Last updated 21 September 2026
This is the privacy policy for Afanor, provided by Hawdren Ltd. It explains the personal information we collect, the purpose of each use, and how you can ask us to delete it.
Hawdren Ltd is registered in England and Wales. Company number 17392723. Registered office: CIWB Business Centre, Llewellyns Quay, Port Talbot, SA13 1RF.
It covers three places:
- the Afanor website at afanor.com, including contact, sign-up and verification pages
- the Afanor cloud application, including the staff workspace, learner portal, quizzes and check-in
- social media connections an organisation sets up inside Afanor: Facebook, Instagram, Threads, LinkedIn and X
Questions and deletion requests go to [email protected].
Information we collect
We collect information you give us, information the cloud application stores for an organisation, information a social network sends after someone connects an account, and a limited amount of technical information collected automatically.
Website
If you contact us or register interest, we collect what you type into the form. That can include:
- your name, work email address, organisation and message
- when you open a workspace: organisation name, administrator email, the password you choose, billing choice, and the centre address
If you check a certificate or an ID card, we collect:
- the certificate reference, awarding body code, and date of birth if you provide one
- the verification link you open for an ID card
We use those details only to answer the check. We do not add you to a marketing list because you verified a certificate or card.
Automatically, the website receives:
- browser and device type, pages viewed, and the address of the site that referred you
- an IP address, which Google Analytics receives in anonymised form so we can see how the website is used
Cloud application
When an organisation uses Afanor, we process two kinds of information.
Account information lets us run the subscription. It includes the names, work email addresses, usernames and roles of people the organisation invites, sign-in records, the organisation name and address, billing status, and messages sent to our support team. Passwords are stored as a secure hash. We do not keep the password you type.
Organisation records are the information that organisation chooses to keep about the people it trains and works with. That can include names and contact details, course bookings, attendance, assessment, qualifications, certificates, ID cards, documents, and the email or SMS the organisation asks Afanor to send, including whether the message was delivered. Course payments are taken through Stripe. Card numbers are collected by Stripe, not stored by Afanor.
The organisation decides what to record and is responsible for having a reason to hold it. Afanor processes those records so the organisation can run its training work.
Social media integrations
An authorised user can connect the organisation’s own Facebook Page, Professional Instagram account, Threads profile, LinkedIn Page or X account. After they approve the permission screen, we store the account or Page name, handle and picture, the platform’s identifier, the permissions granted, an encrypted access token (and a refresh token when the platform provides one), and which Afanor user connected it. We do not receive the password for that social account.
When the organisation publishes, Afanor sends that platform the post they wrote, including any image or video they attached.
How we use information
Each kind of information is used for a specific purpose:
- Website enquiries and sign-up. To reply to you, and to create the workspace you asked for.
- Certificate and ID card checks. To tell you whether the record matches.
- Website analytics. To see which pages are useful and to keep the site working. We do not use this to build an advertising profile of you.
- Cloud accounts. To sign people in, keep each organisation’s workspace separate, bill for the subscription, and answer support requests.
- Learner, contact and course records. To provide the training, qualification, booking and reminder features the organisation has switched on.
- Email and SMS. To send the messages the organisation asks Afanor to send, and to record whether they were delivered.
- Payments. To take subscription payments and course payments through Stripe.
- Social connections. To show which account is connected, and to publish the posts the organisation creates in Afanor to that Facebook Page, Instagram account, Threads profile, LinkedIn Page or X account.
- Security. To protect accounts, detect abuse, and keep an audit of important changes.
Social account information is used only to provide that connection and publishing. We do not sell it. We do not use a connected Page or profile to advertise Afanor to its followers, and we do not use it to build profiles of people who have not signed in to Afanor.
Email from Hawdren about Afanor goes to people who asked to hear from us, such as a register-interest enquiry. You can ask us to stop by emailing [email protected].
How to ask us to delete your data
Email [email protected] and ask us to delete your data. Include the email address you used, your organisation’s name, and, for a social connection, the platform and the account or Page name. We will confirm when the deletion is done.
You can also remove information yourself:
- Disconnect Facebook, Instagram, Threads, LinkedIn or X in the Afanor workspace under Settings → Social accounts. Disconnecting deletes the stored connection, including the access token and refresh token.
- Ask an administrator of your organisation to remove your user, or email us to close the workspace.
- Delete a published post on the social network. A post that has already been published stays on Facebook, Instagram, Threads, LinkedIn or X until it is deleted there. Disconnecting Afanor does not remove it from that network.
If an organisation keeps your learner or contact record in its Afanor workspace, that organisation is responsible for the record. Ask them to delete it. If you email us instead, we will pass the request to that organisation, or delete the information where we hold it ourselves.
We may keep a limited copy where the law requires it, for example invoices, or where we need it to investigate a security incident. If we cannot delete something you asked us to remove, we will tell you what we kept and why.
Who else receives information
We share information with the services that run Afanor, and only for the purpose named here:
- DigitalOcean hosts the application, database and files in London, and hosts the mail service that delivers email.
- Stripe processes subscription payments and course payments.
- Sent (sent.dm) delivers SMS messages an organisation sends.
- Google Analytics measures use of this website.
- PostHog measures use of the cloud application. Those events are sent through t.afanor.cloud.
- Meta provides Facebook, Instagram and Threads account details when someone connects, and receives the content an organisation publishes to those platforms.
- LinkedIn and X do the same for their own platforms.
A published post is then handled by that social network under its own privacy policy. Afanor does not control how the network displays or stores it after publication.
Cookies
The website uses cookies and similar storage so pages load, and so Google Analytics can count visits. The cloud application uses cookies so you stay signed in, and PostHog so we can see how the product is used. You can block or delete cookies in your browser. Blocking essential sign-in cookies will stop the cloud application from keeping you signed in.
How long we keep information
- Website enquiries are kept while we deal with the conversation, then deleted.
- Account and billing records are kept for the life of the subscription, and for as long as the law requires us to keep financial records.
- Organisation records stay in the workspace until the organisation deletes them or the workspace is closed. Backups are then overwritten on their usual cycle.
- A social connection, including its tokens, is kept while it is connected and deleted when it is disconnected or when we action a deletion request.
Your rights
If we decide why and how your information is used — for example a website enquiry, an Afanor login, or a social account you connected — you can ask us for a copy, ask us to correct it, ask us to delete it, ask us to limit how we use it, or object to a use based on our own business reasons. Email [email protected].
If your information is in an organisation’s workspace, contact that organisation first. They decide what is recorded there.
You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
If this policy changes, we will update this page and the date at the top. The current version is always at afanor.com/privacy.