How Train Aid Solutions handles personal data.
Last updated: 27 July 2026
Train Aid Solutions ("TAS", "we") provides a platform that UK classroom-based training businesses use to run attendance registers, issue verifiable certificates, collect feedback, and send renewal reminders.
For a learner's training records, the training business is the data controller and TAS is the data processor acting on its instructions. For our own account holders' details and our website, TAS is the controller. If you are a learner, the training business that trained you is your first point of contact for any data request.
We deliberately minimise data held about minors. When a learner is under 16, the platform does not store the learner's own email address — all correspondence goes to a responsible organiser (for example a parent or the booking organisation), whose email is required instead. Under-16 learners receive an attendance-style certificate that carries no public verification record.
We use no analytics, advertising, or tracking cookies. The only browser storage we use is strictly necessary to keep you logged in (a short-lived session token and your business context, held in your browser). Because this storage is essential to the service, no cookie-consent banner is required.
We use a small number of sub-processors to run the service: DigitalOcean (hosting, database and file storage — located in London, UK), Postmark (transactional email), and Stripe (payments). Each processes data only to provide their part of the service. We do not sell personal data.
Email delivery and payment processing involve providers with operations in the United States; those transfers are covered by the providers' standard contractual safeguards for international data transfers. The platform's database and files themselves stay in the UK.
You have the right to access, correct, or erase your personal data, and to object to or restrict its processing. Training businesses can export a learner's full data or erase it directly from within the platform. Where erasure is requested for someone with an issued certificate, the certificate record is anonymised rather than deleted, so historical verification isn't broken.
Data is encrypted in transit (TLS) and at rest, passwords are hashed with bcrypt, and access is scoped so each business can only see its own data. Payment card details are handled entirely by Stripe.
For any privacy question or to exercise your rights, contact us at [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO).