Legal
This notice describes how Executive Protection London Ltd ("Tier 1 Protection", "we", "us") — a company registered in England and Wales (company number to be inserted), with its registered office at 35 Berkeley Square, Mayfair, London, W1J 5BF — handles personal data collected through our online training platform at tier1-protection.co.uk and any subdomain (the "Platform").
We are the controller of personal data collected through the Platform. You can contact us via our contact form.
When you register, we collect your first name, last name, email address, and a hashed copy of your password (we never store the password itself in clear text). If you sign in with Google, we also receive your Google account ID and confirmation that the account's email is verified. We use this information to identify you, contact you about your account and your courses, and provide the Service.
Lawful basis: performance of our contract with you.
As you use the Platform we record which lessons you have completed, your quiz and test answers, your scores, and the time and date of each attempt. This is necessary to deliver the Service, enforce per-test cooldowns, generate certificates, and prevent abuse.
Lawful basis: performance of our contract with you; legitimate interests in maintaining the integrity of our certifications.
Before a certificate is issued, you complete a one-time identity check operated by Stripe Identity (a service of Stripe Payments Europe, Ltd.). Stripe collects an image of a government-issued document and a short live selfie directly from you and processes them on its own infrastructure. We do not see, receive, or store those images. Stripe returns to us only the verified first name, last name, and the issuing country, plus a verification timestamp and a Stripe session reference. These appear on your certificate and remain on your account.
Lawful basis: performance of our contract with you; legitimate interests in preventing forged or impersonated certificates. For more on Stripe's processing, see Stripe's privacy notice at stripe.com/privacy.
Payments for course access are processed by Stripe. We do not see or store your full card number, expiry, CVC, or banking credentials. We retain a record of each purchase (course or bundle, amount, currency, Stripe session reference, date) for accounting, refunds, dispute handling, and legal record-keeping.
Lawful basis: performance of our contract with you; compliance with our legal accounting and tax obligations.
While you take a final test, the Platform captures periodic webcam snapshots through your browser. These images are reviewed by an administrator to confirm the integrity of the test attempt. The Platform may also record signals such as tab-switching or loss of window focus during a test.
Retention. Snapshots are deleted as soon as they are no longer required:
Proctoring snapshots are not used for any purpose other than reviewing the integrity of that specific test attempt, and they are not shared with third parties.
Lawful basis: performance of our contract with you (the certificate is conditional on a proctored test); legitimate interests in preventing test fraud and protecting the value of our certifications.
We set a single, strictly necessary session cookie when you log in. The cookie holds only an opaque session identifier; it does not contain your name, email, or any other personal data. We send time-limited links by email for password resets (valid for 1 hour), email-address verification (48 hours), and email-address change confirmation (48 hours).
Lawful basis: performance of our contract with you. The session cookie is "strictly necessary" and does not require your consent under UK GDPR / PECR.
Our servers automatically log routine technical information about each request — IP address, request URL, response status, user-agent, and timestamp — for the purposes of troubleshooting, abuse prevention, rate-limiting, and security monitoring. These logs are retained for a short period (typically 30 days) and then rotated.
Lawful basis: legitimate interests in keeping the Service secure and operational.
If you submit our public contact form, we receive your name, email, and the message you wrote. We use this to reply to you and, if appropriate, to keep a record of the enquiry.
Lawful basis: legitimate interests in responding to enquiries; performance of pre-contractual steps where you are asking about our services.
We use only one cookie: a strictly necessary session cookie that keeps you signed in. We do not use analytics, advertising, or third-party tracking cookies on the Platform. Some pages load the Inter and Instrument Sans webfonts via Google Fonts; Google Fonts does not set cookies in the user's browser, but Google may log the request as part of providing the font. If you would prefer not to load fonts from Google, you may block requests to fonts.googleapis.com and fonts.gstatic.com in your browser; the Platform will fall back to your system fonts.
We share personal data only with service providers we engage to run the Service and only to the minimum extent needed for them to perform their role:
We do not sell personal data, and we do not share personal data for the purposes of cross-context advertising. We may disclose data where we are required to by law, court order, or other legal process, or where it is necessary to protect our rights or the safety of others.
Some of our service providers (notably Stripe and Google) may process personal data outside the United Kingdom, including in the United States. Where this happens, the transfer is covered by a UK-recognised mechanism — typically the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, the UK extension to the EU-US Data Privacy Framework, or another mechanism approved by the UK Information Commissioner's Office — ensuring an essentially equivalent level of protection.
We keep different categories of data for different periods:
We use industry-standard measures to protect your data, including encryption in transit, secure password hashing, server-side session management, hardened server configuration, and access controls limiting administrator access to authorised staff. No service is perfectly secure; if a personal-data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office within 72 hours and, where required, notify you directly.
Under UK GDPR you have the right to:
To exercise any of these rights, get in touch via our contact form. We will respond within one month, in line with UK GDPR.
The Platform is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it.
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent changes. Where changes materially affect how we use your personal data, we will notify registered users by email or in-app notice.
Privacy questions, data requests, or complaints can be sent via our contact form or in writing to the address in Section 1.