Legal
Privacy Policy
Data Protection Policy (GDPR Policy)
1. Data protection principles
YCTA is committed to processing data in accordance with its responsibilities under the DPA.
The DPA requires that personal data shall be:
a. processed lawfully, fairly and in a transparent manner in relation to individuals;
b. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
c. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
d. accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
e. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organizational measures required by the DPA in order to safeguard the rights and freedoms of individuals; and
f. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
2. General provisions
a. This policy applies to all personal data processed by YCTA.
b. The Responsible Person shall take responsibility for the YCTA’s ongoing compliance with this policy.
c. This policy shall be reviewed at least annually.
d. YCTA shall register with the Information Commissioner’s Office as an organization that processes personal data.
3. Lawful, fair and transparent processing
a. To ensure its processing of data is lawful, fair and transparent, YCTA shall maintain a Register of Systems.
b. The Register of Systems shall be reviewed at least annually.
c. Individuals have the right to access their personal data and any such requests made to YCTA shall be dealt with in a timely manner.
4. Lawful purposes
a. All data processed by YCTA must be done on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests (see ICO guidance for more information).
b. YCTA shall note the appropriate lawful basis in the Register of Systems.
c. Where consent is relied upon as a lawful basis for processing data, evidence of opt-in consent shall be kept with the personal data.
d. Where communications are sent to individuals based on their consent, the option for the individual to revoke their consent should be clearly available and systems should be in place to ensure such revocation is reflected accurately in YCTA’s systems.
5. Data Minimization
a. YCTA shall ensure that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
6. Accuracy
a. YCTA shall take reasonable steps to ensure personal data is accurate.
b. Where necessary for the lawful basis on which data is processed, steps shall be put in place to ensure that personal data is kept up to date.
7. Archiving / removal
a. To ensure that personal data is kept for no longer than necessary, YCTA shall put in place an archiving policy for each area in which personal data is processed and review this process annually.
b. The archiving policy shall consider what data should/must be retained, for how long, and why.
8. Security
a. YCTA shall ensure that personal data is stored securely using modern software that is kept-up-to-date.
b. Access to personal data shall be limited to personnel who need access and appropriate security should be in place to avoid unauthorized sharing of information.
c. When personal data is deleted this should be done safely such that the data is irrecoverable.
d. Appropriate back-up and disaster recovery solutions shall be in place.
9. Breach
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, YCTA shall promptly assess the risk to people’s rights and freedoms and if appropriate report this breach to the ICO (more information on the ICO website).
10. Personal data we collect
a. Account and profile data: your name, email address, phone number and postal address.
b. Payment data: your purchase is handled by our payment processor (Stripe). We do not store your full card details.
c. Learning data: your course progress, assessment responses and certificates issued to you.
d. Referral data: the email addresses you choose to invite and any referral codes used.
e. Usage and analytics data: pages viewed, links clicked, referring page, campaign (UTM) parameters and a first-party visitor and session identifier — collected only where you have given consent (see section 12).
f. Technical data: IP address, browser and device information and server logs, used to operate and secure the service.
11. How we use your data and our lawful bases
a. To provide and administer the course, your account and your certificate — performance of our contract with you.
b. To take payment and keep required financial records — performance of a contract and compliance with a legal obligation.
c. To secure the platform, prevent fraud and abuse, and improve the service — our legitimate interests.
d. To send you service messages such as enrolment, password reset and completion emails — performance of a contract and our legitimate interests.
e. To send marketing communications and to set analytics and advertising cookies — your consent, which you may withdraw at any time.
12. Cookies and tracking
a. Strictly necessary cookies keep you signed in, remember your cookie choice (the ycta_consent cookie) and protect the site. Because they are essential to the service, they are always active and do not require consent.
b. Analytics cookies: with your consent we set first-party analytics identifiers — ycta_vid (retained for about 12 months) and ycta_sid (retained for about 30 minutes) — to understand traffic and improve YCTA.
c. Advertising and third-party cookies: with your consent our Google Tag Manager container loads Google Analytics 4, Google Ads and the Meta Pixel to measure our marketing and conversions. These remain disabled until you accept — enforced through Google Consent Mode, which defaults to denied.
d. Managing your choice: on your first visit you can Accept all or Reject non-essential cookies in the consent banner. You can change your decision at any time by clearing the ycta_consent cookie (which brings the banner back) or by adjusting your browser cookie settings. Rejecting non-essential cookies does not affect your access to the course.
13. Who we share your data with
We do not sell your personal data. We share it only with service providers who process it on our behalf under contract, and only as needed to run the service:
a. Supabase — application hosting, database, authentication and file storage.
b. Stripe — payment processing.
c. Vimeo — delivery of course video.
d. Resend — delivery of transactional and marketing email.
e. Google (Analytics, Ads and Tag Manager) and Meta (Pixel) — analytics and advertising, only where you have given consent.
f. We may also disclose personal data where required to do so by law or to protect our legal rights.
14. International transfers
Our service providers are located in, and may process your data in, the United States and other countries. Where personal data is transferred outside your country, we rely on appropriate safeguards such as our providers' Standard Contractual Clauses and equivalent protections.
15. Data retention
We keep your personal data for as long as your account is active and for as long as needed to provide the service, and thereafter only for any period required to meet legal, accounting or reporting obligations, after which it is securely deleted or anonymized.
16. Your rights
Subject to applicable law, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to our processing; receive your data in a portable format; and withdraw consent at any time (without affecting processing carried out before withdrawal).
You also have the right to lodge a complaint with your data protection supervisory authority — in the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, contact us at info@yct.academy or through our Contact page. We will respond within the timeframes required by law.
You can also export your personal data, or permanently delete your account and associated data, at any time from the Account area of your student dashboard.
17. Data controller and contact
Yacht Charter Training Academy is the data controller for the personal data described in this policy.
For any privacy question, or to exercise your rights, contact us at info@yct.academy or via our Contact page.
We may update this policy from time to time; material changes will be reflected on this page. Last updated: July 2026.
