Privacy Notice
This privacy notice explains how GP Update Ltd trading as Red Whale collects, uses, shares and protects your personal data when you use our website, app, products and services, contact us, attend our events, or receive marketing from us. Our cookie information sits separately in our cookie policy.
Who we are
GP Update Ltd (trading as Red Whale) is the controller of your personal data for the activities covered by this notice. Company number: 7135974. Registered office: One Canada Square, London, E14 5GS.
We operate https://redwhale.co.uk and associated subdomains.
In our privacy policy, we might refer to 'we', 'us' or 'our', to indicate GP Update Ltd. We might also refer to “group companies” to include the Medical Defence Union Limited (of which the Dental Defence Union is the specialist dental division; company number 00021708), MDU Services Limited (company number 03957086), MDU Reinsurance Limited (registered in Guernsey; company number 42829).
Contact details
If you have any questions about this notice or want to exercise your data protection rights, please contact us at emails@redwhale.co.uk or on 03330 093 090 (Monday to Friday, 9.00am to 5.00pm).
What this notice covers
This notice applies when you use our website or app, create an account, buy a product or service, attend one of our events, contact our support team, subscribe to marketing, or interact with us in any other way.
The personal data we collect
In some cases, we need certain personal data to create your account, process your order, deliver a product or service, or respond to your request. If you do not provide that information, we may not be able to provide the relevant service or complete your request.
Depending on how you use our services, we may collect:
• identity and contact details, such as your name, email address, postal address and telephone number;
• account, profile and professional details, such as your username, encrypted password, professional registration details, job role, training year, employer, favourites, bookmarks and other content preferences, and CPD information you choose to record;
• order, payment and transaction details, such as what you bought, subscription status, invoice information and payment references (we do not store your payment card details on our own systems);
• technical and usage data, such as IP address, device and browser information, sign-in history, cookies, website/app activity and security logs;
• communications and support data, such as emails, chat messages, call recordings and transcripts, feedback, event questions and support history; and
• marketing preferences and suppression records, so we know what you do and do not want to receive.
We may also collect dietary or accessibility information where needed for a face-to-face event.
If you use our CPD tools or contact support, please do not include patient-identifiable information or other third-party personal data in any free text forms or calls
If you have an account with us, please keep your details up to date.
Where we get your data from
We collect personal data:
• directly from you, for example when you create an account, place an order, complete a form, book an event, contact us, record CPD or interact during a live event;
• from your employer, commissioner or colleague where they arrange or fund access for you;
• from payment, webinar, event, support and marketing platforms that help us deliver our services; and
• from public sources such as Companies House, business websites, online directories, news sources and LinkedIn where we are dealing with business-to-business enquiries, relationships or prospecting.
How we use your data and our lawful bases
We use personal data only where the law allows us to. The main reasons and lawful bases are:
• to create and manage your account, give you access to content, CPD tools and event registration, and deliver the services you have asked for - performance of a contract;
• to process orders, payments, refunds, renewals and invoices, and keep the records we need for tax and accounting - performance of a contract and legal obligation;
• to deliver face to face courses, webinars, live events and commissioned courses, including reporting account registration, attendance and feedback to commissioners where relevant - performance of a contract or legitimate interests, depending on the arrangement;
• to verify your eligibility for certain products or services, including checking your membership status with our group companies (such as the MDU) – legitimate Interests
• to help us handle customer support enquiries by email, chat or phone, including recording or transcribing calls where needed for training, quality checks, dispute resolution and managing queries. If a query needs specialist input, we may share it and your contact details internally with the appropriate member of staff, including a Red Whale clinician where relevant, so we can respond accurately - performance of a contract and/or legitimate interests,
• to send you service and administrative messages, such as account, booking and product information - performance of a contract and, where relevant, legal obligation;
• to send newsletters, product updates and other marketing - consent where required by law, and otherwise legitimate interests where permitted (for example some business-to-business marketing or soft opt-in marketing to existing customers);
• to respond to website contact forms and business enquiries, manage sales discussions and keep CRM records - steps before entering into a contract and/or legitimate interests;
•to understand how visitors interact with our website, improve website performance, respond to enquiries, manage website chat, lead capture and conversion tools, and where an enquiry has been submitted, monitor ongoing engagement with our website and content to support sales enquiries and relationship management – legitimate interests;
• if you interact with us through our social media channels, we may use information associated with your interaction (such as your username, profile information, comments or messages) to respond to enquiries, manage community engagement, moderate discussions and protect our reputation - legitimate interests.
• to improve and secure our website, app and services, including analytics relating to website, application and search usage, fraud prevention, bot protection, testing, troubleshooting, hosting and system security - legitimate interests, and consent where required for non-essential cookies or similar technologies; and
• where you choose to do so, to synchronise CPD entries with FourteenFish - performance of a contract and your instruction to use the feature.
If we rely on legitimate interests, we only do so where we are satisfied that your rights and interests are not overridden. If we rely on consent, you can withdraw it at any time.
If you opt out of marketing, we will still send you non-marketing messages that are needed to provide your service, such as booking confirmations, joining instructions and important account updates.
Who we share your data with
We share personal data only where necessary and only with appropriate safeguards in place. Depending on the service you use, this may include:
• service providers who host, maintain or support our website, app and business systems (for example hosting, CRM, support, authentication, search, analytics and security providers);
• providers who help us deliver courses, webinars and events, including event platforms, live audience interaction tools, venues and call-handling providers;
• payment and finance providers, including Stripe, and professional advisers such as lawyers, auditors, insurers and accountants;
• FourteenFish if you choose to use CPD synchronisation;
• commissioners or funding organisations where they have arranged or funded your place and need confirmation of account registration, eligibility verification, attendance, feedback or related reporting;
• group companies where there is a lawful basis to do so; and
• HMRC, regulators, courts, law enforcement or other authorities where we are required to do so or where disclosure is lawful and necessary.
Some recipients act as our processors and handle data only on our instructions. Others, such as Stripe, FourteenFish, and commissioners, may act as independent controllers for their own purposes.
Use of Artificial Intelligence (AI)
We may use, or plan to use, artificial intelligence (AI) tools to help us review, understand and improve our services.
AI is used as a support tool only. It does not make decisions about you. Any analysis or insights produced by AI are reviewed by our staff, and decisions are always made by people.
We use AI within secure systems and with appropriate safeguards in place. We aim to limit the personal data used, keep it secure, and use it only where we have a lawful reason to do so. Personal data provided to us is not used to train AI models.
International transfers
Some of our processors are based outside the UK, or can access data from outside the UK, (the United States and Singapore). Where this happens, we use an appropriate lawful transfer safeguard, such as an adequacy decision or approved contractual transfer protections, ensuring that the data continues to be protected to UK GDPR standards.
How long we keep your data
We keep personal data for different periods depending on what it is and why we hold it. In summary:
• account and service records are usually kept for the life of the account and then for up to 6 years after the account becomes dormant;
• financial, tax and transaction records are generally kept for 6 years after the end of the relevant financial year or transaction;
• marketing records are kept until you unsubscribe, object or withdraw consent, after which we may keep limited suppression information so we can respect your choice;
• CPD entries are kept in your account until you delete them, subject to any limited retention needed for legal, security or accountability reasons;
• dietary or accessibility information collected for a face-to-face event is kept for 90 days after the event date and then deleted in line with our event retention controls;
• live event interaction data is usually deleted shortly after the event; and
• support records, call recordings and related communications are kept for 3 years after the end of the calendar year in which the ticket was closed, in line with our customer support retention schedule, and then securely deleted or anonymised.
If you want the exact period for a specific record type, please ask us.
Security
We use appropriate technical and organisational security measures to protect personal data. Access is limited to people who need it for their job, and our suppliers are expected to protect personal data in line with the law and our contracts with them.
Automated decision-making
We do not make solely automated decisions about you that have legal or similarly significant effects under this notice.
Your rights
You have the right to ask us to access, correct, erase, restrict or transfer your personal data, and to object to processing based on legitimate interests, including direct marketing. Where we rely on consent, you can withdraw it at any time.
We may ask for proof of identity before dealing with a rights request. We usually respond within one month, although this can take longer for complex requests.
You also have the right to complain at any time about our processing of your personal data. If you have any questions, comments or concerns about any aspect of this policy, you can contact us at emails@redwhale.co.uk or the group Data Protection Officer at:
dataprotectionofficer@themdu.com
+44 207 202 1500
One Canada Square, London, United Kingdom, E14 5GS.
We hope we'll be able to resolve any concerns you may have, so please contact us in the first instance.
However, if we cannot resolve your issue to your satisfaction, you have the right to raise a complaint to the UK's supervisory authority for data protection, the Information Commissioner's Office (ICO), at:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Alternatively, you can email the ICO at casework@ico.org.uk or call 0303 123 1113.
Third-party links
Our website and app may contain links to third-party websites or services. We are not responsible for their privacy practices, so please read their privacy information separately.
Changes to this notice
We keep this privacy notice under review and may update it from time to time. If we make a significant change, we will take reasonable steps to bring it to your attention before the change takes effect where required.
Cookie Policy
The cookie policy can be found here.
This Privacy policy was last reviewed on 11 August 2026.