Skip to content
Pass the MSRA

Privacy Policy

Last updated: 21 July 2026

This Privacy Policy explains how Pass the MSRA collects, uses, stores and shares personal information when you visit passthemsra.com, create an account, purchase access or use our educational services.

It also explains your data-protection rights and how to contact us about your personal information.

This Policy should be read alongside our Cookie Policy, Terms and Conditions, Refund and Cancellation Policy and Security Policy.

1. Who we are

Pass the MSRA is an online medical education platform established in London, United Kingdom.

For the purposes of UK data-protection law, Pass the MSRA is the controller of personal information covered by this Policy. This means that we decide why and how that information is used.

In this Policy:

  • “Pass the MSRA”, “we”, “us” and “our” refer to the operator of passthemsra.com;
  • “platform” means our website, courses, question banks, dashboards and associated services;
  • “you” and “your” refer to a visitor, registered user, customer or person contacting us;
  • “personal information” means information relating to an identified or identifiable individual.

Privacy enquiries may be sent to:

Pass the MSRA

London, United Kingdom

Email: passthemsra@gmail.com

2. Data-protection principles

We aim to handle personal information in accordance with the principles of:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • accountability.

These are the core data-processing principles under the UK GDPR. (ICO)

3. Personal information we may collect

The information we collect depends on how you use the platform.

3.1 Account and identity information

When you register or manage an account, we may collect:

  • your name;
  • email address;
  • username;
  • encrypted or securely hashed password information;
  • account identifier;
  • registration date;
  • account status;
  • membership or access level;
  • profile information you choose to provide;
  • records of agreement to our terms and policies.

We should not be able to see your password in plain text.

3.2 Purchase and membership information

When you purchase access or select a subscription, we may collect:

  • the plan purchased;
  • price and currency;
  • order or transaction reference;
  • purchase date;
  • access start and end dates;
  • renewal status;
  • discount code used;
  • payment status;
  • refund or cancellation records;
  • billing details required for the transaction;
  • records of checkout consent, including immediate digital-access consent.

Payment-card information is generally processed by the payment provider rather than stored in full by Pass the MSRA.

We may receive limited payment information such as:

  • payment status;
  • card brand;
  • final digits of the payment card;
  • expiry information;
  • fraud or authentication results;
  • payment-provider customer or transaction identifiers.

The exact information received depends on the payment provider and checkout configuration.

3.3 Learning and performance information

When you use our educational services, we may collect:

  • courses or lessons opened;
  • question attempts;
  • selected answers;
  • correct and incorrect responses;
  • scores;
  • mock-examination results;
  • time spent on activities;
  • completion status;
  • progress;
  • bookmarks or flags;
  • revision history;
  • strengths and weaker areas;
  • dashboard activity;
  • flashcard or spaced-repetition information;
  • technical events linked to your learning session.

We use this information to operate the learning platform, display progress and improve educational features.

Learning information is not an official medical examination result and is not routinely shared with employers, training programmes or official examination bodies.

3.4 Communications and support information

When you contact us, we may collect:

  • your name and email address;
  • the content of your enquiry;
  • relevant account or order information;
  • support correspondence;
  • attachments you choose to send;
  • complaint and resolution records;
  • correction or feedback submissions.

Please do not send:

  • passwords;
  • complete payment-card details;
  • identifiable patient information;
  • confidential live examination material;
  • unnecessary identity documents.

3.5 Marketing information

Where applicable, we may collect:

  • whether you have subscribed to marketing;
  • the date and method of consent;
  • the wording or version of the consent request;
  • email campaign delivery and interaction information;
  • unsubscribe or objection records;
  • advertising attribution and conversion information;
  • promotional preferences.

Service emails necessary to administer an account or purchase are separate from optional marketing communications.

3.6 Technical and usage information

When you visit or use the website, we may automatically receive:

  • IP address;
  • browser type and version;
  • device and operating-system information;
  • approximate location derived from an IP address;
  • date and time of access;
  • pages visited;
  • referral source;
  • session or account identifiers;
  • error and security logs;
  • website performance information;
  • interactions with features;
  • cookie and consent preferences.

Optional analytics and advertising information is collected only in accordance with the choices and legal conditions described in our Cookie Policy.

3.7 Security and fraud-prevention information

We may process information used to protect accounts, payments and the platform, including:

  • login attempts;
  • IP addresses;
  • device and session identifiers;
  • password-reset events;
  • suspected account sharing;
  • unusual usage patterns;
  • payment disputes;
  • security alerts;
  • access-control events;
  • evidence of scraping or automated activity;
  • records relating to suspected fraud or misuse.

3.8 Testimonials and reviews

Where you provide or agree to a testimonial or review, we may process:

  • your submitted wording;
  • name or initials;
  • professional role or training stage;
  • broad location or region;
  • score or outcome information you choose to disclose;
  • evidence of authenticity;
  • consent to publication;
  • communications relating to editing or withdrawal.

We will not knowingly publish private support correspondence as a testimonial without appropriate permission.

3.9 Information from third parties

We may receive information from third parties where necessary, including:

  • payment providers;
  • authentication services;
  • hosting and security providers;
  • analytics and advertising platforms;
  • email-delivery providers;
  • people who purchase access on your behalf;
  • fraud-prevention or payment-dispute services.

Where information is obtained from someone other than the individual, applicable privacy information should normally be provided within the relevant legal timeframe unless an exemption applies. (ICO)

4. Special-category information

Special-category information includes data revealing matters such as health, ethnicity, religion, political opinions, trade-union membership, genetic or biometric information and sexual life or orientation.

Pass the MSRA does not normally need users to provide special-category information.

Please do not include:

  • identifiable patient details;
  • personal health information;
  • unnecessary protected-characteristic information;
  • confidential employment or disciplinary information;

in routine support messages, testimonials or feedback.

Where we intentionally process special-category information, we must identify both an Article 6 lawful basis and an additional condition permitting the processing. (ICO)

5. How and why we use personal information

We use personal information only where we have a lawful basis.

5.1 Creating and managing accounts

We may use account information to:

  • register you;
  • authenticate your login;
  • maintain your account;
  • provide profile and membership controls;
  • reset passwords;
  • show purchased access;
  • communicate important account information.

Likely lawful basis: performance of a contract, or taking steps at your request before entering a contract.

For free accounts, certain processing may also be necessary for our legitimate interests in providing and securing the requested service.

5.2 Supplying paid educational services

We may use purchase, membership and learning information to:

  • process an order;
  • activate access;
  • provide courses and question banks;
  • display progress and scores;
  • manage subscription renewals;
  • verify entitlement;
  • process cancellations or refunds;
  • provide customer support.

Likely lawful basis: performance of a contract.

5.3 Processing payments

We may use transaction information to:

  • collect payments;
  • confirm payment status;
  • administer recurring payments selected by you;
  • investigate incorrect or duplicate charges;
  • handle refunds;
  • manage payment disputes;
  • prevent fraud.

Likely lawful bases:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests in preventing fraud, administering payments and protecting our business.

5.4 Maintaining learning records

We may use learning and performance information to:

  • save progress;
  • show completed lessons;
  • calculate scores;
  • identify revision history;
  • personalise the user dashboard;
  • restore sessions;
  • provide adaptive or weak-area features where offered.

Likely lawful bases:

  • performance of a contract;
  • legitimate interests in providing and improving educational functionality.

5.5 Providing support

We may use contact, account and transaction information to:

  • answer enquiries;
  • troubleshoot access;
  • investigate reported errors;
  • resolve complaints;
  • administer refunds;
  • verify account ownership.

Likely lawful bases:

  • performance of a contract;
  • legitimate interests in customer service and platform administration;
  • compliance with legal obligations where applicable.

5.6 Security, fraud prevention and acceptable use

We may use technical, account and payment information to:

  • secure accounts;
  • investigate unauthorised access;
  • detect account sharing;
  • prevent scraping and automated extraction;
  • protect intellectual property;
  • investigate fraudulent transactions;
  • enforce platform terms;
  • preserve evidence;
  • defend legal claims.

Likely lawful bases:

  • legitimate interests in protecting users, payments, content and the platform;
  • compliance with legal obligations;
  • establishment, exercise or defence of legal claims where applicable.

5.7 Service communications

We may send communications about:

  • registration;
  • order confirmations;
  • receipts;
  • access;
  • password resets;
  • renewals and cancellations;
  • significant service changes;
  • security incidents;
  • policy changes;
  • support enquiries.

Likely lawful bases:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests in administering the service.

You may not be able to opt out of essential service communications while maintaining an active account or purchase.

5.8 Marketing

Where permitted, we may send information about:

  • Pass the MSRA products;
  • revision resources;
  • discounts;
  • new features;
  • related educational content.

Likely lawful bases:

  • consent;
  • or, where legally available, the electronic-mail “soft opt-in” for similar products offered to existing customers, with a clear opportunity to opt out.

You can unsubscribe at any time by using the link in the message or contacting us.

We will not rely on consent where it has not been obtained through a valid, informed and freely given choice.

5.9 Analytics and website improvement

With the required cookie consent, or under another applicable legal exception, we may use analytics information to:

  • understand how the website is used;
  • identify errors;
  • improve page design;
  • assess navigation;
  • measure content performance;
  • plan new features.

Likely lawful bases:

  • consent for applicable cookies and related personal-data processing;
  • legitimate interests for limited security or service-improvement processing that does not require consent.

Cookie consent and the UK GDPR lawful basis are related but separate requirements.

5.10 Advertising and conversion measurement

With appropriate consent, we may use advertising and conversion information to:

  • understand whether advertising resulted in a visit, registration or purchase;
  • measure campaign effectiveness;
  • improve advertising;
  • avoid unnecessary or repeated marketing.

Likely lawful basis: consent.

The current Cookie Policy identifies Google Analytics and Google advertising or conversion technologies. These technologies should remain inactive until the relevant consent has been obtained where required.

5.11 Legal, regulatory and tax requirements

We may use and retain information to:

  • maintain financial records;
  • comply with tax and accounting obligations;
  • respond to lawful requests;
  • comply with court orders;
  • protect legal rights;
  • respond to regulators or law-enforcement authorities.

Likely lawful basis: compliance with a legal obligation, and legitimate interests in establishing or defending legal rights.

5.12 Testimonials

We may use testimonial information for publication and marketing where the individual has agreed to that use.

Likely lawful basis: consent.

You may withdraw consent for future use, although this may not require us to recall printed or previously distributed material where removal is not reasonably possible.

6. Lawful bases

The lawful bases we are most likely to rely on are:

Contract

Processing is necessary to enter into or perform a contract with you, including providing paid access and administering your membership.

Legal obligation

Processing is necessary to comply with a legal requirement, such as accounting, tax or valid regulatory obligations.

Legitimate interests

Processing is necessary for a legitimate business or user interest, and those interests are not overridden by your rights.

Possible legitimate interests include:

  • securing the platform;
  • preventing fraud;
  • responding to users;
  • maintaining accurate records;
  • improving services;
  • protecting intellectual property;
  • establishing or defending legal claims.

Where we rely on legitimate interests, we should assess the purpose, necessity and effect on individuals.

Consent

You have given a clear choice for a specific purpose, such as optional marketing, testimonials or consent-dependent cookies.

You may withdraw consent at any time. Withdrawal does not make earlier lawful processing unlawful.

A privacy notice must identify the lawful basis relied upon, and that choice may affect which individual rights apply. (ICO)

7. When we share personal information

We do not sell personal information to advertisers.

We may share limited personal information with service providers where necessary to operate the platform.

Categories may include:

  • website hosting and infrastructure providers;
  • WordPress and plugin services;
  • payment processors;
  • email-delivery providers;
  • analytics and advertising providers;
  • cloud and backup services;
  • security and fraud-prevention services;
  • technical-support providers;
  • professional advisers;
  • regulators, courts or law-enforcement bodies where legally required.

Service providers should receive only the information reasonably necessary for their function and should be subject to appropriate contractual and security obligations.

Before publication, confirm the exact active provider list. Based on the known platform, this may include services connected with:

  • Hostinger;
  • WordPress;
  • LearnDash;
  • Restrict Content Pro;
  • Stripe or another payment processor;
  • Google Analytics;
  • Google advertising and conversion measurement;
  • email-delivery infrastructure;
  • LiteSpeed;
  • security, backup or caching plugins.

Do not list a provider unless it is actually used.

8. Payment providers

Payment providers process payment information under their own privacy notices and legal responsibilities.

Pass the MSRA should not store complete card numbers or card-security codes unless there is a specific compliant reason and system for doing so.

We may receive transaction status and limited payment details needed to:

  • identify a payment;
  • activate access;
  • process a refund;
  • investigate fraud;
  • answer an account query;
  • maintain financial records.

9. Google analytics and advertising services

Where you consent, Google technologies may process:

  • analytics identifiers;
  • device and browser information;
  • page and event information;
  • approximate location;
  • referral information;
  • advertising-click information;
  • conversion events.

The Cookie Policy identifies:

  • _ga;
  • _ga_*;
  • _gcl_au;
  • _gcl_ls.

The analytics and advertising tags responsible for these technologies should be blocked unless and until the relevant consent is given.

10. International transfers

Some service providers may process personal information outside the United Kingdom.

Where a transfer is a restricted international transfer under the UK GDPR, we should use an appropriate legal mechanism, which may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • another lawful transfer safeguard;
  • an applicable exception in limited circumstances.

A transfer risk assessment may be required depending on the mechanism and destination. The ICO’s international-transfer guidance was updated in January 2026 and explains how to identify and manage restricted transfers. (ICO)

Contact us for more information about relevant safeguards.

11. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.

Indicative retention periods are:

InformationIndicative retention
Active account informationWhile the account remains active
Learning and progress recordsWhile the account is active and for a reasonable period afterwards
Purchase, invoice and accounting recordsNormally up to six years after the relevant accounting period or transaction, subject to applicable requirements
Payment-provider referencesFor the period needed for accounting, refunds, fraud prevention and disputes
Support correspondenceNormally up to three years after the matter closes, unless a longer period is justified
Complaints and legal disputesFor the duration of the matter and the relevant limitation period
Marketing-consent recordsWhile marketing continues and for a reasonable period afterwards to demonstrate the consent or objection
Unsubscribe or suppression recordsAs long as needed to respect the request
Security logsNormally for a limited period appropriate to the security purpose, unless retained for investigation
Cookie informationAs described in the Cookie Policy
TestimonialsUntil consent is withdrawn or the material is no longer used, subject to practical and legal limitations
Failed or abandoned registrationsFor a short period needed for security, support and system administration

These periods are a working schedule and should be checked against the actual WordPress database, backups, accounting system and service-provider settings.

We may retain information for longer where reasonably necessary to:

  • comply with law;
  • investigate fraud or security incidents;
  • resolve a dispute;
  • establish or defend legal claims;
  • enforce an agreement.

The ICO requires privacy information to include the retention period or the criteria used to determine it. (ICO)

12. Security

We use reasonable technical and organisational safeguards designed to protect personal information.

Measures may include:

  • access controls;
  • authentication;
  • secure password storage;
  • encrypted connections;
  • software and plugin updates;
  • restricted administrative access;
  • security monitoring;
  • backups;
  • payment processing through specialist providers;
  • logging and incident investigation;
  • staff or contractor confidentiality requirements where applicable.

No website, database or internet transmission can be guaranteed to be completely secure.

Further information is provided in our Security Policy.

13. Data breaches

Where we become aware of a personal-data breach, we will assess:

  • what information was affected;
  • the likely consequences;
  • the number and type of individuals affected;
  • whether containment or remediation is required;
  • whether the ICO must be notified;
  • whether affected individuals must be informed.

We will maintain appropriate records of personal-data breaches where required.

14. Your rights

Depending on the circumstances, you may have the right to:

Be informed

You have the right to receive clear information about how your personal information is used.

Access

You may request confirmation of whether we process your personal information and ask for a copy.

Rectification

You may ask us to correct inaccurate information or complete incomplete information.

Erasure

You may ask us to delete personal information in certain circumstances.

This right is not absolute. We may need to retain information for legal obligations, fraud prevention, legal claims or other valid reasons.

Restriction

You may ask us to restrict how information is used in certain circumstances.

Data portability

Where processing is based on consent or contract and carried out by automated means, you may have the right to receive relevant information in a structured, commonly used and machine-readable format.

Object

You may object to processing based on legitimate interests in certain circumstances.

You have an absolute right to object to personal information being used for direct marketing. The UK GDPR also provides a right to object to certain other processing. (ICO)

Withdraw consent

Where processing is based on consent, you may withdraw that consent at any time.

Rights relating to automated decision-making

You may have rights concerning a decision based solely on automated processing that produces legal or similarly significant effects.

Complain

You may complain to us or to the Information Commissioner’s Office.

Not every right applies in every situation. We may need to verify your identity and may ask for information needed to locate the relevant records.

15. How to exercise your rights

Email:

passthemsra@gmail.com

Please include:

  • your name;
  • the email address linked to your account;
  • the right you wish to exercise;
  • enough information to identify the relevant records.

Do not send passwords or complete payment-card details.

We will normally respond within the period required by applicable law. Complex or numerous requests may allow an extension where the legal conditions are met.

We will not normally charge a fee. A reasonable fee may be permitted for requests that are manifestly unfounded or excessive, or for additional copies, where allowed by law.

16. Identity verification

Before releasing, deleting or changing personal information, we may take proportionate steps to confirm:

  • your identity;
  • your authority to act for another person;
  • ownership of the relevant account.

We will request only the information reasonably needed for verification.

Any verification material should be deleted or restricted when it is no longer required, subject to necessary records of how the request was handled.

17. Direct marketing

Where we send marketing, every message should provide a clear method to unsubscribe.

You can also object by emailing us.

Opting out of marketing will not normally stop essential service messages about:

  • account security;
  • payment;
  • access;
  • renewal or cancellation;
  • legal or policy changes;
  • support enquiries.

We may retain a minimal suppression record to ensure that your marketing objection continues to be respected.

18. Cookies

We use cookies and similar technologies as described in our Cookie Policy.

The currently identified technologies include:

  • WordPress browser-functionality storage;
  • Google Analytics;
  • Google advertising and conversion measurement;
  • browser local storage used for conversion attribution.

Non-essential analytics and advertising technologies should not operate unless the required consent or another applicable legal exception is present.

You may change your choices through the website’s Cookie settings control.

19. Automated processing and profiling

We may use automated processing to support features such as:

  • calculating question scores;
  • displaying progress;
  • identifying weak areas;
  • recommending revision content;
  • detecting unusual account or security activity;
  • measuring advertising conversions.

These ordinary platform functions are not intended to make legal or similarly significant decisions about users.

We do not use platform performance data to make official decisions about:

  • medical registration;
  • employment;
  • specialty recruitment;
  • training selection;
  • credit;
  • insurance;
  • access to healthcare.

If future features involve solely automated decisions producing legal or similarly significant effects, this Policy and the relevant user information must be updated before deployment.

20. Children and younger users

Pass the MSRA is primarily intended for medical students, doctors and other adult healthcare professionals preparing for postgraduate examinations.

It is not designed for young children.

However, a blanket reference only to children under 13 is not appropriate for UK privacy compliance. The ICO’s Children’s Code may apply to online services likely to be accessed by anyone under 18, even where the service is not expressly targeted at children. (ICO)

Users under 18 should not purchase access without the involvement or permission of a parent, guardian or other authorised adult where required.

We do not knowingly seek unnecessary personal information from children.

If we learn that a child’s information has been processed inappropriately, we will take reasonable steps to investigate and delete, restrict or otherwise address it.

Concerns may be sent to:

passthemsra@gmail.com

21. Patient information

Do not submit identifiable patient information through:

  • support forms;
  • emails;
  • feedback;
  • testimonials;
  • comments;
  • uploaded materials.

Where you need to discuss a clinical-content concern, remove or alter information that could identify a patient.

If identifiable patient information is received unexpectedly, we may delete, restrict or securely retain it only where necessary to address an incident or comply with legal obligations.

22. Third-party websites and embedded services

The platform may link to or embed third-party services, including:

  • payment pages;
  • YouTube;
  • podcast platforms;
  • official medical guidance;
  • recruitment websites;
  • social-media services.

Third parties operate under their own privacy notices.

Pass the MSRA is not responsible for how an unrelated third-party website processes information after you leave our platform.

Where embedded content uses non-essential tracking technology, it should be blocked or limited until the relevant cookie consent has been obtained.

23. Business transfers

If the platform or its operations are reorganised, transferred, financed or sold, personal information may be disclosed to appropriate advisers or a prospective new operator where reasonably necessary.

Any transfer should:

  • have an appropriate lawful basis;
  • be subject to confidentiality and security protections;
  • respect existing user rights;
  • be explained to affected users where required.

Personal information will not be treated merely as an unrestricted commercial asset.

24. Legal disclosures

We may disclose personal information where reasonably necessary to:

  • comply with law;
  • respond to a valid court order;
  • respond to an authorised regulator or law-enforcement request;
  • investigate fraud or security incidents;
  • protect users or the public;
  • establish, exercise or defend legal claims;
  • enforce our contractual rights.

We will not disclose information merely because a person informally requests it without an appropriate basis.

25. Complaints

Please contact us first so that we can attempt to resolve your concern:

passthemsra@gmail.com

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office

The ICO provides guidance and an online complaints process for concerns about the use of personal information. A privacy notice should tell individuals about their right to complain to the relevant supervisory authority. (ICO)

26. Changes to this Policy

We may update this Policy to reflect:

  • legal or regulatory changes;
  • new platform functions;
  • new service providers;
  • changes to data use;
  • changes to cookies or marketing;
  • security or operational improvements;
  • clarification of existing information.

The current version will display a revised “Last updated” date.

Where a change materially affects how personal information is used, we will take reasonable steps to bring it to the attention of affected users and obtain new consent where legally required.

We will not apply a change retrospectively to make previously unlawful processing lawful.

27. Contact

Privacy questions and rights requests may be sent to:

Pass the MSRA

London, United Kingdom

Email: passthemsra@gmail.com

Please do not send:

  • passwords;
  • complete payment-card details;
  • identifiable patient information;
  • confidential live examination questions;
  • unnecessary identity documents.
Back to all policies

Questions about this policy? Email passthemsra@gmail.com.

Scroll to Top