Privacy Policy

Last updated: 25 August 2026

1. Who We Are

Serene Safety is a Norwich-based health and safety consultancy and training provider. We are the data controller for the personal data described in this policy.

  • Registered address: 2 Mill Lane, Horsford, Norwich, NR10 3ET, United Kingdom
  • Phone: 01603 975536
  • Email: [email protected]
  • Data controller: Jonathan Reynolds, Serene Safety

2. What Data We Collect

We collect different categories of personal data depending on how you interact with us:

Contact enquiries

When you submit a contact form or email us, we collect your name, email address, phone number (optional), company name (optional), and the content of your message.

Course bookings

When you book a training course, we collect your name, email address, phone number, company name, and the number of delegates. Payment details (card number, bank details) are collected and processed directly by Stripe - we do not store payment card information on our systems.

Delegate onboarding

For each delegate attending a course, we collect: first name, last name, email address, phone number, company, job title, dietary requirements, access needs, emergency contact name and phone number, and prior qualifications.

Delegate portal accounts

When you use the delegate portal to access course materials, we record your email address, login timestamps, course progress, and any quiz or exercise responses you submit.

Website usage

We use two analytics tools, and both load only after you accept analytics cookies via the banner. If you decline, neither runs and no analytics cookies are set.

  • Google Analytics 4 — aggregate statistics: how many people visit, which pages they read, and which site or search engine sent them.
  • Microsoft Clarity — records how pages are used (clicks, scrolling, mouse movement and the order pages are viewed in) so we can see where the site is confusing and fix it.

Clarity recordings are limited on purpose. Anything you type into a form — your name, email address, phone number, message, or any other field — is hidden before the recording leaves your browser, so we never see it. Recording is switched off entirely on the pages that handle personal data: course booking, delegate enrolment, the delegate portal, certificate verification and the admin area. We do not use the recordings to identify individuals, and we do not use any advertising or remarketing trackers.

Marketing list

If you opt in to our newsletter (footer signup form, or the "Subscribe me" checkbox on the contact or booking forms), we collect your email, first name, surname, and (optionally) company name so we can send Health & Safety insights and course-date announcements. You can unsubscribe at any time using the link at the bottom of every marketing email.

Certificate verification

If you complete a Serene-Safety-issued course we issue a completion certificate with a unique verification code. The verification page (/verify/<code>/) is public and shows your name, the course you completed, and the dates — this lets employers confirm the certificate is authentic. Only the data shown on the certificate itself is published; nothing else (email, phone, company) appears on the verification page.

3. How We Use Your Data

We only process your personal data where we have a lawful basis to do so under UK GDPR. The table below sets out each purpose and its legal basis:

PurposeData usedLegal basis
Responding to your contact enquiryName, email, phone, messageLegitimate interest - responding to your request
Processing your course booking and paymentName, email, phone, company, payment detailsContract performance - fulfilling the booking you have made
Course delivery and delegate managementDelegate name, email, phone, company, job title, prior qualificationsContract performance and legitimate interest - delivering the training service and ensuring course suitability
Catering and reasonable adjustmentsDietary requirements, access needsExplicit consent - this is special category data under UK GDPR and is only processed with your consent
Emergency situations during trainingEmergency contact name and phoneVital interests - protecting your health and safety
Delivering course materials via the delegate portalEmail, course progress, quiz/exercise responsesContract performance - part of the training service
Marketing communications (newsletter, course announcements)Email, first name, surname, company (optional)Consent — collected via the footer signup or an opt-in checkbox on the contact / booking forms. Every marketing email contains a one-click unsubscribe link.
Live classroom delivery (audio / video / chat)Display name + audio / video stream while in the sessionContract performance — running the live training session you booked. Streams are not recorded by us unless explicitly arranged in advance.
Certificate verification (public)Name, course name, issue dateLegitimate interest — allowing employers to verify the qualification you have presented. You can request revocation at any time.
Understanding how the website is usedPages viewed, referring site or search engine, approximate location, device and browser type, and — for usage recordings — clicks, scrolling and mouse movementConsent — given via the cookie banner, and never assumed. Nothing is collected until you accept analytics cookies, and you can withdraw at any time using the “Cookie preferences” link in the footer.

4. Who We Share Your Data With

We share your personal data with the following third-party processors. Each is bound by a data-processing agreement; we have selected providers with strong UK / EU data-protection track records.

  • Stripe — payment processing. Handles card, Klarna, PayPal and Pay by Bank transactions. Card details never touch our servers. Stripe Privacy Policy
  • Resend — transactional and marketing email delivery (booking confirmations, magic-link logins, contact-form notifications, weekly digest, certificate alerts). Resend Privacy Policy
  • Railway — application hosting (Node.js server) and managed Postgres database, EU region. Railway Privacy Policy
  • Cloudflare — CDN, R2 object storage (course materials, document uploads), and DNS. Cloudflare Privacy Policy
  • Cloudflare Stream — video hosting and adaptive-bitrate playback for course videos. The video bytes are uploaded directly from your browser to Cloudflare; we never see the file contents. Cloudflare Privacy Policy
  • Jitsi Meet — live classroom audio / video conferencing. Sessions are not recorded by us unless explicitly arranged. Jitsi Meet Privacy Notice
  • Google — Google Analytics 4 (only if you accept analytics cookies via the banner) and Google Places (used to fetch our public review widget on the home page). Google Privacy Policy
  • Microsoft — two separate uses. Where in-person training requires SharePoint document sync we transfer delegate first / last name and email to a private SharePoint list; that is not used for marketing or analytics. Separately, Microsoft Clarity provides the website usage recordings described in section 2, but only if you accept analytics cookies. Microsoft Privacy Statement
  • NEBOSH and IOSH — where required for course registration, examination booking and accreditation, we share delegate names and (where required) date of birth and results with the relevant awarding body.
  • Sentry — error monitoring. Captures unexpected errors only; we configure it to scrub email addresses and other identifying data from error reports.

We do not sell your personal data to any third party. Where a processor stores data outside the UK or EEA we rely on an adequacy decision or Standard Contractual Clauses as the lawful transfer mechanism.

5. How Long We Keep Your Data

We retain your data only for as long as necessary for the purpose it was collected, or as required by law:

Data typeRetention periodReason
Contact form submissions12 monthsSufficient to respond to and follow up on enquiries
Booking and payment records6 yearsHMRC tax record requirements
Delegate training records6 yearsIndustry standard for training records; regulatory and insurance requirements
Portal accounts and course progressDuration of course + 12 monthsTo allow access to materials after course completion
Quiz and exercise responsesDuration of course + 12 monthsTo allow review and certification processes
Website analytics (Google Analytics 4)2 months for event data; 14 months for visitor-level dataThe shortest periods Google offers that still allow year-on-year comparison. Aggregate reporting totals are unaffected.
Website usage recordings (Microsoft Clarity)30 days, then deleted automaticallyLong enough to spot and fix a usability problem. A small random sample, and any recording we bookmark, is kept by Microsoft for up to 9 months; heatmaps, which are aggregate and not tied to an individual, are kept for up to 9 months.

After the retention period expires, data is securely deleted or anonymised.

6. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access - you can request a copy of all personal data we hold about you (a Subject Access Request).
  • Right to rectification - you can ask us to correct any inaccurate or incomplete data.
  • Right to erasure - you can ask us to delete your personal data. Where we are legally required to retain records (e.g. for HMRC tax purposes), we will anonymise the data instead of deleting it.
  • Right to restrict processing - you can ask us to limit how we use your data while a concern is resolved.
  • Right to data portability - you can request your data in a structured, machine-readable format.
  • Right to object - you can object to processing based on legitimate interest.
  • Rights related to automated decision-making - we do not currently make any automated decisions about you.

To exercise any of these rights, please email [email protected]. We will respond within one month of receiving your request.

If you are not satisfied with how we handle your request, you have the right to complain to the Information Commissioner’s Office (ICO):

7. Cookies

Our website uses a small number of cookies:

Strictly necessary cookies

These cookies are essential for the website to function and cannot be switched off:

CookiePurposeDuration
admin_sessionAuthenticates admin dashboard sessionsSession (expires on browser close or after 24 hours)
serene_portal_sessionAuthenticates delegate portal sessionsSession (expires on browser close or after 7 days)

Analytics cookies

These are set only if you accept analytics cookies. They are not required for the site to work, and you can withdraw consent at any time using the “Cookie preferences” link in the footer.

CookiePurposeDuration
_ga, _ga_*Google Analytics 4 — distinguishes one visitor from another so visit counts are accurateUp to 2 years
_clck, _clskMicrosoft Clarity — links the pages viewed in a single visit into one usage recording1 year and 1 day respectively

Marketing cookies

We do not currently use any marketing or advertising cookies.

Third-party embeds

Some pages may include embedded content from third parties (e.g. Google Maps on our contact page, Vimeo or Microsoft Teams video on the delegate portal). These services may set their own cookies. Please refer to their respective privacy policies for details.

8. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:

  • Encryption in transit - all data is transmitted over HTTPS/TLS.
  • Encryption at rest - data stored on Cloudflare’s edge network is encrypted at rest.
  • Access controls - admin access requires authentication. Personal data is only accessible to authorised personnel.
  • Payment security - payment card details are handled entirely by Stripe, a PCI DSS Level 1 certified provider. We never see or store your full card number.
  • Regular reviews - we regularly review our security measures and update them as necessary.

9. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

10. Contact Us

If you have any questions about this privacy policy or how we handle your personal data, please contact us: