AssuredCPD
How it worksWhat we accreditPricingFor providersStandardsVerify a certificateAboutInsights
Sign inVerifyApply for accreditation

Legal

Privacy Policy

Version 1.0 · effective 18 June 2026

On this page

  1. Introduction & scope
  2. Who we are
  3. Definitions
  4. Personal data we collect
  5. How we collect it
  6. Purposes & lawful bases
  7. Special category data & children
  8. Our role: controller vs processor
  9. Cookies & analytics
  10. Marketing & your choices
  11. Who we share data with
  12. International transfers
  13. How we protect data
  14. How long we keep data
  15. Your rights
  16. Automated decisions
  17. Complaints & the ICO
  18. Changes & contact

1. Introduction and scope

AssuredCPD ("we", "us", "our") is committed to protecting your privacy and handling your personal data in an open, transparent manner. This Privacy Policy explains how we collect, use, store, share, and protect personal data, and the rights available to you, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR).

This policy applies to: visitors to our website; training providers and individuals who apply for or hold accreditation; people who contact us or sign up to our communications; and, in a limited capacity, learners whose certificate details are submitted to us for verification (see section 8). It does not apply to third-party websites we may link to, which have their own policies.

2. Who we are

For the purposes of UK data protection law, the data controller is Assured CPD Ltd, trading as AssuredCPD, a company registered in England and Wales under company number 17277869, with its registered office at 63 Kingsway, Manchester, England, M19 2LL.

  • Data protection contact: [email protected]
  • Postal: Data Protection, Assured CPD Ltd, 63 Kingsway, Manchester, England, M19 2LL
  • ICO registration: ZC176812 — registered with the Information Commissioner’s Office under the Data Protection Act 2018.

We are not currently required to appoint a statutory Data Protection Officer (DPO), but we have designated a person responsible for data protection who can be reached at the address above.

3. Definitions

  • Personal data — any information relating to an identified or identifiable living individual.
  • Processing — any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
  • Controller — the party that determines the purposes and means of processing.
  • Processor — a party that processes personal data on behalf of a controller.
  • Special category data — sensitive data such as health, racial/ethnic origin, religious beliefs, etc., subject to extra protection.

4. The personal data we collect

We collect and process the following categories of personal data.

CategoryExamplesSource
Identity & contactName, job title, organisation, work email, phone, postal addressYou, directly
Application & accountCourse details, learning outcomes, materials submitted, membership tier, account credentialsYou, directly
Billing & transactionBilling name/address, VAT number, payment references, invoices (card details are handled by our payment processor, not stored by us)You / payment processor
Certificate & verificationLearner name, course title, CPD hours, issue date, unique certificate codeProviders, on behalf of their learners
CorrespondenceEmails, support messages, complaint records, feedbackYou, directly
Technical & usageIP address, device/browser type, pages viewed, referring URLs, cookie identifiersAutomatically, via our website
Marketing preferencesConsent status, subscription choices, engagement with our emailsYou / automatically

5. How we collect personal data

  • Directly from you — when you complete an application or contact form, correspond with us, purchase a membership, or subscribe to communications.
  • Automatically — when you use our website, through cookies and similar technologies (see our Cookie Notice).
  • From third parties — from our payment processor (transaction confirmations), analytics providers, and from providers who submit learner certificate data for verification.

6. Purposes and lawful bases for processing

We only process personal data where we have a lawful basis under Article 6 UK GDPR. The table below sets out our main processing activities, purposes, and lawful bases.

PurposeData usedLawful basis
Assessing applications and providing accreditation servicesIdentity, application, accountPerformance of a contract
Operating the public certificate verification serviceCertificate & verification dataLegitimate interests (maintaining a trustworthy verification service); provider's own basis as controller of learner data
Taking payment, invoicing, accounting and taxBilling & transactionPerformance of a contract; legal obligation
Responding to enquiries, support and complaintsContact, correspondenceLegitimate interests (responding to you); contract where applicable
Sending service/administrative messagesIdentity, contactPerformance of a contract; legitimate interests
Sending marketing communicationsContact, marketing preferencesConsent (or soft opt-in for existing customers, where lawful)
Website analytics and improvementTechnical & usageConsent (for non-essential cookies)
Protecting our rights, security, fraud preventionMost categoriesLegitimate interests; legal obligation

Where we rely on legitimate interests, we have carried out a balancing assessment to ensure your rights and freedoms are not overridden. You may ask us for details of that assessment.

7. Special category data and children

We do not intentionally collect special category data and ask that you do not submit it to us unless strictly necessary. If special category data is unavoidably included in materials you submit, we process it only so far as needed to deliver the service and on an appropriate Article 9 condition.

Our services are intended for businesses and professionals. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.

8. Our role — controller and processor

For applicants, members, website visitors, and people who contact us, AssuredCPD is the controller.

Where a provider submits learner certificate data to us so that certificates can be issued and verified, the provider is the controller of that learner data and is responsible for having a lawful basis and for informing their learners. AssuredCPD acts as a processor on the provider's behalf for that limited purpose, under the data-processing terms in our Provider Accreditation Agreement, and only processes the data on the provider's documented instructions.

9. Cookies and analytics

We use cookies and similar technologies. Strictly necessary cookies are always active; analytics and other non-essential cookies are used only with your consent. Full details, including how to manage your preferences, are in our Cookie Notice.

10. Marketing and your choices

We will only send you marketing where you have consented, or where you are an existing customer and we are contacting you about similar services in a way permitted by PECR (the "soft opt-in"). Every marketing email contains an unsubscribe link, and you can opt out at any time by contacting [email protected]. Opting out of marketing does not stop essential service messages (for example, about your accreditation or billing).

11. Who we share your data with

We do not sell personal data. We share it only with:

  • Service providers (processors) acting on our instructions — for example, cloud hosting, email delivery, payment processing, analytics, and customer-support tools. Each is bound by a written contract requiring appropriate security and processing only on our instructions.
  • Professional advisers — accountants, auditors, insurers, and lawyers, where necessary.
  • Authorities and regulators — where required by law, court order, or to establish, exercise, or defend legal claims.
  • Successors — in connection with a merger, acquisition, or reorganisation, subject to appropriate safeguards.

A current list of our main sub-processors is available on request, and we will notify you of material changes.

Lectern (our sister learning platform) is a separate company; we share personal data with it only where you have a bundle or have otherwise asked us to, and on an appropriate lawful basis.

12. International transfers

We aim to keep personal data within the UK or the European Economic Area. Where a processor is located outside the UK, we ensure an appropriate safeguard is in place — typically a UK adequacy decision, or the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any necessary transfer risk assessment. You can request details of the safeguards used.

13. How we protect your data

We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including: encryption in transit (TLS); access controls and the principle of least privilege; secure, reputable hosting; regular software updates; staff confidentiality obligations; and a process for detecting, reporting, and investigating personal data breaches. Where a breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours where required, and affected individuals where the risk is high. Where required under Article 35 UK GDPR, we carry out a Data Protection Impact Assessment (DPIA), including in respect of our certificate verification service.

14. How long we keep your data

DataRetention period
Application & accreditation recordsDuration of accreditation plus 6 years
Billing, invoices & accounting records6 years (legal/tax requirement)
Certificate verification recordsFor as long as certificates need to remain verifiable, or such longer period as is necessary to maintain the integrity of the verification service
Correspondence & complaint records3 years from closure
Marketing dataUntil consent is withdrawn or after 24 months of inactivity
Website analyticsPer cookie durations in the Cookie Notice

When data is no longer needed, we securely delete or anonymise it.

15. Your rights

Subject to conditions in the law, you have the right to:

  • Be informed — about how we use your data (this policy).
  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted in certain circumstances ("right to be forgotten").
  • Restriction — limit how we use your data in certain circumstances.
  • Data portability — receive certain data in a structured, machine-readable format.
  • Object — to processing based on legitimate interests, and to direct marketing at any time.
  • Rights relating to automated decision-making — see section 16.
  • Withdraw consent — at any time, where we rely on consent.

To exercise any right, contact [email protected]. We will respond within one month (extendable by up to two further months for complex or numerous requests, of which we will notify you). There is normally no charge, though we may charge a reasonable fee or refuse manifestly unfounded or excessive requests. We may ask you to verify your identity.

16. Automated decision-making and profiling

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Accreditation decisions are made by a named human assessor against our published Standards Framework.

17. Complaints and the ICO

If you have a concern about how we handle your personal data, please contact us first at [email protected] so we can try to resolve it. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or on 0303 123 1113.

18. Changes to this policy and contact

This policy is Version 1.0; previous versions are available on request. We may update this policy from time to time. The current version, with its effective date, is always published on this page, and we will notify active members of material changes. Questions about this policy or your data should be sent to [email protected].

AssuredCPD

The independent CPD accreditation body. Quietly authoritative, openly priced.

Accreditation

How it worksWhat we accreditStandards FrameworkPricingApply

Trust

Verify a certificateFor providersAbout & independenceContactInsights

Legal

Terms & conditionsPrivacy policyComplaints procedureReferral disclosureCookie notice

AssuredCPD is an independent CPD accreditation body. We are not a government or regulatory body and do not award regulated qualifications.

Assured CPD Ltd is registered in England & Wales, company number 17277869. Registered office: 63 Kingsway, Manchester, England, M19 2LL. © 2026 Assured CPD Ltd. All rights reserved.