Privacy Policy
The Safety Savvy Ltd: How We Handle Your Personal Data. Last updated: 14 May 2026
The Safety Savvy Ltd is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store and share your personal information when you visit our website, enquire about or book our first aid training, or interact with us in any other way. We are registered with the Information Commissioner's Office (ICO) and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are (Data Controller)
The Safety Savvy Ltd is the data controller responsible for your personal data. We are a first aid training provider operating across the UK.
- Registered Office: 25 Greenway Gardens, London, United Kingdom, NW9 5AY
- Company Registration Number: 16473135
- ICO Registration: Registered with the Information Commissioner's Office (ICO) as a data controller
- Email: contact@thesafetysavvy.com
- Phone: +44 7442 321986
- Website: https://www.thesafetysavvy.com
As a small business, data protection queries are handled by the business owner directly. There is no separate Data Protection Officer. If you have any concerns about how we handle your data, please contact us in the first instance using the details above.
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. We only collect information that is necessary to provide our services or respond to your enquiry. This may include:
- Identity Data: first name, last name, title, date of birth
- Contact Data: billing address, email address, telephone numbers
- Financial Data: payment details (note: we do not directly store full card details, these are handled by our secure payment processor, Tide Business)
- Transaction Data: details of payments made and courses purchased
- Course Data: details relevant to your participation in our training, including any declared medical conditions relevant to course participation, emergency contact details, previous qualification history, and assessment results or certificates issued
- Marketing and Communications Data: your preferences for receiving communications from us
- Technical Data: limited technical information collected automatically when you visit our website, such as your IP address and browser type, via standard server logs
- Survey and Feedback Data: responses to post-course surveys or feedback forms
We also collect and use Aggregated Data (such as pass rates and booking statistics) for business analysis. Aggregated Data does not identify you personally.
Sensitive Personal Data
We may collect special category personal data, for example health information relevant to a declared medical condition that might affect your ability to participate in practical first aid training, or to facilitate reasonable adjustments. We will only collect and process such data where there is a clear lawful basis, typically with your explicit consent or where necessary for health and safety reasons during the course.
If You Do Not Provide Personal Data
Where we need personal data to fulfil a contract with you (for example, to process a booking or issue a certificate), failure to provide that data may mean we are unable to deliver the training. We will notify you if this is the case.
3. How We Collect Your Data
- Direct interactions: when you complete a booking or enquiry form, email us, call us, subscribe to our mailing list, complete a survey, or provide feedback
- Automated technologies: our website may collect limited technical data automatically (IP address, browser type) via standard server logs for the purpose of ensuring the website functions correctly. We do not use advertising or tracking cookies
- Third parties: we may receive data from our payment processor (Tide Business), our awarding body (Nuco Training / First Aid Awards Ltd) for qualification verification, and from publicly available sources such as Companies House where relevant
4. How and Why We Use Your Data (Lawful Basis)
We will only use your personal data when the law allows us to. The lawful bases we rely on under UK GDPR are:
- Performance of a Contract: to process your booking, deliver training and issue certificates
- Legitimate Interests: to respond to pre-booking enquiries, improve our services, and send relevant follow-up communications to existing clients; we always consider and balance any impact on your rights
- Legal Obligation: to maintain financial records, meet HMRC requirements, and comply with health and safety obligations
- Consent: for optional marketing communications; you can withdraw consent at any time
| Purpose / Activity | Type of Data | Lawful Basis |
|---|---|---|
| Register you as a new customer / course participant | Identity, Contact | Performance of a contract |
| Process and deliver your course booking | Identity, Contact, Financial, Transaction, Course | Performance of a contract |
| Manage our relationship with you | Identity, Contact, Marketing & Comms | Performance of a contract; Legitimate Interests |
| Administer and protect our business and website | Technical, Usage | Legitimate Interests; Legal obligation |
| Send you marketing communications | Contact, Marketing & Comms | Legitimate Interests; Consent (where applicable) |
| Issue course certificates via Nuco Training | Identity, Course, Date of Birth | Performance of a contract; Legal obligation |
| Comply with HMRC and regulatory requirements | Identity, Financial, Transaction | Legal obligation |
| Notify you of changes to our terms or policy | Identity, Contact | Legal obligation; Performance of a contract |
Marketing
We may use your contact information to let you know about new courses, upcoming refresher dates or services that may be relevant to you, where we have a legitimate interest in doing so (for example, as an existing client) or where you have given your explicit consent. We will always obtain your express consent before sharing your personal data with any third party for their own marketing purposes. You can opt out of marketing communications at any time by emailing us at contact@thesafetysavvy.com or by clicking the unsubscribe link in any email we send you.
5. Disclosures of Your Personal Data
We do not sell, rent or trade your personal data. We may share limited information with the following parties only where necessary to deliver our services:
- Nuco Training (First Aid Awards Ltd): our awarding body, to process and issue certificates. Their own privacy policy applies to data processed on their systems
- Tide Business: our secure payment processor
- Email and communication providers: third-party services used to send and receive emails, contractually bound to handle your data securely and in accordance with UK GDPR
- Professional advisers: lawyers, accountants or insurers where necessary
- HM Revenue & Customs and other UK regulatory authorities: where we are legally required to report
We do not permit any third-party service provider to use your personal data for their own purposes. They may only process your data for the specified purpose and in accordance with our instructions.
6. International Transfers
We store your personal data within the UK. Some of our third-party providers may be based outside the UK or European Economic Area (EEA). Where we transfer personal data outside the UK, we ensure an equivalent level of protection by applying one or more of the following safeguards:
- Transferring only to countries deemed adequate by the UK Government or European Commission
- Using Standard Contractual Clauses approved by the UK Government or European Commission
- Where providers are based in the US, ensuring participation in the EU-US Data Privacy Framework or equivalent robust safeguards
Please contact us if you would like further information about the specific safeguards used for any international transfer.
7. Data Security
We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, accessed without authorisation, altered or disclosed. Access to your personal data is limited to those with a genuine business need, and they are subject to a duty of confidentiality. We have procedures in place to deal with any suspected personal data breach and will notify you and the ICO where we are legally required to do so.
8. Data Retention
We retain your personal data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including any legal, regulatory, tax or accounting requirements. Our standard retention periods are:
- Enquiry records where no booking followed: up to 12 months, after which data is securely deleted
- Customer contact, identity, financial and transaction data: 7 years from the end of the client relationship, in line with HMRC requirements
- Course records and certificates: up to 10 years, in line with awarding body requirements and to assist with requalification and verification enquiries
We may retain data for longer in the event of a complaint or where litigation is reasonably anticipated. At the end of any applicable retention period, your data is securely deleted or anonymised.
9. Your Legal Rights
Under UK GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at contact@thesafetysavvy.com. We will respond within one calendar month.
- Right of access (Subject Access Request): to receive a copy of the personal data we hold about you
- Right to rectification: to have inaccurate or incomplete data corrected
- Right to erasure: to ask us to delete your data where there is no longer a lawful basis to hold it, subject to any legal retention obligations
- Right to restriction of processing: to ask us to pause processing in certain circumstances, for example while a dispute is being resolved
- Right to data portability: to receive your data in a structured, machine-readable format where processing is based on consent or contract
- Right to object: to processing based on our legitimate interests or for direct marketing purposes
- Rights related to automated decision-making: we do not make automated decisions about you that have a legal or significant effect
You will not usually be charged a fee to exercise these rights. We may charge a reasonable fee, or decline, where a request is clearly unfounded, repetitive or excessive. We may need to verify your identity before processing your request.
10. Cookies
Our website uses only essential cookies required for core site functionality, such as maintaining your session during a form submission and ensuring the site operates correctly. We do not use advertising, analytics, profiling or other non-essential tracking cookies. You can control or disable cookies through your browser settings. Disabling essential cookies may affect the functionality of our website.
11. Links to Other Websites
Our website may contain links to third-party websites and social media profiles (including Instagram, TikTok and LinkedIn). We are not responsible for the privacy practices of those sites and encourage you to read their own privacy policies before providing any personal information.
12. Changes to This Privacy Policy
We keep this Privacy Policy under regular review. Any changes will be posted on our website and, where appropriate, notified to you by email. The date at the top of this page will always show when the policy was last revised. We encourage you to check this page periodically.
13. Complaints
If you have any concerns about how we handle your personal data, please contact us in the first instance so that we can try to resolve it for you:
- Email: contact@thesafetysavvy.com
- Phone: +44 7442 321986
You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters:
- Website: www.ico.org.uk
- Phone: 0303 123 1113
We would, however, appreciate the opportunity to address your concerns before you approach the ICO.
