Legal
Privacy policy
What Horizona Limited collects, why, and what you can do about it.
Last updated
This policy explains what personal data we hold when you use CPT, why we hold it, and where it goes. We have tried to describe what the system actually does rather than write something broad enough to cover anything we might ever do.
Who is responsible
Horizona Limited, a company incorporated in Hong Kong, is the data user for the purposes of the Personal Data (Privacy) Ordinance (Cap. 486).
What we collect
When you create an account
- Your name — this is what appears on any certificate you earn
- Your email address, used to identify your account
- Your phone number and organisation, if you choose to give them
- Your password, stored only as a bcrypt hash. We cannot read it, and we cannot tell you what it is
When you take a course
- Which courses you enrol in, and when
- How much of each recording you have watched, and where you stopped, so playback resumes and the assessment unlocks at the right point
- Your assessment answers, scores, and whether you passed
- The certificates issued to you
When you pay
Card payments are processed by Stripe. Your card details go directly to Stripe and never reach our servers. We keep a payment reference and the amount, so we can identify your purchase and process a refund.
When you contact us
What you put in an enquiry form — name, email, organisation, and your message — so we can reply.
What we don't do
We run no analytics, no advertising pixels, and no third-party trackers. We do not sell or rent personal data, and we do not send marketing email you did not ask for.
Certificates are public
This is the part worth reading twice
Every certificate we issue has a reference that resolves to a public page on this site. That page shows the holder's name, the course title, the CPT hours, and the date of issue. Anyone with the reference can view it, without an account.
This is deliberate — a certificate nobody can independently check is worth very little. But it does mean that completing a course results in your name appearing on a publicly accessible page. Nothing else about you is shown: not your email, phone, organisation, assessment answers, or which other courses you have taken.
Where your data is processed
We are based in Hong Kong, but some of the infrastructure is not. Specifically:
- Application servers — Google Cloud Run, Singapore
- Database — Neon, Singapore. This holds your account, enrolments, progress, assessment results, and certificates
- Course recordings — Google Cloud Storage, Hong Kong. These contain no personal data
- Payments — Stripe, which processes internationally
So your personal data is transferred outside Hong Kong, principally to Singapore. We use established providers with their own security and data protection commitments, and we hold no personal data on servers we run ourselves.
Cookies
We use one cookie: a session cookie that keeps you signed in. It is essential — you cannot use an account without it. It is removed when you log out.
Your light or dark theme preference is stored in your browser's local storage, not a cookie, and never sent to us.
No advertising or analytics cookies are set.
How long we keep it
- Account and progress — while your account is open
- Certificate records — indefinitely, including after an account is closed. A certificate that stops verifying is worse than useless: an employer checking a genuine record years later would be told it does not exist. Certificate records hold your name, the course, the hours, and the date — nothing more
- Payment records — as long as tax and accounting law requires
- Enquiries — up to two years, then deleted
Your rights
Under the Personal Data (Privacy) Ordinance you may ask what personal data we hold about you, ask for a copy, and ask us to correct anything inaccurate. Email hello@cpt.com.hk and we will respond within the statutory period.
You can ask us to close your account and delete your data. As above, issued certificate records are retained so verification continues to work — if that is not acceptable to you, tell us and we will discuss it rather than apply a blanket rule.
Security
Passwords are hashed with bcrypt and never stored in readable form. The site is served over HTTPS. Course recordings sit in a private bucket that is not publicly readable, and are served through short-lived signed links issued only after we have confirmed your enrolment. Credentials are held in a managed secret store, not in our code.
Changes
If we change how we handle personal data, we will update this page and the date at the top. Material changes will be notified before they take effect.
Contact
Questions, or a request about your data: hello@cpt.com.hk, or via the contact page.