Policy
Privacy Policy
- Version
- 3.0
- Effective date
- 3 September 2026
- Last updated
- 3 September 2026
- Issued by
- SCCP Academy (SCCP Academy)
- Contact
- contact@sccp-academy.com
This Privacy Policy explains what personal data SCCP Academy collects, why it is collected, how it is used and shared, how long it is kept, and what rights learners have. It should be read together with the Terms of Use and the Cookie Policy.
1. Who is responsible for your data
The Logistics & Supply Chain Academy, operating SCCP Academy, determines how and why personal data is processed on this platform and acts as the data controller.
Privacy enquiries and rights requests: contact@sccp-academy.com.
2. Data we collect
Account data: name, email address, country, password credential held in hashed form by the authentication service, and account status.
Purchase and entitlement data: products purchased or granted, order references, access start and end dates, and payment status received from the payment provider. Full card numbers are never received or stored by the Academy.
Learning data: lessons opened and completed, activity and lab interactions, practice-quiz responses, and course progress.
Assessment data: exam attempts, timestamps, answers submitted, scores, domain-level results, pass or fail outcome, and attempt credits.
Certificate data: certificate number, level, issue and expiry dates, status, and the verification token record where public verification is enabled.
Technical and security data: IP address, device and browser characteristics, session and login events, and security and rate-limiting logs.
Support and feedback data: messages sent to support and feedback submitted in the platform.
3. Why we process data and on what basis
To perform our contract with you: creating and maintaining the account, granting access, delivering courses, administering exams, issuing certificates, and handling purchases and refunds.
For our legitimate interests: keeping the platform secure, preventing fraud and account sharing, protecting assessment integrity, maintaining the reliability of certificate verification, responding to support requests, and improving the programme using aggregated and de-identified information where possible.
To comply with legal obligations: accounting and tax records, and responses to lawful requests.
With your consent: where consent is specifically requested, such as optional communications. Consent may be withdrawn at any time without affecting prior processing.
4. Exam integrity and monitoring
The Academy processes exam attempt metadata, timing patterns, device and login signals, and answer records to detect impersonation, collusion, content extraction, and other integrity violations, as described in the Academic Integrity Policy.
The platform does not use webcam proctoring, screen recording, biometric identification, or keystroke biometrics. Dynamic watermarking may display account-identifying information within the learning interface.
Integrity decisions that affect a result or a certificate are reviewed by a person before they take effect, and the learner may respond and appeal.
5. Certificate verification and disclosure
Certificates are not listed in a public directory and cannot be searched by name, email, or issue date. Verification works only for someone holding the certificate's secure verification link or full verification code.
A successful verification discloses only: holder name, certificate title, certificate type, level, issue date, expiry date, certificate number, issuer, and status. Email addresses, exam scores, answers, internal identifiers, and revocation notes are never disclosed.
Verification requests are logged for security and abuse prevention. Sharing a verification link is the holder's decision, and a holder may ask the Academy to rotate or disable the verification token for their certificate.
6. Sharing your data
Personal data is shared with service providers acting on the Academy's instructions for the following functions: platform hosting and application delivery; database, authentication, and file storage; payment processing; transactional email delivery; and security, logging, and abuse prevention.
Providers are bound by contract to process data only for those purposes. Data may also be disclosed where required by law, to establish or defend legal claims, or in connection with a business transfer, in which case learners are notified.
The Academy does not sell personal data and does not share it for advertising.
7. International transfers
Service providers may process data in countries other than the learner's own. Where data leaves a jurisdiction that restricts international transfers, the Academy relies on an approved transfer mechanism such as standard contractual clauses or an adequacy decision.
8. Retention
Account, purchase, assessment, and certificate records are retained while the account is active and afterwards for as long as needed to operate certificate verification, resolve disputes, prevent fraud, and meet legal and accounting obligations.
Certificate records are retained for the working life of the certificate so that verification remains reliable, including after a certificate expires or is revoked. Security and access logs are retained for a limited period proportionate to their security purpose.
Specific retention periods per category are set out in the Academy's internal retention schedule and are confirmed in this policy before paid enrolment opens.
9. Security
The platform uses encrypted transport, hashed credentials, row-level access controls, least-privilege service access, rate limiting on sensitive endpoints, and logging of administrative actions. Verification tokens are stored only as irreversible hashes.
No system is completely secure. Where a breach is likely to affect learners, the Academy notifies affected learners and the relevant authority as required by law.
10. Your rights
Depending on your jurisdiction, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent.
Requests are made to contact@sccp-academy.com and are answered within the period required by applicable law. Identity may need to be confirmed before a request is actioned.
Deletion of account data does not remove records the Academy must keep, such as accounting records and the certificate records that make verification reliable. Where deletion is limited for that reason, the reason is explained.
Learners may also complain to their local data-protection supervisory authority.
11. Children
The platform is not directed at children. Accounts require the learner to be at least 16 years old. Where the Academy learns that data of a younger person has been collected, the account and data are removed.
12. Cookies
The platform uses only strictly necessary cookies and equivalent local storage. Details are in the Cookie Policy.
13. Changes to this policy
This policy is versioned. The version number, effective date, and last-updated date are shown at the top of this page, and material changes are notified to account holders.