Train Aid Solutions
Legal

Privacy policy

How Train Aid Solutions handles personal data.

Last updated 27 July 2026
On this page
01 Who we are and our role 02 What we collect and why 03 Learners under 16 04 Cookies and storage 05 How long we keep data 06 Who we share data with 07 Your rights 08 How we protect data
01

Who we are and our role

Train Aid Solutions provides a platform that UK classroom-based training businesses use to run attendance registers, issue verifiable certificates, collect feedback and send renewal reminders.

For a learner’s training records the training business is the data controller and TAS is the data processor acting on its instructions. For our own account holders’ details and our website, TAS is the controller. If you are a learner, the business that trained you is your first point of contact for any data request.

02

What we collect and why

Account holders (Admins, Instructors): name, email and a securely hashed password — to provide access. Lawful basis: contract.
Learners: name, email, an optional organiser contact, attendance, assessment outcomes, instructor notes and feedback — to maintain training records, issue certificates and send reminders. Lawful basis: the training business’s legitimate interest in compliance records.
Certificates: name-bearing PDFs verifiable by QR or code. The public verification page shows a redacted name (first name, last initial) with the course, dates and validity — never an email or full personal details.
Historical records: an imported past course keeps the same controller/processor split, and no emails are sent to imported learners.
Email logs: a record of transactional emails sent or deliberately suppressed, so a business can prove what did and didn’t go out.
Payments: handled by Stripe. We store only Stripe reference IDs and invoice records for VAT receipts, never card details.
03

Learners under 16

We deliberately minimise data held about minors. When a learner is under 16 the platform does not store the learner’s own email address — correspondence goes to a responsible organiser, such as a parent or the booking organisation, whose email is required instead. Under-16 learners receive an attendance-style certificate with no public verification record.

04

Cookies and storage

We use no analytics, advertising or tracking cookies. The only browser storage is what’s strictly necessary to keep you logged in — a short-lived session token and your business context. Because that storage is essential to the service, no cookie-consent banner is required.

05

How long we keep data

Active learners — anyone who attended a course in the last 37 months — are retained so renewal reminders keep working.
Records with no certificate issued, such as no-shows, are deleted after 37 months without course activity.
Certificated records are anonymised — identifiers removed, certificate and verification code retained — once the certificate has been expired for 36 months. Certificates issued without an expiry remain valid and are retained indefinitely.
Email logs are kept for up to 37 months from last activity.
If a training business closes its account, data is retained securely so the account can be reactivated, and every certificate it issued stays publicly verifiable.
06

Who we share data with

We use a small number of sub-processors: DigitalOcean (hosting, database and file storage, located in London, UK), Postmark (transactional email) and Stripe (payments). Each processes data only to provide their part of the service. We do not sell personal data.

Email delivery and payment processing involve providers with US operations; those transfers are covered by the providers’ standard contractual safeguards. The platform’s database and files stay in the UK.

07

Your rights

You have the right to access, correct or erase your personal data, and to object to or restrict its processing. Training businesses can export a learner’s full data or erase it from within the platform. Where erasure is requested for someone with an issued certificate, the record is anonymised rather than deleted so historical verification isn’t broken.

08

How we protect data

Data is encrypted in transit (TLS) and at rest, passwords are hashed with bcrypt, and access is scoped so each business sees only its own data. Payment card details are handled entirely by Stripe.

For any privacy question, or to exercise your rights, contact us. You also have the right to complain to the UK Information Commissioner’s Office.
Email us