Privacy Policy
Last updated: 25 May 2026
This Privacy Policy explains how CoomberSewell Training CIC collects, uses, stores, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all other applicable data protection legislation. As a specialist autism training provider, we handle some information that may be of a sensitive nature. Please read this policy carefully before using our website or services.
- Who We Are
CoomberSewell Training CIC ('we', 'us', 'our') is a Community Interest Company (CIC) registered in England and Wales. We are an autism specialist training provider, delivering services to autistic individuals, families, friends, carers, academics, and business professionals. Our services include specialist autism training courses, webinars, face-to-face training, podcasts, and autism awareness programmes for organisations and individuals.
We work in partnership with our sister company, CoomberSewell Enterprises LLP, which provides additional study skills and editorial services. Each company operates as a separate Data Controller for the personal data it holds.
CoomberSewell Training CIC is the Data Controller for all personal information collected through training.coombersewell.co.uk and any associated platforms.
Contact Details
- Website: coombersewell.co.uk
- Email: training@coombersewell.co.uk
- Telephone: 07789 685185
- Important Note on Sensitive Personal Data
Because we are an autism specialist training provider, some of the personal data we collect may relate to health, disability, or neurodiversity — including whether you or someone you support is autistic. Under the UK GDPR (Article 9), this is classified as 'special category' personal data and is afforded the highest level of legal protection. We only collect this type of information where it is strictly necessary to deliver our services or where you have given your explicit consent. You are never required to disclose your neurodivergent status to use our services.
We approach all personal data with sensitivity and respect. We recognise that autism is a distinct way of thinking and being, not a disorder, and we handle all related data accordingly.
- What Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
Identity & Contact Data
- Full name and preferred name
- Email address
- Telephone number
- Postal address (where required for service delivery)
- Organisation or institution name (where applicable)
Account & Membership Data
- Username and encrypted password for the membership portal
- Membership type and subscription status
- Training history, bookings, and virtual workshop attendance
- Communication preferences
Training & Service Data
- Course or webinar registrations and completion records
- CPD (Continuing Professional Development) records where applicable
- Information about your role (e.g. autistic individual, family member, professional, employer) where you choose to share this to help us tailor our services
Special Category Data (collected only with explicit consent or where strictly necessary)
- Information relating to neurodivergent status, autism diagnosis, or disability — only where you voluntarily disclose this to help us adapt our training or communication style to your needs
- Support or accessibility requirements you choose to share with us
Financial & Payment Data
- Payment confirmation records and transaction references
- Card payment details — these are processed securely by Stripe and are never stored on our own systems
Usage & Technical Data
- IP address, browser type, and device information
- Pages visited and time spent on the website
- Cookie data (see Section 11)
- How We Collect Your Personal Data
We collect personal data through the following means:
- Contact forms on our website when you make an enquiry about our training or autism services.
- Membership sign-up forms when you register for an account or subscribe to our training portal.
- Booking forms when you reserve a place on a webinar, face-to-face course, or training event.
- Payment processes via Stripe when you purchase a course, training package, or membership subscription.
- Voluntary disclosure during registration or service use, where you choose to share information about your neurodivergent status or accessibility needs.
- Email correspondence when you contact us directly.
- Automated technologies including cookies, log files, and analytics tools when you browse our website.
- Why We Use Your Personal Data and Our Lawful Basis
Under the UK GDPR, we must have a lawful basis for processing your personal data. For most data, we rely on one of the standard bases below. For any special category data (such as information about neurodivergent status), we rely on explicit consent or, where applicable, the substantial public interest condition under Schedule 1 of the Data Protection Act 2018.
|
Purpose of Processing |
Lawful Basis (UK GDPR) |
|
To respond to enquiries submitted via contact forms |
Legitimate interests / Pre-contractual steps |
|
To create and manage your membership or training account |
Contract performance |
|
To provide access to the membership portal, virtual workshops, and training materials |
Contract performance |
|
To process payments securely via Stripe |
Contract performance |
|
To send booking confirmations, course reminders, and service communications |
Contract performance |
|
To adapt our training or communication to your stated accessibility or support needs |
Explicit consent (special category data) |
|
To send marketing emails, newsletters, and training updates |
Consent (you may withdraw at any time) |
|
To send service updates, policy changes, and important notices |
Legitimate interests |
|
To comply with legal, regulatory, or contractual obligations |
Legal obligation |
|
To maintain CPD records and training completion evidence |
Legitimate interests / Legal obligation |
|
To improve our website and services through analytics |
Legitimate interests |
|
To maintain records for accounting, tax, and dispute resolution |
Legal obligation / Legitimate interests |
- Special Category Data — Additional Safeguards
As an autism specialist organisation, we may occasionally receive information from you that touches on neurodivergent status, mental health, or disability. This is defined as special category data under Article 9 of the UK GDPR and is subject to the following additional safeguards:
- We will only ask for or record this type of information where you have given your explicit consent, or where it is strictly necessary to tailor a service to your needs.
- This information will be held securely, accessible only to authorised members of the CoomberSewell Training CIC team on a strict need-to-know basis.
- You may withdraw your consent to us holding this information at any time by emailing training@coombersewell.co.uk. Withdrawal will not affect any processing already carried out.
- We will never use your neurodivergent status or disability information for any purpose other than delivering or adapting our services to you, or as required by law.
You are never obligated to share information about a diagnosis or neurodivergent status to access our training or services.
- The Fuzzy Logic System — Data Synchronisation
Information you submit through our website — including contact forms, membership registrations, booking requests, and payment confirmations — is automatically synchronised with our internal customer relationship and operations platform, the Fuzzy Logic System.
This platform allows us to manage client relationships, coordinate training delivery, track service agreements, and communicate with you through our membership portal. Any special category data is handled within this system under the same strict access controls and data protection obligations that apply across all our operations.
If you have questions about how your data is handled within this system, please contact us at training@coombersewell.co.uk.
- Stripe — Payment Processing
We use Stripe, Inc. as our payment processor for all financial transactions, including course payments and membership subscriptions. When you make a payment on our website, you enter your card details directly into Stripe's secure, PCI-DSS compliant payment environment. We do not store, access, or retain your full card details at any point.
Stripe processes your payment data under its own Privacy Policy and Terms of Service. We encourage you to review these at stripe.com/gb/privacy. We receive from Stripe only the confirmation information necessary to record that a transaction has taken place.
- Membership Portal, Virtual Workshops, and Training Records
Our membership portal gives registered members access to virtual workshops, recorded training sessions, autism resources, and direct communication with our team. When you register as a member or book onto a training event, we collect and process the data necessary to manage your account, authenticate your access, track your training history and CPD record, and provide a tailored member experience.
CPD and course completion records may be retained for longer than standard data retention periods where you have requested a CPD certificate or professional record, or where our accreditation obligations require us to do so. We will inform you of any extended retention at the time of your booking.
Communications sent through the membership portal — including booking confirmations, course reminders, and training updates — are service communications necessary for delivery of your membership and are not subject to marketing consent requirements.
- Marketing Communications
Where you have given your explicit consent, we may contact you with information about our upcoming training courses, webinars, autism resources, podcasts, and relevant news from CoomberSewell Training CIC. This may be delivered by email newsletter or other agreed channels.
You can withdraw your consent at any time by:
- Clicking the 'Unsubscribe' link at the bottom of any marketing email we send you.
- Emailing us at training@coombersewell.co.uk with the subject line 'Unsubscribe'.
Withdrawal of marketing consent does not affect service communications related to active bookings or membership, nor the lawfulness of any processing already carried out.
- Cookies
Our website uses cookies to support core functionality, improve your browsing experience, and help us understand how our site is used. These may include:
- Strictly necessary cookies required for site security and functionality.
- Analytical cookies that help us understand visitor behaviour (e.g. Google Analytics).
- Functional cookies that remember your preferences and settings.
Where non-essential cookies are used, we will request your consent via our cookie banner when you first visit the site. You may manage or withdraw cookie consent at any time through your browser settings or our cookie management tool.
- How Long We Keep Your Personal Data
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our general retention periods are as follows:
- Enquiry and contact form data: 2 years from date of last contact, or until the matter is resolved.
- Training bookings and service agreement records: 6 years from the end of the contractual relationship (Limitation Act 1980).
- Financial and payment records: 6 years from the end of the tax year to which they relate (HMRC requirement).
- Membership account data: For the duration of membership, plus 2 years from account closure.
- CPD and course completion records: Up to 7 years, or as required by our CPD accreditation obligations.
- Special category data (neurodivergent / disability information): Retained only for as long as necessary to deliver the adapted service; deleted promptly when no longer required or upon your request.
- Marketing consent records: Until you withdraw consent, plus 1 year to evidence compliance.
- Technical and website usage data: Up to 24 months, depending on the analytics service used.
When personal data is no longer required, it will be securely deleted or anonymised in accordance with our internal data retention and disposal procedures.
- Who We Share Your Data With
We do not sell, rent, or trade your personal data. We may share it with trusted third-party service providers only where strictly necessary to deliver our services:
- Stripe: our payment processor for all financial transactions.
- Fuzzy Logic System: our internal platform for managing client data, communications, and training delivery.
- Email marketing platform: used to manage and send email newsletters and marketing communications where applicable.
- Analytics providers: such as Google Analytics, to help us understand how our website is used.
- CoomberSewell Enterprises LLP: our sister company, for clients who use services across both organisations, only where you have been made aware of this sharing.
All third-party processors are contractually required to handle your data securely and in compliance with applicable data protection law. They may not use your data for their own purposes. We do not transfer special category data to any third party except where required by law or with your explicit consent.
- Your Rights Under UK GDPR
Under the UK General Data Protection Regulation and the Data Protection Act 2018, you have the following rights in relation to your personal data:
- Right to be informed: To know how and why we use your personal data, as set out in this policy.
- Right of access: To request a copy of the personal data we hold about you (Subject Access Request).
- Right to rectification: To ask us to correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure: To request that we delete your personal data where there is no compelling reason for its continued processing ('right to be forgotten').
- Right to restrict processing: To ask us to pause processing of your personal data in certain circumstances.
- Right to data portability: To receive your personal data in a structured, commonly used, machine-readable format.
- Right to object: To object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: To withdraw consent for processing of special category data or marketing at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Rights relating to automated decision-making: Not to be subject to decisions made solely by automated processing where these produce significant effects on you.
To exercise any of your rights, please contact us at training@coombersewell.co.uk. We will respond within one calendar month. We may need to verify your identity before processing your request. There is no charge for standard rights requests.
- How to Remove or Manage Your Information
You have several options to manage, update, or request the removal of your personal data:
- Unsubscribe from newsletters: Click the 'Unsubscribe' link at the bottom of any marketing or newsletter email to opt out of future marketing communications immediately.
- Request data deletion by email: Email training@coombersewell.co.uk requesting deletion of your account, personal data, or specific records. Please include your full name and the email address associated with your account.
- Update your account settings: Log in to your account and update your details or communication preferences directly.
Please note that we may be required by law to retain certain records (such as financial, CPD, or contractual records) for specified periods even after a deletion request. We will inform you of any such retention and the reason for it at the time of your request.
- Data Security
We take the security of your personal data seriously — particularly given that we may hold information of a sensitive nature. We have implemented appropriate technical and organisational measures including:
- Secure HTTPS encryption across our website.
- Password protection and role-based access controls for internal systems.
- Restricted access to special category data on a strict need-to-know basis.
- PCI-DSS compliant payment processing via Stripe.
- Regular review of data handling practices and access permissions.
If you have concerns about the security of your data, please contact us at training@coombersewell.co.uk immediately.
- International Data Transfers
Some of our third-party service providers, including Stripe, may process your personal data outside of the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place in line with UK GDPR requirements — for example, through the use of UK International Data Transfer Agreements (UK IDTAs) or other mechanisms approved by the Information Commissioner's Office (ICO). Special category data is not transferred internationally without your explicit consent.
- Your Right to Complain to the ICO
If you are not satisfied with how we have handled your personal data or responded to a rights request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns directly before you contact the ICO. Please email us first at training@coombersewell.co.uk.
- Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the 'Last updated' date at the top of this document and, where appropriate, notify you by email or through a notice on our website. We encourage you to review this policy periodically.
- Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us:
- Organisation: CoomberSewell Training CIC
- Email: training@coombersewell.co.uk
- Telephone: 07789 685185
- Website: coombersewell.co.uk
CoomberSewell Training CIC | training.coombersewell.co.uk | training@coombersewell.co.uk
