Privacy Policy
Last updated: September 2026
1. Introduction and data controller
CPDreflect ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. CPDreflect is a trading name of Cox Financial Services Limited, a company registered in England and Wales. For the purposes of the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), Cox Financial Services Limited is the Data Controller.
2. International hosting
Our services are hosted on infrastructure provided by Railway, located in the United States. While our primary jurisdiction is the United Kingdom, your data will be processed and stored on servers in the US. We ensure appropriate safeguards are in place to protect your data during this transfer (see Section 5).
Founding-member launch lists
For names, email addresses and consent collected for the CPDreflect, CPD Wizard and SurveyorCPD launch lists, read the launch-list privacy notice. Each list has separate email preferences.
3. Information we collect
Personal information: Name and email address, collected for account management and login.
User content: Learning notes, reflections, and text inputs you provide for analysis.
Uploaded media: Documents or images containing CPD materials (PDF, DOCX, TXT).
Technical data: IP address, browser type and version, and operating system, collected automatically for security and service improvement.
4. Lawful basis for processing
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
Contract: Processing your account data and user content is necessary for the performance of the contract between you and us when you create an account and use CPDreflect.
Legitimate interests: We process technical data for security monitoring, fraud prevention, and service improvement. We have assessed that these interests do not override your rights and freedoms.
Consent: Where we send you marketing communications, we do so only with your explicit consent. You may withdraw consent at any time.
5. Data processing and third parties
To provide our service, we use third-party sub-processors:
Hosting (Railway): Your personal data, application usage, and content are stored on Railway's infrastructure in the United States. Railway implements industry-standard security measures.
AI processing (Anthropic): To generate personalised reflections, we transmit your text inputs and learning content to Anthropic's API (Claude). Anthropic does not use your data to train their models under their commercial terms. Data is processed transiently for the purpose of generation only.
Optional wording check (TypeSafe): If the operator turns the optional wording check on, and only after the integrity checks have already passed on our servers, the text of the reflection sections may be sent to TypeSafe at jevtypesafeai.com. The check asks two narrow questions: whether the text states what was learned, and whether it states an action or a change in the writer's own work. It does not write the reflection, and it does not run when a rules check has already failed. Recording CPD in your own words does not require it. Each question is appended to a decision ledger on your account: the question, a hash of the text that was scored, the probability, the threshold, the outcome, the model, the model version, and the time. The reflection text itself is not copied into that row. You can record a sign-off that overrides that outcome. The reason is required and is stored on the sign-off, not on the model row, and it is included when you export the ledger for a CPD year. The probabilities are not stored as the record's validation score, and they are not printed on an Evidence Pack.
Payments (Stripe): Payment processing is handled by Stripe. We do not store card details on our servers.
International data transfers to the United States are made in reliance on the UK-US Data Bridge and, where applicable, Standard Contractual Clauses (SCCs).
6. How we use your information
We use the information we collect to generate personalised CPD reflections via AI, maintain your account and reflection history, improve the performance and accuracy of the service, respond to support requests, and monitor for fraudulent or malicious activity. We do not use your CPD notes or reflections to train AI models.
7. Disclosure of your information
We do not sell, trade, or rent your personal data to any third party. We may share information with our sub-processors as described above. We may also disclose data where required by law or in response to valid requests by public authorities.
8. Data security
We use administrative, technical, and physical security measures to protect your personal data. Data is encrypted in transit using SSL/TLS. Passwords are hashed using bcrypt. While we take all reasonable steps to protect your data, no method of electronic transmission or storage is guaranteed to be 100% secure.
9. Data retention
Account data: Retained while your account is active and for up to 12 months after closure, unless you request earlier deletion.
User content: Reflections and notes are retained while your account is active. You may export or delete your reflections at any time.
AI inputs: Data sent to Anthropic is processed transiently and is not stored by Anthropic after generation is complete.
Wording-check inputs: When the optional check is on, the section text sent to TypeSafe is the text needed for that decision. The ledger row stores a hash of that text, not a second copy of it. An override reason, if you write one, is kept on the sign-off. Neither is saved as the record's validation score.
You may delete your account and all associated data at any time via Settings, or by contacting hello@cpdreflect.com.
10. Cookies
We use strictly necessary cookies to maintain your login session and remember your preferences. These cookies are essential for the service to function and do not require consent under UK law. We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
11. Your rights
Under the UK GDPR, you have the right to:
Access your personal data and request copies.
Rectification of inaccurate or incomplete data.
Erasure of your personal data (the right to be forgotten).
Restriction of processing in certain circumstances.
Data portability to receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact hello@cpdreflect.com. We will respond within one calendar month.
12. Children
CPDreflect is designed for UK financial services professionals. We do not knowingly collect personal data from anyone under the age of 18.
13. Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email.
15. Contact
If you have questions about this Privacy Policy, contact us at: hello@cpdreflect.com