At Expedition Psychology, we are committed to protecting your privacy and personal data. This Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect your personal data when you visit our website, expedition-psychology.com, and use our services, including our online courses. We comply with global privacy laws, including but not limited to:
- General Data Protection Regulation (GDPR) — UK, EU and EEA
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) — California, US
- Lei Geral de Proteção de Dados (LGPD) — Brazil
- Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada
- Act on the Protection of Personal Information (APPI) — Japan
- Australian Privacy Principles (APPs) under the Privacy Act 1988 — Australia
By using our website, you agree to the collection and use of personal data in accordance with this Policy.
In this policy
1Introduction and Scope
This Policy applies to all personal data processed by Expedition Psychology in connection with our services, online courses, and website visitors. We encourage you to read this Policy carefully to understand our practices regarding your data and how we will treat it.
We have not appointed a dedicated Data Protection Officer. For any privacy matter, please contact us using the details above.
2Information We Collect
We collect various types of information for different purposes, to provide and improve our services to you. We only collect data that is necessary for the stated purposes.
2.1 Personal Data
This includes information that can be used to identify you directly or indirectly. The categories of personal data we may collect include:
- Identifiers: name, email address, postal address, IP address, and online identifiers.
- Account Information: username, password, preferences, course enrolment and progress records, feedback.
- Course & Activity Data: climbing- and expedition-related information you provide, course reflections, self-assessment responses, and completion records submitted as part of an online course.
- Financial Information: payment details (processed securely by third-party payment processors; we do not store full payment card numbers) and billing address.
- Communications: information you provide when contacting us, such as support enquiries and survey responses.
- Professional Information: job title and organisation name, where you interact with us in a professional or business capacity.
2.2 Usage Data
When you access our website, we may automatically collect certain information, including:
- Device Information: IP address, browser type and version, operating system, and unique device identifiers.
- Usage Patterns: pages visited, time spent on pages, referral source, navigation paths, and clickstream data.
- Location Data: general location derived from your IP address.
- Cookies and Tracking Technologies: information collected through cookies, web beacons, and similar technologies (as detailed in section 2.4).
2.3 Sensitive Personal Information
Because our courses support reflection on performance, resilience, and wellbeing, we may collect, use, store, and otherwise process certain data considered sensitive, special-category, or protected under global data protection laws. Specifically, this may include:
- Wellbeing self-reports and course reflections: information relating to your mental wellbeing, mindset, or psychological responses that you choose to share in reflective exercises, journals, or self-assessments completed as part of a course.
We only process this type of data when:
- You have given your explicit consent, where required;
- It is necessary to provide a service you have requested;
- It is required or authorised by law;
- It is necessary for the establishment, exercise, or defence of legal claims.
- Encryption and secure storage;
- Access restrictions and role-based controls;
- Staff training and confidentiality obligations;
- Data minimisation and retention limits.
We will never use sensitive personal data for marketing or profiling without your explicit consent where required. Your rights regarding this data — including access, correction, deletion, objection, and withdrawal of consent — may vary by jurisdiction. Please refer to section 7 (“Your Data Protection Rights”) or contact us at contact@expedition-psychology.com for further details.
2.4 Tracking Technologies
We and our third-party partners may use a variety of tracking technologies to collect information about your interactions with our website and services. These include:
- Cookies: small text files stored on your device that help us remember your preferences, enable functionality, and analyse site usage — set by both our website (first-party) and our partners (third-party).
- Tracking Scripts / Analytics Tools: software (such as analytics providers) that collects information about how you interact with our website.
- Web Beacons / Pixels: tiny graphics or scripts embedded in web pages or emails that track whether you have accessed certain content or opened an email.
- Local & Session Storage: technologies that store information on your device for faster access; session storage is cleared when you close your browser.
- Log Files: automatically recorded information about your device and usage on each visit.
Non-essential tracking technologies (such as analytics and marketing pixels) are loaded only after you give consent via our cookie banner, and we honour Global Privacy Control (GPC) signals as an opt-out. You can change your choice at any time using the Cookie Preferences link, or opt out of the sale or sharing of your personal information using the Do Not Sell or Share My Personal Information link, in the footer of any page. You may also adjust your browser or device settings to limit or disable some tracking technologies, though certain features may not function properly without them.
3How We Use Your Information
We use the collected data for various purposes, each based on a specific legal basis:
- To provide and maintain our service: including processing your transactions, managing your account, and delivering the courses and services you request.
- To improve and personalise our service: to understand how you use our services, develop new features, and tailor content to your preferences.
- To send marketing and promotional communications: where you have opted in, about services and offers that may be of interest to you.
- For customer support: to respond to your enquiries, provide technical support, and resolve issues.
- For analytics and research: to monitor and analyse trends, usage, and activities in connection with our services.
- For security and fraud prevention: to detect, prevent, and address technical issues, fraud, or illegal activity.
- To comply with legal obligations: to meet our regulatory and legal requirements, such as tax and accounting obligations.
4How We Share Your Information
We may share your personal data with third parties in certain circumstances, always ensuring appropriate safeguards are in place. We do not sell your personal data.
- Service Providers: we engage third-party companies to facilitate our services or assist us in analysing how our service is used (e.g. hosting providers, payment processors, analytics providers, email service providers). These parties access your personal data only to perform tasks on our behalf and are obliged not to disclose or use it for any other purpose.
- Business Transfers: if Expedition Psychology is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
- Legal Requirements: we may disclose your personal data in good faith where necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability.
- With Your Consent: we may disclose your personal data for any other purpose with your explicit consent.
- Aggregated or De-identified Data: we may share aggregated or de-identified information that cannot reasonably be used to identify you.
5International Data Transfers
Your information, including personal data, may be transferred to — and maintained on — servers located outside your state, province, or country, where data protection laws may differ from those of your jurisdiction.
For transfers of personal data from the UK, European Economic Area (EEA), or Switzerland to countries not deemed to provide an adequate level of protection, we implement appropriate safeguards, such as:
- Standard Contractual Clauses (SCCs): obliging recipients to protect personal data to GDPR standards.
- Binding Corporate Rules (BCRs): for intra-group transfers, where applicable.
- Data Transfer Agreements: ensuring equivalent protection as required by local laws (e.g. LGPD).
Where required, we conduct Transfer Impact Assessments to evaluate the level of protection in the recipient country and implement supplementary measures if necessary. Where consent is the legal basis for a transfer, you have the right to withdraw that consent at any time.
6Data Security and Retention
6.1 Data Security
We employ industry-standard technical and organisational security measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption: using SSL/TLS encryption for data in transit (HTTPS).
- Access Controls: restricting access to personal data to authorised personnel only.
- Data Minimisation: collecting only necessary data.
- Regular Security Reviews: conducting periodic reviews of our security practices.
- Employee Training: educating our staff on data protection and security.
- Pseudonymisation / Anonymisation: where feasible and appropriate.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee its absolute security.
6.2 Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law (e.g. for legal, tax, or accounting purposes). When we no longer need your personal data, we securely delete or anonymise it in accordance with applicable law.
7Your Data Protection Rights
Depending on your location and applicable privacy laws, you have various rights regarding your personal data, and we are committed to facilitating the exercise of these rights.
7.1 General Rights (e.g. GDPR, CCPA, LGPD, PIPEDA, APPI, APPs)
- Right to be informed: to know what personal data we collect, why, and how we use it — this Policy serves that right.
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request that we correct inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): to request deletion of your personal data in certain circumstances.
- Right to restrict processing: to request that we restrict processing under certain conditions.
- Right to data portability: to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller, where technically feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Rights regarding automated decision-making and profiling: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless an exception applies.
- Right to withdraw consent: where we rely on consent, to withdraw it at any time, without affecting the lawfulness of prior processing.
7.2 Specific Rights by Region
California Residents (CCPA/CPRA)
- Right to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties to whom we disclose it.
- Right to opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising.
- Right to limit the use and disclosure of sensitive personal information.
- Right to non-discrimination for exercising your rights, and the right to correct inaccurate personal information.
Brazilian Residents (LGPD)
- Rights similar to GDPR, including confirmation of processing, access, correction, anonymisation/blocking/deletion, portability, information about shared data, and revocation of consent.
Canadian Residents (PIPEDA)
- Rights to access, correction, and challenging compliance, with emphasis on accountability, consent, limiting collection and use, accuracy, safeguards, openness, and recourse.
Japanese Residents (APPI)
- Rights to disclosure, correction, cessation of use, and deletion of personal information, with requirements for appropriate security measures and supervision of service providers.
Australian Residents (APPs)
- Rights to access and correction, with specific principles on collection, use, disclosure, data quality, data security, and direct marketing.
EU / UK Residents
- If you believe your rights have been violated, you may lodge a complaint with your local data protection authority — for the UK, the ICO; for the EU, the EDPB.
7.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at contact@expedition-psychology.com. We will respond within the timeframes required by applicable law (e.g. 30 days under GDPR, 45 days under CCPA). We may need to verify your identity before fulfilling your request. You may exercise your rights free of charge, unless requests are manifestly unfounded or excessive.
8Children's Privacy
Our service is not intended for individuals under the age of 18. We do not knowingly collect personally identifiable information from children without verifiable parental consent. If you are a parent or guardian and are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from a child without verification of parental consent, we take steps to remove that information from our servers.
9Links to Other Websites
Our services may contain links to other websites that are not operated by us. If you click a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
10Changes to This Privacy Policy
We may update this Policy from time to time. We will notify you of any changes by posting the new Policy on this page and updating the “Last Updated” date at the top of this Policy. Where changes are material, we will also inform you via email and/or a prominent notice on our website before the change becomes effective, and update the “Effective Date”. You are advised to review this Policy periodically. Changes are effective when they are posted on this page.
11Complaints and Supervisory Authorities
If you have concerns about our privacy practices, please contact us directly using the details provided in section 1. You also have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction:
- UK Residents: Information Commissioner's Office (ICO).
- EU / EEA Residents: the data protection authority in your Member State (see the European Data Protection Board list).
- Canadian Residents: Office of the Privacy Commissioner of Canada (OPC).
- Brazilian Residents: Autoridade Nacional de Proteção de Dados (ANPD).
- Australian Residents: Office of the Australian Information Commissioner (OAIC).
- California Residents: California Attorney General or the California Privacy Protection Agency (CPPA).