Legal information

Privacy Notice

A provisional explanation of how personal information may be used when adults purchase learning time and manage child learners.

Status
Draft — not approved for a live payment launch
Effective date
[Owner to insert the legally approved effective date]

1. Who is responsible for your data

The intended data controller is [Owner to insert the full legal or sole-trader name, trading name and registration details that apply].

Privacy contact: [Owner to insert a monitored privacy email]. Address: [Owner to insert the approved business address].

[Owner/legal adviser to confirm whether a data protection officer, UK representative, ICO registration or additional contact details are required.]

2. Children's information

Future Forge Academy is intended for families and may handle information about child learners. Children's information needs particular protection. The approved service must explain its data use in clear, age-appropriate language and put the child's best interests first.

An adult account holder is intended to manage purchases and learner profiles. [Owner, privacy adviser and safeguarding adviser to verify the age model, parental responsibility checks, consent route and whether a separate child-friendly notice is required.]

3. Information we may collect

Depending on the parts of the service used, the system may process:

  • adult account and contact information, including name and email;
  • learner profile information needed to plan suitable learning, including information an adult chooses to provide;
  • order, payment-status and refund records, such as Stripe reference identifiers, amount, currency and timestamps, but not full card details;
  • learning-time balances and ledger entries, projects, progress, booking requests, attendance and tutor notes;
  • enquiries, support messages and complaint records; and
  • essential technical and security information, such as request logs, device or browser information and authentication events.

[Owner must complete and approve a real data inventory, including every learner field, tutor tool, analytics service, cookie and retention location. Remove anything not actually collected.]

4. Where information comes from

Information may come directly from the adult account holder, from a learner during a session, from tutors or authorised administrators, and from service providers involved in authentication, hosting, payment, email or security.

[Owner to verify whether schools, organisations or any other third parties provide learner information and add the required Article 14 notice details.]

5. Why information is used

  • to create and secure accounts;
  • to process orders, payment confirmations and refunds;
  • to maintain an accurate learning-time balance;
  • to manage learner profiles, bookings and online lessons;
  • to send service, booking and purchase messages;
  • to answer enquiries and complaints;
  • to prevent misuse and keep the service secure; and
  • to meet legal, accounting and safeguarding obligations.

Personal information must not be reused for an incompatible purpose without an appropriate legal basis and notice.

6. Lawful bases

The UK GDPR requires a lawful basis for each purpose. Possible bases may include taking steps towards or performing a contract, complying with a legal obligation, legitimate interests assessed against the person's rights, or consent where it is genuinely appropriate.

[Owner and qualified privacy adviser must complete a purpose-by- purpose lawful-basis assessment before launch. They must separately identify any special-category or safeguarding information, the Article 9 condition that applies, and the child-specific protections. This draft does not select those bases.]

7. Who information may be shared with

Limited information may be shared with vetted providers that support hosting, databases, authentication, card payments, email delivery, scheduling, security and professional advice. Information may also be disclosed where lawfully required or needed to protect someone from harm.

[Owner must name or categorise the actual processors, document contracts and locations, verify sub-processors, and approve whether a public processor list is needed. Do not approve this notice until the final production stack is known.]

8. International transfers

Some service providers may process information outside the UK. Any restricted transfer must use a lawful transfer mechanism and appropriate safeguards.

[Owner and privacy adviser to map actual data locations, adequacy decisions and contractual safeguards before launch.]

9. How long information is kept

Personal information should be kept only for as long as necessary for the relevant purpose, including legal, tax, accounting, safeguarding and dispute requirements. It should then be securely deleted or anonymised.

[Owner and legal/privacy advisers to approve a record-by-record retention schedule, including accounts, child learner profiles, lesson notes, purchases, refunds, bookings, support messages, logs and backups.]

10. Security

Appropriate organisational and technical safeguards should protect information against unauthorised access, loss, alteration or disclosure. No online system can promise absolute security.

Users should protect their sign-in details and tell the privacy contact promptly if they suspect account misuse.

11. Your data protection rights

Depending on the circumstances, UK data protection law may give you rights to be informed, access information, correct it, erase it, restrict or object to its use, and receive portable data. Where processing relies on consent, consent may be withdrawn without affecting earlier lawful processing.

Children have data protection rights too. A request involving a child must be considered in light of the child's understanding and best interests, rather than automatically treating the adult account holder as the only rights holder.

Send a request to [Owner to insert the monitored privacy email]. The owner must verify identity proportionately and respond within the legally required period.

12. Marketing and automated decisions

[Owner to confirm whether any marketing, profiling or automated decision-making occurs. If it does, add the required choices, lawful basis, logic and consequences. If it does not, replace this placeholder with an accurate statement.]

13. Cookies and similar technologies

The service may need essential cookies or similar storage for authentication and security. [Owner to complete a cookie audit and add an approved cookie notice and consent controls before using any non-essential technology.]

14. Questions and complaints

Raise a privacy concern first with [Owner to insert the monitored privacy email]. You may also complain to the UK Information Commissioner's Office. Current contact and complaint information is available on the ICO website.

15. Changes to this notice

The approved notice should show its effective date. Material changes should be brought to account holders' attention in clear language, with an age-appropriate explanation where they affect learners.