Privacy Notice
TSSG Academy learning platform (learn.tssgbarbados.com)
Version 0.5 (draft) · Last updated 3 August 2026
1. Who we are (data controller)
The data controller for this platform is T.S.S.G. (Barbados) Ltd, #22 2nd Avenue, Bella Vista Terrace, Mount Wilton, St. Thomas BB22069, Barbados. For any privacy query, contact academy@tssgbarbados.com.
2. Personal data we collect
- Your identity details as they appear on your government-issued identification: title, first name, middle name(s) and surname, date of birth, place of birth, and country of citizenship.
- Your contact details: email address, mailing address, and telephone numbers, and your current employer where you provide it.
- Identity verification: the type of identification presented (national ID card, passport or driver’s licence) and only a one-way SHA-256 hash of the identification number plus its last four digits. Your full identification number is never stored anywhere in plain text.
- Your photograph. Applicants provide a photograph which our admissions staff compare, by eye, against the identification document provided, and which appears on your student ID card. We do not use facial recognition or any other automated technique on your photograph. Under the Act, “biometric data” (a category of sensitive personal data) means data resulting from specific technical processing that allows unique identification of a person (section 2); because your photograph is only ever viewed by a person and never processed that way, we handle it as ordinary personal data — but we still protect it strictly: it is stored securely, never published, and only accessible to authorised admissions staff.
- Your application materials: qualifications you cite, your CV, and supporting documents you upload.
- Your learning activity: course progress, assignment and quiz submissions, grades, and certificates.
- Payment records: we do not receive or store your card details — payments are processed by Fygaro. We keep the transaction reference and amount of fees paid, and we treat financial records with the added care the Act requires (financial records are sensitive personal data under section 2).
- Where you opt in, your consent to be featured in the Academy magazine sent to prospective employers. You can withdraw this at any time, and we honour objections to marketing use of your data within 21 days (section 17).
- If you register an interest while applications are closed: your name, email
address and, if you choose to give it, your telephone number. This is the only personal data we
collect from you at that stage — you are not asked for identification, documents or payment
details, and no application or account is created. We record which of the two permissions below you
gave, the date and time you gave them, and the version of this notice in force at that moment, so
that we can evidence what you agreed to.
- Notification that applications have reopened. Required, because it is the purpose of the form; without it we would hold your details with no reason to use them.
- News and updates from the Academy. Entirely optional. You can decline this and still be told when applications reopen. We will never make it a condition of registering your interest, because a permission you must give in order to get something else is not a freely given consent.
- Technical records needed to operate the service securely, such as sign-in events and, where you give consent, the date, time and device details of that consent. For interest registrations this includes the IP address the form was submitted from, kept to detect automated abuse of a public form.
3. Lawful basis for processing
We process your personal data on the bases set out in section 6(1) of the Data Protection Act 2019: your consent (section 6(1)(a)); processing necessary for the performance of our training agreement with you, or to take steps you request before entering into it (section 6(1)(b)(i)–(ii)); and our legitimate interest in maintaining accurate training and certification records for accreditation (section 6(1)(b)(ix)–(x)), which never overrides your rights and freedoms. Where processing rests on consent, you may withdraw it at any time (section 7(3)), without affecting the lawfulness of processing that took place before withdrawal (section 7(4)).
4. How we use your data
To deliver training, mark and moderate assessments, issue certificates, keep regulatory and accreditation records, and communicate with you about your studies.
Where you have registered an interest while applications were closed, we use your details only for the permissions you actually ticked: to tell you when applications reopen, and — separately and only if you asked for it — to send you news and updates about the Academy. We do not use interest registrations for any other purpose, and we do not pass them to anyone outside the processors listed in section 7.
5. Automated assistance and human review
Some assignments receive an initial, computer-assisted assessment with the help of an artificial intelligence service (Anthropic) to speed up feedback. This is never the final word. A qualified TSSG Academy instructor always reviews the work and is responsible for your final grade.
When you apply to the Academy, our admissions staff may also use the same artificial intelligence service (Anthropic) to help them read your application documents: it compares the name and identification details you entered against the documents you uploaded, and summarises the career history in your CV, so that a human reviewer can check and correct the record more quickly. Its output is advisory only, and every admissions decision is made by a member of staff. Your photograph is never included in this processing — photographs are only ever compared by eye, as described in section 2. Because Anthropic is located outside Barbados, this processing involves an international transfer of the documents concerned; section 8 explains how we protect such transfers, and under Anthropic’s commercial terms your data is not used to train its models.
In both cases, you will not be subject to a decision that affects you based solely on automated processing (your right under section 18(1) of the Act), and you may ask us to have any computer-assisted assessment or document check reviewed or explained by a person. Email academy@tssgbarbados.com.
6. How long we keep it
Training and certification records are retained in line with Barbadian record-keeping requirements for accredited education and the needs of our accreditation bodies; where the Act asks us to state a storage period or the criteria used to determine it (section 19(2)(a)), those criteria are the requirements of our accreditation bodies and applicable law. Specific retention periods — including how long we keep the documents and photographs of applicants who are not accepted — are being finalised with counsel and will be stated here.
Interest registrations are different, because they are not training records and no accreditation requirement applies to them. We keep them for 24 months from the date you register, or until you ask us to remove them, whichever comes first. If you have not enrolled by then we delete your details rather than hold them indefinitely against a future intake.
7. Service providers who process data on our behalf
We use the following processors to run the platform. Some are located outside Barbados; see section 8 for how we protect any transfer of your data across borders.
- Cloudflare (hosting, database and content delivery).
- Google Workspace (document, calendar and spreadsheet storage).
- Anthropic (assists with initial assignment marking and with the admissions document checks described in section 5).
- FAL.ai (learning video generation).
- Resend (email delivery, including sign-in codes).
- Certifier.io (certificate issuance).
- Fygaro (payment processing).
8. International transfers of your data
Because several of the service providers above operate outside Barbados, some of your personal data is transferred to, and processed in, other countries. Where we do this, we take steps intended to ensure your data continues to enjoy a level of protection consistent with the Data Protection Act 2019, including relying on appropriate safeguards such as standard or contractual data protection clauses with our providers. The specific safeguards for each provider are being confirmed and will be stated here once finalised. You can ask us for more detail about these safeguards by emailing academy@tssgbarbados.com.
9. Your rights
Under the Data Protection Act 2019, you have the right to:
- ask for access to the personal data we hold about you;
- ask us to correct data that is inaccurate or incomplete;
- ask us to erase your data in certain circumstances;
- ask us to restrict how we process your data in certain circumstances;
- object to certain processing of your data;
- ask us to provide your data in a portable format; and
- withdraw your consent at any time, without affecting processing that took place before you withdrew it.
To exercise any of these rights, email academy@tssgbarbados.com. These rights are set out in sections 10 to 17 of the Act. We will act on your request free of charge (section 21(10)) and without undue delay — at the latest within one month of receiving it, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month and explain why (section 21(5)–(7)). Objections to direct marketing are honoured within 21 days (section 17).
10. Children and young people
The TSSG Academy platform is intended for learners aged 18 and over. Under the Data Protection Act 2019, a child is a person under the age of 18 years (section 2), and a child’s personal data may be processed only where consent is given or authorised by the child’s parent or guardian (section 8(1)). Where we enrol a learner under 18, we will require that parental or guardian consent before processing their data, make reasonable efforts to verify it as the Act requires (section 8(2)), and limit our use of that data to what is necessary to deliver and certify the training.
11. If there is a data breach
We take the security of your data seriously and use measures such as one-way hashing and encryption to protect it. If a personal data breach were to occur, the Act sets two duties, and we will meet both:
- we will notify the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless it is unlikely to result in a risk to your rights and freedoms (section 63(1)); if notification is later than 72 hours, it must be accompanied by reasons for the delay (section 63(2));
- where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay and, where feasible, not later than 72 hours after becoming aware of it (section 64(1));
- that communication will explain, in clear and plain language, what happened, the likely consequences, and the measures taken or proposed to address it (sections 63(4) and 64(2)); and
- we will keep a documented record of any breach, its effects and the remedial action taken (section 63(6)).
Individual notification is not required where the affected data had already been rendered unintelligible to unauthorised persons, for example through encryption (section 64(3)(a)), or where later measures have removed the high risk (section 64(3)(b)) — but we will still act to contain the incident and keep the record the Act requires.
12. Changes to this notice
We may update this notice from time to time. Each version carries a version number and a "last updated" date at the top of this page so you can see when it last changed. Where a change is material, we will ask you to review and accept the updated notice the next time you sign in.
13. Contact and complaints
For questions or complaints, contact the data controller at academy@tssgbarbados.com. You also have the right to lodge a complaint with the supervisory authority for Barbados, the Data Protection Commissioner — the office established under section 70 of the Act (contact details to be confirmed and added here).
Back to sign in