Last updated: 30 September 2026
1. Introduction
Welcome to MedievalCourses.com.
We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what personal data we collect, how we use it, how we protect it and what rights you have.
We process personal data in accordance with the UK? [REMOVE - EU GDPR applies; include UK GDPR only if applicable to your activities], the EU General Data Protection Regulation (GDPR), Spain's Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), and other applicable legislation.
This policy applies to visitors, registered students, customers and anyone who contacts us through MedievalCourses.com.
2. Who We Are
Website: https://medievalcourses.com
Data controller: Tim Ridgway
Trading name: MedievalCourses
Postal address:
Calle Sargento Galera 3
04887 Lúcar
Almería
Spain
Email: admin@medievalcourses.com
The data controller is responsible for deciding how and why personal information is processed.
3. Information We Collect
Depending on how you use our website, we may collect:
- Your name, email address and contact details.
- Your billing address and transaction information.
- Your account username and securely stored password credentials.
- Details of courses you have purchased or enrolled in.
- Your course progress, quiz results and completion records.
- Information you provide when contacting us.
- Comments and other content you voluntarily submit.
- Technical information, including your IP address, browser type, device information and relevant security logs.
- Cookie preferences and website usage information, where applicable.
We collect information directly from you when you register, purchase a course, complete a form or communicate with us. Some technical information is collected automatically when you use the website.
We may also receive transaction confirmations and related information from payment providers.
4. How We Use Your Information
We process personal information for the following purposes and on the following legal bases.
Providing courses and managing accounts
We use your information to create and maintain your account, process enrolments, provide access to purchased courses, record progress, administer assessments and issue completion certificates.
Legal basis: Performance of a contract or steps taken at your request before entering into a contract.
Processing purchases
We use relevant information to process orders, confirm payments, issue receipts and administer refunds.
Legal basis: Performance of a contract and compliance with applicable legal obligations.
Responding to enquiries
We use the information you provide to respond to questions, support requests and other communications.
Legal basis: Performance of a contract, steps taken before entering into a contract or our legitimate interests in responding to enquiries, depending on the circumstances.
Maintaining website security
We may process technical information to prevent fraud, identify suspicious activity, protect user accounts and maintain website security.
Legal basis: Our legitimate interests in operating a secure and reliable service and, where applicable, compliance with legal obligations.
Legal and accounting requirements
We retain and process information where necessary to comply with tax, accounting, consumer protection and other legal obligations.
Legal basis: Compliance with a legal obligation.
Marketing communications
We may send information about new courses, special offers and related educational products where you have consented to receive these communications or where an applicable existing-customer exception permits us to do so.
You can opt out of marketing communications at any time using the unsubscribe link in an email or by contacting admin@medievalcourses.com.
Unsubscribing from marketing does not prevent us from sending essential account, purchase or course-related communications.
Legal basis: Consent or, where legally permitted, our legitimate interests in promoting similar services to existing customers.
5. Course Accounts and Educational Records
When you enrol in a course, we maintain records necessary to provide your learning experience.
These may include your enrolment details, course progress, assessment results, completion status and certificates.
This information allows you to access your courses, resume your studies and demonstrate completion.
We may share limited information with a course leader where necessary for assessment, certification or delivery of the course.
Course leaders and other service providers are permitted to use personal information only for authorised purposes and must handle it in accordance with applicable data protection requirements.
6. Payments
Payments are processed through third-party payment providers, including Stripe and PayPal, where these services are available at checkout.
Payment providers process the information necessary to authorise and complete transactions, prevent fraud and comply with their legal obligations.
We receive relevant transaction information, such as payment status, amount, date and transaction reference, to administer purchases and maintain accounting records.
You can read the payment providers' privacy policies here:
Stripe: https://stripe.com/privacy
PayPal: https://www.paypal.com/privacy
7. Marketing Emails
If you subscribe to our mailing list, we may use your email address to send news about courses, educational content, events and special offers.
Where consent is required, we will ask for it before sending marketing communications.
Where permitted by Spanish law, we may contact existing customers about our own similar products or services, provided the relevant legal conditions are met and a simple, free opportunity to object is offered when contact details are collected and in every marketing message.
We do not sell mailing lists or personal contact details.
You may unsubscribe at any time.
8. Cookies and Similar Technologies
Our website uses cookies and similar technologies to support essential functionality and, where applicable, understand how visitors use the website.
Cookies may be used for:
- Maintaining secure account sessions.
- Remembering login and website preferences.
- Supporting course functionality and progress tracking.
- Remembering cookie consent choices.
- Measuring website usage, where enabled.
- Supporting embedded content or third-party services.
Cookies that are strictly necessary for a service requested by the user, or for transmitting communications, may be used without consent where legally exempt.
Other cookies requiring consent will only be activated after the appropriate consent has been obtained.
You can accept, reject or manage non-essential cookies through our cookie settings.
You can also change your preferences or withdraw consent at any time using [insert permanent cookie settings link].
For further information about the specific cookies used, their providers, purposes and durations, please see our [Cookie Policy - insert link to completed cookie table or separate policy].
9. Comments and User-Submitted Content
If comments are enabled, we may collect the information entered in the comment form together with technical information needed for moderation and spam prevention.
Approved comments and associated display names may be publicly visible.
We may use anti-spam services to identify unwanted or potentially harmful submissions.
If an external service such as Gravatar is enabled, information may be processed by that provider in accordance with its privacy policy.
Please avoid including sensitive personal information in public comments.
10. Embedded Content and External Websites
Our courses and articles may contain videos, images, links or other content provided by external websites.
When you interact with embedded content, the external provider may collect information about your device, browser or interaction.
Where embedded content involves non-essential cookies or tracking, we will implement the consent controls required by applicable law.
External websites operate under their own privacy policies. We encourage you to review those policies before providing personal information.
11. Sharing Personal Information
We do not sell your personal information.
We may share information where necessary with:
- Website hosting and technical maintenance providers.
- Payment processing services.
- Email delivery and mailing list providers.
- Course software and learning platform providers.
- Course leaders involved in teaching, assessment or certification.
- Security, backup and anti-spam service providers.
- Professional advisers or public authorities where legally required.
Where a provider processes personal data on our behalf, we take appropriate steps to ensure that the necessary contractual and data protection arrangements are in place.
Some third parties, including payment providers, may act as independent data controllers for certain activities.
12. International Data Transfers
Some of our service providers may process personal information outside the European Economic Area.
Where personal information is transferred internationally, we take steps to ensure that an appropriate transfer mechanism applies.
Depending on the destination and provider, this may include an adequacy decision by the European Commission or appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with any additional measures required.
You can contact us for further information about applicable transfer safeguards and how to obtain a copy where appropriate.
13. How Long We Keep Information
We retain personal information only for as long as necessary for the purposes for which it was collected, subject to applicable legal requirements.
When information is no longer required, we delete or anonymise it, or restrict its processing where retention remains legally necessary.
14. Your Data Protection Rights
Under the GDPR, you have rights concerning your personal information, subject to applicable legal conditions.
These include:
- Access: Request information about the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete information.
- Erasure: Request deletion of your personal information in circumstances where this right applies.
- Restriction: Request that we limit the processing of your information in certain circumstances.
- Portability: Receive certain personal information in a structured, commonly used, machine-readable format and, where applicable, transfer it to another provider.
- Objection: Object to processing based on legitimate interests in certain circumstances, and object at any time to processing for direct marketing.
- Withdrawal of consent: Withdraw consent at any time where consent is the legal basis for processing, without affecting the lawfulness of earlier processing.
You also have rights relating to certain decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise your rights, email:
admin@medievalcourses.com
We normally respond within one month of receiving a request. Where permitted by law, this period may be extended by up to two further months for complex or numerous requests, and we will explain any extension.
We may request reasonable information to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with the Spanish Data Protection Agency:
Agencia Española de Protección de Datos (AEPD)
https://www.aepd.es
15. Protecting Your Information
We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, alteration and disclosure.
These measures may include encrypted connections, access controls, security updates, backups and monitoring, according to the systems involved.
Access to personal information is limited to those who require it for legitimate operational purposes.
No online service can guarantee absolute security, but we review our arrangements and take reasonable steps to address identified risks.
16. Personal Data Breaches
If a personal data breach occurs, we will assess the potential risks to affected individuals and take appropriate action.
Where required by the GDPR, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals' rights and freedoms, we will also inform affected individuals without undue delay, unless a legal exception applies.
17. Children
Our courses and website content are intended primarily for a general educational audience.
Where consent is required for the processing of personal data in connection with an information society service offered directly to a child in Spain, we will comply with the applicable age and parental authorisation requirements.
18. Automated Decision-Making
We use automated processes where necessary for ordinary course functionality, such as recording quiz scores and tracking progress.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology or legal obligations.
The date at the top of this page indicates when the policy was last updated.
Where a change materially affects how we process personal information, we will provide additional notice where required.
20. Contact Us
If you have questions about this Privacy Policy or how we handle personal information, please contact:
MedievalCourses
Calle Sargento Galera 3
04887 Lúcar
Almería
Spain
Email: admin@medievalcourses.com
