Privacy and Data Protection Policy
What personal data we hold about learners, why we hold it, who else processes it, and what you can require us to do with it.
Last updated 7 August 2026
Who we are
Shift AI Technology Ltd, a company registered in England and Wales under company number 17159725 and trading as Deep Space Commodities, is the data controller for the personal data described in this policy. Our address is Unit 14, The Maltings Industrial Estate, Southminster, Essex, CM0 7EQ.
This policy is written against the UK GDPR and the Data Protection Act 2018. It describes the system as it actually works rather than in the general terms a template would use, because a description you cannot check against what the service does is not much use to you.
We are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions are handled directly by the company at info@spaceeconomy.education.
What we collect and why
We collect the data needed to sell you the course, teach you, assess you and certify you. It falls into six categories.
- Account data. Your name and email address, held so you can sign in and so we can contact you about your purchase and your access. Authentication is operated by Supabase. Your password is stored by Supabase as a hash; we never see it and we cannot recover it, which is why a forgotten password has to be reset rather than looked up.
- Certificate identity. The legal name you want printed on your certificate. This is collected and confirmed before your first module exam, because a certificate in the wrong name is worthless to whoever relies on it.
- Learning records. Which lessons you have watched and how far through, your activity on lesson quick checks and chapter practice quizzes, and every module exam attempt with its date, score and pass or fail outcome. We need these to unlock chapters in sequence, to show you your own progress, and to determine whether a certificate is due.
- AI tutor conversations. The messages you send to the tutor, the replies it gives, and the lesson and video position they relate to. These are stored so you can reopen a conversation later. The section below explains where they go while the reply is being generated.
- Billing records. What you bought, the amount, the date, the invoice number, the billing name and any company name you gave us. Payment is by bank transfer, so we see the payment reference on our own bank statement; we do not hold your bank details. If we add card payment, cards will be handled by Stripe, card numbers will never reach our servers, and we will store only the customer and payment references Stripe returns so a payment can be matched to your account.
- Operational records. Our hosting and infrastructure providers generate technical logs in the ordinary course of running the service, which can include IP addresses, request times and error records. We use these to keep the service running, to investigate faults, and to detect and stop abuse.
We do not ask for special category data such as health information. If you need extra time on an exam we apply it on request and we do not ask for medical evidence, which means we do not create a health record about you in the first place.
We do not buy personal data from third parties, we do not sell or rent it, and we do not use it to build advertising profiles.
Our lawful bases
Every use of your data rests on one of the lawful bases in Article 6 of the UK GDPR. These are the bases we rely on and what each one covers.
- Performance of a contract. Creating and running your account, delivering the lessons, running the AI tutor, recording your progress, marking your exams, issuing your certificate and taking payment are all necessary to provide the thing you bought.
- Legal obligation. We keep records of sales, invoices and payments because UK company and tax law requires a company to keep them.
- Legitimate interests. We rely on legitimate interests to keep the service secure, to prevent and investigate abuse of accounts and of the AI tutor, to look at aggregate patterns in which lessons and which exam questions cause difficulty so we can improve them, to respond to your enquiries, and to establish or defend legal claims. In each case we have asked whether the processing is necessary for that purpose and whether it would override your interests, and we have kept it to what the purpose actually needs.
- Consent. Very little of what we do runs on consent and we would rather say so than pad the list. We do not currently operate a marketing mailing list; the email we send is transactional, meaning invoices, receipts, password resets and notices about your access. If we introduce marketing email it will be opt-in, refusing will not affect your course access in any way, and you will be able to withdraw at any time. We do not use consent as the basis for anything you need in order to use the course, because refusing would then cost you something and would not be a real choice.
The AI tutor and OpenAI
The course includes an AI tutor that answers questions about the lesson you are watching. Learners ask about this more often than anything else in this policy, so it gets its own section rather than a line in a list.
When you send a message to the tutor, three things are sent to OpenAI so a reply can be generated: your message, the most recent turns of the current conversation so that the reply makes sense in context, and the context of the lesson you are on, which is the course title, the lesson title, your position in the video and the relevant part of the lesson transcript. Your name, your email address and your account identifier are not sent.
OpenAI processes that input, returns a reply, and acts as our processor in doing so. We use the OpenAI API under its business terms, which provide that data submitted through the API is not used to train its models. OpenAI is based in the United States, so this involves a transfer outside the UK; see the section on processing outside the UK below.
Your message and the tutor's reply are then written to our database against your account, along with the lesson and the point in the video, so that you can return to the conversation later. You can ask us to delete your tutor history at any time without closing your account.
The tutor is a study aid. Its answers are generated rather than reviewed by a person before you see them, and it can be wrong. Do not put anything into it that you would not want stored on your account, and do not treat what it says as professional advice.
Certificates and the public verification page
Certificates are deliberately verifiable by third parties, and that means a small amount of your personal data is published. You should know exactly what is published before you sit an exam.
Every certificate carries a unique identifier and a link to a public verification page. Anyone holding that identifier, normally because you have given them the certificate, can open the page without an account and without signing in. The page shows the name printed on the certificate, the course title, the date of issue, and whether the certificate is currently valid or has been revoked, with the date and reason if it has. It shows nothing else. It does not show your email address, your exam scores, your progress, your tutor conversations or anything about your billing.
The page cannot be reached by guessing. The identifier is a long random value, and there is no directory, index or search of certificate holders anywhere on the site. In practice your certificate can only be looked up by someone you have given it to.
We publish this because it is necessary to perform our contract with you. A certificate an employer cannot check independently does not do the job you paid for. If you would rather your name were not published in this way, do not request a certificate. If you have one and want it withdrawn, tell us and we will revoke it, after which the page reports it as revoked rather than valid. Revocation does not remove your name from the page; only erasure of your account does that, and the consequences of erasure are set out below.
Who else processes your data
We use a small number of established providers rather than building these things ourselves, because what we would build would be less secure, not more. This is the complete list of processors that touch learner personal data.
- Supabase. Our database, authentication and file storage. It holds your account, your learning records, your exam attempts, your tutor conversations and your billing records, and it stores the hash of your password.
- Cloudflare R2. Storage and delivery of the lesson videos. Video requests pass through it.
- Vercel. Hosting for the application itself. Every page and every API request is served through Vercel's infrastructure, so it processes request data in transit.
- OpenAI. Generates the AI tutor's replies, as described above.
- Google Workspace. Sends and receives our email, including invoices, receipts and account notices. It handles your name, your email address and the contents of those messages.
- Stripe. Not currently used. We intend to add card payment, and when we do, Stripe will take those payments and hold the card data. For some of what it does, including fraud prevention and meeting its own regulatory obligations, Stripe acts as a controller in its own right rather than as our processor.
Each of these is engaged under a written contract that requires them to process personal data only on our instructions, to keep it secure, and to help us meet our own obligations to you.
Processing outside the UK
Several of the providers above are based in the United States or operate infrastructure in more than one country, so some of your personal data is processed outside the United Kingdom.
Where that happens we rely on the transfer safeguards the UK GDPR permits: either the UK adequacy regulations covering the country concerned, or the International Data Transfer Agreement or the UK Addendum to the standard contractual clauses, as set out in each provider's data processing terms. If you want to know which mechanism applies to a particular provider, ask us and we will tell you.
How long we keep it
- Financial records, meaning invoices, payment records and the sales they relate to, are kept for six years from the end of the accounting period they fall in, because UK tax law requires it. This obligation survives a request to erase your account. We will delete the account and everything attached to it, but we cannot delete the record that a sale took place.
- Account data, learning records and certificates are kept for as long as your account exists. Because access to the course is lifetime, there is no point at which we would delete an account for inactivity; leaving for two years and coming back should find everything where you left it. If you want it gone, ask, and we will delete it.
- AI tutor conversations are kept alongside your account so you can return to them. They are deleted when the account is deleted, or sooner if you ask us to clear them.
- Operational logs are kept for the short retention periods our infrastructure providers apply to logging, and are not used to build any profile of you.
- Email correspondence about support, billing or a complaint is kept while we deal with the matter and for a reasonable period afterwards in case it is reopened, and is then deleted.
Your rights
The UK GDPR gives you the following rights over your personal data. Exercising them is free, and for most of them you do not have to give a reason.
- Access. You can ask for a copy of the personal data we hold about you and an explanation of what we do with it.
- Rectification. You can have inaccurate data corrected. This matters most for the name on your certificate, which you can ask us to correct at any time; we will reissue the certificate.
- Erasure. You can ask us to delete your account and the data attached to it. Read the next section before you do, because it has a consequence that cannot be undone.
- Restriction. You can ask us to stop using your data while a dispute about its accuracy, or about our lawful basis for holding it, is resolved.
- Portability. You can ask for the data you gave us, and the records generated by your use of the service, in a structured, commonly used, machine-readable format. In practice that is a file containing your profile, your progress, your exam attempts and results, and your tutor conversations.
- Objection. You can object to processing we carry out on the basis of legitimate interests. We will stop unless we can demonstrate compelling grounds that override your interests, and we will explain our reasoning if we do not stop.
- 1Write to info@spaceeconomy.education, ideally from the email address on your account. If you cannot, tell us which account you are asking about.
- 2Say which right you are exercising, or just describe what you want in your own words. You do not need to cite the legislation and we will not turn a request away for being phrased informally.
- 3We may ask you to confirm your identity, but only where we have a genuine doubt about it rather than as a matter of routine.
- 4We will respond within one month of receiving the request. If a request is genuinely complex we may extend that by up to two further months, which the UK GDPR allows, but we will tell you inside the first month that we are doing so and why.
Erasure and your certificate
This is the one place where exercising a right costs you something, so we would rather be blunt about it now than let you discover it afterwards.
Your certificate is verified against the record held with your account. If we erase your account, that record goes with it. The public verification page will no longer confirm the certificate, and anyone checking it will be told the certificate is not recognised. The PDF in your possession will still exist, but it will no longer be verifiable, and verifiability is the part that gives it value to an employer.
We cannot design around this. Keeping a verification record after erasure would mean keeping your name and your issue date, which is precisely the data you asked us to delete. Where an erasure request comes from someone who holds a certificate, we will confirm they understand this before we act, and then we will act. If you want a copy of your records, or a static PDF of your certificate, ask for it in the same message and we will provide it before deleting anything.
Cookies
We use cookies only to sign you in and keep you signed in. Supabase sets session and refresh cookies when you authenticate, and these are refreshed as you move around the site. They are strictly necessary: without them every page would forget who you are and the course would be unusable.
We do not use advertising cookies, we do not run third-party analytics, and there is no tracking pixel on the site. That is why you are not shown a cookie banner when you arrive. The consent requirement applies to non-essential cookies, and we do not set any. If that changes we will ask for your consent properly before setting them rather than assuming it from your continued use of the site.
Security
We are not going to publish a map of our defences, but we can describe their shape honestly.
- Traffic to and from the site is encrypted in transit, and data is encrypted at rest by our database and storage providers.
- Access to learner data is enforced at the database itself, so your records can be read by you and by us and not by another learner, rather than depending on the application remembering to check each time.
- Exam answer keys are never sent to the browser and marking happens on our servers, so results cannot be manufactured from the client.
- We take no card payments, so no card data reaches our systems. If we add card payment, it will be handled entirely by Stripe on the same basis. Passwords are stored as hashes by our authentication provider and are not visible to us.
- Administrative access to production data is limited to the people who need it to run the business, and is used for support and operational purposes only.
- The AI tutor is rate limited per account, which caps both the cost of abuse and the volume of data any single account can push through it.
Personal data breaches
If personal data we hold is lost, exposed or accessed without authorisation, we will investigate and contain it immediately.
Where the breach is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where it is likely to result in a high risk to you specifically, we will tell you directly and without undue delay, in plain language, setting out what happened, what data was involved, what we are doing about it and what you should do. We keep an internal record of every breach, including those we assess as not reportable, with the reasoning for that assessment, so the decision can be reviewed later.
Complaints
If you think we have handled your personal data badly, tell us first at info@spaceeconomy.education. It is usually the fastest way to get it put right, and our Complaints policy sets out how we handle it and how long we take.
You also have the right to complain to the Information Commissioner's Office, which is the UK's supervisory authority for data protection. You can do that at any time and you do not have to come to us first. The ICO can be reached at ico.org.uk/make-a-complaint or on 0303 123 1113.
Changes to this policy
We update this policy when what we do changes, and the date at the top changes with it. Where a change materially affects how we use your data, we will email account holders rather than relying on you to notice. Earlier versions are available on request.
Contact
Data protection questions, subject access requests and complaints: info@spaceeconomy.education. By post: Shift AI Technology Ltd, Unit 14, The Maltings Industrial Estate, Southminster, Essex, CM0 7EQ.
This policy is published by Shift AI Technology Ltd, trading as Deep Space Commodities, registered in England and Wales, company number 17159725. Unit 14, The Maltings Industrial Estate, Southminster, Essex, CM0 7EQ.
All policies