Privacy Policy —
Med Device PM Academy
Last updated: 02/07/2026
This Privacy Policy explains how Med Dev Services Ltd ("we", "us", "our"), trading as Med Device Academy / PM Academy, collects, uses and protects your personal data when you visit learn.meddeviceacademy.co.uk (the "Site") or enrol in the PM Academy.
We are committed to protecting your privacy and handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are (Data Controller)
The data controller responsible for your personal data is:
- Business name: Med Dev Services Ltd
- Address: 4 Kings End Road, Powick, Worcester, Worcestershire, WR2 4RA. England
- Email: [email protected]
If you have any questions about this policy or your data, contact us at the email above.
2. The personal data we collect
Depending on how you use the Site, we may collect:
- Account and identity data — your name, email address, username, and password when you create an account or enrol.
- Payment data — billing name, billing address and country, and transaction details. Card payments are processed securely by our payment provider; we do not see or store your full card number.
- Course activity data — which modules and lessons you access, quiz results, progress, downloads, and community activity.
- Communications data — messages you send us, support requests, and your marketing preferences.
- Technical data — IP address, browser type, device information, and pages visited, collected through cookies and similar technologies (see Section 8).
3. How we collect your data
We collect data when you:
- create an account, enrol, or purchase a course or the free taster module;
- complete lessons, quizzes, or take part in the PM Academy Community;
- contact us or request a consultation or quote;
- browse the Site (via cookies).
Our platform provider, Thinkific, and our payment provider collect some of this data on our behalf.
4. How we use your data and our legal basis
| What we use it for | Legal basis under UK GDPR |
|---|---|
| Creating and managing your account, giving you access to purchased courses | Performance of a contract |
| Processing payments and sending receipts | Performance of a contract |
| Providing customer support | Performance of a contract / legitimate interests |
| Tracking course progress and issuing certificates | Performance of a contract |
| Sending service emails (e.g. enrolment, updates to content you bought) | Performance of a contract / legitimate interests |
| Sending marketing emails about new courses or offers | Consent (you can opt out at any time) |
| Improving the Site and understanding how it is used | Legitimate interests |
| Meeting legal, tax and accounting obligations | Legal obligation |
| Preventing fraud and keeping the Site secure | Legitimate interests |
5. Who we share your data with
We do not sell your personal data. We share it only with trusted providers who help us run the Academy:
- Thinkific — our course hosting and learning platform.
- PAYMENT PROVIDER — e.g. Thinkific Payments / Stripe— to process payments securely.
- Professional advisers — such as our accountant, where necessary.
- Authorities or regulators — where we are legally required to do so.
Each provider is only permitted to use your data to provide their service to us.
6. International transfers
Some of our providers (including Thinkific) may store or process data outside the UK, for example in Canada, the EU or the USA. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as UK-approved standard contractual clauses or an adequacy decision.
7. How long we keep your data
We keep your personal data only as long as necessary:
- Account and course data — for as long as your account is active, and for a reasonable period afterwards.
- Payment and transaction records — retained for at least 6 years to meet UK tax and accounting law.
- Marketing data — until you unsubscribe or ask us to delete it.
When data is no longer needed, we securely delete or anonymise it.
8. Cookies
The Site uses cookies and similar technologies to make it work, to remember your login, and to understand how the Site is used. You can control or disable cookies through your browser settings, though some features may not work properly without them. [If you add a cookie banner, reference it here.]
9. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- erase your data ("right to be forgotten"), where applicable;
- restrict or object to how we process your data;
- data portability — receive your data in a portable format;
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email us at [email protected]. We will respond within one month. You can unsubscribe from marketing emails at any time using the link in each email.
10. Marketing
We will only send you marketing emails if you have agreed to receive them. You can opt out at any time by clicking "unsubscribe" in any email or by contacting us. Opting out of marketing will not stop essential service messages about a course you have purchased.
11. Children
The PM Academy is intended for professionals and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Data security
We take reasonable technical and organisational measures to protect your data against loss, misuse and unauthorised access. Our platform and payment providers use industry-standard security, including encryption of payment data.
13. Changes to this policy
We may update this policy from time to time. The latest version will always be posted on this page with an updated "Last updated" date. Significant changes will be communicated to you where appropriate.
14. How to complain
If you have a concern about how we handle your data, please contact us first at [email protected] so we can try to resolve it.
You also have the right to complain to the UK regulator:
Information Commissioner's Office (ICO) Website: ico.org.uk Helpline: 0303 123 1113