Privacy & Data Use
Private educational information should remain private by design.
The ecosystem is being built around a simple separation: public knowledge belongs on the public web; personal educational records, consultation notes, assessment responses, reports, orders and private documents belong in an authenticated private system.
Current website state
The current public site is primarily static. The student login, registration and private-platform routes are not yet connected to a production secure service and therefore do not currently accept passwords, private educational records or secure document uploads.
Where an email contact link is used, users are asked not to send identity documents, medical records, report cards or other sensitive files in the initial message. If a document becomes genuinely necessary for a service, a more appropriate transfer method should be used.
What the future private platform is designed to hold
Depending on the service, the private platform may eventually hold account information, educational history, assessment responses, parent or teacher observations, consultation records, recommendations, private reports, appointment information, orders and approved uploaded documents. Access will be role- and relationship-based rather than public.
Data minimisation
Information should be collected because it is needed for a defined service, not simply because it might be useful later. A consultation intake therefore begins with the minimum information required to understand the question. Sensitive files are requested only when they are relevant to the case.
Different kinds of consent remain separate
Using a service is not the same as agreeing to research, publication or marketing. Service/privacy acknowledgement, research participation, publication permission and marketing consent are separate decisions. A user should not have to agree to research or promotional use in order to receive an ordinary educational service.
Research use
Operational data are not automatically research data. Research use requires an approved study path, appropriate consent or other lawful basis where applicable, pseudonymous case identifiers, de-identification and a version-frozen research dataset with provenance. Researchers should not receive direct identity information by default.
Payments
The ecosystem is designed so that card credentials are handled by the payment provider rather than stored by this website. Payment status and provider references may be retained for order, accounting and support purposes once a lawful production payment route is activated.
Children and families
Educational services may involve minors. A parent account will not automatically gain access merely because an email address claims a relationship. Parent–student access must be verified and governed by explicit relationship and visibility rules.
Access, correction, export and deletion requests
The production platform is designed to support privacy requests such as access, correction, export and deletion requests, subject to legitimate operational, research, financial or legal retention requirements that may apply. These workflows will be activated before the private platform accepts real educational records.
Before production launch
This page describes the product and privacy baseline. A jurisdiction-specific legal review, final retention schedule, production contact details and final terms will be completed before the authenticated platform begins accepting real private educational data.