Griffinity

Legal

Privacy Policy

How Griffinity collects, uses, shares, and protects personal data when you use our courses, workshops, consulting services, and website.

Last updated: 28 July 2026

Griffinity (“we”, “us”, “our”) provides education and advisory services on AI ethics, AI governance, data privacy, and responsible data practice—particularly for hospitality and related sectors. This Privacy Policy explains our practices for the Griffinity website, learning platform, newsletter, and related services (together, the “Services”).

By creating an account, purchasing a course, submitting a form, or otherwise using the Services, you acknowledge this Policy. Where consent is required by law, we will ask for it separately.

1. Who we are (controller)

For personal data collected through the Services, Griffinity is the data controller (or equivalent under applicable law), unless we act as a processor for an organisation under a separate Data Processing Agreement—see our DPA at /legal/dpa.

Questions about this document: hello@griffinity.com. Postal / registered address details will be inserted once finalised.

2. Scope

This Policy covers personal data relating to learners, website visitors, newsletter subscribers, workshop attendees, consulting contacts, and administrators. It does not cover third-party sites linked from our content. Educational materials about privacy law are for training purposes and do not themselves create a client–attorney relationship.

3. Data we collect

3.1 Account and profile

  • Name, email address, password (stored hashed / via our auth provider)
  • Organisation / employer (if provided)
  • Role or job title (if provided)
  • Preferences such as marketing opt-in and terms acceptance timestamps

3.2 Learning and platform activity

  • Course enrolments, lesson progress, quiz attempts and scores
  • Certificate records and serial numbers where issued
  • Support messages and admin notes tied to your account

3.3 Transactions

  • Order history, product purchased, amount, currency, and status
  • Payment references from our payment provider (we do not store full card numbers on Griffinity servers)
  • Billing name and email as provided at checkout

3.4 Communications

  • Contact-form submissions and workshop/consulting enquiry details
  • Newsletter subscription email and source
  • Email delivery and engagement metadata from our email provider (where applicable)

3.5 Technical and cookie data

  • IP address, browser type, device type, approximate location derived from IP
  • Session identifiers and authentication cookies
  • Diagnostics and security logs needed to operate and protect the Services

See our Cookie Policy at /legal/cookies for categories and choices.

4. How we use personal data

  • Provide, operate, and improve the learning platform and account features
  • Process purchases, refunds, and entitlement to paid content
  • Issue certificates and verify completion where applicable
  • Respond to enquiries about courses, workshops, and consulting
  • Send transactional messages (receipts, password resets, important service notices)
  • Send marketing or insight emails only where permitted (consent or soft opt-in where lawful), with an unsubscribe option
  • Monitor abuse, fraud, security incidents, and platform integrity
  • Comply with legal obligations and enforce our Terms
  • Analyse aggregated, de-identified usage to improve curriculum and UX

5. Legal bases (where GDPR / UK GDPR apply)

  • Contract — to deliver the Services you request (account, courses, workshops)
  • Legitimate interests — security, product improvement, B2B outreach proportionate to context, defending legal claims
  • Consent — certain marketing and optional profile fields where required
  • Legal obligation — tax, accounting, responding to lawful requests

6. Sharing and processors

We share personal data only as needed to run the Services, including with:

  • Hosting, database, and authentication providers (e.g. managed cloud / Supabase-class infrastructure)
  • Payment processors (e.g. Paystack or successor providers) for checkout
  • Email and transactional messaging providers
  • CMS / media hosts used to deliver course media (where configured)
  • Analytics or error-monitoring tools if enabled (configured to minimise personal data)
  • Professional advisers (legal, accounting) under confidentiality
  • Authorities when required by law or to protect rights, safety, or security

We do not sell personal data. Course accounts and purchases are currently for individual learners; Griffinity does not provide an organisation dashboard or disclose learner progress to an employer through the platform. Data-processing roles for a separately contracted workshop or consulting engagement must be set out in its DPA, order form, or statement of work.

7. International transfers

Our providers may process data in multiple regions. Where we transfer personal data from the EEA/UK to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (or UK equivalent) and supplementary measures as required.

8. Retention

  • Account and learning records — while the account is active and for a reasonable period afterward (typically up to 24 months after last activity), unless a longer period is needed for certificates, disputes, or legal retention
  • Orders and invoices — as required for tax and accounting (often 5–7 years depending on jurisdiction)
  • Marketing lists — until you unsubscribe or we delete inactive contacts
  • Support and contact messages — typically up to 24 months unless needed longer for an ongoing matter
  • Security logs — typically 30–180 days unless investigating an incident

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), access controls, role-based admin access, and database access policies. Details are summarised in our Security Overview at /legal/security. No method of transmission or storage is perfectly secure; please use a strong unique password and protect your credentials.

10. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, object, port data, and withdraw consent. This version of the platform does not provide in-app account export, self-service account deletion, or self-service email change. To exercise rights or request an email update, contact hello@griffinity.com. We aim to acknowledge requests within 5 business days and complete them within 30 days unless law permits more time. Some requests may be limited where we must retain data for legal or security reasons, or where another person or organisation’s rights would be affected. You may also lodge a complaint with a supervisory authority.

11. Children

The Services are aimed at professionals and are not directed to children under 16 (or higher age required locally). We do not knowingly collect children’s data. If you believe we have, contact us and we will delete it.

12. Automated decision-making

We do not use solely automated decision-making that produces legal or similarly significant effects about you. Quiz scoring and progress tracking are functional learning features, not credit, employment, or legal determinations about you by Griffinity.

13. AI and training content

Griffinity teaches AI ethics and governance. Unless we expressly say otherwise in a product feature, we do not use your private account content or support messages to train public foundation models. Aggregated analytics may inform curriculum design. Do not upload unlawful, special-category, or third-party confidential data into free-text fields unless necessary and authorised.

14. Changes

We may update this Policy. Material changes will be indicated by updating the “Last updated” date and, where appropriate, notifying account holders by email or in-product notice. Continued use after the effective date constitutes acceptance where permitted by law.

15. Contact

Questions about this document: hello@griffinity.com. Postal / registered address details will be inserted once finalised.