Privacy Policy – SIRPA Ltd
SIRPA Ltd is committed to protecting your privacy and handling personal data responsibly and transparently. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our website, training school, and related services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who We Are
SIRPA Ltd is the data controller for the personal data processed through our website, training school, and associated communications.
If you have any questions about this policy or how your data is used, please contact us using the details at the end of this policy.
Information We Collect
Website Usage Information
When you visit our website (including www.sirpa.org and related domains), we may automatically collect information such as:
- Date and time of visits
- Pages viewed and time spent on the site
- Referring and exit websites
- IP address
- Responses to quizzes or surveys
This information helps us understand how our website is used and how we can improve it.
Information You Provide Voluntarily
We may collect personal information when you:
- Contact us by email
- Register on our website or training school
- Complete forms
- Sign up to receive communications
- Purchase products or services
This information may include your name, email address, and other details relevant to your enquiry or registration.
Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance user experience and analyse site usage. Cookies are small text files stored on your device that help us understand how visitors interact with our site.
We use the following types of cookies:
- Essential / functional cookies — these are necessary for the website to function and cannot be switched off. They support core functions such as the shopping basket and maintaining your session while you browse the site.
We do not currently use analytics or marketing cookies, and no non-essential cookies or tracking technologies (such as Google Analytics or the Facebook Pixel) are placed on your device. Should this change in future, we will update this policy and put appropriate consent mechanisms in place before any non-essential cookies are used.
How We Use Your Information
We use personal information to:
- Administer our website and training services
- Provide customer support and respond to enquiries
- Deliver training and educational services
- Improve our services and learning experience
- Communicate relevant information, where consent has been given
- Meet legal and regulatory obligations
We do not sell, rent, or trade personal data to third parties.
Lawful Basis for Processing (UK GDPR)
Under UK GDPR, we process personal data on the following lawful bases, depending on the circumstances:
- Consent – where you have given clear permission
- Contract – where processing is necessary to deliver services you have requested
- Legal obligation – where required by law
- Legitimate interests – where processing is necessary for the effective operation of our organisation and does not override your rights
Where special category data (such as health-related information) is processed, this is done in accordance with Article 9 UK GDPR, with appropriate safeguards in place.
Marketing Communications
We may contact you from time to time with information about our products, services and events that we think may be of interest to you.
Where you have given us your consent to do so — for example by ticking a box on one of our sign-up forms — we will use your contact details to send you marketing communications. We use a double opt-in process, meaning you will receive a confirmation email and will need to click a link to confirm your subscription before being added to our mailing list. You can withdraw your consent at any time by clicking the unsubscribe link in any of our emails or by contacting us at admin@sirpa.org.
Where you are an existing customer, we may also send you marketing communications about similar products and services where we have a legitimate interest in doing so. We will always give you a clear opportunity to opt out, and you can unsubscribe at any time using the link in any of our emails or by contacting us at admin@sirpa.org.
Separately, we may send you operational communications relating to a purchase, membership, or training course you have signed up for — for example order confirmations, delivery updates, or CPD records. These are necessary to deliver the service you have requested and are sent on the basis of contract or our legitimate interest in administering our services, rather than marketing consent, and are not affected by your marketing preferences.
We will never sell your personal data to third parties or share it for their marketing purposes.
Training School Data
If you register for the SIRPA Training School, your information will be used to:
- Manage your registration and access
- Support your learning experience
- Improve training content based on feedback
Training-related data is not sold or shared with unaffiliated third parties without your consent, unless required by law.
Data Sharing and Legal Disclosure
We may disclose personal information if required to do so by law, regulation, safeguarding obligations, or to protect our legal rights.
Third-Party Data Processors
We use a number of trusted third-party services to help us deliver our website, training school, and communications. These providers process personal data on our behalf and are required to handle it in accordance with UK GDPR. Our key processors include:
- MailerLite — email marketing platform. Used to send newsletters and marketing communications, and to manage subscriber lists and consent records (including sign-up date, IP address, and opt-in confirmation). Personal data is also passed to MailerLite from WooCommerce to facilitate the delivery of purchases/orders to the customer.
- WordPress.com (Automattic) / WooCommerce — website hosting, our online shop, the practitioner directory, and contact forms
- Zenler — online course hosting, enrolments, and CPD records
- Stripe — payment processing for course fees and membership payments
- PayPal — PayPal — payment processing. PayPal acts as an independent data controller (not a processor) for data it handles in connection with your payment. For details of how PayPal processes your data, see PayPal’s Privacy Statement at www.paypal.com.
- Microsoft (Outlook / OneDrive) — email correspondence and internal document/file storage
- Zapier — automation tool used to transfer relevant data between Zenler and MailerLite, for example to add course or membership participants to the appropriate email list
Where any of these processors store or transfer data outside the UK, appropriate safeguards are in place in accordance with UK GDPR requirements. Data processing agreements are held on file for each processor and are reviewed periodically as part of our data protection register.
Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, professional, and insurance requirements. When data is no longer required, it is securely deleted or destroyed.
Retention periods vary depending on the type of data and the purpose for which it is held. As a general guide:
- Marketing communications — your contact details are retained until you unsubscribe or ask us to stop contacting you.
- Training, CPD, and membership records — retained for the duration of your membership or training relationship with SIRPA, and for 6 years afterwards, to meet our professional, insurance, and regulatory obligations.
- Purchase and order records — retained for 6 years, in line with our obligations under UK tax and accounting law.
- Website enquiries and general correspondence — retained for up to 12 months, unless a longer period is needed to respond to or resolve your enquiry.
- Data protection complaints — retained for 3 years from the date a complaint is closed, in line with our Data Protection Complaints Procedure.
Where data is processed by a third-party provider on our behalf, that provider’s own retention rules may also apply — for example, our automation tool Zapier automatically deletes its own processing logs after a maximum of 69 days, separately from how long we retain your data in our own systems.
If you would like more detail on how long a specific category of your data is retained, you can contact us using the details below.
Data Security
We take appropriate technical and organisational measures to protect personal data, including:
- Secure systems and access controls
- Password protection and restricted access
- Secure transmission methods (such as SSL)
While we take reasonable steps to protect information, email is not considered a fully secure method of communication. Please avoid sending sensitive information by email where possible.
Data Breaches
In the event of a personal data breach, we will assess the risk and take appropriate action in line with UK GDPR requirements, including notification to the Information Commissioner’s Office (ICO) and affected individuals where required.
We have a formal data protection complaints procedure in place. If you wish to raise a complaint about how your personal data has been handled, please contact us at admin@sirpa.org and we will respond within 30 days.
Your Rights Under GDPR
You have the right to:
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request erasure of your data, where applicable
- Restrict or object to processing in certain circumstances
- Request data portability, where applicable
- Lodge a complaint with the Information Commissioner’s Office (ICO)
Requests can be made using the contact details below.
External Links
Our website may contain links to external websites. We are not responsible for the content or privacy practices of those sites and encourage you to review their privacy policies.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page. We will not use your personal information in a way that is materially inconsistent with this policy without your consent.
Contact Us
If you have any questions about this Privacy Policy or how your personal data is handled, please contact:
SIRPA Ltd – admin@sirpa.org
You also have the right to contact the Information Commissioner’s Office: www.ico.org.uk
SIRPA Ltd
Company no. 08353000
VAT no. 501 2505 53
Yorkshire, UK