Last updated: 10 September 2025

1. Introduction

BritCars Ltd ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website sandy-twilight.com, use our services, or engage with BritCars Academy courses.

This policy complies with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).

2. Information We Collect

2.1 Personal Information You Provide

  • Contact Information: Name, email address, phone number, postal address
  • Account Information: Username, password, profile preferences
  • Course Enrollment: Educational background, career interests, learning preferences
  • Payment Information: Billing address, payment method details (processed securely by third-party payment processors)
  • Communication Data: Messages, feedback, survey responses, customer service interactions

2.2 Automatically Collected Information

  • Usage Data: Pages visited, time spent on site, click patterns, referral sources
  • Device Information: IP address, browser type, operating system, device identifiers
  • Location Data: General geographic location based on IP address
  • Cookie Data: Information stored by cookies and similar tracking technologies

2.3 Third-Party Information

  • Social media profile information (when you connect social accounts)
  • Information from business partners and referral sources
  • Publicly available information for business networking purposes

3. How We Use Your Information

3.1 Primary Uses

  • Service Delivery: Provide courses, consultations, and automotive cataloguing services
  • Account Management: Create and maintain your account, process payments, manage subscriptions
  • Communication: Send course materials, updates, newsletters, and respond to inquiries
  • Personalisation: Customise content and recommendations based on your interests
  • Customer Support: Provide technical support and resolve service issues

3.2 Legal Bases for Processing

  • Contract Performance: Processing necessary to fulfil our services to you
  • Legitimate Interests: Marketing, analytics, fraud prevention, business development
  • Consent: Marketing communications, non-essential cookies, special category data
  • Legal Obligation: Compliance with tax, accounting, and regulatory requirements

4. Information Sharing and Disclosure

4.1 Service Providers

We share information with trusted third-party service providers who assist in:

  • Payment processing (Stripe, PayPal)
  • Email marketing (Mailchimp, ConvertKit)
  • Web hosting and content delivery (AWS, Cloudflare)
  • Analytics and performance monitoring (Google Analytics)
  • Customer support tools (Zendesk, Intercom)

4.2 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

4.3 Legal Requirements

We may disclose information when required by law, court order, or to protect our rights, safety, or the rights of others.

4.4 We Do Not Sell Personal Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5. Data Security

5.1 Security Measures

  • Encryption: All data transmissions use SSL/TLS encryption
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Audits: Quarterly security assessments and vulnerability testing
  • Data Minimisation: We collect only necessary information and delete it when no longer needed
  • Staff Training: Regular privacy and security training for all employees

5.2 Data Breach Response

In the unlikely event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by UK GDPR.

6. Your Rights Under UK GDPR

6.1 Individual Rights

  • Right of Access: Request copies of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Opt out of marketing communications and certain processing
  • Rights Related to Automated Decision Making: Protection from automated profiling

6.2 Exercising Your Rights

To exercise any of these rights, contact us at:

  • Email: [email protected]
  • Post: Data Protection Officer, BritCars Ltd, 123 Regent Street, London W1B 4HA

We will respond to requests within one month and may require verification of your identity.

7. Cookie Policy

7.1 Types of Cookies We Use

  • Essential Cookies: Required for website functionality
  • Performance Cookies: Help us understand how visitors use our site
  • Functionality Cookies: Remember your preferences and settings
  • Marketing Cookies: Track visitors across websites for advertising purposes

7.2 Cookie Management

You can control cookies through:

  • Our cookie banner settings
  • Your browser settings
  • Third-party opt-out tools

8. Data Retention

8.1 Retention Periods

  • Account Data: Retained while your account is active plus 3 years
  • Course Records: Maintained for 7 years for certification purposes
  • Marketing Data: Retained until you unsubscribe plus 2 years
  • Financial Records: Kept for 6 years as required by UK tax law
  • Website Analytics: Anonymised after 26 months

8.2 Secure Deletion

When data reaches its retention limit, we securely delete it using industry-standard methods to ensure it cannot be recovered.

9. International Transfers

Some of our service providers are located outside the UK. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Adequacy decisions by the UK government
  • Standard Contractual Clauses (SCCs)
  • Certification schemes and codes of conduct

10. Children's Privacy

Our services are designed for adults aged 18 and over. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of significant changes by:

  • Email notification to registered users
  • Prominent notice on our website
  • Updates to the "Last updated" date above

12. Contact Information

Data Controller

BritCars Ltd
123 Regent Street
London W1B 4HA
United Kingdom

Contact Details

Supervisory Authority

If you have concerns about our data handling practices, you can contact the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Questions About This Policy?

If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us. We're committed to transparency and protecting your privacy.

Email: [email protected]