Privacy Policy

Last updated: 30 July 2026

1. Introduction

Welcome to FindMySIA ("we", "us", or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website (findmysia.com), use our marketplace to search, compare, and book SIA training courses, and use our job board to advertise or apply for security vacancies.

FindMySIA is the data controller for the personal data described in this notice, except where stated otherwise — in particular, an employer who receives your job application becomes an independent controller of it. Our contact details are in section 12.

2. Information We Collect

We collect personal information that you provide to us, such as:

  • Learner Details: Name, email address, phone number, and billing/booking information.
  • Provider Details: Business name, address, Companies House details, VAT registration details, SIA trainer credentials, and bank account details for payouts.
  • Job Application Details: If you apply for a vacancy advertised on our job board, the name, email address and phone number you submit, together with your CV and any cover letter you upload.
  • Job Posting Details: If you advertise a vacancy, the posting content and the record of the listing fee you paid.
  • Sign-In Data: If you choose to sign in with Google, we receive your name, email address and Google account identifier from Google. We never receive your Google password.
  • Support Correspondence: The content of support tickets and messages you send us, so we can answer and keep a record of the issue.
  • Verification Data: Information returned by third-party checks we run on business details you give us, such as Companies House lookups.
  • Automatic Info: IP address, browser type, and cookie data gathered when navigating our platform.

3. How We Use Your Data

We use your data for various business purposes, including:

  • To facilitate course bookings and coordinates sharing between Learners and Training Providers.
  • To verify Training Provider qualifications and maintain platform security.
  • To securely process payments and commissions using Stripe.
  • To send transaction receipts, verification codes (OTPs), and customer service updates.
  • To pass your job application, including your CV, to the employer who advertised the vacancy you applied for.
  • To publish job postings and take payment for them.
  • To answer your support enquiries.

4. Our Lawful Bases For Processing

Under UK GDPR we must have a lawful basis for each purpose. Ours are:

  • Performance of a contract: creating and running your account, processing course bookings, taking job listing payments, and passing your application to the employer whose vacancy you applied for.
  • Legal obligation: keeping transaction and payment records for tax and accounting purposes, and responding to lawful requests from regulators or authorities.
  • Legitimate interests: verifying that providers are legitimate, preventing fraud and abuse, keeping the platform secure, and improving our services. Where we rely on this basis we have considered the impact on you and you may object at any time.
  • Consent: optional marketing communications, and the promotional use of provider names, logos and listing content. You can withdraw consent at any time without affecting anything done beforehand.

5. Sharing Your Information

We do not sell or rent your personal information. We share it only as follows:

  • Training Providers: your booking details are shared with the provider whose course you booked.
  • Employers: your application and CV are shared with the employer who advertised the vacancy you applied for.
  • Stripe: to process card payments and listing fees.
  • Google: where you choose to sign in with your Google account.
  • Our email provider: to deliver receipts, verification codes and service messages.
  • Our hosting and database providers: who store the platform's data on our behalf.
  • Companies House: where we verify business registration details you have supplied.

When you apply for a vacancy, your application and CV are shared with the employer who advertised it. From that point the employer handles your data as an independent controller under their own privacy practices, and we do not control how long they keep it. Employers are required by our Terms & Conditions to use it only to assess your application, to keep it no longer than necessary, and not to sell it, share it, or use it for marketing.

6. International Data Transfers

Some of the providers we use — including Stripe and Google — are based outside the United Kingdom or process data on servers outside it. Where personal data is transferred abroad, we rely on the UK Government's adequacy regulations for that country, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that your data continues to receive an equivalent level of protection. You can ask us for details of the safeguard applying to a specific transfer.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal data, including secure SSL encryption in transit, password hashing, encryption at rest of provider payout and bank details, and administrative access restricted to authorised staff.

8. How Long We Keep Your Data

We keep personal data only as long as we need it. In practice:

  • Account data: while your account is open, and for up to 12 months after you close it, so we can deal with any follow-up queries.
  • Payment and transaction records: six years from the end of the relevant financial year, as required by UK tax law.
  • Job applications and CVs: 12 months from the date of application, unless you ask us to delete yours sooner.
  • Support correspondence: 24 months from the date the ticket was closed.
  • Verification codes (OTPs): minutes — they expire shortly after being issued.

Where we no longer need data for these purposes, we delete it or anonymise it.

9. Your Rights

Under UK GDPR you have the right to:

  • Be informed about how your data is used — which is the purpose of this notice.
  • Access a copy of the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased, where we have no continuing reason to keep it.
  • Restrict how we use your data while a concern is being resolved.
  • Object to processing we carry out on the basis of legitimate interests, and to direct marketing at any time.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these rights, email us at support@findmysia.com. We will respond within one month. Exercising your rights is free, and we will not treat you differently for doing so.

If you are unhappy with how we have handled your data or your request, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to address your concern first.

10. Cookies

We only use cookies that are strictly necessary to run the platform, so no cookie banner is required and there is nothing for you to opt into. Specifically:

  • auth_token: keeps you signed in to your account.
  • oauth_state and oauth_meta: short-lived cookies used only during Google sign-in, to complete the process securely.

We do not use advertising, tracking or analytics cookies, and we do not share cookie data with third parties for those purposes. You can block or delete cookies in your browser settings, but you will not be able to stay signed in if you block the cookies above.

11. Automated Decision-Making

We do not make decisions about you by automated means alone, and we do not carry out profiling that produces legal effects for you. Provider applications and job postings are reviewed by our team before approval or removal.

12. Contact Us

If you have any questions or concerns about this policy, or wish to exercise your rights, please reach out to us: