Privacy Policy
1. INTRODUCTION
MCR First Aid Training (“we,” “us,” or “our”) is committed to protecting and respecting your privacy. This policy explains how we collect, use, and protect your personal data when you visit our website, make an enquiry via our web forms, or book a training course with us.
We act as the Data Controller for the personal data we collect from you.
2. THE DATA WE COLLECT AND WHY WE COLLECT IT
To comply with the principle of “data minimisation,” we only collect the information necessary to provide our training services.
- Identity & Contact Data (Name, email, phone number, address): To respond to course enquiries and process bookings. Lawful Basis (UK GDPR): Performance of a Contract / Legitimate Interests.
- Course & Training Data (Course attended, results, certificate numbers): To manage your training records and issue valid certifications. Lawful Basis (UK GDPR): Performance of a Contract.
- Special Category Data (Medical conditions or disabilities relevant to training): To ensure your safety during practical assessments (e.g., CPR). Lawful Basis (UK GDPR): Explicit Consent (via separate opt-in on forms).
- Marketing & Communication Data (Preferences for receiving updates/offers): To send renewal reminders and relevant training updates. Lawful Basis (UK GDPR): Consent / Legitimate Interests (Soft opt-in).
3. SPECIAL CATEGORY DATA (HEALTH INFORMATION)
First aid training involves physical activity. If you disclose information regarding a disability or medical condition that impacts your ability to participate safely, we will process this as Special Category Data. We only do so if you provide explicit consent via a checkbox on our booking forms. This data is used solely for safety purposes and is deleted once the training session concludes, unless required for certification records.
4. THIRD-PARTY DISCLOSURES & DATA SHARING
We do not sell your personal data. We may share information with:
- Awarding Bodies: External organisations that require your details to issue your certificate.
- Service Providers: IT hosting, CRM, and email providers (some of which may be located outside the UK/EEA).
- Legal Obligations: Authorities if required by law or to protect our legal rights.
International Transfers: Where we transfer data outside the UK (e.g., using US-based tools like Google Analytics), we ensure appropriate safeguards, such as Standard Contractual Clauses (SCCs) or reliance on UK Adequacy Decisions, are in place.
5. DATA RETENTION
We retain your personal data only for as long as necessary:
- Training Records: We retain certification history for 6 years to facilitate renewals and meet regulatory audits.
- Marketing Data: We retain contact details until you withdraw consent or after a period of 24 months of inactivity.
6. YOUR LEGAL RIGHTS
Under the UK GDPR, you have the right to:
- Access your data;
- Rectify inaccuracies;
- Erase your data (where applicable);
- Restrict or Object to processing; and
- Request Data Portability.
7. CONTACT INFORMATION & COMPLAINTS
- Data Protection Officer: Anna Kolder
- Email: mcrfirstaidtraining@gmail.com
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) (www.ico.org.uk).
