Home / Privacy policy

Privacy policy

At Pelican Training, privacy follows the same logic as first aid: simple steps, applied seriously. This page describes what data we process, why, for how long, and how to exercise your rights, in accordance with the General Data Protection Regulation (GDPR).

Last updated: 6 July 2026

Contents

  1. Controller
  2. Data we process
  3. Online manual
  4. Cookies
  5. Recipients
  6. Security
  7. Your rights
The bare minimum

We only collect what is needed to organise your training and issue your certificates.

Zero advertising

No selling of data, no advertising cookies, no audience-measurement tools on our sites.

Hosted in Europe

All data is hosted with OVH, in the European Union. No transfers outside the EU on our part.

Your rights, simply

An e-mail to hello@pelican.brussels is enough to view, correct or erase your data.

1. Who is the data controller?

Pelican Training (trading name), operated by Tom Vanobbergen, sole trader, Avenue Victor Rousseau 25, 1190 Forest, Belgium. Company number: BE1027086676. Contact for any question about your data: hello@pelican.brussels.

2. What data, why, and for how long?

ProcessingDataLegal basis and purposeRetention period
Contact requests Name, contact details, content of the message Pre-contractual measures: answering your request, preparing a quote 3 years after the last exchange
Registration and training follow-up Surname, first name, employer, attendance (signature), continuous-assessment result; date of birth and national register number only where required for the certificate Performance of the training contract and legal obligations linked to our accreditation (Workplace Well-Being Code, training of workplace first aiders) 7 years after the training for the training record; see below for the certificate
Certificates Data shown on the certificate and its unique number Legal obligation and legitimate interest: allowing an employer to verify authenticity and a duplicate to be reissued 7 years after issue
Invoicing Billing details, services provided Accounting and tax obligations As required by accounting and tax law
Certificate verification (pelican.brussels/verify) The number entered Legitimate interest: fighting fake certificates Checked on the fly, never stored

3. The online manual (firstaidmanual.pelican.brussels)

Participants in the Workplace First Aid course receive access to an online revision manual. This service is deliberately designed without accounts: no e-mail address, no password, no profile.

  • Identifier: your certificate code, which does not contain your name. It is what links your progress from one device to another.
  • Progress: lessons viewed, revision-quiz scores and dates, stored so that you can pick up where you left off. This data is used for nothing else: no official assessment, no reporting to your employer.
  • Duration: this data is kept for as long as the service is active for your code, and deleted on simple request.
  • Logging: in the event of repeated attempts with wrong codes, the IP address is kept for at most one hour, solely to slow down rapid-fire attempts.

4. Cookies

The pelican.brussels website and the online manual only use strictly technical cookies, exempt from consent (no advertising cookies, no trackers):

CookieRoleDuration
Session cookie (pelican_session)Security (CSRF protection), client area and registrations on pelican.brusselsEnd of the browsing session
Session cookie (manual)Keeping you signed in to the online manual while you read itEnd of the browsing session
Recognition cookie (manual)Saving you from re-entering your code on every visit180 days

These cookies are only set when they are necessary for the feature you requested (for example your client area or a registration). The preference linked to the cookie notice is stored locally by your browser (localStorage): it is not a cookie and nothing is sent to our servers.

No advertising cookies, no audience-measurement cookies, no third-party trackers. Fonts are hosted on our own servers: no request is made to Google Fonts or to any external service to display them.

5. Who has access to your data?

  • Pelican Training: the trainer, for organisation and certification.
  • Your employer or the organisation commissioning the training: attendance list and certificates, when the training is organised by them, as part of their own legal obligations.
  • OVH SAS (2 rue Kellermann, 59100 Roubaix, France): hosting of the websites and data, in the European Union.

That is all. We neither sell nor rent any data, and we transfer nothing outside the European Union.

6. Security

Encrypted connections (HTTPS), cryptographically signed certificate numbers (tamper-proof), data kept to a minimum, secrets stored outside the publicly accessible area of the server, access limited to the controller alone. In the event of a data breach likely to affect you, we would inform you as well as the Data Protection Authority, in accordance with the GDPR.

7. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability. Write to hello@pelican.brussels: we reply within a month. Some data cannot be erased before the legal deadline (certificates, invoicing); if so, we will tell you clearly.

If you believe your rights are not being respected, you can lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels).

8. Changes to this policy

This page may evolve along with our services. The date of the last update is shown at the top of the page; in the event of a substantial change, we will flag it visibly.

Exercise your rights or ask a question?

Write to us: hello@pelican.brussels

Contact us