info@cpdcertificationcentre.co.uk

Important notice: This Privacy Policy has been drafted based on CPD Certification Centre’s known business model, services, and applicable UK data protection law. Before publishing on your website, it should be reviewed and approved by a qualified solicitor or data protection specialist to ensure it fully reflects your actual data processing activities and complies with all current legal requirements.

Privacy Policy | CPD Certification Centre

CPD Certification Centre Last updated: May 2026

1. Introduction

CPD Certification Centre, the CPD Certification Centre, is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website at cpdcertificationcentre.co.uk, register as an Approved Provider, submit an accreditation application, or otherwise interact with our services.

We are the data controller responsible for the personal data we collect from you. This means we determine the purposes and means by which your personal data is processed. We are committed to processing your personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this Privacy Policy carefully. By using our website or services, you confirm that you have read and understood this policy. If you do not agree with this policy, you should not use our website or services.

This policy should be read alongside our Terms and Conditions, which are available on our website.

2. Who We Are

CPD Certification Centre Lynn Road, Ely, Cambridgeshire, CB6 1RY, United Kingdom

Email: info@cpdcertificationcentre.co.uk Telephone: +44 7418 354137 Website: cpdcertificationcentre.co.uk

If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us using the details above.

3. Definitions and Interpretation

In this Privacy Policy, the following terms have the following meanings:

“Personal Data” means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

“Data Controller” means the person or organisation that determines the purposes and means of processing personal data. CPD Certification Centre is the Data Controller for personal data collected through our website and services.

“Data Processor” means a person or organisation that processes personal data on behalf of a Data Controller.

“Processing” means any operation performed on personal data, including collection, recording, storage, use, disclosure, or erasure.

“UK GDPR” means the UK General Data Protection Regulation, as retained in UK law following the United Kingdom’s departure from the European Union.

“Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, and any applicable subordinate legislation and regulations made under them, as amended from time to time.

“Cookie” means a small text file placed on your computer or device when you visit our website. Further details are set out in clause 11.

“Website” means the CPD Certification Centre website at cpdcertificationcentre.co.uk.

“Services” means all CPD accreditation services provided by CPD Certification Centre, as described in our Terms and Conditions.

“Provider Portal” means the online account management system through which Approved Providers submit accreditation applications and manage their accreditation.

4. What Data We Collect

We may collect, use, store, and transfer different categories of personal data about you, as follows:

Identity Data includes your first name, last name, job title, professional designation, and username or similar identifier associated with your Provider Portal account.

Contact Data includes your email address, telephone number, postal address, and business address.

Business Data includes your organisation name, company registration number (where applicable), website address, industry sector, and information about your professional learning activities submitted in connection with accreditation applications.

Financial Data includes payment card details, bank account information, and billing address. Please note that full payment card details are processed directly by our payment processor and are not stored by CPD Certification Centre on our own systems.

Transaction Data includes details of payments made to us, invoices issued, accreditation plans purchased, and the history of services provided to you.

Accreditation Submission Data includes all materials, content, documentation, and information submitted by you in connection with accreditation applications, including course materials, trainer credentials, qualification evidence, professional indemnity documentation, and any other materials forming part of a submission.

Technical Data includes your IP address, browser type and version, device type, operating system, time zone, and other technical identifiers collected automatically when you visit our website or use our Provider Portal.

Usage Data includes information about how you use our website and Provider Portal, including pages visited, time spent, links clicked, and features used.

Communications Data includes the content of any correspondence between you and CPD Certification Centre by email, telephone, or any other channel, including enquiries, support requests, complaints, and feedback.

Marketing and Preferences Data includes your preferences regarding receiving marketing communications from CPD Certification Centre, and your communication preferences more generally.

Learner Certificate Data includes name and email address data collected when learners or event participants claim a CPD Certification Centre certificate through a QR code or access link provided by an accredited provider. This data is collected and processed in accordance with clause 7.

We do not intentionally collect special category personal data (such as data relating to health, ethnicity, religious beliefs, sexual orientation, or political views) or data relating to criminal convictions. If you include any such data within materials you submit to us in connection with an accreditation application, it will be processed only to the extent necessary to carry out the assessment and will be treated with the highest level of care.

We do not knowingly collect personal data from children under the age of 18. If you believe we have inadvertently collected data from a child, please contact us immediately so that we can delete it.

5. How We Collect Your Data

We collect personal data from you in the following ways:

Directly from you when you register as an Approved Provider, complete any form on our website, submit an accreditation application through the Provider Portal, contact us by email or telephone, subscribe to our newsletter or marketing communications, request a quote, attend a CPD Certification Centre event, respond to a survey, or otherwise communicate with us.

Automatically through cookies and similar technologies when you visit our website or use the Provider Portal. See clause 11 for further details about our use of cookies.

From third parties in limited circumstances, for example, where a company registration search is conducted as part of verifying your organisation’s details, or where you have been referred to us by an accredited provider or partner organisation.

6. How We Use Your Data and Our Lawful Basis

We will only use your personal data where we have a lawful basis to do so. Under the UK GDPR, the lawful bases we rely on are as follows:

Performance of a contract: Where processing is necessary to perform our contractual obligations to you or to take steps at your request before entering into a contract.

Legitimate interests: Where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and interests.

Legal obligation: Where processing is necessary to comply with a legal or regulatory obligation to which we are subject.

Consent: Where you have given your freely given, specific, informed, and unambiguous consent to the processing of your personal data for a specific purpose. You have the right to withdraw consent at any time.

The table below sets out in more detail how and why we use your personal data, and the lawful basis for each type of processing:

Processing your registration and delivering our services Data used: Identity, Contact, Business, Financial, Transaction, Accreditation Submission Lawful basis: Performance of a contract with you; legitimate interests (business administration and service delivery) Retention: 6 years from the date our contract with you terminates or expires

Processing payments and managing financial transactions Data used: Identity, Contact, Financial, Transaction Lawful basis: Performance of a contract with you; legitimate interests (recovering fees owed to us) Retention: 6 years from the date of the relevant transaction, in accordance with statutory accounting and tax requirements

Assessing and processing accreditation applications Data used: Identity, Contact, Business, Accreditation Submission Lawful basis: Performance of a contract with you Retention: 6 years from the date our contract with you terminates or expires

Managing your Provider Portal account Data used: Identity, Contact, Technical, Usage Lawful basis: Performance of a contract with you; legitimate interests (account administration and security) Retention: For the duration of your account and 6 years thereafter

Maintaining the CPD Certification Centre Directory Data used: Identity, Contact, Business Lawful basis: Performance of a contract with you; legitimate interests (maintaining a publicly accessible record of accredited providers) Retention: For the duration of your accreditation and a reasonable period thereafter

Issuing learner and participant certificates Data used: Identity, Contact (of the learner or participant) Lawful basis: Legitimate interests (providing a record of professional development to learners); consent (where collected via QR code or access link) Retention: 3 years from the date the certificate is issued

Communicating with you about your account, accreditation, and our services Data used: Identity, Contact, Communications Lawful basis: Performance of a contract with you; legitimate interests (customer communication and account management) Retention: 6 years from the date our contract with you terminates or expires

Sending marketing communications Data used: Identity, Contact, Marketing and Preferences Lawful basis: Consent (where required); legitimate interests (marketing our services to existing clients and enquirers) Retention: 2 years from the date we received your personal data, or until you opt out

Operating, maintaining, and improving our website and Provider Portal Data used: Technical, Usage Lawful basis: Legitimate interests (maintaining and improving our digital services; network security and fraud prevention) Retention: 2 years from the date of collection

Complying with legal and regulatory obligations Data used: Identity, Contact, Financial, Transaction Lawful basis: Legal obligation Retention: As required by the applicable legal or regulatory obligation

Responding to enquiries, complaints, and disputes Data used: Identity, Contact, Communications Lawful basis: Legitimate interests (responding to enquiries and resolving disputes); legal obligation (where applicable) Retention: 6 years from the date the matter is resolved

7. Learner and Participant Data

Where learners, delegates, or participants claim a CPD Certification Centre certificate by scanning a QR code or using an access link provided by a CPD Certification Centre Accredited Provider, CPD Certification Centre may collect their name and email address for the purpose of generating and issuing the certificate.

This data is collected with the individual’s consent, given at the point they opt in to claim their certificate. Individuals must read and agree to this Privacy Policy before their certificate is issued.

Learner and participant data collected through QR codes or access links may be shared with the Approved Provider who delivered the relevant accredited activity, for the purposes described in clause 8 below. If you do not wish your data to be shared with the provider, you may contact us to request that this sharing be restricted.

CPD Certification Centre does not sell learner or participant data to any third party.

8. How We Share Your Data

We take your privacy seriously and do not sell your personal data to any third party. We will only share your personal data in the following circumstances:

With our service providers and data processors who provide services to us in connection with the operation of our business and the delivery of our services. These include but may not be limited to:

Cloud hosting and infrastructure providers who store and process data on our behalf in accordance with our instructions and applicable data protection law.

Email service providers used to send transactional communications, including account notifications, accreditation updates, and renewal reminders.

Payment processing providers who handle payment transactions on our behalf. Payment data is processed directly by our payment processor and is not stored in full on CPD Certification Centre’s own systems.

Customer relationship management and support software providers used to manage communications with providers and applicants.

Website analytics providers, including Google Analytics, used to understand how visitors use our website. Analytics data is collected in aggregated or anonymised form where possible.

All service providers we engage are required to process personal data only in accordance with our instructions and applicable data protection law, and to implement appropriate technical and organisational security measures.

With Approved Providers where learner or participant data is collected in connection with a certificate claim for an activity delivered by that provider, as described in clause 7. Providers receive this data for the purpose of managing their relationship with their learners and for their own marketing purposes, subject to compliance with applicable data protection law. Providers are independent data controllers in respect of any personal data they receive and are responsible for their own compliance.

With professional or regulatory bodies where required in connection with the verification of accreditation credentials.

With legal and regulatory authorities where we are required to do so by law, court order, or the instructions of a competent regulatory authority.

In connection with a business transfer where CPD Certification Centre’s business or assets are acquired by or merged with another organisation. In such circumstances, personal data held by CPD Certification Centre may be transferred to the acquiring or merged organisation. Where this occurs, you will be notified in advance.

9. International Data Transfers

CPD Certification Centre is based in the United Kingdom and we aim to store and process your personal data within the UK wherever possible.

Where we use third-party service providers who process data outside the UK, for example cloud hosting providers or software platforms with servers in the European Economic Area or elsewhere, we will ensure that appropriate safeguards are in place to protect your personal data to the standard required by the Data Protection Legislation. These safeguards may include adequacy decisions recognised by the UK Information Commissioner’s Office, standard contractual clauses, or binding corporate rules, as appropriate.

For further information about the safeguards in place for any international data transfer, or to request a copy of the relevant transfer mechanism, please contact us using the details in clause 14.

10. How Long We Keep Your Data

We will not retain your personal data for longer than is necessary for the purpose for which it was collected, having regard to our legal and regulatory obligations, the nature of our relationship with you, and any applicable limitation periods for legal claims.

In general terms, we apply the following retention periods:

Personal data collected in connection with a contract with you, including accreditation application data, account data, and transaction data, is retained for 6 years from the date the contract terminates or expires, in line with standard commercial limitation periods.

Financial and payment records are retained for 6 years from the date of the relevant transaction, in compliance with statutory accounting and tax requirements.

Marketing communications data is retained for 2 years from the date we received your personal data, or until you opt out of marketing communications, whichever is earlier.

Learner and participant certificate data is retained for 3 years from the date the certificate is issued.

Technical and usage data collected through our website is retained for up to 2 years from the date of collection.

Where we are required by law or regulation to retain personal data for a longer or shorter period, we will comply with that legal or regulatory requirement.

At the end of the applicable retention period, personal data will be securely deleted or anonymised.

11. How We Keep Your Data Secure

The security of your personal data is important to us. We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

The measures we take include restricting access to personal data to those employees, contractors, and service providers who have a legitimate need to access it, and ensuring that all such persons are subject to appropriate confidentiality obligations. We use secure, encrypted connections (HTTPS) for data transmitted through our website and Provider Portal. We require our service providers and data processors to implement appropriate security measures and to process personal data only in accordance with our instructions. We maintain procedures for detecting, investigating, and responding to personal data breaches, including notification to you and to the Information Commissioner’s Office where required by law.

While we take all reasonable steps to protect your personal data, no method of transmission over the internet or electronic storage is completely secure. You use our website and submit data to us at your own risk. If you become aware of any security concern relating to your account or data, please contact us immediately at info@cpdcertificationcentre.co.uk.

12. Our Use of Cookies

12.1 What are cookies?

Cookies are small text files placed on your computer or device when you visit a website. They are widely used to make websites work correctly, to improve user experience, and to provide information to website owners about how their site is used.

12.2 How we use cookies

CPD Certification Centre uses cookies on our website and Provider Portal for the following purposes:

Strictly necessary cookies are essential for the website and Provider Portal to function correctly. They enable core features such as account login, session management, and security. These cookies do not collect personal data for marketing purposes and cannot be disabled without affecting the functionality of the site.

Analytics and performance cookies help us understand how visitors use our website and Provider Portal, which pages are most visited, and whether any errors occur. We use Google Analytics to collect this information in aggregated form. This helps us improve the website and the services we offer. Google’s privacy policy is available at policies.google.com/privacy.

Functional cookies remember your preferences and settings to improve your experience on return visits, such as remembering your login details or preferred language.

Marketing and targeting cookies may be used to deliver relevant content and advertising to you based on your interests. These cookies are only placed with your consent.

12.3 Your cookie choices

When you first visit our website, you will be presented with a cookie notice asking for your consent to place non-essential cookies on your device. You may accept all cookies, reject non-essential cookies, or manage your preferences through the cookie settings tool.

You may also manage cookies through your internet browser settings. Most browsers allow you to refuse or delete cookies. Please note that restricting or deleting cookies may affect the functionality of certain features of our website or Provider Portal.

For further information about managing cookies, please visit aboutcookies.org or allaboutcookies.org.

12.4 Cookie details

The following cookies are currently used on our website:

Cookie name: _ga | Category: Analytics | Purpose: Registers a unique ID used to generate statistical data on how visitors use the website | Expiry: 2 years

Cookie name: ga[ID] | Category: Analytics | Purpose: Used by Google Analytics to collect data on the number of times a user has visited the website and the dates of the first and most recent visits | Expiry: 2 years

Cookie name: [Session cookie] | Category: Strictly necessary | Purpose: Manages user sessions and authentication in the Provider Portal | Expiry: Session

[Additional cookies should be added here based on any further tools implemented on the website before launch.]

13. Your Rights

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are subject to certain limitations and exemptions under applicable law.

The right to be informed. You have the right to be informed about how we collect and use your personal data. This Privacy Policy is designed to fulfil that obligation. If you have any questions that are not answered by this policy, please contact us.

The right of access. You have the right to request a copy of the personal data we hold about you. This is known as a subject access request. See clause 14 for details of how to submit a request.

The right to rectification. You have the right to ask us to correct any personal data we hold about you that is inaccurate or incomplete. Please contact us if any of the data we hold about you needs to be updated.

The right to erasure. You have the right to ask us to delete or destroy personal data we hold about you in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, or where you withdraw your consent and we have no other lawful basis to continue processing. This right is not absolute and does not apply where we are required to retain the data by law or for the establishment, exercise, or defence of legal claims.

The right to restrict processing. You have the right to ask us to restrict how we process your personal data in certain circumstances, for example where you contest the accuracy of the data, while we verify it.

The right to data portability. Where we are processing your personal data on the basis of your consent or the performance of a contract, and the processing is carried out by automated means, you have the right to receive a copy of your data in a structured, commonly used, and machine-readable format, and to have it transferred to another data controller where technically feasible.

The right to object. You have the right to object to our processing of your personal data where we are relying on legitimate interests as the lawful basis. You also have an absolute right to object to processing for direct marketing purposes at any time, without needing to give a reason.

Rights in relation to automated decision-making and profiling. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. CPD Certification Centre does not currently make decisions about individuals solely by automated means.

The right to withdraw consent. Where we are relying on your consent as the lawful basis for processing your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, please contact us using the details in clause 14. We will respond to your request within one month of receiving it. In some cases, particularly where a request is complex or you have made multiple requests, we may extend this period by a further two months, in which case we will notify you of the extension and the reason for it.

We will not normally charge a fee for handling a rights request. However, where a request is manifestly unfounded, repetitive, or excessive, we may charge a reasonable administrative fee or, in some circumstances, decline to respond.

14. Subject Access Requests and Contacting Us

14.1 Subject access requests

If you wish to make a subject access request, or to exercise any of your other data protection rights, please contact us in writing at:

Data Protection Enquiries CPD Certification Centre Lynn Road, Ely, Cambridgeshire, CB6 1RY, United Kingdom Email: info@cpdcertificationcentre.co.uk

Please mark your request clearly as a data subject access request or specify which right you are seeking to exercise. Please provide sufficient information for us to verify your identity and locate the data you are requesting.

We will respond to your request within one month of receiving it. There is no charge for a subject access request unless the request is manifestly unfounded or excessive.

14.2 General enquiries

If you have any questions about this Privacy Policy, about how we use your personal data, or about any aspect of our data protection practices, please contact us at:

Email: info@cpdcertificationcentre.co.uk Telephone: +44 7418 354137 Post: CPD Certification Centre, Lynn Road, Ely, Cambridgeshire, CB6 1RY, UK

15. Complaints

If you have a concern about how we have handled your personal data, we would encourage you to contact us in the first instance so that we can seek to resolve your concern.

If you are not satisfied with our response, or if you believe we are not processing your personal data in accordance with the law, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO), the supervisory authority responsible for data protection in the United Kingdom.

The ICO’s contact details are:

Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 Website: ico.org.uk

16. Marketing Communications

CPD Certification Centre may from time to time send you information about our services, updates, news, and offers that we believe may be of interest to you.

Where you are an existing client or Approved Provider, we may contact you by email about our own similar services on the basis of our legitimate interests, in accordance with applicable privacy and electronic communications regulations. You may opt out of receiving these communications at any time by clicking the unsubscribe link in any marketing email or by contacting us directly.

Where you are not an existing client, we will only send you marketing communications where you have given your consent to receive them. You may withdraw your consent at any time.

We will never share your personal data with third parties for their own marketing purposes without your explicit consent.

17. Third-Party Links

Our website may contain links to third-party websites, social media platforms, and external resources. This Privacy Policy applies only to our website and services. We have no control over and accept no responsibility for the privacy practices or content of any third-party websites. We recommend that you review the privacy policies of any third-party websites you visit before providing any personal data to them.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our data processing activities, or our business practices. Any material changes will be notified to you in advance, either by email or by prominent notice on our website.

The date at the top of this policy indicates when it was last updated. We recommend that you review this policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services following any updates to this policy will be taken as acceptance of the revised policy.

19. Glossary of Key Terms

For reference, the following brief definitions may assist in reading this policy:

Data Controller means the organisation that decides how and why personal data is processed. CPD Certification Centre is the Data Controller for data processed in connection with our website and services.

Data Processor means an organisation that processes personal data on behalf of a Data Controller, under the Controller’s instructions.

UK GDPR means the UK General Data Protection Regulation, the principal data protection law in the United Kingdom.

Personal Data means any information that identifies or can identify a living individual, either directly or indirectly.

Special Category Data means a defined subset of personal data that is particularly sensitive and attracts additional legal protections, including data relating to health, race or ethnicity, religious or philosophical beliefs, sexual orientation, political opinions, trade union membership, biometric data, and genetic data.

Lawful Basis means the legal ground on which a Data Controller is permitted to process personal data under the UK GDPR.

Legitimate Interests means a lawful basis for processing personal data where the processing is necessary for the Data Controller’s genuine and proportionate business interests and does not override the rights and freedoms of the data subject.

Subject Access Request means a formal request by an individual to receive a copy of the personal data a Data Controller holds about them.

This Privacy Policy was last updated in May 2026. CPD Certification Centre, Lynn Road, Ely, Cambridgeshire, CB6 1RY, UK | info@cpdcertificationcentre.co.uk | +44 7418 354137 | cpdcertificationcentre.co.uk