Account, Pricing & Access
Your data and GDPR rights
PathologyLabTraining is a UK service governed by the UK GDPR and the Data Protection Act 2018. As an individual user you have specific rights over the data we hold about you. This article is the practical guide; the legal text is in the Privacy Policy.
What we hold about you
- Account data: email, name and a hashed password (or a link to your Google or institutional identity if you sign in that way). Platform administrators also hold two-factor authentication settings.
- Subscription data: plan, billing history and a payment reference. We never store full card numbers; those stay with Stripe or Paystack.
- Activity data: practice test results, training and simulator attempts, AI coach sessions and their questions, CPD activities, favourite questions, portfolio drafts and study notes.
- Organisation membership: if you joined through a Trust or university, the organisation, the date you joined, your role, and whether you have chosen to share your training record with it.
- Help chat records: when you ask the help assistant a question we keep a one-way hash of the question, its length, which help articles were used to answer, whether it needed a person, and your user ID if you were signed in. We do not keep the text of the question itself.
- Consent records: your cookie choices and newsletter preferences.
- Site measurement: a Google Ads conversion tag and a ReachSurge tracker measure page views and which search engines and AI assistants bring visitors to the site. Neither receives your name, email or account details. See the Cookie Policy and use the cookie banner to change your choices.
What we do not hold
- Patient-identifiable data. Please do not paste real patient identifiers into the AI coach, practice tests, simulators, portfolio drafts or the help chat. The platform is for training and interview preparation, not clinical work.
- Card numbers. Handled by Stripe or Paystack; we only see a masked reference.
- The text of your help chat questions. Only the hash described above.
Your GDPR rights
Right of access: export your data
Open the Data Protection page, linked from the site footer. Under Export Your Data, choose JSON or CSV and click Request Data Export. The file downloads immediately and we send a confirmation email. You can request one export per 24 hours.
The export contains your profile, subscriptions and invoices, practice test results, AI coach sessions and questions, training attempts, CPD activities, organisation membership and invitations, newsletter preferences and consent records. Portfolio drafts, favourites and study notes are visible in the app but are not yet part of the export; email us if you need a copy.
Right of rectification: correct your data
Your first and last name are editable under Account Settings → Profile, and your password under Security. The email field is read-only by design; to change it, follow Account security. For anything you cannot edit yourself, email us and we will correct it within one month.
Right to erasure: delete your account
There are two paths:
- Account Settings → Security → Deactivate Account & Cancel Billing cancels any subscription and closes the account. Your data is retained under the Privacy Policy until you ask for erasure.
- Data Protection page → Delete Your Data is the full erasure. Any subscription is cancelled first, then we email you a 6-digit code valid for 30 minutes. Enter it to confirm, and your account data is permanently deleted or anonymised. Deletion requests are limited to one per 30 days and cannot be undone.
What is kept after erasure: anonymised payment records, which HMRC requires us to keep for 7 years, and the help chat hashes described above, which contain no personal data.
Right to object or restrict processing
Email us if you want to stop us using your activity data for anonymised product analytics, stop all non-essential email, or restrict processing while a dispute is resolved.
Right to data portability
The JSON export above is the portable format. CSV is available from the same page.
Retention
Taken from the Privacy Policy:
- Active accounts: data is kept while the account is active.
- Closed accounts: account data is kept for 90 days after closure, then deleted.
- Backups: deleted data is put beyond use immediately and disappears from backups in the next rotation, typically within 30 days.
- Payment records and VAT invoices: 7 years, an HMRC requirement.
- Anonymised aggregate analytics: kept indefinitely; no individual can be identified.
Sessions and devices
Log out in the user menu signs out the current browser only. There is no "sign out everywhere" button. If you think another device has access, change your password from Account Settings → Security and email us.
Patient data reminder
Do not paste real patient-identifiable information into any text field. Use anonymised or fictional scenarios. If you have pasted patient data by mistake, email us immediately and we will remove the specific record.
Regulators and contacts
- Information Commissioner's Office (ICO): the UK data protection regulator. You can complain to them at any time at ico.org.uk.
- Data protection lead: [email protected], as named in the Privacy Policy, for subject access requests and data protection questions.
- General help: [email protected]. Put "Data Protection" or "SAR" in the subject line so the request reaches the right person without delay.