PREPXPERTS ONLINE ACADEMY
Privacy Policy
Updates on 1st March 2026 by PrepXperts Online Academy
1. Introduction & Scope
PrepXperts Online Academy (“PrepXperts”, “we”, “us”, or “our”) is an online medical examination preparation platform dedicated to helping doctors, postgraduate trainees, and international medical graduates succeed in licensing and specialty exams including MRCP, MRCPCH, MRCOG, MRCEM, MRCPI, MRCS, and FCPS.
We take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your personal information when you access or use our website, learning management platform, mobile applications, or any other service we offer.
This policy applies to all users of our platform, regardless of their location. By creating an account or otherwise using PrepXperts services, you acknowledge that you have read and understood the practices described in this document.
If you do not agree with any part of this Privacy Policy, we respectfully ask that you refrain from using our platform.
2. Information We Collect
2.1 Information You Provide Directly
When you register, subscribe to a course, or interact with us, we may collect the following categories of personal information:
- Identity & Professional Data: Full name, username, professional title, medical specialisation, and academic credentials
- Contact Data: Email address, phone number, and mailing address
- Account Data: Login credentials, security settings, and account preferences
- Profile Data: Profile photograph, institution name, country of practice, and exam goals
- Payment Data: Billing details and transaction records (processed exclusively via secure, certified third-party payment gateways — we do not store card numbers on our servers)
- Learning Records: Course enrolments, attendance, quiz and mock exam scores, progress milestones, and certificates issued
- Communications: Messages, feedback, and support requests submitted to our team
2.2 Information Collected Automatically
When you interact with our platform, certain technical information is gathered automatically:
- Device & Browser Data: IP address, browser type and version, operating system, and unique device identifiers
- Usage & Navigation Data: Pages viewed, session duration, click paths, and feature interactions
- Geographic Data: Approximate location inferred from your IP address
- Cookie & Tracking Data: Information gathered through cookies, pixels, and similar tracking technologies (see Section 8)
2.3 Information from Third Parties
In some cases, we may receive information about you from third-party sources, such as social login providers (e.g., Google or Facebook), payment processors, or referral partners. We handle all such data in accordance with this policy.
3. How We Use Your Information
We process personal data only for legitimate, clearly defined purposes. The table below summarises how we use the information we collect:
| Purpose | What We Do |
|---|---|
| Platform Delivery | To operate, maintain, and continuously improve our exam preparation courses, mock tests, and mentorship services. |
| Account Administration | To create and manage your learner account, process registrations, and handle customer support requests. |
| Learning Personalisation | To tailor course recommendations, track your progress, and adapt content to your exam preparation goals. |
| Communications | To send you important updates, course alerts, study reminders, and respond to your queries in a timely manner. |
| Payments & Billing | To process subscription fees and course purchases securely through our trusted third-party payment partners. |
| Platform Analytics | To analyse usage patterns, improve content quality, and optimise the overall learner experience. |
| Safety & Security | To detect, investigate, and prevent fraudulent activity, data breaches, or any misuse of our platform |
| Legal Obligations | To fulfil our obligations under applicable data protection laws and enforce our Terms & Conditions. |
4. Legal Basis for Processing
Where applicable data protection laws require a legal basis, we rely on the following grounds:
- Contractual Necessity: To fulfil our obligations under our Terms & Conditions when you subscribe to or use our services
- Legitimate Interests: To improve our platform, maintain security, and communicate relevant information to learners
- Consent: Where you have given us explicit permission, such as for marketing communications
- Legal Obligation: Where processing is required to comply with applicable laws and regulations
You may withdraw consent at any time without affecting the lawfulness of processing that occurred prior to withdrawal.
5. Information Sharing & Disclosure
5.1 Trusted Service Providers
We engage carefully vetted third-party vendors to help us operate our platform. These may include hosting providers, payment processors, email delivery services, analytics tools, and customer support platforms. All providers are contractually obligated to handle your data securely and solely for the purposes we specify.
5.2 Business Transfers
In the unlikely event that PrepXperts undergoes a merger, acquisition, restructuring, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change and ensure your data remains protected under equivalent standards.
5.3 Legal & Regulatory Disclosures
We may disclose your information where required by law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of PrepXperts, our users, or the public.
5.4 Our Commitment: We Do Not Sell Your Data
PrepXperts does not sell, rent, lease, or trade your personal information to third parties for any commercial or marketing purposes. Your data is not a product — it is a responsibility we take seriously.
6. Data Security
We implement a multi-layered approach to protecting your personal information, including:
- SSL/TLS encryption for all data in transit between your device and our servers
- Secure hashing and salting of passwords — we never store passwords in plain text
- Role-based access controls to limit internal staff access to personal data
- Regular security audits, penetration testing, and vulnerability assessments
- Encrypted backups and secure disaster recovery procedures
- Ongoing staff training on data protection and information security best practices
While we apply industry-standard safeguards, no method of data transmission or storage is entirely without risk. We cannot provide an absolute guarantee of security, and we encourage you to protect your own account by using a strong, unique password and logging out after each session.
In the event of a data breach that is likely to affect your rights or interests, we will notify you and the relevant authorities in accordance with applicable law.
7. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes described in this policy, or as required by law. Specifically:
- Active account data is retained throughout the duration of your relationship with PrepXperts
- Learning records, certificates, and transcripts may be retained for up to 7 years to support professional regulatory requirements
- Financial transaction records are retained for a minimum of 5 years in compliance with tax and accounting obligations
- Upon account deletion, we will securely erase or anonymise your personal data within 90 days, unless a longer retention period is legally mandated
8. Cookies & Tracking Technologies
PrepXperts uses cookies and similar technologies to enhance your experience, remember your preferences, and understand how our platform is used. Cookies we use include:
- Essential Cookies: Required for the platform to function correctly, such as session management and authentication
- Performance Cookies: Help us measure traffic, page load times, and feature usage to improve performance
- Functional Cookies: Store your preferences, such as language settings or previously visited courses
- Analytics Cookies: Allow us to understand aggregate usage trends through tools such as Google Analytics
You can manage or disable cookies through your browser settings at any time. Please note that disabling certain cookies may impact the functionality of some features on our platform. For further detail on our specific cookie usage, please refer to our Cookie Policy available on our website.
9. Your Privacy Rights
Depending on your country of residence, you may be entitled to exercise the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete information
- Right to Erasure: Request deletion of your personal data, subject to legal retention obligations
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Restriction: Request that we limit how we use your data in certain circumstances
- Right to Withdraw Consent: Withdraw consent at any time where processing is consent-based
To exercise any of these rights, please contact us using the details in Section 11. We will acknowledge your request promptly and respond within 30 calendar days. In complex cases, this may be extended by a further 60 days with prior notification.
We will never discriminate against you for exercising any of your privacy rights.
10. Children's Privacy
PrepXperts is designed exclusively for medical professionals, postgraduate trainees, and licensed graduates. Our platform is not intended for, nor directed at, individuals under the age of 18.
We do not knowingly collect personal information from minors. If we become aware that a user under 18 has registered on our platform, we will promptly delete all associated data. If you believe we have inadvertently collected information from a minor, please notify us immediately using the contact details below.
11. International Data Transfers
PrepXperts serves learners across multiple countries, including the United Kingdom, Pakistan, and other regions. Where your personal data is transferred to countries outside your jurisdiction, we ensure that appropriate safeguards are in place, such as standard contractual clauses or equivalent protections recognised under applicable data protection law.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we do:
- The revised policy will be published on this page with an updated "Last Reviewed" date
- For material changes that significantly affect your rights, we will provide prominent notice via email or a banner notification on our platform
- Continued use of PrepXperts following the publication of any changes constitutes your acceptance of the revised policy
We encourage you to review this policy regularly to stay informed about how we protect your information.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please do not hesitate to reach out to us:
- Organisation: PrepXperts Online Academy
- Email (General): support@prepxperts.com
- Email (Privacy): privacy@prepxpertsonline.com
- Platform: www.prepxperts.com
