Privacy Policy

Nexus by Cara Technology

nexusbycara.com | Cara Technology Limited | Company No. 2242098 | VAT No. GB 492 3199 23 | Registered in England & Wales

Version 1.0 — Last updated: 26 May 2026

1. Introduction

1.1 Cara Technology Limited (“we”, “us” or “our”) operates the Nexus by Cara Technology online learning platform at http://www.nexusbycara.com (the “Platform”). This Privacy Policy explains how we collect, use, store, share and protect personal information about you when you visit our website, register an account, purchase or access our courses, or otherwise interact with us.

1.2 Cara Technology Limited is the data controller responsible for personal information processed via the Platform, except where stated otherwise in this Policy (see in particular section 9 on Group Administrators).

1.3 We are a company registered in England and Wales under company number 2242098, with registered office at Ashcombe Court, Woolsack Way, Godalming, Surrey, United Kingdom, GU7 1LQ. Our VAT number is GB 492 3199 23.

1.4 This Privacy Policy forms part of our Terms and Conditions and should be read alongside them. By using the Platform, registering an account or purchasing a Product, you confirm that you have read and understood this Policy.

1.5 We comply with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, and where applicable the EU General Data Protection Regulation (“EU GDPR”).

2. How to Contact Us

2.1 For any questions about this Privacy Policy, or to exercise any of your data protection rights, please contact us:

  • Email: sales@cara-online.com
  • Post: Cara Technology, Bluebird House, Mole Business Park, Station Road, Leatherhead, Surrey, KT22 7BA, UK
  • Telephone: +44 (0)1372 439 990, Monday–Friday (excluding English bank holidays), 08:00–18:00 UK time

2.2 We have not appointed a Data Protection Officer because we are not required to do so under the UK GDPR. The named contact for data protection queries within Cara Technology Limited is the Senior Leadership Team, contactable via the channels above.

3. Information We Collect About You

3.1 We collect and process the following categories of personal information:

Information you provide directly

  • Account registration data: name, email address, password (stored in encrypted form), job title, organisation name, country, telephone number (optional).
  • Purchase and billing data: billing address, delivery address (where physical kits are ordered), VAT number (for business customers), purchase order references, invoice details.
  • Payment data: payment card details are NOT stored by us. Card details are entered directly into our payment providers (Stripe and PayPal), who hold them securely on our behalf. We receive only a payment confirmation, transaction reference and the last four digits of the card used.
  • Communications data: any information you provide when you contact us by email, telephone, support form or post, including the content of your message.
  • Marketing preferences: your consent (or refusal) to receive marketing communications and the channels you have opted into.

Information we generate when you use the Platform

  • Course progress data: which courses you are enrolled in, lessons and topics accessed, dates of access, time spent on content, quiz and assessment attempts and scores, certificates issued.
  • Account activity data: login dates and times, IP address used at login, browser and device information, pages viewed within the Platform.
  • Order history: a record of Products you have purchased, the prices paid, the dates of purchase, and any refunds or cancellations.

Information we collect automatically

  • Technical data: IP address, browser type and version, operating system, device type, time zone setting, referring website, and other technical information needed to deliver the Platform to your device.
  • Cookies and similar technologies: see our Cookie Policy for full details.
  • Analytics data: pseudonymous information about how visitors use the Website (which pages they visit, how they navigate, which links they click) collected via Google Analytics 4.

Information from third parties

  • Group enrolment data: where you are enrolled by a Group Administrator on behalf of an organisation, we may receive your name and email address from that organisation in order to set up your account.
  • Payment confirmations: from Stripe and PayPal in respect of completed transactions.

4. Special Category Data

4.1 We do not intentionally collect any special category personal data (such as data relating to health, racial or ethnic origin, religious beliefs, sexual orientation, political opinions, trade union membership, genetic or biometric data) through the Platform. You should not provide such information to us via the Platform, support channels, course content or assessments.

4.2 If you voluntarily share special category data with us — for example, by mentioning health information when requesting an accessibility accommodation — we will process it only for the purpose for which you provided it, and will delete it as soon as that purpose is fulfilled.

5. Children’s Data

5.1 The Platform is intended for use by adult professionals and learners in the food and beverage industry. We do not knowingly collect personal data from children under the age of 16. If we discover that we have inadvertently collected personal data from a child under 16, we will delete it promptly.

6. How We Use Your Information and Our Legal Basis

6.1 We process your personal data only where we have a lawful basis under data protection law to do so. The following sets out the main purposes for which we process personal data, the categories of data involved, and our lawful basis.

Providing the Platform and fulfilling orders

  • Purposes: setting up and managing your account; enrolling you in purchased courses; tracking your course progress; issuing certificates; processing payments; dispatching physical kits; providing customer support.
  • Lawful basis: performance of a contract between you and us (the contract being our Terms and Conditions).

Communicating with you about your account and orders

  • Purposes: sending purchase confirmations, course welcome emails, certificate notifications, access expiry reminders, password reset emails, security notifications, and other transactional messages necessary to provide the service.
  • Lawful basis: performance of a contract.

Marketing communications

  • Purposes: sending you information about new courses, updates to existing courses, training events, and related products and services from Cara Technology Limited (including AROXA and SensCheck), where you have consented to receive such communications.
  • Lawful basis: your consent. You can withdraw consent at any time by clicking the unsubscribe link in any marketing email, by updating your account preferences, or by contacting us at sales@cara-online.com.
  • Soft opt-in: where you are an existing customer who has purchased a Product from us, we may send you marketing emails about similar Products on the basis of our legitimate interest in promoting our business, unless you opt out. You can opt out at any time using the methods above.

Improving the Platform and our services

  • Purposes: analysing aggregated and pseudonymous usage data to understand how the Platform is used, identify problems, and improve the service.
  • Lawful basis: our legitimate interest in maintaining and improving our service, balanced against your privacy rights. We minimise the data used for this purpose and apply pseudonymisation where possible.

Compliance with legal obligations

  • Purposes: retaining transaction records for tax purposes (HMRC requires retention of business records for 6 years); responding to lawful requests from courts, regulators or law enforcement; preventing fraud and money laundering; complying with sanctions and export controls.
  • Lawful basis: compliance with a legal obligation.

Protecting our rights and interests

  • Purposes: investigating breaches of our Terms and Conditions (including account sharing, content scraping, assessment fraud); enforcing our intellectual property rights; defending or pursuing legal claims; protecting the security of the Platform and our users.
  • Lawful basis: our legitimate interest in protecting our business, our intellectual property, and the integrity of our service.

7. Who We Share Your Information With

7.1 We do not sell your personal data to anyone. We share personal data only with the categories of recipient listed below, and only to the extent necessary.

Service providers (data processors acting on our behalf)

7.2 We rely on a number of trusted third-party service providers to operate the Platform. These providers process personal data on our behalf, under contract, and in accordance with our instructions. The main categories are:

  • Hosting and infrastructure: our website hosting provider, located in the United Kingdom or European Union, who provides the servers and storage on which the Platform runs.
  • Payment processing: Stripe Payments Europe Ltd and PayPal (Europe) S.à r.l. et Cie S.C.A., who process card payments on our behalf. Each operates under their own privacy policy: stripe.com/gb/privacy and paypal.com/uk/legalhub/privacy-full.
  • Learning platform components: LearnDash (course delivery and progress tracking), BuddyBoss (account profiles and community features), and WooCommerce (e-commerce functionality). These are software components installed on our hosting infrastructure; data they process is held on our servers, not on theirs.
  • Email delivery: transactional email service providers used to send account-related and purchase-related emails; HubSpot for sales pipeline and marketing automation; Omnisend for marketing email flows.
  • Analytics: Google Analytics 4 (Google Ireland Limited) for aggregated and pseudonymous website analytics. Google Analytics is configured with IP anonymisation and without advertising features enabled, to minimise the data shared.
  • E-commerce analytics: Metorik, which provides reporting on WooCommerce sales and customer behaviour.
  • International couriers: where you order a physical training kit, we share your name, delivery address and contact details with our courier in order to arrange delivery.
  • Professional advisers: our accountants, auditors, lawyers and other professional advisers under appropriate confidentiality obligations, where necessary for the management of our business.

Group Administrators (separate data controllers)

7.3 Where you have been enrolled in a course by a Group Administrator on behalf of an organisation (for example, your employer purchased Group Seats on the Platform), we share certain training data about you with that Group Administrator, as set out in our Terms and Conditions. See section 9 below for more detail.

Other recipients

  • Successors in business: if we sell or transfer our business or any part of it, your information may be transferred to the buyer or transferee. We will take reasonable steps to ensure your privacy rights continue to be protected.
  • Courts, regulators and law enforcement: where we are required to disclose information by law, court order, or in response to a lawful request from a regulator or law enforcement authority.

8. International Transfers

8.1 Our primary hosting and storage of personal data is located in the United Kingdom or European Union.

8.2 Some of our service providers (for example, Stripe and Google) are global companies whose processing may involve the transfer of personal data outside the United Kingdom or European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, which may include:

  • Transfers to countries the UK government has determined provide an adequate level of data protection (“adequacy decisions”)
  • UK International Data Transfer Agreements or the UK Addendum to the EU Standard Contractual Clauses with the recipient
  • Other lawful transfer mechanisms recognised under UK data protection law

8.3 You can request further information about the safeguards in place for international transfers by contacting us at sales@cara-online.com.

9. Group Enrolments and Organisational Purchases

9.1 Many of our customers are organisations that purchase Group Seats to enable their employees or members to access our courses. This creates a more complex data protection picture which we explain here for transparency.

9.2 Where you (the “end user”) are enrolled in a course by a Group Administrator working on behalf of an organisation (the “purchasing organisation”):

  • The purchasing organisation is the data controller in respect of: your employment relationship with them; their decision to enrol you in training; and their access to your training data within their organisational context.
  • Cara Technology Limited is the data controller in respect of: your account on the Platform; your direct interactions with course content; the technical operation of the Platform; your communications with us.

9.3 What the Group Administrator can see. The Group Administrator can view the following information about each end user enrolled against their Group Seats: name, email address, enrolled courses, enrolment date, access expiry date, course progress (typically as a percentage), quiz and assessment scores, and certificate status.

9.4 What the Group Administrator cannot see. The Group Administrator does not have access to: your detailed interactions with course content (such as time spent on individual lessons or replay activity); personal information you have provided that is not necessary for training administration; or any communications between you and us.

9.5 Your data within your organisation. How your purchasing organisation uses your training data internally (for example, for HR purposes, performance management, or career development) is governed by your relationship with that organisation and their privacy notices to you. We are not responsible for the purchasing organisation’s internal use of your training data. If you have questions about how your training data is being used within your organisation, please contact them directly.

9.6 Notice to end users. When you are enrolled by a Group Administrator, we will inform you (typically by email at the point of enrolment) that your training progress, assessment results and certificates will be visible to your organisation’s nominated Group Administrator(s).

10. How Long We Keep Your Information

10.1 We keep personal data only for as long as necessary for the purposes for which it was collected, taking into account our legal, regulatory and business requirements. Our standard retention periods are:

  • Account data: for as long as you have an active account with us, plus 24 months after account closure or last activity (whichever is later). Inactive accounts may be closed after 24 months of no logins.
  • Course progress and certificates: for as long as your account is active. Certificates remain accessible in your account record for the lifetime of the account.
  • Purchase and financial records: retained for 6 years from the end of the relevant accounting period in accordance with HMRC requirements (Finance Act 1998 and related provisions).
  • Communications records: retained for 2 years from the date of the last communication unless retention for longer is required to resolve an ongoing matter.
  • Marketing data: retained for as long as you continue to consent to marketing. If you withdraw consent, your contact details are removed from marketing lists promptly (within 30 days).
  • Technical and analytics data: retained for the periods specified in our Cookie Policy. Google Analytics 4 default retention is set to 14 months.

10.2 After the applicable retention period, we will securely delete or anonymise the personal data.

10.3 Where personal data is held in backups, those backups are deleted on a rolling cycle in accordance with our backup retention schedule. Personal data deleted from active systems will accordingly remain in backups for a limited period until those backups are themselves overwritten.

11. Your Data Protection Rights

11.1 You have the following rights in relation to your personal data under the UK GDPR and Data Protection Act 2018:

  • Right of access: the right to obtain a copy of the personal data we hold about you, together with information about how we process it.
  • Right to rectification: the right to have inaccurate personal data corrected, or incomplete data completed.
  • Right to erasure (‘right to be forgotten’): the right to have your personal data deleted in certain circumstances (for example, where it is no longer needed for the purpose for which it was collected, or where you withdraw consent).
  • Right to restrict processing: the right to ask us to limit how we process your personal data in certain circumstances.
  • Right to data portability: the right to receive your personal data in a structured, commonly used and machine-readable format, and to have it transferred to another data controller.
  • Right to object: the right to object to processing that is based on our legitimate interests, including marketing.
  • Rights in relation to automated decision-making: we do not use automated decision-making that produces legal or similarly significant effects on individuals.
  • Right to withdraw consent: where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

11.2 To exercise any of these rights, please contact us at sales@cara-online.com. We will respond within one month of receiving a valid request. We may need to verify your identity before complying with a request.

11.3 Most rights are not absolute. There are circumstances in which we can lawfully refuse a request, for example where compliance would require us to delete records we are legally obliged to keep, or where the request is manifestly unfounded or excessive. We will explain our reasons if we cannot fully comply with a request.

11.4 Right to complain. If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the opportunity to address your concerns directly before you contact the ICO.

12. How We Protect Your Information

12.1 We take the security of your personal data seriously and use appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, alteration or disclosure. These measures include:

  • Encryption of data in transit using TLS (HTTPS) for all communications between your device and the Platform
  • Encryption of sensitive data at rest, including passwords (which are hashed and salted, never stored in clear text)
  • Access controls limiting which staff and contractors can access personal data, on a need-to-know basis
  • Two-factor authentication for administrative access to systems holding personal data, where supported
  • Regular software updates and security patching
  • Regular backups, themselves protected against unauthorised access
  • Use of reputable third-party service providers who maintain appropriate security standards
  • Staff training on data protection and information security

12.2 However, no method of internet transmission or electronic storage is 100% secure. While we use industry-standard measures, we cannot guarantee absolute security. You also play an important role in protecting your account by keeping your login credentials confidential, using a strong unique password, and notifying us immediately of any suspected unauthorised access.

12.3 Personal data breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours where required by law, and we will also notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Cookies and Similar Technologies

13.1 We use cookies and similar technologies on the Platform to operate the service, remember your preferences, understand how the Platform is used, and (where you consent) to support marketing. Full details of the cookies we use, the purpose of each, and how to control them are set out in our separate Cookie Policy.

13.2 On your first visit to the Website, we will ask you to indicate your cookie preferences via a cookie banner. You can change your preferences at any time by clicking the cookie settings link in the footer of the Website.

14. Marketing Communications

14.1 If you have consented to receive marketing communications, we may send you information about new courses, updates to existing courses, events and related products and services across the Cara Technology family of brands (including Nexus, AROXA and SensCheck).

14.2 We will only send you marketing communications if either: (a) you have given your specific consent (for example, by ticking a marketing opt-in box at registration or via our website), or (b) you are an existing customer and the marketing relates to similar Products to those you have previously purchased (the “soft opt-in” recognised under UK direct marketing rules).

14.3 Opting out. You can opt out of marketing communications at any time:

  • By clicking the unsubscribe link at the bottom of any marketing email
  • By updating your marketing preferences in your account
  • By emailing us at sales@cara-online.com

We will process your opt-out promptly, normally within a few business days. Note that even after you opt out of marketing, we will continue to send you transactional emails about your account, orders and courses, as these are necessary to provide the service.

15. Third-Party Websites and Services

15.1 Our Website and Platform may contain links to other websites and services that are not operated by us. This Privacy Policy does not apply to those third-party sites or services. We are not responsible for their privacy practices, and we recommend you review the privacy notice of any third-party site you visit.

16. Changes to This Policy

16.1 We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. The latest version will always be published on our Website with a clearly visible “last updated” date.

16.2 Where changes are material (for example, changes that affect how we process your personal data in a significant way), we will notify registered users by email or via a notice on the Platform.

16.3 We encourage you to review this Policy periodically to stay informed about how we use your personal data.

Version History

v1.0 — Initial Privacy Policy. Effective 26 May 2026.

© Cara Technology Limited. All rights reserved.

GBP
USD
EUR
GBP
USD
EUR