List of active policies
| Name | Type | User consent |
|---|---|---|
| Privacy Policy | Privacy policy | Authenticated users |
| Privacy Policy — gtonlineawards.com | Site policy | All users |
| Cookie Policy | Other policy | All users |
Summary
GT ONLINE AWARDS
Privacy Policy Summary
Essential information about how personal data is handled
|
GT Online Awards is operated by Grays Medic in the United Kingdom using Moodle 5.1 and the Lambda theme. This summary should be read with the full Privacy Policy. |
Who controls your information
Grays Medic is the data controller for personal information processed through GT Online Awards. Employers, training partners or awarding bodies may sometimes act as separate controllers for their own purposes.
Information collected
We may collect identity and account details, contact and payment records, enrolment and assessment information, grades, certificates, platform activity, IP and device information, support communications, consent choices and limited health or accessibility information when required.
Why information is used
Information is used to provide accounts, courses, assessments, support and certificates; process payments; keep required regulatory and financial records; secure and improve the platform; prevent misuse; and send optional marketing where permitted. The relevant lawful bases include contract, legal obligation, legitimate interests and consent.
Moodle, cookies and security
Moodle records course activity, progress, submissions, grades and security logs. Essential cookies support login and platform security. Optional analytics or functional technologies remain subject to the choices described in the Cookie Policy. Security measures include access controls, authentication, encryption in transit, backups and logging.
Who may receive information
Information may be shared where necessary with authorised Grays Medic staff, tutors and assessors; contracted hosting, IT, email, payment and certificate providers; a sponsoring employer or purchaser; awarding or regulatory bodies; and public authorities where legally required. Grays Medic does not sell personal information.
How long information is kept
Routine account and Moodle activity data is normally kept for up to 24 months after last activity or closure. Assessment and certificate records are normally retained for six years, accounting records for six years, security logs for up to 12 months, and complaint or rights-request records for around three years. Longer retention may apply where legally or regulatorily required.
Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability; object to processing based on legitimate interests; and withdraw consent. You have an absolute right to object to direct marketing. Requests are normally answered within one month.
Contact and complaints
Contact Grays Medic through its website or call 0808 166 1016 and mark the request “Data Protection”. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113.
Summary version 1.3 | 3 August 2026
Full policy
GT ONLINE AWARDS
Privacy Policy
How Grays Medic handles personal information on its online learning platform
|
Effective 3 August 2026 This notice applies to GT Online Awards, operated by Grays Medic in the United Kingdom. The platform currently runs Moodle 5.1 with the Lambda theme. |
1. Who we are
Grays Medic is the controller of personal information processed through GT Online Awards. We decide why and how that information is used. This notice covers visitors, account holders, learners, purchasers, workplace sponsors and people who contact us. Where an employer, training provider or awarding body decides independently how learner information is used, that organisation may also be a separate controller and its own privacy notice will apply.
Contact us about privacy or exercise your rights through the Contact Us page on the Grays Medic website or by telephone on 0808 166 1016. Please mark correspondence “Data Protection”.
2. Information we collect
· Identity and account data — name, username, password hash, date of birth where required, employer or organisation, learner identifiers and profile details.
· Contact and transaction data — email, telephone, billing address, order, invoice, payment status, refunds and related correspondence. Card details are normally handled by the payment provider, not stored in Moodle.
· Learning and assessment data — enrolments, progress, attendance, answers, submissions, grades, feedback, completion, certificates, qualification and expiry information.
· Technical and usage data — IP address, device/browser information, login times, session and security logs, pages and activities accessed, course interactions, cookie identifiers and diagnostics.
· Communications and preferences — support requests, survey responses, complaints, marketing choices and records of consent.
· Limited special category data — for example health, disability or accessibility information only where needed to provide adjustments or meet a legal obligation.
We collect information directly from you, automatically through the platform, and sometimes from a purchaser, employer, training partner, awarding body or administrator who enrols you.
3. Why we use it and our lawful bases
Contract: to create and administer accounts; process orders; provide courses, assessments, support and certificates; and manage the learner relationship. Legal obligation: to maintain tax, accounting, safeguarding, qualification or regulatory records and respond to lawful requests. Legitimate interests: to secure and administer the service, prevent fraud and misuse, troubleshoot, improve learning delivery, keep proportionate audit records and manage business-to-business relationships. We balance these interests against your rights. Consent: for optional marketing, non-essential cookies and specific uses of special category data where consent is the appropriate condition. You may withdraw consent at any time without affecting earlier processing.
4. If you do not provide information
Fields marked as required are needed to create an account, take payment, enrol you, verify achievement or issue a certificate. Without them, we may be unable to provide the relevant service. Optional profile fields may be left blank.
5. How Moodle and the Lambda theme are used
Moodle records account, course and activity information needed to operate the learning environment. Teachers and authorised administrators can see information relevant to their role, such as enrolment, activity completion, submissions and grades. Moodle logs also help us investigate access, security and technical problems. The Lambda theme controls presentation of the Moodle site; it does not by itself determine our purposes for processing. Enabled Moodle plugins, embedded content or integrations may process additional information, in which case we provide appropriate information or choices at the relevant point.
6. Cookies and similar technologies
Strictly necessary cookies keep you signed in, maintain security and remember essential session choices. We may also use functional or analytics technologies to understand performance and improve the platform. Where UK law requires consent, these technologies remain off until you choose them. You can change available choices through the cookie settings and browser controls, although blocking essential cookies may prevent login or course functions. See our separate Cookie Policy for the current list, providers, purposes and durations.
7. Who receives your information
We disclose only what is reasonably necessary to:
· authorised Grays Medic staff, tutors, assessors and administrators;
· Moodle hosting, IT support, email, security, backup, analytics and certificate-service providers acting under contract;
· payment processors, banks, accountants and professional advisers;
· the purchaser, employer or training sponsor, where they arranged or funded the learning and have a proper basis to receive progress or completion information;
· awarding, accreditation or regulatory bodies where needed to register a learner, quality-assure delivery or issue/verify an award; and
· courts, regulators, law-enforcement bodies or other parties where the law requires or permits disclosure, or to establish, exercise or defend legal claims.
Our processors may use information only on documented instructions, must protect it and must delete or return it when their services end, subject to law. We do not sell personal information.
8. International transfers
Some service providers may store or access information outside the UK. Before making a restricted transfer, we use a lawful safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved EU standard contractual clauses, and apply supplementary security measures where appropriate. Contact us for information about the safeguard relevant to your information.
9. Retention
We keep information only for as long as needed for the stated purpose, then delete or anonymise it unless law requires longer retention. Our working periods are:
· account and routine Moodle activity data — while the account is active and normally up to 24 months after the last activity or closure;
· assessment, achievement and certificate records — normally 6 years after completion, or longer where an awarding/accreditation rule requires it;
· orders, invoices and accounting records — 6 years after the end of the relevant financial year;
· support, complaint and rights-request records — normally 3 years after closure; security logs — normally up to 12 months; and
· marketing records — until opt-out, plus a minimal suppression record so we honour the choice.
These periods may be extended for an unresolved dispute, fraud investigation, legal claim or binding regulatory requirement. We review and document exceptions.
10. Security
We use proportionate technical and organisational measures, including role-based access, authentication controls, encryption in transit, backups, logging, staff confidentiality and incident procedures. No internet service is completely secure. Keep your password confidential, use a unique password and notify us promptly if you suspect unauthorised access.
11. Your data protection rights
Depending on the circumstances and lawful basis, you may ask us to:
· give you access to your personal information and a copy of it;
· correct inaccurate or incomplete information;
· erase information, or restrict how it is used;
· provide information you supplied in a portable, machine-readable form;
· stop processing based on legitimate interests; and
· withdraw consent at any time.
|
Your right to object You have an absolute right to object to direct marketing. You may also object to processing based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims. |
Rights are not absolute and exemptions may apply. We may ask for information needed to confirm identity or authority. We normally respond within one month; complex or multiple requests may lawfully take longer, and we will explain why. There is usually no fee.
12. Marketing and automated decisions
We send electronic marketing to individuals only where permitted by law and provide an unsubscribe route in each message. Opting out does not stop service messages about an account, order or course. We do not currently use solely automated decision-making that produces legal or similarly significant effects. If that changes, we will explain the logic, significance, likely consequences and available safeguards before it applies.
13. Children and accessibility information
GT Online Awards is intended for learners able to enter the relevant training arrangement themselves or through a parent, guardian, employer or other authorised organisation. If we knowingly provide an online service directly to a child and rely on consent, we apply the UK age and parental-authorisation rules. A parent or guardian should contact us before creating an account for a child. Accessibility or health information should be limited to what is necessary for an adjustment; we restrict access and apply an Article 9 condition under the UK GDPR.
14. Complaints
Please first raise a data protection complaint through our Contact Us page or telephone number above, stating what happened and the outcome you seek. We will acknowledge it within 30 days, investigate and keep you informed without undue delay, and explain the outcome. You may also complain to the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint or 0303 123 1113. You can approach the ICO at any time, although it will usually expect you to have contacted us first.
15. Links, changes and governing framework
The platform may link to third-party sites or embedded services. Their operators control their own processing, so review their notices. We may update this policy when our services, suppliers or law change. Material changes will be highlighted on the platform or sent to affected users where appropriate. The current version and effective date will remain published.
This policy is written for the UK GDPR and the Data Protection Act 2018, as amended (including by the Data (Use and Access) Act 2025), and the Privacy and Electronic Communications Regulations 2003 where cookies or electronic marketing are involved.
|
Privacy contact Grays Medic — operator of GT Online Awards | Contact via the Grays Medic website | 0808 166 1016 | Please mark correspondence “Data Protection”. |
Publication version 1.3 • Effective 3 August 2026
Summary
GT ONLINE AWARDS
Privacy Policy Summary
Essential information for all website and platform users
|
GT Online Awards is operated by Grays Medic Training Services in the UK using Moodle 5.1 and the Lambda theme. This summary does not replace the full Privacy Policy. |
Who this policy covers
It applies to visitors, enquirers, purchasers, account holders, learners, workplace sponsors and authorised administrators using gtonlineawards.com or related e-learning services. Grays Medic Training Services is the data controller for the Platform.
Information collected
We may collect account and contact details, enrolment and course activity, attendance, assessments, certificates, transaction references, enquiries, marketing choices, IP and device data, security logs and limited health or accessibility information needed for adjustments.
Why information is used
Information is used to provide accounts, courses, assessments, support and certificates; process transactions; meet tax, regulatory, safeguarding and awarding-body requirements; secure and improve the Platform; prevent misuse; and provide optional marketing or non-essential technologies where permitted. Lawful bases include contract, legal obligation, legitimate interests and consent.
Storage and security
Moodle 5.1 is hosted by LSM Webhost in the UK. Some electronic records may be stored in encrypted AWS S3 storage in an EU region. Secured devices and Apple iCloud may support limited business functions. Controls include HTTPS, role-based access, authentication, device security, backups, logging and breach-response procedures.
Who receives information
Necessary information may be shared with authorised Grays Medic personnel, contracted service providers, Stripe or PayPal, awarding or accreditation organisations such as ITC First and the CPD Accreditation Office, a sponsoring school or employer, and public authorities where legally required. Some recipients act as independent controllers. Personal information is not sold.
International transfers
Processing is mainly in the UK and EEA. Where a service involves a restricted transfer elsewhere, Grays Medic uses an applicable UK adequacy decision, approved transfer agreement or other lawful safeguard, with additional security measures where appropriate.
How long information is kept
Account and routine course records are normally kept for up to three years after inactivity or closure; accredited records for three to six years or the awarding body’s required period; financial records for six years; enquiries for around one year; and identifiable analytics information for up to 26 months. Longer retention may apply for disputes, safeguarding, claims or regulatory requirements.
Cookies and children
Essential cookies support login and security. Optional analytics and similar technologies are controlled through Cookie Settings and the Cookie Policy. When an online service is offered directly to a child under 13 and consent is relied upon, parental authorisation is required. Child users receive enhanced privacy protections and data minimisation.
Your rights and marketing
Depending on the circumstances, you may request access, correction, erasure, restriction or portability; object to legitimate-interest processing; and withdraw consent. You may object to direct marketing at any time. GT Online Awards does not currently use solely automated decisions with legal or similarly significant effects.
Contact and complaints
Email privacy@graysmedic.com, call 0808 166 1016 (Monday–Friday, 9am–5pm), or write to Grays Medic Training Services, Unit 5, Hillyard Place, London SW20 0QQ, United Kingdom. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113.
Summary version 1.3 | Based on the Privacy Policy effective 5 August 2026
Full policy
GT ONLINE AWARDS
Privacy Policy
For visitors, enquirers, purchasers, account holders and learners
|
|
|
EFFECTIVE 5 AUGUST 2026 This policy applies to gtonlineawards.com and related e-learning services operated by Grays Medic Training Services in the United Kingdom. The Platform uses Moodle 5.1 with the Lambda theme. |
1. Data controller and scope
Grays Medic Training Services is the trading name of the sole-trader business responsible for deciding why and how personal information is used through GT Online Awards. In this policy, “Grays Medic”, “we”, “us” and “our” refer to that business.
This policy covers visitors and users of gtonlineawards.com and related Moodle services, including people who enquire by telephone or email, purchasers, account holders, learners, workplace sponsors and authorised administrators. A school, employer, training partner, payment provider or awarding body may also act as a separate controller for its own purposes; its privacy notice will then apply alongside this one.
2. Information we collect and its source
· Account and identity information — name, email address, telephone number, postal or billing address, username, password hash, organisation and account preferences.
· Learner and course information — enrolment, attendance, course activity, progress, submissions, assessment results, feedback, completion and certificate records. Date of birth and learner or qualification identifiers may be required for accredited courses.
· Payment and transaction information — order, invoice, payment status, refund and transaction references. Stripe, PayPal or another payment provider processes full card or account details; Grays Medic does not normally store full payment-card details.
· Enquiry and relationship information — contact details, organisation, course interests, correspondence, support requests, complaints and marketing preferences.
· Technical and usage information — IP address, browser/device details, login and security logs, pages and activities accessed, cookie identifiers and analytics information where permitted.
· Limited special-category information — for example health, disability or accessibility information supplied for reasonable adjustments or another specific lawful purpose.
We collect information directly from you, automatically through the Platform, and sometimes from a parent or guardian, purchaser, employer, school, training partner, awarding body or authorised administrator.
3. Purposes and lawful bases
|
Purpose |
Examples |
Main lawful basis |
|
Deliver services |
Create accounts; enrol learners; deliver courses and assessments; provide support; issue certificates. |
Contract |
|
Meet obligations |
Tax and accounting; awarding-body and regulatory records; safeguarding; lawful requests. |
Legal obligation |
|
Operate and protect |
Service administration; security; fraud prevention; troubleshooting; proportionate improvement and audit. |
Legitimate interests |
|
Optional activities |
Non-essential cookies; newsletters to individuals; specific consent-based uses. |
Consent |
|
Adjustments |
Use limited health or disability information to arrange appropriate support. |
Article 6 basis plus an Article 9 condition, such as explicit consent or legal obligations where applicable |
Where we rely on legitimate interests, we consider necessity, proportionality and the impact on individuals. Consent may be withdrawn at any time without affecting processing already carried out.
4. Marketing communications
Service messages about an account, order, course, security or certificate are not marketing and may still be sent after a marketing opt-out. For promotional messages, we apply the UK GDPR and Privacy and Electronic Communications Regulations 2003 (PECR).
· Individuals receive electronic marketing only where consent, the statutory “soft opt-in”, or another PECR permission applies.
· Corporate contacts may receive relevant business-to-business information where permitted, but sole traders and some partnerships are treated as individual subscribers under PECR.
· Every marketing message provides a simple opt-out. Objections to direct marketing are honoured and a minimal suppression record may be retained to prevent further messages.
5. Moodle, hosting and storage
· Moodle 5.1 is hosted by LSM Webhost in the United Kingdom under contractual data-protection and security requirements. Moodle records account, course, assessment, activity and security information needed to operate the learning environment.
· Electronic records, including scanned registers where used, may be stored in Amazon Web Services S3 in an EU region with encryption and restricted access.
· Apple iCloud and secured company devices may support limited business functions. Device protection includes access controls and remote-management or remote-wipe capabilities where configured.
· Paper records are kept securely, scanned where appropriate and confidentially destroyed when no longer required.
· Access is role-based and limited to authorised personnel who are subject to confidentiality obligations.
|
OPERATIONAL ACCURACY Supplier services, configurations and data locations can change. Grays Medic maintains a current internal supplier and data-location register and updates this policy when a change materially affects individuals. |
6. Security
We use proportionate technical and organisational measures, including HTTPS, encryption in transit and where available at rest, role-based and least-privilege access, strong authentication, device security, backups, logging, confidentiality requirements and staff guidance on phishing and safe handling.
Suspected incidents are logged, contained, investigated and assessed under our breach procedure. Where required, we notify the ICO within 72 hours of becoming aware and inform affected individuals without undue delay where a breach is likely to create a high risk to their rights and freedoms. No online service can be guaranteed completely secure; users must keep login details confidential and report suspected unauthorised access promptly.
7. Service providers, awarding bodies and other recipients
We disclose only information reasonably necessary for the relevant purpose to:
· authorised Grays Medic personnel, trainers, tutors, assessors and administrators;
· hosting, cloud-storage, email/IT, security, backup and other suppliers acting under written terms. Where a supplier is our processor, the contract includes the requirements of Article 28 UK GDPR;
· payment providers such as Stripe and PayPal, which may act as processors or independent controllers depending on the activity;
· awarding and accreditation organisations, including ITC First and the CPD Accreditation Office, where necessary for registration, quality assurance, certification or verification. They may act as independent controllers;
· a purchaser, school, employer or workplace sponsor where it arranged or funded learning and has a lawful basis to receive limited progress, completion or certification information;
· professional advisers, courts, regulators, law-enforcement bodies or other parties where disclosure is required or permitted by law; and
· a prospective buyer or successor in a genuine business reorganisation, subject to confidentiality and data-protection safeguards.
We do not sell personal information or disclose it for another organisation’s unrelated marketing.
8. International transfers
We primarily process information in the UK and EEA. Storage in an EU region is covered by the United Kingdom’s applicable adequacy arrangements for the EEA. Where another service involves a restricted transfer to a country without UK adequacy regulations, we use an approved safeguard—such as the UK International Data Transfer Agreement or UK Addendum to approved EU Standard Contractual Clauses—carry out required transfer-risk assessment and apply supplementary controls where appropriate. Contact us for information about safeguards relevant to your information.
9. Retention
|
Record |
Normal working period |
|
Learner account and routine course activity |
While active and normally up to 3 years after the last activity or account closure. |
|
Accredited attendance, assessment and achievement |
Normally 3–6 years after completion, or longer where the awarding/accreditation organisation requires it for verification. |
|
Financial and transaction records |
Normally 6 years after the end of the relevant financial year, or longer where a specific legal requirement applies. |
|
Enquiries and prospective-client records |
Normally up to 1 year after the last meaningful contact, unless a relationship continues or marketing permission remains valid. |
|
Analytics information |
Normally up to 26 months where identifiable or pseudonymous; aggregate or genuinely anonymised statistics may be retained longer. |
|
Security and incident records |
According to risk and need; routine logs are normally retained for a shorter period, while incident evidence may be kept for claims, regulatory or safeguarding purposes. |
Records are securely deleted or anonymised when the period ends. If immediate deletion from a protected backup is not technically practicable, the information is isolated from ordinary use and deleted through the next scheduled backup cycle. A dispute, investigation, safeguarding concern, legal claim or binding awarding-body requirement may justify longer retention, which we document.
10. Cookies and similar technologies
Strictly necessary technologies support login, session security and requested platform functions. MoodleSession keeps a user signed in and normally expires on logout or when the browser session ends. If enabled, rememberusername stores the chosen login preference. Analytics technologies, including Google Analytics cookies such as _ga, _gid and _gat, are used only where configured and where the required consent or applicable legal exception is in place.
Non-essential technologies are controlled through the consent mechanism. Users can revisit “Cookie Settings” in the footer and can also manage cookies in their browser, although blocking essential technologies may prevent login or course functions. The separate Cookie Policy provides the current names, providers, purposes and durations.
11. Children’s privacy
We design the service with children’s best interests in mind and apply data minimisation, clear information, appropriate account controls and proportionate retention. A parent, guardian, school or other authorised organisation should arrange or approve an account where required by the circumstances.
The UK age of consent for an information-society service is 13. If we offer an online service directly to a child under 13 and rely on consent for the relevant processing, we obtain authorisation from a person with parental responsibility and make reasonable efforts to verify it. This rule does not mean that consent is always the lawful basis for every child account. We consider the Children’s Code where the service is likely to be accessed by children.
12. Your rights
Depending on the circumstances and lawful basis, you may ask us to:
· give you access to your personal information and a copy of it;
· correct inaccurate or incomplete information;
· erase information or restrict its use;
· provide information you supplied in a portable, machine-readable form;
· object to processing based on legitimate interests, and object absolutely to direct marketing; and
· withdraw consent at any time.
These rights are not absolute and lawful exemptions may apply. We may request information needed to verify identity or authority. We normally respond within one month; a lawful extension may apply to complex or multiple requests, and we will explain it. There is usually no fee.
13. Automated decisions
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects. If that changes, we will explain the logic, significance, likely consequences and available safeguards before the processing applies.
14. Complaints
Please first contact us using the details below, explain the concern and state the outcome you seek. We will investigate fairly, keep you informed and respond without undue delay. You may complain at any time to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113. The ICO will usually expect you to have raised the matter with us first.
15. Changes to this policy
We may update this policy to reflect changes in law, official guidance, platform functions, suppliers or business operations. The current version and date will remain published. Material changes will be highlighted through an appropriate notice, such as a website banner, platform message or email to affected users.
16. Contact us
|
DATA CONTROLLER Grays Medic Training Services (sole trader, England, UK) |
Publication version 1.3 | Effective 5 August 2026
Summary
GT ONLINE AWARDS
Cookie Policy Summary
Essential information for visitors and learners
|
GT Online Awards is operated by Grays Medic in the UK using Moodle 5.1 and the Lambda theme. This summary does not replace the full Cookie Policy or the live Cookie Settings panel. |
What cookies are
Cookies and similar technologies store or access information on your device. Session cookies normally expire when the browser closes; persistent cookies remain for a stated period or until deleted. They may be set by GT Online Awards or by an integrated third-party service.
Essential Moodle cookies
MoodleSession, or a site-prefixed equivalent, maintains login, security and continuity while you move between pages. It is strictly necessary and normally ends when you log out or close the browser. Blocking it prevents the Platform from maintaining your login.
Preference cookies
MOODLEID, or a similar identifier, may remember the username entered on the login form. It is optional and persistent for the configured period shown in your browser or Cookie Settings. Refusing it only means re-entering your username. The Lambda theme or plugins may also store preferences if configured.
Analytics and optional technologies
Analytics, performance, embedded-media, payment or other third-party technologies may be used when actually configured. Non-exempt technologies remain off until you actively consent. Limited statistical or appearance technologies may be used without consent only where every applicable UK legal condition is met and a simple objection mechanism is provided.
Your consent choices
Use Cookie Settings on the Platform to accept, reject or change optional categories. Continuing to browse is not consent. You may withdraw consent at any time as easily as you gave it. Optional advertising, retargeting, cross-site tracking and social-media pixels are not activated without prior consent.
Live cookie information
Because Moodle configuration, plugins and embedded content can change, the live Cookie Settings panel is the current inventory for non-core technologies. It should identify each cookie or storage item, provider, purpose, category, first- or third-party status and expiry period.
Information and retention
Depending on the technology and your choices, data may include IP address, device/browser details, identifiers, login state, timestamps, pages or activities, referral source, errors and interactions. Durations are limited to what is reasonably necessary and persistent technologies are reviewed periodically. The Privacy Policy applies where this information is personal data.
Browser controls and third parties
Your browser can display, delete or block cookies and site storage, but doing so may sign you out or remove saved choices. Embedded content and external provider sites may be governed by their own privacy and cookie information. Provider controls may also be available.
Rights, contact and complaints
Where cookie information is personal data, relevant UK data-protection rights may apply. Contact Grays Medic through its website or call 0808 166 1016 and mark the enquiry “Data Protection”. You may complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or 0303 123 1113.
Summary version 1.3 | Based on the Cookie Policy effective 4 August 2026
Full policy
GT ONLINE AWARDS
Cookie Policy
Cookies and similar technologies used by our online learning platform
|
Effective 4 August 2026 GT Online Awards is operated by Grays Medic in the United Kingdom and currently uses Moodle 5.1 with the Lambda theme. |
1. About this policy
This policy explains how GT Online Awards uses cookies and similar storage or access technologies when you visit the platform, sign in or complete learning activities. It should be read with our Privacy Policy. The policy applies to cookies, browser storage, pixels, scripts, tags and comparable technologies that store information on, or access information from, your device.
2. What cookies are
Cookies are small text files stored by a website in your browser. Session cookies normally expire when the browser is closed; persistent cookies remain for a defined period or until removed. First-party cookies are associated with the platform domain. Third-party technologies are supplied by another organisation, for example an embedded-video, analytics or payment provider.
3. Core Moodle cookies
A standard Moodle installation uses the following core cookies. The exact prefix may be changed by the site administrator, so the name visible in your browser may vary.
|
Name |
Purpose |
Category |
Duration |
|
MoodleSession (or a site-prefixed equivalent) |
Maintains continuity, security and login status while you move between pages. |
Strictly necessary |
Session; destroyed on logout or when the browser session closes. |
|
MOODLEID or similar |
Remembers the username in the login form for convenience. It is safe to refuse; you will need to re-enter the username. |
Functional / preference |
Persistent; the live browser record shows the configured expiry. |
Cookie names and lifetimes can change if Moodle configuration is updated. The platform’s live cookie settings and your browser’s storage inspector provide the current technical values.
4. Cookie categories
Strictly necessary
These technologies are required for security, authentication, session continuity, load balancing or a service you request. They cannot normally be switched off through the consent panel. Blocking them in your browser may prevent login, course navigation, assessments or other essential functions.
Functional and preference
These remember choices such as a username, language, display preference or interface setting. We use them with consent or, where the statutory appearance exception applies, after providing clear information and a simple way to object.
Analytics and performance
These help us understand how learners and visitors use the platform, diagnose performance and improve the service. Where an analytics technology qualifies for the UK statistical-purpose exception, it may be used without consent only if the information is used solely to produce aggregate statistics, is not shared except to produce those statistics, and users have a simple way to object. Otherwise, it is activated only after consent.
Embedded content and media
Courses may contain videos, documents, interactive resources or content hosted by another provider. Loading that content may allow the provider to set cookies or receive technical information. Where consent is required, the content should remain blocked until you choose to load or enable it. The provider’s own privacy and cookie information also applies.
Payments and external services
If a checkout, payment, webinar, support or certificate service is integrated, it may use necessary security and transaction technologies, plus optional technologies where permitted. A link that opens a separate provider site is governed by that provider’s policy. We do not treat an optional third-party technology as active unless it is actually configured on GT Online Awards.
Advertising and social-media tracking
GT Online Awards does not activate advertising, retargeting, cross-site tracking or social-media pixels without prior consent. Such technologies must remain disabled when consent is refused or withdrawn. If introduced, the consent panel must identify the provider, purpose and duration before activation.
5. Current third-party inventory
Moodle plugins, course content and integrations can change. For accuracy, the live cookie settings panel is the authoritative inventory for non-core technologies. Before any optional technology is enabled, the panel should display:
· the cookie or storage identifier;
· the organisation responsible for it;
· its specific purpose and category;
· whether it is first-party or third-party;
· its expiry or retention period; and
· a link to the provider’s information where appropriate.
|
Implementation requirement Grays Medic should run a cookie scan after every significant Moodle, Lambda-theme, plugin, analytics, payment or embedded-content change and update both the consent panel and this policy where necessary. |
6. Consent and legal exceptions
The general rule under the Privacy and Electronic Communications Regulations 2003 is that we provide clear information and obtain consent before using non-exempt storage or access technologies. Consent must be freely given, specific, informed and expressed through a clear positive action. Optional technologies must not be pre-enabled merely because a visitor continues browsing.
The law permits limited exceptions, including technologies necessary to transmit a communication or provide a service requested by the user. Following changes made by the Data (Use and Access) Act 2025, limited statistical and appearance/functionality technologies may also be exempt when all statutory conditions are met, including clear information and a simple means of objection. Where a technology serves several purposes, every purpose must qualify or the non-exempt purpose requires consent.
7. How to manage your choices
· Use “Cookie settings” on the platform to accept, reject or change optional categories.
· Withdraw consent at any time; withdrawal must be as easy as giving consent.
· Use your browser settings to view, delete or block cookies and site storage.
· Use provider controls where an embedded or third-party service offers them.
Effects of blocking or deleting cookies
Deleting cookies may remove saved choices and sign you out. Blocking MoodleSession will prevent the platform from maintaining your login. If you withdraw consent, we stop the relevant optional technology and associated processing, subject to limited information already lawfully retained.
8. Information collected through these technologies
Depending on the technology and your choices, information may include an IP address, device and browser details, cookie or session identifier, login state, timestamps, pages or activities accessed, referral source, performance events, error information and interactions with course or embedded content. Where this identifies or relates to a person, our Privacy Policy explains the purposes, lawful bases, recipients, retention and data-protection rights.
9. Moodle, the Lambda theme and plugins
Moodle provides the learning, login and session functions. The Lambda theme controls presentation and may store or read preferences if configured to do so. Neither the theme name nor a plugin label determines whether consent is required; the purpose and operation of each technology do. Plugins, external fonts, media players, analytics, chat, payment tools or other integrations must be assessed before deployment.
10. Security and retention
We limit cookie duration to what is reasonably necessary for its purpose and review persistent technologies periodically. Security controls are used to protect identifiers and associated information. Cookie identifiers may still be personal data when they can single out or link activity to a user, even if they do not contain a person’s name.
11. Your rights
Where cookie information is personal data, you may have rights of access, correction, erasure, restriction, portability or objection, depending on the circumstances. You may withdraw consent at any time. These rights are explained in the GT Online Awards Privacy Policy and are not always absolute.
12. Contact and complaints
GT Online Awards is operated by Grays Medic. For questions about this policy, your cookie choices or personal information, use the Grays Medic website contact form or call 0808 166 1016 and mark the enquiry “Data Protection”. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint/ or 0303 123 1113.
13. Changes to this policy
We may update this policy when the platform, Moodle configuration, theme, plugins, providers or law changes. The current version and effective date will be published on the platform. Material changes affecting consent will be reflected in the consent tool and, where necessary, we will ask for a fresh choice.
14. Legal framework
This policy is written for the Privacy and Electronic Communications Regulations 2003, the UK General Data Protection Regulation and the Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025.
|
Cookie contact Grays Medic — operator of GT Online Awards | Contact via email info@gtonlinewards.com | 0808 166 1016 | Mark correspondence “Data Protection”. |
Publication version 1.3 • Effective 4 August 2026
