Privacy Policy

 

  • Version: 1.0
  • Last updated: 01/03/2026
  • Organisation: Sole Survivor PTSD Support CIC (“we”, “us”)
  • Website: Sole Survivor Training Portal
  • Portal URL: www.soletraining.co.uk
  • Contact (privacy): system-support@ptsdsupport.co.uk
  • Registered address: Office 4, Wirral Chamber of Commerce & Industry, Egerton House, 2 Tower Road, Birkenhead, Wirral, CH41 1FN
  • ICO registration number: ZB563212ZB563212

 

1) What this notice covers

  • This notice explains how we use personal data when you:
    • Access our online training portal
    • Buy training (B2B) via PayPal
    • Use course features (progress tracking, quizzes, certificates if enabled)
    • Contact support

 

2) Personal data we collect

  • Identity & account data
    • Name, work email, organisation name, username, password (encrypted/hashed where applicable)
  • Training activity data
    • Course enrolments, lesson completion, progress %, quiz results, assessment outcomes, certificates (if enabled), timestamps
  • Technical data
    • IP address, device/browser info, login events, error logs, cookie identifiers
  • Purchase/admin data (B2B)
    • Purchaser name, business email, organisation details, transaction references, invoices/receipts
  • Support data
    • Messages you send us, attachments you provide, and admin notes relating to support

 

3) Where do we get your data from

  • Directly from you (account creation, support requests)
  • From your organisation (where your employer books seats and provides staff details)
  • From our systems (TutorLMS and website logs)
  • From PayPal (transaction confirmation and references)

 

4) How we use your data (purposes)

  • Provide and manage portal access
    • Create accounts, enrol learners, manage seat allocations, and create personal admin accounts.
  • Deliver training
    • Display content, track progress, manage quizzes/assessments, issue certificates (if enabled)
  • Business administration
    • Payments, receipts, accounting, customer service, contract management
  • Security
    • Prevent fraud, protect accounts, monitor suspicious activity
  • Improve the portal
    • Fix issues, performance monitoring, analytics (only where lawfully enabled)

 

5) Our lawful bases (UK GDPR)

  • Contract (B2B)
    • To provide portal access and deliver training agreed with the client organisation
  • Legitimate interests
    • Security, service improvement, business administration (balanced against your rights)
  • Legal obligation
    • Accounting/tax records and compliance requirements
  • Consent (limited)
    • For non-essential cookies/analytics (where used)

 

6) Who we share data with (processors/sub-processors)

  • PayPal / Xero / Stripe (payment processing and transaction confirmation)
  • Professional advisers (accountant, legal adviser), where necessary
  • IT support (only when needed to maintain the portal

Anonymised & non-identifiable data is collected for analytics purposes (Google Analytics)

 

7) International transfers

  • Some suppliers (e.g., PayPal and certain web services) may process data outside the UK.
  • Where international transfers occur, we use appropriate safeguards (e.g., recognised transfer mechanisms) where required.

 

8) How long do we keep your data (retention)

  • Learner accounts & training records: 12 months (e.g., duration of contract + 12–24 months). Completion/Participation data may be retained for analytical purposes after course completion & account deletion.
  • Financial records: 6 years (UK accounting practice)

 

9) Your data protection rights

  • You can request:
    • access to your data, correction, deletion (where applicable)
    • restriction or objection (in certain cases)
    • data portability (where applicable)
  • To request, email: system-support@ptsdsupport.co.uk 

 

10) Complaints

  • Please raise issues with us first: info@ptsdsupport.co.uk
  • You can also lodge a complaint with the Information Commissioner’s Office (ICO) (UK regulator).

 

11) Security

  • We use practical controls such as:
    • role-based access (admin access limited)
    • strong passwords and 2FA where applicable
    • regular updates/patching
    • secure hosting and backups
    • logging/monitoring for suspicious activity

 

12) Changes to this notice

  • We may update this notice from time to time.
  • The latest version will be published on our website.