Legal
Privacy Notice
Last updated: July 30, 2026
1. Who we are
GayleSolutions, Elmont, New York, United States, operates the Gayle Formation Theory (GFT) platform and is the data controller for personal data processed through it. Contact: pr@gaylesolutions.com.
2. Personal data we collect, why, and on what legal basis
| Category | Purpose | Legal basis |
|---|---|---|
| Account data (name, email, password hash, role, organization) | Create and secure your account; authenticate you | Performance of a contract |
| Learning data (course progress, assessment attempts, scores, credentials, ethics acknowledgments) | Deliver courses, grade assessments, issue and verify credentials | Performance of a contract |
| Submitted professional content (lesson plans, assessments, portfolio evidence) | Human review and certification decisions | Performance of a contract |
| Support messages and correspondence | Respond to enquiries and provide support | Legitimate interests |
| Usage, device data, and IP address (log and audit records) | Security, fraud prevention, abuse detection, product improvement | Legitimate interests |
| Order and billing records | Fulfil purchases, maintain accounting and tax records | Contract; legal obligation |
| Marketing contact details | Send updates you have asked for | Consent (withdrawable at any time) |
Card and payment details are collected and processed directly by Paddle as Merchant of Record; we do not receive or store full payment card data.
3. Student data is prohibited
The platform is not designed to store personally identifiable information about students. Practitioners must not upload student names, photos, contact information, or identifiable audio or video into portfolio evidence, lesson plans, or assessments. Automated scanning warns before submission, and we may remove content that violates this rule.
4. Who we share data with
- Merchant of Record — Paddle.com, for sale of our products, order processing, subscription management, payments, tax compliance, invoicing, and returns.
- Service providers / subprocessors — cloud hosting, database and file storage, authentication, and email delivery providers acting on our instructions.
- Certification reviewers — trained GFT reviewers who assess submitted evidence, under confidentiality obligations.
- Professional advisers — legal, accounting, and insurance advisers where necessary.
- Authorities — where required by law or to protect rights and safety.
We do not sell personal data.
5. Public credential verification
Issued credentials can be checked through our public verification tool, which displays the credential holder's name, credential level, issue date, and status. This is intrinsic to the purpose of a professional credential; contact us if you have concerns.
6. Retention
- Account and learning records: for the life of your account and 3 years after closure, so credentials can be verified and reissued.
- Issued credential records: retained for as long as the credential is presented as valid, so public verification remains reliable.
- Submitted portfolio evidence: 2 years after the certification decision, then deleted.
- Support correspondence: 2 years.
- Security and audit logs: 12 months.
- Order and tax records: 7 years, as required by law.
When data is no longer needed, we delete or irreversibly anonymise it.
7. International transfers
We are based in the United States and our providers may process data in the US and other countries. Where data is transferred from the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
8. Your rights
Subject to your local law, you may request:
- access to the personal data we hold about you;
- correction of inaccurate or incomplete data;
- deletion of your data;
- restriction of processing;
- a portable copy of data you provided;
- to object to processing based on our legitimate interests, including direct marketing;
- to withdraw consent at any time, without affecting prior processing.
Email pr@gaylesolutions.com and we will respond within one month. UK/EEA residents may also complain to their local supervisory authority. We do not use automated decision-making that produces legal effects; certification decisions involve human review.
9. Security
We apply appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, row-level security so records are only readable by authorised roles, role-based access control, hashed credentials, audit logging, and least-privilege access for administrators. No system is perfectly secure, but we review these measures regularly.
10. Cookies
We use strictly necessary cookies and local storage to keep you signed in and to maintain session security. Paddle sets cookies during checkout to process your order and prevent fraud. We do not use advertising cookies. You can clear or block cookies in your browser, though sign-in will not work without the essential ones.
11. Children
The platform is intended for education professionals. It is not directed at children, and we do not knowingly collect data from them.
12. Changes and contact
We will update this notice as our practices evolve and revise the date above. Questions or data subject requests: pr@gaylesolutions.com — GayleSolutions, Elmont, New York, USA.