Data processing
Four of our five products are ours to answer for. One is not. This page explains which, why it matters to you, and what we sign.
Module Six Ltd is the data controller for your personal data, except in the one case described under “Where we are not the controller” below. We are registered in England and Wales under company number 17311940, at Henge Barn, Pury Hill Business Park, Alderton Road, Towcester, Northamptonshire, NN12 7LS, and with the Information Commissioner’s Office under reference ZC198668.
The Institute of Project Professionals is a professional body we operate. It is not a separate legal entity. Where an Institute document says the Institute decides something, it means Module Six Ltd acting as the Institute, and Module Six Ltd is answerable for it. There is one controller behind everything here, and it is us.
Validate is the one exception. An employer uses Validate to hold an Authority to Work register: which of their workers hold which competencies, what each is cleared to do, and the evidence behind it. Those are the employer’s records about the employer’s workforce.
For those records the employer is the controller and Module Six Ltd is the processor. We act on their written instructions, not our own judgement. If you appear on an employer’s register and want your record changed or removed, ask your employer. We will show you everything we hold and pass your request on, but we will not delete an employer’s evidence that its people were qualified to do the work they did on the instruction of somebody who is not their controller. The terms are at modulesix.co.uk/dpa.
Most of what we hold is private to you and to the people you work with. Three things are different, because their whole purpose is to be seen, and all three are yours to switch off.
Where an outcome you claim names somebody else — a sponsor, a client organisation, a project — the person who confirms it is told what they are confirming, and their confirmation is recorded against your record with their name and the date. They may withdraw it. Editing a confirmed claim removes the confirmation, because it was given for what the claim said at the time.
What appears on each public surface, field by field, and the basis for each, is set out in IPP-DAT-002. This section is the summary; that document governs.
What the Institute holds about a member, including the public register of members and what is published in it, is set out in full at ipp.pro/privacy.
Four suppliers process personal data on our behalf. Each is bound by a written agreement, acts only on our instructions, may not use your data for its own purposes, and is listed here with the safeguard we rely on where data leaves the United Kingdom. No other party processes personal data on our behalf, and we sell nothing, share nothing with advertisers or data brokers, and run no tracking service.
That is a different question from who your information reaches. Where you publish a Passport, appear in the public register, make yourself visible to recruiters, or where your employer holds a register you are on, your information reaches people who are not our suppliers and who are not acting on our instructions. They answer for what they do with it on their own account.
Stripe has two roles and it matters which is which. When it takes a payment on our instruction it is our processor and this notice governs it. When it decides how to detect fraud, how to meet its own anti-money-laundering and identity obligations, and how to manage its own relationship with you, it is a controller in its own right. For that part Stripe’s own privacy policy applies alongside this one and you exercise your rights against Stripe. We cannot instruct them out of obligations they carry directly.
We hold encrypted backups so we can recover from a failure. Daily backups are deleted after 30 days and weekly backups after 365 days. An erasure does not reach into a backup, so for a short period after we erase you a copy may remain in one until it expires on that schedule. We do not restore a backup to bring erased data back.
You can ask us to do any of the following, and it is free.
We answer within one month. If a request is complex we may take longer, and if we do we will tell you inside that month, why, and when to expect an answer.
Two limits, stated so they are not a surprise. Where a record is the basis of somebody else’s entitlement we may anonymise it rather than delete it, so that the other person does not lose something they hold. And for an Authority to Work register we act on the employer’s instruction and not yours, as above.
MS-DAT-001 · Issue 1 · 25 August 2026
Anything in this notice, including a request under “Your rights”, goes to data@modulesix.co.uk. It reaches a person.
If you are unhappy with how we have handled your personal data you can complain to us, and we would rather you did, because we can usually fix it. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, and you do not have to come to us first.
A complaint about the Institute, its decisions or its members is a different route, set out in IPP-GOV-006 at ipp.pro/complaints.
Module Six Ltd operates five products: the Institute of Project Professionals, Calibrate, Educate, Activate and Validate. For the first four we are the data controller. We decide what personal data is held and why, and we answer to the individuals concerned.
Validate is different. A Validate register holds competence and authorisation records about your workers, gathered so that you can show who is cleared to do what. You decide who goes on it, which competencies matter and how long the record is kept. That makes you the controller and us your processor. We process those records only on your instructions.
Owning the software does not make us the controller of what you put in it. UK GDPR decides the roles by who determines the purposes and means of the processing, and for a workforce competence register that is you.
The contract that binds us to all of the above is our standard data processing agreement. It is a single document used two ways, so the terms you get are the terms everybody gets.
MS-DAT-002 · Issue 1 · 16 August 2026
Issued as MS-DPA-001 and renumbered on 25 August 2026. No change to the terms of the agreement.
This agreement is incorporated into the terms you accept at checkout. We record which version you accepted and when, against your order. You do not need to sign anything separately, and you do not need to ask us for a copy: it is the document above.
Where we load your workforce data on your behalf rather than you entering it yourself, we ask for a signed copy before any real person is written to your register. That is a technical block, not a promise: the import is refused until the signature is recorded.
We use a small number of suppliers to run the platform, and under the agreement they are our sub-processors for your data. They are named in the agreement, and we commit to telling you before we add or replace one so that you have the chance to object.
Your data is stored in the United Kingdom and the European Economic Area. Where a supplier processes it elsewhere, the agreement sets out the safeguard we rely on.
We would rather say this here than have you find it in clause 9. When you instruct us to delete a register, we delete it from our own storage, including uploaded evidence files. Copies held by our suppliers, such as an authentication account or an email delivery log, fall out on those suppliers' own retention cycles rather than immediately. The agreement says so in terms rather than promising something we cannot yet do.
Data protection questions, including anything about this agreement, go to data@modulesix.co.uk.