Privacy & Data Use

Private educational information should remain private by design.

The ecosystem is being built around a simple separation: public knowledge belongs on the public web; personal educational records, consultation notes, assessment responses, reports, orders and private documents belong in an authenticated private system.

Current siteStatic public layerNo production private-record secure service is accepting educational records yet.
CollectionData minimisationOnly information needed for a defined service should be collected.
Private dataAuthenticated onlyEducational records belong outside the public web.
Legal reviewBefore productionJurisdiction-specific final terms and retention rules remain a launch gate.

Current website state

The current public site is primarily static. The student login, registration and private-platform routes are not yet connected to a production secure service and therefore do not currently accept passwords, private educational records or secure document uploads.

Where an email contact link is used, users are asked not to send identity documents, medical records, report cards or other sensitive files in the initial message. If a document becomes genuinely necessary for a service, a more appropriate transfer method should be used.

What the future private platform is designed to hold

Depending on the service, the private platform may eventually hold account information, educational history, assessment responses, parent or teacher observations, consultation records, recommendations, private reports, appointment information, orders and approved uploaded documents. Access will be role- and relationship-based rather than public.

Data minimisation

Information should be collected because it is needed for a defined service, not simply because it might be useful later. A consultation intake therefore begins with the minimum information required to understand the question. Sensitive files are requested only when they are relevant to the case.

Different kinds of consent remain separate

Using a service is not the same as agreeing to research, publication or marketing. Service/privacy acknowledgement, research participation, publication permission and marketing consent are separate decisions. A user should not have to agree to research or promotional use in order to receive an ordinary educational service.

Research use

Operational data are not automatically research data. Research use requires an approved study path, appropriate consent or other lawful basis where applicable, pseudonymous case identifiers, de-identification and a version-frozen research dataset with provenance. Researchers should not receive direct identity information by default.

Payments

The ecosystem is designed so that card credentials are handled by the payment provider rather than stored by this website. Payment status and provider references may be retained for order, accounting and support purposes once a lawful production payment route is activated.

Children and families

Educational services may involve minors. A parent account will not automatically gain access merely because an email address claims a relationship. Parent–student access must be verified and governed by explicit relationship and visibility rules.

Access, correction, export and deletion requests

The production platform is designed to support privacy requests such as access, correction, export and deletion requests, subject to legitimate operational, research, financial or legal retention requirements that may apply. These workflows will be activated before the private platform accepts real educational records.

Before production launch

This page describes the product and privacy baseline. A jurisdiction-specific legal review, final retention schedule, production contact details and final terms will be completed before the authenticated platform begins accepting real private educational data.