Legal · Data protection

    Read inFrançais

    Privacy Policy

    How Bespoke Learning collects, uses, shares, retains and protects personal information across its website, tutoring services and portal.

    Effective:
    5 August 2026
    Last updated:
    5 August 2026
    Version:
    BL-LEGAL-2026-08-05
    1

    Who is responsible and what this Policy covers

    Bespoke Learning Inc., 103-2727 Steeles Ave West, Toronto, Ontario M3J 3G9, Canada, is responsible for the personal information covered by this Policy. Privacy questions and rights requests may be sent to privacy@bespokelearning.io.

    This Policy covers our public website, enquiries, consultations, purchases, tutoring and intensive programmes, educational communications, and the Bespoke student or parent portal. A service-specific notice presented when information is collected supplements this Policy and controls if it gives more precise information.

    We apply this Policy alongside applicable law, including Canada’s PIPEDA and provincial requirements, the EU GDPR and UK GDPR where they apply, and Hong Kong’s Personal Data (Privacy) Ordinance. A mandatory local requirement prevails over an inconsistent statement.

    2

    Customers, students and schools

    The contracting customer and the student may be different people. A parent or guardian providing information about a student confirms authority to do so and must give the student age-appropriate notice. Adult students may ask us to separate their information from a parent account where legally and operationally appropriate.

    When we process information solely on a school’s documented instructions, the school may be the controller and its notice also applies. We will identify that arrangement where relevant. Tutors and authorised contractors may access only the information needed for their assigned work and are subject to confidentiality and data-protection duties.

    3

    Information we collect

    We collect information directly from you or the student, from an authorised parent, school or payer, automatically from the site or portal, and from service providers or public sources when necessary to verify a transaction, prevent abuse or respond to an authorised referral. Please do not send information that is not reasonably needed.

    CategoryExamples
    Identity and contactName, pronouns if provided, age or age range, parent/guardian details, email, phone, country, billing address and communication preferences.
    Account and transactionPortal identifiers, authentication and security events, purchases, invoices, bank-transfer references, currency, taxes and consent records. We do not ask for online-banking passwords.
    EducationalSchool, programme, subjects, learning goals, availability, assignments shared for review, tutor notes, attendance, progress, practice responses and feedback.
    Session and communicationsBooking messages, support requests, email, meeting metadata and, only with the notice and legal permission required, audio/video recording, transcription or summary.
    Accessibility or sensitiveLearning accommodations, disability, health or safeguarding information that you choose to provide and that is reasonably needed to support the student.
    Device and websiteIP address, browser, device, approximate region, referring page, pages and actions, cookie identifiers, error logs, security and bot-detection signals.
    Connected servicesCalendar or document identifiers and limited content or permissions when you deliberately connect an external account or use an integration.
    4

    Purposes and legal grounds

    Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact, especially because students may be minors. You may ask for information about that assessment. Where consent is the basis, it may be withdrawn prospectively without affecting prior lawful processing or service that genuinely requires the data for another legal ground.

    PurposeTypical legal ground where GDPR-style grounds apply
    Answer enquiries, form and administer the contract, book and deliver lessons, invoice and supportSteps at your request before contract; performance of contract; legitimate interests in customer service.
    Personalise teaching, keep progress notes and coordinate tutorsPerformance of contract; legitimate interests in effective, continuous education. Explicit consent or another lawful condition where sensitive data requires it.
    Record or transcribe a session for a stated educational or quality purposeConsent where required; otherwise contract or legitimate interests only when lawful, necessary and balanced. A specific notice is provided.
    Protect accounts, prevent fraud, keep audit records and enforce rulesLegitimate interests; legal obligation; establishment, exercise or defence of legal claims.
    Comply with tax, accounting, safeguarding, court and regulatory dutiesLegal obligation; vital interests where genuinely necessary.
    Measure and improve the websiteConsent for non-essential storage or tracking; limited legitimate interests for cookie-free, aggregate operational measurements where lawful.
    Send promotional email or create advertising audiencesConsent where required. In limited lawful cases, legitimate interests for existing-customer communications, always with an easy opt-out.
    5

    Recordings, transcription and AI-assisted tools

    Not every session is recorded. When recording, transcription or an AI-assisted feature is proposed, the meeting, checkout or feature notice explains the purpose, data involved, whether it is required or optional, and available alternative where required. We do not rely on silence as recording consent where affirmative consent is legally required.

    AI-assisted tools may help produce practice questions, summaries, lesson plans, feedback or administrative drafts. Output may be inaccurate and is subject to appropriate human review before it is relied on for a material educational or account decision. We do not use solely automated decision-making that produces legal or similarly significant effects on a student without a lawful basis, required safeguards and notice.

    We minimise identifiers sent to AI providers, use business/API configurations intended to restrict provider use of customer content where available, and contractually limit processing where we control the provider relationship. We do not promise that every optional third-party tool has identical terms; its specific notice and provider policy must be reviewed. We do not knowingly use a student’s session content to train a public general-purpose model without separate, informed permission.

    Private recording prohibited

    Customers, students and tutors must not secretly record or upload a session to an external AI or transcription service. Ask everyone involved and follow the law of each participant’s location.

    6

    Children and young people

    Our services are directed to families and students, including minors, but purchases and material account decisions must be made by an adult unless local law permits otherwise. We seek verifiable parental or guardian authorisation when required and use age-appropriate explanations.

    We collect only information reasonably needed for education, safety, billing and service administration. We do not knowingly use children’s personal information for behavioural advertising, sell it for money, or ask a child to disclose more than reasonably necessary. A parent or guardian may request access, correction or deletion, subject to the student’s developing autonomy, confidentiality, safety and applicable law.

    If we learn that information was collected from a child without required authorisation, we will restrict it and take reasonable steps to delete it unless retention is necessary to protect the child, comply with law or establish a legal claim.

    7

    Who receives information

    We disclose personal information only as reasonably necessary to authorised staff and tutors; a parent, guardian, school or payer with proper authority; and vetted providers supporting hosting, database, authentication, communications, video meetings, calendars, payment or banking, accounting, customer support, security, analytics, advertising and optional AI features.

    Providers used for a particular interaction may include Vercel; Supabase and portal infrastructure; Google services such as Workspace, Calendar, Meet, Analytics, Ads and reCAPTCHA; Microsoft services such as Clarity; Meta where marketing consent permits; Zoom; Cal.com; Brevo; Trustpilot; banks and Wise; and AI providers identified in the relevant feature notice. This list describes current categories and representative providers, not a promise that every provider processes every user’s data.

    We may disclose information to advisers, insurers, auditors, courts, regulators or law enforcement when lawfully required or reasonably necessary to protect rights and safety; and in a genuine financing, reorganisation or sale subject to confidentiality and continued protection. We do not sell personal information for money.

    Advertising disclosures

    With marketing consent, identifiers may be disclosed to advertising providers for measurement or audience services. Some laws call this “sharing” or a “sale” even when no money is exchanged. Reject marketing cookies, reopen Cookie Settings, send a recognised opt-out signal where supported, or email us to opt out.

    8

    International transfers

    Bespoke is based in Canada and serves students internationally. Information may therefore be accessed or stored in Canada, the United States, the European Economic Area and other countries where an authorised tutor or provider operates. Foreign authorities may have lawful access under their laws.

    Where a restricted transfer rule applies, we use an available lawful mechanism appropriate to the relationship, such as an adequacy decision, European Commission standard contractual clauses, the UK addendum or international data transfer agreement, contractual safeguards and supplementary security measures. You may request information about the applicable safeguard, subject to protection of confidential security terms.

    9

    Retention and deletion

    We retain information only while reasonably necessary for the stated purpose, a legal obligation, safety, dispute or legitimate record-keeping need. The criteria include service status, age of the student, sensitivity, limitation periods, tax rules, active disputes and whether the record can be de-identified.

    RecordNormal retention criterion
    Enquiries not becoming a customerUp to 24 months after the last substantive contact, unless you opt out sooner or a shorter period is required.
    Account, educational profile, tutor notes and progress recordsDuring the engagement and normally up to 24 months after the last service, then deleted or de-identified unless a legal or safeguarding need continues.
    Raw session recordingOnly for the disclosed purpose and ordinarily no more than 90 days; shorter where the purpose is completed, longer only with a documented need, notice and lawful basis.
    Transcript, summary or delivered feedbackDuring the engagement and normally up to 24 months after the last service, subject to the feature notice.
    Contracts, invoices, payments, tax and consent evidenceGenerally seven years after the relevant transaction or relationship, or the period required by applicable law.
    Security logs and support recordsNormally 12–24 months, extended only for an active incident, dispute or legal requirement.
    Marketing profileUntil consent is withdrawn, you object or the relationship is inactive under our review cycle; a minimal suppression record may be kept to honour opt-out.
    Analytics identifiersThe shorter of the configured provider period and the period stated in the Cookie Policy; non-essential identifiers require consent.
    10

    Security and incidents

    We use safeguards proportionate to the information and risk, including access controls, least-privilege practices, encryption in transit, provider review, authentication controls, backups, logging, confidentiality duties and incident procedures. No online system can be guaranteed perfectly secure.

    If a breach creates a risk requiring notification, we will investigate, contain and notify affected people and authorities within the time and with the information required by applicable law. Please report suspected unauthorised access to privacy@bespokelearning.io and do not include passwords or unnecessary sensitive information.

    11

    Your privacy rights

    Depending on your location and the circumstances, you may request access, a copy, correction, deletion, restriction, portability, information about use and recipients, withdrawal of consent, objection to legitimate-interest or direct-marketing processing, and review of a qualifying automated decision. Canadian and Hong Kong users have rights including access and correction; EU/EEA and UK users have the GDPR-style rights that apply to their situation.

    Send a request to privacy@bespokelearning.io. State the right, account email and enough detail to locate the record. We verify identity and authority proportionately and will not ask for unnecessary identity documents. We respond within the legally required period—commonly 30 days under GDPR or PIPEDA and 40 days for a Hong Kong data-access request—subject to lawful extensions and exceptions. We explain any refusal and available appeal or complaint.

    Rights are not absolute. We may retain information needed for another person’s rights, student safety, legal privilege, tax, fraud prevention, contract administration or legal claims. We do not discriminate for exercising a right, though deleting data essential to an optional or contracted function may make that function unavailable.

    12

    Marketing, cookies and opt-out signals

    Service messages about a booking, invoice, safety or account are not marketing. Promotional messages identify Bespoke and provide a working unsubscribe method. We honour consent and anti-spam requirements applicable to the recipient and keep a limited suppression record after opt-out.

    Non-essential analytics, replay, personalisation and advertising technologies remain off until affirmative consent under our global opt-in approach. Cookie Settings allows equal acceptance or rejection and category choices. We treat a technically recognisable Global Privacy Control signal as an opt-out of marketing or sale/sharing where legally required and technically supported. See the Cookie Policy for detail.

    13

    Questions and complaints

    Contact our privacy lead at privacy@bespokelearning.io or by post at the address above. We aim to acknowledge a complaint promptly, investigate fairly and explain our response. You may also complain to the Office of the Privacy Commissioner of Canada, the supervisory authority in your EU/EEA country, the UK Information Commissioner’s Office, Hong Kong’s Privacy Commissioner for Personal Data, or another competent local authority.

    If an EU or UK representative is legally required for the processing in question, current representative contact information will be provided in the relevant collection notice and on this page. Contacting Bespoke directly does not affect your right to approach an authority.

    14

    Changes to this Policy

    We may update this Policy to reflect law, services, providers or practices. The date and version identify the current text. A material change is announced by a prominent notice, email or portal message as appropriate before it takes effect. We seek fresh consent where a new purpose legally requires it; continued use is not treated as consent when affirmative consent is required.

    Contact us

    Bespoke Learning Inc.103-2727 Steeles Ave WestToronto, ON M3J 3G9, Canadalegal@bespokelearning.ioprivacy@bespokelearning.io+1 (647) 770-2074