Privacy Policy

Last updated: March 2026 · Newbee Publication

This policy explains how MyCPD (operated by Newbee Publication) collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Irish/EU data protection law.

What Data We Collect

When you use MyCPD, we collect the following personal data:

  • Name and Email Address — provided at registration via Google, Microsoft, or email sign-in.
  • Profile Information — profession, phone number, profile picture, CPD target (optionally provided by you).
  • Login and Authentication Data — timestamps of login events, session data, OAuth tokens.
  • CPD Records — entries including titles, descriptions, activity types, hours, reflections, evidence files, and European CPD points.
  • Subscription and Billing Data — plan type, subscription status, renewal dates. Payment details are processed by Stripe and never stored on our servers.
  • Usage and Interaction Data — pages visited, actions taken (used for product improvement only).
Purpose of Data Collection

We process your personal data for the following lawful purposes under GDPR:

  • Contract performance — to provide the MyCPD service you signed up for.
  • Legitimate interest — to improve the platform, monitor system health, and prevent abuse.
  • Consent — for marketing and optional communications (you may withdraw at any time).
  • Legal obligation — to comply with applicable law and respond to regulatory requests.

We do not sell your data to third parties. We do not use your data for advertising profiling.

Google OAuth Data Usage

When you sign in with Google, we access: your email address, name, and profile picture. We use this solely to create and manage your account.

MyCPD's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke access via Google Account Permissions.

Data Storage and Security

Location: Data is hosted on secure cloud infrastructure. Where data is processed outside the EU/EEA, appropriate safeguards (Standard Contractual Clauses) are in place in accordance with GDPR Article 46.

Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest.

Access Control: Row-Level Security (RLS) ensures no user can access another user's records. It is technically impossible for one user to view another's CPD entries or personal information.

Backups: Automated daily backups protect against data loss.

Payment Security: Payments are processed by Stripe (PCI-DSS compliant). We never store card details.

Data Retention Policy

Active accounts: Data is retained for as long as your account is active.

Expired subscriptions: Data is held for a 6-month grace period to allow re-subscription and data recovery.

After grace period: All personal data and CPD records are permanently and irreversibly deleted. You will receive email reminders before deletion.

Account deletion: When you delete your account, all associated data is immediately scheduled for permanent removal. A deletion log is kept for regulatory compliance (containing only your email and deletion timestamp — no CPD data).

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of Access — request a copy of all personal data we hold about you.
  • Right to Rectification — correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten") — request deletion of your data.
  • Right to Data Portability — receive your data in a machine-readable format (CSV/PDF).
  • Right to Restrict Processing — limit how we use your data.
  • Right to Object — object to processing based on legitimate interests.
  • Right to Withdraw Consent — withdraw marketing consent at any time via Profile settings.

You can exercise these rights via your Profile page (Download My Data / Delete Account) or by contacting us directly.

You also have the right to lodge a complaint with the Data Protection Commission (Ireland).

Cookie Policy

We use a layered cookie consent approach. Cookies are grouped into three categories:

  • Strictly Necessary — Always active. These cookies are essential for the platform to function: keeping you logged in, securing your session, and storing your consent preferences. No consent is required for these.
  • Analytics — Only active with your consent. Used to understand how users interact with MyCPD so we can improve the platform (e.g. Google Analytics via Google Tag Manager). No personal identifiers are shared with third parties for profiling purposes.
  • Marketing & Advertising — Only active with your consent. Used to measure ad campaign performance and show relevant content via Google Ads (via GTM). Currently not active — may be used in future. You will be asked for consent before any advertising cookies are enabled.

You can change your cookie preferences at any time by clearing your browser's local storage or contacting us. We do not sell cookie data to third parties.

Contact & Data Requests

For any privacy questions, data access or erasure requests, or to exercise your GDPR rights, contact our Data Controller:

Email: info@newbeepublication.com

Company: Newbee Publication

Response time: Within 30 days as required by GDPR.

🔒 Your data is securely stored and processed in accordance with GDPR. Users may request access, correction, or deletion of their data at any time.

We Value Your Privacy

We use strictly necessary cookies to keep the platform running. With your consent, we may also use analytics and marketing cookies. Privacy Policy.