Privacy Policy — gtonlineawards.com
GT ONLINE AWARDS
Privacy Policy Summary
Essential information for all website and platform users
|
GT Online Awards is operated by Grays Medic Training Services in the UK using Moodle 5.1 and the Lambda theme. This summary does not replace the full Privacy Policy. |
Who this policy covers
It applies to visitors, enquirers, purchasers, account holders, learners, workplace sponsors and authorised administrators using gtonlineawards.com or related e-learning services. Grays Medic Training Services is the data controller for the Platform.
Information collected
We may collect account and contact details, enrolment and course activity, attendance, assessments, certificates, transaction references, enquiries, marketing choices, IP and device data, security logs and limited health or accessibility information needed for adjustments.
Why information is used
Information is used to provide accounts, courses, assessments, support and certificates; process transactions; meet tax, regulatory, safeguarding and awarding-body requirements; secure and improve the Platform; prevent misuse; and provide optional marketing or non-essential technologies where permitted. Lawful bases include contract, legal obligation, legitimate interests and consent.
Storage and security
Moodle 5.1 is hosted by LSM Webhost in the UK. Some electronic records may be stored in encrypted AWS S3 storage in an EU region. Secured devices and Apple iCloud may support limited business functions. Controls include HTTPS, role-based access, authentication, device security, backups, logging and breach-response procedures.
Who receives information
Necessary information may be shared with authorised Grays Medic personnel, contracted service providers, Stripe or PayPal, awarding or accreditation organisations such as ITC First and the CPD Accreditation Office, a sponsoring school or employer, and public authorities where legally required. Some recipients act as independent controllers. Personal information is not sold.
International transfers
Processing is mainly in the UK and EEA. Where a service involves a restricted transfer elsewhere, Grays Medic uses an applicable UK adequacy decision, approved transfer agreement or other lawful safeguard, with additional security measures where appropriate.
How long information is kept
Account and routine course records are normally kept for up to three years after inactivity or closure; accredited records for three to six years or the awarding body’s required period; financial records for six years; enquiries for around one year; and identifiable analytics information for up to 26 months. Longer retention may apply for disputes, safeguarding, claims or regulatory requirements.
Cookies and children
Essential cookies support login and security. Optional analytics and similar technologies are controlled through Cookie Settings and the Cookie Policy. When an online service is offered directly to a child under 13 and consent is relied upon, parental authorisation is required. Child users receive enhanced privacy protections and data minimisation.
Your rights and marketing
Depending on the circumstances, you may request access, correction, erasure, restriction or portability; object to legitimate-interest processing; and withdraw consent. You may object to direct marketing at any time. GT Online Awards does not currently use solely automated decisions with legal or similarly significant effects.
Contact and complaints
Email privacy@graysmedic.com, call 0808 166 1016 (Monday–Friday, 9am–5pm), or write to Grays Medic Training Services, Unit 5, Hillyard Place, London SW20 0QQ, United Kingdom. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113.
Summary version 1.3 | Based on the Privacy Policy effective 5 August 2026
GT ONLINE AWARDS
Privacy Policy
For visitors, enquirers, purchasers, account holders and learners
|
|
|
EFFECTIVE 5 AUGUST 2026 This policy applies to gtonlineawards.com and related e-learning services operated by Grays Medic Training Services in the United Kingdom. The Platform uses Moodle 5.1 with the Lambda theme. |
1. Data controller and scope
Grays Medic Training Services is the trading name of the sole-trader business responsible for deciding why and how personal information is used through GT Online Awards. In this policy, “Grays Medic”, “we”, “us” and “our” refer to that business.
This policy covers visitors and users of gtonlineawards.com and related Moodle services, including people who enquire by telephone or email, purchasers, account holders, learners, workplace sponsors and authorised administrators. A school, employer, training partner, payment provider or awarding body may also act as a separate controller for its own purposes; its privacy notice will then apply alongside this one.
2. Information we collect and its source
· Account and identity information — name, email address, telephone number, postal or billing address, username, password hash, organisation and account preferences.
· Learner and course information — enrolment, attendance, course activity, progress, submissions, assessment results, feedback, completion and certificate records. Date of birth and learner or qualification identifiers may be required for accredited courses.
· Payment and transaction information — order, invoice, payment status, refund and transaction references. Stripe, PayPal or another payment provider processes full card or account details; Grays Medic does not normally store full payment-card details.
· Enquiry and relationship information — contact details, organisation, course interests, correspondence, support requests, complaints and marketing preferences.
· Technical and usage information — IP address, browser/device details, login and security logs, pages and activities accessed, cookie identifiers and analytics information where permitted.
· Limited special-category information — for example health, disability or accessibility information supplied for reasonable adjustments or another specific lawful purpose.
We collect information directly from you, automatically through the Platform, and sometimes from a parent or guardian, purchaser, employer, school, training partner, awarding body or authorised administrator.
3. Purposes and lawful bases
|
Purpose |
Examples |
Main lawful basis |
|
Deliver services |
Create accounts; enrol learners; deliver courses and assessments; provide support; issue certificates. |
Contract |
|
Meet obligations |
Tax and accounting; awarding-body and regulatory records; safeguarding; lawful requests. |
Legal obligation |
|
Operate and protect |
Service administration; security; fraud prevention; troubleshooting; proportionate improvement and audit. |
Legitimate interests |
|
Optional activities |
Non-essential cookies; newsletters to individuals; specific consent-based uses. |
Consent |
|
Adjustments |
Use limited health or disability information to arrange appropriate support. |
Article 6 basis plus an Article 9 condition, such as explicit consent or legal obligations where applicable |
Where we rely on legitimate interests, we consider necessity, proportionality and the impact on individuals. Consent may be withdrawn at any time without affecting processing already carried out.
4. Marketing communications
Service messages about an account, order, course, security or certificate are not marketing and may still be sent after a marketing opt-out. For promotional messages, we apply the UK GDPR and Privacy and Electronic Communications Regulations 2003 (PECR).
· Individuals receive electronic marketing only where consent, the statutory “soft opt-in”, or another PECR permission applies.
· Corporate contacts may receive relevant business-to-business information where permitted, but sole traders and some partnerships are treated as individual subscribers under PECR.
· Every marketing message provides a simple opt-out. Objections to direct marketing are honoured and a minimal suppression record may be retained to prevent further messages.
5. Moodle, hosting and storage
· Moodle 5.1 is hosted by LSM Webhost in the United Kingdom under contractual data-protection and security requirements. Moodle records account, course, assessment, activity and security information needed to operate the learning environment.
· Electronic records, including scanned registers where used, may be stored in Amazon Web Services S3 in an EU region with encryption and restricted access.
· Apple iCloud and secured company devices may support limited business functions. Device protection includes access controls and remote-management or remote-wipe capabilities where configured.
· Paper records are kept securely, scanned where appropriate and confidentially destroyed when no longer required.
· Access is role-based and limited to authorised personnel who are subject to confidentiality obligations.
|
OPERATIONAL ACCURACY Supplier services, configurations and data locations can change. Grays Medic maintains a current internal supplier and data-location register and updates this policy when a change materially affects individuals. |
6. Security
We use proportionate technical and organisational measures, including HTTPS, encryption in transit and where available at rest, role-based and least-privilege access, strong authentication, device security, backups, logging, confidentiality requirements and staff guidance on phishing and safe handling.
Suspected incidents are logged, contained, investigated and assessed under our breach procedure. Where required, we notify the ICO within 72 hours of becoming aware and inform affected individuals without undue delay where a breach is likely to create a high risk to their rights and freedoms. No online service can be guaranteed completely secure; users must keep login details confidential and report suspected unauthorised access promptly.
7. Service providers, awarding bodies and other recipients
We disclose only information reasonably necessary for the relevant purpose to:
· authorised Grays Medic personnel, trainers, tutors, assessors and administrators;
· hosting, cloud-storage, email/IT, security, backup and other suppliers acting under written terms. Where a supplier is our processor, the contract includes the requirements of Article 28 UK GDPR;
· payment providers such as Stripe and PayPal, which may act as processors or independent controllers depending on the activity;
· awarding and accreditation organisations, including ITC First and the CPD Accreditation Office, where necessary for registration, quality assurance, certification or verification. They may act as independent controllers;
· a purchaser, school, employer or workplace sponsor where it arranged or funded learning and has a lawful basis to receive limited progress, completion or certification information;
· professional advisers, courts, regulators, law-enforcement bodies or other parties where disclosure is required or permitted by law; and
· a prospective buyer or successor in a genuine business reorganisation, subject to confidentiality and data-protection safeguards.
We do not sell personal information or disclose it for another organisation’s unrelated marketing.
8. International transfers
We primarily process information in the UK and EEA. Storage in an EU region is covered by the United Kingdom’s applicable adequacy arrangements for the EEA. Where another service involves a restricted transfer to a country without UK adequacy regulations, we use an approved safeguard—such as the UK International Data Transfer Agreement or UK Addendum to approved EU Standard Contractual Clauses—carry out required transfer-risk assessment and apply supplementary controls where appropriate. Contact us for information about safeguards relevant to your information.
9. Retention
|
Record |
Normal working period |
|
Learner account and routine course activity |
While active and normally up to 3 years after the last activity or account closure. |
|
Accredited attendance, assessment and achievement |
Normally 3–6 years after completion, or longer where the awarding/accreditation organisation requires it for verification. |
|
Financial and transaction records |
Normally 6 years after the end of the relevant financial year, or longer where a specific legal requirement applies. |
|
Enquiries and prospective-client records |
Normally up to 1 year after the last meaningful contact, unless a relationship continues or marketing permission remains valid. |
|
Analytics information |
Normally up to 26 months where identifiable or pseudonymous; aggregate or genuinely anonymised statistics may be retained longer. |
|
Security and incident records |
According to risk and need; routine logs are normally retained for a shorter period, while incident evidence may be kept for claims, regulatory or safeguarding purposes. |
Records are securely deleted or anonymised when the period ends. If immediate deletion from a protected backup is not technically practicable, the information is isolated from ordinary use and deleted through the next scheduled backup cycle. A dispute, investigation, safeguarding concern, legal claim or binding awarding-body requirement may justify longer retention, which we document.
10. Cookies and similar technologies
Strictly necessary technologies support login, session security and requested platform functions. MoodleSession keeps a user signed in and normally expires on logout or when the browser session ends. If enabled, rememberusername stores the chosen login preference. Analytics technologies, including Google Analytics cookies such as _ga, _gid and _gat, are used only where configured and where the required consent or applicable legal exception is in place.
Non-essential technologies are controlled through the consent mechanism. Users can revisit “Cookie Settings” in the footer and can also manage cookies in their browser, although blocking essential technologies may prevent login or course functions. The separate Cookie Policy provides the current names, providers, purposes and durations.
11. Children’s privacy
We design the service with children’s best interests in mind and apply data minimisation, clear information, appropriate account controls and proportionate retention. A parent, guardian, school or other authorised organisation should arrange or approve an account where required by the circumstances.
The UK age of consent for an information-society service is 13. If we offer an online service directly to a child under 13 and rely on consent for the relevant processing, we obtain authorisation from a person with parental responsibility and make reasonable efforts to verify it. This rule does not mean that consent is always the lawful basis for every child account. We consider the Children’s Code where the service is likely to be accessed by children.
12. Your rights
Depending on the circumstances and lawful basis, you may ask us to:
· give you access to your personal information and a copy of it;
· correct inaccurate or incomplete information;
· erase information or restrict its use;
· provide information you supplied in a portable, machine-readable form;
· object to processing based on legitimate interests, and object absolutely to direct marketing; and
· withdraw consent at any time.
These rights are not absolute and lawful exemptions may apply. We may request information needed to verify identity or authority. We normally respond within one month; a lawful extension may apply to complex or multiple requests, and we will explain it. There is usually no fee.
13. Automated decisions
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects. If that changes, we will explain the logic, significance, likely consequences and available safeguards before the processing applies.
14. Complaints
Please first contact us using the details below, explain the concern and state the outcome you seek. We will investigate fairly, keep you informed and respond without undue delay. You may complain at any time to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113. The ICO will usually expect you to have raised the matter with us first.
15. Changes to this policy
We may update this policy to reflect changes in law, official guidance, platform functions, suppliers or business operations. The current version and date will remain published. Material changes will be highlighted through an appropriate notice, such as a website banner, platform message or email to affected users.
16. Contact us
|
DATA CONTROLLER Grays Medic Training Services (sole trader, England, UK) |
Publication version 1.3 | Effective 5 August 2026