Privacy and Data Protection

Privacy Policy

Clear information about how we collect, use, store, share and protect personal information when you use our website and learner platform.

Transparent data use Secure information handling Clear privacy rights
Overview

Protecting your personal information

This Privacy Policy explains how CPD212 Ltd collects, uses, stores and shares personal information when you visit the website, create an account, purchase courses, complete learning or contact our support team.

We aim to process personal information lawfully, fairly, transparently and securely. We also seek to collect only the information reasonably required to provide and manage our services.

This policy applies to learners, prospective customers, website visitors, business contacts and people who submit an enquiry through the platform.

Information Collected

Categories of personal information

1

Identity and Contact Details

Your name, email address, telephone number, correspondence address and organisation details where these are supplied.

2

Account Information

Login credentials in protected form, account status, email-verification status, preferences and account administration records.

3

Learning Records

Course enrolments, lesson progress, completion dates, assessment attempts, scores, CPD hours and learning transcripts.

4

Certificate Records

Learner name, course title, certificate number, verification code, issue date, result and certificate validity status.

5

Orders and Transactions

Products purchased, order values, discounts, payment status, invoice information and payment-provider transaction references.

6

Communications

Contact-form submissions, emails, support requests, complaints, feedback and records of our responses.

7

Technical Information

IP address, browser type, device information, session details, security logs and information produced through cookies or similar technologies.

8

Fraud and Security Information

Records used to investigate suspicious activity, repeated failed access attempts, misuse, payment fraud or threats to the platform.

Sources

How we obtain personal information

Most personal information is collected directly from you when you register, purchase a course, complete learning, submit an assessment, request support or otherwise interact with the platform.

We may also receive limited information from payment processors, employers or organisations purchasing training, technical service providers, fraud-prevention services or other parties authorised to provide information to us.

Purposes and Legal Grounds

Why we use personal information

Purpose Information involved Typical lawful basis
Creating and managing learner accounts Identity, contact and account information Performance of a contract
Processing orders and providing purchased courses Account, order, payment-status and course information Performance of a contract
Recording progress, assessments and completed learning Learning activity, attempts, scores and completion records Performance of a contract and legitimate interests
Issuing and verifying certificates Identity, course, result and certificate information Performance of a contract and legitimate interests
Responding to support requests and enquiries Contact details, account references and correspondence Contractual steps and legitimate interests
Maintaining financial, tax and accounting records Orders, invoices and transaction information Legal obligation
Protecting accounts and preventing fraud or misuse Technical logs, transaction references and security records Legitimate interests and legal obligations
Sending optional promotional communications Name, contact details and communication preferences Consent or legitimate interests, where legally permitted
Payment Processing

Payment and card information

Payments are processed by an external payment provider

Card payments are completed through Stripe or another authorised payment service used by the platform. We do not normally receive or store your complete payment-card number or card security code. We may retain transaction references, payment status, amount, currency and related order information needed to administer the purchase, respond to disputes and maintain financial records.

Recipients

When information may be shared

We may share limited personal information with organisations that help us operate the platform or fulfil legal and contractual responsibilities.

Hosting and Infrastructure
Website hosting, database storage, backups, security, availability and technical maintenance.
Payment Providers
Secure payment processing, transaction confirmation, fraud checks, refunds and payment disputes.
Email Services
Account verification, password resets, order notifications, support correspondence and platform messages.
Professional Advisers
Legal, accounting, insurance, auditing and compliance support where reasonably necessary.
Public Authorities
Information may be disclosed where required by law, a court order, regulatory requirement or lawful request.
Business Purchasers
If the business is reorganised, sold or transferred, relevant information may be disclosed subject to appropriate confidentiality and legal safeguards.

We do not sell personal information as a commercial database.

International Processing

Transfers outside the United Kingdom

Some suppliers may process information internationally

Where a service provider processes personal information outside the United Kingdom, we will seek to use an appropriate transfer mechanism or other safeguard required by applicable data-protection law. The precise arrangements depend on the supplier, destination and services in use. You may contact us for further information about relevant safeguards.

Retention

How long information is kept

Personal information is retained only for as long as reasonably necessary for the purpose for which it was collected, including contractual, certification, accounting, legal, security and dispute-resolution requirements.

Account Records
Retained while the account is active and afterwards where required to maintain learning, contractual, security or legal records.
Learning and Certificates
May be retained for an extended period so that completed learning and certificate authenticity can continue to be evidenced and verified.
Orders and Invoices
Retained for the period required by applicable tax, accounting and financial-record obligations.
Support Correspondence
Retained for a reasonable period according to the enquiry, complaint, transaction or potential dispute.
Technical and Security Logs
Retained for a limited period appropriate to platform security, troubleshooting and fraud prevention.
Information Security

How information is protected

✓

Access Controls

Administrative access is restricted according to role, operational requirement and account permissions.

✓

Secure Authentication

Passwords are stored using secure hashing rather than being retained as readable plain text.

✓

Encrypted Connections

The public platform uses encrypted HTTPS connections when information is transmitted through the website.

✓

Monitoring and Backups

Appropriate logging, maintenance and backup procedures may be used to support availability and incident response.

No online service can guarantee absolute security. Users should protect their account password, avoid sharing login credentials and contact us promptly if they suspect unauthorised access.

Automated Processing

Assessments and automated decisions

Assessment scores may be calculated automatically

Online multiple-choice assessments may be marked automatically by comparing submitted answers against the configured correct answers. The resulting score may determine whether the course pass mark has been met and whether completion and certificate records are created. Contact support where you believe an assessment result or record is incorrect.

Children

Use of the platform by children

The platform is intended primarily for adult learners

Our courses and purchasing services are not intentionally directed at young children. Where an organisation intends to enrol a learner under 18, it should contact us before providing personal information so that suitability, authority and any additional safeguarding or consent requirements can be considered.

Your Rights

Data-protection rights

1

Right to Be Informed

You may receive clear information about how and why your personal information is used.

2

Right of Access

You may request a copy of personal information held about you, subject to applicable exemptions.

3

Right to Rectification

You may ask us to correct inaccurate information or complete information that is incomplete.

4

Right to Erasure

You may request deletion in certain circumstances. The right is not absolute and may not apply to records we must retain.

5

Right to Restriction

You may ask us to restrict particular processing in circumstances provided by data-protection law.

6

Right to Data Portability

You may request eligible information in a structured, commonly used and machine-readable format.

7

Right to Object

You may object to processing based on legitimate interests and to direct marketing.

8

Consent Withdrawal

Where processing is based on consent, you may withdraw that consent without affecting prior lawful processing.

Identity checks: we may request reasonable information to verify your identity before responding to a rights request. The rights available depend on the circumstances and lawful basis involved.
Contact and Complaints

Privacy enquiries and concerns

Contact us about your personal information

Send privacy questions, rights requests or concerns to support@cpd212.co.uk. Include enough information for us to identify the relevant account or transaction, but do not send passwords or complete card details.

You also have the right to raise a concern with the UK Information Commissioner’s Office. We would appreciate the opportunity to review and respond to your concern first.

Policy Changes

Updates to this Privacy Policy

We may update this policy when our services, suppliers, processing activities or legal obligations change. The latest version will be published on this page with an updated review date.

Last reviewed: 03 October 2026. This policy should be checked against the organisation’s actual data flows, retention schedule, supplier contracts and lawful-basis assessment before publication.