Skip to content

RLC // SCO Nexus

Request accessSign in

Privacy

Privacy notice

How RLC SCO Nexus collects, uses, protects and lets you control your personal data.

Last updated 13 September 2026

In short

  • Nexus is run independently by its own owner-administrator, not the Ministry of Defence, the British Army or the Royal Logistic Corps.
  • We only collect what's needed to run your account, your learning records and your certificates. Nothing is used for advertising, profiling or sold to anyone.
  • Everything we do relies on providing you the service you've asked for, or a genuine need to keep Nexus secure and trustworthy, never on marketing consent.
  • You can download your own data, correct it from your profile, or ask us to anonymise your account at any time.
  • There's no analytics or tracking. The only cookies are for staying signed in and remembering an explicit dark/light choice.
  • You can ask a question or exercise a right at any time through Contact.
On this page
  • Who runs Nexus
  • What we collect
  • Why, and on what basis
  • What we don't collect
  • Who we share it with
  • Where it's processed
  • How long we keep it
  • Your rights
  • Complaints
  • Cookies and storage
  • Certificates and verification
  • Changes

On this page

  • Who runs Nexus
  • What we collect
  • Why, and on what basis
  • What we don't collect
  • Who we share it with
  • Where it's processed
  • How long we keep it
  • Your rights
  • Complaints
  • Cookies and storage
  • Certificates and verification
  • Changes

Who runs Nexus

The controller is Kris Kirby, who operates RLC SCO Nexus as an individual (not a company or a government body). It is not the Ministry of Defence, the British Army or the Royal Logistic Corps. See Legal for what that independence means for the platform as a whole.

The way to reach us about anything on this page, whether a question, a correction, or a request to exercise one of your rights, is the contact form. If you're signed in, you can also start a request from your profile. Written enquiries can be raised through the contact form; we will confirm a postal address on request.

What we collect

The minimum needed to run a role-controlled training platform:

Your display name, email address and access-request reason are required. Without them we can't create or run an account. Rank, location and unit are optional and nothing is withheld if you leave them out.

  • Account identity: your display name and email address.
  • Optional profile details: rank/grade, home location and unit, if you choose to give them. These are display-only and never used to decide your access on their own.
  • Your access-request reason: the free-text explanation you gave when requesting an account.
  • Learning records: course progress, bookmarks, tutorial progress, simulation attempts, assessment attempts and your answers, and your marks.
  • Certificatesyou've earned, and their verification history.
  • Cohort membership: the classes you belong to, for instructors managing that class.
  • In-app notifications sent to you inside the platform.
  • Administration and moderation records: decisions made about your account or content you've submitted, and any notes staff record when making them.
  • Security records: audit log entries identified by account, sign-in security counters, and (for the contact form) a one-way hash of the IP address used to submit it, kept only to throttle abuse.
  • Anything you send us: the content of a message sent through the contact form, and an optional name or reply address if you choose to give one.

Some of this comes from staff rather than you: cohort membership recorded by an instructor, and notes an administrator or moderator records when deciding something about your account or content.

Why, and on what basis

UK GDPR requires us to have a lawful basis for each way we use your data. Here's the basis for each purpose:

Purpose, what it covers, and the lawful basis relied on

PurposeWhat this coversLawful basis
Considering your access requestYour registration request, including the reason you gaveSteps you asked us to take before you have an account, under our Terms of Use, plus our legitimate interest in deciding requests safely
Providing the service you're signed in forYour account, courses, progress, bookmarks, tutorials, simulations, assessments, marks, certificates, notifications and cohortsContract: necessary to provide the service you've asked for under our Terms of Use
Keeping Nexus secureAudit log entries, sign-in security counters, hashed IP used for throttlingLegitimate interests: running a secure, trustworthy platform and preventing misuse
Public certificate verificationName, course, dates and status, shown only when both the certificate number and its verification code are suppliedLegitimate interests: the integrity of certificates, for holders and verifiers alike
Handling a privacy, security, accessibility or general requestAny name or reply address you give, and your messageLegitimate interests, and a legal obligation to respond to it where it's a data-protection rights request
Platform administrationRole changes, content holds, account anonymisation and retention actionsLegitimate interests, and a legal obligation to comply with data-protection law

Nothing on Nexus relies on your consent, and nothing is used for marketing or profiling. Assessment marking is carried out automatically by the server, re-deriving your result from the question bank, never by your device, and never trusted from anything it submits. This doesn't have a legal or similarly significant effect on you in its own right; if you'd like a member of staff to check a marked attempt, you can ask through Contact.

What we don't collect

  • Special-category data (health, religion, ethnicity and similar) isn't required by any part of Nexus and isn't designed to hold it. Free-text fields (like your access-request reason or a contact message) carry guidance not to include it.
  • We don't track your location. Your "home location" is a place you choose from a list, shown to instructors for class management. It isn't GPS or IP-based tracking.
  • No analytics, advertising or third-party tracking technology runs anywhere on the platform.

Who we share it with

We don't sell your data, and we don't share it for advertising. It's processed by:

  • Supabase: hosts the database, authentication and file storage the platform is built on.
  • Vercel: hosts and runs the application itself.
  • Supabase's own default email sender: sends account and password-reset emails. A dedicated production email provider hasn't been configured yet; until it is, these emails come from Supabase's built-in sender rather than a provider chosen specifically for Nexus.

We'd also share data where the law requires it: for example, in response to a valid court order.

Where your information is processed

Vercel runs the platform's server functions in its Washington DC (US) region by default. Supabase's project region is under confirmation. Both providers publish data processing agreements built on standard contractual safeguards (the UK's international data transfer addendum or equivalent clauses) that apply to any transfer of your data outside the UK. We'll update this notice if either provider's processing location changes.

How long we keep it

A weekly automated process enforces the timed rules below (access requests, notifications, contact requests, sign-in counters). The remaining rows are criteria we apply on review.

What's kept, and for how long

DataKept
Account, profile, learning records, certificates, cohort membershipWhile your account is active. If you ask us to erase your account, or if you haven't signed in for 24 months, your account is listed for administrator review and anonymised unless there's a recorded reason to keep it.
Rejected access requestsPersonal fields removed 90 days after the decision
In-app notificationsDeleted after 12 months
Closed contact requestsName, reply address and message removed 12 months after the request is closed
Sign-in security countersReset after 12 months of inactivity. This doesn't apply to an account an administrator has locked indefinitely, which only clears via a completed password reset or an administrator
Audit, certificate and content-review recordsKept for the life of the platform as accountability and certificate-verification evidence. These records contain identifiers only, and are reviewed annually. Anonymisation removes the link to you personally; it doesn't delete these records.
BackupsOur hosting provider's own routine backups may hold copies for a limited period before being overwritten, independently of the rules above

Your rights

Under UK GDPR, you have the right to:

  • Be informed: this notice.
  • Access your data: download a structured copy any time from your profile, or ask us for one.
  • Rectification: correct your display name, rank, location and unit directly from your profile; ask us about anything else.
  • Erasure: because certificates and assessment records need to stay verifiable and auditable, we can't delete a full account outright. Instead, we anonymise it on request: your name, rank, avatar, location and unit are removed and the account is disabled, while your learning history, attempts and certificates are kept, with the identifying details already stripped, as evidence rather than as data about you personally. Your bookmarks and in-app notifications are deleted outright, and your sign-in identity is replaced so it can no longer be used to sign in.
  • Restriction: you can ask us to limit how we use your data while a question about it is resolved; in practice we do this by disabling the account.
  • Object to processing that relies on our legitimate interests.
  • Portability: the same download above is a structured, machine-readable (JSON) export.
  • Rights around automated decision-making: see "Why, and on what basis" above for how marking works and how to ask for a human check.
Not every right applies in every situation. For example, erasure and portability depend on which lawful basis applies to that data, and objection applies where we rely on legitimate interests. If a right doesn't apply the way you expected, we'll explain why.

To ask about any of this, use Contact(choose "Privacy") or your profile. We respond within one month of a valid request, and will tell you if we need to extend that for a complex or repeated request, as the law allows.

Complaints

If you're unhappy with how we've handled your data or a request, we'd like the chance to put it right first. Tell us through Contact. You can also complain directly to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk/make-a-complaint. We'll acknowledge a complaint about how we've handled your data within 30 days and respond to it without undue delay.

Cookies and storage

Nexus doesn't run analytics, tracking or advertising technology. What is set is:

  • Authentication cookies (set by our sign-in library): keep you signed in. Strictly necessary; set on sign-in, cleared on sign-out.
  • A theme-preference cookie (sco-theme-preference): only ever set to remember an explicit choice of Lightdisplay, kept for up to a year. Dark is the platform's default, so choosing Dark doesn't store anything: it deletes this cookie (and, if you're signed in, clears the matching preference on your account) rather than writing "dark" as a value. Choosing Dark again is the objection mechanism. It removes the preference entirely, and clearing your browser's cookies for this site does the same. No consent banner is shown for it, since it exists only to remember a display choice you asked for.
  • A reading-focus-mode preference (sco-reader-focus-mode): remembers a lesson-reader display toggle, stored locally in your browser only, never sent to us. Clearing your browser's site data removes it.

Certificates and public verification

Anyone who has both a certificate's number and its separate verification code can check it. This shows the holder's name, course, dates and status only, the same information printed on the certificate itself. Each verification is logged for integrity, and checking is rate-limited to prevent automated enumeration.

Changes

We date this notice whenever it changes, and announce material changes in-app rather than silently. This version is dated 13 September 2026.

RLC SCO Nexus is operated by its owner-administrator, an individual, as an independent platform. It is not part of, endorsed by, or operated by the Ministry of Defence, the British Army or the Royal Logistic Corps.

PrivacySecurityAccessibilityLegalContact