Updated 15 August 2026

Privacy and GDPR Policy

How the platform handles personal data, learner records, payment events, and privacy rights.

Signing is unavailable while this document remains a draft. It must have a recorded professional review, approval date, and final version before it can be accepted.

Privacy approach

Daskerel collects only the information needed to provide accounts, paid access, learning progress, support, fraud prevention, payment processing, and platform security.

Account creation, membership delivery, learning progress, requested support, and learner-controlled CV workspace features are processed as necessary to provide the requested service or take steps before entering a contract. Billing, VAT, accounting, fraud-prevention, and statutory records are processed to meet legal obligations and establish or defend legal claims.

Platform security, service reliability, proportionate content-protection monitoring, and service improvement are processed under legitimate interests after balancing those interests against user rights. Optional marketing and optional AI-assisted CV drafting are activated only by the learner's clear choice; consent-based processing can be withdrawn without affecting earlier lawful processing.

Learner rights

Learners may request access, correction, deletion, restriction, portability, or objection where applicable under UK GDPR, EU GDPR, or other relevant privacy laws.

The European Commission describes GDPR rights including being informed, access, rectification, erasure, restriction, portability, and objection.

Privacy requests must be sent to privacy@cloudforgeacademy.co.uk. General support requests can be sent to support@cloudforgeacademy.co.uk. Daskerel responds without undue delay and normally within one calendar month; where UK GDPR permits an extension, the requester will be told within that first month and given the reason.

A person who is dissatisfied with Daskerel's response may complain to the UK Information Commissioner's Office through ico.org.uk or by calling 0303 123 1113. Daskerel asks for the opportunity to address the concern first, but this does not limit the right to complain to the ICO or seek another legal remedy.

Data categories

Expected data categories include name, email address, account identifier, subscription status, Stripe payment event references, course access records, mock test progress, support messages, consent preferences, security logs, and device or analytics events needed to operate the platform.

Payment card details should be handled by Stripe or another approved payment processor and should not be stored directly by Daskerel.

Contact and ordinary support submissions are retained for up to 400 days. Learning progress and account records are normally retained while the account is active and for up to 24 months after closure so the learner can recover evidence and Daskerel can resolve service issues.

Billing, VAT, invoice, and accounting records are retained for at least 6 years after the relevant financial period where UK tax or company law requires it. Security, fraud, and content-protection events are normally retained for up to 12 months, unless an active investigation, legal claim, or safeguarding concern requires a documented longer period.

CV drafts and selected evidence are retained while the learner uses the workspace and for up to 90 days after deletion or account closure for controlled recovery, then deleted or anonymised unless the learner asks for earlier deletion or law requires retention. Candidate applications, extracted CV text, screening notes, and interview scheduling data normally expire 180 days after the latest recruitment activity. Candidates may request access, correction, withdrawal, restriction, or earlier deletion through the privacy request service; a documented legal hold may delay deletion. Electronic agreements and signature audit evidence are retained for the life of the agreement and up to 6 years afterwards for contract and claim handling.

Adult virtual classes use booking, attendance, accessibility, participation-route, recording-choice, consent-notice-version, and delivery audit records to provide the requested class and protect learners. Approved conferencing providers may process display name, voice, image, chat, captions, transcript, device and meeting-security metadata. Recording is disabled by default; an approved recording is limited to booked attendees, expires within 90 days, and remains subject to earlier withdrawal, safeguarding, dispute, or legal-hold review.

Content-protection monitoring

To protect paid materials and investigate account sharing, scraping, bulk extraction, or unauthorised distribution, the platform may record policy version and acceptance time, protected content identifiers, download events, trace IDs, rate-limit outcomes, and privacy-hashed request fingerprints.

Raw passwords, payment-card data, page text typed by learners, private study notes, keystrokes, camera data, and microphone data are not collected for content-protection monitoring.

Daskerel limits this monitoring to necessary security and contractual purposes, applies retention controls, restricts owner and security access, documents the legitimate-interests assessment where relied upon, and explains significant account decisions with a review route.

Processors and retention

Current production processors may include AWS for hosting and data storage, Stripe for payment processing and billing portal access, Resend for transactional email, and Google Workspace for official mailbox operations.

When a learner deliberately uses optional AI-assisted CV drafting, Daskerel sends OpenAI only the learner name, target role, selected evidence, and drafting instructions needed to generate the requested draft. Learners should not include special-category data, secrets, third-party confidential information, or unrelated personal data. AI output remains a draft for learner editing and human review and is not used as the sole basis for an employment or access decision.

Interview recordings remain local to the learner's browser tab and are not uploaded by the rehearsal feature. Optional dictation and voice commands use the browser's speech-recognition service only after a separate learner opt-in; depending on the browser and operating system, microphone audio may be processed by that provider under its own service and privacy terms. Daskerel receives the resulting dictated text or recognised command, not the rehearsal media, and learners can use every core rehearsal control without enabling the speech service.

For an explicitly recorded adult virtual class, the approved conferencing or private media provider stores the raw media. Daskerel stores the controlled provider link, attendance, consent notice and expiry metadata. A learner may decline or withdraw recording consent before the attendance register is finalised and receive the stated non-recorded participation route. Recording links are re-authorised against current paid access and attendance each time they are opened.

Some processors may process data outside the United Kingdom. Before such a transfer, Daskerel uses an applicable UK adequacy regulation or approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment and appropriate technical and organisational controls. Processor access is limited by contract to documented service instructions.

Retention is reviewed by data category and purpose rather than kept indefinitely. When a retention period ends, records are securely deleted or irreversibly anonymised unless a legal hold, active dispute, fraud investigation, tax obligation, or safeguarding duty requires documented continued retention.

Launch note

This page is a production-readiness template. It should be reviewed against the final business entity, domain, payment setup, processors, jurisdictions, and customer support process before full commercial launch.