This Privacy Policy sets out the data processing practices of Simply MSK LTD. Please note that all data thus captured will be used and held in accordance with the requirements of the General Data Protection Regulation (GDPR) 2018.

Last updated: 6 October 2026
1. Who we are and how to contact us
Simply MSK LTD (Simply MSK, we, us or our) provides multidisciplinary musculoskeletal education, including Clinical Reasoning Without Silos (CRWS), CRWS Professional, Beyond Silos and other online and live educational activities.
We are the controller of the personal information we use to manage our website, learner relationships, education services and marketing. This means we decide why and how that information is used.
For privacy enquiries, requests to exercise your rights, publication-permission changes or data protection complaints, contact learnmore@simplymsk.com. Please tell us which course, account or communication your enquiry relates to. Do not include patient-identifying information.
This policy explains our use of personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable privacy and electronic communications legislation, as amended. It covers website visitors, prospective learners, learners, event attendees and people contacting us. Separate information may be provided for particular activities, such as event photography or a new service.
2. Information we collect
Depending on your interaction with us, we collect:
Identity and contact details, such as your name, email address and any billing address, telephone number or professional details you provide.
Account and learning information, including registration, enrolment, access, lesson-completion records, quiz responses, submitted reflections, submission dates and certificate information.
Order and transaction information, including purchases, invoices, payment status, refunds, payment-provider references and any relevant affiliate referral.
Apply & Earn Challenge information, including the purchase-based deadline, the four official reflection submissions, eligibility, credit earned, redemption and any restored credit.
Feedback and correspondence, including survey answers, support enquiries, complaints and our responses.
Preferences and permissions, including marketing choices, publication choices, your chosen publication name and optional professional role, the wording presented, submission dates and changes or withdrawal.
Technical information, such as IP address, browser and device information, access logs and information about website use, subject to the cookie and tracking choices explained below.
Event information, such as attendance and practical arrangements. If you request accessibility support, we seek only the information needed to arrange it.
You do not have to provide optional profile details, positive feedback or publication permission to receive the services you have purchased.
3. Where information comes from
Most information comes directly from you when you register, purchase, complete a course or form, contact us or attend an event. Our learning and payment providers also generate records of activity, submissions and transactions.
If an employer or other organisation books a place for you, we may receive your name, contact details and booking information from it. An affiliate referral may provide a referral identifier associated with your purchase. Social media platforms provide the messages and profile information you choose to share when you contact us there.
Where information comes from someone else, we explain the source and relevant use when required. We do not treat a third party providing your details as permission to send you promotional emails.
4. Why we use information and our lawful bases
We use information for the following purposes:
Providing accounts, course access, purchased education, certificates and agreed learner benefits: we rely on performance of our contract with you, or steps you ask us to take before entering a contract. We use the information necessary to deliver the requested service.
Managing the 90-Day Apply & Earn Challenge and £60 Beyond Silos credit: we rely on performance of our contract to record eligibility and honour the benefit, and legitimate interests to maintain accurate records and investigate errors or misuse.
Responding to enquiries and providing support: we rely on contract where the enquiry concerns delivering your service, and legitimate interests in answering other enquiries and resolving problems.
Evaluating course feedback and improving education: we rely on legitimate interests in understanding learners' experiences, evaluating educational quality and improving our services. We use aggregated or anonymised information where individual identification is unnecessary.
Security, fraud prevention and essential administration: we rely on legitimate interests in protecting learners, accounts and our business, and legal obligations where applicable.
Accounting, tax and legally required records: we rely on legal obligations. Managing complaints, disputes and legal claims also involves legitimate interests in investigating matters and protecting legal rights.
Promotional emails: we rely on consent, or legitimate interests where the customer soft opt-in lawfully applies. Section 6 explains the separate electronic-marketing requirements.
Publishing selected feedback or reflection excerpts: we rely on your separate, optional consent, within the submissions, channels and attribution choices you authorise. This is explained in section 8.
Optional cookies and tracking: we rely on consent where required by electronic communications law and, where personal information is involved, the appropriate data protection basis explained with the technology. Our approach is described in section 10.
Consent and withdrawal records: we rely on legal obligations to demonstrate compliance where applicable, and legitimate interests in evidencing permissions and respecting your choices.
Where we rely on legitimate interests, we assess the purpose, necessity and impact on your privacy. Those interests do not override your rights automatically. You can object as explained in section 15.
5. Course administration, reflections and feedback
We use learning and submission records to administer CRWS, CRWS Professional and other education. Official forms linked from the course may open on a separate page. Their responses remain part of the course process and are linked to the appropriate learner record.
For the 90-Day Apply & Earn Challenge, the deadline starts on the date of purchase. We use the three case reflections and final implementation reflection submitted through the official Module 10 forms to record completion and eligibility for the £60 Beyond Silos credit. Marking a lesson complete is a separate platform action and does not, by itself, prove that a reflection was submitted.
The £60 credit does not expire. We retain a minimal record needed to identify the entitled learner and honour the credit until it is redeemed or you ask us to relinquish it. This does not require us to retain every reflection or survey answer indefinitely.
The Module 11.1 feedback form forms part of the final CRWS Professional completion process. We use responses to evaluate the course and inform future education. Honest criticism is welcome. The content of your feedback and your decision about publication permission do not affect certificate eligibility or earned credit.
We record form submission separately from lesson completion. The course platform's Certificate of Completion becomes available when its required lessons have been marked complete. Challenge evidence, credit eligibility, feedback submission and certificate generation are distinct records.
Course forms are associated with your learner record and should not be treated as anonymous surveys. Where possible, use the email address associated with your purchase so that submissions and permissions are matched correctly.
6. Service messages and promotional emails
We send information necessary to deliver or administer your service, such as access details, purchase confirmations, event arrangements, relevant challenge reminders and credit or certificate notices. These are distinct from promotional messages.
Promotional emails may include education updates, offers, resources and invitations to future courses. We send them where you have given appropriate consent or where all requirements of the customer soft opt-in are met: we obtained your details during a sale or negotiations for a sale, the messages concern our own similar products or services, and you were offered an easy opt-out when details were collected and in each message.
Registering for free CRWS, completing a survey or permitting publication does not automatically subscribe you to promotional emails. We make any promotional-email choice clear when collecting it. We do not use legitimate interests to bypass electronic-marketing consent requirements.
You can unsubscribe using the link in our promotional emails or by contacting learnmore@simplymsk.com. We stop promotional messages covered by your request and retain a limited suppression record to prevent accidental resubscription. Unsubscribing does not remove purchased access, certificate eligibility or earned credit. Necessary service messages may continue.
7. Tags, segmentation and automation
Our platform uses tags and other account fields to record course progress, purchases, official submissions, feedback completion, credit and communication or publication preferences. Tags help us send relevant messages and avoid repeatedly promoting a product you have already purchased.
This is limited segmentation based on your interactions with Simply MSK. A tag is an administrative record, rather than a clinical assessment of your competence. Permission tags do not replace the underlying consent evidence.
Some actions are automated, including access, reminders, completion records and credit-related updates. If an error affects access, a certificate or a credit record, contact us for human review and correction. These processes are not used to decide your professional registration, employment suitability or clinical fitness to practise.
If we introduce automated decision-making that has a legal or similarly significant effect, we will explain it and provide the applicable safeguards before using it.
8. Optional publication of reflections and feedback
Submitting a reflection or completing the Module 11.1 feedback form does not automatically authorise publication. The form offers separate, optional publication choices, presented apart from required feedback and course administration.
The consent statement identifies the material covered, including whether it covers the three Module 10 case reflections, the final implementation reflection and comments in the feedback form. We do not assume that permission for one submission covers other material.
You can choose whether to permit selected excerpts on our website, organic social media and promotional emails, and separately whether to permit their use in paid advertising. Your actual selections determine the authorised channels. Permission to use a comment in promotional emails is not permission to send promotional emails to you.
The default is publication without your name or professional role. You can separately choose to associate an excerpt with the exact publication name and optional professional role you provide. Named attribution requires publication permission and an affirmative attribution choice. Your account or certificate name is not automatically your publication name. Workplace details and photographs require separate permission.
Within the scope you authorise, we may select and shorten excerpts and make minor spelling or grammar corrections while preserving their meaning and context. We may use them without asking you to approve each individual publication. A materially different purpose, channel or attribution requires further permission.
Unnamed publication means we do not display your name or role. It does not make the original submission anonymous within our records. We also check excerpts for details that could identify patients, colleagues or others; simply removing a name may be insufficient.
Online publication can be seen, copied or shared by a worldwide audience. Social media platforms process information under their own privacy arrangements. We cannot guarantee that third parties will not retain or share published material.
You can withdraw publication permission or change attribution choices by contacting learnmore@simplymsk.com, or by using a publication-preference form where one is provided. Tell us the account email and the permission you want changed; you do not need to give a reason. We stop future uses covered by withdrawal and remove affected material from channels we control without undue delay. Distributed emails, printed materials and independent third-party copies may remain in circulation. Withdrawal does not make earlier lawful processing unlawful.
Giving, refusing or withdrawing publication permission does not affect course access, completion, certificate eligibility or earned credit. We retain proportionate consent and withdrawal records to demonstrate and respect your choices. Permission to publish an excerpt does not authorise uploading your contact details to an advertising audience list.
9. Patient confidentiality and sensitive information
Our learner forms are educational submissions, not patient records. Do not include patient names, initials, dates of birth, addresses, contact details, NHS numbers, identifiable images, unredacted documents or combinations of details that could identify someone. Avoid identifying colleagues or workplaces unnecessarily. Describe cases using genuinely anonymised information.
If you discover identifying information in a submission, contact us promptly without repeating the sensitive material in your message. We restrict access and arrange appropriate redaction or deletion. Publication permission from a clinician does not authorise publication of a patient's information.
If you request accessibility support, we focus on the adjustment needed rather than asking for a diagnosis. Where processing your health or other special-category information is necessary, we explain the purpose and use an appropriate lawful basis and additional condition. For voluntary health disclosures used to arrange support, we seek explicit consent before using that information. If you withdraw it, we discuss what support can still be provided without those details.
10. Cookies and similar technologies
Our website and course platform use cookies and similar technologies, such as local storage, to support functions including login, security, checkout and remembering essential choices. Technologies strictly necessary to provide a service you request may operate without optional-cookie consent.
Where we use optional analytics, advertising technologies or other tracking requiring consent, we ask for that consent before they operate. Rejecting optional tracking does not remove access to purchased learning, although an optional embedded feature may depend on a separate choice.
Information accompanying the relevant cookie and preference controls explains the technologies in use, their providers, purposes and durations. You can change choices through the controls made available on the relevant page. You can also delete or block cookies through your browser, although blocking necessary cookies can interfere with login or checkout.
Where email-opening pixels or similar device-tracking technologies are used, we obtain any consent required before using them. Some communications generate delivery or link-interaction records. We use such information to operate communications and, where permitted, understand engagement. We do not treat consent to receive promotional emails as blanket consent to unrelated advertising tracking.
11. Who we share information with
Access is limited to people and organisations with a relevant purpose. These include:
Authorised Simply MSK directors, staff, tutors and contractors who need information for course delivery, support, administration or authorised publication.
Systeme.io, operated by ITACWT Limited, for website and funnel pages, contact records, forms, course delivery, email and automation services used in our build.
Stripe for payments, refunds and associated payment administration. Stripe also processes information for its own purposes, including fraud prevention and legal compliance, under its privacy policy.
Other service providers used for business email, secure storage, technical support or form delivery where applicable. We disclose relevant additional providers when a collection route introduces a materially different use or recipient.
Venues and delivery partners, where necessary for attendance or practical arrangements. We share accessibility information only where needed and on the applicable basis.
Accountants, professional advisers, insurers, regulators, courts and authorities where necessary for their services, legal compliance or legal claims.
The public and relevant publishing platforms, but only for material you have authorised us to publish under section 8.
Providers processing information on our behalf are subject to appropriate contractual requirements. Independent controllers, including payment providers for some activities and social media platforms, have their own responsibilities and privacy policies.
An affiliate referral does not give an affiliate access to your reflections, feedback or full learner record. We limit any referral or commission information shared to what is necessary to administer the arrangement.
We do not sell learner contact lists or provide sponsors with them for their own marketing without separate, specific permission. A future business transfer may require limited disclosure to prospective purchasers or advisers under appropriate confidentiality safeguards; affected individuals will be informed where required.
Provider information is available at https://systeme.io/privacy-policy and https://stripe.com/privacy.
12. Payments
Payment details are handled through the payment provider's checkout facilities. We receive the transaction information needed to confirm payment, issue invoices, process refunds and manage orders. We do not need your complete card details or security code for these purposes; do not email them to us.
A refund does not immediately erase purchase records. We retain the information needed for accounting, refund evidence and any relevant dispute, subject to section 14.
13. International processing
Some providers are based outside the UK or use international infrastructure. Systeme.io states that its servers are hosted in Ireland. Stripe and other providers may process information in multiple countries. We do not assume that every provider stores or accesses all information solely in the UK.
For transfers subject to UK transfer restrictions, we use an applicable UK adequacy arrangement or appropriate safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, with the assessments required by law. Ask us for information about relevant destinations and safeguards, or an appropriate copy of those safeguards.
Material you authorise us to publish online is accessible internationally. This public availability is explained separately from transfers to service providers.
14. How long we keep information
We retain information for its stated purpose, rather than keeping all learner information indefinitely. Our retention approach is:
Account and access information: while needed to provide the agreed access and support. After that, we remove unnecessary account details and retain only relevant completion, transaction or dispute records under the criteria below.
Full reflections and identifiable feedback: normally up to two years after course completion or, if you do not complete it, your last course activity. We then delete or genuinely anonymise them unless a current publication permission, unresolved issue or legal requirement justifies retaining relevant material. We need not retain full reflections merely because credit remains unredeemed.
Certificate and completion records: the minimal record needed to confirm course completion and respond to certificate enquiries. We review the need for continued retention and explain the implications if you ask us to delete the identifying record.
Unredeemed £60 credit: a minimal entitlement record until redemption or your request to relinquish it, because the credit has no expiry. After redemption, relevant transaction records follow our accounting retention rules.
Accounting, purchase and refund records: normally six years from the end of the company financial year they relate to, or longer where law requires it.
Published excerpts and attribution details: while we continue to use them within a valid permission. We review their relevance and permissions, remove outdated material and act on withdrawals.
Consent evidence and withdrawal records: while the relevant permission is in use, then normally for up to six years after its last use or withdrawal, where necessary to demonstrate compliance or address claims. We retain the minimum evidence rather than unnecessary underlying submissions.
Marketing contacts: while we have a valid basis and the communications remain relevant. We review inactive records and remove those no longer needed. Minimal suppression records are kept for as long as needed to respect an opt-out.
Routine enquiries and support correspondence: normally up to two years after resolution. Information relevant to a dispute, complaint or legal claim may be retained for the applicable investigation or limitation period.
Technical and tracking records: for the period needed for their security or operational purpose, or the duration explained for the particular tracking technology.
We may retain particular records longer for an outstanding complaint, investigation, legal obligation or claim. This does not justify retaining unrelated information. Deletion from live systems may be followed by removal from protected backups through their normal replacement cycle; retained backup copies are not used to restart marketing or withdrawn publication.
Genuinely anonymised statistics, which no longer identify you or others, may be retained for ongoing educational evaluation.
15. Your rights
Depending on the circumstances and applicable exemptions, you can ask us to:
Explain how we use your information and provide access to it.
Correct inaccurate information or complete incomplete information.
Erase information where there is no continuing lawful reason to retain it.
Restrict particular processing.
Provide eligible information in a portable format.
Stop processing based on legitimate interests, taking account of your situation.
Stop direct marketing and related profiling. This right is absolute.
Apply the safeguards available for significant automated decisions where relevant.
You can withdraw consent at any time. This affects future consent-based processing and does not invalidate processing lawfully carried out before withdrawal.
Contact learnmore@simplymsk.com to exercise a right. We normally respond without undue delay and within one calendar month, subject to the lawful rules about identity verification, clarification and extensions. Where an extension is permitted because a request is complex or there are multiple requests, we explain it within the initial response period.
We do not routinely require a passport, driving licence or utility bill. If there are reasonable doubts about identity or authority, we request only proportionate information needed to verify the request. Requests are normally free; any permitted charge or refusal will be explained.
Deleting information necessary for an account, certificate verification or unused credit may affect our ability to provide that particular function. We explain the consequences and consider retaining a smaller necessary record where lawful. Refusing optional marketing or publication permission does not have those consequences.
16. Security
We use appropriate technical and organisational measures, including restricted access and suitable provider arrangements, to protect personal information. Access is limited according to responsibilities, and sensitive information receives additional protection. We review safeguards as our services develop.
No online service can guarantee absolute security. If a personal data breach occurs, we assess it and notify the regulator and affected individuals where required by law. Tell us promptly if you suspect an account or submission has been compromised.
17. Required and optional information
Some information is necessary to create an account, deliver a booking, match submissions, issue a certificate or honour a credit. If you do not provide the necessary details, we may be unable to provide the relevant service. Information needed for legally required financial records must also be retained.
Optional professional details, publication names and publication or promotional-email permissions are separate. You can decline them. Feedback completion is part of the course process, but you do not have to provide a positive evaluation or agree to publication.
18. External sites and social media
Independent websites and social media platforms have their own privacy notices. If you contact us through a social platform, avoid sharing patient information or sensitive account details there. We may ask you to continue through our support email.
Our responsibility for information processed to deliver our services continues when we use a service provider. Linking to a provider's policy does not replace our obligations as controller.
19. Complaints
If you are concerned about our handling of personal information, email learnmore@simplymsk.com with the subject “Data protection complaint”. You do not have to use those exact words for us to recognise a complaint. Tell us what happened and the outcome you are seeking. We can help you make a complaint if you need an accessible alternative.
We acknowledge data protection complaints within 30 days, investigate appropriately, keep you informed and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator. Information is available at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113.
20. Changes to this policy
We review this policy as our services, providers and legal requirements change. The date above identifies the latest revision. We bring material changes to your attention where required and provide relevant information before introducing a new purpose.
Using our website or continuing to use a course does not, by itself, constitute consent to new marketing, publication or tracking. Where a new use requires consent, we ask for it separately.
Privacy Policy | 6 October 2026
All Rights Reserved.