Privacy Policy

Privacy Statement

 

 

Effective Date: March 27, 2025

 

Our Commitment

The HEART/NSTA Trust (referred to as “HEART”, “We” or “Our”}, as the leading provider ofTechnical Vocational Education and Training in Jamaica, is committed to human development. As part of this commitment, we will ensure that the personal information we collect and process, is kept confidential and shared only with authorised personnel (internally/externally} in accordance with the principles in the Data Protection Act. We commit to strict adherence to the Data Protection Act; always operating in a manner that will safeguard the Organisation from sanctions.

 

HEART’s data subjects include current and past trainees, staff members (including those who are separated}, HEART contributors, employers, and other partners such as suppliers and contractors. We commit to abide by the basic principle that everyone has a right to privacy and therefore everyone expects confidentiality.

 

We may update this Privacy Statement periodically to reflect changes in our privacy practices with respect to the services or changes in applicable law, regulations and standards.

 

The purpose of this Privacy Statement is to inform you about our practices in relation to:

      how we collect your personal information;

      what personal information we collect;

      how your personal information is used, stored, and disposed of;

      who we share your personal information with;

      how we secure your personal information; and

      your rights.

 

What is personal information?

Personal information, as we use it in this privacy statement, falls in two categories:

i.        personal data – information that can be used to identify an individual.

ii.        sensitive personal data- a special category of information which may be used to identify an individual and must be handled with greater care. This category, if exposed, can have severe consequences and therefore must only be handled if there is a need to do so. Examples include medical records, biometric information (such as fingerprints}, and sex life.

 

How does HEART collect your personal information?

We collect your personal information in both electronic (e.g. email, scanned documents, virtual chats, meeting recordings, and data from our website} and paper formats. Your personal information is collected in one (or a combination} of three(3} ways:

 

i.        Directly from you. We obtain your personal information when you apply for a job, training, or to conduct business with HEART. During engagement, additional personal information may be collected and processed.

ii.        From others. We obtain your personal information from references you provide to us upon application for a job, to do business, or participate in one of our training programmes. Additionally, we collect your personal information from our training partners. We may also be required to contact previous training providers to verify your personal information.

If you are a current or past employee, we may also obtain some of your personal information from a previous employer.

Your personal information will only be accessed from these-sources with your permission.

 

iii.        From publicly available sources. We may obtain personal information from the internet and the media (newspapers, radio, television and social media – Facebook, lnstagram, Twitter, etc.). We only look at what you have made available publicly and never consult ‘dark sources’ (those that obtain personal information without the permission or, sometimes, knowledge of the data subject).

 

What personal information does HEART collect?

The personal information we collect includes:

      Names

      Addresses

      Telephone numbers

      Email addresses

      Date of birth

      Gender

      Nationality

      Ethnicity

      Marital status

      Employment details

      Educational background

      Disabilities/medical conditions

 

We also collect copies of certificates, transcripts, or identification (Driver’s License, Passport, National Identification, etc.) which contain your personal information.

 

How does HEART manage your personal information?

Personal information is managed in four parts:

i.        how we use your personal information;

ii.        how we store your personal information;

iii.        how long do we retain your personal information; and

 

iv.        how we dispose (destroy) of your personal information when we no longer need to retain it.

 

I.             How do we use your personal information?

Only those persons who need to use your personal information, based on their job function, will have access. These persons include:

      Receptionist who may be the first officer to accept your documents when you submit for processing. Thereafter, the Receptionist will submit the documents to the relevant personnel for further processing.

      The Human Resources Management Team who maintains staff files.

      The Admissions Team who are responsible for determining if trainees meet the requirements for a training programme.

      Trainers who handle trainees’ personal information.

      The Legal Department who is responsible for all litigation matters, contract, labour relation matters and other documents regarding legal relationships.

      The Auditors who audit records for operational purposes.

      The Finance and Revenue Services Division who is responsible for processing payments and revenue collection

      The Corporate Services Division who is responsible to managing procurement of goods and services

      The Information, Communications and Technology Division that is responsible for storage of Organisation wide data

 

II.            How do we store your personal information?

We store active paper records with personal information at HEART locations in secured, locked storage containers. However, when personal paper records become inactive, they are transferred to our Records Centre for storage. The Records Centre stores all types of paper records belonging to staff and students. Access to inactive paper records at the Records Centre is strictly controlled by the Manager with responsibility for Records and Information Management. Only authorised persons can request access to paper records that contain personal information.

 

We have several computer programmes that store electronic records. These programmes are enforced by access restriction based on employees’ job functions. This is called role-based security.

 

As part of the security of personal information, the Information and Communications Technology Division performs daily (incremental) and weekly (full) backup to safeguard against loss of information. Only authorised persons from our Information and Communications Technology ICT} team can access these backups.

 

Ill.   How long do we retain your personal information?

Your personal information is retained in accordance with our established Records Retention and Disposition Schedule. It is retained to enforce the agreements and contractual obligations we have with other entities, comply with applicable laws, regulations and standards, address complaints and facilitate audits.

 

Not all personal information is retained for the same length of time before disposal.

 

      For trainees:

information relating to enrolment and orientation is retained for 6 years; assessment information is retained for 7 years;

lifelong learning partner certificate request information is retained for 4 years; and

      information concerning the distribution and tracking of certificates is retained for 6 years.

 

      For staff

attendance reports are retained permanently. personal information is retained for 50 years.

staff development information (performance evaluations, information on overseas travel, seminars and workshops attended, certifications attained) and information related to motor vehicle loans is retained for 10 years.

emails sent to our info@heart-nsta.org are retained for 1 year; and

information collected from social media, telephone calls, and face-to-face interactions is retained for 2 years.

 

IV.          How we dispose (destroy) of your personal information when we no longer need to retain it?

Your personal information is disposed in a secure manner to prevent unauthorised access or release

to a third party. Paper records containing personal data are destroyed by confidential shredding, while personal data held in electronic format are disposed by deleting the information and the physical destruction of the devices that collected and/or stored the information. Whether your personal information is paper-based or electronic, HEART ensures that the most secure and confidential method of disposition is utilised.

 

Who do we share your personal information with?

The personal information of staff, trainees, contractors, and suppliers is shared with the government and partners based on our legal and contractual obligations.

 

Since we are a training organisation, we share personal information with partners such as:

         potential employers (trainees would be advised, prior to sharing their personal information);

         certifying bodies (e.g. National Council on Technical and Vocational Education and Training (NCTVET), University Council of Jamaica (UCJ), City and Guilds, The American Culinary Institute);

         insurance providers; and

         partners for work-study programmes.

 

How does HEART secure your personal information?

We maintain active paper records with personal information at HEART locations in secured, locked storage containers. Access to your personal information is restricted to only authorised personnel.

 

Access to inactive paper records with personal information stored at the Records Centre is strictly controlled by the Manager with responsibility for Records and Information Management. Only authorised persons can request access to inactive paper records that contain personal information.

 

Electronic records with personal information are stored on computers – both PCs and servers – and only authorised users can access these computers. Authorised users are assigned a unique username and password to access computers.

Our computers are connected to a network that is protected by a firewall which is constantly monitored and provides 24/7 alerts to our ICT Security team in the event of an attempted or a suspected intrusion.

 

What are your rights in relation to your personal information?

You are guaranteed certain rights, under law, and HEART enforces these rights.

         The Right to access your personal information

You may ask us what personal information we have for you, and we will provide you with a description of that data. You may request a copy of the personal information, and we will provide you with this information for a small fee.

 

         The Right to consent and withdraw consent for us to process your personal information We will seek your permission to handle your personal information. This permission will always be sought unless we are legally obligated (by government or the courts) to process your personal information, are processing your personal information as part of the services we provide to you or on your behalf or are processing your personal information to fulfil a contract at your request.

 

         The Right to prevent processing

You have the right to ask that we stop processing your personal information. However, if it goes against what we must do to provide service to you or others (we call this our Legitimate Interest) or if the processing is required by law or contract, then we will not be able to stop processing your personal information.

 

         The Right to correct inaccurate personal information

If you believe that the personal information we have for you is incorrect, you have a right to make the correction. You may request that we stop processing your personal information until it is corrected.

 

Once you advise of the inaccuracy, we will correct the information within five (5) working days.

 

         The Right in relation to automated decision-taking

You have a right to have another person review or make important decisions about you. Various technology tools are used to assist the organisation to operate, however, the use of these tools does not remove your right.

 

Should you have questions, concerns, and/or comments, please feel free to contact our Data Protection Officer at dpo@heart-nta.org.

 

APPENDIX 1

 

Legal Definitions

Personal Data means information (however stored) relating to:

(a)           a living individual; or

(b)          an individual who has been deceased for less than thirty years, who can be identified from that information alone or from that information and other information in the possession of, or likely to come into the possession of, the data controller;

It includes any expression of opinion about that individual and any indication of the intentions of the data controller or any other person in respect of that individual.

 

Sensitive Personal Data means personal data consisting of any of the following information in respect of a data subject:

(a)          genetic data or biometric data;

(b)          filiation, or racial or ethnic origin;

(c)           political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar nature;

(d)           membership in any trade union;

(e)           physical or mental health or condition;

(f)            sex life;

(g)          the alleged commission of any offence by the data subject or any proceedings for any offence alleged to have been committed by the data subject.