Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Independent Investigation Services collects, uses, shares and protects your personal data when you use IIS Academy (the "Platform"), and sets out your rights. We are committed to protecting your privacy and to handling your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
1. Who we are & data controller
Independent Investigation Services is the data controller responsible for the personal data processed through IIS Academy. This means we decide how and why your personal data is processed. If you have any questions about this policy or about how we handle your data, you can contact us at support@iisinvestigations.co.uk or via our website at iisinvestigations.co.uk.
2. What data we collect
- Account & profile data: your name, email address, password (which is stored only in a securely hashed form by our authentication provider), and any profile details you choose to provide.
- Payment metadata: when you buy a course, your payment is processed by Stripe. We receive only limited metadata such as the transaction reference, amount, currency, payment status and the card brand and last four digits. We do not receive or store your full card number or security code — these are handled directly and securely by Stripe.
- Usage & progress data: the courses you are enrolled in, your lesson and chapter progress, assessment results, certificates issued to you, and technical information such as device and browser type, IP address and log data.
- Support communications: the messages, emails and any information you provide when you contact us for help or make a request.
3. How & why we use your data
We use your personal data for the purposes below, relying on the following lawful bases under UK GDPR:
- To provide the service — creating your account, delivering courses, tracking progress and issuing certificates. Lawful basis: performance of our contract with you.
- To process payments and prevent fraud — taking payment for courses and protecting against fraudulent transactions. Lawful basis: contract, legal obligation and our legitimate interests.
- To send transactional emails — such as receipts, account notifications and certificate emails. Lawful basis: performance of our contract with you.
- To secure, maintain and improve the Platform — diagnosing problems, keeping the service secure and improving our courses. Lawful basis: our legitimate interests in running a safe, reliable service.
- To meet legal and financial obligations — including accounting, tax and record-keeping duties. Lawful basis: compliance with a legal obligation.
- To send optional marketing — only where you have opted in, and you can withdraw your consent at any time. Lawful basis: consent.
4. Cookies & essential storage
We use strictly necessary cookies and similar browser storage to operate the Platform — for example, to keep you signed in, to maintain your session, and to protect the security of your account (such as authentication and session tokens). These are essential to provide the service you have requested and do not require your consent. We keep the use of non-essential cookies to a minimum; where we ever introduce any analytics or similar non-essential storage, we will ask for your consent first. We do not use third-party advertising cookies.
5. Third-party processors we use
We use a small number of carefully selected service providers who process personal data on our behalf, under written data-processing agreements and only as needed to provide their service to us:
- Supabase — hosting, database, authentication and file storage for the Platform.
- Stripe — secure payment processing.
- Resend — delivery of transactional email (such as receipts and account notifications).
- Mux — hosting, encoding and streaming of course videos.
6. International transfers
Some of our processors operate outside the United Kingdom. Where personal data is transferred to a country outside the UK, we make sure that appropriate safeguards are in place to protect it, such as reliance on UK adequacy regulations or the use of the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses). You can contact us for more information about the safeguards we use.
7. Data retention
We keep your personal data only for as long as necessary for the purposes for which it was collected. Account, enrolment and progress data is kept while your account remains active and for a reasonable period afterwards. Transaction and tax records are retained for as long as we are required to keep them by law (typically six years for UK accounting and tax purposes). Support communications are kept for a reasonable period to help us handle follow-up queries. When personal data is no longer needed, we securely delete or anonymise it.
8. Your rights under UK GDPR
Subject to certain conditions and exemptions, you have the following rights in relation to your personal data:
- Access — to request a copy of the personal data we hold about you.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to ask us to delete your personal data in certain circumstances.
- Restriction — to ask us to limit how we use your data.
- Portability — to receive certain data in a portable, machine-readable format.
- Objection — to object to processing based on our legitimate interests, and to withdraw consent where we rely on it.
To exercise any of these rights, please contact us at support@iisinvestigations.co.uk. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk — though we would appreciate the chance to resolve your concerns first.
9. Children
IIS Academy is intended for adults and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under the age of 18, and if we become aware that we have done so, we will take steps to delete it.
10. Data security
We take the security of your personal data seriously and put in place appropriate technical and organisational measures to protect it. These include encryption of data in transit (HTTPS), storing passwords only in hashed form, access controls that limit who can view personal data, and the use of reputable infrastructure providers. While no method of transmission or storage is completely secure, we work hard to protect your data and, in the event of a personal-data breach that is likely to affect your rights, we will notify you and the ICO where we are required to do so by law.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our processors or the law. When we do, we will post the updated policy here with a revised "Last updated" date, and where the changes are material we will take reasonable steps to notify you.
12. How to contact us or make a request
If you have any questions about this policy, wish to exercise your rights, or want to make a data-protection request, please contact Independent Investigation Services:
- Email: support@iisinvestigations.co.uk
- Website: iisinvestigations.co.uk
