Legal
Privacy policy
Last updated 8 September 2026
Draft, pending legal review. Published so acceptance at registration refers to a real document. Not yet reviewed by counsel.
What we hold
- Your name and email address.
- Your employer and team, where an organization has enrolled you.
- Your training and assessment records — enrollments, lesson progress, attempts, scores and competency results.
- Sign-in metadata: session times, IP address and user agent, used for security and to let you revoke devices.
- A record of which version of these documents you accepted, and when.
What we deliberately never hold
No real merchant bank statement, application or financial record enters this platform in any environment, including test data. Every training file is generated by us. A breach of this platform cannot expose merchant financial records, because we never held them.
Identity verification
Where a credential-bearing programme requires identity verification, we store the result and its provenance — which provider checked, when, and the outcome. We do not retain the identity document beyond the period policy requires. The free tier requires no verification at all.
Retention
Training records are retained for the life of the credential and any recertification period, because their whole purpose is to be producible later. Where an employer deactivates you, the training record is retained rather than deleted — that is what the record is for.
Sub-processors
SendGrid (Twilio) for transactional email. Our database and application hosting provider. Fonts are self-hosted, so no request for them leaves your browser to a third party. We will publish a full list with change notice before the first enterprise contract.