Privacy & Cookie Policy
Last updated: 31 July 2026 · Version 1.1 · UK GDPR / Data Protection Act 2018 / PECR
This policy explains how Comera Medical Training ("we", "us", "our") collects, uses, shares and protects personal data when you visit our website or get in touch about our training, and your rights under UK data protection law.
It covers visitors to our website and people who enquire about our courses. If you go on to book or attend training, we will give you any additional privacy information relevant to delivering and certifying that training.
Who we are
- Data controller: Comera Medical Training Limited, a company registered in England and Wales under company number 08728994, part of Comera Group.
- Registered/office address: Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP, United Kingdom.
- ICO registration number: ZA476308.
- Data protection contact: privacy@comeragroup.co.uk.
- General enquiries: medenquiries@comeragroup.co.uk.
This policy is governed by UK data protection law, principally the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) for cookies and marketing.
What data we collect
- Enquiry & contact data you give us through our enquiry form: your name, email address, organisation (if you provide it), phone number (if you provide it), the nature of your enquiry, and whether you opt in to marketing.
- Booking & billing data, if your enquiry becomes a booking: the billing name, organisation, address and contact details needed to raise an invoice, plus the invoice and payment record. See Booking and payment.
- Communications: the content of any emails or messages you send us.
- Technical & usage data: IP address, device and browser type, pages visited and referring pages — collected through cookies and analytics, and only with your consent for non-essential cookies (see Cookies below).
Please don't include health or other sensitive personal information in a form message. This website is not intended to collect special category data. Any health information needed to deliver a course safely (for example a medical declaration) is collected separately as part of the booking/training process, with its own privacy information and safeguards.
Booking and payment
Most of our training is booked by arrangement, not online. You send us an enquiry, we contact you to agree dates, numbers and location, and the course is then normally invoiced. To do that we hold the billing details you give us — your name, your organisation, a billing address and contact details — and the invoice and payment records that follow. We keep those records because tax and company law require it.
Two things are handled elsewhere. First Aid at Home, our online course, is bought directly on the Comera store (store.comeragroup.co.uk), and online learning is delivered through the Comera Group learning platform (lms.comeragroup.co.uk). Both are operated within Comera Group and have their own privacy and cookie information, which applies when you use them.
We never collect or process card details through this website.
How we use your data and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Respond to your enquiry about training | Taking steps at your request before entering a contract (Art. 6(1)(b)), and our legitimate interests in responding to enquiries (Art. 6(1)(f)) |
| Manage our relationship with you and keep business records | Legitimate interests; legal obligation |
| Arrange and invoice a course you have booked, and keep the accounting records | Contract (Art. 6(1)(b)); legal obligation for the accounting and tax records (Art. 6(1)(c)) |
| Send you marketing (occasional course news and updates) | Consent (Art. 6(1)(a)) — only if you opt in; you can withdraw at any time |
| Measure and improve the website | Consent (for non-essential analytics cookies) |
| Deliver, assess and certify training you book (if you become a learner) | Contract; legal obligation; and, for any health data, explicit consent or another Art. 9 condition, explained to you at the time |
We will only send you marketing if you have opted in, and every marketing email includes an unsubscribe link. We do not sell your data or share it with third parties for their own marketing.
Cookies and similar technologies
When you first visit our site we show a cookie banner that lets you accept or reject non-essential cookies. Non-essential cookies are not set until you consent, and you can change your choice at any time by clearing the site data in your browser. We use the following categories:
| Category | Examples | Purpose | Consent needed? |
|---|---|---|---|
| Strictly necessary | A record of your cookie choice, stored in your browser | Remembers your consent decision so we don't ask again, and keeps the site working | No — required for the service |
| Analytics / performance | Google Analytics (_ga, _ga_*) | Measures how the site is used so we can improve it | Yes |
Google Analytics loads only after you accept analytics cookies. We enable IP anonymisation and do not use it for advertising. Google Analytics cookies last up to 2 years; we retain the analytics data for up to 14 months. You can also block or delete cookies through your browser settings, though some parts of the site may not work properly without strictly necessary cookies.
Who we share your data with
We do not sell your data. We share it only with providers who help us run our business, each under a contract that requires them to protect it and use it only on our instructions. These are the categories of recipient, and the providers in each:
- Our website host — hosts this website.
- Zoho Corporation — ZeptoMail (EU) — sends transactional emails, such as the acknowledgement you receive after making an enquiry.
- Zoho Corporation — Zoho CRM & Zoho Campaigns — manages enquiries and, if you opt in, sends our marketing.
- Google — Google Analytics, used only with your consent.
- Comera Group — the Comera store and learning platform, when you buy our online course or access e-learning.
- Our accountants and accounting software — invoicing, bookkeeping and statutory accounts.
We may also disclose data where required by law, by a regulator, or to establish, exercise or defend legal claims. Where a course is delivered under an awarding organisation (for example QA Awards) or a funding scheme, we share the data necessary to register, assess and certify you — this is explained when you book.
International transfers
Some of our providers process data outside the UK. Where they do, an appropriate safeguard is in place:
| Provider | Role | Location | Safeguard |
|---|---|---|---|
| Zoho (ZeptoMail) | Transactional email | European Union | UK adequacy regulations for the EEA |
| Zoho (CRM / Campaigns) | CRM & marketing | International | International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses |
| Analytics | United States / global | UK Extension to the EU–US Data Privacy Framework and/or the IDTA |
Details of the specific safeguards are available on request from our data protection contact.
How long we keep your data
- Enquiries that don't lead to a booking: up to 24 months from your last contact with us, then deleted.
- Marketing contacts: until you unsubscribe or withdraw consent (we also review our list periodically).
- Website analytics: up to 14 months.
- Invoices & accounting records: six years from the end of the financial year they relate to, as company and tax law require.
- Training & certification records (if you attend a course): kept for as long as the relevant awarding organisation and applicable law require. The exact period is set by the awarding organisation for your qualification, and we tell you when you book.
We keep personal data no longer than necessary for the purpose it was collected, unless the law requires us to keep it for longer.
How we protect your data
We use technical and organisational measures proportionate to the data we hold: encryption in transit (HTTPS/TLS), reputable service providers, access limited to those who need it, and protections on our forms against spam and abuse. No system is completely secure, but we take reasonable steps to safeguard your information.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to our processing of your personal data, to data portability, and to withdraw consent at any time where processing is based on consent. To exercise any of these, contact our data protection contact above. We will respond within one month, and there is normally no charge.
Complaints
If you have concerns about how we handle your data, please contact us first so we can try to put things right. You also have the right to complain to the UK supervisory authority: the Information Commissioner's Office (ICO) — ico.org.uk, helpline 0303 123 1113.
Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "last updated" date above. Where changes are significant, we will take reasonable steps to highlight them.
Contact us
Comera Medical Training Limited
Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP
Data protection: privacy@comeragroup.co.uk
General enquiries: medenquiries@comeragroup.co.uk
0117 971 8124