Legal
Privacy Policy
Northlight Training respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, store and share personal information when you:
use our website;
book or attend training;
arrange training for other people;
request a quotation or make an enquiry;
use our learner or customer services;
receive marketing from us;
interact with our website analytics or advertising.
1. Who we are
Northlight Training is the controller responsible for the personal information described in this Privacy Policy.
Email: privacy@northlighttraining.co.uk
Website: northlighttraining.co.uk
If you have a question about this policy or how we use your personal information, please contact us using the email address above.
2. What information we collect
The information we collect depends on how you interact with Northlight Training.
Course bookings and learners
We may collect:
name;
email address;
telephone number;
date of birth where required for learner registration, assessment or certification;
organisation or employer;
course and session information;
booking reference;
learner reference;
attendance;
assessment results;
qualification and certification records;
certificate expiry and renewal information;
payment and transaction information;
correspondence relating to the booking or course.
If one person makes a booking for several learners, they may provide us with information about the other attendees.
On-site training enquiries and quotations
We may collect:
name;
organisation;
job title or role;
work email address;
telephone number;
training requirements;
proposed venue;
number of learners;
preferred dates;
information supplied during correspondence.
Contact enquiries
If you contact us, we may collect:
your name;
contact details;
the contents of your enquiry;
records of subsequent correspondence.
Payments
Card payments may be processed by third-party payment providers such as Stripe.
Northlight Training does not need to store your full card details.
We may retain transaction information such as:
amount;
payment status;
payment method;
booking reference;
payment or transaction reference;
date of transaction.
Website and technical information
When you use our website we may process information such as:
IP address;
browser and device information;
pages viewed;
interactions with the website;
referring website;
campaign information;
approximate location derived from technical data;
cookie preferences;
analytics events;
advertising attribution information.
Optional analytics and advertising technologies operate according to the choices you make through our cookie controls.
Accessibility, support and health-related information
If you tell us about an accessibility requirement, medical consideration or another individual need so that we can support you during training, that information may include special category personal data.
We only use this information where it is relevant and necessary to support participation, safety or another legitimate requirement.
We aim to keep this information only for as long as it is needed for that purpose.
3. How we use personal information
We may use personal information to:
process course bookings;
register learners;
deliver training;
administer attendance and assessment;
issue certificates;
manage qualification records;
communicate with learners and organisers;
manage course transfers, changes and cancellations;
provide booking-management services;
respond to enquiries;
prepare quotations;
manage customer relationships;
process payments;
maintain financial and transaction records;
identify renewal opportunities;
improve our courses and services;
maintain website security;
analyse website performance;
measure advertising and campaign effectiveness;
send marketing where permitted;
comply with legal, regulatory and contractual requirements;
establish, exercise or defend legal claims.
We will not use your information for an unrelated new purpose without considering whether further privacy information or consent is required.
4. Our lawful bases
We use different lawful bases depending on the purpose.
Contract
We may use personal information where necessary to:
take steps before entering into a contract;
process a booking;
provide training;
administer the booking;
provide related customer support.
Legal obligation
We may process information where necessary to comply with legal or regulatory obligations, including financial, tax, record-keeping and data protection requirements.
Legitimate interests
We may rely on legitimate interests for reasonable business purposes where those interests are not overridden by your rights and interests.
These may include:
operating and improving Northlight Training;
maintaining accurate customer and training records;
responding to business enquiries;
protecting our systems;
preventing fraud and misuse;
managing relationships with organisational customers;
measuring service performance;
maintaining appropriate records;
establishing or defending legal claims.
Consent
We rely on consent where required, including for:
optional analytics;
advertising and marketing technologies;
certain direct marketing communications;
uses of sensitive information where consent is the appropriate condition.
You can withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Safety Training Awards
Where you undertake a regulated qualification, we may share relevant learner information with Safety Training Awards.
This may include information required for:
learner registration;
assessment;
quality assurance;
certification;
qualification administration;
regulatory compliance.
Safety Training Awards may process this information as part of its role as an awarding organisation.
Safety Training Awards currently requires course organisers, tutors and assessors to retain specified first-aid course documentation and assessment evidence for the lifetime of the relevant qualification, including three years for First Aid at Work, Emergency First Aid at Work, Paediatric First Aid and Emergency Paediatric First Aid, and two years for CPR/AED qualifications.
6. Bookings made for other people
An organisation, employer or adult booking organiser may provide information about learners attending a course.
If you provide someone else’s information to Northlight Training, you should ensure that:
the information is accurate;
you have authority to provide it where required; and
the learner is made aware that their information will be used for training administration, assessment and certification.
We may contact learners directly where necessary to administer their training or qualification.
Northlight Training does not accept direct course bookings from people under 18.
Training involving someone under 18 must be arranged by an appropriate adult or organisation, such as:
a parent or guardian;
a school;
a sports club;
an employer;
another responsible organisation.
Where we process information about a young person, we aim to collect only what is reasonably necessary for:
training administration;
safety;
attendance;
assessment;
certification.
Where appropriate, information may be provided by or shared with the adult or organisation responsible for arranging the training.
UK GDPR transparency obligations still apply to children’s information, and privacy information should be presented in clear language appropriate to the audience.
We may send information about Northlight Training courses, services, upcoming dates and relevant training opportunities.
Where consent is required, we will ask you to make an active choice to receive marketing.
A course booking does not automatically mean that you have agreed to receive unrelated marketing.
You can unsubscribe at any time by:
using the unsubscribe option included in a marketing message; or
contacting privacy@northlighttraining.co.uk.
We may keep a suppression record so that we can remember that you have opted out.
For some business-to-business communications, the rules differ from consumer marketing, but individuals still have data protection rights and must be informed about the use of their personal data for marketing.
Our website uses necessary and optional technologies.
Necessary technologies
Necessary technologies are used for functions such as:
security;
storing cookie preferences;
operating essential website functionality.
These technologies do not depend on optional consent.
Analytics
If you consent to analytics, we may use services including:
Google Analytics;
Microsoft Clarity.
These services help us understand how visitors use the website, identify technical issues and improve content and performance.
Advertising
If you consent to marketing technologies, we may use services including:
Google Ads;
Meta Pixel.
These technologies may help us:
measure advertising effectiveness;
understand which campaigns result in bookings or enquiries;
measure conversions;
support advertising attribution;
build or measure advertising audiences where permitted.
Google Consent Mode
We use Google Consent Mode to communicate your choices to Google services.
Google services may operate in a consent-denied mode that does not use normal analytics or advertising storage but may send limited cookieless measurement signals for modelling.
Where you grant the relevant consent, Google services may use the corresponding cookies and storage.
Meta
The Meta Pixel is not loaded unless you consent to marketing technologies.
We may introduce Meta’s Conversions API in the future for selected events. If we do, we will review this policy and our data protection arrangements before implementation.
Microsoft Clarity
Microsoft Clarity is not loaded unless you consent to analytics technologies.
Changing your cookie preferences
You can change your cookie choices at any time using the cookie-settings control available on the website.
Rejecting optional cookies will not prevent you from browsing the site or booking a course.
We use service providers to operate Northlight Training.
These may include:
Framer
Used to host and operate our public website.
Fillout
Used for online forms and booking workflows.
Stripe
Used to process eligible card payments.
Airtable
Used for business administration, including booking, learner, organisation and training records.
Make
Used to automate approved workflows between Northlight systems.
Zite
Used for Northlight applications and services, including customer, learner, training or learning functionality where applicable.
Google services may include:
Google Tag Manager;
Google Analytics;
Google Ads.
Meta
Used for advertising and advertising measurement where appropriate consent has been given.
Microsoft Clarity
Used for website analytics where analytics consent has been given.
We may also use professional advisers, IT providers, communications providers and other suppliers where reasonably necessary to operate our business.
Sharing personal information
We do not sell personal information.
We may share information with:
Safety Training Awards;
trainers and assessors;
payment processors;
hosting and technology providers;
organisations that arrange training for their staff or members;
professional advisers;
regulatory bodies;
public authorities;
law-enforcement bodies where required by law.
Where an employer, school, club or other organisation arranges training, we may provide appropriate training information to that organisation, such as:
attendance;
completion;
qualification achieved;
certificate information;
expiry information.
We would not normally disclose unrelated personal information to an organiser.
Some suppliers may process personal information outside the United Kingdom.
Where data protection law requires safeguards, we will use an appropriate transfer mechanism, such as:
UK adequacy regulations;
contractual safeguards;
the UK International Data Transfer Agreement;
the UK Addendum;
another lawful transfer mechanism.
The mechanism used depends on the provider and destination.
We do not keep personal information for longer than necessary.
Our current retention approach is:
First Aid at Work, Emergency First Aid at Work and Paediatric course documentation / assessment evidence
3 years
CPR/AED course documentation / assessment evidence
2 years
Fire Marshal course documentation
3 years
Certificate and qualification records
For the relevant qualification period and any required verification period
Booking and financial transaction records
6 years
Customer correspondence forming part of a booking or contractual record
Up to 6 years
Enquiries that do not result in a booking
Up to 24 months
Quotations that do not proceed
Up to 24 months
Marketing records
While relevant, with suppression records retained where needed to respect opt-outs
Cookie consent preference
180 days
GA4 analytics data
Normally up to 14 months where configurable
Accessibility or health-related support information
Deleted as soon as reasonably possible after the course unless there is a clear reason to retain it
Safety Training Awards’ current published requirements support the qualification-specific retention periods above.
We may retain information for longer where required by law, an awarding body, a dispute, a complaint or the need to establish or defend legal claims.
UK GDPR requires organisations to tell people how long their personal data will be retained, or explain the criteria used where a fixed period is not possible.
We use appropriate technical and organisational measures to protect personal information.
These may include:
authentication and access controls;
restricted administrative access;
secure cloud services;
data minimisation;
appropriate supplier controls;
confidentiality requirements;
backups and resilience measures.
No internet-based system can be guaranteed to be completely secure, but we take reasonable measures appropriate to the nature and risk of the information we process.
Your Rights
Depending on the circumstances, you may have rights including:
access to your personal information;
correction of inaccurate information;
deletion in certain circumstances;
restriction of processing;
data portability in certain circumstances;
objection to certain processing;
withdrawal of consent;
rights relating to certain automated decision-making.
Not every right applies in every situation.
To exercise your rights, contact:
privacy@northlighttraining.co.uk
We may need to verify your identity before responding.
The ICO expects privacy information to explain the purposes of processing, lawful bases, recipients, retention periods, individual rights and other key transparency information.
Northlight Training does not currently make decisions about individuals that are based solely on automated processing and that produce legal or similarly significant effects.
If this changes, we will update this Privacy Policy.
If you are concerned about how we have handled your personal information, please contact us first at:
privacy@northlighttraining.co.uk
You also have the right to complain to the Information Commissioner’s Office (ICO).
The ICO is the UK’s data protection regulator.
We may update this Privacy Policy when:
our services change;
our suppliers change;
our systems change;
our legal or regulatory obligations change.
We will publish the current version on this page and update the date at the top.
Where a change materially affects how we use personal information, we will take reasonable steps to make affected individuals aware of it.