Data Protection / GDPR
Data Controller: HandyCPD Ltd
Date of Issue: February 2026
Review Date: February 2027
Data controller
HandyCPD is operated by HandyCPD Ltd, a company registered in England and Wales.
- Company number: 17211826
- ICO registration number: ZC151160
- Registered office: 61 Bridge Street, Kington, HR5 3DJ, United Kingdom
- Privacy contact: privacy@handycpd.com
1. Introduction & Scope
HandyCPD is committed to protecting the privacy of our users. This policy outlines how HandyCPD Ltd approaches data protection obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all personal data processed by HandyCPD, including account information, professional logs, and metadata.
2. The Data Protection Principles
We process all data in accordance with the seven core principles of GDPR:
- Lawfulness, Fairness, and Transparency: We only process data on a valid legal basis and are clear with users about our methods.
- Purpose Limitation: Data is used strictly for CPD tracking and professional reflection.
- Data Minimisation: We collect the account, professional CPD, billing, support, and operational data needed to provide and secure the service.
- Accuracy: Users can edit or delete their records at any time to ensure accuracy.
- Storage Limitation: If your account shows no meaningful activity for approximately 90 days, we may schedule deletion from the active service with approximately 60 days' notice and email reminders at approximately 30 days, 7 days, and 24 hours before the scheduled date. Meaningful activity includes signing in, filing CPD records, updating settings, or exporting data. Active paid Pro subscriptions are excluded from automatic inactivity deletion while the subscription remains active. Operator accounts are excluded from automatic inactivity deletion. When deletion completes, data is removed from the active service; limited operational records may be retained in minimised or anonymised form where required for legal, security, billing, audit, or system integrity purposes. Users can also request erasure through the app or support at any time.
- Integrity and Confidentiality: We use Supabase Auth, secure API access controls, TLS in transit, and provider-managed database/storage security controls.
- Accountability: We maintain records of processing and our ICO registration (registration number ZC151160).
3. Lawful Bases for Processing
HandyCPD relies on the following legal grounds for processing:
- Contractual Necessity (Art 6.1.b): To manage your subscription and provide the SaaS tools.
- Consent (Art 6.1.a): For optional marketing emails, non-essential cookies, and optional aggregated CPD theme insights (when you explicitly enable them in onboarding or Settings).
- Legitimate Interests (Art 6.1.f): Specifically "Recognised Legitimate Interests" under the 2025 Act for platform security, fraud prevention, and crime detection.
4. Technical and Organisational Measures (TOMs)
We mitigate risk by utilising high-security, third-party infrastructure and controlled administrative access:
- Authentication: Via Supabase Auth, including email one-time codes and supported OAuth providers such as Google and Microsoft. HandyCPD does not store or see third-party account passwords.
- Hosting & Storage: Hosted using Vercel for the frontend, Railway for the backend/API, and Supabase for authentication, Postgres database, and file storage.
- AI Privacy: Google Gemini is used for reflection generation, extraction, image description, standards support, and optional aggregated theme classification when enabled. Users should not submit unauthorised or sensitive content.
- Access Control: Administrative access to backend systems is restricted to authorised personnel and protected by Multi-Factor Authentication (MFA).
4.1 Optional aggregated CPD theme insights
Separately from essential CPD and reflection features, you may choose to contribute optional aggregated CPD theme insights. If you enable this in onboarding or Settings, HandyCPD may use AI to classify finalised CPD records into broad, non-identifying categories (for example learning themes, activity types and reflective challenges) to understand common professional development patterns and improve the service.
This processing is optional. It is not required to create, edit, finalise or export your CPD records. We do not store your raw CPD text in this insights dataset. Insights are intended for aggregate product and operational understanding, not for reviewing individual reflections. You can turn contribution off at any time to stop future contribution. Turning it off does not automatically delete categories already contributed; account erasure removes associated insight data as part of account deletion where implemented. This is separate from consent-based website/product behavioural analytics (such as PostHog or GA4) and from essential AI processing that supports drafting and structuring your records. You should still avoid uploading unnecessary patient/client-identifiable, confidential or special-category data in CPD content.
5. Data Subject Rights & Procedures
We provide routes for users to raise data rights requests under UK law:
5.1 Subject Access Requests (SARs)
- Response Time: 30 days.
- "Stop-the-Clock" Provision: Under the 2025 Act, if we require clarification from a user to fulfil a complex SAR, the 30-day deadline is paused until that clarification is received.
- Proportionate Search: We are only required to conduct "reasonable and proportionate" searches for data.
5.2 The Right to be Forgotten (Erasure)
- Users can trigger account erasure from their dashboard.
- Account erasure removes live CPD records and owned files where possible and deletes or anonymises personal data we no longer need. Some limited operational, billing, support, security, processor, or backup records may be retained or minimised where required.
- If an account is banned for a policy violation, access and download arrangements may be restricted where necessary for safety, legal, or abuse-prevention reasons.
5.3 Mandatory Complaints Handling (Effective June 2026)
As required by the DUAA 2025, users have a right to complain directly to the controller.
- Contact: privacy@handycpd.com
- Process: We will acknowledge any data complaint within 30 days and aim to resolve the issue "without undue delay."
6. International Data Transfers
While HandyCPD is UK-based, some providers may process data outside the UK depending on their configuration and service terms. Final provider and transfer wording should be confirmed during iubenda/legal setup and may include:
- Provider safeguards: Data processing agreements, regional settings, and transfer mechanisms offered by Supabase, Vercel, Railway, Stripe, Google, PDFShift, Resend, and Sentry where applicable.
- Final review: International transfer wording should be checked against the production provider configuration before launch.
7. Data Breach Response Plan
In the event of a breach:
- Detection: We use application, hosting, database, and privacy-safe error monitoring information to investigate security and reliability issues.
- Notification: If a breach presents a risk to users, we will notify the ICO within 72 hours.
- Communication: Affected users will be emailed directly with advice on how to protect their accounts where appropriate.