Privacy Policy
Last Updated: June 29, 2026
At TAP Clinical Education ("TAP", "we", "us", or "our"), we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal data when you visit our website, register for an account, purchase licenses, use our Learning Management System (LMS), and complete our training courses.
This Privacy Policy is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Important Information & Who We Are
1.1 Data Controller
For the purposes of the UK GDPR and DPA 2018, the Data Controller is:
TAP Clinical Education
Founder & Lead Educator: Amy J. Taphouse
Contact Email: [email protected]
If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us using the email address above.
1.2 Complaints
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
2. What Personal Data We Collect & Why
"Personal data" means any information about an individual from which that person can be identified. We collect, use, store, and transfer different kinds of personal data which we have grouped as follows:
| Data Category | Specific Elements Collected | Legal Basis for Processing (UK GDPR) |
|---|---|---|
| Identity Data | First name, last name, username, and account profile image. | Performance of a Contract (Article 6(1)(b)) |
| Contact Data | Email address and telephone number (if provided). | Performance of a Contract (Article 6(1)(b)) |
| Organization & Team Data | Organization name, slug, logo, member roles (admin or member), and colleague email addresses invited to the studio workspace. |
Performance of a Contract (Article 6(1)(b)) |
| Course & Progress Data | Course enrollments, lesson progress (watched seconds, completion timestamps), quiz responses, test attempts, exam scores, and certificate status. | Performance of a Contract (Article 6(1)(b)) |
| Proctoring & Anti-Cheat Data | Focus loss occurrences (tab switching, window blurring, minimizing browser), quiz warning counts, automated lockout logs, and lockout reasons. | Performance of a Contract (Article 6(1)(b)) & Legitimate Interests (Article 6(1)(f)) to verify academic integrity. |
| Billing & Transaction Data | Lemon Squeezy order references, seat packages purchased, payment amounts, and transaction dates. Note: We do not collect or store credit/debit card numbers on our servers; they are processed securely by Lemon Squeezy. | Performance of a Contract (Article 6(1)(b)) |
| Technical & Connection Data | IP address, browser type and version, time zone setting, browser plug-in types, operating system, and platform. | Legitimate Interests (Article 6(1)(f)) for system security, fraud prevention, and performance monitoring. |
| Usage & Analytics Data | Anonymous aggregate visitor statistics (derived from cookieless analytics). | Legitimate Interests (Article 6(1)(f)) for site optimization and user experience enhancement. |
3. Academic Integrity & Anti-Cheat Monitoring
To maintain the accreditation value and trust of TAP Clinical Education certificates, our LMS monitors user behavior in real-time during quizzes and exams:
- What is tracked: The system monitors browser page visibility and focus changes (specifically
visibilitychangeandblurevents). It logs instances where a student leaves the exam tab or window. - Why it is tracked: To ensure students do not look up answers, copy exam contents, or seek unauthorized assistance during testing, maintaining compliance standards.
- How it is used: The LMS automatically calculates warning counts and triggers a lockout upon three (3) focus-loss events. The lockout event and reason are recorded in the database, requiring manual review and reset by our training administrator.
- Legal Basis: Performance of a Contract (Article 6(1)(b)) — as completing courses honestly is a prerequisite for certificate issuance, and Legitimate Interests (Article 6(1)(f)) — to protect the academic integrity and public trust of our accredited educational outcomes.
4. Cookies & Similar Technologies (PECR Compliance)
The Privacy and Electronic Communications Regulations (PECR) regulate the use of cookies and similar technologies on users' devices.
4.1 Better Auth Session Cookies (Strictly Necessary)
Our authentication framework, Better Auth, sets essential HTTP-only cookies to manage user logins and security:
- Session Token (
better-auth.session_token): Stores a unique session token to identify your logged-in state across requests. - CSRF Token: Protects your account from Cross-Site Request Forgery attacks.
- Organization Context: Stores the active organization ID if you manage multiple studio profiles.
[!NOTE] Strictly Necessary Exemption: These session cookies are strictly necessary to provide the information society service (the authenticated LMS portal) explicitly requested by you when you log in. Under PECR and ICO guidelines, strictly necessary cookies do not require prior consent via a cookie banner. They are set automatically upon login and are securely cleared when you log out or when your session expires.
4.2 Umami Web Analytics (Cookieless & Private)
We use Umami to monitor traffic, visitor counts, and website performance.
- Zero Terminal Storage: Unlike legacy tracking services (such as Google Analytics), Umami does not use cookies, does not write to your browser's LocalStorage or SessionStorage, and does not store or read any identifiers on your device.
- IP Hashing & Salt Rotation: Umami collects your IP address transiently to determine unique visitor counts. This IP is immediately hashed with a daily rotating salt and converted into an anonymous, temporary session ID. The raw IP address is discarded and never stored in the database. The salted hash is updated every 24 hours, making it impossible to track you across different days.
- Status: Because Umami does not write to or retrieve information from your terminal device, it does not trigger PECR Regulation 6 consent requirements. The transient, anonymous processing of IP addresses is conducted under our Legitimate Interests (Article 6(1)(f) UK GDPR) to keep our site secure and optimized.
Summary: TAP Clinical Education does not deploy any tracking or advertising cookies. Therefore, no cookie consent overlay is required on our website or LMS.
5. How We Share Your Personal Data
We do not sell, rent, or trade your personal data. We only share personal data with selected third parties in the following limited circumstances:
- Studio/Organization Administrators: If you enroll in courses using a seat license purchased by your employer, studio, or organization, your course progress, quiz scores, attempt counts, and certificate status will be visible to your organization's Administrator.
- Merchant of Record (Lemon Squeezy): All payment processing is handled by Lemon Squeezy. They share order confirmation metadata (order reference, seats purchased) with us to enable licensing in your account.
- Email Delivery (MailServer): We dispatch critical transactional emails (email verification links, password reset tokens) through our remote MailServer via cryptographic HMAC-signed API requests.
- Cloud Infrastructure Providers: We use hosting and storage providers (such as Cloudflare and AWS S3) to host the LMS, database records, video lectures, and certificates.
- Certificate Verification (Public Mode): If you choose to set your Certificate of Clinical Accomplishment to Public, anyone with your unique certificate link or QR code will be able to verify your completion details. If left in Private mode, it remains visible only to you and your studio admin.
- Legal & Regulatory Obligations: We may disclose data if required by UK law, court order, or to enforce our Terms of Service.
6. International Data Transfers
Some of our third-party infrastructure partners (such as cloud hosting and database backup services) may be located outside the United Kingdom.
When we transfer your personal data outside the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government (Adequacy Regulations).
- We use specific Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement/Addendum (IDTA) approved by the UK Government, which give personal data the same protection it has in the UK.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed in an unauthorized way:
- All database connections and web traffic are encrypted using Secure Sockets Layer/Transport Layer Security (SSL/TLS).
- Better Auth passwords are securely hashed using cryptographic hashing algorithms.
- Better Auth session tokens are marked as HTTP-only, secure, and SameSite=Lax.
- Communication with our remote MailServer is protected by custom API keys and HMAC-SHA256 signatures.
- Access to personal data is restricted to authorized administrators who have a business need-to-know.
8. Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Account Data: Retained as long as your account is active. If your account is inactive for more than 3 years, we may contact you or proceed to archive/delete it.
- Certificate & Progress Records: To support long-term professional accountability (e.g. if an employer or local authority licensing officer requests verification of your training certificate years after completion), we retain certificate verification records and enrollment logs indefinitely or until the user explicitly requests their deletion.
- Transient Session Logs: Deleted or expired automatically.
9. Your Legal Rights (UK GDPR)
Under the UK GDPR and DPA 2018, you have the following rights in relation to your personal data:
- Right of Access ("Subject Access Request"): You have the right to receive a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request that we correct any incomplete or inaccurate data we hold about you.
- Right to Erasure ("Right to be Forgotten"): You have the right to ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note: We may deny deletion of certificate records if they are required to prove professional training compliance under ongoing contract or regulatory claims.
- Right to Restrict Processing: You have the right to ask us to suspend the processing of your personal data in certain scenarios.
- Right to Data Portability: You have the right to request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format.
- Right to Object: You have the right to object to the processing of your personal data where we are relying on a legitimate interest.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us at [email protected]. We aim to respond to all legitimate requests within one month.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
TAP Clinical Education
Founder/Lead Educator: Amy J. Taphouse
Email: [email protected]