Skip to main content

— Legal

Privacy Policy

Last updated: 9 June 2026 · Effective: 9 June 2026

This Privacy Policy explains how SP Legacy Ltd ("we", "us", "our") — trading as FP Institute — collects, uses, stores, and protects your personal data when you visit fp-institute.com (the "Site") and the related private area at app.fp-institute.com (the "App").

We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) for visitors in the European Economic Area, and the Data Protection Act 2018.

1. Who we are

Legal entity
SP Legacy Ltd
Trading as
FP Institute (Fundamentals of Preparation Institute)
Company number
14788718 (registered in England & Wales)
Registered office
24 Tax Suite 137b Westlink House, 981 Great West Road, Brentford, United Kingdom, TW8 9DN
Privacy contact
via our contact form (select "Other" and mention "Privacy")

SP Legacy Ltd is the data controller for the personal data described in this Policy.

2. Personal data we collect

We collect personal data only when necessary to provide our services or to respond to you. Specifically:

2.1 Contact form

When you submit the form at fp-institute.com/contact-us we receive your full name, email address, subject category, and message. We process this to reply to your inquiry.

2.2 Private area account

When you activate your account through the QR code printed inside an FP Institute book, we collect your full name, email address, an encrypted password (we never see the plaintext), and — if you choose to sign in via Google — your Google profile email and display name. Authentication is provided by Supabase, our authentication processor.

2.3 Marketing email opt-in

If you submit your email on a landing page to receive a free guide or downloadable resource, we store your email and the source tag with our email service provider (AWeber) to send you the requested content and related FP Institute communications. You can unsubscribe from any email in one click.

2.4 Technical data

Our infrastructure provider (Cloudflare) processes standard server logs: IP address, user agent, time of request, requested URL, HTTP status code. These logs are used for security, abuse prevention, and operational debugging.

We do not use Google Analytics, Meta Pixel, or any third-party advertising or behavioural tracking on our website.

3. Why we process your data (lawful basis)

  • ·Contact formlegitimate interest, namely responding to inquiries about our products.
  • ·Private area accountperformance of a contract: providing access to the CBT Simulator and Digital Workbook you unlocked through your book.
  • ·Marketing emails (AWeber)consent, given when you submit your email on a landing page. You can withdraw consent at any time.
  • ·Server logs / securitylegitimate interest, namely keeping our infrastructure secure and operational.

4. Who we share data with (processors)

We share personal data only with the following processors, under data-processing agreements:

  • ·Supabase Inc. (USA) — authentication and database for the private area.
  • ·AWeber Communications, Inc. (USA) — email service provider for opt-in mailing lists.
  • ·Cloudflare, Inc. (USA) — hosting, CDN, and DNS.
  • ·Make (Celonis SE) (EU) — workflow automation that routes contact form and landing page submissions.
  • ·Hostinger International Ltd (Cyprus) — hosting of business email addresses.

We do not sell your personal data, ever. We do not share it with advertisers, data brokers, or any third party for marketing purposes.

5. How long we keep your data

  • ·Contact form messages: 24 months from receipt, then deleted.
  • ·Private area account: for as long as your account is active. You can request deletion at any time (see Section 7).
  • ·Mailing list subscription: until you unsubscribe, after which your record is deleted within 30 days.
  • ·Server logs: retained by Cloudflare for up to 30 days for security purposes.

6. Cookies and local storage

Our website uses only the minimum cookies and local storage required for the site to work:

  • ·Authentication cookies (App only) — set by Supabase to keep you signed in. Strictly necessary.
  • ·Security cookies — set by Cloudflare (__cf_bm) to detect and mitigate bots. Essential.
  • ·Local storage flags (App only) — e.g. to remember dismissed banners.

We do not use analytics, advertising, or behavioural-tracking cookies. Because no non-essential cookies are placed, no cookie consent banner is required under the PECR / ePrivacy framework.

7. Your rights

Under UK GDPR and EU GDPR, you have the right to:

  • ·Access a copy of the personal data we hold about you (Art. 15).
  • ·Rectify inaccurate or incomplete data (Art. 16).
  • ·Request erasure ("right to be forgotten") (Art. 17).
  • ·Restrict processing (Art. 18).
  • ·Portability — receive your data in a structured, machine-readable format (Art. 20).
  • ·Object to processing based on legitimate interest (Art. 21).
  • ·Withdraw consent at any time for processing based on consent.
  • ·Lodge a complaint with the UK Information Commissioner's Office (ICO) or with your local EU data protection authority.

To exercise any of these rights, contact us through our contact form (select "Other" and mention "Privacy request"). We will respond within 30 days, as required by GDPR.

8. International data transfers

Some of our processors are based in the United States (Supabase, AWeber, Cloudflare). Transfers of personal data outside the UK / EEA are covered by appropriate safeguards, including Standard Contractual Clauses (SCCs) and, where applicable, the UK Extension and the EU–US Data Privacy Framework.

9. Children

FP Institute products are aimed at adult professionals preparing for the Fundamentals of Engineering exam. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, please contact us so we can delete it.

10. Security

We protect your data with industry-standard measures: HTTPS in transit, encryption at rest in our processors' infrastructure, password hashing via Supabase, OAuth-restricted database access, and database triggers that prevent unauthorised account creation.

No system is completely secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, inform affected individuals without undue delay.

11. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent version. Material changes will be highlighted on the Site for at least 30 days from publication.