Privacy Statement

Researchers in Schools is run by The Brilliant Club

About Us

The Brilliant Club is a charity registered with the Charities Commission in England and Wales under registration number 1147771, at 1st Floor, Kensington Centre, 66 Hammersmith Road, London, W14 8UD.

The Brilliant Club must process personal data (including special categories of data / sensitive personal data) so that it can provide its services and deliver its programmes of work – in doing so, the charity acts as a data controller.

You may give your personal details to The Brilliant Club directly, such as on an application or registration form or via our website, or we may collect them from another source such as directly from a school or another partner organisation.

The Brilliant Club must have a legal basis for processing your personal data.  For the purposes of administering all aspects of The Brilliant Club’s work, and for monitoring, evaluating, and researching the effectiveness of its programmes, the charity will only use your personal data in accordance with this privacy statement. At all times we will comply with current data protection laws.


The EU General Data Protection Regulation (GDPR) is the most significant piece of European privacy legislation in recent history, replacing that of the 1995 EU Data Protection Directive (European Directive 95/46/EC). It aims to support the rights individuals have on data about themselves which is collected and stored. It also aims to detect, identify and mitigate against data breaches or leaks for all companies in the EU, as well as enforcing the reporting on these issues. Any business that deals with EU nationals must comply with the legislation.

In line with the changes to European Union data protection law, The Brilliant Club updated its privacy policy. These changes include explaining to you in more detail how we use your information, including your choices, rights, and controls.

The Brilliant Club also uses Third Party suppliers and software to process, control and manage data. These systems have been audited in line with GDPR commitments. In the context of this statement, ‘data subject’ refers to the person or entity submitting data and can include employees, pupils, tutors, programme participants, and other individuals or organisations that The Brilliant Club works with.

Data Collection and Processing

The Brilliant Club collects information in the following ways:

  • Information you give us. For example, when you apply to work on or participate in one of our programmes, express an interest in taking up one of our programmes or services, register for an event, engage with us via social media or message boards, or otherwise provide us with your personal information.
  • Information we get from your use of our website and services, including portals. We collect information about the services you use and how you use them – please refer to our Cookies Policy.
  • Information from third parties. Like all organisations we are able to see what browser you are using, your IP address and what computer operating systems you are using. We may use this information to improve the services we offer.
  • Data protection law recognises that certain categories of personal information are more sensitive than others. This is known as ‘sensitive personal data’ or ‘special categories of data’ and includes health information, race, religious beliefs and political opinions (please note that this is a non-exhaustive list). We only collect sensitive personal data about people engaged with us where there is a clear reason for doing so. For example, when a tutor applies to work for The Scholars Programme, we need to understand what, if any, reasonable adjustments need to be made to our assessment processes. We may also collect this information for monitoring purposes.

We may also collect sensitive personal data if you make the information public or if you tell us about your experiences on one of our programmes. In any such instances, we will always make it clear to you when we collect this information what sensitive personal data we are collecting and why, and where applicable, seek your consent for us to do this.

We must have a legal basis to process your personal data. The legal bases we rely upon to offer our programmes and services to you are:

  • Your consent, where required;
  • Where we have a legitimate interest;
  • To comply with a legal obligation that we have;
  • To fulfil a contractual obligation that we have with you or a partner organisation.

Legitimate Interest

This is where The Brilliant Club has a legitimate reason to process your data provided it is reasonable and does not go against what you would reasonably expect from us. Where the charity has relied on a legitimate interest to process your personal data our legitimate interests is/are as follows:

  • Registering and maintaining records of pupils / tutors / programme participants / and other individuals or organisations that The Brilliant Club works with to administer all aspects of the charity’s work;
  • For monitoring, evaluating, and researching the effectiveness of its programmes;
  • Contacting you to seek your consent where we need it;
  • Giving you information about similar products or services that you have used from us recently.

Statutory / Contractual Requirement

The Brilliant Club has certain legal and contractual requirements to collect personal data (e.g. to comply with immigration and tax legislation, and in many circumstances safeguarding requirements.) Our partner organisations may also require this personal data, and/or we may need your data to enter into a contract with you. If you do not give us the personal data we need to collect, we may not be able to continue to provide our services to you or be able to effectively administer our core programmes of work.

Overseas Transfers

The Brilliant Club may transfer the information you provide to us to countries outside the European Economic Area (‘EEA’) for the purposes of administering, monitoring, evaluating, and researching the effectiveness of its programmes. We will take steps to ensure adequate protections are in place to ensure the security of your information and where applicable, seek your express consent to do so. The EEA comprises the EU member states plus Norway, Iceland and Liechtenstein.

Data Retention

The Brilliant Club will retain your personal data only for as long as is necessary for the purpose we collect it and never longer than seven years. Different laws may also require us to keep different data for different periods of time. For example, we must keep payroll records, holiday pay, sick pay and pensions auto-enrolment records for as long as is legally required by HMRC and associated national minimum wage, social security and tax legislation.

Where The Brilliant Club has obtained your consent to process your personal/sensitive personal data, we will do so in line with our retention policy. Upon expiry of that period the charity will seek further consent from you. Where consent is not granted The Brilliant Club will cease to process your personal data/sensitive personal data and or anonymise it in full.

Your Rights / Rights of the Data Subject

You as the data subject have the following data protection rights:

  • The right to be informed about the personal data The Brilliant Club processes on you;
  • The right of access to the personal data the charity processes on you;
  • The right to rectification of your personal data;
  • The right to erasure of your personal data in certain circumstances;
  • The right to restrict processing of your personal data;
  • The right to data portability in certain circumstances;
  • The right to object to the processing of your personal data that was based on a public or legitimate interest;
  • The right not to be subjected to automated decision making and profiling; and
  • The right to withdraw consent at any time.

Where you have consented to The Brilliant Club processing your personal / special categories of data you have the right to withdraw that consent at any time by contacting the charity’s Data Protection Officer, Ciara Lynch via email to Please note that if you withdraw your consent to further processing that does not affect any processing done prior to the withdrawal of that consent, or which is done according to another legal basis.

There may be circumstances where The Brilliant Club will still need to process your data for legal or official reasons. Where this is the case, we will tell you and we will restrict the data to only what is necessary for those specific reasons.

If you believe that any of your data that the charity processes is incorrect or incomplete, please contact us using the details above and we will take reasonable steps to check its accuracy and correct it where necessary. You can also contact us using the above details if you want us to restrict the type or amount of data we process for you, access your personal data or exercise any of the other rights listed above.

Complaints or Queries

If you wish to complain about this privacy notice or any of the procedures set out within it please contact the charity’s Data Protection Officer, Ciara Lynch at

You also have the right to raise concerns with the Information Commissioner’s Office on 0303 123 1113 or at, or any other relevant supervisory authority should your personal data be processed outside of the UK, if you believe that your data protection rights have not been adhered to.

Data Security

The charity takes the security of your data seriously and takes every precaution to protect our users’ information. The Brilliant Club has internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by its employees in the performance of their duties. Measures applied include:

  • Access control throughout its buildings;
  • CCTV Cameras;
  • Intrusion alarms;
  • Regularly tested fire detection;
  • All staff are DBS checked;
  • Comprehensive network security;
  • Remote wipe and location tracking on devices;
  • System administrative restrictions and controls;
  • Full disk encryption in place; and
  • Regularly reviewed disaster recovery plan.

Where the charity engages third parties to process personal data on its behalf, they do so on the basis of written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data as outlined within the GDPR.

Reporting Data Breaches

It is The Brilliant Club’s policy to be fair and proportionate when considering the actions to be taken to inform affected parties regarding breaches of personal data. In line with the GDPR, where a breach is known to have occurred which is likely to result in a risk to the rights and freedoms of individuals, the relevant supervisory authority will be informed within 72 hours.

Changes to this Privacy Statement

We will update this privacy statement from time to time. We will post any changes on the statement with revision dates. If we make any material changes, we will notify you.

Cookies Policy

We use a system of classifying the different types of cookies which we use on the Website, or which may be used by third parties through our websites. The classification was developed by the International Chamber of Commerce UK and explains more about which cookies we use, why we use them, and the functionality you will lose if you decide you don’t want to have them on your device.

What is a cookie?

Cookies are text files containing small amounts of information which are downloaded to your personal computer, mobile or other device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognises that cookie. Cookies are useful because they allow a website to recognise a user’s device.

How long are cookies stored for?

Persistent cookies – these cookies remain on a user’s device for the period of time specified in the cookie. They are activated each time that the user visits the website that created that particular cookie.

Session cookies – these cookies allow website operators to link the actions of a user during a browser session. A browser session starts when a user opens the browser window and finishes when they close the browser window. Session cookies are created temporarily. Once you close the browser, all session cookies are deleted.

Cookies do lots of different jobs, like letting you navigate between pages efficiently, remembering your preferences, and generally improve the user experience.

You can find more information about cookies at and

Cookies used on the Website

A list of all the cookies used on the Website by category is set out below.

Strictly necessary cookies:

These cookies enable services you have specifically asked for.  These cookies are essential in order to enable you to move around the Website and use its features, such as accessing secure areas of the Website.

Performance cookies:

These cookies collect anonymous information on the pages visited.  By using the Website, you agree that we can place these types of cookies on your device.

These cookies collect information about how visitors use the Website, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies don’t collect information that identifies a visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve how the Website works.

Third party cookies:

These cookies allow third parties to track the success of their application or customise the application for you. Because of how cookies work we cannot access these cookies, nor can the third parties access the data in cookies used on our site.

For example, if you choose to ‘share’ content through Twitter or other social networks you might be sent cookies from these websites. We don’t control the setting of these cookies, so please check those websites for more information about their cookies and how to manage them.