Skip to content
ICORA MED

Privacy Policy

Last updated: 6 September 2026.

This Privacy Policy explains how ICORA MED LTD ("ICORA MED", "we", "us") collects, uses and protects personal information when you use this website and training platform.

Information we collect

Account and learning records: full name, email address, optional country, phone and organisation; course enrolments, progress, assessment results, certificates and any learning reflections you add.

Membership records: your membership type, status, start date and Founding Member number where applicable.

Questions and content you submit: questions sent through Ask ICORA MED, messages to course creators, contact and enquiry form submissions, event registrations, the email address you give us when you ask to be told that a course has opened for enrolment, and the questions you ask the in-course AI assistant together with its replies.

Email subscription records: if you subscribe to updates, your email address, optional name, the fact that you gave consent, and the date and source of that consent.

Payments: where you buy a paid course or membership, payment and order records are processed by our payment provider, Stripe, which does not share full card details with us; we receive your name, email address, the amount paid and a transaction reference.

How we use your information

To provide access to enrolled courses, issue and verify certificates, operate membership and Ask ICORA MED, respond to enquiries, and send essential account and course-related emails.

Marketing emails — updates about new courses, articles, activities and resources — are sent only to people who have actively given consent by ticking the subscription box. We never add you to that list automatically, and every marketing email contains a one-click unsubscribe link. Essential emails about your account, enrolments and certificates are separate and are not marketing.

We do not sell personal information and we do not use advertising profiling.

Sharing and processing

We use service providers to operate the platform: Supabase (database, accounts and file storage), Resend (email delivery), Stripe (payments) and OpenAI (drafting and narration tools used by our content team on material they choose to upload, and the in-course AI assistant available on some courses: when you use the assistant, the question you type, the earlier messages in that conversation and the relevant course material are sent to OpenAI to generate a reply). Your account details, enrolments, payment records and questions submitted through Ask ICORA MED are not sent to OpenAI. These providers process data on our behalf under their data-processing terms.

Some of them store or process data outside the UK and the European Economic Area, including in the United States; where they do, the transfer is made under safeguards recognised under UK and EU data-protection law, such as the UK International Data Transfer Addendum or standard contractual clauses, or under an adequacy decision where one applies. You can ask us which safeguard applies to a particular provider and for a copy of it.

Questions published in the Knowledge Base

Questions you submit through Ask ICORA MED are private between you and the ICORA MED team. A question and its response are only published in the public Knowledge Base if you have given permission when submitting it, and published entries are edited to remove identifying details. You can withdraw that permission by contacting us.

Cookies

We use only the browser storage that is strictly necessary for the site to work. Once you have an account, a session cookie keeps you signed in. A small local-storage entry records that you have seen the cookie notice. We set no cookies for visitors who are not signed in, and none for advertising or analytics. The light or dark appearance follows your device setting and is not stored. Payments are taken on Stripe's own hosted checkout page; any cookies Stripe uses there are set on Stripe's domain and covered by Stripe's privacy policy.

Data retention and your rights

We retain account and course records for as long as your account is active and as required for legal, tax and certification purposes — certificate records are kept so that issued certificates remain verifiable. Email subscription records, including your consent and any later unsubscribe, are kept as evidence that we had permission to contact you.

Anyone who has a certificate ID, for example an employer, recruiter or auditor, can enter it on our verification page and see the name the certificate was issued to, the course title, the issue date and whether the certificate is still valid. Nothing else about your account is shown. This remains the case after you close your account, so that certificates already issued to you stay verifiable.

You may request access to, correction of, or deletion of your personal information; you may object to, or ask us to restrict, processing based on our legitimate interests; and you may ask for the information you gave us in a portable, machine-readable format. We normally respond to such requests within one month, subject to any extension permitted by applicable law. You may unsubscribe from marketing emails at any time using the link in any such email or the setting in your account. You can request deletion of your account from your account settings, and you can request a copy of your learning record — your enrolments, results and certificates — either by downloading your CPD transcript from your dashboard or by asking us for a copy.

Why we are allowed to hold this data. We process account and course records because they are necessary to provide the training you asked for and to issue and verify your certificate (performance of a contract). We respond to enquiries, keep the platform secure, detect duplicate or fraudulent registrations and improve our courses on the basis of our legitimate interests in running the service. We send marketing email only with your consent. We keep payment records to meet legal and tax obligations, and certificate and consent records on the basis of our legitimate interest in keeping issued certificates verifiable and in evidencing consent. Where we rely on consent, you may withdraw it at any time; this does not affect processing carried out before withdrawal or training you have already received.

If you believe we have handled your personal information improperly, please contact us first so we can put it right. You also have the right to lodge a complaint with a data-protection supervisory authority: in the EU, the authority of the member state where you live or work; elsewhere, the authority in your country of residence.

Children. The platform is intended for maritime professionals and learners in professional education and is not directed at children. We do not knowingly collect personal information from anyone under 16.

Who controls your information

ICORA MED LTD (company no. 17436212), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, is the controller of personal information collected through this website and training platform.

Contact

Questions about this policy, and requests to exercise your rights, can be sent through the contact form, by email to [email protected], or by post to ICORA MED LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).