Privacy and Cookie Policy

Centre for Homeopathic Education (CHE) group: websites, courses, app and services

Version

3.0

Effective Date

September 2026

Review Date

September 2027

Policy Owner

Data Protection Lead

Controller: CHE Health & Wellbeing Limited, company number 10722903, ICO registration ZB035578

Data protection enquiries and requests: [email protected] (Data Protection Lead)

All other enquiries: [email protected] · 020 3405 4580

1. About this policy

1.1 This policy explains how we collect and use personal information about people who visit our websites, enquire about or apply for our courses, study with us, apply for a scholarship, use the CHE app, attend our events, receive our communications or apply to work with us. It also explains how we use cookies and what rights you have.

1.2 It covers chehomeopathy.com, cheonline.co.uk, the CHE mobile app, our learning platforms and community spaces, and our events and communications.

1.3 Two groups of people have their own notice, which applies instead of this policy where the two differ:

  • Patients of the CHE Homeopathy Clinic: see our Clinic Privacy Notice, available on our clinic page (https://chehomeopathy.com/che-homeopathy-clinic/) and at booking.
  • CHE PRO Members and scorecard users: see the CHE PRO Privacy Policy on the CHE PRO website.

1.4 We comply with UK data protection law (the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations) and, where it applies to you, the EU General Data Protection Regulation.

2. Who we are

2.1 CHE Health & Wellbeing Limited (“CHE“, “we“, “us” and “our“) is the controller of your personal information. We are registered in England and Wales under company number 10722903, our registered office is 4th Floor, 100 Fenchurch Street, London EC3M 5JD, and we are registered with the Information Commissioner’s Office under registration number ZB035578. We trade as the Centre for Homeopathic Education (CHE).

2.2 CHE Health & Wellbeing Limited is the group company of the CHE group, which also includes CHE Online Limited, CHE London Limited and CHE PRO Limited. Where you contract with another group company (for example for an online course), that company also uses your information for that contract, under the same rules and safeguards set out in this policy. CHE Health & Wellbeing Limited remains your point of contact for all data protection matters.

2.3 Data Protection Lead. Our Data Protection Lead, Marcus Fernandez, oversees how we handle personal information. Contact them at [email protected] or by post to our registered office, marked “For the attention of the Data Protection Lead”.

2.4 EU representative. We have appointed Prighter Group, with its local partners, as our representative in the European Union under Article 27 of the EU GDPR. If you are in the EU, you can contact us through Prighter, or use it to exercise your rights, at https://app.prighter.com/portal/EU-GDPR.

3. The information we collect

3.1 Depending on how you interact with us, we collect the following:

Type of information
Examples

Providing our educational services and the App

Contract performance

Processing enrolments, fees and transactions

Contract performance

Account management and security

Contract / Legitimate interests

Sending course updates and notifications

Contract performance

Sending marketing communications

Consent (withdrawable at any time)

Analytics and improving our website and App

Legitimate interests

Compliance with legal obligations (e.g. HMRC, accreditation bodies)

Legal obligation

Protecting vital interests in an emergency

Vital interests

Establishing, exercising or defending legal claims

Legitimate interests

4. Sharing Your Personal Data

We do not sell your personal data. We may share it with:

  • Group companies: CHE Health and Wellbeing Ltd (holding company), CHE Online Ltd, CHE London Ltd and CHE Pro Ltd, where necessary for the purposes described in this policy.
  • Payment processors: Stripe and PayPal process card payments on our behalf. Their privacy policies are available at stripe.com/gb/privacy and paypal.com.
  • Learning platforms: Kajabi and Thinkific host our online course content and hold student progress data.
  • CRM and marketing: ActiveCampaign and ConvertFlow support student communications. ConvertFlow uses Amazon Web Services and FullContact for data enrichment, both of which operate appropriate safeguards.
  • Teaching staff and lecturers: academic performance data is shared with lecturers and staff as necessary for educational administration.
  • Accreditation and regulatory bodies: we may share relevant data with the Society of Homeopaths, Middlesex University or other accrediting bodies.
  • Professional advisers and insurers: solicitors, accountants and insurers where necessary.
  • Law enforcement or regulators: where required by law or to protect rights and safety.

5. International Transfers

Some of our service providers are based in the United States, including Stripe, PayPal, ActiveCampaign, ConvertFlow, Kajabi and Thinkific. Transfers to the USA are protected by Standard Contractual Clauses approved by the UK ICO (or equivalent UK adequacy mechanisms). You may obtain a copy of the relevant safeguards by contacting our Data Protection Officer.

The UK ICO’s guidance on international transfers is available at ico.org.uk.

6. Data Retention

We retain personal data only for as long as necessary. Our standard retention periods are:

  • Student academic records (grades, attendance, assessments): minimum 3 years after graduation or leaving, maximum 5 years.
  • Application forms: minimum 3 years after graduation or leaving, maximum 5 years.
  • Transaction data: minimum 6 years (to comply with HMRC requirements).
  • Enquiry data: minimum 12 months, maximum 24 months.
  • Marketing email addresses: minimum 1 year, maximum 4 years (or until consent withdrawn).
  • App usage logs and device data: maximum 12 months unless needed for ongoing dispute resolution.

We may retain data longer where required by a legal obligation or to defend legal claims.

7. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of personal data in transit (TLS) and at rest.
  • Access controls and role-based permissions to limit who can access your data.
  • Regular security reviews and staff training.
  • Secure hosting within the United Kingdom.

Despite our precautions, transmission of data over the internet carries inherent risk. Please protect your account password and notify us immediately if you suspect unauthorised access.

8. Cookies & Tracking Technologies

Our websites and App use cookies and similar technologies. We use: 

  • Strictly necessary cookies: essential for the website and App to function (no consent required).
  • Analytics cookies: Google Analytics, Hotjar — to understand how users interact with our services. These require your consent.
  • Marketing/advertising cookies: Google AdSense, Facebook, LinkedIn, Pinterest — to deliver relevant advertisements. These require your consent.
  • Functional cookies: ConvertFlow, Tawk.to (live chat) — to personalise your experience.

You can manage cookie preferences at any time via our cookie consent banner or your browser settings. Detailed cookie information is provided in our Cookie Notice, available on our website.

9. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access: to receive a copy of the personal data we hold about you (Subject Access Request).
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure (“right to be forgotten”): to request deletion of your data in certain circumstances.
  • Right to restrict processing: to request that we limit how we use your data.
  • Right to object: to object to processing based on legitimate interests or for direct marketing.
  • Right to data portability: to receive your data in a structured, machine-readable format.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
  • Right to complain: you have the right to lodge a complaint with the ICO (ico.org.uk, 0303 123 1113).

To exercise any of these rights, contact our Data Protection Officer at [email protected], or write to us at the address below. We will respond within one calendar month.

10. Children

Our services are directed at persons aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that we hold personal data of a person under 18, we will delete it promptly.

11. Third-Party Links

Our websites and App may contain links to third-party websites. We are not responsible for the privacy practices of those sites and recommend you review their privacy policies before providing any personal data.

12. How to Delete Your Data

You have the right to request deletion of your personal data at any time, subject to our legal retention obligations.

  • By email: send a deletion request to [email protected] with the subject line ‘Data Deletion Request’.
  • In-App: go to Settings > Account > Delete My Account to request deletion of your App account and associated data.
  • By post: write to the Data Protection Officer at the address in Section 14.

We will delete or anonymise your data within 30 days and confirm this to you by email. Some data must be retained to comply with legal obligations (e.g. financial records for 6 years under HMRC requirements, academic records for up to 5 years for accreditation purposes). We will inform you of any such retention at the time of your request.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will publish any changes on our website and, where changes are significant, notify you by email. The version date at the top of this document indicates when it was last updated.

14. Contact Us

If you have any questions about this policy or wish to exercise your rights, please contact:

Data Protection Officer: Marcus Fernandez