Privacy Policy
Last updated: 6 July 2026
1. Who we are
HourlyCPD Ltd ("we", "us", "our"), registered in Scotland (Company No. to be confirmed), operates the HourlyCPD service available at hourlycpd.com. We are the data controller for personal data processed through this service.
Registered address: available on request (contact [email protected])
ICO registration number: to be confirmed
Contact us about data protection at: [email protected]
2. What data we collect
- Account data: name, email address, password (bcrypt-hashed — we never store your plaintext password), and optional marketing consent flag provided when you register.
- CPD records: activity titles, dates, hours, categories, reflections, and any notes you enter about your continuing professional development.
- Membership data: professional body names, membership numbers, renewal dates, and CPD requirements you configure.
- Supervision data: session logs, supervisor names, hours, and notes.
- Uploaded files: certificates and other evidence documents you attach to CPD entries. Files are stored encrypted at rest.
- Payment data: subscription tier, status, and billing period. Card details are processed exclusively by Stripe and are never stored on our servers.
- Usage data: server logs including IP address, browser type, and pages visited, retained for up to 30 days for security and debugging purposes. For logged-out visitors to hourlycpd.com, we may use a country-level inference derived from your IP address (provided by our content delivery network) solely to display a notice suggesting a regional version of the service; this inference is not stored on our servers and is not linked to your identity.
3. Legal basis for processing
- Contract performance (Article 6(1)(b) UK GDPR): processing your account and CPD data to provide the service you have signed up for.
- Legitimate interests (Article 6(1)(f) UK GDPR): security monitoring, fraud prevention, and service improvement. We have assessed that these interests are not overridden by your rights.
- Consent (Article 6(1)(a) UK GDPR): sending marketing emails, where you have opted in at registration or in your account settings. You can withdraw consent at any time by updating your notification preferences or emailing us.
- Legal obligation (Article 6(1)(c) UK GDPR): retaining billing records for HMRC purposes (up to 7 years).
4. How we use your data
- To create and manage your account
- To provide the CPD tracking, supervision log, and renewal reminder features
- To generate audit PDF exports on your request
- To process subscription payments via Stripe
- To send transactional emails (magic links, password resets, renewal reminders)
- To send marketing emails, only if you have explicitly opted in
- To investigate security incidents and prevent abuse
5. Data sharing and international transfers
We do not sell your personal data. We share data only with the following sub-processors:
- Stripe (USA) — payment processing. Data transfers are covered by Stripe's UK GDPR-compliant Data Processing Agreement and Standard Contractual Clauses. See stripe.com/privacy.
- Resend (USA) — transactional and marketing email delivery. Data transfers are covered by Standard Contractual Clauses. Only your email address and the content of emails we send you are shared.
- Mistral AI (France, EU) — AI processing for the optional AI-assisted features (for example, suggesting a category for a CPD activity, extracting details from an evidence file you upload, or reading an email and its attachments that you forward to your personal logging address in order to pre-fill a draft entry for your review). Only the text, file or forwarded email content submitted for that request is sent, in order to generate the response; we have disabled the use of this data for model training. Processing takes place in the EU, so no UK adequacy transfer issue arises.
- Hetzner (EU) — cloud hosting and object storage. Your data is stored in EU data centres subject to GDPR. No UK adequacy transfer issue arises.
- Cloudflare (USA) — content delivery network and DDoS protection, through which all hourlycpd.com traffic passes. Cloudflare attaches the country-level inference described in section 2 to incoming requests. We also use Cloudflare R2 object storage, configured under EU jurisdiction, to hold encrypted copies of our database backups (see section 9). Data transfers are covered by Cloudflare's Data Processing Agreement and Standard Contractual Clauses.
All sub-processors are bound by data processing agreements meeting UK GDPR requirements. We do not transfer your data to any country without an adequate level of protection or without appropriate safeguards in place.
6. Data retention
- Account and CPD data: retained while your account is active.
- After account deletion: all personal data is permanently and irreversibly deleted within 30 days, except billing records which are retained for up to 7 years to meet our legal obligations under UK tax law.
- Server logs: retained for up to 30 days then automatically purged.
- Uploaded evidence files: deleted from storage within 30 days of account deletion.
- Transactional email history: retained for 12 months then automatically deleted.
- Application error logs: retained for 6 months then automatically deleted.
- Usage and campaign-attribution events: retained for 24 months then automatically deleted.
- Security tokens (email verification, sign-in links, password resets): deleted automatically once expired, checked daily.
- Abandoned CPD import previews: deleted 90 days after the import was started if it was never completed.
7. Your rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — ask us to pause processing of your data
- Portability — receive your data in a structured, machine-readable format (available via Settings → Data → Export)
- Object — to processing based on legitimate interests
- Withdraw consent — for marketing emails at any time
You can exercise your right to portability directly from your account settings. For all other requests, email us at [email protected]. We will respond within one calendar month as required by UK GDPR Article 12.
8. Cookies
We use a single session cookie to keep you signed in. We also set one functional cookie named hcpd_banner_dismissed that records whether you have dismissed our notice suggesting a regional version of the service. This cookie contains no personal data, is not shared with any third party, and expires after 30 days. We do not use advertising cookies, third-party tracking, or analytics cookies. No third-party scripts are loaded on the platform that would place cookies on your device without your knowledge.
On your first visit we store the campaign parameters from the link you arrived on (such as utm tags, a referral code, and the landing page) in your browser's sessionStorage, which your browser clears when you close the tab. If you go on to sign up, we record those details against your account so we can understand which of our own posts and campaigns work. This information is not shared with any third party.
9. Security
- All data is encrypted in transit using TLS 1.2 or higher.
- Evidence files are encrypted at rest (AES-256) on Hetzner Object Storage. Database data is stored within the EU on Hetzner infrastructure subject to UK GDPR.
- Passwords are hashed using bcrypt before storage — we cannot retrieve your password.
- We apply the principle of least privilege: each system component accesses only the data it needs.
- Database backups are taken nightly and retained on a rolling schedule for up to 18 months. Backup copies are stored in the EU — on Hetzner infrastructure and in Cloudflare R2 object storage configured under EU jurisdiction — and are encrypted at rest.
10. Data breach notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
11. Complaints
If you are unhappy with how we handle your personal data, please contact us first at [email protected]. If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
12. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes by email at least 30 days before they take effect. The date at the top of this page shows when it was last revised.
13. Governing law and jurisdiction
HourlyCPD Ltd is incorporated and registered in Scotland. This privacy policy and any disputes arising from it are governed by the laws of Scotland. Any dispute that cannot be resolved informally will be subject to the exclusive jurisdiction of the Scottish courts.
UK GDPR and the Data Protection Act 2018 apply across the United Kingdom. Our supervisory authority is the Information Commissioner's Office (ICO), which covers England, Wales, Scotland, and Northern Ireland. If you are based in Scotland and prefer to raise a concern with a Scottish body, you may also contact the ICO Scotland office directly.