Privacy Policy

How we collect, use, and protect your personal data when you visit our website or enrol in our course.

Our commitment to your privacy

We treat your personal data with the same care we apply to our own business records. This policy sets out exactly what information we gather, why we need it, how we store it, and who has access to it. We designed our data practices to comply with the UK General Data Protection Regulation and the Data Protection Act 2018.

By using our website or purchasing our course, you confirm that you have read and understood this policy. If any term is unclear, please contact us before proceeding. We update this document when our processing activities change or when regulatory guidance evolves. The effective date at the top of the page tells you when the last revision took place.

Information we collect

We collect only the data necessary to deliver our course, process payments, respond to enquiries, and improve our website. We never purchase marketing lists or scrape publicly available profiles. The information we hold falls into two categories: data you provide directly and data collected automatically through our systems.

Data you provide to us

  • Identity details: your full name, email address, and telephone number when you submit a contact form or enrol.
  • Payment information: billing address and transaction records processed through our third-party payment gateway.
  • Communication records: messages you send through our contact page, email, or course forum.
  • Account credentials: the username and encrypted password you create to access course materials.
  • Course progress data: module completion status, quiz scores, and feedback you submit during the training.

Data collected automatically

  • Technical identifiers: your IP address, browser type, operating system, and device category.
  • Usage patterns: pages visited, time spent on each module, and links clicked.
  • Referral source: the website or search term that brought you to our Bilarexion.
  • Session recordings: anonymised interaction data that helps us fix usability issues.
  • Cookie data: preferences and session tokens as described in our Cookie Policy.

How we use your data

We process personal data on specific legal bases defined by UK data protection law. For each processing purpose listed below, we identify the lawful ground that applies. We do not use your data for automated decision-making or profiling that produces legal effects.

  • Contract performance: to create your account, grant course access, and deliver the training you purchased.
  • Payment processing: to transmit transaction details to our payment service provider and issue receipts.
  • Customer support: to respond to your enquiries, troubleshoot technical issues, and process refund requests.
  • Service improvement: to analyse aggregated usage data and identify which course modules need refinement.
  • Legal compliance: to maintain records required by HMRC and respond to lawful requests from regulators.
  • Legitimate interests: to send you essential service updates, such as changes to course content or this policy.
  • Consent-based marketing: to send you occasional emails about course updates, but only when you have opted in.

Our promise: We never sell, rent, or trade your personal data to third parties. Your information stays within our organisation and the carefully vetted service providers who help us operate the website and deliver the course. We do not use your data to train artificial intelligence models or to build advertising profiles.

Who we share data with

We disclose personal data only to the following categories of recipients and only for the purposes described in this policy. Each recipient is bound by a data processing agreement that restricts their use of your information to our instructions.

Our service providers

We engage a payment processor to handle card transactions, a hosting provider to store course materials, and an email delivery service to send transactional messages. These providers receive only the minimum data required to perform their function. We audit their security certifications annually and require them to delete or return data when our contract ends.

Legal and regulatory disclosures

We may disclose your personal data if required to do so by a court order, regulatory investigation, or other binding legal process. We will notify you of such disclosure unless prohibited by law. We also reserve the right to share data to protect our legal rights or to prevent fraud.

Aggregated and anonymised data

We compile anonymised statistics about course completion rates, common questions, and website traffic patterns. These reports contain no personally identifiable information. We may share aggregated insights with instructors to improve teaching materials or publish general trends on our website.

Your data protection rights

Under UK data protection law, you have several rights regarding your personal data. We respond to all legitimate requests within one month. Complex or numerous requests may take an additional two months, in which case we will inform you of the extension within the first month.

  • You may request a copy of the personal data we hold about you, free of charge.
  • You may ask us to correct any inaccurate or incomplete data without undue delay.
  • You may request erasure of your data where there is no compelling reason for us to retain it.
  • You may receive your data in a structured, machine-readable format and transfer it to another controller.
  • You may object to processing based on legitimate interests, including any related profiling activities.
  • You may restrict processing while we verify accuracy, lawfulness, or the grounds for your objection.

To exercise any of these rights, please email us at the address listed in the contact section below. We may ask for proof of identity before acting on your request. If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office.

How we protect your data

We implement technical and organisational measures designed to protect your personal data against accidental loss, unauthorised access, alteration, or disclosure. Our security posture is reviewed quarterly and updated when new threats emerge or when our infrastructure changes.

Technical safeguards

  • Transport Layer Security encryption for all data transmitted between your browser and our servers.
  • Database encryption at rest using industry-standard AES-256 algorithms for sensitive fields.
  • Multi-factor authentication required for all administrative access to our hosting environment.
  • Automated intrusion detection and firewall rules that block suspicious traffic patterns.

Organisational safeguards

  • Staff training on data protection obligations, completed during onboarding and refreshed annually.
  • Access controls that restrict personal data to named individuals who require it for their role.
  • A documented incident response plan tested with a tabletop exercise every twelve months.
  • Regular audits of third-party providers to verify their compliance with our data processing standards.

How long we keep data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. When the retention period expires, we securely delete or anonymise the information. The specific periods vary by data category as described below.

  • Account and course progress data: retained for three years after your last login.
  • Quiz scores and assessment data: retained for three years after course completion.
  • Customer support messages: retained for two years after your last correspondence.
  • Payment and transaction records: retained for six years to comply with HMRC requirements.
  • Marketing consent records: retained indefinitely unless you withdraw your consent.

We may retain anonymised statistical data indefinitely for research purposes. If legal proceedings or regulatory investigations require us to preserve specific records, we will extend the retention period accordingly and notify you where permitted.

International data transfers

Our servers are located in the United Kingdom. Some of our service providers may process data in other countries. When we transfer personal data outside the UK, we ensure an equivalent level of protection is in place through one of the following safeguards.

  • Adequacy regulations: we transfer data only to countries deemed adequate by the UK government.
  • Standard contractual clauses: we use UK-approved model clauses in our data processing agreements.
  • Binding corporate rules: we verify that multinational providers have approved internal data protection policies.
  • Derogations: in limited cases we may rely on your explicit consent for a specific transfer.

Cookies and tracking

Our website uses cookies and similar technologies to distinguish you from other users, remember your preferences, and analyse site traffic. For detailed information about the cookies we deploy and how you can manage them, please read our Cookie Policy.

Cookie categories we use

  • Session cookies that keep you logged in and protect form submissions from cross-site request forgery.
  • Analytics cookies that collect anonymised data about page visits and navigation paths.
  • Preference cookies that remember your display settings, such as font size and contrast.
  • Course progress cookies that track your module completion status during a session.

You can block or delete cookies through your browser settings at any time. Please note that disabling essential cookies may prevent you from accessing course materials or submitting contact forms. Our Cookie Policy includes step-by-step instructions for managing cookies in the most common browsers.

Changes to this policy

We review this privacy policy every six months and update it whenever our data processing activities change. When we make material changes, we notify you through one or more of the following channels.

  • A prominent banner on our website displayed for at least fourteen days after the update.
  • An email sent to the address associated with your account, summarising the key changes.
  • A notice posted in the course forum, visible to all enrolled members.
  • An update to the effective date at the top of this page, with a link to the previous version.

We encourage you to check this page periodically. Your continued use of our website and course after the effective date of any revised policy constitutes your acceptance of the changes. If you disagree with an update, you may request deletion of your account and data.

Contact and complaints

If you have questions about this privacy policy, wish to exercise your data protection rights, or want to report a concern, please contact us using the details below. We will acknowledge your message within one working day and provide a substantive response within one calendar month.

Bilarexion

Easton Business Centre, 112-114 Cheltenham Road, Bristol, BS6 5RW United Kingdom

Phone: +44(0)4406 553148

Email: content@bilarexion.com

This privacy policy was last reviewed and updated on June 17, 2026.

The terms of this policy are effective from June 17, 2026.

We use cookies to remember your preferences and understand how you use our site. By continuing, you consent to our use of cookies.