Legal

Privacy Policy

How Beyond School Futures Academy collects, uses and protects the information you share with us.

Awaiting legal review

This policy accurately describes how the platform currently works, but it has not yet been reviewed by a legal advisor. BSFA should confirm it against applicable data protection law, add the academy's registered operating details, and remove this notice before launch.

Last updated: 4 October 2026

Who we are

Beyond School Futures Academy™ ("BSFA", "we", "us") operates this website and digital learning platform. If you have any question about this policy or about your information, contact us at admin@beyondschoolfutures.com or through our contact page.

What we collect

When you create an account: your name, email address and a password. Your password is never stored in a readable form — it is converted into a secure one-way hash, which means nobody at BSFA can see or recover it.

When you complete your profile (optional): a phone number, a short biography and a profile photo, if you choose to add them.

As you learn: which programmes you are enrolled in, which lessons you have marked complete, your overall progress in each course, your quiz attempts and scores, and any certificates issued to you.

When you contact us: your name, email address, optional phone number and the content of your message.

When you subscribe to our newsletter: your email address, subscription status and newsletter preference. An account registration does not automatically subscribe you. We also record which campaign emails were accepted by our mail server, skipped or not confirmed, so we can operate the mailing list and avoid resending the same campaign.

Automatically: a session cookie that keeps you logged in as you move between pages. We do not currently run third-party advertising or analytics trackers on this website.

How we use it

We use your information to create and secure your account, to deliver the programmes you enrol in and record your progress, to issue your certificates, to reply when you contact us, and to send you the newsletter if you have asked for it.

We keep a record of people who have been in touch with us — an enquiry, a subscription, a registration — so that our team can respond properly and know the history of a conversation rather than starting from nothing each time.

We do not sell your personal information, and we do not share it with third parties for their own marketing.

Emails we send

There are three kinds. Account emails — verifying your email address when you register, and a welcome message once you have. Newsletters — only if you subscribed, and every one carries an unsubscribe link at the bottom. Replies — when you have written to us and a member of the team responds.

Registered users can opt in during registration or change their newsletter preference from My Profile. Newsletter sign-ups and opted-in verified accounts share one mailing list; we do not add existing accounts just because they registered. Promotional campaigns, course updates, resources and event newsletters all use that preference. Newsletter emails contain an unsubscribe link and support email-provider one-click unsubscribe. We do not use email-open tracking pixels.

Unsubscribing from the newsletter never affects your learning account, and never stops essential account emails.

Children and young people

BSFA serves families, and some of our learners are children. We ask that a parent or guardian sets up, approves and oversees an account for any learner under 18.

We collect no more from a young learner than we do from any other account holder — a name, an email address and their learning progress — and learner information is never used for advertising. A parent or guardian may contact us at any time to ask what information we hold about their child, to correct it, or to have the account and its data deleted.

How we protect your information

Passwords are stored only as secure one-way hashes. Login sessions use cookies that cannot be read by scripts in your browser and, on our live site, are only sent over an encrypted HTTPS connection. Access to learning content is restricted to enrolled learners, and administrative areas are restricted to authorised BSFA staff accounts.

No system can promise perfect security, but we treat the protection of family and learner information as a core design principle rather than an afterthought.

Payments

When you start card checkout, we supply your account email to Stripe where appropriate. Stripe collects billing information, including the payer's name and billing address, and device and connection signals to process payments and assess fraud risk. We may reuse a Stripe customer record linked to your previous confirmed purchases. Full billing addresses are collected by Stripe; BSFA's sales reporting retains only country, region and city when provided. Learn more in Stripe's privacy policy.

For physical cash payments, we keep token references, USD amounts, issuing administrator IDs, receipt and refund dates, and redemption records linking the buying account to its course. Token codes are stored as hashes, not readable codes. Redeemed tokens contribute to internal course sales reports; we do not infer billing location for cash payments.

Card payments are processed through Stripe. Payment details are entered with Stripe; BSFA does not store full card numbers or card security codes. We keep payment references, purchased courses, amounts and payment status to provide access and maintain transaction records.

Where Stripe supplies billing country, region or city, we use those details together with account type and course purchases in internal sales reports to understand our audience and plan marketing. Billing location is not precise device location and may differ from where a learner lives. We do not infer age, gender or nationality from payment details. This reporting feature does not send customer lists to advertising platforms or add advertising trackers.

Testing passes and anonymous feedback

When you redeem a complimentary testing pass, we link that pass and its selected courses to your signed-in account so we can provide course access and prevent the code being used twice. This is not a payment and is not counted as sales revenue. Codes are stored as hashes rather than readable codes; newly generated codes may be held briefly in the issuing administrator's session for copying.

The separate feedback questionnaire stores ratings, the optional course title and device category you select, reported issue categories, your written answers and a submission date without the precise time. We do not attach your name, email, account ID, internet address or pass reference to those responses. Please do not write identifying details in your answers. Responses are visible only to authorised administrators and are not public course reviews or support tickets.

A website session temporarily checks the feedback form's security token and submission cooldown; these session checks are not stored with the feedback. Hosting providers may independently retain routine connection logs, and identifying details you voluntarily write may reveal who you are. “Anonymous” describes the feedback records shown to the BSFA review team, not a guarantee against identification in every circumstance. Use Contact if you want a personal reply. We retain feedback while it is useful for improving the service and reviewing issues.

Visitor chat assistant

If you choose to use our AI visitor-support chat, your messages and a short recent conversation history are sent to OpenAI to generate replies, together with public course information and approved support notes. This chat is intended for parents and visitors aged 18 or older. Please do not share passwords, card details or children's personal information. The assistant cannot see private student records or take payments. Replies can contain mistakes; confirm important details with the BSFA team.

BSFA does not create a permanent chat-transcript database. A limited recent history is kept in your website session and stops being used after 30 minutes of inactivity. You can clear it with “New conversation”. Session storage is also subject to our hosting provider's session-cleanup schedule. We keep short-lived message counters, including a keyed hash of your internet address, to limit abuse and costs. OpenAI requests use store: false, but this is not a promise of zero retention: OpenAI may retain abuse-monitoring logs under its own policies. See OpenAI's data controls. Our chat does not automatically send your enquiry to a human; use the contact page when you need a staff response.

How long we keep it

We keep your account and learning records for as long as your account is open, so that your progress, history and certificates remain available to you. If you ask us to close your account, we delete your personal information, except anything we are required to retain by law.

Newsletter subscriptions are kept until you unsubscribe. We keep a record of the unsubscribe itself so that we do not accidentally email you again.

Your choices

You may ask us to show you what information we hold about you, correct anything inaccurate, delete your account and its data, or stop sending you marketing email. You can update much of this yourself from your profile page, and for anything else, write to us and we will act on your request.

Changes to this policy

If we change how we handle your information — for example when payments or new features go live — we will update this page and change the "last updated" date above.

Contact

Questions, requests or concerns: admin@beyondschoolfutures.com, or use our contact form.