TERMS
The following terms are used throughout the document:
PERSONAL DATA
We collect and store personal data that can identify you as an individual in order to provide our services. This data is willingly provided to us by you. We operate under the General Data Protection Act of the United Kingdom, and as such, data is stored, accessed and handled in ways defined by GDPR.
Data you choose to provide by creating an account
When creating an account, you agree to provide us with data that can identify you on our servers. This includes:
First and Last Names. When you sign up you provide us with your first name and last name.
Email Addresses. When you sign up, you provide us with an email address so we can validate your account, send communications and this is used to log in.
Passwords. When you create an account, you provide us with a password to access the account. We hash this password with a cryptographically secure algorithm and store it on our servers.
Data you choose to provide but is not required to create an account
When creating an account, you may optionally provide us with additional data that may help us to provide services for you. You do not need to provide this data to use our services. This data includes:
School Names.
School Addresses.
School Postcodes.
Data required to use the service
In order for the website to function, we use a number of tracking cookies to ensure you get the best experience. A session cookie tracks the user that is logged in at a given time. This allows you to access account features without repeatedly entering your password. The session cookie stores a reference to a server token identifying your account ID, it does not collect or store any personal data, and is reset when you log out or your browser session expires.
We also make use of Cloudflare protection when you sign up for an account. This collects information about your system and interactions with the sign-up web page in order to differentiate a real human from a bot. Cloudflare's privacy policy can be found here: https://www.cloudflare.com/en-gb/privacypolicy/ .
As per standard security practice, we log all IP addresses for connections to our servers. We cannot trace these back to any individual. and logs will never be shared unless at the request of applicable authorities.
WHAT WE DO WITH YOUR DATA
We will never share your data with other platforms or on our platform without explicit consent, which you may revoke at any time. However, your data is used to provide our services. Data you provide to us is used to:
Provide our services
We use personal information to: Allow you to access your user area, Allow you to sign up for events and courses, Allow you to download restricted content.
With your permission, we use personal information to: Showcase your participation in our events, Show testimonials about our services.
Create and maintain a secure and trusted platform
Your data is used to: Identify and prevent spam and mallicious use of the website.
SHARING AND DISCLOSURE
We occasionally share data with our partners: Goldsmiths University of London, CAABU and Qatar Foundation International, in order to show sign-up rates, geographical distribution of users and feedback and uptake of resources we provide.
We will never share any account data with any other platforms without your permission, and will never share personally identifiable information.
YOUR RIGHTS
You may exercise any right as defined by content in this policy, and by applicable law in your jurisdiction. You may submit requests as defined by applicable law by emailing l.hameed@gold.co.uk. We may ask for verification you are the owner of the data before we complete your request.
Managing your information
Data held on our servers relating to your account can be managed under your account homepage. You may also submit requests to manage data not editable here.
Data access
In some jurisdictions, as applicable by law, we may be required to provide you with a copy of all the data held on our servers relating to your account. This information is generally available on your account management page; however, any data not visible here can be requested. We cannot provide copies of plain text passwords as we do not store them.
SECURITY
Although we take every precaution to ensure your account data is secure, security cannot be guaranteed. We use password-grade hashing for your passwords to ensure that; in the event of a security incident, an attacker cannot gain access to your account, nor identify your password. Of course, it is still good practice to use different passwords for different sites.