Privacy Policy
How FLT Academy Ltd collects, uses, shares and protects personal information.
Last updated: 11 September 2026
FLT Academy Ltd is the controller of the personal information described in this notice. We are registered in England and Wales under company number 17332251, with our registered office at 10A Home Road, Bedford, MK43 9BL. You can contact us at info@fltacademy.co.uk or 07379 260161.
Who this notice applies to
This notice applies to visitors, training customers and candidates, candidate account holders, recruitment-agency and employer users, job applicants, certificate holders, Trusted Partner applicants and people who contact us or subscribe to vacancy alerts or News & Rewards updates.
Information we collect
Depending on how you use our services, we may collect:
- identity and contact details, including your name, email address, telephone number, date of birth and postal address;
- account and security information, including sign-in details, account status, audit records, whether two-factor security is active, and protected authenticator and one-use recovery-code records;
- training, certificate and training-card information, including course details, completion and review dates, certificate and card numbers, certificate documents and card approval status;
- booking, order and payment information, including the service selected, amount, payment status and Stripe transaction reference. We do not receive or store your full card number;
- candidate and recruitment information, including your CV profile, general location, home county, other counties where you would work, preferred travel distance, employment history, availability, preferred shifts, experience, additional qualifications, optional qualification evidence, job applications and introduction choices;
- business advertiser and vacancy information, including business type, contact details, company number, job descriptions, application email addresses and advert photographs;
- Trusted Partner application information, including the business name, category, website, location, summary, contact details, link-back page, consent and review decision;
- referral information, including the referral code used, the referring account, reward status, qualifying purchase or training completion and credits awarded;
- profile photographs and your separate choices about where a photograph may be displayed, together with your separate optional choice to display your age rather than your date of birth on a generated CV;
- communications, enquiries, feedback and records of how we respond;
- News & Rewards subscription information, including the email address, confirmation, unsubscribe choice and the announcements already sent;
- questions sent to Cody, our optional AI website assistant, including optional CV-drafting prompts about a candidate's real work experience, skills or training. We also receive the recent Cody conversation supplied with a question, the selected reply language and limited page context needed to produce a relevant answer. For service improvement, we keep a locally redacted copy of the latest question, its general audience, language, page, token totals and optional helpful or needs-work rating for up to 90 days; and
- limited technical, security and consented analytics information, such as page, device category, referring website, browser or robot identifier, approximate country or area, a privacy-protected network identifier and security events. Exact network addresses are encrypted only until an on-server approximate location check is completed and are not displayed in the administrator report.
Please do not place unnecessary health, financial, identity-document or other sensitive information in a CV, free-text form or email. If information about health or reasonable adjustments is needed to deliver training safely, we will explain why it is needed and handle it with additional care.
Where information comes from
Most information comes directly from you. We may also receive training or certificate information from our trainer, an employer or training customer that booked on your behalf, an accreditation or registration body, a recruitment agency or direct employer when it manages a vacancy, and service providers that confirm payments or email delivery. We tell you about the relevant use when we obtain information from another source.
How and why we use information
- Enquiries and quotations: to respond, understand your requirements and take steps towards a contract.
- Training and bookings: to check suitability, reserve places, take payment, provide joining information, deliver training, maintain training records and issue certificates. We rely on our contract with you, steps requested before a contract, legal obligations and legitimate interests in running safe, accountable training.
- Candidate and business accounts: to create, verify, approve, secure and administer accounts and prevent misuse. This includes providing optional authenticator-app two-factor security, one-use recovery codes and stronger protection where an administrator account requires it. We rely on the service contract and our legitimate interests in protecting users and the platform.
- Certificates and training cards: to store and supply training records, create approved photo cards, send expiry reminders and provide limited public verification by certificate or card number. We rely on the service contract, legitimate interests in confirming genuine training and, where applicable, record-keeping obligations.
- Job applications: to send an application and the selected CV to the recruitment agency or direct employer advertising a vacancy when the candidate asks us to do so. That business becomes responsible for its own use of the application.
- CV builder and qualification checks: to create a candidate-controlled CV, attach the current version to an application, and allow FLT Academy staff to review privately uploaded evidence before marking an additional qualification as verified. Full home addresses and dates of birth are not placed on generated CVs. Photo and age display are optional and off by default.
- Candidate Match: to show an approved recruitment business limited candidate details or allow an introduction request only while the candidate has actively opted in. This choice can be withdrawn through the candidate account.
- Secure messages: to let a candidate and an approved recruitment agency or direct employer communicate after a job application or accepted introduction. Messages stay inside the protected accounts; notification emails say that a message is waiting but do not include its contents. We use the service contract and our legitimate interests in providing safe recruitment communication, preventing misuse and reviewing reports.
- Local jobs and job alerts: to prioritise genuine approved vacancies in the counties a candidate selects and send matching county, town or category alerts only after double opt-in confirmation. We also use anonymous county totals in the private administrator area to understand where candidate demand is growing; these totals do not identify candidates. We rely on the service contract and legitimate interests for local job ordering and anonymous planning, and on consent for alert emails. Every alert includes an unsubscribe link.
- News & Rewards updates: to send new articles, member bonuses and partner offers only after double opt-in confirmation. We rely on consent; every announcement includes an unsubscribe link. Reading public articles does not require a subscription.
- Payments and orders: to create Stripe Checkout sessions, reconcile payments, prevent fraud, fulfil digital or postal certificate orders and keep accounting records.
- Referral Programme: to attribute new accounts to a unique referral link, show progress in the referring account, issue valid credits or free adverts, notify participants and prevent self-referral, duplicate accounts, fraud and abuse. We rely on the service contract and our legitimate interests in operating and protecting the programme.
- Trusted Partners: to review genuine business applications, contact the applicant about the review, publish approved business details in the directory and provide approved referral-banner code. We rely on the applicant's requested steps, consent to publication and our legitimate interests in maintaining a useful, moderated directory.
- Safety, security and legal compliance: to detect abuse, rate-limit certificate searches, investigate problems, establish or defend legal claims and meet legal or regulatory requirements.
- Essential visitor activity: to understand website demand, distinguish people from search engines and other robots, identify broken or abused pages and protect the service. This server-side record does not use an analytics cookie and is based on our legitimate interests in operating, understanding and securing the website. Approximate location is calculated locally from an on-server IP location database; a visitor's network address is not sent to the database provider.
- Optional analytics and Google Ads measurement: to understand use of public pages and whether Google Ads visits lead to business registration, only after optional measurement consent. Candidate, agency and administrator dashboards, payment areas and certificate-check pages are excluded.
- Cody AI assistant: to answer optional questions about FLT Academy services, help visitors navigate the public website and protected account areas, and help candidates draft CV wording from their real experience when they choose to ask. Cody's suggestions are for the candidate to review and add to their own CV; Cody cannot see, edit or save a candidate's account CV, and is not used to make employment decisions. Before a question is kept for service improvement, common emails, links, phone-like numbers, postcodes, identifiers and stated names are removed locally. Cody does not receive unrestricted access to account, payment, certificate or message records and must not be given passwords, payment details, identity documents or unnecessary sensitive information. We rely on our legitimate interests in providing and improving accessible customer support and the steps a visitor asks us to take before a service contract.
We do not make decisions with legal or similarly significant effects using solely automated processing.
Certificate and training-card verification
A successful check requires a certificate or training-card number and the candidate surname. A card QR code supplies only its random verification reference; the surname is still required. Results show limited training information and do not expose certificate files, dates of birth, addresses or contact details. A profile photograph appears in a public result only where the candidate has given separate permission. That permission may be withdrawn at any time without affecting the underlying training record.
Certificate verification shows the holder's full name, certificate number, training and truck details, instructor, assessment results and original dates/status so employers can compare them with the certificate and the holder's identity. Following account deletion, certificate QR references and this limited verification service remain available for the remainder of our five-year period from training. The profile photograph is removed. Certificate expiry and revocation are not reset by deletion. Verification stops when the retained record expires.
Who we share information with
We share only what is reasonably necessary with:
- Stripe for secure payment processing;
- Resend for transactional messages, reminders, consented vacancy alerts and consented News & Rewards updates;
- our hosting, database, secure-file storage, backup and website-support providers;
- Microsoft, where communications are handled through our business email service;
- OpenAI, where a visitor chooses to send a question to the Cody AI assistant, including an optional CV-drafting prompt. We send the question, limited recent conversation and page context through the OpenAI API with response storage disabled in our request;
- trainers, training customers, accreditation or registration bodies where necessary to administer training and certification;
- the recruitment agency or direct employer advertising a vacancy, when a candidate submits an application to it;
- approved recruitment businesses using Candidate Match, but only within the candidate's active choices;
- professional advisers, insurers, payment-dispute services, regulators, courts, law enforcement or public authorities where reasonably necessary or required by law; and
- a purchaser or successor if the business is reorganised or sold, subject to appropriate confidentiality and data-protection safeguards.
Recruitment agencies and direct employers are independent controllers for the applications they receive. Candidates should also read the relevant business advertiser's privacy information before applying.
For an approved Trusted Partner, the business name, category, website, location and submitted summary may be shown publicly. The contact person's private email address and telephone number are used for administration and are not published in the directory unless the person separately asks us to do so.
International processing
Some technology providers may process information outside the UK. Where this happens, we use a lawful transfer mechanism, such as UK adequacy regulations or approved contractual safeguards, and apply additional protections where required. You may contact us for more information about the safeguards relevant to your information.
How long we keep information
We keep information only for as long as needed for the purpose collected, legal obligations, accreditation requirements, security and the handling of disputes. Our usual periods are:
- enquiries that do not become bookings: up to 24 months after the last contact;
- training records, certificate copies, assessment evidence and the minimum identifying details: five years from the training date under our training-record policy. This is separate from certificate expiry and from retaining an active app account;
- necessary booking, payment and order records: normally six years after the relevant service or transaction. Existing paid bookings and unfulfilled orders remain available to authorised staff for fulfilment after account deletion;
- account login, profile and recruitment information: deleted when a confirmed online account-deletion request is processed. The account is frozen immediately; automatic deletion normally runs within 15 minutes. Technical or necessary record-review exceptions are tracked and resolved within one calendar month. We provide completion confirmation and explain any restricted retained records and their expiry dates. A minimal deletion reference and processing record are retained to prevent accidental restoration and demonstrate completion;
- CV profiles, employment history, additional qualifications and private evidence: while the candidate account is active; inactive CV versions and job applications are normally kept no longer than 24 months after the last relevant activity, unless the candidate asks for earlier deletion or retention is needed for a dispute;
- secure recruitment messages and associated reports: normally no longer than 24 months after the last relevant activity, unless earlier deletion is appropriate or longer retention is needed to investigate misuse, handle a complaint or establish or defend a legal claim;
- live job adverts: 30 days after approval; associated payment and moderation records may be retained for up to 6 years;
- referral and reward records: normally while either account remains active and up to 6 years after the final reward or related transaction where needed for accounting, fraud prevention or disputes;
- Trusted Partner applications: while a listing is active, or normally up to 24 months after rejection, removal or the last relevant contact; a minimal review record may be retained longer where needed to prevent abuse or handle a dispute;
- job-alert details: while subscribed. After unsubscribing, we retain the minimum consent and suppression record needed to honour the choice and demonstrate compliance;
- News & Rewards subscription details: while subscribed. After unsubscribing, we retain the minimum consent and suppression record needed to honour the choice and demonstrate compliance;
- private server-side visitor activity, including robots, referring websites and approximate locations: up to 90 days. Exact network addresses are removed after the on-server approximate location check; privacy-protected visitor identifiers are not shown outside authorised administration;
- raw consented analytics events: up to 90 days; aggregated daily totals that do not identify account holders: up to 2 years; and
- security and verification-attempt records: only for the period reasonably needed to prevent abuse, investigate incidents and protect the service.
- Cody conversations: the recent conversation is normally kept in that browser for up to 24 hours so it can continue between pages and can be cleared at any time using Cody's clear button. FLT Academy keeps a locally redacted question, limited context, token totals and optional rating for up to 90 days to improve the service, but does not keep Cody's full answer or link this improvement record to an account or raw network address. Our service providers may retain limited information under their own security and legal requirements; and
We securely delete, anonymise or restrict information when it is no longer required. Backup copies expire through the normal backup cycle.
Security
We use access controls, encrypted connections, protected private-file storage, encryption for selected high-risk fields, authenticator-app two-factor security, signed payment notifications, rate limits, logging and backups. Recovery codes are intended for the account holder alone: keep them private and replace them promptly if they may have been copied. No internet service can promise absolute security, so please use a strong, unique password and tell us promptly if you suspect misuse.
Your rights
Subject to the circumstances and exemptions in data-protection law, you may ask us to:
- give you a copy of your personal information;
- correct inaccurate or incomplete information;
- delete information or restrict how it is used;
- provide certain information in a portable format;
- stop processing based on legitimate interests; or
- withdraw consent at any time where consent is the basis, including for job alerts, News & Rewards updates, Candidate Match, photographs, optional analytics and Google Ads measurement.
Withdrawing consent does not make earlier lawful use invalid. We may need to verify your identity before completing a request. Contact info@fltacademy.co.uk. We normally respond within one month.
Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
Changes to this notice
We may update this notice when our services or legal responsibilities change. The date at the top shows the current version. We will provide a prominent notice where a change materially affects how existing account information is used.
