Legal

Privacy Policy

Last updated: 1 May 2026  ·  Effective: 1 May 2026
Loxbrook Associates Limited · Company No. 04924146

The short version: we collect only what we need, store it securely, never sell it, and give you full control over it. This document explains everything in detail as required by UK law.

Contents
  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing
  5. Cookies and tracking
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. Your rights
  10. Children
  11. Security
  12. Changes to this policy
  13. How to contact us

01 Who we are

Jiffy Compliance is a workforce compliance platform run by Loxbrook Associates Limited. We also trade as Marble Training.

DetailInformation
Registered company nameLoxbrook Associates Limited
Company number04924146
Registered office182 Worcester Road, Bromsgrove, B61 7AZ
Trading asJiffy Compliance · Marble Training
ICO Registration Number[To be inserted]
Contact email[email protected]

For UK GDPR and Data Protection Act 2018 purposes, Loxbrook Associates Limited is the data controller for personal data collected through the Jiffy Compliance website, marketing activities, and standalone eLearning purchases.

For personal data that business customers upload about their workers, we act as a data processor — following your instructions under our Data Processing Agreement.

02 What data we collect

2.1 Data you give us directly

2.2 Data collected automatically

2.3 Data we don't collect

We don't knowingly collect special category data (health, biometric, religious, political or genetic data) through our website or contact forms. If your workforce records or accident reports contain occupational health information, that's processed strictly as your data processor under the Data Processing Agreement — you're responsible for ensuring you have a lawful basis for processing it.

03 How we use your data

PurposeData used
Responding to contact form enquiries and gap analysis bookingsName, email, company, role, message
Creating and managing your platform accountName, email, company, role, password (hashed)
Processing standalone eLearning purchases and giving you course accessName, email, payment data (Stripe), course progress and completion
Managing business eLearning accounts and tracking team completionsAccount holder details, team member names and emails, completion records
Issuing and storing course certificatesName, completion data, course details
Delivering the Jiffy Compliance platform and its featuresAccount data, workforce data you upload
Sending you transactional emails — account alerts, expiry notifications, order confirmationsName, email
Improving the platform through analyticsUsage data, technical data (anonymised where possible)
Complying with legal obligationsAny data required by law
Protecting against fraud and misuseTechnical data, payment data, usage data

We don't use your data for automated decision-making that has a legal or similarly significant effect on you without a human reviewing it first. We don't sell, rent or trade your personal data to third parties for marketing purposes.

04 Legal basis for processing

Under UK GDPR, we rely on the following legal bases depending on what we're using your data for:

Processing activityLegal basis
Responding to contact enquiriesLegitimate interests (Article 6(1)(f)) — responding to business communications
Platform account creation and deliveryPerformance of a contract (Article 6(1)(b))
Standalone eLearning purchase and course deliveryPerformance of a contract (Article 6(1)(b))
Issuing certificates and managing learner accountsPerformance of a contract (Article 6(1)(b))
Transactional communicationsPerformance of a contract (Article 6(1)(b))
Analytics and platform improvementLegitimate interests (Article 6(1)(f)) — only where analytics cookies are accepted
Legal complianceLegal obligation (Article 6(1)(c))
Fraud prevention and securityLegitimate interests (Article 6(1)(f))

Where we rely on legitimate interests, we've assessed that those interests don't override your rights and freedoms. You can object to processing on legitimate interests grounds at any time — see Section 9.

05 Cookies and tracking

5.1 Strictly necessary cookies

These are essential for the website and platform to work — session management, security tokens and load balancing. They don't require your consent under PECR or UK GDPR.

5.2 Analytics cookies (opt-in)

With your consent, we use Google Analytics (Google LLC) to understand how visitors use our website. Google Analytics collects information about your use of the site in anonymised form. IP addresses are anonymised. You can opt in or withdraw consent at any time using our cookie preference tool.

Google LLC is a US company. Where data is transferred outside the UK, we have appropriate safeguards in place (UK-US Data Bridge / Standard Contractual Clauses). See Google's privacy policy.

5.3 Google Fonts

Our website loads fonts from Google Fonts. Google may collect your IP address when serving these fonts. This is a technical necessity for rendering the site. See the Google Fonts privacy FAQ.

5.4 Managing your preferences

You can manage cookie preferences at any time using the cookie banner or by contacting us. You can also control cookies through your browser settings.

06 Who we share data with

We don't sell your data. We only share it where it's necessary to provide the service or where the law requires it.

RecipientWhyLocation
Lovable Technologies Inc. Platform infrastructure, hosting, database and application services. They act as our data processor under a signed Data Processing Agreement. EU region (EU data hosting selected)
Stripe, Inc. Payment processing for standalone eLearning purchases, LMS subscriptions and other paid add-ons. Stripe processes your payment card details directly — we don't store your card information. Stripe's privacy policy is at stripe.com/gb/privacy. USA (UK-US Data Bridge / SCCs)
Google LLC (Google Analytics) Website analytics — only where you've consented to analytics cookies. USA (UK-US Data Bridge / SCCs)
Legal and regulatory authorities Where required by law, court order or regulatory request. UK

Lovable's sub-processors include Supabase (database hosting) and others listed at trust.lovable.dev. All are bound by contractual data protection obligations.

We never share your personal data or your workers' data with partner companies (see Terms of Service, Section 8) without your explicit consent.

07 International transfers

We've selected EU-region data hosting through Lovable. Your platform data is stored within the EU/EEA by default.

Some transfers outside the UK do happen — for example to Google for analytics and to Stripe for payment processing. In each case we make sure the right safeguards are in place:

You can request a copy of the transfer mechanisms we rely on by emailing [email protected].

08 How long we keep data

Data typeHow long we keep it
Contact form submissions and gap analysis enquiries12 months from submission, then securely deleted
Platform account data (profiles, settings, workforce records)For as long as your account is active, then deleted within 3 months of account closure
Standalone eLearning learner accounts and course completion records12 months from purchase date (matching course access period), then deleted — unless you upgrade to a full account
Business eLearning account data and team completion recordsFor as long as the account is active, then deleted within 3 months of closure
Payment transaction records7 years (HMRC requirement)
Analytics data (Google Analytics)26 months (Google's default — you can opt out at any time)
Legal and compliance recordsAs required by law — typically 6 years for contractual records under the Limitation Act 1980

When retention periods end, data is securely deleted or anonymised. You can ask us to delete your data earlier — see Section 9.

eLearning certificates: we recommend downloading your certificate as soon as you complete a course. If your learner account expires and you haven't saved your certificate, you may lose access to it.

09 Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights over your personal data:

To exercise any of these rights, email us at [email protected]. We'll respond within one calendar month. We may ask you to verify your identity first.

Right to complain: if you're unhappy with how we've handled your data, you can complain to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We'd appreciate the chance to put things right first — please email us before contacting the ICO.

10 Children

Jiffy Compliance is a business platform for organisations and their adult employees and contractors. We don't knowingly collect personal data from anyone under 18. If you think we've collected data from a minor by mistake, please contact us at [email protected] and we'll delete it promptly.

11 Security

We take the security of your data seriously. The measures we have in place include:

If a personal data breach is likely to affect your rights and freedoms, we'll notify the ICO within 72 hours and contact affected individuals without undue delay.

No system is completely secure. If you have concerns about the security of your account, please contact us straight away at [email protected].

12 Changes to this policy

We may update this Privacy Policy from time to time — to reflect changes in how we operate, the technology we use, or what the law requires. When we make material changes, we'll update the date at the top and, where appropriate, let registered users know by email. It's worth checking this page periodically.

13 How to contact us

For any questions about this Privacy Policy or how we handle your data:

Loxbrook Associates Limited (trading as Jiffy Compliance and Marble Training)
182 Worcester Road, Bromsgrove, B61 7AZ
Email: [email protected]
Website: jiffyaiportal.com