Privacy Policy

Last updated: 15th March 2025

At cortex-gleam, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information when you interact with our platform and services.

We're committed to transparency about our data practices. If something isn't clear here, reach out and we'll explain it properly.

Who We Are

Cortex-gleam operates as an educational platform focused on user interface design training. We're based at 36-42 Northumberland St, Newcastle upon Tyne NE1 7DE, United Kingdom. Our programmes help people build practical skills in UI design through structured learning experiences.

When we refer to "we," "us," or "our" in this document, we mean cortex-gleam and our operational team who manage the platform, course delivery, and student support services.

Information We Collect

Information You Provide Directly

When you register for our programmes or contact us, we collect the information you choose to share:

  • Contact details: Your name, email address, phone number, and postal address
  • Account information: Username, password (encrypted), and profile preferences
  • Educational background: Previous experience, skill level, and learning goals when you enrol
  • Payment information: Billing details processed through secure payment providers (we don't store full card numbers)
  • Communications: Messages you send us through contact forms, email, or support channels

Information We Collect Automatically

Like most websites, we gather certain data automatically when you use our platform:

  • Usage data: Pages visited, time spent on lessons, course progress, and interaction patterns
  • Device information: Browser type, operating system, IP address, and device identifiers
  • Technical data: Access times, referring websites, and error reports that help us fix problems
  • Learning analytics: Quiz results, project submissions, and completion rates to track your progress

Information From Third Parties

Occasionally, we receive information from external sources:

  • Payment processors confirming transaction details
  • Analytics services providing anonymized usage patterns
  • Social media platforms if you choose to connect your account

How We Use Your Information

We use the information we collect for specific purposes that directly relate to delivering our educational services:

Service Delivery: We need your information to provide access to courses, track your progress, and ensure you can complete your learning journey. This includes processing enrollments, managing your account, and delivering course materials.

Purpose Data Used Legal Basis (UK GDPR)
Course enrollment and delivery Contact details, payment info, learning data Contract performance
Customer support Contact details, support messages, account data Contract performance
Platform improvement Usage data, technical information Legitimate interest
Marketing communications Email address, preferences Consent (you can opt out)
Legal compliance Transaction records, identity verification Legal obligation

We'll contact you about your course, important updates, and technical issues. If you've agreed to receive them, we'll also send programme announcements and educational content we think you'll find useful. You can unsubscribe from marketing emails anytime.

Data Sharing and Disclosure

We don't sell your personal information to anyone. That's not our business model, and it never will be.

We do share certain information with trusted service providers who help us run the platform:

  • Payment processors: To handle course payments securely
  • Email service providers: To send course materials and communications
  • Cloud hosting services: To store course content and platform data
  • Analytics providers: To understand how students use the platform (anonymized where possible)

These partners are contractually required to protect your data and can only use it for the specific services they provide to us.

Legal Requirements: We may disclose your information if required by law, court order, or government regulation. We'll notify you about such requests unless legally prohibited from doing so.

Your Privacy Rights

Under UK data protection law, you have several rights regarding your personal information. Here's what you can do and how to do it:

Access Your Data

Request a copy of all personal information we hold about you. We'll provide this in a readable format within one month.

Correct Inaccuracies

Update or correct any information that's wrong or outdated. You can do this directly in your account settings or by contacting us.

Delete Your Data

Ask us to remove your personal information from our systems. Some data may need to be retained for legal or legitimate business purposes.

Restrict Processing

Limit how we use your data in certain circumstances, such as when you're contesting its accuracy or questioning our lawful basis.

Data Portability

Receive your data in a structured, commonly used format so you can transfer it to another service provider if you choose.

Object to Processing

Oppose our use of your data for certain purposes, particularly direct marketing or processing based on legitimate interests.

To exercise any of these rights, email us at support@cortex-gleam.com with your request. We'll respond within one month and verify your identity before processing requests that involve sensitive data access or deletion.

How We Protect Your Information

We take data security seriously and implement multiple layers of protection:

  • Encryption: All data transmitted between your browser and our servers uses TLS encryption
  • Secure storage: Personal information is stored on encrypted servers with restricted access
  • Access controls: Only authorized team members can access personal data, and only when necessary
  • Regular audits: We review our security practices and update them as new threats emerge
  • Password protection: We hash and salt all passwords using industry-standard methods

Despite our best efforts, no system is completely secure. If we detect a data breach that poses a risk to your rights, we'll notify you and the relevant authorities as required by law.

Data Retention

We keep your information only as long as needed for the purposes described in this policy:

  • Active accounts: Data retained while your account is active and for a reasonable period afterward
  • Course records: Learning progress and certificates kept for seven years after completion for verification purposes
  • Financial records: Transaction data retained for six years to comply with tax and accounting regulations
  • Marketing data: Removed immediately when you unsubscribe from communications
  • Support communications: Kept for three years to help resolve ongoing or future issues

When data is no longer needed, we securely delete or anonymize it so it can't be linked back to you.

Cookies and Tracking

Our website uses cookies – small text files stored on your device that help the site function properly and improve your experience.

Types of Cookies We Use

  • Essential cookies: Required for the platform to work – logging in, remembering your preferences, and maintaining your session
  • Performance cookies: Help us understand how visitors use the site so we can improve it (anonymized data)
  • Functional cookies: Remember your choices like language preference and accessibility settings

You can control cookies through your browser settings. Blocking essential cookies may prevent some features from working properly.

International Data Transfers

Our primary servers are located in the United Kingdom. However, some of our service providers operate servers in other countries. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard contractual clauses approved by UK authorities
  • Adequacy decisions recognizing equivalent protection standards
  • Additional security measures for transfers to countries without adequacy decisions

We only work with providers who commit to protecting your data according to UK standards.

Children's Privacy

Our services are designed for adults aged 18 and over. We don't knowingly collect information from children under 18 without parental consent.

If you're under 18 and interested in our programmes, please have a parent or guardian contact us. If we discover we've collected data from a child without proper consent, we'll delete it promptly.

Changes to This Policy

We update this policy occasionally to reflect changes in our practices or legal requirements. When we make significant changes, we'll notify active users by email and update the "last updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of our platform after changes indicates your acceptance of the updated policy.

Complaints and Regulatory Authority

If you're unhappy with how we've handled your personal information, please contact us first so we can try to resolve the issue.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk

Contact Us About Privacy

If you have questions about this privacy policy or how we handle your data, get in touch:

Email: support@cortex-gleam.com

Phone: +44 7855 521964

Post: cortex-gleam, 36-42 Northumberland St, Newcastle upon Tyne NE1 7DE, United Kingdom

We aim to respond to privacy inquiries within five working days.