Privacy Policy – Festival of Internships (UK)
Effective date: 26 September 2025
1) Who we are (Data Controller)
Festival of Internships (“we”, “us”, “our”) helps students and employers create successful internship matches using explainable, fairness-aware AI.
All legal representations and operations are made by Festival Internships Ltd (Company No. 14876699), domiciled at Lab 18, Bristol and Bath Science Park, Dirac Crescent, Emersons Green, Bristol, United Kingdom, BS16 7FR.
- Data Controller: Festival Internships Ltd (14876699)
- Contact (privacy): privacy@festivalofinternships.uk
- Postal address: Lab 18, Bristol and Bath Science Park, Dirac Crescent, Emersons Green, Bristol, BS16 7FR, United Kingdom
Data Protection Lead: Pete Allison, Paul Welham & Floren Cabrera (contact via the email above)
This policy is designed to meet the requirements of the UK GDPR and the Data Protection Act 2018 and the ICO’s expectations on transparency, lawful bases, and individual rights.
In some collaborations (e.g., a university-run programme), the university or employer may act as the Data Controller and Festival Internships Ltd acts as a Data Processor; we will tell you when this applies and process data only on that party’s written instructions.
2) Who this policy applies to
- Students/candidates who create profiles, apply to roles, or attend our events.
- Employer sponsors/partners and their staff who list opportunities or participate in our events.
- Website visitors and newsletter subscribers.
We do not knowingly collect data from children under 16. If you believe a child under 16 has provided personal data, contact us to request deletion.
3) The data we collect
A) Students / candidates
- Identity & contact: name, email, phone, university, programme, graduation year.
- Profile & history: CV/resumé, portfolio links (e.g., GitHub/Behance), projects, certifications, languages, availability, location preferences, visa/right-to-work status.
- Skills & interests: skills self-ratings, domain interests, role preferences, learning goals.
- Application data: interviews scheduled, feedback, offers/outcomes.
- Optional/special category data (only if you choose): accessibility needs, health accommodations, or ethnicity data for fairness monitoring. We will only process special category data with your explicit consent or where required by law.
B) Employers / sponsors
- Business contact: name, role, email, phone, organisation, location.
- Role & project information: skill requirements, tools/tech stacks, mentoring capacity, working model, compliance notes.
- Feedback & outcomes: interview notes, offer decisions, internship results.
C) Website & communications
- Usage data: IP address, browser type, device, pages viewed, timestamps (for security and analytics).
- Cookies/Identifiers: set and managed via our Cookie Banner (see Section 11).
- Marketing preferences: newsletter opt-in/opt-out and related metadata.
Sources: We collect data directly from you, from your university/career service where a partnership exists, from referees you nominate, from public profiles you link (e.g., GitHub), and from the tools we use to run events and forms.
4) Why we use your data (purposes & lawful bases)
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide and manage your account and participation | Profiles, applications, scheduling, event access | Contract (Art. 6(1)(b)) |
| Matchmaking recommendations with explainable factors | AI-assisted shortlists for roles/participants | Legitimate interests (Art. 6(1)(f)) – talent matching for participants, balanced against your rights |
| Service communications | Transactional emails, interview reminders, policy updates | Contract / Legitimate interests |
| Marketing communications | Newsletters, event/sponsor updates | Consent (Art. 6(1)(a)); you can withdraw anytime |
| Product improvement and fairness checks | Anonymised/aggregated analytics, bias monitoring | Legitimate interests |
| Security, fraud prevention, legal compliance | Access logs, incident handling, regulatory requests | Legal obligation (Art. 6(1)(c)) / Legitimate interests |
Special category data (e.g., health/accommodation or ethnicity for fairness analytics) is processed only with explicit consent (Art. 9(2)(a)) or another applicable condition (e.g., equality monitoring under Schedule 1 DPA 2018) and always minimised.
You may object to processing based on legitimate interests (see Section 9).
5) Automated decision-making & profiling
We use algorithms to assist with candidate–role matching and produce explainable recommendations. These do not have legal or similarly significant effects by themselves; human decision-makers (employers/advisors) review outcomes.
Your rights include:
- Request a human review of recommendations you believe are inaccurate or unfair.
- Ask for an explanation of key factors used in a recommendation.
- Object to profiling for direct marketing.
6) Sharing your data
We share data only where necessary:
- Employers/sponsors: Candidate profiles relevant to a role/event you apply for or explicitly express interest in.
- Service providers (processors): Trusted vendors for hosting, CRM/email, video/event platforms, forms, analytics, and security—bound by contracts meeting UK GDPR requirements.
- Universities/career services: Where we run joint programmes, in line with our roles as controller/processor.
- Professional advisers/insurers: Where needed for compliance or claims.
- Authorities: If required by law or to protect rights, safety, and security.
We do not sell your personal data.
7) International transfers
Some vendors may process data outside the UK. Where they do, we use lawful transfer mechanisms such as:
- UK IDTA or the UK Addendum to EU SCCs;
- Adequacy regulations (e.g., EEA) where applicable;
- Transfer risk assessments and additional safeguards (e.g., encryption, access controls).
A current list of sub-processors and transfer safeguards is available on request.
8) Security
We apply appropriate technical and organisational measures, including:
- Encryption in transit and at rest (where applicable).
- Role-based access control and least-privilege.
- MFA for administrative access.
- Secure development practices and vendor due diligence.
- Backups, logging, and incident response procedures.
If a personal data breach is likely to result in a risk to individuals, we will notify the ICO and affected individuals when legally required.
9) Your rights (UK GDPR)
You have the right to:
- Access your data and obtain a copy.
- Rectify inaccuracies.
- Erase data in certain circumstances.
- Restrict processing in certain circumstances.
- Data portability (where applicable).
- Object to processing based on legitimate interests and to direct marketing at any time.
- Withdraw consent at any time where processing relies on consent (this won’t affect prior lawful processing).
- Not be subject to decisions based solely on automated processing producing legal or similarly significant effects.
To exercise any right, contact privacy@festivalofinternships.uk