Draft, pending legal review. This page is a working draft prepared for internal review. It is not legal advice and it is not yet in force. It must be reviewed and approved by a qualified UK solicitor, and the bracketed placeholders below (company details, addresses and dates) completed, before it is published or relied upon.
Privacy Policy
This policy explains what personal data we collect when you use Trigfell, why we use it, who processes it on our behalf, and the rights you have under UK data protection law.
Last updated: [date to be completed on publication]
1. Who is responsible for your data
Trigfell is a platform operated by [JGP Consultancy Limited, company number to be completed], whose registered office is at [registered office address to be completed] (“Trigfell”, “we”, “us” or “our”). JGP Consultancy is the company behind the Trigfell brand and is the party you contract with when you use the platform.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, JGP Consultancy is the data controller for the personal data described in this policy. Our data protection contact is [data protection contact name and email to be completed].
2. The personal data we collect
Depending on how you use Trigfell, we may collect:
- Account and profile data: your name, email address, password (stored in hashed form by our authentication provider), and any profile details you add such as a handle, bio, skills and goals.
- Learning data: the courses and cohorts you enrol in, your lesson progress, work you submit for feedback, and the certificates and CPD hours you earn.
- Community data: posts, comments, reactions, space memberships and any reports you make.
- Purchase data: a record of what you have bought, your subscription status and entitlements. Card and payment details are collected and processed by Paddle, our payments provider, and not by us.
- Communications: messages you send us and transactional emails we send you.
- Technical and usage data: information collected through cookies and similar technologies, product-analytics events, and error diagnostics. See our Cookie Policy for the detail.
3. Why we use it, and our lawful bases
We use your personal data to provide and improve the Services, and we rely on the following lawful bases under UK GDPR:
- Performance of a contract: to create and run your account, deliver the courses, community, certificates and events you sign up for, and process your purchases.
- Legitimate interests: to keep the platform secure, prevent abuse, understand how the product is used so we can improve it, and run our business. Where we rely on legitimate interests, we balance them against your rights.
- Consent: for non-essential cookies and similar technologies, and for any optional marketing messages. You can withdraw consent at any time.
- Legal obligation: to meet our legal and regulatory duties, for example tax and accounting records.
4. Who processes data on our behalf
We use a small number of trusted providers to run Trigfell. They process personal data on our behalf, under contract, and only as needed to provide their service:
- Supabase for authentication and our application database, which holds your account, profile, learning and community data. We use an EU region for this data.
- Paddle as our Merchant of Record and payments provider. Paddle collects and processes your payment details and handles billing, tax and refunds as the seller of record.
- Postmark to send transactional emails, such as sign-in, receipts and course notifications.
- PostHog (EU) for privacy-conscious product analytics, to understand how the platform is used.
- Sentry (EU) for error monitoring and diagnostics, to detect and fix problems.
Some of these providers, or their sub-processors, may process data in the European Economic Area (EEA) or elsewhere. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or addendum, or an adequacy decision. [The full list of sub-processors and transfer mechanisms to be confirmed with each provider].
5. How long we keep it
We keep personal data only for as long as we need it for the purposes described above, then delete or anonymise it. Account and learning data is generally kept for as long as your account is active and for a reasonable period afterwards. Records we must keep for legal reasons, such as purchase and tax records, are kept for the period the law requires. [Specific retention periods per data type to be confirmed].
6. Your rights and how to exercise them
Under UK data protection law you have the right to:
- access a copy of the personal data we hold about you;
- rectify inaccurate or incomplete data;
- eraseyour data (the “right to be forgotten”) in certain circumstances;
- data portability, to receive your data in a structured, commonly used, machine-readable format;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent where we rely on it.
To make this straightforward, Trigfell includes self-service tooling in your account settings. When you are signed in, you can request a downloadable export of your own data and request erasure of your account and data directly from your settings. For your security, we may ask you to have signed in recently before you can start an export or erasure request, and we keep an internal audit record of these requests. You can also contact our data protection contact using the details above, and we will respond within the time limits set by law.
7. Cookies and similar technologies
We use cookies and similar technologies for essential functions such as keeping you signed in, for a referral cookie, and, subject to your choices, for analytics and error monitoring. Our Cookie Policy explains each cookie and how to control them.
8. How we protect your data
We take appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and restricting who can access data to those who need it. No online service can be completely secure, but we work to reduce risk and to respond quickly if something goes wrong.
9. Children
Trigfell is a professional platform intended for adult, professional users. It is not directed at children, and we do not knowingly collect personal data from children.
10. Complaints
If you have a concern about how we handle your personal data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the “last updated” date above and, where the change is significant, take reasonable steps to tell you.