Legal

Privacy Policy

Last updated: 5 September 2026

Version v1.2 — effective 5 September 2026. See the Version history at the end of this policy for a summary of what has changed.

Who we are

The School of Digital Health (“we”, “us”, “our”) operates the website schoolofdigitalhealth.org and publishes the Handbook of Digital Health.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for personal data you provide through this website.

We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, but you may direct any data protection queries to the email address above.

What information we collect and how

We collect personal data only when you voluntarily submit the enquiry form on this website. The information we collect is:

Data item Source Purpose
Your name You provide it To identify you and personalise our response
Your email address You provide it To reply to your enquiry and, with your separate consent, to contact you about relevant activities in the future
Your area of interest (e.g. Handbook, Courses, Consultancy, Other) You provide it To route your enquiry and tailor future communications to your interests
Your message (free text) You provide it To understand and respond to your enquiry
Consent record Generated at submission To evidence your consent choices
IP address Automatically collected Spam / abuse prevention
Browser identifier (user agent) Automatically collected Spam / abuse prevention
Timestamp Automatically collected Spam / abuse prevention and audit trail

We do not use analytics tools or advertising / tracking technologies anywhere on this website. The public website sets no cookies and no browser storage. The members’ area uses only strictly-necessary browser storage to keep you signed in after you log in (see “Member accounts” below); it is not used for tracking. We do not collect data from visitors who do not submit the form or create an account.

Provision of your name and email address is necessary for us to respond to your enquiry. If you do not provide them, we will be unable to reply. All other fields are optional.

Member accounts

If you create an account to access the members’ area of this website, we collect and process the following additional personal data:

Data item Source Purpose
Your email address You provide it at sign up To identify your account, verify ownership of the address, sign you in, and send account messages such as email-verification and password-reset codes
Authentication records (email-verification status, password-reset activity, sign-in and session metadata) Generated by the authentication service To operate and secure your account: confirm your email, authenticate you, manage your session, and detect suspicious activity

Your account password is set by you but is never stored by us in a form we can read: it is held only as a salted hash by our authentication provider (see “Who we share your data with”). We do not have access to your password.

Creating an account is entirely optional and separate from submitting an enquiry. You do not need an account to browse the public website or to use the enquiry form.

Anti-spam protection (Cloudflare Turnstile)

To protect the enquiry form and members’ area against automated abuse, we use Cloudflare Turnstile — a privacy-focused, invisible alternative to CAPTCHA. Turnstile runs on the following pages and only on the following pages:

When you load one of those pages, your browser makes a background request to challenges.cloudflare.com and Turnstile processes a small set of technical signals to decide whether the request is coming from a human or a bot. Cloudflare describes these signals as “minimal” and covers them in detail in its Turnstile Privacy Policy (also known as the Turnstile Privacy Addendum), which we incorporate by reference into this policy. The signals include:

Turnstile is invisible: it does not display a puzzle, does not require you to click a box, and does not use tracking cookies, browser fingerprinting for advertising, or any cross-site identifier. Cloudflare states that Turnstile signals are used only to score the request and are not used to build a profile of you, sold to third parties, or combined with data from other Cloudflare products for marketing. The signals are processed only long enough to return a pass/fail score to us and are then discarded by Cloudflare in accordance with its policy.

Our lawful basis for using Turnstile is legitimate interest (Article 6(1)(f) UK GDPR): protecting our website and users from spam, brute-force attacks, and automated abuse. We have assessed that this interest is not overridden by your rights, given (i) the narrow and technical nature of the signals processed, (ii) their use solely for security purposes, (iii) Cloudflare’s public commitment not to profile users on the basis of these signals, and (iv) the absence of tracking or advertising cookies.

Why we process your data (lawful bases)

We rely on the following lawful bases under Article 6(1) of the UK GDPR:

(a) Consent — Article 6(1)(a)

(f) Legitimate interests — Article 6(1)(f)

Who we share your data with

We share your data only with the following service providers, each acting as a data processor on our behalf under a written data processing agreement (Article 28 UK GDPR):

Processor Role Location
Amazon Web Services (Amazon Web Services EMEA SARL) Website hosting, database, application logic, and account authentication / identity management (Amazon Cognito) London region (eu-west-2), UK
Brevo (Sendinblue SAS) Delivery of email notifications to us when an enquiry is submitted France (EU/EEA)
Cloudflare, Inc. Anti-spam / bot-detection signal processing via Cloudflare Turnstile on the enquiry form and members’ authentication screens (see “Anti-spam protection” above) Global edge network; corporate entity is US-based

We do not sell, rent, or trade your personal data. We do not share it with any third party for their own marketing purposes.

International transfers

Personal data that we ourselves store — enquiry submissions and member account data — is held only within the United Kingdom and the European Economic Area (London region, eu-west-2).

The one exception is the narrow set of technical signals processed by Cloudflare’s Turnstile bot-detection service on the enquiry form and members’ authentication screens (described under “Anti-spam protection” above). Because Cloudflare, Inc. is US-based and operates a global edge network, these signals may be processed outside the UK and the EEA. This transfer relies on the following safeguards, which Cloudflare makes available under its data processing addendum:

Should the set of processors or transfer arrangements change in the future, we will update this policy and ensure appropriate safeguards are in place before any new transfer occurs.

How long we keep your data

Data category Retention period Basis
Enquiry data (where you did not opt in to future contact) 12 months from submission, then automatically deleted Sufficient to respond to your enquiry and handle any follow-up
Enquiry data (where you opted in to future contact) Until you withdraw consent or for a maximum of 36 months from your last interaction with us, whichever is sooner Necessary to fulfil the purpose you consented to
Security data (IP, user agent, timestamp) 6 months, then automatically deleted Sufficient to detect patterns of abuse
Member account data (email address and authentication records) Retained for the life of your account. When you delete your account, your identity and its authentication records are removed so the account can no longer sign in Necessary to operate the account for as long as you choose to keep it

You may ask us to delete your data at any time (see “Your rights” below). If you hold a member account, you can delete it yourself at any time from your account settings, which erases your account and its authentication records.

Your rights

Under UK GDPR you have the following rights. These are free of charge unless requests are manifestly unfounded or excessive:

To exercise any of these rights, contact us at enquiries@schoolofdigitalhealth.org. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it).

Complaints

If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

We would appreciate the opportunity to address your concerns before you approach the ICO, but you are not required to do so.

Automated decision-making

We do not carry out any automated decision-making or profiling (as described in Article 22 UK GDPR) based on the data you provide.

Children’s data

This website and its services are intended for individuals aged 16 or over. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has submitted data through our form, please contact us and we will delete it promptly.

Security measures

We implement appropriate technical and organisational measures to protect your data, including:

Changes to this policy

We may update this policy from time to time. Each version carries a version number and an effective date, both shown at the top of this page, and a summary of substantive changes is recorded in the Version history below. Where we make substantive changes we will provide a summary of what has changed; if you have opted in to future communications, we will notify you by email of any material changes that affect how we use your data.

We keep a record of the policy version in force when you gave consent (for example, when you submitted an enquiry or created an account), so we can always identify which version of this policy applied to you.

Version history