Privacy Policy

In Plain English (Summary)

At Rapid Focus Medical Education Limited, we take your privacy seriously. We only collect the minimal personal information needed to deliver high-quality medical education courses, manage your learner account, process purchases securely, and issue course completion certificates. We never sell or rent your personal data to third parties.

1. Who We Are

This Privacy Policy explains how Rapid Focus Medical Education ("we", "us", or "our") collects, stores, uses, and protects your personal information when you visit our website, register for an account, or purchase our educational materials and revision resources.

Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, Rapid Focus Medical Education is the Data Controller responsible for your personal information.

2. What Personal Information We Collect

We collect information only when necessary to provide you with our educational services:

  • Identity and Contact Details: Name, professional title, email address, phone number, medical grade/stage of training (e.g., Core Trainee, Specialty Registrar, Consultant), specialty, and hospital/trust/institution.

  • Account and Learning Progress Data: Login details, course enrolments, quiz scores, mock examination answers, completion dates, and Continuing Professional Development (CPD) / completion certificates.

  • Payment & Transaction Details: Billing address, order history, transaction timestamps, and invoice records.

    (Note: We use secure, accredited third-party payment gateways such as Stripe or PayPal. We never store or have access to your full credit or debit card numbers).

  • Technical and Browsing Data: IP address, browser type, device information, operating system, and pages visited on our site to ensure platform security and optimize your experience.

  • Communication Data: Feedback forms, survey responses, course evaluations, and emails sent to our support desk.

3. Why We Collect Your Information & Our Legal Bases

Under UK GDPR (Article 6), we must have a lawful reason to collect and use your data. We rely on the following bases:

  1. Performance of a Contract: To create your learner profile, provide course access, issue certificates, process transactions, and deliver our services.

  2. Legitimate Interests: To maintain website security, prevent fraudulent use, improve our educational curriculum, and assist with learner support queries.

  3. Legal Obligation: To comply with statutory requirements, such as maintaining tax and accounting records for HMRC.

  4. Consent: To send you optional revision updates, newsletters, or use non-essential website analytics cookies. You can withdraw your consent at any time.

4. How We Use Your Information

We use your information to:

  • Grant you immediate access to revision modules, question banks, and learning resources.

  • Track individual learning progress, exam revision statistics, and issue verifiable certificates.

  • Process payments and generate VAT/tax receipts and invoices.

  • Provide technical assistance and respond to customer support enquiries.

  • Analyse aggregated, anonymous learner feedback to refine syllabus questions and improve clinical accuracy.

  • Send administrative notices (e.g., maintenance alerts, password resets, syllabus updates).

5. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers who assist us in operating our platform, under strict data protection agreements:

  • Payment Providers: Secure gateways (e.g., Stripe, PayPal) to process payments under PCI-DSS standards.

  • Website Hosting & Cloud Infrastructure: Secure cloud servers and database hosts that power our learning management system.

  • Email & Communication Tools: Software platforms used to send transactional emails, enrolment links, and course access credentials.

  • Professional & Legal Advisors: Accountants, auditors, or legal representatives where strictly required by law.

All our service providers are obligated to handle your information securely and strictly in accordance with data protection regulations.

6. International Data Transfers

Where third-party service providers host data outside the United Kingdom or European Economic Area (EEA), we ensure adequate safeguards are in place (such as the UK International Data Transfer Addendum or approved Standard Contractual Clauses) to guarantee your data receives the same level of legal protection.

7. How Long We Keep Your Data

We retain your data only for as long as necessary:

  • Learner & Revision Accounts: Kept for the duration of your active subscription, plus up to 3 years following inactivity to allow re-enrolment and historical verification of course certificates.

  • Billing & Financial Records: Kept for 6 years following the end of the relevant financial year to comply with UK statutory HMRC accounting laws.

  • General Enquiries & Support Messages: Kept for up to 2 years following resolution.

When records are no longer required, they are permanently and securely deleted or fully anonymised.

8. How We Keep Your Data Secure

We have implemented robust technical and organizational measures to safeguard your personal information, including:

  • Full SSL/TLS encryption across our entire website (HTTPS).

  • Role-based access controls ensuring only authorized staff access personal data.

  • Regular security patches, encrypted cloud storage, and secure automated backups.

9. Your Legal Rights Under UK GDPR

You hold the following rights regarding your personal information:

  • Right of Access (Subject Access Request): You can ask for a copy of the personal data we hold about you.

  • Right to Rectification: You can ask us to correct inaccurate or incomplete information.

  • Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal data when there is no longer a lawful reason for us to keep it.

  • Right to Restrict Processing: You can request that we temporarily pause the processing of your data.

  • Right to Data Portability: You can request a machine-readable copy of your personal data to transfer elsewhere.

  • Right to Object: You can object to processing based on legitimate interests or direct marketing.

  • Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time without penalty.

To exercise any of these rights, email us at [Insert Contact Email]. We will respond within one calendar month, free of charge.

10. Cookies & Tracking

Our website uses cookies (small text files stored on your device) to:

  • Essential Cookies: Enable secure log-ins, track session state, and maintain checkout baskets.

  • Analytics Cookies (Optional): Help us understand aggregate visitor numbers and navigation trends so we can improve site performance.

You can adjust your cookie settings at any time via your browser preferences or through our website's cookie banner.

11. External Links

Our revision resources or website may occasionally provide links to clinical guidelines, research papers, or professional surgical bodies (e.g., JCST, Royal Colleges, GMC). We do not control these third-party websites and encourage you to review their respective privacy notices.

12. Changes to This Privacy Policy

We may periodically update this policy to reflect changes in our services or legal obligations. Any updates will be posted on this page with a revised "Last Updated" date.

13. Contact Us & Complaints

If you have any questions about this Privacy Policy or wish to make a data request, please contact us:

  • Email: info@rapidfocuscourses.com

If you are unsatisfied with how we handle your request, you have the right to lodge a complaint with the UK's supervisory body:

  • Information Commissioner's Office (ICO)

    • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

    • Helpline: 0303 123 1113

    • Website: ico.org.uk