1. Who we are
Fitness To Practice is a trading name of Fitness to Practise ("we", "us"). We are responsible for (the "controller" or "agency" holding) the personal information described in this policy. For any privacy question or request, email support@fittopractisesg.com with "Privacy" in the subject line, or use our contact page.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account details | Name (as it appears on your certificate), email address, password (stored encrypted), country edition chosen | You |
| Optional profile details | Profession or job title, employer, if you choose to give them | You |
| Order and payment records | Courses bought, price, currency, date, billing name and address, payment status | You and our payment provider |
| Learning records | Course progress, knowledge-check and final assessment answers and scores, completion dates, certificates issued | Created as you use courses |
| Reflective accounts | The text you write in the reflective account template | You |
| Messages | Emails and contact form messages, including group enquiries | You |
| Technical and usage data | IP address, browser and device type, pages visited, cookie identifiers | Your device, our website and analytics tools |
We do not collect your full card number. Card payments are handled by our payment provider, which gives us only a confirmation and limited details such as card type and last four digits.
Please do not enter patient information. We are not a health care provider and do not need any information about your patients or clients. Keep reflections and messages de-identified. If you do include such information, we will treat it confidentially, but we may delete it.
3. Why we use your information
| Purpose | Legal basis (where GDPR-style rules apply) |
|---|---|
| Create and run your account, give access to courses, save progress, mark assessments and issue certificates | Performing our contract with you |
| Process payments, refunds and invoices; keep tax and accounting records | Contract; legal obligation |
| Reply to messages and support requests | Contract; legitimate interests |
| Keep the website secure, prevent fraud and certificate misuse | Legitimate interests; legal obligation |
| Understand how the site is used and improve courses | Legitimate interests; consent for non-essential cookies |
| Send course updates or marketing emails | Consent, which you can withdraw at any time using the unsubscribe link |
We only collect information that we need for these purposes. We do not use your information for automated decisions that have legal or similarly significant effects on you.
4. Your answers and reflections stay private
Your assessment answers and reflective accounts are private to your account. We never share them with any regulator, responsible authority, tribunal, state board, employer or professional body unless you ask us to, or we are legally required to (for example by a court order or a lawful request we cannot refuse). If we receive such a demand, we will tell you unless the law prevents us.
You control what you download and who you share it with. Remember that written reflections you share may be disclosable in some legal or regulatory processes, so keep them de-identified and take advice if you are involved in a live case.
5. Who we share information with
We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising. We share it only with service providers (data processors) who help us run the website, under contracts requiring them to protect it and use it only on our instructions:
- Payment provider: to take card payments and process refunds securely
- Website hosting and learning platform providers: to store and run the website, accounts and courses
- Email service providers: to send order confirmations, account emails and messages you have agreed to receive
- Analytics provider: to measure site use, where you have allowed analytics cookies
- Professional advisers: such as accountants or lawyers, where needed
We may also disclose information where the law requires it, to protect our rights or users' safety, or to a buyer if our business is sold (in which case this policy will continue to apply). If you enrol through an employer group, we share completion status with that employer only where you have been told about this at enrolment; we do not share your reflections or answers.
6. International transfers
Our service providers may store or process information outside the country where you live, including in New Zealand, the United States, Australia or the European Union. When information leaves your country, we take reasonable steps to make sure it is protected to a standard comparable to the law that applies to you, for example through contractual safeguards. This includes meeting the cross-border disclosure requirements of the New Zealand Privacy Act 2020.
7. How long we keep information
- Account and learning records, certificates and reflective accounts: while your account is open, and for 7 years after your last course activity, so that you can retrieve or we can verify your certificate. You can ask us to delete your account sooner.
- Order and payment records: for as long as tax and accounting laws require.
- Support messages: 2 years after the matter is closed.
- Analytics data: in line with the analytics provider's retention settings, no longer than 26 months.
After these periods we delete or anonymise the information.
8. Cookies and analytics
We use essential cookies to keep you logged in, run the shopping cart and checkout, and remember the country edition you chose. These are needed for the site to work. With your consent, we also use analytics cookies to understand how visitors use the site. You can accept or decline non-essential cookies in the cookie banner and change your choice at any time; you can also block cookies in your browser, although some features may then not work.
9. Security and breaches
We use reasonable safeguards to protect your information, including encrypted connections (HTTPS), encrypted passwords, access controls and reputable service providers. No online service is completely secure. If a privacy breach is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires, including the Office of the Privacy Commissioner in New Zealand.
10. Your rights
Wherever you live, you can ask us to:
- access the personal information we hold about you;
- correct information that is wrong or out of date (for example, the name on your certificate);
- delete your account and personal information, subject to records we must keep by law;
- receive a copy of information you gave us in a portable format;
- object to or restrict certain uses, and withdraw consent to marketing or analytics at any time.
Email support@fittopractisesg.com to make a request. We will need to confirm your identity, and we will respond within 20 working days (or sooner where your local law requires). We will not charge you or treat you differently for using your rights.
11. New Zealand: Privacy Act 2020
If you are in New Zealand, we handle your information in line with the Privacy Act 2020 and its information privacy principles. You have the right to access and request correction of your personal information. Since 1 May 2026, information privacy principle 3A requires agencies that collect personal information about you indirectly (from someone other than you) to let you know; for example, if an employer enrols you in a course, we will tell you that we hold your information and why. If you are not satisfied with how we handle a privacy concern, you can complain to the Office of the Privacy Commissioner.
12. United States: state privacy rights
If you live in the United States, some states (for example California, and a growing number of others) give residents specific privacy rights, such as the right to know what personal information is collected, to delete or correct it, and to opt out of its sale, sharing for targeted advertising or profiling. We do not sell your personal information or use it for targeted advertising, and we honor the rights listed above for all US users whether or not a state law requires it. You may use an authorized agent to make a request where your state law allows. If we deny a request, you can appeal by replying to our decision. We are not a HIPAA covered entity; please do not send us protected health information about patients.
13. Children
Our courses are for health professionals and are not directed at children. We do not knowingly collect information from anyone under 16.
14. Changes to this policy
We may update this policy when our services or the law change. The current version is always on this page with its date. If we make a significant change, we will tell account holders by email or on the website. See also our terms of use.
Official sources
Checked October 2026. Rules and processes change, so confirm the current position with the official source. This page is general information, not legal advice.