Privacy Policy

Last updated: 18/06/2018

At Stairway Learning, we take privacy very seriously. This notice explains how we treat your personal information when you give it to us and includes detail on your rights connected with this. This privacy notice is compliant with the General Data Protection Regulation (GDPR) and the UK’s Data Protection Act 2018.

Who we are - a controller

Our company, Sophist Education Limited is the data controller of the personal data you choose to provide to us. We are responsible for its security and for the way in which we use it. If you have any questions about this privacy notice or your rights, please contact us using the details set out below.

Contact Details

Our company is called Sophist Education Limited. Our registered address is 86-90 Paul Street, London, EC2A 4NE. We are registered with the Information Commissioner’s Office with registration number ZA430043. If you need to get hold of us for any reason in connection with your personal data, please email us at support@stairwaylearning.com You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns about data protection before you contact the ICO so please contact us in the first instance. This version of our privacy notice was last updated on 18th February 2019 and we might need to update it every so often.

The information we collect about you and why we collect it

We do not ask you to disclose any more personal information than is reasonably necessary to enable you to participate in any service that we offer and to improve our online services. Below, we list the types of data we collect and explain why we collect it from you.

Type of Data What the information contains How we use it
User Data Real name, email address, date of birth, phone number if you choose to call us at any point. So you can set up an account with us and use our services in accordance with our terms and conditions and so we can email you about your account and about your progress.
Parent Data Real name, email address of parent or guardian with responsibility for you. If you submit this information on your parent or guardian’s behalf, we will assume you have the authority to do that. If you are under 13, to verify that your parent or guardian consents to your use of this website and whether or not they consent to us sending marketing to you and otherwise to verify the payment method where you use a bank card belonging to your parent/guardian.
Usernames This will be the name that you choose if you wish to take part in any of our community discussion forums. We ask that you do not identify yourself (and we remind you of this when you choose your username). We will use your User Name to be able to link you with your Learning Data and Discussion Data. We ask that you do not identify yourself through your User Name. If you choose to do so, then we will take that as consent for your personal information to be published on our website.
Learning Data Includes any information that you submit on our website or otherwise, relating to your participation in our services and any scores or results which you obtain. In accordance with our terms and conditions
Discussion data Includes any information that you choose to publish on our community discussion forum. In accordance with our terms and conditions
Marketing Data any requests to receive our marketing emails or our newsletters and your email address So that we can send you our newsletter or marketing information at your request – you can opt out at any time by following the unsubscribe link in our message to you.
Payment Data Sums paid for our services So that we can keep a record of which of our users has paid for which services
Usage data Includes any general information about how you use our website. So that we can analyse how visitors use our website to help us improve it.
Technical data Includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website. So that we can analyse how visitors use our website to help us improve it and so that we can store your Learning Data before you have chosen to set up an account so that we are ready if you choose to set up an account.

How is your personal data collected?

We use different methods to collect data from and about you including through:

  1. Direct interactions. We collect the majority of your data when you choose to give this to us on our website or by email or otherwise in the course of using our services.
  2. Automated technologies or interactions. As you interact with our website, we may automatically collect Technical Data and Usage Data about your browsing actions and patterns. We collect this personal data by using cookies, and other similar technologies. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. For more information about the cookies we use, and how to disable them, please see our cookie policy
  3. Third parties. We may receive Technical and Usage Data about you from analytics providers such as Google and Mixpanel with servers based outside the UK (as set out in our Cookie Policy)

Disclosures of your personal data

We will need to share your personal data as below for the purposes set out in paragraph 2 above.

  1. All personal information is stored within the Google Cloud, with servers based in London.
  2. If you enter personal information in discussion with our website chat support service, our chat support service company will have a copy of that.
  3. Your User Name (which will not identify you) and your Discussion Data will be publically available. You should never include any information in the Discussion Data that will identify you.
  4. Your User Data will be shared with our email management company.
  5. We do not see the details of any bank cards as all Payment Data is handled by a secure payment company, Stripe - https://stripe.com/gb/privacy.
  6. We may share data with third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

International transfers

Certain companies who provide us with cookie analytic and IT support services have servers based in the US. This involves a transfer of your personal information outside the European Economic Area (EEA). We are required to ensure that when we store your personal data with companies like this, your personal data is as secure as it would be if it stayed in the UK. Both these companies are registered with the US Privacy Shield which confirms they offer the correct degree of security to your data even when it is not in the UK. If you would like more detail about this, please let us know.

Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to our employees, agents or business partners who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. If you have an account with us, we will automatically delete your account 6 years after your last login, unless you ask us to do that sooner. If you choose not to open an account with us, we will automatically delete any personal data we have collected through the website https://stairwaylearning.com from the date on which you last submitted any data. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

Your legal rights

You have the right in certain circumstances to:

  1. Request access to your personal data (a "data subject access request").
  2. Request correction of the personal data that we hold about you.
  3. Request erasure of your personal data.
  4. Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms.
  5. Request restriction of processing of your personal data.
  6. Request the transfer of your personal data to you or to a third party.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.