisation, email address, telephone number and correspondence;
- information submitted through contact, enquiry, demo or support forms;
- customer administration information, including authorised users, contracts, invoices and payment status;
- technical information such as IP address, browser, device, approximate location, timestamps and security logs;
- website usage and analytics information, where you have consented to non-essential technologies;
- support information, including messages, diagnostic information and recordings where agreed;
- marketing preferences and records of communications;
- recruitment or supplier information where relevant.
We do not intentionally collect personal information directly from children through the public website.
3. How we use personal information
We use personal information to:
- respond to enquiries and arrange demonstrations;
- provide, secure, support and improve our website and services;
- set up and administer customer accounts;
- manage contracts, invoicing and customer relationships;
- investigate faults, misuse and security incidents;
- comply with legal, regulatory, accounting and insurance requirements;
- send relevant business-to-business updates and marketing where permitted;
- understand website performance where consent has been given;
- establish, exercise or defend legal claims.
4. Lawful bases
We rely on one or more of the following lawful bases:
- Contract: where processing is necessary to enter into or perform a contract.
- Legitimate interests: for running and improving our business, responding to business enquiries, maintaining security, preventing fraud and communicating with professional contacts, where those interests are not overridden by individual rights.
- Legal obligation: where we must retain or disclose information to meet a legal duty.
- Consent: for optional cookies, certain marketing communications and any other activity where consent is requested.
- Legal claims: where special category information is processed because this is necessary to establish, exercise or defend legal claims.
Where we rely on consent, you may withdraw it at any time.
5. Information processed for schools
Schools may use Bridge Admissions to manage information about prospective and current families, applicants, pupils, parents, guardians, staff and professional contacts. This may include contact details, admissions history, communications, availability, notes, tasks, documents and, where the school considers it necessary, information requiring additional protection.
For this information:
- the school decides why and how the information is used;
- 25Thirty processes it only on the school’s documented instructions, subject to applicable law;
- the school is responsible for providing appropriate privacy information to individuals;
- our processing is governed by our contract and Data Processing Agreement with the school.
We do not use school-controlled personal data for our own advertising or sell it.
6. Sharing information
We may share information with:
- hosting, infrastructure, email, support, analytics, authentication and security providers;
- professional advisers, accountants, insurers and auditors;
- payment and banking providers;
- regulators, law-enforcement bodies, courts or public authorities where required;
- a buyer, investor or successor in connection with a genuine corporate transaction;
- other parties where you have asked us to do so or where the law permits.
Our current subprocessors are listed at: [SUBPROCESSOR PAGE URL].
We require service providers to protect personal information and use it only for agreed purposes.
7. International transfers
Some providers may process information outside the United Kingdom. Where a restricted transfer occurs, we will use an approved safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with any required risk assessment.
Details of relevant locations and safeguards are provided on our subprocessor page or on request.
8. Retention
We keep personal information only for as long as reasonably necessary. Our typical periods are:
- sales enquiries that do not proceed: [12–24 MONTHS];
- customer and contract records: for the contract term and normally [6 YEARS] afterwards;
- invoices and accounting records: normally [6 YEARS] after the relevant financial year;
- support records: normally [2 YEARS] after closure, unless needed for security or legal reasons;
- security logs: normally [90–365 DAYS];
- marketing records and suppression lists: for as long as needed to respect preferences and legal requirements;
- school-controlled data: as instructed by the school and in accordance with the customer contract.
We may retain information for longer where required by law, an active dispute or a security investigation.
9. Security
We use technical and organisational measures designed to protect information against unauthorised access, loss, alteration or disclosure. These include access controls, encryption, logging, backups, secure development practices and supplier management, as appropriate to the risk.
No online service can guarantee absolute security. Customers should also use strong authentication, appropriate permissions and secure devices.
10. Your rights
Depending on the circumstances, you may have the right to:
- be informed about how your information is used;
- access your personal information;
- correct inaccurate or incomplete information;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- receive certain information in a portable form;
- withdraw consent;
- complain to the Information Commissioner’s Office.
These rights are subject to legal conditions and exemptions. To exercise a right, contact privacy@bridgeadmissions.co.uk. We may need to verify your identity.
Where your request relates to information held by a school in Bridge Admissions, please contact that school first.
11. Marketing
You can opt out of marketing emails at any time by using the unsubscribe link or contacting us. We may retain limited information on a suppression list so that we can respect your request.
12. Cookies
We use essential technologies needed for security and operation. We use non-essential analytics or similar technologies only where permitted and, where required, after consent. See our Cookie Policy for details and controls.
13. Complaints
Please contact us first so we can try to resolve your concern.
You may also complain to the Information Commissioner’s Office. Current contact information is available on the ICO website.
14. Changes
We may update this notice to reflect changes in our services or legal requirements. We will publish the updated version and revise the “Last updated” date. Material changes may also be brought to customers’ attention.