Legal
Privacy Policy
Version 1.0 · effective 18 June 2026
On this page
- Introduction & scope
- Who we are
- Definitions
- Personal data we collect
- How we collect it
- Purposes & lawful bases
- Special category data & children
- Our role: controller vs processor
- Cookies & analytics
- Marketing & your choices
- Who we share data with
- International transfers
- How we protect data
- How long we keep data
- Your rights
- Automated decisions
- Complaints & the ICO
- Changes & contact
1. Introduction and scope
AssuredCPD ("we", "us", "our") is committed to protecting your privacy and handling your personal data in an open, transparent manner. This Privacy Policy explains how we collect, use, store, share, and protect personal data, and the rights available to you, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR).
This policy applies to: visitors to our website; training providers and individuals who apply for or hold accreditation; people who contact us or sign up to our communications; and, in a limited capacity, learners whose certificate details are submitted to us for verification (see section 8). It does not apply to third-party websites we may link to, which have their own policies.
2. Who we are
For the purposes of UK data protection law, the data controller is Assured CPD Ltd, trading as AssuredCPD, a company registered in England and Wales under company number 17277869, with its registered office at 63 Kingsway, Manchester, England, M19 2LL.
- Data protection contact: [email protected]
- Postal: Data Protection, Assured CPD Ltd, 63 Kingsway, Manchester, England, M19 2LL
- ICO registration: ZC176812 — registered with the Information Commissioner’s Office under the Data Protection Act 2018.
We are not currently required to appoint a statutory Data Protection Officer (DPO), but we have designated a person responsible for data protection who can be reached at the address above.
3. Definitions
- Personal data — any information relating to an identified or identifiable living individual.
- Processing — any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
- Controller — the party that determines the purposes and means of processing.
- Processor — a party that processes personal data on behalf of a controller.
- Special category data — sensitive data such as health, racial/ethnic origin, religious beliefs, etc., subject to extra protection.
4. The personal data we collect
We collect and process the following categories of personal data.
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, job title, organisation, work email, phone, postal address | You, directly |
| Application & account | Course details, learning outcomes, materials submitted, membership tier, account credentials | You, directly |
| Billing & transaction | Billing name/address, VAT number, payment references, invoices (card details are handled by our payment processor, not stored by us) | You / payment processor |
| Certificate & verification | Learner name, course title, CPD hours, issue date, unique certificate code | Providers, on behalf of their learners |
| Correspondence | Emails, support messages, complaint records, feedback | You, directly |
| Technical & usage | IP address, device/browser type, pages viewed, referring URLs, cookie identifiers | Automatically, via our website |
| Marketing preferences | Consent status, subscription choices, engagement with our emails | You / automatically |
5. How we collect personal data
- Directly from you — when you complete an application or contact form, correspond with us, purchase a membership, or subscribe to communications.
- Automatically — when you use our website, through cookies and similar technologies (see our Cookie Notice).
- From third parties — from our payment processor (transaction confirmations), analytics providers, and from providers who submit learner certificate data for verification.
6. Purposes and lawful bases for processing
We only process personal data where we have a lawful basis under Article 6 UK GDPR. The table below sets out our main processing activities, purposes, and lawful bases.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Assessing applications and providing accreditation services | Identity, application, account | Performance of a contract |
| Operating the public certificate verification service | Certificate & verification data | Legitimate interests (maintaining a trustworthy verification service); provider's own basis as controller of learner data |
| Taking payment, invoicing, accounting and tax | Billing & transaction | Performance of a contract; legal obligation |
| Responding to enquiries, support and complaints | Contact, correspondence | Legitimate interests (responding to you); contract where applicable |
| Sending service/administrative messages | Identity, contact | Performance of a contract; legitimate interests |
| Sending marketing communications | Contact, marketing preferences | Consent (or soft opt-in for existing customers, where lawful) |
| Website analytics and improvement | Technical & usage | Consent (for non-essential cookies) |
| Protecting our rights, security, fraud prevention | Most categories | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure your rights and freedoms are not overridden. You may ask us for details of that assessment.
7. Special category data and children
We do not intentionally collect special category data and ask that you do not submit it to us unless strictly necessary. If special category data is unavoidably included in materials you submit, we process it only so far as needed to deliver the service and on an appropriate Article 9 condition.
Our services are intended for businesses and professionals. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.
8. Our role — controller and processor
For applicants, members, website visitors, and people who contact us, AssuredCPD is the controller.
Where a provider submits learner certificate data to us so that certificates can be issued and verified, the provider is the controller of that learner data and is responsible for having a lawful basis and for informing their learners. AssuredCPD acts as a processor on the provider's behalf for that limited purpose, under the data-processing terms in our Provider Accreditation Agreement, and only processes the data on the provider's documented instructions.
9. Cookies and analytics
We use cookies and similar technologies. Strictly necessary cookies are always active; analytics and other non-essential cookies are used only with your consent. Full details, including how to manage your preferences, are in our Cookie Notice.
10. Marketing and your choices
We will only send you marketing where you have consented, or where you are an existing customer and we are contacting you about similar services in a way permitted by PECR (the "soft opt-in"). Every marketing email contains an unsubscribe link, and you can opt out at any time by contacting [email protected]. Opting out of marketing does not stop essential service messages (for example, about your accreditation or billing).
11. Who we share your data with
We do not sell personal data. We share it only with:
- Service providers (processors) acting on our instructions — for example, cloud hosting, email delivery, payment processing, analytics, and customer-support tools. Each is bound by a written contract requiring appropriate security and processing only on our instructions.
- Professional advisers — accountants, auditors, insurers, and lawyers, where necessary.
- Authorities and regulators — where required by law, court order, or to establish, exercise, or defend legal claims.
- Successors — in connection with a merger, acquisition, or reorganisation, subject to appropriate safeguards.
A current list of our main sub-processors is available on request, and we will notify you of material changes.
Lectern (our sister learning platform) is a separate company; we share personal data with it only where you have a bundle or have otherwise asked us to, and on an appropriate lawful basis.
12. International transfers
We aim to keep personal data within the UK or the European Economic Area. Where a processor is located outside the UK, we ensure an appropriate safeguard is in place — typically a UK adequacy decision, or the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any necessary transfer risk assessment. You can request details of the safeguards used.
13. How we protect your data
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including: encryption in transit (TLS); access controls and the principle of least privilege; secure, reputable hosting; regular software updates; staff confidentiality obligations; and a process for detecting, reporting, and investigating personal data breaches. Where a breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours where required, and affected individuals where the risk is high. Where required under Article 35 UK GDPR, we carry out a Data Protection Impact Assessment (DPIA), including in respect of our certificate verification service.
14. How long we keep your data
| Data | Retention period |
|---|---|
| Application & accreditation records | Duration of accreditation plus 6 years |
| Billing, invoices & accounting records | 6 years (legal/tax requirement) |
| Certificate verification records | For as long as certificates need to remain verifiable, or such longer period as is necessary to maintain the integrity of the verification service |
| Correspondence & complaint records | 3 years from closure |
| Marketing data | Until consent is withdrawn or after 24 months of inactivity |
| Website analytics | Per cookie durations in the Cookie Notice |
When data is no longer needed, we securely delete or anonymise it.
15. Your rights
Subject to conditions in the law, you have the right to:
- Be informed — about how we use your data (this policy).
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted in certain circumstances ("right to be forgotten").
- Restriction — limit how we use your data in certain circumstances.
- Data portability — receive certain data in a structured, machine-readable format.
- Object — to processing based on legitimate interests, and to direct marketing at any time.
- Rights relating to automated decision-making — see section 16.
- Withdraw consent — at any time, where we rely on consent.
To exercise any right, contact [email protected]. We will respond within one month (extendable by up to two further months for complex or numerous requests, of which we will notify you). There is normally no charge, though we may charge a reasonable fee or refuse manifestly unfounded or excessive requests. We may ask you to verify your identity.
16. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Accreditation decisions are made by a named human assessor against our published Standards Framework.
17. Complaints and the ICO
If you have a concern about how we handle your personal data, please contact us first at [email protected] so we can try to resolve it. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or on 0303 123 1113.
18. Changes to this policy and contact
This policy is Version 1.0; previous versions are available on request. We may update this policy from time to time. The current version, with its effective date, is always published on this page, and we will notify active members of material changes. Questions about this policy or your data should be sent to [email protected].