We strive for excellent training experiences and continuously improve for learners and organizations.








Because you deserve a training platform that delivers.
Clarivive MedInsight
Last Updated: 5 July 2026
Version Number: 1.0
Clarivive MedInsight Ltd is committed to protecting personal information and handling it lawfully, fairly and transparently. This Privacy Policy explains how we collect, use, store, share and protect personal information when individuals visit our website, create a learner account, register for training, purchase a course, use our Learning Management System, attend training, communicate with us, submit a complaint or appeal, or otherwise use our services. This policy applies to learners, prospective learners, website users, employer clients, organisation representatives, trainers, assessors, contractors and other individuals who interact with Clarivive MedInsight Ltd.
Clarivive MedInsight Ltd provides health and social care training services, including online learning, face-to-face training, webinars, in-house employer training and blended learning.
For the purposes of this Privacy Policy, āapplicable data protection lawā includes the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and, where applicable, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), together with any subsequent amendments or replacement legislation, Clarivive MedInsight Ltd will normally act as the data controller for personal information collected directly through our website, booking systems, learner accounts, training activities and business communications. This means that we determine why and how that personal information is used.
In some circumstances, such as employer-funded or commissioned training, the employer or commissioning organisation may also act as a controller or may provide personal information to us for the purpose of delivering the agreed training service.
We may collect personal information directly from you, from your employer or booking organisation, through our website and Learning Management System, from payment and communication providers, or through your participation in our training services.
The personal information we may collect includes:
⢠Name
⢠Email address
⢠Telephone number
⢠Postal or billing address where required
⢠Organisation or employer details
⢠Job title or professional role where provided
⢠Learner account and login information
⢠Learner identification number or booking reference
⢠Course enrolment and registration records
⢠Attendance and non-attendance records
⢠Course progress and completion information
⢠Assessment records
⢠Certificate details and certificate-verification information
⢠Learning Management System activity and access records
⢠Internal LMS messages and support communications
⢠Booking, invoice, transaction and payment information
⢠Enquiry, correspondence and customer-support records
⢠Complaint, appeal, refund or cancellation information
⢠Accessibility and reasonable-adjustment information where provided
⢠Marketing preferences and communication choices
⢠Website usage, device, browser, IP address and cookie information
⢠Records relating to technical problems, suspected misuse or security incidents
⢠Any supporting documents voluntarily submitted in connection with a request, complaint, appeal or reasonable adjustment
We aim to collect only personal information that is adequate, relevant and reasonably necessary for the purpose for which it is being used. The UK GDPR requires organisations to avoid collecting more personal information than they need.
Please do not provide unnecessary medical, financial, identity or other sensitive information unless we have specifically requested it for a legitimate purpose.
We may use personal information to:
⢠Create, verify and manage learner accounts
⢠Register learners for courses
⢠Provide access to online learning and LMS functions
⢠Deliver face-to-face, webinar, in-house or blended training
⢠Communicate course dates, joining instructions and service updates
⢠Record attendance, non-attendance and course participation
⢠Monitor course progress and completion
⢠Administer assessments, reassessments and practical observations
⢠Issue, manage, correct, revoke and verify certificates
⢠Respond to enquiries and provide learner or customer support
⢠Process bookings, invoices, payments, refunds and cancellations
⢠Administer employer-funded or group bookings
⢠Manage reasonable-adjustment and accessibility requests
⢠Investigate complaints, appeals, malpractice concerns or service disputes
⢠Maintain learner, training, assessment and quality-assurance records
⢠Carry out internal quality assurance, audit, moderation and standardisation
⢠Improve course content, delivery systems and customer experience
⢠Send service-related communications
⢠Send marketing communications where permitted
⢠Prevent fraud, unauthorised access, misuse and security threats
⢠Maintain the security, performance and integrity of our website and LMS
⢠Obtain professional, legal, accounting or insurance advice
⢠Meet legal, tax, accounting, regulatory, contractual and governance obligations
⢠Establish, exercise or defend legal claims
We will not use personal information for a materially different and incompatible purpose without considering whether further information, consent or another lawful basis is required.
We must have a lawful basis before using personal information. The basis used will depend on the specific purpose and circumstances. Organisations must tell individuals which lawful basis applies to their processing.
We may rely on the following lawful bases:
Contract
We may use personal information where processing is necessary to take steps at your request before entering into a contract or to perform a training, booking or service contract with you.
This may include registering you for a course, giving you LMS access, delivering training, administering assessments, issuing certificates, processing payments and providing course-related support.
Legal obligation
We may use or retain personal information where necessary to comply with legal, tax, accounting, regulatory, court or law-enforcement obligations.
Legitimate interests
We may process personal information where this is necessary for our legitimate business interests or those of another party, provided those interests are not overridden by your rights and freedoms.
These interests may include:
⢠Operating and administering our training business
⢠Maintaining accurate learner and certificate records
⢠Quality assurance and service improvement
⢠Preventing fraud and misuse
⢠Protecting systems and information
⢠Managing complaints, disputes and legal claims
⢠Communicating with employer clients
⢠Maintaining appropriate audit trails
Where appropriate, we will consider the necessity, proportionality and effect of the processing before relying on legitimate interests.
Consent
We may rely on consent where you have been given a genuine choice, such as for certain marketing communications, non-essential cookies, photographs, recordings or optional activities.
Where consent is the lawful basis, you may withdraw it at any time. Withdrawal will not affect processing that was lawful before consent was withdrawn.
Vital interests
In rare circumstances, we may use personal information where this is necessary to protect someoneās life. Vital interests generally apply only where the processing is genuinely necessary and another less intrusive basis is not reasonably available.
Special Category information
Certain personal information requires additional protection under data protection law. This includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data used for unique identification; data concerning health; and data concerning a personās sex life or sexual orientation. Information concerning a disability may also constitute special-category data where it reveals information about a personās physical or mental health.
Where Clarivive MedInsight Ltd processes special-category information, we will identify an appropriate lawful basis under Article 6 of the UK GDPR and a separate condition for processing under Article 9 of the UK GDPR and, where required, the relevant condition and safeguards under Schedule 1 of the Data Protection Act 2018.
For example, health or accessibility information may be processed where necessary to consider or provide reasonable adjustments, comply with applicable legal obligations, respond appropriately to safeguarding or emergency circumstances where the relevant legal conditions are met, or establish, exercise or defend legal claims. Where we rely on explicit consent as an Article 9 condition, this will be clearly identified and the requirements for valid explicit consent will be followed.
We do not assume that consent is always the appropriate lawful basis or Article 9 condition for processing special-category information. The appropriate basis and condition will be determined according to the purpose and circumstances of the processing.
Our Learning Management System is the primary system used to administer learner participation and maintain training records.
The LMS may process:
⢠Registration and profile information
⢠Course enrolment details
⢠Login and access records
⢠Course activity and progress
⢠Assessment answers and outcomes
⢠Attendance records
⢠Completion information
⢠Certificate records
⢠Internal LMS messages
⢠Technical and security logs
⢠Support and administrative records
Certificates are generated using the information held in the learner record. Learners are responsible for checking that their name and other relevant registration details are accurate before completing training or requesting certificate issue.
Once a certificate has been issued, it may be locked from ordinary editing to protect the accuracy and integrity of the certification record. Where a correction is justified, the original certificate may need to be revoked, cancelled or replaced through a controlled administrative process.
Certificate metadata may be retained to:
⢠Confirm whether a certificate is genuine
⢠Respond to verification requests
⢠Maintain an audit trail
⢠Detect fraudulent or altered certificates
⢠Record revoked or replaced certificates
Access to LMS records is limited according to role and operational need.
Our LMS may include internal messaging or chat features to support learner communication, course support and administration.
Messages may be reviewed where necessary for learner support, safeguarding, complaints, system misuse, quality assurance or legal reasons.
Where training is booked, arranged, commissioned or funded by an employer or another organisation, that organisation may provide learner information to us.
We may use that information to:
⢠Register learners
⢠Allocate course access
⢠Confirm attendance
⢠Monitor completion
⢠Administer assessments
⢠Issue certificates
⢠Provide agreed training reports
⢠Resolve booking or administrative issues
Where lawful and appropriate, we may share the following information with the booking organisation:
⢠Registration status
⢠Attendance or non-attendance
⢠Course progress
⢠Completion status
⢠Certificate issue or expiry status
⢠Assessment outcome where relevant to the service purchased
⢠Reassessment or referral status
⢠Administrative or learner-support issues where disclosure is necessary
⢠Conduct or safeguarding information where there is a lawful and proportionate reason to disclose it
We will not routinely provide employers with detailed assessment answers, private correspondence, medical information or unrelated personal information.
The extent of information shared may depend on the contractual arrangements, the purpose of the training, the employerās legal responsibilities and the reasonable expectations of the learner.
We may send information about courses, services, events, offers, newsletters and relevant training updates where we have a lawful basis to do so.
Where consent is required, marketing will only be sent after the appropriate consent has been obtained.
In some business-to-business circumstances, we may rely on legitimate interests or another lawful basis where permitted by law. We will still provide a clear way to object or unsubscribe.
You may opt out of marketing communications at any time by:
⢠Using the unsubscribe link in an email
⢠Updating your communication preferences where available
⢠Contact us by filling the form below.
Opting out of marketing does not prevent us from sending essential service communications relating to:
⢠Your booking
⢠Your learner account
⢠Course access
⢠Training dates
⢠Assessment or completion
⢠Certificates
⢠Payments, refunds or cancellations
⢠Security or policy changes
⢠Complaints, appeals or support requests
We do not sell personal information or marketing lists.
Our website may use cookies and similar technologies to operate, secure and improve the website.
Cookies may be used to:
⢠Maintain website functionality
⢠Remember settings and preferences
⢠Support login or account functions
⢠Maintain security
⢠Understand website performance
⢠Measure visitor interaction
⢠Support analytics
⢠Deliver marketing or embedded third-party content where permitted
Some cookies are strictly necessary for the website to operate and may not require consent.
Analytics, advertising and other non-essential cookies will be used only where permitted and, where required, after consent has been obtained.
You may manage your choices through our cookie-control mechanism or your browser settings. Blocking some cookies may affect website functionality.
Please read our separate Cookie Policy for further information.
We may share personal information only where there is a lawful and legitimate reason to do so.
Recipients may include:
⢠Learning Management System providers
⢠Website, domain and hosting providers
⢠Cloud-storage and backup providers
⢠Payment processors and financial-service providers
⢠Email, messaging and communication providers
⢠Customer-support and booking-system providers
⢠IT support, cybersecurity and technical-service providers
⢠Trainers, assessors, internal quality assurers and authorised administrators
⢠Employer clients or commissioning organisations
⢠Accreditation, certification or awarding bodies where applicable
⢠Professional advisers, including accountants, auditors and legal advisers
⢠Insurers and insurance representatives
⢠Debt-recovery or fraud-prevention providers where necessary
⢠Government departments, regulators, courts, law-enforcement bodies or public authorities where required
⢠A purchaser, investor or professional adviser involved in a legitimate corporate transaction, subject to appropriate confidentiality controls
Service providers that process personal information on our behalf are expected to use it only for authorised purposes and to apply appropriate confidentiality and security measures.
We may also disclose information where necessary to protect a person from serious harm, investigate suspected unlawful conduct, enforce our terms, or establish, exercise or defend legal rights.
We do not sell personal information.
Clarivive MedInsight Ltd operates primarily within the United Kingdom. Some service providers, cloud platforms or software systems we use may process or permit access to personal information outside the UK.
Where we make a restricted international transfer, we will ensure that it is carried out in accordance with applicable international-transfer requirements under the UK GDPR (Chapter V, Articles 44Aā49), the Data Protection Act 2018 and relevant amendments made by the Data (Use and Access) Act 2025 (Schedule 7).
Where required, we will use an appropriate legal transfer mechanism, such as:
⢠UK adequacy regulations or approved transfers (UK GDPR, Article 45A);
⢠Appropriate safeguards (UK GDPR, Article 46);
⢠The UK International Data Transfer Agreement (IDTA) or UK Addendum (UK GDPR, Article 46; Data Protection Act 2018, section 119A);
⢠An applicable legal exception where permitted (UK GDPR, Article 49); and
⢠A transfer risk assessment and any necessary contractual, technical or organisational safeguards where required (UK GDPR, Article 46; Data (Use and Access) Act 2025, Schedule 7).
We will review relevant international-transfer arrangements when selecting and managing service providers.
We retain personal information only for as long as it is reasonably required for the purpose for which it was collected, or where continued retention is necessary for legal, contractual, tax, accounting, audit, safeguarding, certification, insurance or dispute-management reasons.
There is no single statutory retention period applying to every category of personal information. Retention must be assessed according to the purpose and circumstances.
Retention periods may therefore differ. For example:
⢠Website security and activity logs may be kept for a relatively short period unless needed for an investigation.
⢠Enquiry and routine support records may be deleted when they are no longer operationally necessary.
⢠Learner registration, attendance and assessment records may be retained for quality-assurance, audit and certification purposes.
⢠Certificate metadata may be retained for a longer period to support verification and fraud prevention.
⢠Financial and transaction records may be retained to meet legal and accounting obligations.
⢠Complaint, appeal, malpractice, safeguarding or legal-dispute records may be retained for longer where justified by the nature of the matter.
⢠Marketing records may be kept until consent is withdrawn, an objection is made, or the information is no longer needed.
⢠Suppression records may be retained where necessary to ensure that a person who has opted out is not unintentionally contacted again.
At the end of the relevant retention period, information will be securely deleted, anonymised or otherwise disposed of unless a lawful reason requires continued retention.
The storage-limitation principle requires personal information not to be kept in identifiable form for longer than necessary.
Please refer to our Records Retention Policy for further information.
Depending on the circumstances and the lawful basis used, you may have the right to:
⢠Be informed about how your personal information is used
⢠Request access to your personal information
⢠Ask us to correct inaccurate or incomplete information
⢠Request deletion of personal information
⢠Request restriction of processing
⢠Object to certain processing
⢠Withdraw consent where consent is the lawful basis
⢠Request data portability where applicable
⢠Ask for information about certain automated decisions where applicable
⢠Complain to the Information Commissionerās Office
These rights are not absolute.
For example, we may lawfully refuse or limit a request where:
⢠Information must be retained to meet a legal obligation
⢠The information is required for certificate verification
⢠Retention is necessary for an existing complaint, appeal or legal claim
⢠Disclosure would adversely affect another personās rights
⢠An exemption applies
⢠The request is manifestly unfounded or excessive
⢠We cannot identify the information or verify the person making the request
Where a request cannot be fully accepted, we will explain the reason where legally permitted.
To exercise your data protection rights or raise a concern about how we use your personal information, please complete the Privacy Request Form provided below.
The form may be used to request:
⢠Access to the personal information we hold about you
⢠Correction of inaccurate or incomplete information
⢠Deletion of personal information where applicable
⢠Restriction of processing
⢠Objection to certain uses of your information
⢠Withdrawal of consent where consent is the lawful basis
⢠Data portability where applicable
⢠Any other privacy-related request or concern
Please provide enough information for us to identify you, understand your request and locate the relevant records.
We may contact you for further information or reasonable proof of identity before processing your request. This is necessary to ensure that personal information is not disclosed, changed or deleted without proper authorisation.
Submitting the form does not mean that every request will automatically be approved. Some data protection rights are subject to legal limitations, and we may need to retain certain records for legal, contractual, financial, safeguarding, audit or certificate-verification purposes.
We will respond within the timeframe required by applicable data protection law. Where a request is particularly complex, we will inform you if additional time is legally permitted.
You may also contact us regarding a privacy request at:
Email: info@clarivive.co.uk
We use proportionate technical and organisational measures intended to protect personal information against accidental or unlawful loss, alteration, destruction, disclosure, access or misuse.
Depending on the system and risk involved, measures may include:
⢠User authentication
⢠Password controls
⢠Role-based access restrictions
⢠Restricted administrative permissions
⢠Secure configuration
⢠Encryption where appropriate
⢠Secure hosting and storage
⢠Backups and recovery controls
⢠Audit and activity logs
⢠Certificate-access controls
⢠Staff and contractor confidentiality requirements
⢠Malware and security monitoring
⢠Incident reporting and response procedures
⢠Supplier due diligence
⢠Data minimisation
⢠Controlled deletion and disposal
⢠Periodic review of access rights
Access to personal information is limited to individuals who reasonably require it for their role.
Users are responsible for keeping login credentials secure and must not share passwords or allow another person to access their account.
No website, email service, cloud platform or electronic system can be guaranteed to be completely secure. However, we take reasonable and proportionate measures to reduce privacy and security risks.
Our training services are mainly intended for adults, employees, professionals and organisations.
We do not knowingly collect personal information from children through ordinary course bookings unless the training has been specifically arranged for younger learners and appropriate safeguards have been established.
Where a child or young person participates in training, we may require:
⢠Consent or authorisation from a parent, guardian, school, college or commissioning organisation
⢠Age-appropriate privacy information
⢠Appropriate supervision
⢠Safeguarding controls
⢠Restricted communications
⢠Additional identity and booking checks
We will collect only the information reasonably required to administer the training and protect the learner.
If we become aware that a childās information has been provided without an appropriate basis, we will review the circumstances and delete or restrict the information where required.
Clarivive MedInsight Ltd may operate official social-media accounts for communication, education, promotion and customer engagement.
Our official channels may include:
⢠LinkedIn
⢠Facebook
⢠Instagram
⢠X
⢠Pinterest
⢠YouTube
⢠Telegram
⢠Threads
If you interact with us through a social-media platform, the platform provider may collect and process your information independently under its own privacy policy and terms.
Depending on how you interact with us, we may receive:
⢠Your profile name
⢠Public account details
⢠Comments, reactions or messages
⢠Enquiry details
⢠Engagement and analytics information
⢠Information you choose to share publicly or privately
You should not send sensitive, medical, identity, financial or confidential information through public comments or unsecured social-media messages.
We may moderate, hide, retain, report or delete content where necessary to address inappropriate conduct, protect users, meet platform rules or manage legal and reputational risks.
Only social-media accounts linked from our official website should be treated as authorised Clarivive MedInsight Ltd channels.
We may update this Privacy Policy where necessary to reflect:
⢠Changes in law or regulatory guidance
⢠Changes to our services
⢠New systems or service providers
⢠Changes to our use of personal information
⢠Changes to security or governance arrangements
⢠Feedback, audits or operational improvements
The latest version will be published on our website with an updated revision date.
Where a change is significant and materially affects how personal information is used, we may provide additional notice through our website, LMS, email or another appropriate communication method.
We recommend reviewing this policy periodically.
For questions, privacy requests or concerns about how we handle personal information, Please fill the inquiry form given below or contact:
Clarivive MedInsight Ltd
Email: info@clarivive.co.uk
When contacting us, please provide sufficient information for us to understand and investigate your enquiry. Do not send unnecessary identity documents, medical records, financial details or other sensitive information unless we specifically request them through an appropriate method.