Introduction
This Privacy Policy explains how nimble-finch collects, uses, stores and protects personal information provided by users of our website and learning platform. We are committed to ensuring your privacy is protected in accordance with applicable data protection legislation.
Information We Collect
We collect and process the following categories of personal information:
Information You Provide Directly
- Name and contact details when you enrol in courses
- Email address for account creation and communications
- Payment information processed through secure third-party payment processors
- Course preferences and learning objectives
- Correspondence when you contact us with enquiries
Information Collected Automatically
- Learning platform usage data including course progress and completion rates
- Exercise submissions and assessment results
- Technical information such as IP address, browser type and operating system
- Website navigation patterns through cookies and similar technologies
How We Use Your Information
We process personal information for the following purposes:
- Providing access to purchased courses and learning materials
- Processing enrolment and managing your account
- Tracking learning progress and providing completion certificates
- Communicating important updates about courses or platform changes
- Responding to support requests and enquiries
- Improving course content and user experience based on aggregated usage patterns
- Complying with legal obligations including financial record-keeping
Legal Basis for Processing
We process personal information under the following legal bases:
- Contract performance: Processing necessary to deliver courses you have purchased
- Legitimate interests: Improving our services and platform functionality
- Legal compliance: Meeting tax, accounting and other regulatory requirements
- Consent: Where specifically requested for marketing communications
Information Sharing and Disclosure
We do not sell personal information to third parties. We share information only in the following limited circumstances:
- Service providers: Third-party platforms that host our learning content, process payments, or provide email delivery services. These providers operate under contractual obligations to protect your data.
- Legal requirements: When required by law, court order, or governmental authority
- Business transfers: In the event of a merger, acquisition or sale of assets, though data protection obligations would transfer to the new entity
Data Retention
We retain personal information for as long as necessary to fulfil the purposes outlined in this policy:
- Account and enrolment information: Retained while your account remains active
- Learning progress and certificates: Retained indefinitely to maintain your educational records
- Financial records: Retained for seven years to meet accounting and tax obligations
- Marketing consent records: Retained until consent is withdrawn
Your Rights
Under data protection legislation, you have the following rights:
- Access: Request a copy of personal information we hold about you
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your personal information in certain circumstances
- Restriction: Limit how we use your information in specific situations
- Portability: Receive your information in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise these rights, contact us at [email protected]. We will respond to requests within one month.
Security Measures
We implement appropriate technical and organisational security measures to protect personal information against unauthorised access, alteration, disclosure or destruction. These measures include:
- Encryption of data in transit using SSL/TLS protocols
- Secure password storage using industry-standard hashing
- Regular security assessments and updates
- Access controls limiting who can view personal information
- Employee training on data protection responsibilities
International Data Transfers
Our primary data processing occurs within the European Economic Area. Where information is transferred to countries outside the EEA, we ensure appropriate safeguards are in place through standard contractual clauses or other approved transfer mechanisms.
Children's Privacy
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, contact us immediately so we can delete it.
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance website functionality and analyse usage patterns. For detailed information about our cookie practices, see our separate Cookie Policy.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated via email or prominent notice on our website. The date at the top of this document indicates when it was last revised.
Contact Information
For questions about this Privacy Policy or our data practices, contact us at:
Email: [email protected]
Address: 42 Broadwick Street, London W1F 7AF, United Kingdom
Supervisory Authority
If you believe we have not addressed your data protection concerns adequately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters.