Privacy policy

How we handle your personal data

This notice explains what personal data Stellar Catalyst UK Ltd collects, why we collect it, the lawful bases on which we process it, how long we keep it, and the rights available to you under data protection legislation.

Last updated 3 August 2026. Issued by Stellar Catalyst UK Ltd, company number 17108493, registered office 24 Norfolk Street, Coventry, CV1 3BX.

01

Controller and contact

Who is responsible for your data.

Stellar Catalyst UK Ltd is the controller in respect of the personal data described in this notice. We determine the purposes and means of processing and are accountable for compliance with the United Kingdom General Data Protection Regulation and the Data Protection Act 2018.

ControllerStellar Catalyst UK Ltd
Company number17108493
Registered office24 Norfolk Street, Coventry, CV1 3BX, United Kingdom
Data protection contactinfo@stellarcatalystuk.co.uk

We have not appointed a statutory Data Protection Officer, as we are not required to do so. Data protection matters are handled by the company directly at the address above.

02

Data we collect

What we hold, and where it comes from.

Data you provide

  • Identity data — name, title, and where relevant your institution, department or employer.
  • Contact data — electronic mail address, telephone number, postal address.
  • Account data — username, password in hashed form, account preferences.
  • Order data — services purchased, mode and duration selected, scheduling preferences, order references.
  • Academic data — where relevant to the service, your programme of study, level, institution and prior experience.
  • Correspondence — enquiries, support requests, complaints and our replies.

Data generated automatically

  • Technical data — internet protocol address, browser type and version, device and operating system, time zone.
  • Usage data — pages viewed, navigation paths, features used, duration of visits.

Data we do not hold

We do not receive, process or store full payment card details. Card data is captured and processed by our payment service provider. We receive only a transaction reference, the result, and the last four digits of the card for reconciliation.

We do not deliberately collect special category data. Where you disclose such data to us in correspondence — for example a health condition relevant to attendance arrangements — we process it only so far as necessary and on the basis of your explicit consent or the establishment of legal claims.

03

Purposes and lawful bases

Why we process, and the legal ground for each purpose.
PurposeLawful basis
Creating and administering your accountPerformance of a contract
Accepting and fulfilling ordersPerformance of a contract
Delivering services and issuing certificationPerformance of a contract
Responding to enquiries and support requestsLegitimate interests — responding to those who contact us
Handling complaintsLegitimate interests — resolving disputes; legal obligation where applicable
Maintaining accounting recordsLegal obligation — Companies Act 2006 and tax legislation
Preventing fraud and securing the platformLegitimate interests — protecting the business and its users
Analytics and service improvementConsent, given through the cookie banner
Marketing communicationsConsent, or soft opt-in for existing customers

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your interests, rights and freedoms. You may object to such processing as set out below.

04

Sharing and recipients

Who else may receive your data.

We share personal data only where necessary and under appropriate safeguards. Recipients fall into the following categories:

  • Payment service providers — to process card payments and manage refunds and chargebacks.
  • Hosting and infrastructure providers — who store data on our behalf as processors.
  • Electronic mail and communication providers — to deliver transactional and support correspondence.
  • Analytics providers — where you have consented, as described in the cookie policy.
  • Professional advisers — accountants, auditors and lawyers, where required.
  • Public authorities — where we are under a legal obligation to disclose.

Where a recipient acts as a processor, a written contract is in place requiring the processing to be carried out only on our documented instructions and subject to appropriate technical and organisational measures.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

05

International transfers

Where data may be processed outside the United Kingdom.

Delivery of services within the NTHRYS platform involves operational support from the wider NTHRYS organisation, part of which is located in India. Certain personal data necessary for delivering a service you have purchased may therefore be transferred outside the United Kingdom.

Where such a transfer occurs, we rely on the International Data Transfer Agreement or the United Kingdom Addendum to the European Commission standard contractual clauses, together with a transfer risk assessment, so that the level of protection afforded to your data is not undermined.

You may request a copy of the safeguards applied by writing to the data protection contact above.

06

Retention

How long we keep data, and why.
Account and profile dataFor the life of the account, then 12 months after closure.
Order and transaction recordsSix years from the end of the accounting period, as required by the Companies Act 2006 and tax legislation.
Certification recordsRetained indefinitely, so that certification can be verified on request.
Correspondence and supportThree years from the date of the last exchange.
Complaint recordsSix years from resolution.
Marketing consentsUntil withdrawn, and a record of the withdrawal thereafter.
Analytics data26 months from collection.

At the end of a retention period data is deleted or anonymised so that it can no longer be associated with you.

07

Your rights

What you may require us to do, and how.

Subject to the conditions set out in data protection legislation, you have the right to:

  • Be informed about how your data is processed — the purpose of this notice.
  • Access a copy of the personal data we hold about you.
  • Rectification of inaccurate data and completion of incomplete data.
  • Erasure in the circumstances where that right applies.
  • Restriction of processing while an issue is investigated.
  • Portability of data you provided to us, where processing is by consent or contract and carried out by automated means.
  • Object to processing based on legitimate interests, and to direct marketing at any time and without qualification.
  • Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

To exercise a right, write to the data protection contact stated above. We will respond within one month. That period may be extended by two further months where a request is complex or where several requests have been made, and we will tell you within one month if that is the case. No fee is payable, though we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

Complaints to the regulator. If you are not satisfied with how we have handled your data, you may complain to the Information Commissioner's Office, the United Kingdom supervisory authority for data protection, at ico.org.uk. We would ask that you raise the matter with us first so that we have the opportunity to resolve it.

08

Security

Measures taken to protect your data.

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, hashed storage of credentials, access control on a least-privilege basis, logging of administrative access, and segregation of production data from development environments.

No transmission over the internet can be guaranteed entirely secure. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and will notify you where the risk is high.

09

Cookies and changes

Related material and amendment of this notice.

Cookies and similar technologies are addressed separately in the cookie policy, which sets out the categories used, their purpose and duration, and how consent may be given or withdrawn.

We may amend this notice to reflect changes in our processing, in the services we provide or in applicable law. The date at the head of this page indicates when it was last revised. Where a change is material we will notify registered account holders directly.