Privacy
Privacy notice
How RLC SCO Nexus collects, uses, protects and lets you control your personal data.
Last updated 13 September 2026
In short
- Nexus is run independently by its own owner-administrator, not the Ministry of Defence, the British Army or the Royal Logistic Corps.
- We only collect what's needed to run your account, your learning records and your certificates. Nothing is used for advertising, profiling or sold to anyone.
- Everything we do relies on providing you the service you've asked for, or a genuine need to keep Nexus secure and trustworthy, never on marketing consent.
- You can download your own data, correct it from your profile, or ask us to anonymise your account at any time.
- There's no analytics or tracking. The only cookies are for staying signed in and remembering an explicit dark/light choice.
- You can ask a question or exercise a right at any time through Contact.
On this page
Who runs Nexus
The controller is Kris Kirby, who operates RLC SCO Nexus as an individual (not a company or a government body). It is not the Ministry of Defence, the British Army or the Royal Logistic Corps. See Legal for what that independence means for the platform as a whole.
The way to reach us about anything on this page, whether a question, a correction, or a request to exercise one of your rights, is the contact form. If you're signed in, you can also start a request from your profile. Written enquiries can be raised through the contact form; we will confirm a postal address on request.
What we collect
The minimum needed to run a role-controlled training platform:
Your display name, email address and access-request reason are required. Without them we can't create or run an account. Rank, location and unit are optional and nothing is withheld if you leave them out.
- Account identity: your display name and email address.
- Optional profile details: rank/grade, home location and unit, if you choose to give them. These are display-only and never used to decide your access on their own.
- Your access-request reason: the free-text explanation you gave when requesting an account.
- Learning records: course progress, bookmarks, tutorial progress, simulation attempts, assessment attempts and your answers, and your marks.
- Certificatesyou've earned, and their verification history.
- Cohort membership: the classes you belong to, for instructors managing that class.
- In-app notifications sent to you inside the platform.
- Administration and moderation records: decisions made about your account or content you've submitted, and any notes staff record when making them.
- Security records: audit log entries identified by account, sign-in security counters, and (for the contact form) a one-way hash of the IP address used to submit it, kept only to throttle abuse.
- Anything you send us: the content of a message sent through the contact form, and an optional name or reply address if you choose to give one.
Some of this comes from staff rather than you: cohort membership recorded by an instructor, and notes an administrator or moderator records when deciding something about your account or content.
Why, and on what basis
UK GDPR requires us to have a lawful basis for each way we use your data. Here's the basis for each purpose:
Purpose, what it covers, and the lawful basis relied on
| Purpose | What this covers | Lawful basis |
|---|---|---|
| Considering your access request | Your registration request, including the reason you gave | Steps you asked us to take before you have an account, under our Terms of Use, plus our legitimate interest in deciding requests safely |
| Providing the service you're signed in for | Your account, courses, progress, bookmarks, tutorials, simulations, assessments, marks, certificates, notifications and cohorts | Contract: necessary to provide the service you've asked for under our Terms of Use |
| Keeping Nexus secure | Audit log entries, sign-in security counters, hashed IP used for throttling | Legitimate interests: running a secure, trustworthy platform and preventing misuse |
| Public certificate verification | Name, course, dates and status, shown only when both the certificate number and its verification code are supplied | Legitimate interests: the integrity of certificates, for holders and verifiers alike |
| Handling a privacy, security, accessibility or general request | Any name or reply address you give, and your message | Legitimate interests, and a legal obligation to respond to it where it's a data-protection rights request |
| Platform administration | Role changes, content holds, account anonymisation and retention actions | Legitimate interests, and a legal obligation to comply with data-protection law |
Nothing on Nexus relies on your consent, and nothing is used for marketing or profiling. Assessment marking is carried out automatically by the server, re-deriving your result from the question bank, never by your device, and never trusted from anything it submits. This doesn't have a legal or similarly significant effect on you in its own right; if you'd like a member of staff to check a marked attempt, you can ask through Contact.
What we don't collect
- Special-category data (health, religion, ethnicity and similar) isn't required by any part of Nexus and isn't designed to hold it. Free-text fields (like your access-request reason or a contact message) carry guidance not to include it.
- We don't track your location. Your "home location" is a place you choose from a list, shown to instructors for class management. It isn't GPS or IP-based tracking.
- No analytics, advertising or third-party tracking technology runs anywhere on the platform.
Where your information is processed
Vercel runs the platform's server functions in its Washington DC (US) region by default. Supabase's project region is under confirmation. Both providers publish data processing agreements built on standard contractual safeguards (the UK's international data transfer addendum or equivalent clauses) that apply to any transfer of your data outside the UK. We'll update this notice if either provider's processing location changes.
How long we keep it
A weekly automated process enforces the timed rules below (access requests, notifications, contact requests, sign-in counters). The remaining rows are criteria we apply on review.
What's kept, and for how long
| Data | Kept |
|---|---|
| Account, profile, learning records, certificates, cohort membership | While your account is active. If you ask us to erase your account, or if you haven't signed in for 24 months, your account is listed for administrator review and anonymised unless there's a recorded reason to keep it. |
| Rejected access requests | Personal fields removed 90 days after the decision |
| In-app notifications | Deleted after 12 months |
| Closed contact requests | Name, reply address and message removed 12 months after the request is closed |
| Sign-in security counters | Reset after 12 months of inactivity. This doesn't apply to an account an administrator has locked indefinitely, which only clears via a completed password reset or an administrator |
| Audit, certificate and content-review records | Kept for the life of the platform as accountability and certificate-verification evidence. These records contain identifiers only, and are reviewed annually. Anonymisation removes the link to you personally; it doesn't delete these records. |
| Backups | Our hosting provider's own routine backups may hold copies for a limited period before being overwritten, independently of the rules above |
Your rights
Under UK GDPR, you have the right to:
- Be informed: this notice.
- Access your data: download a structured copy any time from your profile, or ask us for one.
- Rectification: correct your display name, rank, location and unit directly from your profile; ask us about anything else.
- Erasure: because certificates and assessment records need to stay verifiable and auditable, we can't delete a full account outright. Instead, we anonymise it on request: your name, rank, avatar, location and unit are removed and the account is disabled, while your learning history, attempts and certificates are kept, with the identifying details already stripped, as evidence rather than as data about you personally. Your bookmarks and in-app notifications are deleted outright, and your sign-in identity is replaced so it can no longer be used to sign in.
- Restriction: you can ask us to limit how we use your data while a question about it is resolved; in practice we do this by disabling the account.
- Object to processing that relies on our legitimate interests.
- Portability: the same download above is a structured, machine-readable (JSON) export.
- Rights around automated decision-making: see "Why, and on what basis" above for how marking works and how to ask for a human check.
To ask about any of this, use Contact(choose "Privacy") or your profile. We respond within one month of a valid request, and will tell you if we need to extend that for a complex or repeated request, as the law allows.
Complaints
If you're unhappy with how we've handled your data or a request, we'd like the chance to put it right first. Tell us through Contact. You can also complain directly to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk/make-a-complaint. We'll acknowledge a complaint about how we've handled your data within 30 days and respond to it without undue delay.
Certificates and public verification
Anyone who has both a certificate's number and its separate verification code can check it. This shows the holder's name, course, dates and status only, the same information printed on the certificate itself. Each verification is logged for integrity, and checking is rate-limited to prevent automated enumeration.
Changes
We date this notice whenever it changes, and announce material changes in-app rather than silently. This version is dated 13 September 2026.