Privacy policy
Version 2.1. Effective 6 August 2026. Replaces the previous privacy policy and the separate GDPR policy, both withdrawn.
1. Who we are
Auren Institute is the data controller for the personal data described in this notice. We are established in Malta at 92, No. 1, St Edward Street, Qormi QRM 2136, Malta. Our registration number is P1421 and our VAT number is MT20967027.
We also trade as Apollo Accreditation, through which we provide accreditation, curriculum development and quality assurance services. Auren Institute is the controller for that activity too. Apollo Accreditation publishes its own privacy notice covering its outreach, and it should be read alongside this one.
You can reach us about anything in this notice at info@aureninstitute.com.
2. What this notice covers
This notice explains what personal data we collect, why we collect it, what allows us to do so in law, who we share it with, how long we keep it, and what rights you have. It applies to learners and customers, to visitors to our websites, and to business contacts we approach about our services.
This notice replaces our previous privacy policy and our separate GDPR policy, which are both withdrawn. Where they said anything different, this notice governs.
3. The personal data we collect
We hold different data depending on our relationship with you.
If you are a learner or a customer, we hold identification and contact details, your employer and job role, your course enrolments, progress, assessment results and certificates, your payment and billing details, and technical data such as IP address and device information when you use our platform.
If you visit our websites, we hold technical and usage data, and any information you choose to submit through a form, a diagnostic or an enquiry.
If you are a business contact we have approached, we hold your name, your business email address, your job title, your employer and its website, publicly stated information about your organisation such as its accreditation status, and a single fact drawn from public material that we use to make our message relevant to you. We do not hold anything else about you, and we do not hold your personal contact details.
We do not seek or knowingly hold special category data as defined in Article 9, and we do not knowingly hold data about anyone under 18.
4. Where we get your data
Most often, directly from you: when you register, enrol, buy, complete a diagnostic, subscribe or contact us.
Sometimes from your employer, where your employer buys training and enrols you on it.
For business contacts, from sources other than you. We use published professional directories and public registers, for example accreditation directories that list providers and their contact details, and registers of licensed education providers. We also use commercial business contact-data providers to confirm a name, a job title or a business email address. We collect this only about people in professional decision-making roles at organisations, and only business contact details.
Where we obtain your data from a source other than you, we tell you so in our first message to you, and we tell you which kind of source it came from. That is the purpose of this section and of that message.
5. Why we process your data, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Delivering courses, assessments, certification and support you or your employer have bought | Article 6(1)(b), performance of a contract |
| Running and securing our learning platform and websites | Article 6(1)(f), legitimate interests, being the interest in operating a functioning and secure service |
| Issuing and verifying certificates and maintaining learner records | Article 6(1)(b), and Article 6(1)(c) where a legal or accreditation-body obligation applies |
| Meeting accounting, tax, regulatory and accreditation obligations | Article 6(1)(c), compliance with a legal obligation |
| Sending you our newsletter and marketing about our courses where you have signed up | Article 6(1)(a), consent, which you may withdraw at any time |
| Sending relevant business-to-business communications to professional contacts about our services | Article 6(1)(f), legitimate interests. Section 6 explains this in full because it is the basis most people want to understand |
| Improving our courses and services, including analysing how they are used | Article 6(1)(f), legitimate interests, being the interest in improving what we offer |
| Establishing, exercising or defending legal claims | Article 6(1)(f), legitimate interests, and Article 6(1)(c) where applicable |
6. Business-to-business outreach, explained
If you have received a message from us that you did not ask for, this section is the one that matters, and we would rather explain it plainly than bury it.
We contact people in professional roles at organisations to tell them about services we think are relevant to what their organisation does. We rely on legitimate interests under Article 6(1)(f) to do this. Our interest is in reaching the small number of organisations for whom our services are genuinely relevant. We have carried out a formal assessment weighing that interest against your rights, we have recorded the outcome in writing, and you may ask us for it.
We limit this activity deliberately. We contact people at incorporated organisations, not sole traders. We use business contact details only. We stop immediately if you tell us to, in whatever words you use. We do not use tracking pixels in these messages. We identify ourselves in every message and tell you where we obtained your details.
How we might reach you, and how often.
We use business contact details only. That means a work email address, a work telephone number, or a message through a professional network such as LinkedIn. We do not use personal email addresses, personal phone numbers or home addresses.
We only get in touch when we have something relevant to say to you in the role you actually hold. That is the limit we work to, and it is a real one: if there is nothing relevant, there is no reason for us to write. We decide before each campaign how many messages it will involve and how far apart they will be, and we write that down.
We stop the moment you tell us to, and you never have to tell us twice. If we have not heard from you and we get in touch again later, we check first that you still hold the role and that your details are still current.
If we call you in the United Kingdom, we check your number against the Telephone Preference Service and the Corporate Telephone Preference Service first, and we do not call if it is registered.
You can stop all of it at any time. Reply to any message, tell us on the phone, or write to us at the address in section 1. Whichever route you use, it stops every route.
You have an absolute right to object to this under Article 21(2). You do not need to give a reason, we will not ask for one, and we will not weigh anything against it. Reply to any message, or write to us at the address in section 1, and we will stop and keep a record of your address for the sole purpose of making sure we do not contact you again.
7. Marketing and your choices
We treat marketing to individuals who have signed up, and business-to-business communications to professional contacts, as different things with different bases, and we have said which is which in section 5.
Whichever applies to you, you can stop it at any time. Every marketing message carries a one-click unsubscribe. You can also write to us. We act on it straight away rather than at the end of a campaign.
8. Who we share your data with
We share personal data with service providers who process it on our behalf and under contract. These fall into the following categories: our learning platform provider, our customer relationship management provider, our email sending and marketing providers, our business contact-data providers, our payment processors, our cloud hosting and infrastructure providers, and our professional advisers.
Each is bound by a written contract that requires them to process the data only on our instructions and to protect it.
We also share data with accreditation and certification bodies where that is necessary to award, verify or maintain a qualification or a CPD record, and with authorities where the law requires it.
We do not sell personal data, and we do not share it with third parties for their own marketing.
9. Sending data outside the European Economic Area
Some of our providers are established outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA we rely on one of the following: an adequacy decision of the European Commission, the European Commission Standard Contractual Clauses, or, for transfers from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner, together with any additional measures the transfer requires.
You can ask us which safeguard applies to a particular transfer.
10. How long we keep your data
| What | How long we keep it |
|---|---|
| Learner and course records, including assessment results and certificates | For the duration of the relationship and then for 7 years, so that certificates can be verified and accreditation and audit obligations met |
| Financial and transaction records | For the period required by Maltese tax and accounting law |
| Marketing subscribers | Until you unsubscribe, and then only a record that you unsubscribed |
| Business contacts we have approached who did not respond | 24 months from the date we last verified the details, and then deleted |
| Anyone who has objected or unsubscribed | We keep the email address alone, indefinitely. We keep it precisely because it is what stops us contacting you again, and we would be unable to honour your objection without it |
| Website and platform technical logs | As set out in our cookie policy, and no longer than necessary for security and diagnostics |
11. Your rights
You have the following rights over your personal data. Exercising any of them is free of charge. We respond within one month, and we will tell you if we need longer because a request is complex.
The right to be told what we hold and to receive a copy of it. The right to have inaccurate data corrected. The right to have data erased in certain circumstances. The right to have processing restricted while a matter is resolved. The right to receive data you gave us in a portable format. The right to object to processing based on legitimate interests. The right to object to direct marketing, which is absolute and which we always honour. The right to withdraw consent at any time where we relied on consent, without affecting anything done before you withdrew it.
To exercise any of these, write to info@aureninstitute.com. We may ask you to confirm who you are, so that we do not disclose your data to somebody else.
12. Complaints
If you are unhappy with how we have handled your data, please tell us first and we will try to put it right.
You also have the right to complain to a supervisory authority. We are established in Malta, so our lead authority is the Information and Data Protection Commissioner, at idpc.org.mt. If you are in the United Kingdom, you may instead complain to the Information Commissioner's Office, at ico.org.uk. Complaining to us first is not a condition of complaining to them.
13. How we protect your data
We use encryption in transit and at rest, role-based access controls so that staff see only what they need, secure cloud infrastructure, monitoring, backup procedures, and training for anyone handling personal data. We review these measures periodically.
14. Changes to this notice
We keep this notice under review and update it when what we do changes. The version and date are shown at the top, and material changes are recorded in the change log at the foot. Where a change is material we will tell people it affects rather than relying on them noticing.
v2.1 (6 August 2026): Added telephone and professional network messaging to the outreach section. Described how the frequency of outreach is limited and recorded. Removed the statement that outreach is a short sequence that then stops, which no longer reflects our assessment.
v2 (31 July 2026): Consolidates the previous privacy policy and GDPR policy into one notice. Updated to Regulation (EU) 2016/679 and the Data Protection Act Cap. 586, replacing outdated references to the Data Protection Act 1998. Lawful bases stated in full, including legitimate interests for business-to-business outreach. Subject access is free of charge. Retention periods stated. Supervisory authorities named. Apollo Accreditation identified as a trading name.
Compliance, Done Right.
Auren Institute is a compliance management training partner for SMEs and mid-market employers in the UK and the EU. Eleven compliance domains. Three levels in each. UK and EU variants where the law differs. Updated within 30 days of legislative change.
Main Pages
-
Contact Us
-
Training Diagnostics
-
Corporate Training Courses
-
Corporate Training Services
-
Corporate Training Advisory
-
Auren Live Courses
-
Auren eLearning Certificates
-
AGRC eLearning Certificates
-
AGRC eLearning Diplomas
-
Onboarding Training
-
Top Leadership Training
-
Training That Sticks
-
Compliance Beyond Ticking The Box
-
Procurement That Performs
-
The Compliance Management Journal
-
YouTube Channel
-
News
-
Our Partners & Affiliates
-
About Us