Privacy Policy

HOW WE PROTECT YOUR PRIVACY

This privacy policy tells you how we CourseWeDo.com, a trading division of Worth Publishing Limited, a company registered in the United Kingdom number 01234904, collect, use, and protect your personal information. By visiting coursewedo.com or swis.reach2teach.net or worthpublishing.com (our websites), you accept and agree to the terms and conditions of this privacy policy. This privacy policy applies to information we collect on our websites and through e-mail and other electronic messages between you and us. It does not apply to information collected by any third party, including through any application or content that may be accessible from our websites. In particular, by visiting our websites you consent to our collection and use of your personal information as described in this privacy policy, including any updates or revisions to this privacy policy.

1. GENERAL DATA PROTECTION REGULATION (GDPR) AND THE DATA PROTECTION ACT (UK 2018).
We are processing your data on the basis of legitimate interest as defined under Article 6 of the GDPR. Registered Users must satisfy themselves they have a lawful interest in entering and processing data under the terms of the GDPR. A Registered User is defined as a person or organisation that has a unique email and password in order to enter our web site. By agreeing the contents of this Privacy Policy Registered Users warrant that they already have such lawful interest. We are and will not be responsible for any liability whatsoever if a Registered User does not have a lawful interest in processing data under the GDPR or allows a third party to know of and or use their unique email and password. If a Registered User is unsure of their status under the GDPR they are responsible for clarifying this by visiting the web site below:

https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing

2. CHILDREN UNDER 18 YEARS OF AGE
We do not knowingly provide services or sell products to children. If you are below the age of 18, you may use our websites only with the permission and active involvement of a parent or legal guardian. If you are a minor, please do not provide us or other website visitors with any personal information and do not use our websites. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at info@coursewedo.com

3. THIS POLICY IS PART OF OUR TERMS AND CONDITIONS OF USE
Our privacy policy is part of, and subject to, our websites’ terms and conditions of use. You may view these terms and conditions on our websites.

4. THE TYPE OF INFORMATION WE COLLECT FROM YOU
Like most places on the Internet, simply by visiting our websites you automatically tell us certain information. This includes basic information such as your IP address, when you visited, the website from where you came prior to visiting us, the website where you go when you leave our websites, your computer’s operating system, location data, and the type of web browser that you are using. Our websites automatically record this basic information about you.

And like many other websites, we may use cookies or similar tracking technologies. In plain English, this means information that our websites’ server transfers to your computer. This information can be used to track your session on our websites. Cookies may also be used to customize our website content for you as an individual. We may also use the services of Google Analytics. You can see how Google uses data when you use our partners’ sites or apps by clicking on this link www.google.com/policies/privacy/partners/. If you are using one of the common Internet web browsers, you can set up your browser to either let you know when you receive a cookie or to deny cookie access to your computer.

We may also collect any data that you provide us by posting it at our websites or by e-mail, including information by which you might be personally identified such as name, postal address, e-mail address, and telephone number, and/or any other contact or personally identifiable information.

5. REGISTERED ACCOUNTS / APPLICATION USERS

If you have a registered account and are a user of applications provided by us, you may voluntarily provide, and we may collect and store, additional information related to the registered account, including but not limited to: your email address, name and contact information, any API key provided by you or images you choose to upload. An application programming interface key (API key) is a code passed in by computer programs calling an application programming interface (API) to identify the calling program, its developer, or its user to the Web site.

You can always choose not to provide us with information. However, if you do withhold information, you may not be able to make use of some or all of our websites’ services and features.

Some transactions between you and our websites may involve payment by credit card, debit card, checks, money orders, and/or third party online payment services. In such transactions, we will collect information related to the transaction as part of the course of doing business with you, including your billing address, telephone number, and other information related to the transaction.
We may also obtain information from third parties, for example, our business partners, third-party suppliers, and customers.

6. WHAT WE DO WITH YOUR INFORMATION
We use your information to operate our business activities. For example, we may use this data to contact you about changes to our website, new services, or special offers, provide you with notices about your account, resolve disputes, troubleshoot issues, enforce our website’s terms and conditions, to carry out our obligations and enforce our rights arising from contracts entered into between you and us, to protect our business interests and the interests and rights of third parties, and to fulfil any other purpose for which you provide data.

As a general rule, we will not give your data to third parties for direct marketing purposes without your permission. However, there are some important exceptions to this rule that are described in the following paragraphs and the paragraphs above.

We may, in our sole discretion, provide information about you to comply with a court order, law or legal process, to law enforcement or other government officials for purposes of fraud investigations, alleged intellectual property infringement, or any other suspected illegal activity or matters that may expose us to legal liability or infringe on our rights or the rights of third parties.

We may provide information about you to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal information held by us about our website users is among the assets transferred.

We may disclose aggregate data about our websites’ visitors to advertisers or other third parties.

From time to time, we may use third party suppliers to provide services on our websites. If a supplier wants to collect information about you through our websites, you will be notified. We restrict the way third party suppliers can use your information.

We will share information with third parties to fulfil the explicit purpose for which you provide it. For example, we will post information that you enter into our blog’s comment system to our blog; share information where you give consent; and use information for the purpose that is disclosed by us when you provide the information; we share information with third parties who assist us in operating our business; for example if we use an email-service-provider, we may provide your email to such vendor to assist us in sending email communications.

All information inputted into SWIS (Social Worker Inclusion Software) is stored in the cloud (Azure, AWS or Linode) and is fully encrypted and secure.

If you have a registered account and are a user of SWIS, all information and data that you enter will remain the property of the organisation the account is held by. Should you archive data or unsubscribe from SWIS the deleted data will be encrypted in the cloud and lie dormant and remain the property of your organisation or relevant institution.

In order to help other professional users of SWIS follow the progress of children who have been assessed by you we have created a facility to transfer data. This is particularly useful for those responsible for looked after children to be able to keep track of a child when they move to a new area away from their organisation.

Should a child move organisation or institution, a professional at their new organisation (providing they are a registered user of SWIS) can search the SWIS database to see if the child’s case record is registered on SWIS (either an active account or an archived account). No information regarding the child is divulged at this stage. The professional can request for the child’s account to be released from their old organisation and transferred to the new. The Team Leader of the old organisation will receive a notification with the requester’s details and contact information, should they need further information and can either accept or decline the transfer. In the event of the old organisation no longer being a subscriber of SWIS, the SWIS team will contact the organisation and gain written consent to transfer the child’s account before any data can be transferred.

You can refuse to agree to a data transfer. In general, however, it is clearly helpful for those taking on responsibility for the welfare of a child after your relationship with the child has ended that they have as full a picture of the child’s history as possible. We therefore hope that you will agree to transfer data when requested.

7. USER NAMES AND PASSWORDS
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a username and password for access to certain parts of our website, you are responsible for keeping the username and password confidential. Do not give your password to anyone. If you enter a section of our websites that requires a password, you should log out when you leave. As a safety precaution, you should also close out of your web browser completely and re-open it before viewing other parts of the Internet.

8. ACCESSING AND CORRECTING YOUR INFORMATION
If you have a customer account with us, you can review and change your personal information by logging into our websites and visiting your account profile page. You may also send us an e-mail at info@coursewedo.com to request access to, correct or delete any personal information that you have provided to us. We cannot delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

9. YOUR VOLUNTARY DISCLOSURE OF INFORMATION TO THIRD PARTIES WHO ARE NOT OUR SUPPLIERS
You may choose to provide personal information to website visitors or other third parties who are not our suppliers. Please use caution when doing so. The privacy policies and customs of these third parties determine what is done with your information.

10. DATA PROCESSING AGREEMENT
As part of our Privacy Policy you, as Data Controller (Data Controller), must enter into an agreement between you, a registered user of our website swis.reach2teach.net and whose contact details are those you have registered with us, and we, who are the data processor (Data Processor) at swis.reach2teach.net a website owned by Worth Publishing Limited a company registered in England number 01234904 whose address is Highgate Cottage Cheltenham Road Broadway WR12 7BX.

WHEREAS:
(1) You agree we as Data Processor shall provide you as Data Controller the Services described in Schedule 1.
(2) The provision of the Services by the Data Processor involves it in processing the Personal Data described in Schedule 2 on behalf of the Data Controller.
(3) Under Article 28(3) of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) (the UK GDPR), the Data Controller is required to put in place an agreement in writing between the Data Controller and any organisation which processes personal data on its behalf governing the processing of that personal data.
(4) The Parties have agreed to enter into this Agreement to ensure compliance with the said provisions of the UK GDPR in relation to all processing of the Personal Data by the Data Processor for the Data Controller.
(5) The terms of this Agreement are to apply to all processing of Personal Data carried out for the Data Controller by the Data Processor and to all Personal Data held by the Data Processor in relation to all such processing.

IT IS AGREED as follows:

1. Definitions and Interpretation — standard defined terms (Commissioner, Controller, Data Protection Legislation, Data Subject, Personal Data, Personal Data Breach, Processor, processing, Services, UK GDPR) as per UK GDPR and Data Protection Act 2018, plus standard interpretation clauses (writing includes electronic communication, statute references include amendments, headings for convenience only, singular includes plural, gender includes all genders, persons includes corporations).

2. Scope and Application of this Agreement — applies to processing of Personal Data described in Schedule 2; supersedes prior arrangements; continues for as long as the Processor processes Personal Data for the Controller; is part of and incorporated into the Terms and Conditions on the SWIS website.

3. Provision of the Services and Processing Personal Data — Controller retains control and compliance responsibility; Processor processes Personal Data only for the purposes of the Services and strictly per the Controller’s written instructions.

4. Data Protection Compliance — Processor acts only on Controller’s written instructions; complies with Data Protection Legislation; implements appropriate technical/organisational security measures (encryption, pseudonymisation, access control, breach detection, secure backups, secure disposal); does not transfer Personal Data outside the UK or to third parties without written consent; keeps records and supports Controller audits and compliance.

5. Data Subject Requests, Notices, Complaints, and Personal Data Breaches — Processor notifies Controller immediately of any Data Subject request, complaint, or Personal Data Breach, and cooperates fully with the Controller’s response, investigation, and any regulatory notification (which is the Controller’s sole decision).

6. Staff — Processor ensures staff handling Personal Data are trained, bound by confidentiality, and aware of their obligations. Controller and Processor each have an appointed data protection officer per Article 37 UK GDPR.

7. Warranties — Processor warrants its staff are appropriately trained and it will process data compliantly and securely; Controller warrants its instructions comply with the Data Protection Legislation.

8. Liability and Indemnity — mutual indemnities: Controller indemnifies Processor for Controller’s non-compliance; Processor indemnifies Controller for Processor’s breach of this Agreement or the Controller’s instructions.

9. Intellectual Property Rights — IP in the Personal Data belongs to the Controller (or relevant third party); Processor is licensed to use it only to provide the Services.

10. Confidentiality — Processor keeps Personal Data confidential, does not disclose without consent, and this obligation continues for two years after the Services end.

11. Subcontractors — Processor may not subcontract without Controller’s prior written consent, and remains fully liable for any subcontractor’s compliance.

12. Deletion and/or Disposal of Personal Data — Processor deletes, disposes of, or returns Personal Data at the Controller’s written request once the Services end or the data is no longer needed, unless retention is required by law.

13. Consideration — the Processor accepts these obligations in consideration of £1 from the Controller.

14. Law and Jurisdiction — governed by, and subject to the courts of, England and Wales.

11. AUTORESPONDERS
We may use autoresponders to communicate with you by e-mail. To protect your privacy, we use a verified opt-in system for such communications and you can always opt-out of such communications using the links contained in each autoresponder message. If you have difficulties opting out, you may contact us by sending an e-mail to info@coursewedo.com, or sending us mail to the address listed below.

12. DO NOT TRACK
This website does not monitor for or behave differently if your computer transmits a do not track or similar beacon or message.

13. DISCLAIMER
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on our Websites, including the illegal acts of third parties (such as criminal hacking).

14. POLICY CHANGES
The terms of this policy may change from time to time. If we make material changes to how we treat our users’ personal information, we will notify you by e-mail to the e-mail address specified through your account. Your continued use of our websites constitutes your consent to such revised privacy policy.

If you are concerned about the topic covered by this policy, you should read it each time before you use our websites. Any questions or concerns about this policy should be brought to our attention by sending an e-mail to info@coursewedo.com, or one of the methods provided under Contact Information, and providing us with information relating to your concern.

15. CONTACT INFORMATION
To ask questions or comment about this privacy policy and our privacy practices, contact us at:

CourseWeDo.com
Highgate Cottage
Cheltenham Road
Broadway WR12 7BX
United Kingdom

info@coursewedo.com
Last updated on 16th July 2026

SCHEDULE 1 — Services
A six or twelve month subscription whenever paid by the Controller for the use of the website swis.reach2teach.net owned by the Processor.

SCHEDULE 2 — Personal Data

Type of Personal DataCategory of Data SubjectNature of ProcessingPurpose(s)Duration
Name, Date of Birth, Gender, case/social care ID. Optional data includes: family background, significant incidents and chronology, the child’s voice/wishes/feelings, professional observations, and social and emotional characteristics.Child or young person known to children’s social careScoring the answers to a needs analysis questionnaire before and after applying intervention strategies provided by the software to help the child.To help identify the child’s needs, inform evidence-based intervention planning, and support coordinated multi-agency working.Data is kept as long as the user or we have a good reason to justify retention

SCHEDULE 3 — Technical and Organisational Data Protection Measures
Standard security measures maintained by the Processor: a documented security policy with named responsibility, virus/security safeguards, prevention of unauthorised access, pseudonymisation and encryption where practical, secure storage and access controls, secure transfer methods, password-protected devices, vetting of personnel with data access, breach detection and reporting procedures, secure backups stored separately from originals, and secure disposal of unwanted Personal Data.