Privacy Policy
Last updated:
1. Information We Collect
We collect personal information in the following ways:
- Contact Form: When you complete our contact form, we collect your name, email address, and message content.
- Course Enrolment: When you enrol in a course, we collect name, email, and payment information (processed securely through payment providers).
- Automatic Collection: We collect information about your visit through cookies and analytics tools, including IP address, browser type, pages visited, and time spent on site.
- Communications: If you email us or correspond through our platform, we retain those messages for service purposes.
2. How We Use Your Information
- To respond to your enquiries and provide courses or consultations you've requested
- To send course materials, updates, and administrative communications
- To improve our website and services through analytics
- To comply with legal obligations
- To prevent fraud and ensure site security
- To send promotional emails (with your opt-in consent)
3. Legal Basis for Processing (GDPR)
We process your data under the following legal grounds:
- Consent (Art. 6(1)(a)): You've actively agreed to receive newsletters or promotional content.
- Contract (Art. 6(1)(b)): Processing is necessary to fulfil a course purchase or consultation booking.
- Legal Obligation (Art. 6(1)(c)): We must retain certain records for tax and company law compliance.
- Legitimate Interest (Art. 6(1)(f)): We analyse site usage to improve our services and prevent abuse.
4. Data Sharing & Disclosure
We do not sell or rent your personal data. We may share information with:
- Payment Processors: Your payment card details are processed by secure third-party payment providers (e.g., Stripe, PayPal).
- Email Service Providers: We use third-party email platforms to send newsletters and course updates.
- Analytics Providers: We use Google Analytics to understand site usage (configured to anonymise IP addresses).
- Legal Requirements: If required by law, we may disclose information to relevant authorities.
5. Data Protection & Security
We take your privacy seriously. We use:
- SSL/TLS encryption for all data transmission
- Secure password practices for account management
- Limited staff access to personal data on a need-to-know basis
- Regular security audits and vulnerability assessments
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security, only that we use industry-standard protections.
6. Your Data Rights (GDPR)
Under GDPR, you have the right to:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Correction (Art. 16): Request correction of inaccurate or incomplete data.
- Erasure (Art. 17): Request deletion of your data (subject to legal retention requirements).
- Restrict Processing (Art. 18): Request that we limit how we use your data.
- Portability (Art. 20): Request your data in a structured, portable format.
- Object (Art. 21): Object to marketing communications or certain processing activities.
- Lodge a Complaint: Contact the Information Commissioner's Office (ICO) in the UK if you believe your rights have been violated.
To exercise any of these rights, contact us at infor@elbowsflushing.world.
7. International Data Transfers
If we transfer your data outside the UK or EU, we ensure appropriate safeguards such as Standard Contractual Clauses or adequacy decisions are in place.
8. Data Retention
- Contact Enquiries: Retained for 2 years unless you request deletion.
- Course Records: Retained for 7 years (tax and compliance requirements).
- Analytics Data: Automatically deleted after 26 months (Google Analytics default).
- Email Lists: Retained until you unsubscribe.
9. Children's Privacy
Our services are intended for adults. We do not knowingly collect personal data from children under 16. If we become aware that a child has provided data without parental consent, we will delete it promptly.
10. Third-Party Services
Our site may use the following services:
- Google Analytics: Tracks site usage. Google Privacy Policy
- Google Maps: Displays our office location. Google Privacy Policy
- Google Ads Conversion Tracking: Tracks conversions from ads. Google Privacy Policy
- Stripe/PayPal: Payment processing. See their respective privacy policies.
These services have their own privacy policies. We recommend reviewing them.
11. Cookies & Tracking
We use cookies for:
- Essential: Site functionality and security.
- Analytics: Understanding how visitors use our site.
- Marketing: Personalised advertising through Google Ads (requires Consent Mode v2).
You can manage cookie preferences through our cookie banner at the bottom of every page.
12. Updates to This Policy
We may update this privacy policy periodically. Changes will be effective immediately upon posting. Your continued use of our site constitutes acceptance of the updated policy. We recommend reviewing this page periodically.
13. Contact Information
If you have questions about this privacy policy or your personal data, please contact us:
Elbowsflushing Ltd
Email: infor@elbowsflushing.world
Phone: +44 20 7946 0958
Address: 47 Eastcastle Street, London W1W 8DJ, United Kingdom
Data Protection Authority (UK):
Information Commissioner's Office (ICO)
www.ico.org.uk