CES Medical Ltd t/a CES Academy

Privacy Policy

How we collect, use and protect your personal data · Version 1.0 · May 2026

This Privacy Policy applies to cesacademy.co.uk and all CES Academy events and communications. It explains how CES Medical Ltd t/a CES Academy collects, uses, stores and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

CES Academy is the training and CPD platform of CES Medical Ltd (ICO Registration: ZB998269), a registered company operating surgical and clinical centres across Kent and the South East. CES Academy is registered with the General Optical Council (GOC) as a CPD provider.

CES Medical Ltd is the Data Controller for all personal data processed through CES Academy.

Data ControllerCES Medical Ltd t/a CES Academy
Registered AddressMaidstone Innovation Centre, Gidds Pond Way, Weavering, Maidstone, ME14 5FY
ICO Registration NumberZB998269
ICO Registration Expires23 September 2026
Data Protection OfficerMrs Karolina Ker — [email protected] | 07795 744533
General Contact[email protected]
Websitecesacademy.co.uk

2. What Personal Data We Collect

2.1 CPD Event Feedback Forms

When you complete a CES Academy CPD feedback form we collect:

  • Full name
  • GOC registration number
  • Email address
  • Practice name (optional)
  • Feedback ratings and comments
  • Your declaration regarding perceived commercial bias

2.2 Event Registration

When you register for a CES Academy CPD event we collect:

  • Full name and professional title
  • GOC registration number
  • Email address
  • Practice details

2.3 Website

Our website uses essential cookies to ensure the site functions correctly, and analytics cookies (with your consent). See our Cookie Policy.

3. Why We Process Your Data and Our Lawful Basis

PurposeData UsedLawful Basis (UK GDPR)
Issue GOC CPD certificates of attendanceName, GOC number, emailLegitimate Interests Art. 6(1)(f) — regulatory obligation as GOC provider
Maintain GOC audit recordsName, GOC number, attendance recordsLegitimate Interests Art. 6(1)(f) — GOC provider compliance
Improve CPD content and deliveryFeedback ratings and commentsLegitimate Interests Art. 6(1)(f) — quality improvement
Send CPD certificates and event communicationsEmail addressLegitimate Interests Art. 6(1)(f) — direct benefit to data subject
Send marketing about future eventsEmail addressConsent Art. 6(1)(a) — opt-in only

Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

4. How Long We Keep Your Data

Data typeRetention period
CPD attendance records and certificates6 years following the end of the CPD cycle (GOC requirement)
Event feedback responses6 years following the end of the CPD cycle
Marketing consent recordsUntil withdrawn or 3 years of inactivity
Website analytics26 months (rolling)

After the applicable retention period, data is securely deleted or anonymised.

5. Who We Share Your Data With

We do not sell your personal data. We may share data only in these limited circumstances:

  • The General Optical Council (GOC) — if selected for a provider audit, we may provide attendee records
  • IT service providers — hosting our systems under data processing agreements
  • Legal obligation — if required by law, court order or regulatory authority

All third-party processors are bound by data processing agreements and are required to handle your data in accordance with UK GDPR.

6. Your Rights Under UK GDPR

RightWhat this means
Right to be informedTo know how your data is used — this policy fulfils that obligation
Right of accessTo request a copy of personal data we hold about you
Right to rectificationTo correct inaccurate personal data
Right to erasureTo request deletion — note: GOC obligations may limit this during the 6-year retention period
Right to objectTo object to processing based on legitimate interests — we will respond within one month
Right to withdraw consentWhere processing is consent-based (e.g. marketing), to withdraw at any time

To exercise any right, contact [email protected] or the DPO at [email protected]. We will respond within one month. If unsatisfied, you may complain to the ICO at ico.org.uk or 0303 123 1113.

7. Data Security

  • Secure admin panel with role-based access controls
  • SSL encryption on cesacademy.co.uk
  • Access restricted to authorised CES Medical Ltd staff
  • Regular security reviews
  • Data Protection Officer appointed: Mrs Karolina Ker — [email protected] | 07795 744533

8. Changes to This Policy

We may update this policy from time to time. The version date above shows when it was last updated. We will notify registered attendees of material changes by email.

9. Contact

Data ControllerCES Medical Ltd t/a CES Academy
Registered AddressMaidstone Innovation Centre, Gidds Pond Way, Weavering, Maidstone, ME14 5FY
ICO RegistrationZB998269 (expires 23 September 2026)
Email[email protected]
Data Protection OfficerMrs Karolina Ker — [email protected] | 07795 744533
Websitecesacademy.co.uk

For data protection queries, email [email protected] with subject line 'Data Protection'.

For any privacy-related queries, contact us at [email protected]. See also our Cookie Policy and Terms & Conditions.