Privacy Policy
1. INTRODUCTION
This Privacy Policy explains how we collect, use, store, and protect your personal information when you interact with our website, services, programmes, workshops, or mailing list.
By using our website or providing your information, you confirm that you are over 13 years old.
Blue Jay Learning Ltd (referred to as “we”, “us”, or “our”) is the data controller responsible for your personal data.
If you have any questions, you can contact us at: houraamin@bluejaylearning.com
Please let us know if your personal information changes, so we can keep our records accurate.
2. WHAT WE COLLECT AND WHY
Personal data means any information that identifies you. We may collect and process:
a) Contact and Communication Data
Includes: name, email address, phone number, and messages you send us.
Why: To respond to enquiries, manage conversations, and support clients.
Legal basis: Our legitimate interests (to respond and keep records).
b) Customer and Payment Data
Includes: billing details, service bookings, invoices, and payment confirmations.
Payments are handled securely by our payment provider (e.g., Stripe) — we do not store your card details.
Why: To provide services you have purchased.
Legal basis: Contract (we can’t deliver services without this).
c) Programme, Workshop & Event Participation Data
Includes: attendance, communications, and access to learning materials.
Why: To deliver your learning experience and support participation.
Legal basis: Contract & legitimate interests.
d) Technical & Usage Data
Includes: IP address, browser type, device information, pages viewed, and site navigation patterns.
Collected automatically through analytics tools and cookies.
Why: To maintain our website performance and improve user experience.
Legal basis: Legitimate interests (to run our business and improve our services).
e) Marketing Preferences
Your preferences for receiving newsletters or updates.
Legal basis: Your consent (you can unsubscribe any time).
We Do NOT Collect
Sensitive personal data (e.g., health, race, religion, sexual orientation)
Criminal offence data
3. HOW WE COLLECT DATA
We collect data in the following ways:
You provide it directly (e.g., forms, programme sign-up, email contact)
Automatically via cookies and analytics on our website
From third-party platforms we use to run our business (e.g., payment processors, webinar platforms, CRM tools)
See our Cookie Policy for details on website tracking.
4. MARKETING COMMUNICATIONS
We will only send you marketing emails if:
You signed up to receive them, or
You’ve purchased from us before and didn’t opt out.
You can unsubscribe at any time using the link in our emails or by contacting us.
Unsubscribing from marketing does not affect essential service emails (e.g., booking confirmations, access instructions).
5. SHARING YOUR DATA
We only share your data when necessary to run our business, such as with:
Payment processors (e.g., Stripe)
Email/newsletter platforms (e.g., MailerLite/Mailchimp)
Scheduling & event platforms (e.g., Calendly / Zoom)
Cloud storage & document systems (e.g., Google Workspace / Notion)
Professional advisors (IT and system administration services, accountants, legal support if needed)
We do not sell your data, ever.
We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
6. INTERNATIONAL TRANSFERS
Some of the service providers we use to run our business are based outside the UK/EEA or store data on servers located internationally (for example, email platforms, cloud storage tools, scheduling and event software).
Because of this, your personal data may be transferred outside the UK/EEA. When this happens, we rely on the safeguards those providers have in place to protect your information. These safeguards commonly include:
Standard Contractual Clauses (SCCs) approved for international data protection; and/or
Participation in the UK–US Data Privacy Framework (where applicable); and/or
Data hosting in regions with recognised adequacy decisions.
We only use well-established service providers who demonstrate strong privacy and security practices and who are transparent about how they handle data.
7. DATA SECURITY
We take data protection seriously. We use technical and organisational measures to safeguard your data from loss, misuse, unauthorised access, or disclosure.
Only individuals who genuinely need your data to perform their role have access to it.
8. DATA RETENTION
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When deciding what the correct time is to keep the data for we look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.
For tax purposes the law requires us to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they stop being customers.
In some circumstances we may anonymise your personal data for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
9. YOUR RIGHTS
Under UK data protection law, you have several rights in relation to your personal data. These include the right to:
Request access to the personal data we hold about you
Request correction of any information that is inaccurate or incomplete
Request erasure of your personal data, in certain circumstances
Request restriction on how your data is used
Object to processing where we are relying on legitimate interests as the basis for using your data
Request data portability, which allows you to obtain and reuse your data across different services
Withdraw consent at any time, where we are relying on your consent to process your data (for example, email marketing)
You can read more about your rights on the ICO website:
https://ico.org.uk/for-the-public/your-rights/
If you would like to exercise any of these rights, please contact us at: houraamin@bluejaylearning.com
You will not be charged a fee for accessing your personal data or exercising your rights. However, we may charge a reasonable fee, or refuse to act, if your request is clearly unfounded, repetitive, or excessive. We will explain this clearly if it applies.
To protect your privacy, we may need to request specific information to confirm your identity before we share or update any data. We may also ask for further clarification to help us respond more effectively.
We aim to respond to all valid requests within one month. If your request is complex, or you have made multiple requests, we may need more time, but we will let you know.
If you are unhappy with how we handle your personal data, you have the right to make a complaint to the Information Commissioner’s Office (ICO): www.ico.org.uk.
We would appreciate the chance to resolve the matter with you first, so please contact us in the first instance if you have concerns.
10. LINKS TO OTHER WEBSITES
Our website may include links to external sites. We are not responsible for their privacy practices. We recommend reading their privacy policies.
11. COOKIES
We use cookies to understand website usage and improve your experience. You can manage or disable cookies in your browser settings. See our Cookie Policy for details.
