Privacy Policy
How we collect, use and protect your personal data under UK GDPR and the Data Protection Act 2018.
The Trading Field Guide (tradingfieldguide.co.uk) is the data controller for the platform. It is an independently run, education-only platform operated by an individual in the United Kingdom. You can contact the controller about any privacy question or to exercise your rights by email at [email protected].
- Account details: your name and email address.
- A password, which we only ever store as a secure one-way hash (we never keep your actual password).
- A record of the confirmations you give when you register: that you accepted these terms, read the risk warning, acknowledged this policy and are 18 or over, each with the date and time.
- Your learning progress: which courses and lessons you have completed, and your quiz and chart-exercise attempts and scores.
- A sign-in session record so we can keep you logged in, which includes your browser’s user-agent and the session timing (see ‘Cookies and local storage’ below).
- A vulnerability status: a single minimised, categorical result (‘clear’ or ‘on hold’) derived from the risk and vulnerability questionnaire.
Importantly, we do not store your raw answers to the vulnerability questionnaire. They are scored the moment you submit them and then discarded. If your answers raise a hold, we keep only one short category describing the type of concern (for example an essential-funds or gambling concern); there is no free text and no stored explanation. That category is treated as sensitive information and is visible only to a single senior safeguarding role, never to ordinary staff, and never to you. In this way we hold as little sensitive information about you as possible (data minimisation).
We do not collect payment or card details, government ID, or your date of birth (the 18-or-over check is a simple confirmation). We do not run advertising or analytics trackers and we do not build marketing profiles about you.
- To create and run your account and deliver the courses: performance of our contract with you.
- To gate content responsibly and safeguard learners through the risk and vulnerability foundation: our legitimate interest in running the platform safely and protecting learners from trading-related harm. Because a vulnerability flag can be sensitive information, we also rely on an additional condition for special-category data — the safeguarding of individuals as a matter of substantial public interest.
- To keep the platform secure and meet our legal obligations: legitimate interests and legal obligation.
We do not sell your data, and we do not share it with advertisers or data brokers. We rely on a small number of service providers who act only on our instructions:
- Amazon Web Services (AWS), which hosts the servers and database that run the platform in its London region (eu-west-2), so this data stays in the United Kingdom.
- Amazon Simple Email Service (SES), part of AWS, which delivers our transactional emails — the email-verification and password-reset messages — using your email address only for that purpose.
- Cloudflare, our content-delivery network and reverse proxy, which sits in front of the platform to provide caching, TLS encryption and protection against abuse. As traffic passes through it, Cloudflare processes your device’s IP address and request details.
- Self-hosted course media is not currently in use. If and when it is enabled, course videos and images would be stored on Cloudflare R2 (a Cloudflare storage service) and loaded by your browser over a short-lived link, which would mean Cloudflare receiving your IP address and request details to deliver the file. This holds course content, not your account data.
Separately, some lessons and blog posts embed videos from YouTube (using its privacy-enhanced no-cookie domain) or Vimeo. If you choose to play one, your browser connects to that provider directly. These providers are independent third parties, not our service providers: they receive your IP address and device and request details in order to deliver the video, and handle it under their own privacy policies. Because you contact the provider yourself, this may involve your request going to servers outside the UK (for example in the United States). It happens only after you click to play (see ‘Cookies and local storage’); until then no connection to YouTube or Vimeo is made.
A decorative gold-price chart on our public pages uses market data that we fetch on our own server. No personal data about you is sent to that source.
Your account records — your name, email and learning progress — are stored in the United Kingdom, in AWS’s London region, and our transactional email is sent from there too. Cloudflare, which sits in the request path to deliver and protect the site, is a global provider and may process limited technical data such as your IP address outside the UK; where that happens it is covered by Cloudflare’s own international data-transfer protections. Separately, if you choose to load a YouTube or Vimeo video, that request goes to the provider directly and may reach servers outside the UK (for example in the United States); because it is a request you initiate to a third party, it does not need a transfer safeguard from us.
We keep your account and learning-progress data for as long as your account is active. Short-lived security tokens expire automatically: a sign-in session lasts up to 14 days on the web (7 days in the mobile app), a password-reset link expires after 1 hour, and an email-verification link expires after 24 hours.
When you erase your account, we do it immediately and in place: we replace your name, email and password with non-identifying values, sign you out of every device at once, and remove your safeguarding vulnerability flag. There is no grace period, and your raw vulnerability answers were never stored to begin with.
For legal-accountability reasons we keep a minimal administrator audit record of significant actions (such as an erasure), but it is linked only to the anonymised account and no longer identifies you. We do not currently operate a fixed automatic deletion schedule for these accountability records.
We use one automated decision. Your answers to the risk and vulnerability self-assessment are scored automatically, and the result can pause (‘hold’) your progress through the course so we can safeguard you. You are never shown a category or reason, only a supportive clear-or-hold outcome with signposting to support.
If your progress is paused, you can reflect and try the assessment again after a 24-hour cool-off, and you can ask us to have a person review the decision and lift the hold — so there is always a human you can turn to. We make no other automated decisions, and we do not profile you for marketing.
Under UK GDPR you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data, such as your name or email, corrected.
- Erasure: have your account erased, so your identifying details are removed.
- Portability: receive your data in a portable, machine-readable format.
- Object: object to processing based on our legitimate interests, including the safeguarding vulnerability flag.
- Restrict: ask us to limit how we use your data while a concern is resolved.
- Automated decisions: ask for a person to review a decision made only by automated means (see ‘Automated decisions’ above).
You can exercise access, portability and erasure yourself at any time from your Your data page. For anything else, contact us using the details above.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator, at ico.org.uk. We would ask that you contact us first so we can try to help.
We use one cookie: an essential session cookie that keeps you signed in. It is strictly necessary for the platform to work, so it does not require consent.
We also keep two small preferences in your browser’s local storage: your chosen display theme (light or dark) and your response to the cookie notice. These stay on your device, are never sent to us, and are used only to remember your choices, not to track you.
We do not use tracking, advertising or analytics cookies or storage of any kind. Some lessons and blog posts embed videos from YouTube or Vimeo. To protect your privacy we do not load these from the provider until you choose to play them: until you press play, no connection is made to YouTube or Vimeo and none of their cookies can be set. When you do play a video, your browser loads it from the provider, which may then set its own cookies; we use YouTube’s privacy-enhanced no-cookie domain where possible.
We may update this policy from time to time; the current version always appears here. For any privacy question, or to exercise your data-protection rights, contact us at [email protected].
See also our Terms of Use.