Privacy Policy
Your data protection rights and how we safeguard your information
Introduction and Data Controller
Novasummitadv operates as your trusted partner in financial education and budget management. We're committed to protecting your personal information while providing valuable learning resources. This policy explains exactly how we handle your data, what rights you have, and the steps we take to keep everything secure.
As the data controller, Novasummitadv is responsible for determining how and why your personal data gets processed. We take this responsibility seriously and have implemented comprehensive measures to ensure your privacy rights are respected under UK GDPR and Data Protection Act 2018.
Our registered address is Hargate Fields Farm, Egginton Rd, Hilton, Derby DE65 5FJ, United Kingdom. For any privacy-related questions, you can reach our data protection team at support@novasummitadv.com or call +447967222278.
Information We Collect
We collect several types of information to provide and improve our educational services. Here's what we gather and why:
Account Information
Your name, email address, phone number, and account preferences. We need this to create your learning profile and send important updates about our courses.
Learning Data
Course progress, quiz results, and learning preferences. This helps us personalise your educational experience and recommend relevant content.
Technical Information
IP address, browser type, device information, and how you interact with our platform. We use this to improve site performance and security.
Communication Records
Support conversations, feedback, and any correspondence with our team. This ensures we can provide consistent, helpful customer service.
How We Use Your Information
We process your personal data for specific, legitimate purposes that directly benefit your learning experience. Our primary uses include providing access to educational content, tracking your progress through courses, and communicating important updates about our services.
Your learning data helps us understand which topics need more explanation and where students typically struggle. This insight drives our content development, making our courses more effective for everyone. We also use technical information to identify and fix platform issues before they affect your experience.
For marketing communications, we only send information about new courses or educational resources that align with your expressed interests. You can opt out of these communications at any time through your account settings or by contacting us directly.
Legal Basis for Processing
Under UK GDPR, we must have a valid legal basis for processing your personal data. Most of our data processing relies on contract performance - we need your information to deliver the educational services you've requested.
We also process data based on legitimate interests, particularly for improving our platform security and developing better educational content. When we rely on legitimate interests, we've carefully balanced our business needs against your privacy rights.
For marketing communications and certain analytics, we seek your explicit consent. You have complete control over these consent-based activities and can withdraw permission at any time without affecting other services.
Data Sharing and Third Parties
We don't sell your personal information to anyone. However, we do work with carefully selected service providers who help us deliver our educational platform. These include hosting providers, payment processors, and email service providers.
All third-party processors are bound by strict contractual obligations to protect your data and use it only for specified purposes. We regularly review these partnerships to ensure they maintain appropriate security standards and data protection practices.
In rare circumstances, we may need to disclose information to comply with legal obligations, such as responding to court orders or assisting with legitimate law enforcement requests. We will notify you of such disclosures unless legally prohibited from doing so.
Your Privacy Rights
Under UK data protection law, you have several important rights regarding your personal information. We've made it straightforward to exercise these rights:
-
Right of Access
Request a copy of all personal data we hold about you. We'll provide this information within one month, usually much sooner. You can make this request through your account settings or by emailing us.
-
Right to Rectification
Correct any inaccurate or incomplete personal data. Most account information can be updated directly through your profile settings, but we're happy to help with any changes you can't make yourself.
-
Right to Erasure
Request deletion of your personal data in certain circumstances. We'll honour these requests while respecting any legal obligations that require us to retain specific information for defined periods.
-
Right to Data Portability
Receive your data in a structured, machine-readable format or have it transmitted to another service provider. This includes your learning progress and account information.
-
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes. We'll stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Data Security and Protection
We've implemented multiple layers of security to protect your personal information. Our technical measures include encryption of data in transit and at rest, regular security audits, and access controls that ensure only authorised personnel can view your information.
Our staff receive regular training on data protection principles and security best practices. We maintain strict policies about who can access personal data and under what circumstances. All access is logged and monitored for unusual activity.
While we take extensive precautions, no system is completely immune to security risks. In the unlikely event of a data breach that could impact your privacy, we'll notify you and relevant authorities within 72 hours as required by law.
Data Retention and Deletion
We keep your personal data only as long as necessary for the purposes we collected it. Active account information remains available while you use our services and for two years after your last login to accommodate users who take breaks from learning.
Learning progress data is retained for three years to support long-term educational tracking and course improvement. Communication records are kept for two years to ensure consistent customer service. Technical logs and security data are typically deleted after one year.
When retention periods expire, we securely delete personal data using industry-standard deletion procedures. Some information may be retained longer if required by legal obligations, but this will be clearly communicated to you.
International Data Transfers
While we primarily process data within the UK, some of our service providers operate in other countries. When we transfer data internationally, we ensure appropriate safeguards are in place through adequacy decisions, standard contractual clauses, or other approved transfer mechanisms.
We regularly review our international processing arrangements to ensure they comply with UK data protection requirements. Any transfers outside the UK are subject to the same high standards of protection as domestic processing.
Cookies and Tracking
Our website uses cookies to enhance your learning experience and analyse how our platform is used. Essential cookies are necessary for basic functionality like maintaining your login session and remembering your preferences.
We also use analytics cookies to understand which parts of our platform are most helpful and where students encounter difficulties. This information helps us improve our educational content and user experience. You can manage your cookie preferences through your browser settings.
We don't use tracking cookies for advertising purposes or share cookie data with advertising networks. Our focus is entirely on improving educational outcomes rather than commercial tracking.
Children's Privacy
Our services are designed for adults aged 18 and over. We don't knowingly collect personal information from children under 18. If we discover that we've inadvertently collected data from someone under 18, we'll delete this information promptly.
Parents or guardians who believe their child has provided personal information to us should contact our support team immediately. We'll work quickly to remove any inappropriate data and prevent future collection.
Updates to This Policy
We review this privacy policy regularly to ensure it reflects our current practices and legal requirements. When we make significant changes, we'll notify you via email and provide at least 30 days' notice before the changes take effect.
Minor updates that don't affect your rights or how we process data may be made without individual notification, but we'll always update the effective date at the top of this policy. We encourage you to review this policy periodically to stay informed about how we protect your privacy.
Contact Our Privacy Team
Email: support@novasummitadv.com
Phone: +447967222278
Address: Hargate Fields Farm, Egginton Rd, Hilton, Derby DE65 5FJ, United Kingdom
We typically respond to privacy inquiries within 48 hours