Privacy Policy
Effective Date: 01/08/2025
True North Learning (“we”, “our”, “us”)
respects your privacy and is committed to protecting your personal data. This
Privacy Policy explains how we collect, use, share, and safeguard your
information when you visit our website [www.truenorthlearning.co.uk]
(“Website”), register for our training, or interact with us.
We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) (where applicable), and other relevant data protection and privacy laws, including those governing international data transfers.
1. Who We Are
True North Learning is a UK-based training
provider offering professional learning and certification courses. We act as
the data controller of your personal data when you use our Website or
services.
If you have any questions about this
Privacy Policy, please contact us:
 Email:
info@truenorthlearning.co.uk
2. Personal Data We Collect
We may collect and process the following
types of personal data:
- Identity Data: Name, title, date of
     birth, gender.
 - Contact Data: Email address, phone
     number, postal address.
 - Account Data: Login credentials (if
     you create an account).
 - Transaction Data: Payment details
     (processed securely by third-party providers), billing address, order
     history.
 - Training Data: Course
     registrations, attendance, assessments, certifications achieved.
 - Technical Data: IP address, browser
     type, operating system, device information, cookies, and usage data.
 - Marketing & Communications Data: Preferences for receiving communications and marketing.
 
3. How We Collect Your Data
- Directly from you (when you register, sign up for a course,
     fill in a contact form, subscribe to newsletters, or communicate with us).
 - Automatically (through cookies, analytics tools, and tracking
     technologies on our Website).
 - From third parties (partners, certification bodies, or payment providers).
 
4. How We Use Your Personal Data
We process your personal data for the
following purposes:
- To register you for courses and deliver training services.
 - To issue certifications in partnership with recognised
     accreditation bodies.
 - To process payments and maintain financial records.
 - To provide customer support and respond to enquiries.
 - To send you service updates, reminders, and important notices.
 - To deliver marketing communications (with your consent or as
     permitted by law).
 - To improve our Website, services, and user experience.
 - To comply with legal obligations (e.g., tax, audit, regulatory compliance).
 
5. Lawful Basis for Processing
We rely on the following lawful bases under
UK GDPR/EU GDPR:
- Contract: Processing necessary to
     perform our agreement with you (e.g., delivering courses).
 - Consent: Where you explicitly agree
     (e.g., marketing communications).
 - Legal Obligation: Compliance with
     applicable laws (e.g., financial regulations).
 - Legitimate Interests: For business operations, Website improvement, fraud prevention, provided your rights are not overridden.
 
6. Cookies & Tracking
We use cookies and similar technologies to enhance user experience, analyse traffic, and personalise content. When you visit our site we may automatically log your IP address, a unique identifier for your computer or other access device, and your device type. We will not use your IP address to identify you in any way. We collect this to advise us how you use our website, how you got to our website, and how the website performs during your visit. The data is anonymised before being used for analytics and web performance processing. We will not identify you through analytics information, and we will not combine analytics information with other data sets in a way that would identify who you are. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors. For more information, please see our Cookie Policy [link].
7. Data Sharing & Disclosure
We may share your data with:
- Accreditation & Certification Bodies (to issue your certifications).
 - Payment Providers (to process
     transactions securely).
 - IT & Cloud Service Providers
     (hosting, storage, LMS platforms).
 - Regulators & Legal Authorities
     (where legally required).
 
We do not sell your data to third parties.
8. International Data Transfers
Where data is transferred outside the UK/EU
(e.g., to cloud providers or accreditation bodies), we ensure protection by:
- Using countries deemed adequate by the UK/EU (e.g., EEA,
     Switzerland).
 - Implementing Standard Contractual Clauses (SCCs)
     approved by the European Commission or UK ICO.
 - Ensuring providers adhere to recognised frameworks (e.g., UK-US Data Bridge, EU-US Data Privacy Framework, where applicable).
 
9. Data Retention
We retain your personal data only for as
long as necessary to fulfil the purposes outlined above, including legal, tax,
and certification obligations.
Retention periods:
- Training & Certification Records: up to 7 years (for
     verification purposes).
 - Financial Data: 6 years (in line with UK tax law).
 - Marketing Data: until you withdraw consent or opt out.
 
10. Your Rights
Under UK GDPR/EU GDPR, you have the
following rights:
- Access: Request a copy of the data
     we hold about you.
 - Rectification: Correct inaccurate
     or incomplete data.
 - Erasure (“Right to be Forgotten”):
     Request deletion where lawful.
 - Restriction: Limit how your data is
     processed.
 - Data Portability: Request transfer
     of your data in a structured format.
 - Object: To processing for marketing
     or legitimate interests.
 - Withdraw Consent: At any time for
     processing based on consent.
 
To exercise your rights, contact info@truenorthlearning.co.uk.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or the relevant supervisory authority in your country.
11. Data Security
We implement appropriate technical and
organisational measures, including:
- Encryption of data in transit and at rest
 - Secure access controls
 - Regular security monitoring and audits
 - Data minimisation and confidentiality practices
 
12. Children’s Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children without parental consent.
13. Changes to this Policy
We may update this Privacy Policy from time
to time. Any changes will be posted on this page with the updated date.