Privacy Policy
Last updated: 20/07/2026
- About this Privacy Policy
This Privacy Policy explains how International Professional Engineering Academy or IPEA, collects, uses, stores, shares and protects personal information.
It applies when you:
- visit theipea.org or another website operated by IPEA;
- create or use an IPEA account;
- enrol in or complete a course;
- purchase a course, membership, subscription or other service;
- participate in an assessment, live session, survey or event;
- receive a certificate or learning record;
- contact our support team;
- subscribe to our marketing communications;
- interact with us through social media or another communication channel;
- use IPEA through your employer, educational institution or another organisation; or
- otherwise use a product or service that links to this Privacy Policy.
In this Privacy Policy, our websites, online courses, learning platform, memberships, assessments, certificates, events, business learning services and related products are collectively referred to as the “Services.”
- Who we are
For the purposes of applicable UK data-protection law, the data controller is:
International Professional Engineering Academy or IPEA
Email: info@theipea.org
We are registered in England and Wales.
The data controller is the organisation that decides why and how personal information is used.
- Data-protection laws
We process personal information in accordance with applicable data-protection and privacy laws, which may include:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025;
- the Privacy and Electronic Communications Regulations 2003; and
- other applicable national data-protection, consumer and electronic-communications laws.
In this Privacy Policy, these are referred to collectively as “Data Protection Law.”
- Personal information
Personal information means information relating to an identified or identifiable living individual.
It does not include information that has been irreversibly anonymised so that an individual can no longer be identified.
We may use aggregated or anonymised information for research, statistical analysis, reporting, service development and business planning. Where information is genuinely anonymised, it is not personal information.
- Personal information we collect
The information we collect depends on how you interact with IPEA and which Services you use.
5.1 Identity information
This may include:
- full name;
- title;
- username or account identifier;
- date of birth, where necessary;
- photograph or profile image;
- signature;
- employer or organisation;
- job title;
- professional role;
- professional membership information;
- learner or employee number;
- identity-verification information; and
- copies or details of identification documents where verification is reasonably necessary.
We will not normally request a copy of an identity document unless it is required to prevent fraud, verify a certificate, confirm eligibility, respond securely to a rights request or satisfy another legitimate or legal requirement.
5.2 Contact information
This may include:
- email address;
- postal address;
- billing address;
- telephone number;
- employer contact details;
- communication preferences; and
- social-media or messaging contact information.
5.3 Account information
This may include:
- login credentials;
- encrypted or hashed password information;
- account status;
- account preferences;
- membership or subscription status;
- language and accessibility preferences;
- authentication information;
- security questions;
- account creation and login records; and
- records of account changes.
You should keep your login credentials confidential and must not share your account with another person.
5.4 Transaction and payment information
This may include:
- products and Services purchased;
- order number;
- transaction date;
- amount and currency;
- discounts or promotional codes;
- billing details;
- payment status;
- invoices;
- refund and cancellation information;
- subscription renewal information;
- limited payment-method information;
- tax information; and
- records of payment disputes or chargebacks.
Payments may be processed by an external payment provider.
IPEA does not normally receive or store complete payment-card numbers, card security codes or equivalent authentication data when payment is processed by an external provider.
The payment provider may process your information as an independent controller under its own privacy policy.
5.5 Learning and course information
This may include:
- course enrolments;
- lessons accessed;
- learning progress;
- time spent on activities;
- course completion status;
- quiz and assessment answers;
- marks, scores and results;
- assignment submissions;
- feedback from instructors or assessors;
- attendance at live sessions;
- course notes or saved progress;
- certificate information;
- continuing professional development records;
- dates of enrolment and completion;
- requests for extensions or adjustments;
- academic-integrity records; and
- communications relating to your learning.
5.6 Certificate and verification information
This may include:
- learner name;
- course title;
- certificate number;
- issue date;
- completion date;
- assessment result;
- certificate status;
- verification code;
- certificate expiry date, if applicable; and
- records of certificate verification requests.
Where we provide a public or third-party certificate-verification service, we will display only the minimum information reasonably necessary to confirm whether a certificate is authentic.
The relevant verification page will explain what information is publicly visible.
5.7 Business and organisational learning information
Where an employer, educational institution or another organisation purchases or administers access for you, we may collect:
- the organisation’s name;
- administrator contact details;
- department, team or location;
- employee, contractor or student identifier;
- licence allocation;
- courses assigned;
- enrolment status;
- learning progress;
- attendance;
- assessment results;
- completion records;
- certificates; and
- communications concerning the organisation’s learning programme.
The organisation may provide some of this information directly to us.
5.8 Communications and support information
This may include:
- emails and contact-form submissions;
- support requests;
- complaints;
- telephone notes;
- chat messages;
- survey responses;
- reviews and testimonials;
- social-media messages;
- records of consent;
- records of marketing objections;
- records of privacy requests; and
- other communications with IPEA.
Telephone or video calls will only be recorded where you are informed in advance and we have an appropriate lawful basis.
5.9 Technical and usage information
This may include:
- internet protocol address;
- browser type and version;
- device type;
- operating system;
- screen resolution;
- language;
- time zone;
- approximate location derived from an IP address;
- referring website;
- pages visited;
- links selected;
- session duration;
- course and feature usage;
- download activity;
- login dates and times;
- error and diagnostic records;
- security events; and
- cookie or similar technology identifiers.
5.10 Marketing and preference information
This may include:
- marketing consent;
- communication preferences;
- interests inferred from your use of our Services;
- courses viewed or purchased;
- responses to campaigns;
- email opening and interaction information, where lawful;
- event attendance;
- survey responses; and
- records showing that you opted out of marketing.
5.11 Fraud, compliance and security information
This may include:
- suspicious transaction information;
- unsuccessful login attempts;
- misuse reports;
- plagiarism or impersonation concerns;
- assessment-integrity information;
- account restrictions;
- sanctions-screening results, where required;
- complaints and investigation information; and
- evidence relating to a suspected breach of our Terms of Use.
5.12 Recruitment information
Where you apply to work for or provide services to IPEA, we may collect:
- employment and education history;
- curriculum vitae;
- qualifications;
- professional experience;
- references;
- interview notes;
- work eligibility;
- expected remuneration;
- portfolio or work samples; and
- other information relevant to the application.
A separate recruitment privacy notice may apply.
5.13 Special-category information
Special-category information includes information about matters such as health, disability, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric identification, sex life and sexual orientation.
We do not normally need to collect special-category information from learners.
We may process limited health, disability or accessibility information where it is necessary to:
- provide a reasonable adjustment;
- respond to an accessibility request;
- protect an individual’s vital interests;
- comply with a legal obligation; or
- provide another requested accommodation.
Where special-category information is processed, we will identify both a lawful basis and an additional legal condition for processing it.
Please do not provide special-category information unless we have requested it or it is necessary for us to address your request.
5.14 Criminal-offence information
We do not routinely collect criminal-conviction or offence information.
We will process such information only where it is necessary, lawful and supported by an appropriate legal condition.
- How we collect personal information
We collect personal information from several sources.
6.1 Information you provide directly
We receive information directly from you when you:
- register an account;
- complete a form;
- place an order;
- enrol in a course;
- submit an assessment;
- participate in a survey;
- request support;
- make a complaint;
- exercise a data-protection right;
- subscribe to marketing;
- attend an event;
- communicate with us; or
- otherwise use the Services.
6.2 Information collected automatically
We may automatically collect technical and usage information through:
- server logs;
- cookies;
- pixels;
- local storage;
- software development kits;
- security tools;
- analytics services; and
- similar technologies.
Non-essential technologies will be used only where permitted by applicable law and, where required, after obtaining your consent.
6.3 Information provided by an organisation
We may receive information from:
- your employer;
- an educational institution;
- a training sponsor;
- a membership organisation;
- a corporate account administrator;
- a professional body; or
- another organisation that purchases, assigns or administers your access.
The organisation should have an appropriate legal basis for providing your information to us and should tell you how it uses and shares your information.
6.4 Information from service providers and business partners
We may receive information from:
- payment providers;
- learning-platform providers;
- identity-verification providers;
- event platforms;
- customer-support providers;
- email and communication providers;
- marketing platforms;
- analytics providers;
- fraud-prevention services;
- certificate-verification providers; and
- authorised resellers or referral partners.
6.5 Information from public sources
Where relevant and lawful, we may receive professional information from publicly available sources such as:
- company websites;
- professional registers;
- professional networking platforms;
- public company records;
- conference or event websites; and
- other legitimate public sources.
- How we use personal information
We use personal information only where we have an appropriate purpose and lawful basis.
The table below summarises our principal processing activities.
| Purpose | Information normally used | Principal lawful basis |
| Creating and managing accounts | Identity, contact, account and technical information | Performance of a contract; legitimate interests in administering secure accounts |
| Processing orders and payments | Identity, contact, transaction and payment information | Performance of a contract; compliance with legal obligations |
| Providing courses and learning services | Account, learning, course and technical information | Performance of a contract |
| Managing memberships and subscriptions | Account, transaction, payment and usage information | Performance of a contract; compliance with legal obligations |
| Delivering assessments | Identity, account, learning and assessment information | Performance of a contract; legitimate interests in maintaining assessment integrity |
| Issuing and verifying certificates | Identity, course, assessment and certificate information | Performance of a contract; legitimate interests in preventing certificate fraud |
| Providing customer support | Identity, contact, account, transaction, course and communication information | Performance of a contract; legitimate interests in responding effectively |
| Operating business and team learning | Identity, organisational, learning and certificate information | Performance of a contract; legitimate interests; legal obligations where applicable |
| Reporting progress to a sponsoring organisation | Identity, organisational, learning, assessment and certificate information | Performance of a contract; legitimate interests of IPEA and the sponsoring organisation |
| Maintaining safety and platform security | Account, technical, security, communication and transaction information | Legitimate interests in protecting users, systems and Services; legal obligations |
| Preventing fraud and misuse | Identity, transaction, account, technical and security information | Legitimate interests; legal obligations |
| Investigating academic misconduct | Identity, learning, assessment, technical and communication information | Performance of a contract; legitimate interests in maintaining integrity |
| Maintaining financial and legal records | Transaction, payment, identity and communication information | Compliance with legal obligations; legitimate interests in establishing or defending legal claims |
| Improving courses and Services | Learning, usage, feedback, communication and technical information | Legitimate interests; consent where required for cookies or similar technologies |
| Conducting research and analysis | Usage, learning, survey and aggregated information | Legitimate interests; consent where appropriate |
| Sending service communications | Identity, contact, account, transaction and course information | Performance of a contract; legal obligations; legitimate interests |
| Sending marketing to individuals | Contact, preference, transaction and marketing information | Consent or legitimate interests where the applicable electronic-marketing rules permit |
| Sending business-to-business marketing | Professional contact and marketing information | Legitimate interests, subject to applicable electronic-marketing rules |
| Managing marketing opt-outs | Contact and preference information | Compliance with legal obligations; legitimate interests in respecting objections |
| Managing events and live sessions | Identity, contact, registration, attendance and communication information | Performance of a contract; legitimate interests; consent where applicable |
| Managing reviews and testimonials | Identity, course, review and communication information | Consent or legitimate interests, depending on the use |
| Responding to privacy requests and complaints | Identity, contact, account, communication and verification information | Compliance with legal obligations; legitimate interests |
| Complying with regulators and law enforcement | Any relevant information | Compliance with legal obligations; recognised legitimate interests or legitimate interests where applicable |
| Managing corporate operations | Supplier, adviser, business contact, transaction and communication information | Performance of a contract; legitimate interests; legal obligations |
| Establishing or defending legal claims | Any relevant information | Legitimate interests; legal obligations; legal-claims conditions where special-category information is involved |
A lawful basis is the legal justification that allows us to use personal information.
The lawful bases on which we principally rely are explained below.
- Performance of a contract
We process personal information where it is necessary to:
- provide a course or membership you purchased;
- create and maintain your account;
- process an order;
- administer an assessment;
- issue a certificate;
- provide support;
- administer a subscription;
- take steps you request before entering into a contract; or
- perform another contractual obligation.
When information is required to provide a purchased Service, failing to provide it may mean that we cannot create your account, process your order or provide the Service.
- Legal obligations
We process personal information where necessary to comply with legal obligations, including obligations relating to:
- tax and accounting;
- consumer protection;
- company records;
- fraud prevention;
- sanctions and financial controls;
- data protection;
- information security;
- court orders;
- regulatory requests; and
- the establishment, exercise or defence of legal rights.
- Legitimate interests
We may process personal information where it is necessary for a legitimate interest and that interest is not overridden by your rights and freedoms.
Our legitimate interests may include:
- operating and improving IPEA;
- providing effective learner support;
- protecting the security of our systems;
- preventing fraud;
- protecting intellectual property;
- maintaining academic and assessment integrity;
- verifying certificates;
- understanding how the Services are used;
- developing courses;
- managing relationships with customers and suppliers;
- communicating with professional and corporate contacts;
- recovering amounts owed;
- handling disputes; and
- establishing, exercising or defending legal claims.
Where required, we conduct an assessment that considers:
- the purpose of the processing;
- whether the processing is necessary;
- the nature of the information;
- your reasonable expectations;
- the possible effect on you; and
- the safeguards that can reduce that effect.
You may object to processing based on legitimate interests. Further information appears in section 25.
- Consent
We rely on consent where applicable, including for:
- certain marketing communications;
- non-essential cookies and similar technologies;
- publication of some testimonials;
- optional photographs or recordings;
- certain uses of special-category information; and
- other optional processing clearly presented to you.
Consent must be freely given, specific, informed and indicated through a clear affirmative action.
You may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing that occurred before consent was withdrawn.
You will not ordinarily be denied a core purchased Service merely because you refuse consent to an optional activity.
- Service communications
We may send communications that are necessary to administer your account or provide the Services.
These may include:
- account verification messages;
- password-reset messages;
- order confirmations;
- payment receipts;
- course enrolment notices;
- assessment information;
- certificate notifications;
- subscription and renewal notices;
- changes to a Service;
- security alerts;
- important changes to legal terms; and
- responses to support requests.
These are service communications rather than marketing communications.
You may not be able to opt out of essential service communications while maintaining an active account or Service.
- Marketing communications
We may send information about:
- courses;
- memberships;
- professional-development resources;
- events;
- promotions;
- business learning services;
- surveys; and
- related IPEA products and news.
Where consent is required, we will send electronic marketing only after obtaining valid consent.
Where permitted by law, we may contact existing customers about similar IPEA products or Services, provided that:
- we obtained the contact information in connection with a sale or genuine sales enquiry;
- the marketing concerns our own similar products or Services; and
- we provided a clear opportunity to opt out when the information was collected and in each message.
Different rules may apply to marketing sent to corporate contacts.
Every electronic marketing message will provide a clear method of unsubscribing.
You can also opt out by contacting us.
When you opt out, we may retain limited information on a suppression list to ensure that we continue to respect your request.
Opting out of marketing does not stop essential service communications.
- Cookies and similar technologies
Our website and learning platform may use cookies, local storage, pixels, tags, software development kits and similar technologies.
These technologies may be used for:
- website operation;
- authentication;
- account security;
- shopping-basket functions;
- remembering preferences;
- fraud prevention;
- fault detection;
- accessibility;
- audience measurement;
- analytics;
- course functionality;
- content personalisation; and
- advertising or marketing measurement.
Some technologies are strictly necessary to provide a service requested by you and may be used without consent where the law permits.
Other technologies will be used only after we have obtained any consent required by law.
You may manage available choices through cookie setting link.
Further information, including the names, providers, purposes and durations of cookies, is available in our separate Cookie Policy.
Blocking some cookies may affect the operation of certain features.
- Business and employer-sponsored learning
Where your employer, educational institution or another organisation provides access to IPEA, IPEA and that organisation may each act as an independent controller for different purposes.
IPEA normally acts as a controller for purposes such as:
- creating and securing learner accounts;
- delivering courses;
- maintaining learning records;
- administering assessments;
- issuing certificates;
- providing technical support;
- protecting intellectual property;
- preventing misuse; and
- complying with legal obligations.
The sponsoring organisation normally determines why it assigns training, which learners participate and how it uses reports received from IPEA.
Depending on the arrangement, we may provide the organisation with:
- enrolment status;
- course assignments;
- progress;
- attendance;
- assessment results;
- completion information;
- certificate information; and
- related administrative information.
We will not normally provide an employer or sponsor with private communications unrelated to its programme unless:
- you ask us to do so;
- it is necessary to investigate misuse;
- disclosure is required by law; or
- another lawful and proportionate reason applies.
Your employer or sponsoring organisation should provide its own privacy information explaining how it uses your learning records.
In some arrangements, IPEA may process information as a processor acting only on the documented instructions of the organisation. Where that applies, the relevant contract will define the parties’ responsibilities.
- Assessments and academic integrity
We may analyse assessment, account, technical and usage information to:
- confirm that course requirements have been completed;
- detect plagiarism;
- identify unusual assessment activity;
- prevent impersonation;
- identify unauthorised account sharing;
- investigate suspected manipulation;
- protect the credibility of certificates; and
- enforce our Terms of Use.
An investigation may involve reviewing:
- submission timing;
- assessment answers;
- similarity between submissions;
- login activity;
- IP address information;
- device and browser information;
- communications;
- identity-verification material; and
- other information relevant to the concern.
We will use information that is reasonably necessary and proportionate to the issue being investigated.
- Automated decision-making
Automated decision-making occurs where a decision is made using personal information solely by automated means, without meaningful human involvement.
IPEA does not currently use solely automated decision-making to make decisions that produce legal effects or similarly significant effects concerning learners, except where:
- it is necessary for entering into or performing a contract;
- it is authorised by law; or
- you have given valid consent,
and the legally required safeguards are in place.
Some quizzes may be marked automatically. Ordinary automatic scoring of a course quiz will not usually produce a legal or similarly significant effect.
Where we introduce significant automated decision-making, we will provide appropriate information about:
- the use of automation;
- the principal factors involved;
- the significance and likely consequences;
- available safeguards;
- the right to obtain human intervention;
- the right to express a view; and
- the right to contest the decision.
- Who we share personal information with
We may share personal information with the following categories of recipient where necessary and lawful.
18.1 Technology and service providers
These may include providers of:
- website hosting;
- cloud infrastructure;
- content delivery;
- learning-management systems;
- account authentication;
- cybersecurity;
- data backup;
- email delivery;
- customer support;
- communications;
- video conferencing;
- document storage;
- analytics;
- survey tools;
- assessment tools;
- certificate generation and verification;
- fraud prevention; and
- business administration.
Service providers acting as processors are permitted to use personal information only for agreed purposes and must protect it appropriately.
18.2 Payment providers
Payment processors, banks and payment networks may receive information necessary to:
- authorise payments;
- process refunds;
- prevent fraud;
- handle disputes; and
- comply with financial regulations.
Some payment providers act as independent controllers and apply their own privacy policies.
18.3 Instructors, assessors and support personnel
Authorised instructors, assessors, moderators and support personnel may access information necessary to:
- deliver teaching;
- review submissions;
- mark assessments;
- provide feedback;
- respond to questions;
- investigate misconduct; and
- administer courses.
They must handle information confidentially and only for authorised purposes.
18.4 Employers and sponsoring organisations
Where an organisation purchases or administers your learning access, we may share the progress and completion information described in section 15.
18.5 Professional advisers
We may share relevant information with:
- lawyers;
- accountants;
- auditors;
- insurers;
- tax advisers;
- banking providers; and
- other professional advisers.
18.6 Regulators, courts and public authorities
We may disclose information where reasonably necessary to:
- comply with a legal obligation;
- respond to a court order;
- cooperate with a regulator;
- prevent or investigate crime;
- protect an individual’s safety;
- enforce legal rights; or
- defend a legal claim.
18.7 Business transfers
If IPEA or part of its business is reorganised, financed, merged, acquired, transferred or sold, relevant personal information may be disclosed to:
- prospective purchasers;
- investors;
- lenders;
- advisers; and
- the organisation that acquires or operates the relevant business.
Appropriate confidentiality and data-protection safeguards will be used.
18.8 Other recipients authorised by you
We may share information with another person or organisation where you instruct or authorise us to do so.
- Sale of personal information
IPEA does not sell personal information in exchange for money.
We do not permit service providers acting on our behalf to use personal information for their own unrelated marketing.
This statement must be reviewed if IPEA introduces advertising, data-sharing or partnership arrangements that fall within broader statutory definitions of “sale,” “sharing” or targeted advertising in another jurisdiction.
- International transfers
Some recipients or service providers may be located outside the United Kingdom or may permit access to personal information from outside the United Kingdom.
Where personal information is transferred internationally, we will take steps required by applicable Data Protection Law.
These may include:
- transferring information to a country or recipient covered by UK adequacy regulations;
- using the United Kingdom International Data Transfer Agreement;
- using the UK Addendum to approved standard contractual clauses;
- conducting an appropriate transfer-risk assessment;
- applying supplementary technical or organisational safeguards; or
- relying on a legally permitted exception in limited circumstances.
Additional safeguards may include:
- encryption;
- access controls;
- contractual confidentiality;
- data minimisation;
- restrictions on onward transfers; and
- security and compliance reviews.
You may contact us for information about the safeguards applying to a particular transfer, subject to lawful confidentiality restrictions.
- Data security
We use appropriate technical and organisational measures designed to protect personal information against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access; and
- other unlawful processing.
Measures may include:
- encryption in transit;
- access controls;
- password protection;
- multi-factor authentication where appropriate;
- role-based permissions;
- secure hosting;
- system monitoring;
- backups;
- staff confidentiality obligations;
- security policies;
- supplier due diligence;
- incident-response procedures; and
- periodic reviews.
No online service or transmission method can be guaranteed to be completely secure.
You are responsible for choosing a strong password, protecting your login credentials and notifying us promptly if you suspect unauthorised account access.
- Personal-data breaches
We maintain procedures for identifying, assessing, managing and documenting personal-data breaches.
Where legally required, we will:
- notify the Information Commissioner’s Office;
- notify another competent supervisory authority; and
- inform affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
Notifications will be made within the periods required by applicable law.
- Data retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, security, certificate-verification and reporting requirements.
When deciding how long to retain information, we consider:
- the nature and sensitivity of the information;
- the purpose for which it is used;
- the duration of the customer relationship;
- the period during which a certificate may need to be verified;
- legal and regulatory requirements;
- tax and accounting obligations;
- limitation periods for legal claims;
- security and fraud-prevention needs;
- contractual commitments; and
- whether the information can be anonymised.
Our intended retention periods are set out below. These periods must be aligned with IPEA’s documented retention schedule before publication.
| Information | Intended retention period |
| Basic account information | While the account is active and for 5 years after closure or last activity |
| Orders, invoices and accounting records | Normally at least six years after the end of the relevant financial or accounting period, or longer where legally required |
| Contract and subscription records | The contract period and normally six years after it ends |
| Course enrolment and progress records | 5 years after completion, expiry or last course activity |
| Assessment submissions and results | 5 years after the final result or certificate issue |
| Certificate records | 5 years |
| Identity-verification documents | Only for the verification process and 5 years afterwards, unless longer retention is necessary for fraud prevention or legal claims |
| Support communications | 5 years after the request is closed |
| Complaints and disputes | 5 years after final resolution, subject to legal limitation periods |
| Security and access logs | 5 years, unless longer retention is necessary to investigate an incident |
| Marketing records | Until consent is withdrawn, an objection is made or 5 years passes |
| Marketing suppression records | For as long as reasonably necessary to ensure that the opt-out continues to be respected |
| Cookie-consent records | 5 years or as otherwise required to demonstrate valid consent |
| Survey responses | 5 years, after which they will be deleted or anonymised |
| Live-session recordings | 5 years stated when the recording is made |
| Business contact information | For the duration of the relationship and 5 years afterwards |
| Privacy-rights requests | 5 years after completion of the request |
We may retain information for longer where:
- required by law;
- a complaint or legal claim is ongoing or reasonably anticipated;
- fraud or misuse is being investigated;
- a regulator requires retention; or
- the information is necessary to protect legal rights.
When information is no longer required, we will delete it, securely destroy it or irreversibly anonymise it.
Backups may retain information for a limited additional period before being overwritten through the normal backup cycle.
- Your data-protection rights
Depending on the circumstances and applicable law, you may have the rights described below.
These rights are not absolute. A legal exemption or limitation may apply in some situations.
24.1 Right to be informed
You have the right to receive clear information about how we collect and use your personal information.
This Privacy Policy is intended to provide that information.
24.2 Right of access
You may request:
- confirmation of whether we process your personal information;
- a copy of that information; and
- supplementary information about how it is used.
This is commonly called a subject access request.
24.3 Right to rectification
You may ask us to correct inaccurate personal information or complete information that is incomplete.
You can update some account information directly through your profile.
24.4 Right to erasure
You may ask us to delete personal information in certain circumstances.
This right may not apply where continued retention is necessary for:
- compliance with a legal obligation;
- freedom of expression;
- a legal claim;
- fraud prevention;
- certificate integrity;
- public-interest purposes; or
- another lawful reason.
Closing an account does not necessarily require immediate deletion of all associated information.
24.5 Right to restrict processing
You may ask us to restrict the use of personal information in certain circumstances, including while accuracy or a lawful-basis objection is being assessed.
24.6 Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal information you provided in a structured, commonly used and machine-readable format.
Where technically feasible and legally required, you may ask us to transmit it directly to another controller.
24.7 Right to object
You may object to processing based on legitimate interests.
We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.
You may object to direct marketing at any time. When you object to direct marketing, we will stop using your information for that purpose.
24.8 Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
24.9 Rights relating to automated decisions
Where a solely automated decision produces a legal or similarly significant effect, you may have rights to:
- obtain human intervention;
- express your point of view;
- receive an explanation; and
- challenge the decision.
24.10 Right to complain
You may complain to IPEA and to the Information Commissioner’s Office about our use of your personal information.
- Exercising your rights
To exercise a data-protection right, contact:
Email: info@theipea.org
Please describe:
- the right you wish to exercise;
- the information or processing concerned;
- the account or email address involved; and
- any details that may help us locate the relevant information.
You do not need to use a specific form.
We may request information reasonably necessary to verify your identity and ensure that personal information is not disclosed to an unauthorised person.
Identity-verification requests will be proportionate to the risk and nature of the request.
We will normally respond without undue delay and within the period required by applicable law. This is usually one month, although the period may be extended where the request is complex or multiple requests have been made.
We will inform you if an extension applies.
Rights requests are normally handled without charge. We may charge a reasonable fee or decline to act where permitted by law, including where a request is manifestly unfounded or excessive.
Where another person submits a request for you, we may require evidence that they are authorised to act on your behalf.
- Data-protection complaints
You may complain about our use of personal information by contacting:
Email: info@theipea.org
Please include:
- your name and contact details;
- a description of the concern;
- the information or processing involved;
- relevant dates;
- any previous correspondence; and
- the outcome you are seeking.
We will:
- take reasonable steps to facilitate the making of a complaint;
- acknowledge receipt within 30 days;
- investigate the complaint appropriately;
- keep you informed where appropriate; and
- respond without undue delay.
Our response will explain the outcome and, where relevant, any action taken.
- Complaints to the Information Commissioner
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection supervisory authority.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching the Information Commissioner’s Office.
If you live outside the United Kingdom, you may also have the right to complain to the data-protection authority in your country.
- Children’s information
The Services are primarily intended for adults and professional learners.
A person must normally be at least 18 years old to purchase a Service or enter into a subscription in their own name.
A person under 18 may use an appropriate Service only under the arrangements described in our Terms of Use and where any required parent, guardian, school or organisational involvement has been established.
The Services are not directed at children under 13, and we do not knowingly collect personal information directly from children under 13.
If you believe that a child has provided personal information contrary to this section, contact us.
We will investigate and take appropriate action.
Where an online Service is likely to be accessed by children, we will consider their specific needs, interests and rights when designing and operating that Service.
- External websites and services
The Services may contain links to websites, content, applications or platforms operated by third parties.
Those third parties control their own privacy practices.
This Privacy Policy does not apply to a third party’s use of personal information, and IPEA is not responsible for the content or privacy practices of external services.
You should review the privacy information provided by the relevant third party before supplying personal information.
- Social media
When you interact with IPEA through a social-media service, both IPEA and the social-media provider may receive information about the interaction.
The provider may act as an independent controller and may process information according to its own privacy policy.
Information posted publicly on social media may be visible to other users. You should avoid posting confidential, sensitive or unnecessary personal information publicly.
- Reviews, testimonials and learner stories
We may invite learners to provide reviews, feedback or testimonials.
We may publish a review with limited identifying information where this is lawful and consistent with the manner in which it was submitted.
We will obtain separate permission before using:
- your photograph;
- your full professional biography;
- your employer’s name or logo;
- a recorded video testimonial; or
- your personal story in a prominent marketing campaign,
unless another lawful basis clearly applies and the use would be within your reasonable expectations.
You may withdraw consent for future use of a consent-based testimonial. Withdrawal will not necessarily require us to retrieve printed materials already distributed, but we will stop new use where reasonably practicable.
- Accuracy of information
Please ensure that personal information supplied to us is accurate and current.
You can update certain information through your account or by contacting support.
We may ask you to confirm or update information where necessary to:
- provide the Services;
- issue an accurate certificate;
- process payments;
- protect account security; or
- comply with legal obligations.
- Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to the Services;
- new processing activities;
- changes in technology;
- changes in suppliers;
- legal or regulatory developments; or
- improvements in transparency.
The updated version will be published with a revised “Last updated” date.
Where a change is material, we may also notify you through:
- email;
- an account notification;
- a website notice; or
- another appropriate communication.
We will request new consent where a proposed change requires consent.
- Contact us
Questions, requests or concerns about this Privacy Policy may be sent to:
International Professional Engineering Academy or IPEA
Email: info@theipea.org

