Legal
Privacy Policy
Version v1.2 — effective 5 September 2026. See the Version history at the end of this policy for a summary of what has changed.
Who we are
The School of Digital Health (“we”, “us”, “our”) operates the website schoolofdigitalhealth.org and publishes the Handbook of Digital Health.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for personal data you provide through this website.
- Controller: The School of Digital Health
- Postal address: 45 Lincoln Drive, Woking, UK GU22 8RR
- Data protection enquiries: enquiries@schoolofdigitalhealth.org
- ICO registration number: Registration pending
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, but you may direct any data protection queries to the email address above.
What information we collect and how
We collect personal data only when you voluntarily submit the enquiry form on this website. The information we collect is:
| Data item | Source | Purpose |
|---|---|---|
| Your name | You provide it | To identify you and personalise our response |
| Your email address | You provide it | To reply to your enquiry and, with your separate consent, to contact you about relevant activities in the future |
| Your area of interest (e.g. Handbook, Courses, Consultancy, Other) | You provide it | To route your enquiry and tailor future communications to your interests |
| Your message (free text) | You provide it | To understand and respond to your enquiry |
| Consent record | Generated at submission | To evidence your consent choices |
| IP address | Automatically collected | Spam / abuse prevention |
| Browser identifier (user agent) | Automatically collected | Spam / abuse prevention |
| Timestamp | Automatically collected | Spam / abuse prevention and audit trail |
We do not use analytics tools or advertising / tracking technologies anywhere on this website. The public website sets no cookies and no browser storage. The members’ area uses only strictly-necessary browser storage to keep you signed in after you log in (see “Member accounts” below); it is not used for tracking. We do not collect data from visitors who do not submit the form or create an account.
Provision of your name and email address is necessary for us to respond to your enquiry. If you do not provide them, we will be unable to reply. All other fields are optional.
Member accounts
If you create an account to access the members’ area of this website, we collect and process the following additional personal data:
| Data item | Source | Purpose |
|---|---|---|
| Your email address | You provide it at sign up | To identify your account, verify ownership of the address, sign you in, and send account messages such as email-verification and password-reset codes |
| Authentication records (email-verification status, password-reset activity, sign-in and session metadata) | Generated by the authentication service | To operate and secure your account: confirm your email, authenticate you, manage your session, and detect suspicious activity |
Your account password is set by you but is never stored by us in a form we can read: it is held only as a salted hash by our authentication provider (see “Who we share your data with”). We do not have access to your password.
Creating an account is entirely optional and separate from submitting an enquiry. You do not need an account to browse the public website or to use the enquiry form.
Anti-spam protection (Cloudflare Turnstile)
To protect the enquiry form and members’ area against automated abuse, we use Cloudflare Turnstile — a privacy-focused, invisible alternative to CAPTCHA. Turnstile runs on the following pages and only on the following pages:
- the public enquiry form at
/contact; - the members sign-up, forgotten-password, and password-reset
screens under
/members; - any future public form we add where automated abuse is a real risk (we will not silently expand Turnstile beyond this list).
When you load one of those pages, your browser makes a background request
to challenges.cloudflare.com and Turnstile processes a small set of
technical signals to decide whether the request is coming from a human or
a bot. Cloudflare describes these signals as “minimal” and covers them in
detail in its Turnstile Privacy Policy (also known as the Turnstile
Privacy Addendum),
which we incorporate by reference into this policy. The signals include:
- your IP address;
- your browser’s user-agent string;
- basic device and browser characteristics (screen size, language, timezone, and similar) needed to detect automated traffic;
- interaction telemetry with the page (mouse movement, keyboard activity, page timing) collected in-browser to distinguish humans from bots.
Turnstile is invisible: it does not display a puzzle, does not require you to click a box, and does not use tracking cookies, browser fingerprinting for advertising, or any cross-site identifier. Cloudflare states that Turnstile signals are used only to score the request and are not used to build a profile of you, sold to third parties, or combined with data from other Cloudflare products for marketing. The signals are processed only long enough to return a pass/fail score to us and are then discarded by Cloudflare in accordance with its policy.
Our lawful basis for using Turnstile is legitimate interest (Article 6(1)(f) UK GDPR): protecting our website and users from spam, brute-force attacks, and automated abuse. We have assessed that this interest is not overridden by your rights, given (i) the narrow and technical nature of the signals processed, (ii) their use solely for security purposes, (iii) Cloudflare’s public commitment not to profile users on the basis of these signals, and (iv) the absence of tracking or advertising cookies.
Why we process your data (lawful bases)
We rely on the following lawful bases under Article 6(1) of the UK GDPR:
(a) Consent — Article 6(1)(a)
-
Responding to your enquiry: By submitting the form and ticking the required consent checkbox, you consent to us storing and processing your data to respond to your enquiry.
-
Future contact: If you tick the optional “keep me informed” checkbox, you consent to us retaining your name, email address, and area of interest so we may contact you in the future about activities, courses, or publications from The School of Digital Health that are relevant to the interest you indicated. This is a separate, optional consent — you may submit an enquiry without opting in to future communications.
-
Member accounts: By creating an account you consent to us storing and processing your email address and the associated authentication records so we can operate your account — verifying your email, signing you in, maintaining your session, and enabling password reset. You may withdraw this consent at any time by deleting your account (see “Your rights”), which removes your account and its authentication records.
(f) Legitimate interests — Article 6(1)(f)
- Security data (IP address, user agent, timestamp): Our legitimate interest is protecting the website and its users from spam, automated abuse, and malicious activity. We have assessed that this interest is not overridden by your rights, given the limited nature of the data and its use solely for security purposes.
- Account security: We also have a legitimate interest in keeping member accounts secure — for example, detecting and blocking suspicious sign-in attempts and applying rate limiting to authentication requests.
Who we share your data with
We share your data only with the following service providers, each acting as a data processor on our behalf under a written data processing agreement (Article 28 UK GDPR):
| Processor | Role | Location |
|---|---|---|
| Amazon Web Services (Amazon Web Services EMEA SARL) | Website hosting, database, application logic, and account authentication / identity management (Amazon Cognito) | London region (eu-west-2), UK |
| Brevo (Sendinblue SAS) | Delivery of email notifications to us when an enquiry is submitted | France (EU/EEA) |
| Cloudflare, Inc. | Anti-spam / bot-detection signal processing via Cloudflare Turnstile on the enquiry form and members’ authentication screens (see “Anti-spam protection” above) | Global edge network; corporate entity is US-based |
We do not sell, rent, or trade your personal data. We do not share it with any third party for their own marketing purposes.
International transfers
Personal data that we ourselves store — enquiry submissions and member
account data — is held only within the United Kingdom and the
European Economic Area (London region, eu-west-2).
The one exception is the narrow set of technical signals processed by Cloudflare’s Turnstile bot-detection service on the enquiry form and members’ authentication screens (described under “Anti-spam protection” above). Because Cloudflare, Inc. is US-based and operates a global edge network, these signals may be processed outside the UK and the EEA. This transfer relies on the following safeguards, which Cloudflare makes available under its data processing addendum:
- Cloudflare’s certification under the UK Extension to the EU-US Data Privacy Framework (also known as the UK-US Data Bridge) and the EU-US Data Privacy Framework, providing an adequate level of protection for personal data transferred from the UK / EEA to the US;
- the UK International Data Transfer Agreement and the EU Standard Contractual Clauses as fallback safeguards if the frameworks above cease to apply.
Should the set of processors or transfer arrangements change in the future, we will update this policy and ensure appropriate safeguards are in place before any new transfer occurs.
How long we keep your data
| Data category | Retention period | Basis |
|---|---|---|
| Enquiry data (where you did not opt in to future contact) | 12 months from submission, then automatically deleted | Sufficient to respond to your enquiry and handle any follow-up |
| Enquiry data (where you opted in to future contact) | Until you withdraw consent or for a maximum of 36 months from your last interaction with us, whichever is sooner | Necessary to fulfil the purpose you consented to |
| Security data (IP, user agent, timestamp) | 6 months, then automatically deleted | Sufficient to detect patterns of abuse |
| Member account data (email address and authentication records) | Retained for the life of your account. When you delete your account, your identity and its authentication records are removed so the account can no longer sign in | Necessary to operate the account for as long as you choose to keep it |
You may ask us to delete your data at any time (see “Your rights” below). If you hold a member account, you can delete it yourself at any time from your account settings, which erases your account and its authentication records.
Your rights
Under UK GDPR you have the following rights. These are free of charge unless requests are manifestly unfounded or excessive:
- Right of access (Article 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Article 16) — ask us to correct inaccurate or incomplete data.
- Right to erasure (Article 17) — ask us to delete your data (“the right to be forgotten”).
- Right to restriction of processing (Article 18) — ask us to limit how we use your data while a concern is resolved.
- Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21) — object to processing based on legitimate interests.
- Right to withdraw consent (Article 7(3)) — withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. You can withdraw by emailing us or by using the unsubscribe link in any communication we send.
To exercise any of these rights, contact us at enquiries@schoolofdigitalhealth.org. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it).
Complaints
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Live chat: ico.org.uk/make-a-complaint
We would appreciate the opportunity to address your concerns before you approach the ICO, but you are not required to do so.
Automated decision-making
We do not carry out any automated decision-making or profiling (as described in Article 22 UK GDPR) based on the data you provide.
Children’s data
This website and its services are intended for individuals aged 16 or over. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has submitted data through our form, please contact us and we will delete it promptly.
Security measures
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption at rest (AWS-managed encryption keys);
- Encryption in transit (HTTPS/TLS);
- Access restricted to authorised personnel using multi-factor authentication;
- Regular review of access permissions;
- Data processing agreements with all processors.
Changes to this policy
We may update this policy from time to time. Each version carries a version number and an effective date, both shown at the top of this page, and a summary of substantive changes is recorded in the Version history below. Where we make substantive changes we will provide a summary of what has changed; if you have opted in to future communications, we will notify you by email of any material changes that affect how we use your data.
We keep a record of the policy version in force when you gave consent (for example, when you submitted an enquiry or created an account), so we can always identify which version of this policy applied to you.
Version history
- v1.2 — 5 September 2026. Added the “Anti-spam protection (Cloudflare Turnstile)” section covering our use of Cloudflare’s invisible bot-detection challenge on the enquiry form and the members’ authentication screens (sign-up, forgotten-password, password-reset). Documented the technical signals Turnstile processes (IP address, user-agent, basic device and browser characteristics, in-browser interaction telemetry) and incorporated by reference Cloudflare’s Turnstile Privacy Policy. Named Cloudflare, Inc. as an additional data processor. Expanded the “International transfers” section to disclose the UK→US transfer of the Turnstile signals and identify the safeguards relied on (Cloudflare’s certification under the UK-US Data Bridge and the EU-US Data Privacy Framework, with the UK IDTA and EU SCCs as fallback). Confirmed that Turnstile is used solely for security, does not use tracking cookies or advertising fingerprinting, and does not profile users.
- v1.1 — 27 August 2026. Added the “Member accounts” section covering the members’ area: the personal data collected when you create an account (email address and authentication records), the lawful bases for operating an account, Amazon Cognito named as the identity/authentication service (an Amazon Web Services processor, London region), account-data retention (kept for the life of the account and removed on account deletion), and confirmation that account passwords are never stored in a form we can read. Also clarified that we use only strictly-necessary browser storage to keep signed-in members authenticated, and that we still use no analytics or advertising trackers.
- v1.0 — 5 August 2026. Initial privacy policy covering the website enquiry form: data collected, consent and legitimate-interest lawful bases, processors (Amazon Web Services and Brevo), retention periods, and your rights under UK GDPR.