This notice adds detail to our Privacy Policy for people in the United Kingdom, the European Economic Area and Switzerland. It explains how legal name of the organisation — to be confirmed meets its obligations under the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). It doesn't change what we collect — the Privacy Policy covers that.
The data controller
legal name of the organisation — to be confirmed is the controller for the personal data described in our Privacy Policy. Contact: privacy contact email — to be confirmed.
When a partner community uses our services — for example publishing courses through Community Programs, or following its members' progress through Guild Teams — that community decides for itself what it does with the information we let it see, and is responsible for its own use of it.
Our legal basis for each use
| What we do | Legal basis |
|---|---|
| Signing you in with Discord and running your account on our portals | Legitimate interests — running the services you've chosen to use |
| Academy learning records, exams, grading and certificates | Legitimate interests — providing the training you signed up for, and certificates others can rely on |
| Public certificate verification pages | Legitimate interests — letting you prove your training, which only works if the check is public |
| Guild Teams: sharing your progress with a community | Consent — you give it by joining the team, and withdraw it by leaving. Sharing extra certificates or scores is a separate, optional consent |
| Volunteer applications, staff files, leave, quotas and reports | Legitimate interests — organising a volunteer team fairly and safely |
| Moderation, bans, appeals and reports | Legitimate interests — keeping our communities safe |
| Support tickets and their transcripts | Legitimate interests — helping you, and keeping a record of what was agreed |
| Bots reading messages; daily message counts | Legitimate interests — running community features and staff activity quotas |
| Wellbeing ("care") alerts to moderators | Vital interests and the safeguarding of individuals at risk — see below |
| Giveaways, events, economy rewards and payouts | Legitimate interests — running the community activities you take part in |
| Automatic announcement posts in our Discord | Legitimate interests — recognising members and keeping the community informed |
| Responding to legal requests | Legal obligation |
Where we rely on legitimate interests, we've weighed them against your rights. You can object at any time (see below), and we'll stop unless we have a compelling reason to continue — for example, keeping a moderation record needed to protect others.
Sensitive information
We don't ask for sensitive ("special category") information. The one place we may handle it is the wellbeing check: a message that suggests someone is in distress can reveal information about their health. We process it only to get a trained moderator to check on the person, keep it within the moderation team, and don't keep it longer than needed for that. Our condition for this is the protection of the vital interests of the person, and the safeguarding of individuals at risk.
Your rights
You have the right to:
- access the personal data we hold about you (a "subject access request");
- rectification of inaccurate or incomplete data;
- erasure ("the right to be forgotten"), where there's no overriding reason for us to keep it;
- restriction of our use of it;
- object to our use of it where we rely on legitimate interests;
- data portability — your data in a structured, machine-readable format;
- withdraw consent at any time where we rely on it (for Guild Teams, just leave the team or switch sharing off), without affecting what happened before.
We don't make decisions about you based solely on automated processing that produce legal or similarly significant effects.
How to use your rights
Email privacy contact email — to be confirmed, or open a support ticket in our Discord server. Tell us which right you're using and which services you've used. To protect you, we'll confirm you own the Discord account concerned — usually by asking you to message us from it.
We'll respond within one month. For complex requests we may extend this by up to two more months, and we'll tell you if we do and why. Using your rights is free unless a request is clearly unfounded or excessive.
Complaints
If you're unhappy with how we've handled your data, please talk to us first. You also have the right to complain to a data protection authority. Ours is data protection authority — to be confirmed (authority website — to be confirmed). If you live elsewhere in the EEA you can complain to the authority where you live or work; in Switzerland, to the Federal Data Protection and Information Commissioner (FDPIC).
International transfers
Our data is stored where our server is located — to be confirmed. Some of our service providers — Discord, Cloudflare and UnbelievaBoat — process data in the United States and elsewhere. Where personal data leaves the UK or EEA, we rely on an adequacy decision (such as the UK–US and EU–US data bridges, for certified providers) or the Standard Contractual Clauses approved for the purpose.
Children
Our services are for people aged 13 and over, in line with Discord's own rules. Where the law in your country sets a higher age for consenting to online services, we don't rely on consent from anyone under that age — the only consent-based use, Guild Teams, requires you to be old enough to give it where you live.
Data protection by design
We collect only what each feature needs. Access in our portals is limited by role, and actions are logged. Partner communities only ever see aggregate statistics about their public content — never who did what — unless a member chooses to join their team. Certificates show your name only because proving your training is the point of them.
Breaches
If a personal data breach is likely to put your rights at risk, we'll report it to data protection authority — to be confirmed within 72 hours of becoming aware of it, and tell you directly if the risk to you is high.
Contact
legal name of the organisation — to be confirmed · privacy contact email — to be confirmed