Who is responsible and what this Policy covers
Bespoke Learning Inc., 103-2727 Steeles Ave West, Toronto, Ontario M3J 3G9, Canada, is responsible for the personal information covered by this Policy. Privacy questions and rights requests may be sent to privacy@bespokelearning.io.
This Policy covers our public website, enquiries, consultations, purchases, tutoring and intensive programmes, educational communications, and the Bespoke student or parent portal. A service-specific notice presented when information is collected supplements this Policy and controls if it gives more precise information.
We apply this Policy alongside applicable law, including Canada’s PIPEDA and provincial requirements, the EU GDPR and UK GDPR where they apply, and Hong Kong’s Personal Data (Privacy) Ordinance. A mandatory local requirement prevails over an inconsistent statement.
Customers, students and schools
The contracting customer and the student may be different people. A parent or guardian providing information about a student confirms authority to do so and must give the student age-appropriate notice. Adult students may ask us to separate their information from a parent account where legally and operationally appropriate.
When we process information solely on a school’s documented instructions, the school may be the controller and its notice also applies. We will identify that arrangement where relevant. Tutors and authorised contractors may access only the information needed for their assigned work and are subject to confidentiality and data-protection duties.
Information we collect
We collect information directly from you or the student, from an authorised parent, school or payer, automatically from the site or portal, and from service providers or public sources when necessary to verify a transaction, prevent abuse or respond to an authorised referral. Please do not send information that is not reasonably needed.
| Category | Examples |
|---|---|
| Identity and contact | Name, pronouns if provided, age or age range, parent/guardian details, email, phone, country, billing address and communication preferences. |
| Account and transaction | Portal identifiers, authentication and security events, purchases, invoices, bank-transfer references, currency, taxes and consent records. We do not ask for online-banking passwords. |
| Educational | School, programme, subjects, learning goals, availability, assignments shared for review, tutor notes, attendance, progress, practice responses and feedback. |
| Session and communications | Booking messages, support requests, email, meeting metadata and, only with the notice and legal permission required, audio/video recording, transcription or summary. |
| Accessibility or sensitive | Learning accommodations, disability, health or safeguarding information that you choose to provide and that is reasonably needed to support the student. |
| Device and website | IP address, browser, device, approximate region, referring page, pages and actions, cookie identifiers, error logs, security and bot-detection signals. |
| Connected services | Calendar or document identifiers and limited content or permissions when you deliberately connect an external account or use an integration. |
Purposes and legal grounds
Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact, especially because students may be minors. You may ask for information about that assessment. Where consent is the basis, it may be withdrawn prospectively without affecting prior lawful processing or service that genuinely requires the data for another legal ground.
| Purpose | Typical legal ground where GDPR-style grounds apply |
|---|---|
| Answer enquiries, form and administer the contract, book and deliver lessons, invoice and support | Steps at your request before contract; performance of contract; legitimate interests in customer service. |
| Personalise teaching, keep progress notes and coordinate tutors | Performance of contract; legitimate interests in effective, continuous education. Explicit consent or another lawful condition where sensitive data requires it. |
| Record or transcribe a session for a stated educational or quality purpose | Consent where required; otherwise contract or legitimate interests only when lawful, necessary and balanced. A specific notice is provided. |
| Protect accounts, prevent fraud, keep audit records and enforce rules | Legitimate interests; legal obligation; establishment, exercise or defence of legal claims. |
| Comply with tax, accounting, safeguarding, court and regulatory duties | Legal obligation; vital interests where genuinely necessary. |
| Measure and improve the website | Consent for non-essential storage or tracking; limited legitimate interests for cookie-free, aggregate operational measurements where lawful. |
| Send promotional email or create advertising audiences | Consent where required. In limited lawful cases, legitimate interests for existing-customer communications, always with an easy opt-out. |
Recordings, transcription and AI-assisted tools
Not every session is recorded. When recording, transcription or an AI-assisted feature is proposed, the meeting, checkout or feature notice explains the purpose, data involved, whether it is required or optional, and available alternative where required. We do not rely on silence as recording consent where affirmative consent is legally required.
AI-assisted tools may help produce practice questions, summaries, lesson plans, feedback or administrative drafts. Output may be inaccurate and is subject to appropriate human review before it is relied on for a material educational or account decision. We do not use solely automated decision-making that produces legal or similarly significant effects on a student without a lawful basis, required safeguards and notice.
We minimise identifiers sent to AI providers, use business/API configurations intended to restrict provider use of customer content where available, and contractually limit processing where we control the provider relationship. We do not promise that every optional third-party tool has identical terms; its specific notice and provider policy must be reviewed. We do not knowingly use a student’s session content to train a public general-purpose model without separate, informed permission.
Private recording prohibited
Customers, students and tutors must not secretly record or upload a session to an external AI or transcription service. Ask everyone involved and follow the law of each participant’s location.
Children and young people
Our services are directed to families and students, including minors, but purchases and material account decisions must be made by an adult unless local law permits otherwise. We seek verifiable parental or guardian authorisation when required and use age-appropriate explanations.
We collect only information reasonably needed for education, safety, billing and service administration. We do not knowingly use children’s personal information for behavioural advertising, sell it for money, or ask a child to disclose more than reasonably necessary. A parent or guardian may request access, correction or deletion, subject to the student’s developing autonomy, confidentiality, safety and applicable law.
If we learn that information was collected from a child without required authorisation, we will restrict it and take reasonable steps to delete it unless retention is necessary to protect the child, comply with law or establish a legal claim.
International transfers
Bespoke is based in Canada and serves students internationally. Information may therefore be accessed or stored in Canada, the United States, the European Economic Area and other countries where an authorised tutor or provider operates. Foreign authorities may have lawful access under their laws.
Where a restricted transfer rule applies, we use an available lawful mechanism appropriate to the relationship, such as an adequacy decision, European Commission standard contractual clauses, the UK addendum or international data transfer agreement, contractual safeguards and supplementary security measures. You may request information about the applicable safeguard, subject to protection of confidential security terms.
Retention and deletion
We retain information only while reasonably necessary for the stated purpose, a legal obligation, safety, dispute or legitimate record-keeping need. The criteria include service status, age of the student, sensitivity, limitation periods, tax rules, active disputes and whether the record can be de-identified.
| Record | Normal retention criterion |
|---|---|
| Enquiries not becoming a customer | Up to 24 months after the last substantive contact, unless you opt out sooner or a shorter period is required. |
| Account, educational profile, tutor notes and progress records | During the engagement and normally up to 24 months after the last service, then deleted or de-identified unless a legal or safeguarding need continues. |
| Raw session recording | Only for the disclosed purpose and ordinarily no more than 90 days; shorter where the purpose is completed, longer only with a documented need, notice and lawful basis. |
| Transcript, summary or delivered feedback | During the engagement and normally up to 24 months after the last service, subject to the feature notice. |
| Contracts, invoices, payments, tax and consent evidence | Generally seven years after the relevant transaction or relationship, or the period required by applicable law. |
| Security logs and support records | Normally 12–24 months, extended only for an active incident, dispute or legal requirement. |
| Marketing profile | Until consent is withdrawn, you object or the relationship is inactive under our review cycle; a minimal suppression record may be kept to honour opt-out. |
| Analytics identifiers | The shorter of the configured provider period and the period stated in the Cookie Policy; non-essential identifiers require consent. |
Security and incidents
We use safeguards proportionate to the information and risk, including access controls, least-privilege practices, encryption in transit, provider review, authentication controls, backups, logging, confidentiality duties and incident procedures. No online system can be guaranteed perfectly secure.
If a breach creates a risk requiring notification, we will investigate, contain and notify affected people and authorities within the time and with the information required by applicable law. Please report suspected unauthorised access to privacy@bespokelearning.io and do not include passwords or unnecessary sensitive information.
Your privacy rights
Depending on your location and the circumstances, you may request access, a copy, correction, deletion, restriction, portability, information about use and recipients, withdrawal of consent, objection to legitimate-interest or direct-marketing processing, and review of a qualifying automated decision. Canadian and Hong Kong users have rights including access and correction; EU/EEA and UK users have the GDPR-style rights that apply to their situation.
Send a request to privacy@bespokelearning.io. State the right, account email and enough detail to locate the record. We verify identity and authority proportionately and will not ask for unnecessary identity documents. We respond within the legally required period—commonly 30 days under GDPR or PIPEDA and 40 days for a Hong Kong data-access request—subject to lawful extensions and exceptions. We explain any refusal and available appeal or complaint.
Rights are not absolute. We may retain information needed for another person’s rights, student safety, legal privilege, tax, fraud prevention, contract administration or legal claims. We do not discriminate for exercising a right, though deleting data essential to an optional or contracted function may make that function unavailable.
Questions and complaints
Contact our privacy lead at privacy@bespokelearning.io or by post at the address above. We aim to acknowledge a complaint promptly, investigate fairly and explain our response. You may also complain to the Office of the Privacy Commissioner of Canada, the supervisory authority in your EU/EEA country, the UK Information Commissioner’s Office, Hong Kong’s Privacy Commissioner for Personal Data, or another competent local authority.
If an EU or UK representative is legally required for the processing in question, current representative contact information will be provided in the relevant collection notice and on this page. Contacting Bespoke directly does not affect your right to approach an authority.
Changes to this Policy
We may update this Policy to reflect law, services, providers or practices. The date and version identify the current text. A material change is announced by a prominent notice, email or portal message as appropriate before it takes effect. We seek fresh consent where a new purpose legally requires it; continued use is not treated as consent when affirmative consent is required.