Privacy Policy
Last updated: February 2026
1. Introduction and data controller
CPDreflect ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. CPDreflect is a trading name of Cox Financial Services Limited, a company registered in England and Wales. For the purposes of the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), Cox Financial Services Limited is the Data Controller.
2. International hosting
Our services are hosted on infrastructure provided by Railway, located in the United States. While our primary jurisdiction is the United Kingdom, your data will be processed and stored on servers in the US. We ensure appropriate safeguards are in place to protect your data during this transfer (see Section 5).
Founding-member launch lists
For names, email addresses and consent collected for the CPDreflect, CPD Wizard and SurveyorCPD launch lists, read the launch-list privacy notice. Each list has separate email preferences.
3. Information we collect
Personal information: Name and email address, collected for account management and login.
User content: Learning notes, reflections, and text inputs you provide for analysis.
Uploaded media: Documents or images containing CPD materials (PDF, DOCX, TXT).
Technical data: IP address, browser type and version, and operating system, collected automatically for security and service improvement.
4. Lawful basis for processing
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
Contract: Processing your account data and user content is necessary for the performance of the contract between you and us when you create an account and use CPDreflect.
Legitimate interests: We process technical data for security monitoring, fraud prevention, and service improvement. We have assessed that these interests do not override your rights and freedoms.
Consent: Where we send you marketing communications, we do so only with your explicit consent. You may withdraw consent at any time.
5. Data processing and third parties
To provide our service, we use third-party sub-processors:
Hosting (Railway): Your personal data, application usage, and content are stored on Railway's infrastructure in the United States. Railway implements industry-standard security measures.
AI processing (Anthropic): To generate personalised reflections, we transmit your text inputs and learning content to Anthropic's API (Claude). Anthropic does not use your data to train their models under their commercial terms. Data is processed transiently for the purpose of generation only.
Payments (Stripe): Payment processing is handled by Stripe. We do not store card details on our servers.
International data transfers to the United States are made in reliance on the UK-US Data Bridge and, where applicable, Standard Contractual Clauses (SCCs).
6. How we use your information
We use the information we collect to generate personalised CPD reflections via AI, maintain your account and reflection history, improve the performance and accuracy of the service, respond to support requests, and monitor for fraudulent or malicious activity. We do not use your CPD notes or reflections to train AI models.
7. Disclosure of your information
We do not sell, trade, or rent your personal data to any third party. We may share information with our sub-processors as described above. We may also disclose data where required by law or in response to valid requests by public authorities.
8. Data security
We use administrative, technical, and physical security measures to protect your personal data. Data is encrypted in transit using SSL/TLS. Passwords are hashed using bcrypt. While we take all reasonable steps to protect your data, no method of electronic transmission or storage is guaranteed to be 100% secure.
9. Data retention
Account data: Retained while your account is active and for up to 12 months after closure, unless you request earlier deletion.
User content: Reflections and notes are retained while your account is active. You may export or delete your reflections at any time.
AI inputs: Data sent to Anthropic is processed transiently and is not stored by Anthropic after generation is complete.
You may delete your account and all associated data at any time via Settings, or by contacting hello@cpdreflect.com.
10. Cookies
We use strictly necessary cookies to maintain your login session and remember your preferences. These cookies are essential for the service to function and do not require consent under UK law. We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
11. Your rights
Under the UK GDPR, you have the right to:
Access your personal data and request copies.
Rectification of inaccurate or incomplete data.
Erasure of your personal data (the right to be forgotten).
Restriction of processing in certain circumstances.
Data portability to receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact hello@cpdreflect.com. We will respond within one calendar month.
12. Children
CPDreflect is designed for UK financial services professionals. We do not knowingly collect personal data from anyone under the age of 18.
13. Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email.
15. Contact
If you have questions about this Privacy Policy, contact us at: hello@cpdreflect.com