How Train Aid Solutions handles personal data.
Train Aid Solutions provides a platform that UK classroom-based training businesses use to run attendance registers, issue verifiable certificates, collect feedback and send renewal reminders.
For a learner’s training records the training business is the data controller and TAS is the data processor acting on its instructions. For our own account holders’ details and our website, TAS is the controller. If you are a learner, the business that trained you is your first point of contact for any data request.
We deliberately minimise data held about minors. When a learner is under 16 the platform does not store the learner’s own email address — correspondence goes to a responsible organiser, such as a parent or the booking organisation, whose email is required instead. Under-16 learners receive an attendance-style certificate with no public verification record.
We use no analytics, advertising or tracking cookies. The only browser storage is what’s strictly necessary to keep you logged in — a short-lived session token and your business context. Because that storage is essential to the service, no cookie-consent banner is required.
We use a small number of sub-processors: DigitalOcean (hosting, database and file storage, located in London, UK), Postmark (transactional email) and Stripe (payments). Each processes data only to provide their part of the service. We do not sell personal data.
Email delivery and payment processing involve providers with US operations; those transfers are covered by the providers’ standard contractual safeguards. The platform’s database and files stay in the UK.
You have the right to access, correct or erase your personal data, and to object to or restrict its processing. Training businesses can export a learner’s full data or erase it from within the platform. Where erasure is requested for someone with an issued certificate, the record is anonymised rather than deleted so historical verification isn’t broken.
Data is encrypted in transit (TLS) and at rest, passwords are hashed with bcrypt, and access is scoped so each business sees only its own data. Payment card details are handled entirely by Stripe.