Privacy Policy
Privacy Policy
Last updated: September 2026
1. About this Privacy Policy
Thinkco Pty Ltd is an Australian company providing online continuing professional development (CPD) and educational services to podiatrists in Australia and other countries.
Our international services include Podiatry CPD Online, which is used by podiatrists in the United Kingdom and other locations.
This Privacy Policy explains how we collect, use, store and share personal information when you visit our websites, create an account, purchase or complete CPD, attend a webinar, download a resource, join our mailing list or otherwise interact with us.
Where UK data protection law applies to you, this Policy also explains your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and related UK privacy laws.
2. Who We Are
The organisation responsible for your personal information is:
Thinkco Pty Ltd
PO Box 1829
Bowral NSW 2576
Australia
For privacy enquiries, contact:
Thinkco Pty Ltd is the data controller for the personal information covered by this Policy, except where another organisation acts as a separate controller.
3. Who This Policy Applies To
This Policy applies to people who interact with our websites, courses and services, including:
- members and customers;
- course and webinar participants;
- people who create an account;
- people who register for free resources or events;
- email subscribers;
- prospective customers;
- presenters and contributors where relevant; and
- people who contact us or interact with our online services.
Our professional CPD services are intended for adults and are not directed at children.
4. Personal Information We Collect
The information we collect depends on how you interact with us.
It may include:
Identity and contact information
- name;
- email address;
- country or location;
- profession or professional details where provided; and
- other contact information you choose to provide.
Account information
- login and account details;
- membership status;
- subscriptions;
- courses purchased or available to you; and
- account preferences.
Transaction information
- products or memberships purchased;
- purchase dates;
- amounts paid;
- payment status;
- invoices and transaction records; and
- information needed to deal with refunds or payment queries.
Payment card information is generally processed by our payment provider rather than stored directly by us.
Learning and CPD information
- courses and activities you enrol in;
- learner progress;
- completion dates;
- assessment responses and results;
- CPD hours where applicable;
- certificates issued; and
- webinar or activity participation.
Communications
- emails and messages you send us;
- customer support requests;
- survey responses;
- feedback; and
- other communications with us.
Marketing information
- whether you have subscribed to marketing;
- marketing preferences;
- emails sent, opened or interacted with, where this information is available;
- unsubscribe requests; and
- information about your interaction with our advertising.
Technical and website information
When you use our websites, we and our service providers may collect information such as:
- IP address;
- browser and device information;
- pages viewed;
- referring pages;
- interactions with our website;
- approximate location derived from technical information; and
- cookie, pixel and similar technology information.
Non-essential tracking technologies are subject to the consent requirements that apply in your location.
5. Where We Get Personal Information
We collect most personal information directly from you when you:
- purchase a product;
- create an account;
- enrol in or complete CPD;
- register for a webinar;
- download a resource;
- complete a form;
- subscribe to emails;
- respond to a survey; or
- contact us.
We may also receive information from service providers involved in delivering our services, such as Kajabi, Stripe and Zoom.
We may receive information about interactions with our advertising through services such as Google and Meta, subject to applicable privacy and cookie requirements.
6. How and Why We Use Your Information
We use personal information where we have a valid reason to do so.
This may include using information to:
- create and manage your account;
- process purchases and subscriptions;
- provide courses, memberships and resources;
- administer live and recorded webinars;
- record learner progress and course completion;
- administer assessments;
- issue CPD certificates;
- provide customer support;
- communicate important information about products you have purchased;
- maintain financial, tax and business records;
- prevent fraud and protect our systems;
- manage and improve our services;
- understand how our websites and services are used;
- manage our email communications;
- advertise and promote our products where permitted;
- measure advertising performance;
- manage our business;
- establish, exercise or defend legal claims; and
- comply with our legal obligations.
7. Our Lawful Bases Under UK Data Protection Law
Where UK GDPR applies, we rely on one or more lawful bases depending on what we are doing with your information.
Contract
We may process your information because it is necessary to enter into or perform our contract with you.
This includes processing needed to:
- create and administer your account;
- process your order;
- provide a membership or course;
- record your progress;
- administer assessments;
- provide webinars or resources; and
- issue certificates.
Legal obligation
We may process information where necessary to meet legal requirements, including financial, taxation, accounting and other applicable legal obligations.
Legitimate interests
We may process information where this is necessary for our legitimate business interests and those interests are not overridden by your rights and interests.
Depending on the circumstances, these interests may include:
- operating and improving our services;
- providing customer support;
- protecting our systems and preventing fraud;
- maintaining appropriate business records;
- understanding how customers use our services;
- managing our relationship with customers; and
- promoting relevant products to existing customers where permitted by law.
We consider the nature of the information, your reasonable expectations and the possible effect on you before relying on legitimate interests.
Consent
We rely on consent where the law requires it.
This may include certain:
- marketing communications;
- advertising and tracking technologies; and
- non-essential cookies or similar technologies.
Where processing relies on consent, you may withdraw that consent at any time.
Withdrawing consent does not affect processing that was lawful before you withdrew it.
8. CPD, Course and Assessment Records
Providing professional education requires us to keep information about your learning activity.
This may include:
- courses undertaken;
- progress through course content;
- assessment results;
- completion dates;
- CPD hours;
- webinar participation; and
- certificates.
We use this information to provide your learning service, make completion records available to you and administer our CPD products.
You remain responsible for determining whether a particular activity meets the requirements of your regulator, professional body, employer or jurisdiction unless we expressly state otherwise.
9. Payments
We use third-party payment services, including Stripe, to process payments.
Payment providers may collect and process information needed to complete your transaction and prevent fraud.
Payment providers may act as processors or independent controllers for different parts of their services and maintain their own privacy information.
We do not normally receive or store your full payment card details.
10. Email and Direct Marketing
We use Kajabi to manage email communications and marketing.
We may send you:
- information about products or services you have requested;
- service and account communications;
- CPD and educational updates;
- information about new courses, webinars or events; and
- promotional offers.
Where UK electronic marketing rules apply, we will only send marketing where we have the required permission or another lawful basis permitted by those rules.
For existing customers, this may include the UK “soft opt-in” where its legal requirements are met.
You can unsubscribe from marketing emails at any time by using the unsubscribe option included in our marketing emails.
You may still receive essential service messages about an active account, purchase, membership, event or transaction after opting out of marketing.
We may retain limited information on a suppression list after you unsubscribe so that we can respect your request and avoid sending further marketing.
11. Cookies, Advertising and Similar Technologies
Our websites use cookies and similar technologies.
Some are necessary for the website, account functions, security or services you request to work.
We may also use non-essential technologies for advertising, measurement and marketing.
These may include technologies associated with:
- Kajabi;
- Google Ads; and
- Meta, including the Meta Pixel.
These technologies may collect information about visits to and interactions with our website and may be used to measure advertising performance or show more relevant advertising.
Where UK law requires consent before non-essential technologies are stored on or access information from your device, we will seek that consent through our cookie controls.
You can change your available cookie choices through our website’s cookie controls.
Further information should be available in our Cookie Policy.
12. Who We Share Information With
We do not sell your personal information.
We may disclose personal information where reasonably necessary to organisations that help us operate our business and provide our services.
These may include:
- Kajabi, for website, course, account and email services;
- Stripe, for payment processing;
- Zoom, for online webinars and meetings;
- Google, for advertising and related services;
- Meta, for advertising and measurement;
- professional advisers such as accountants, lawyers and consultants;
- IT, security and technical service providers; and
- government, regulatory, law enforcement or other authorities where disclosure is required or permitted by law.
We only share information that is reasonably necessary for the relevant purpose.
Some providers may process information on our behalf. Others may act as independent data controllers for some of their activities.
13. International Processing and Transfers
Thinkco Pty Ltd is based in Australia and provides services internationally.
If you are located outside Australia, your personal information may therefore be transferred to or accessed from Australia.
Our technology providers may also process information in other countries.
Where UK GDPR applies and a transfer of personal information outside the UK is subject to UK international transfer rules, we take steps to ensure that an appropriate legal mechanism or safeguard applies.
Depending on the destination and service provider, this may include:
- UK adequacy regulations;
- approved contractual safeguards such as the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses; or
- another transfer mechanism permitted by UK data protection law.
Where required, we also consider whether additional measures are needed for the particular transfer.
14. How Long We Keep Personal Information
We keep personal information only for as long as reasonably needed for the purpose for which it was collected, our legitimate business needs and applicable legal requirements.
Different information may therefore be kept for different periods.
When deciding how long to retain information, we consider:
- the nature and purpose of the information;
- how long your account or membership remains active;
- the value of retaining CPD completion and certificate records for customers;
- financial, accounting and taxation requirements;
- legal limitation periods;
- security and fraud prevention needs; and
- whether you have asked us to stop processing information.
We may retain limited information after a marketing opt-out to maintain a suppression record and ensure that your preference is respected.
When personal information is no longer required, we take reasonable steps to delete, anonymise or securely dispose of it.
15. Security
We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.
We also use established third-party technology providers to deliver parts of our services.
No online service or method of electronic storage can guarantee complete security. We therefore cannot promise that a security incident will never occur.
16. Your Rights in the United Kingdom
If UK GDPR applies to the processing of your personal information, you may have rights including the right to:
- ask for access to your personal information;
- ask us to correct inaccurate information;
- ask us to erase personal information in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to certain processing, including direct marketing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent; and
- raise concerns about how your personal information is handled.
These rights do not apply in every circumstance and may be subject to legal exceptions.
To exercise a privacy right, contact:
We may need to confirm your identity before dealing with a request.
17. Automated Decision-Making and Profiling
We may use information about website or marketing interactions to help measure advertising and create or reach advertising audiences.
We do not currently use solely automated decision-making that produces legal or similarly significant effects on customers.
If this changes, we will update this Privacy Policy and provide any information required by law.
18. Children’s Privacy
Our CPD services are intended for health professionals and other adult users.
They are not directed at children.
If we become aware that personal information relating to a child has been collected in circumstances where it should not have been, we will take appropriate steps to address this.
19. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms or services.
Those organisations have their own privacy practices and policies. We are not responsible for the privacy practices of third-party websites that we do not control.
20. Business and Legal Requirements
We may disclose or process personal information where reasonably necessary to:
- comply with applicable law;
- respond to lawful requests from authorities;
- protect our legal rights;
- investigate fraud, security incidents or misuse;
- establish, exercise or defend legal claims; or
- manage a proposed sale, restructure or transfer of all or part of our business.
Where another organisation acquires or takes over part of our business, personal information associated with that part of the business may form part of the transaction, subject to applicable privacy law.
21. Changes to This Privacy Policy
We may update this Privacy Policy when our services, technology or legal obligations change.
The current version will be published on our website with its most recent update date.
Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected users where required.
22. Contact Us
For questions about this Privacy Policy or the way we handle personal information, contact:
Thinkco Pty Ltd
PO Box 1829
Bowral NSW 2576
Australia
Email: [email protected]
23. Additional Information for People in the United Kingdom
Thinkco Pty Ltd is established in Australia but offers its Podiatry CPD Online services to customers in the United Kingdom.
Where UK GDPR applies to our processing of your personal information, the rights and protections described in the UK sections of this Policy apply.
If you have a concern, we encourage you to contact us first so that we can try to resolve it.
You also have the right to make a complaint to the UK Information Commissioner’s Office (ICO), the UK’s independent data protection regulator.
Information about making a complaint and exercising your rights is available from the ICO.
24. Australian Privacy
As an Australian company, Thinkco Pty Ltd may also have obligations under applicable Australian privacy law.
Nothing in this Policy limits any privacy rights available to you under legislation that applies to your personal information.
Last updated: September 2026