Privacy Policy
23 June 2026
23 June 2026
United Kingdom
UK GDPR · Data Protection Act 2018 · PECR
1. Who We Are
CrownEthics ('we', 'us', 'our') provides professional standards training for UK-registered healthcare professionals. Our courses cover ethics, probity and honesty, professionalism, fitness to practise, and professional boundaries.
As the data controller for personal data processed through our website and services, we are responsible for ensuring your data is handled lawfully, fairly, and transparently under UK GDPR and the Data Protection Act 2018.
| Trading name | CrownEthics |
| Website | crownethics.com |
| Contact email | info@crownethics.com |
| Role | Data Controller |
2. What Personal Data We Collect
2.1 Account and registration data
- Full name
- Email address
- Username and password (stored in encrypted form — never in plain text)
- Date of account creation
2.2 Purchase and billing data
- Billing name and address
- Order history and purchase records
- Invoice records
2.3 Course and learning data
- Courses enrolled in and purchased
- Lesson and topic completion status
- Quiz attempt records and scores
- Final assessment results
- Certificates of completion issued
- Date and time of course activity
2.4 Communications data
- Messages sent via our contact form or by email
- Email marketing preferences and consent records
- Support enquiries and our responses
2.5 Technical and usage data
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time on page
- Referring website
- Cookie identifiers (see Section 9)
2.6 Data we do not collect
We do not collect or process special category data as defined in Article 9 of the UK GDPR — including health data, religious beliefs, racial or ethnic origin, or criminal record information. Our courses discuss healthcare regulation and professional standards in general terms. We do not ask you to share details of any specific concern, complaint, or investigation you may be facing.
3. How We Collect Your Data
- Directly from you when you register an account, purchase a course, submit a contact form, or email us
- Automatically when you use our website, through cookies and server logs
- From our payment provider who confirms successful payment transactions
- From our platform tools — WooCommerce processes purchases, LearnDash records course progress
4. How We Use Your Personal Data
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and manage your account | Name, email, password | Contract |
| Process your course purchase | Purchase data, billing address | Contract |
| Deliver your course and issue certificates | Learning data, assessment results | Contract |
| Send purchase confirmation and course emails | Name, email | Contract |
| Respond to enquiries and support requests | Communications data | Contract / Legitimate interests |
| Send marketing emails about new courses | Email, marketing preferences | Consent |
| Maintain financial and tax records | Purchase data, billing address, invoices | Legal obligation |
| Improve our courses and website | Technical and usage data (anonymised) | Legitimate interests |
| Prevent fraud and ensure website security | IP address, technical data | Legitimate interests |
5. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share it only with the following trusted third parties, for the specific purposes described, and only to the extent necessary.
5.1 Payment processors
We use a third-party payment provider (such as Stripe or Airwallex) to process course payments. Your payment card data is transmitted directly to and processed by the payment provider. We receive only a payment confirmation and transaction reference. These providers are PCI-DSS compliant and operate under their own privacy policies.
5.2 Website and course platform
Our website runs on WordPress, with WooCommerce handling purchases and LearnDash handling course delivery. Your account, purchase, and learning data is stored on our web hosting infrastructure. These platforms process your data only to deliver the service we have contracted to provide.
5.3 Email service providers
We use an email service provider to send transactional emails (purchase confirmation, enrolment, certificate delivery) and, where you have consented, marketing emails. These providers process your name and email address only for the purpose of sending these communications.
5.4 Analytics tools
We may use analytics tools (such as Google Analytics) to understand how our website is used. These tools process technical and usage data. We configure analytics tools to anonymise IP addresses and do not enable features that permit cross-site tracking without your consent.
5.5 Legal and regulatory disclosure
We may disclose your personal data to law enforcement, regulatory authorities, or legal advisers if we are required to do so by law, or if disclosure is necessary to protect the rights, property, or safety of CrownEthics, our users, or others.
5.6 Business transfers
If CrownEthics is acquired, merged, or its assets are transferred to another entity, your personal data may form part of that transfer. We will notify you before any such transfer and explain its implications for your data.
6. International Data Transfers
Some of our third-party service providers are based outside the United Kingdom or process data on servers located outside the UK. Where we transfer your personal data outside the UK, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V, including:
- Transfers to countries with UK adequacy decisions
- International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses
- Binding Corporate Rules, where applicable
You may request details of the safeguards we rely on for any specific transfer by contacting us at info@crownethics.com.
7. How Long We Keep Your Data
| Data type | Retention period | Reason |
|---|---|---|
| Account data | Duration of account + 2 years | Service delivery and support |
| Purchase and billing records | 7 years from transaction date | HMRC legal requirement |
| Course and learning data | Duration of account | Certificate access and portfolio use |
| Marketing consent records | Until consent withdrawn + 2 years | PECR compliance audit trail |
| Technical and usage data | Up to 26 months | Analytics and security |
| Support communications | 2 years from last contact | Legitimate interests |
Where we are legally required to retain data (such as financial records for HMRC purposes), we cannot delete it earlier even on request. In all other cases, we will delete or anonymise your data at the end of the applicable retention period.
8. Your Rights Under UK GDPR
Under UK GDPR and the Data Protection Act 2018, you have the following rights. These may be subject to certain legal exemptions and conditions.
Right of access
Request a copy of the personal data we hold about you and how we use it (a Subject Access Request). We will respond within one month.
Right to rectification
Ask us to correct inaccurate or incomplete personal data we hold about you.
Right to erasure
Ask us to delete your data where we no longer need it or where you withdraw consent. This does not apply where we have a legal obligation to retain it.
Right to restrict processing
Ask us to restrict how we use your data in certain circumstances — for example, while we investigate an accuracy dispute.
Right to data portability
Where we process your data by automated means on the basis of consent or contract, receive it in a structured, machine-readable format.
Right to object
Object to processing based on our legitimate interests. You have an absolute right to object to processing for direct marketing purposes.
Right to withdraw consent
Where processing relies on your consent (such as marketing emails), withdraw it at any time. This does not affect previous lawful processing.
No automated decisions
We do not use your data for automated decision-making or profiling that produces significant legal effects.
9. Cookies and Similar Technologies
Our website uses cookies — small text files placed on your device — to make the site work and to improve your experience. Under the Privacy and Electronic Communications Regulations (PECR), we must obtain your consent before placing non-essential cookies.
9.1 Essential cookies (no consent required)
- Session cookies that keep you logged in during a visit
- Shopping cart and checkout cookies (WooCommerce)
- Security and fraud prevention cookies
- Your cookie consent preference record
9.2 Analytics cookies (consent required)
- Analytics tools to understand how our website is used — only activated where you have given consent through our cookie banner. IP addresses are anonymised.
9.3 Managing cookies
You can manage your cookie preferences at any time through our cookie consent tool on the website, or through your browser settings. Blocking essential cookies may affect the functionality of the site. For more information about managing cookies, visit allaboutcookies.org.
10. How We Protect Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:
- SSL/TLS encryption for all data transmitted between your browser and our website
- Encrypted password storage — passwords are never stored in plain text
- Strict access controls — only authorised personnel can access personal data
- Regular software updates and security patches
- Payment data handled exclusively by PCI-DSS certified payment providers
No method of transmission over the internet is completely secure. While we take every reasonable precaution, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at info@crownethics.com.
11. Children's Privacy
Our services are intended for UK-registered healthcare professionals and other adult professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us at info@crownethics.com and we will delete it promptly.
12. Third-Party Links
Our website may contain links to external websites — including your regulator, defence organisations, or professional bodies. This privacy policy applies only to CrownEthics. We are not responsible for the privacy practices of any external site and encourage you to read the privacy policy of any site you visit.
13. Marketing Communications
We will only send you marketing emails if you have explicitly opted in to receive them. You can unsubscribe at any time by clicking the unsubscribe link in any marketing email, or by emailing info@crownethics.com.
We may send you service emails related to your account and purchases without requiring separate marketing consent — for example, purchase confirmation, course enrolment notification, and certificate delivery. These are necessary to fulfil your contract with us.
14. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, our services, or applicable law. When we make material changes, we will notify you by email and/or by a prominent notice on our website. The 'Last reviewed' date at the top of this policy shows when it was last updated.
Your continued use of our website and services after any change constitutes acceptance of the updated policy.
15. How to Complain
We take data protection seriously and aim to resolve any concerns promptly. If you have a complaint about how we have handled your personal data, please contact us first at info@crownethics.com.
If you are not satisfied with our response, or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
| ICO website | ico.org.uk |
| ICO helpline | 0303 123 1113 |
| ICO address | Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
16. Contact Us
For any questions, requests, or concerns about this privacy policy or how we handle your personal data, please get in touch.
Email: info@crownethics.com
Website: crownethics.com
We aim to respond to all data protection enquiries within one calendar month of receipt.
Legal notice: This privacy policy is intended to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). CrownEthics recommends seeking independent legal advice to confirm full compliance with applicable data protection law. This policy does not constitute legal advice.

