Privacy policy

Version V0.1, 24 August 2026

1. Who we are and how to contact us

1.1   This policy explains how Blue Skies Drone Training Ltd looks after personal information. Where this policy says "we", "us" or "our", it means Blue Skies Drone Training Ltd. Where it says "you", it means anyone whose personal information we hold, including website visitors, customers, course candidates, community members and people who contact us with an enquiry.

1.2   We are the controller of the personal information described in this policy. That means we decide why and how it is used, and we are responsible for it under UK data protection law.

Legal entity Blue Skies Drone Training Ltd, a company registered in England and Wales
Company number 17035449
Registered office Suite A, 82 James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE
Trading name Blue Skies Drone Training, or BSDT
Website www.blueskiesdronetraining.com
General contact hello@blueskiesdronetraining.com
Privacy contact hello@blueskiesdronetraining.com
ICO registration number Pending Issuance from ICO
Postal address for privacy requests Blue Skies Drone Training Ltd, Suite A, 82 James Carter Road, Mildenhall, IP28 7DE.

1.3   We are not required by law to appoint a Data Protection Officer and we have not appointed one. Day to day responsibility for data protection sits with Matthew Williams, CEO.

2. What this policy covers

2.1   This policy covers personal information we collect when you:

(a)  visit or browse our website;

(b)  make an enquiry, join a waiting list, or subscribe to our emails;

(c)  buy a course, an examination, a piece of equipment, or a consulting or advisory service from us;

(d)  take part in training, an examination or a practical flight assessment;

(e)  use the BSDT Hub, including the learning platform and the community;

(f)  apply for, or are considered for, access arrangements or reasonable adjustments; or

(g)  contact us with a question, a complaint or an appeal.

2.2   Separate privacy information applies to people who work with us as staff, examiners, practical flight assessors or contractors. If that applies to you, we will give you that information directly.

2.3   Our website contains links to other websites. This policy does not apply to those, and we are not responsible for how they handle your information.

3. The information we collect

3.1   The table below sets out the categories of personal information we collect, with examples. Not all of it applies to everyone. What we hold about you depends on what you buy from us and how you use our services.

Category What this includes Where it comes from
Identity and contact Name, email address, telephone number, billing and delivery address, and any name you use in the community. You
Account Your BSDT Hub login details, account settings and preferences, and a record of your enrolments. You, and our systems
Regulatory identifiers Your CAA Flyer ID and Operator ID numbers, and images of those IDs where we are required to verify them. You
Eligibility evidence Images of existing A2 CofC or GVC certificates and, for GVC refresher candidates seeking a practical assessment exemption, an extract from your flying logbook. You
Identity verification A photograph of a government issued photographic identity document, and an image of you taken at the time of an examination, used to confirm that the person sitting the examination is the person named on the certificate. You, and our invigilation providers
Payment The fact and amount of a payment, the payment method type, the last four digits of a card, and billing details. We do not receive or store full card numbers. Our payment providers
Learning records Course progress, lesson and module completion, quiz attempts and scores, time spent, and any declarations or confirmations you submit during a course. Our systems
Examination records Examination attempts including unsuccessful attempts, scores, the date and method of assessment, and the outcome. Our systems
Invigilation records Where an examination is invigilated remotely: video and audio recording of you and your surroundings, screen capture, a scan of the room, and any automated or human flags raised during the session. Our invigilation providers
Practical assessment records Assessment sheets, outcomes, assessor notes, the site used and the aircraft flown. Our practical flight assessors
Certification records Certificate numbers, dates of issue, and records of correction, reissue or withdrawal. Our systems
Access arrangements Information about a disability, health condition or additional need, any supporting evidence you choose to send us, and the adjustment we agreed. This is special category data. See section 4. You
Community content Posts, comments, replies, reactions, direct messages sent through the platform, and any reports made about content. You and other members
Orders and deliveries What you bought, order and invoice numbers, delivery and tracking information, returns and any warranty claim. You, our systems, our carriers
Correspondence Emails, contact form submissions, support tickets, chat messages, and notes of telephone calls. You
Complaints, appeals and integrity records Records of complaints, appeals against an assessment decision, and any investigation into suspected malpractice. You, our staff, our providers
Marketing preferences Whether you have subscribed or unsubscribed, and which emails you have opened or clicked. You, and our systems
Technical and usage IP address, approximate location derived from it, device and browser type, operating system, referring page, pages viewed, and time on site. Your device, via cookies and similar technologies

3.2   We do not deliberately collect information about criminal offences or convictions. If you send us information of that kind, for example in a fitness of character declaration or in support of a complaint, we will only keep it where we have a lawful reason to do so.

4. Special category information

4.1   Some information is treated as more sensitive under data protection law and needs extra protection. We handle two kinds.

Health and disability information

4.2   If you ask for an access arrangement or a reasonable adjustment, we will collect information about your disability, health condition or additional need, and any supporting evidence you send us. We ask what would help you rather than what your diagnosis is, and we keep the evidence requirement as light as we reasonably can.

4.3   We use this information only to decide on and deliver the adjustment, to record that we have met our obligations under the Equality Act 2010 and under the CAA requirements that apply to our examinations, and to defend a complaint if one is made.

4.4   Our lawful basis for using it is your explicit consent under Article 9(2)(a) of the UK GDPR, and we also rely on the condition in paragraph 8 of Schedule 1 to the Data Protection Act 2018, which permits processing for the purposes of equality of opportunity or treatment. You can withdraw your consent at any time, although we may not be able to continue providing an adjustment if you do.

4.5   Where we can, we record the decision and the arrangement agreed rather than keeping the underlying medical evidence indefinitely.

5. Why we use your information, and our lawful basis

5.1   Data protection law requires us to have a lawful basis for everything we do with your personal information. The table below sets out what we use it for and which basis applies.

What we use it for Information used Lawful basis
Setting up your account and giving you access to a course you have bought Identity, contact, account Performance of a contract
Verifying that you meet the entry conditions for a course or pathway Regulatory identifiers, eligibility evidence Performance of a contract, and legal obligation where the CAA scheme requires the check
Delivering training and tracking your progress Account, learning records Performance of a contract
Confirming your identity before and during an examination Identity verification, invigilation records Performance of a contract, and our legitimate interest in protecting the integrity of a regulated qualification
Invigilating examinations and investigating suspected malpractice Invigilation records, examination records, integrity records Legitimate interests: protecting examination integrity, protecting other candidates and the value of the certificate, and meeting the standards expected of an approved training organisation
Arranging and recording practical flight assessments Identity, contact, practical assessment records Performance of a contract
Issuing, correcting and if necessary withdrawing certificates Certification records Performance of a contract, and legal obligation
Keeping the training, examination and certification records that our CAA approval requires Most categories Legal obligation, and our legitimate interest in being able to evidence our own compliance
Making our examinations and training accessible Access arrangements Explicit consent, plus the equality of opportunity condition. See section 4
Taking payment, invoicing and preventing fraud Payment, identity, contact, orders Performance of a contract, legal obligation for tax records, and our legitimate interest in preventing fraud
Selling, delivering and supporting equipment, and handling returns and warranty claims Orders, identity, contact Performance of a contract
Running the BSDT community and moderating it Account, community content Performance of a contract, and our legitimate interest in keeping the community safe and lawful
Answering enquiries and providing support Contact, correspondence Performance of a contract where you are a customer, otherwise our legitimate interest in responding to people who contact us
Handling complaints and appeals Complaints and appeals records Legal obligation, and our legitimate interest in resolving disputes
Sending marketing emails to existing customers about similar products Contact, marketing preferences Our legitimate interest in promoting our own similar services, together with the soft opt-in in regulation 22 of the Privacy and Electronic Communications Regulations
Sending marketing emails to people who are not yet customers Contact, marketing preferences Consent
Measuring how our website and emails perform, and improving them Technical and usage, marketing preferences Consent for non-essential cookies, otherwise our legitimate interest in understanding and improving our services
Protecting our website and systems from misuse Technical and usage Legitimate interests: security
Establishing, exercising or defending legal claims, and taking professional advice Any relevant category Legitimate interests, and legal obligation where a court or regulator requires it

5.2   Where we rely on legitimate interests, we have considered whether our interest is outweighed by the effect on you. You can ask us for a summary of that assessment using the contact details in section 1.

6. Who we share your information with

6.1   We do not sell your personal information, and we do not share it with third parties for their own marketing.

6.2   We share it with the following, and only as far as necessary.

Who Why Their role
The UK Civil Aviation Authority Regulatory oversight and audit of our approved training and examination activity, and certification matters Controller in their own right
The Air Accidents Investigation Branch Where they request information in connection with an investigation Controller in their own right
Practical flight assessors on our authorised register Conducting and recording practical flight assessments Processors
Our technology providers, including Shopify for the store and checkout, Google Workspace for email and document storage, and our hosting provider for the BSDT Hub on which we store your data Running the services described in this policy Processors
Payment providers, including Shopify Payments, Stripe, PayPal and Klarna Taking and reconciling payments, and preventing fraud Controllers in their own right for their own compliance purposes
Carriers and couriers Delivering equipment and handling returns Processors
Our accountants and our accounting software, Xero Bookkeeping, invoicing and statutory accounts Processors, and controller where professional obligations apply
Our insurers, solicitors and other professional advisers Taking advice, and handling claims Controllers in their own right
Law enforcement, regulators and courts Where we are required by law to disclose, or where disclosure is necessary to protect someone Controllers in their own right
A buyer or successor If we sell or reorganise the business, information will transfer with it, subject to the same protections Controller

6.3   Where a third party acts as our processor, we have a written contract requiring them to act only on our instructions and to keep your information secure.

7. Where your information is held

7.1   Some of our providers are based outside the United Kingdom, or store or access information outside it. Where that happens, we make sure the transfer is protected by one of the following:

(a)  the country has been assessed by the UK government as providing an adequate level of protection;

(b)  the transfer is covered by the UK International Data Transfer Agreement, or by the UK Addendum to the European Commission's standard contractual clauses, supported by a transfer risk assessment; or

(c)  another safeguard permitted by UK data protection law applies.

7.2   You can ask us for details of the safeguards that apply to a particular transfer using the contact details in section 1.

8. How long we keep your information

8.1   We keep personal information only for as long as we need it. Some of our retention periods are set by the requirements that apply to us as an approved training organisation, and by tax law.

What How long Why
Training, examination and certification records, including unsuccessful attempts and certificate issue records At least five years from the date of the record, or the date of certificate issue. Required by our approval and needed to support CAA oversight
Invigilation recordings and identity verification images At least five years from the date of the record, or the date of certificate issue. Examination integrity, appeals and investigation
Access arrangement decisions With the candidate record, at least five years Evidencing that we met our obligations
Supporting medical or diagnostic evidence Deleted once the decision is recorded, or kept no more than 12 months We keep the decision, not the diagnosis, wherever we can
Complaints, appeals and malpractice records At least five years from closure Oversight and defence of claims
Orders, invoices and financial records Six years from the end of the accounting period in which the transaction took place Tax and company law
Equipment warranty and returns records Six years from purchase Consumer law claim periods
Community content While your account is active, then confirm: deleted, or retained and anonymised so threads stay readable Running the community
Enquiries that do not become sales 24 months from the last contact Following up and understanding demand
Marketing preferences and unsubscribe records Indefinitely for the record of your unsubscribe So we do not contact you again by mistake
Website analytics 26 months Understanding how the site performs

8.2   When we no longer need information we delete it, or we remove anything that identifies you so that what is left can no longer be linked back to you.

9. How we keep it safe

9.1   We use technical and organisational measures appropriate to the risk, including role based access controls, multi factor authentication where our systems support it, encryption in transit, restricted access to examination and candidate records, backups, and staff briefing on handling personal data and examination material.

9.2   No system is completely secure. If a breach happens that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it where we are required to. If it is likely to result in a high risk to you, we will tell you as well.

10. Your rights

10.1   You have the following rights over your personal information. They are not absolute and some only apply in particular circumstances.

Right What it means
Access To be told whether we hold information about you, and to receive a copy of it.
Rectification To have inaccurate information corrected, and incomplete information completed.
Erasure To have information deleted in certain circumstances. This will rarely apply to training, examination and certification records, because we are required to keep them.
Restriction To ask us to stop using information while a dispute about it is resolved.
Portability To receive information you gave us in a machine readable format, or have it sent to another organisation, where we rely on consent or contract and the processing is automated.
Objection To object to processing based on our legitimate interests. You can object to direct marketing at any time and we will always stop.
Withdraw consent Where we rely on consent, to withdraw it at any time. This does not affect anything we did before you withdrew it.
Automated decisions To ask for human involvement in a decision made solely by automated means that has a legal or similarly significant effect on you. See section 11.

10.2   To exercise any of these rights, contact us using the details in section 1. We will normally respond within one month. If your request is complex, or if you have made several requests, we may extend that by up to two further months and we will tell you if we do. If we need more information from you in order to deal with the request, the time limit does not start until we have it.

10.3   You do not have to pay a fee. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and we will explain why.

11. Automated decisions

11.1   Our remote invigilation systems may use automated tools to flag events during an examination, such as movement, sound, a second face in the room, or a device being detected. A flag is not a decision. Any decision that affects your result, including a decision about suspected malpractice, is made by a person who reviews the evidence, and you will be told the outcome and how to appeal it.

11.2   We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you.

12. Cookies and similar technologies

12.1   Our website uses cookies and similar technologies. Some are strictly necessary to make the site work, for example to keep items in your basket or to log you in, and these do not require your consent.

12.2   For other cookies our approach is as follows. We ask for your consent before setting cookies used for advertising or for anything that tracks you across other websites. For cookies used only to measure how our website is used, or only to remember a display preference such as language or a colour setting, we rely on the exemptions introduced on 5 February 2026 and we give you a clear and simple way to opt out instead of asking for consent up front.

13. Marketing

13.1   If you buy from us, or ask us about buying from us, we may email you about our own similar courses, services and products. Every message includes an unsubscribe link, and you can also tell us at any time using the contact details in section 1.

13.2   If you are not a customer, we will only email you marketing if you have asked us to.

13.3   Unsubscribing from marketing does not stop us sending you messages we need to send about something you have bought, such as your enrolment confirmation, examination arrangements, certificate, order updates or an important change to a course.

14. Children

14.1   Our website and our services are not directed at children. You must be at least 18 to buy from us. Where a candidate under 18 is enrolled by a parent, guardian or employer, confirm the process and the consent that applies.

15. Complaints

15.1   If you are unhappy with how we have handled your personal information, please tell us first using the contact details in section 1. We will acknowledge your complaint within 30 days, keep you informed of progress, and tell you the outcome.

15.2   You also have the right to complain to the Information Commissioner's Office at any time. You can reach them at ico.org.uk, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to resolve things first.

16. Changes to this policy

16.1   We review this policy at least once a year and whenever our services change. The version and date at the top of this document show when it was last updated. If we make a significant change we will tell customers and community members directly.

16.2   Previous versions are available on request.