Privacy policy
This policy explains what personal data The Exchange collects, why we hold it, who we share it with, how long we keep it, and what you can ask us to do with it. It covers the website and the member platform.
Who is responsible for your data
The data controller is [[CONTROLLER LEGAL NAME]], registered at [[REGISTERED ADDRESS]] (company number [[COMPANY NUMBER]], ICO registration [[ICO REGISTRATION NUMBER]]). For anything in this policy, including any of the requests described below, contact [[PRIVACY CONTACT EMAIL]].
What we collect
If you create an account
- Your email address and name, and a securely hashed version of your password. We never store your password itself.
- Profile details you choose to add: job title, employer, a short biography, an optional display nickname, professional qualifications, and the topics you have expertise in.
- If you turn on two-factor authentication — required for administrators — the secret used to verify your codes.
- Your membership tier, and the organisation you belong to where you joined through one.
As you use the platform
- Courses you enrol on, and your CPD ledger — the activities you log, the hours claimed, and the certificates issued to you.
- Anything you post publicly on the platform: community threads and replies, likes, ratings, and articles or videos you submit.
- Your notification preferences and the topics you subscribe to, plus a record of the notifications we have sent you.
- Reports you make about other members’ content, and moderation decisions taken about your own account.
If you contact us or send us a suggestion
- Suggestions for improving the Exchange, including any email address you choose to give us. On the public form the email is optional, and we use it only to tell you if your suggestion is built.
- Complaints, including your name and contact email. You do not need to be a member to raise one.
- Requests about your own data, and a record of how we handled them.
Consent records
When you agree to something — these terms, marketing emails, topic notifications, or the terms attached to a gated download — we store the decision, when it was made, and the version of the policy it was made against. We keep an equivalent, append-only log of cookie decisions. These records exist so we can show what you agreed to and when, and so that withdrawing consent is as reliable as giving it.
Why we use it, and on what basis
- To provide membership — running your account, giving you access to content and courses, and maintaining your CPD record and certificates. Necessary to perform our contract with you.
- To send you things you asked for — marketing emails, and notifications about topics you follow. Based on your consent, which you can withdraw at any time.
- To keep the platform safe and working — authentication, moderation, preventing abuse of public forms, and acting on the suggestions and complaints we receive. Our legitimate interest in a secure, usable service.
- To meet our obligations — keeping consent and data-request records so we can demonstrate compliance. Necessary for compliance with a legal obligation.
Who we share it with
We do not sell your personal data. We share it only with the service providers we need to run the Exchange, and only so far as they need it:
| Provider | What for | What they see |
|---|---|---|
| Resend | Sending email — sign-in links, service notices and member updates | Your email address and the message content |
| Vimeo | Hosting and streaming some of our videos | Technical data from your browser when you play a video, including your IP address |
| [[HOSTING PROVIDER AND REGION]] | Running our servers and database | Everything above, stored at rest |
Some of these providers are based outside the United Kingdom. Where that is the case we rely on the safeguards described in [[TRANSFER SAFEGUARD — e.g. UK IDTA / adequacy]].
Other members can see what you post publicly, and your name on a course roster — but only if you have turned roster visibility on, which is off unless you choose otherwise.
Cookies
We currently set only the cookies needed to run the site: those that keep you signed in and protect forms against cross-site request forgery. We do not currently run analytics or advertising cookies. If that changes, this policy and the cookie policy will be updated first, and non-essential cookies will not be set before you have made a choice.
How long we keep it
We keep your account and profile data for as long as you have an account. If you ask us to erase your data, we clear or anonymise the personal details on your account and you will no longer be able to sign in.
Two things deliberately survive that process. Your CPD ledger and any certificates issued to you are retained, so a professional development record you have already relied on stays verifiable. Records of consent and of data requests are also retained, because they are the evidence that we handled your data properly. Neither is used to contact you or to rebuild a profile.
If you unsubscribe from our emails we keep your address on a suppression list. That is the only way to be sure we do not email you again.
Your rights
Under UK data protection law you can ask us to give you a copy of your personal data, correct it if it is wrong, erase it, restrict or object to how we use it, or send it to another provider. Where we rely on your consent, you can withdraw it at any time — and withdrawing is as easy as giving it.
To exercise any of these, email [[PRIVACY CONTACT EMAIL]]. We will respond within one month. If your request is complex we may need longer, and we will tell you within that first month if so. You will not be charged.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would rather you came to us first so we can put it right.
Changes to this policy
If we change how we use your personal data we will update this page. A change that affects something you have consented to means asking you again, not assuming your previous answer still applies.