top of page

THE INTERNATIONAL CERTIFICATION AND TRAINING ACADEMY LTD

TICTA Privacy Notice

How we collect, use, share and protect personal information

Effective date: 27 July 2026     Version: 1.0     Next review: 27 July 2027

Our commitment

TICTA uses personal information responsibly, transparently and only for legitimate business, training, assessment and legal purposes. We limit access, retain records only for as long as necessary and respect the rights of each individual.

1. About this notice

This notice explains how TICTA handles personal information when we provide training, assessment, certification and related professional services. It also explains the choices and rights available to individuals under UK data protection law.

We provide this notice when we collect personal information directly and make it available through our website, enrolment and booking processes, online learning platform and working arrangements. If another organisation supplies information to us, it should also tell the individual that it will be shared with TICTA.

2. Who is responsible for your information?

Data controller

The International Certification and Training Academy Ltd (trading as TICTA)

Company number

08729859

ICO registration

ZB116927

Registered address

6 Bridle Road, Coalville, Leicestershire, United Kingdom, LE67 3GB

Contact

info@ticta.co.uk  |  +44 (0)330 094 0166  |  www.ticta.co.uk

TICTA is the data controller for the processing described in this notice unless we state otherwise. We have not appointed a statutory Data Protection Officer. The Director acts as TICTA’s data protection lead and can be contacted at info@ticta.co.uk.

3. Who this notice applies to

This notice covers personal information relating to:

  • learners, candidates and certificate holders;

  • employees, job applicants, trainers, assessors and other contractors;

  • contacts at universities, academies, employers, clients and partner organisations;

  • website visitors, people who make enquiries and recipients of professional updates; and

  • suppliers, professional advisers and other business contacts.

4. Personal information we collect

The information we collect depends on the relationship and the service involved. It may include:

  • Identity and contact information — name, title, date of birth where necessary, postal and email addresses, telephone number, organisation, role, learner or candidate identifier, signature and emergency contact details.

  • Training and certification information — enrolment, bookings, attendance, course progress, assessment submissions, assessor comments, results, feedback, qualification details, certificate numbers and verification history.

  • Online and technical information — Thinkific account information, login and course activity, website enquiry data, IP address, device/browser information, security logs and cookie preferences.

  • Financial and transaction information — invoice and payment status, payer details, purchase references and accounting records. TICTA currently accepts customer payment by bank transfer and does not collect payment-card details.

  • Employment and professional information — employment history, qualifications, experience, references, right-to-work evidence, training and continuing professional development, availability and performance records.

  • Correspondence and case information — emails, meeting notes, requests, complaints, appeals, malpractice or safeguarding information, incident records and evidence needed to investigate or resolve a matter.

  • Special category information — health, disability or other sensitive information where genuinely needed for a reasonable adjustment, welfare, safeguarding or legal requirement. Equality-monitoring information may be collected only where appropriate and lawful.

  • Criminal-offence information — only where it is necessary, proportionate and lawful for a particular role, safeguarding matter or legal requirement.

5. Where personal information comes from

We may receive personal information:

  • directly from the individual, including through enquiries, forms, email, meetings and course activity;

  • from a university, academy, employer, client or other organisation arranging or funding training;

  • from authorised trainers, assessors, referees, recruitment contacts and quality-assurance personnel;

  • from our website and service platforms when an individual uses them; and

  • from public or professional sources where it is reasonable and lawful to do so.

6. Why we use personal information and our lawful bases

UK data protection law requires us to identify a lawful basis for each use of personal information. More than one basis may apply, depending on the circumstances.

Purpose

How we use personal information

Main lawful basis

Enquiries, bookings and course delivery

Responding to enquiries; enrolling learners; arranging training; communicating about schedules, access and support.

Contract or steps before a contract; legitimate interests.

Assessment, certification and verification

Recording attendance, assessment evidence, results, certificates, quality assurance and future verification.

Contract; legitimate interests; legal obligation where applicable.

Online learning and account administration

Creating and supporting Thinkific accounts; providing content; tracking course progress and activity.

Contract; legitimate interests.

Client and partner management

Managing relationships with universities, academies, employers and other commissioning organisations.

Contract; legitimate interests.

Finance and administration

Issuing invoices, receiving bank transfers, maintaining accounts, recovering debts and meeting tax obligations.

Contract; legal obligation; legitimate interests.

People and resourcing

Recruiting, engaging and managing employees, trainers, assessors, contractors and applicants.

Contract or steps before a contract; legal obligation; legitimate interests.

Quality, complaints and safety

Managing complaints, appeals, malpractice, safeguarding concerns, incidents and service improvement.

Legal obligation; legitimate interests; vital interests where applicable.

Marketing and professional updates

Sending relevant information to people who have requested it or where business-contact marketing is permitted.

Consent or legitimate interests, subject to electronic-marketing rules and the right to opt out.

Website operation and security

Handling web enquiries, protecting our website and services, and using non-essential cookies only where consent is required.

Legitimate interests for essential operation and security; consent for non-essential cookies.

Compliance and rights

Answering data-rights requests, keeping compliance records, investigating breaches and establishing or defending legal claims.

Legal obligation; legitimate interests.

Our legitimate interests include delivering and improving reliable training and assessment services, administering our organisation, maintaining professional relationships, protecting systems, ensuring quality and defending legal rights. We balance those interests against the individual’s rights and reasonable expectations.

7. Special category and criminal-offence information

Sensitive information receives additional protection. When we process health, disability or other special category information, we identify both an Article 6 lawful basis and an appropriate additional condition. Depending on the circumstances, this may be explicit consent, employment or social-protection law, vital interests, or substantial public interest supported by law—for example, safeguarding.

We collect only what is necessary. Medical or disability evidence used to decide a reasonable adjustment is access-restricted and removed as soon as reasonably possible after the decision. Criminal-offence information is processed only where a lawful condition applies and suitable safeguards are in place.

8. If you do not provide information

Some information is needed to answer an enquiry, enter into a contract, deliver training, verify identity, assess competence, issue a certificate, make a reasonable adjustment or meet a legal requirement. If required information is not provided, we may be unable to enrol the learner, provide the service, complete an assessment or certification process, make the requested adjustment or engage the person for a role. We will explain where providing information is optional.

9. Who we share personal information with

We share personal information only where there is a legitimate need and apply appropriate confidentiality, access and contractual controls. Recipients may include:

  • the university, academy, employer, client or other organisation that arranged or funded the training, where relevant;

  • authorised trainers, assessors, internal or external quality-assurance personnel and certification or approval bodies;

  • service providers that support our operations, including Thinkific, Certifier, Wix, Names.co.uk, Google Drive and QuickBooks;

  • our business bank in connection with bank-transfer payments;

  • professional advisers, auditors and insurers; and

  • regulators, courts, law-enforcement bodies, emergency services or other authorities where disclosure is required or permitted by law.

We do not sell personal information

TICTA does not sell or rent personal information to third parties.

10. International access and transfers

TICTA operates in the United Kingdom and the United Arab Emirates. Access from the UAE is limited to TICTA’s Director. Some cloud and technology providers, or their approved sub-processors, may store or access information outside the United Kingdom.

Where UK restricted-transfer rules apply, we use an available lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another legally recognised safeguard. We also use processor contracts, access controls and security measures. Individuals may contact us for more information about the safeguards relevant to their data.

11. How we keep information secure

We use proportionate technical and organisational measures designed for a small training and certification organisation. These include:

  • role-based access and restricted folders, with access limited to people who need the information;

  • strong passwords and multi-factor authentication where the service supports it;

  • encrypted connections and secure transfer methods for electronic information;

  • confidentiality expectations for employees, trainers, assessors and contractors;

  • supplier due diligence and data-processing terms where a supplier processes personal information for us;

  • backup and recovery arrangements, access reviews, record minimisation and secure disposal; and

  • a documented data-breach management process, including assessment and escalation to the ICO or affected individuals where legally required.

12. How long we keep information

We keep information only for as long as needed for the purpose for which it was collected, including legal, accounting, quality-assurance, certification and dispute requirements. Our normal retention periods are:

Record type

Normal retention period

Course administration and client booking records

6 years

Attendance and assessment evidence

3 years

Core qualification and certificate-verification records

7 years

Thinkific course-activity records

Course duration plus 3 years

Medical or disability evidence used for a reasonable-adjustment decision

Deleted as soon as reasonably possible after the decision, normally within 12 months

Complaints, appeals, malpractice and safeguarding records

6 years, subject to the needs and circumstances of the case

Trainer, assessor, employee and contractor records

6 years after the relationship ends

Unsuccessful recruitment applications

6 months

Finance and accounting records

6 years after the relevant financial year

General website enquiries

12 months; up to 2 years for genuine prospective clients

Marketing contacts

Until opt-out or 2 years without engagement; a minimal suppression record may be kept

Data-rights request records

3 years

Personal-data breach and significant compliance records

6 years

Supplier due-diligence and data-processing agreements

6 years after the relationship ends

A record may be kept for longer where a complaint, safeguarding matter, legal claim, investigation, regulatory requirement or other documented need makes this necessary. When the retention period ends, information is securely deleted, destroyed or irreversibly anonymised.

13. Your data protection rights

Depending on the circumstances and the lawful basis used, an individual may have the right to:

  • Be informed about how their personal information is used;

  • Access their personal information and receive a copy;

  • Rectification of inaccurate or incomplete information;

  • Erasure of information in certain circumstances;

  • Restriction of processing in certain circumstances;

  • Object to processing based on legitimate interests and to direct marketing at any time;

  • Data portability for certain information processed by automated means under consent or contract; and

  • Withdraw consent at any time where consent is relied upon, without affecting earlier lawful processing.

These rights are not absolute and legal exemptions may apply. We will normally respond within one month after receiving a valid request and any information reasonably needed to confirm identity or clarify the request. We do not normally charge a fee.

To exercise a right, email info@ticta.co.uk. We will not disadvantage a person for making a genuine data protection request.

14. Automated decision-making

TICTA does not make decisions about individuals solely by automated means where the decision produces legal effects or similarly significant effects. If this changes, we will provide the information and safeguards required by law.

15. Children and young people

Our services may occasionally involve a person under 18. Where this applies, we minimise the information collected, provide clear and age-appropriate privacy information, and involve a parent, guardian, school, academy, university or commissioning organisation where appropriate and lawful. Safeguarding information is handled on a strict need-to-know basis.

16. Marketing and cookies

Marketing communications will identify TICTA and provide a simple way to opt out. We will honour an opt-out promptly and may keep a minimal suppression record so that we do not contact the person again by mistake.

Our website uses cookies and similar technologies for operation, security and user preferences. Non-essential cookies or analytics will be used only where the required consent has been obtained through the website’s cookie controls. Browser settings may also be used to manage cookies, although disabling essential cookies may affect website functionality.

17. Questions and complaints

Please contact TICTA first if you have a question or concern. We will take it seriously and aim to resolve it promptly:

Contact TICTA

Email: info@ticta.co.uk
Telephone: +44 (0)330 094 0166
Post: 6 Bridle Road, Coalville, Leicestershire, United Kingdom, LE67 3GB

An individual also has the right to complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office

Website: ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

18. Changes to this notice

We review this notice at least annually and sooner if our services, systems or legal obligations change. The current version will be published on our website. Where a change would materially affect individuals, we will take reasonable steps to bring it to their attention.

19. Accessibility and alternative formats

If you need this notice in another format, or would like help understanding how it applies to you, contact info@ticta.co.uk or telephone +44 (0)330 094 0166. We will make reasonable efforts to provide the information in an accessible form.

Document control

Document owner

TICTA Director / Data Protection Lead

Approved

27 July 2026

Version

1.0

Next scheduled review

27 July 2027

THE INTERNATIONAL CERTIFICATION AND TRAINING ACADEMY LTD

TICTA Privacy Notice

How we collect, use, share and protect personal information

Effective date: 27 July 2026     Version: 1.0     Next review: 27 July 2027

Our commitment

TICTA uses personal information responsibly, transparently and only for legitimate business, training, assessment and legal purposes. We limit access, retain records only for as long as necessary and respect the rights of each individual.

​

union-jack-1027898_1920.jpg

GET IN TOUCH

6 Bridle Road, Coalville, Leicestershire, United Kingdom, LE67 3GB
Tel: +44 (0)3300940166

info@ticta.co.uk

© 2022 by TICTA. Proudly created with Wix.com

bottom of page