← Back to home

Privacy Policy

Last updated: April 2026

1. Who we are

Nodus Learning operates the website noduslearning.com and provides curriculum resources and CPD services to primary schools in the United Kingdom. In this policy, "we", "us" and "our" refers to Nodus Learning.

If you have any questions about this policy or how we handle your data, please contact us at hello@noduslearning.com.

2. What data we collect

We collect the following categories of personal data:

  • Account data: your email address, password (stored as a secure hash), school name, and school postcode when you register.
  • Usage data: which units you have accessed, when you log in, and which lesson slides you view. We use this to provide and improve the service.
  • Payment data: payment processing is handled by Stripe. We do not store card numbers or full payment details. We receive a record of completed transactions including amount, date, and the unit purchased.
  • Communications: if you contact us by email, we retain a copy of that correspondence.
  • Technical data: IP address, browser type, and device information collected automatically when you use the service. This is used for security and service reliability.

3. How we use your data

We use your personal data to:

  • Create and manage your account
  • Provide access to purchased curriculum units and CPD sessions
  • Process payments and issue receipts
  • Send transactional emails (e.g. account confirmation, purchase receipts)
  • Respond to support enquiries
  • Improve and develop the service
  • Comply with our legal obligations

We will only send you marketing communications if you have explicitly opted in. You can unsubscribe at any time.

4. Legal basis for processing

We process your personal data under the following lawful bases under UK GDPR:

  • Contract: processing necessary to provide the service you have purchased or registered for.
  • Legitimate interests: to improve the service, detect fraud, and ensure security.
  • Legal obligation: where we are required to process data to comply with law.
  • Consent: for optional communications such as product updates and newsletters.

5. Data sharing

We do not sell your personal data. We share it only with the following third-party service providers, who process it on our behalf:

  • Supabase — our database and authentication provider. Data is stored in their EU (London) region. Supabase privacy policy.
  • Stripe — our payment processor. Stripe handles all card data under PCI DSS compliance. Stripe privacy policy.
  • Vercel — our hosting provider. Your requests are served from Vercel infrastructure. Vercel privacy policy.

All providers are contractually bound to process your data only on our instructions and in compliance with UK GDPR.

6. Data retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or tax purposes (typically 7 years for financial records).

Technical logs are retained for up to 90 days for security and debugging purposes.

7. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data ("right to be forgotten"), subject to legal obligations.
  • Restriction — ask us to restrict how we process your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email hello@noduslearning.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use essential cookies to maintain your login session. We do not currently use advertising or analytics cookies. If this changes, we will update this policy and request your consent.

9. Children's data

Nodus Learning is intended for use by teachers and school staff. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us immediately at hello@noduslearning.com.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.