Privacy Policy & Legal Notice
Section 01
Who We Are
DiplomaEdge ("we", "us", "our") operates the website at diplomaedge.com and provides IB exam preparation resources including video lessons, multiple choice questions, and extended response worksheets.
For the purposes of the EU General Data Protection Regulation (GDPR) and UK GDPR, DiplomaEdge is the data controller of the personal data you provide to us when creating an account or purchasing a subscription.
If you have any questions about how we handle your data, please contact us at privacy@diplomaedge.com.
Section 02
Data We Collect
We collect only the minimum personal data necessary to provide our service. Specifically, we collect and store the following directly:
- Name — to personalise your account
- Email address — to create and manage your account, send receipts, and communicate with you
- Phone number — optionally provided during registration, used for account verification and support
We do not store your payment or billing information. All payment processing is handled entirely by Stripe. We never see, transmit, or store your card number, bank details, or billing address. See Section 5 for more detail.
We may also receive limited technical data automatically, including your IP address, browser type, and pages visited, through our hosting infrastructure. This data is used solely for security and operational purposes and is not used for profiling or advertising.
Section 03
How We Use Your Data
We use the personal data we collect for the following purposes only:
- Account creation and management — to set up your account and allow you to log in
- Service delivery — to give you access to the lessons, quizzes, and worksheets included in your subscription
- Subscription management — to verify your active subscription and process renewals via Stripe
- Customer support — to respond to your questions and resolve issues
- Service communications — to send you important notices about your account, subscription, or material changes to these terms
- Security — to detect and prevent fraud or unauthorised access
We do not use your personal data for targeted advertising, sell it to third parties, or share it with any party not listed in Section 5.
Section 04
Legal Basis for Processing
Under the GDPR, we rely on the following lawful bases to process your personal data:
- Contract performance (Art. 6(1)(b) GDPR) — processing your name and email is necessary to fulfil the subscription agreement between you and DiplomaEdge.
- Legitimate interests (Art. 6(1)(f) GDPR) — we process limited technical data (such as server logs) to keep the platform secure and operational. We have carried out a balancing test and are satisfied our legitimate interests do not override your rights.
- Consent (Art. 6(1)(a) GDPR) — where we send optional marketing communications, we will ask for your explicit consent first. You may withdraw consent at any time.
Section 05
Third-Party Services
We use the following third-party services to operate DiplomaEdge. Each is a data controller or processor in their own right and is bound by their own privacy policies and, where applicable, GDPR-compliant data processing agreements.
| Service | Purpose | Data involved | Location | Transfer mechanism |
|---|---|---|---|---|
| DiplomaEdge VPS (Ghost platform) |
Account management, platform & content delivery | Name, email address, phone number, session data, progress data | Spain, EU | None required — data stays within the EU |
| Stripe | Payment processing & subscription billing | Name, email, billing address, payment card details | USA | EU Standard Contractual Clauses & Data Privacy Framework |
| Vimeo | Video hosting & playback | IP address, viewing interactions, browser data | USA | Controller-to-controller EU Standard Contractual Clauses |
Stripe — Payment Data. All payment and billing data is collected and stored directly by Stripe, Inc. DiplomaEdge never receives, processes, or stores your card number or banking information. Stripe is certified under the EU–US Data Privacy Framework and complies fully with the GDPR through its Data Processing Agreement. Stripe acts as an independent data controller for payment data and as a data processor for account-related data passed to it. You may review Stripe's full privacy practices at stripe.com/privacy.
Vimeo — Video Hosting. Our lesson videos are hosted on Vimeo. When you watch a video, Vimeo may collect technical data such as your IP address, browser information, and viewing interactions. Vimeo acts as an independent data controller for this data. Vimeo is based in the United States and participates in the EU–US Data Privacy Framework. We have executed controller-to-controller Standard Contractual Clauses with Vimeo as required for GDPR-compliant data transfers. You may review Vimeo's privacy policy at vimeo.com/privacy.
Note on international transfers. Both Stripe and Vimeo are US-based companies. Transfers of your personal data to the US are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an equivalent level of data protection to that required within the EEA.
Section 06
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Active accounts — your name, email, and phone number are retained for the duration of your subscription.
- Cancelled or expired accounts — we retain basic account data for up to 12 months after cancellation to facilitate reactivation or resolve disputes, after which it is permanently deleted.
- Legal obligations — certain transactional records may be retained for up to 7 years where required by tax or financial law.
Payment transaction records are retained by Stripe in accordance with their own data retention policies and applicable financial regulations. We do not control Stripe's retention of payment data.
Section 07
Your Rights
Under the GDPR and UK GDPR, you have the following rights regarding your personal data. You may exercise any of these rights by contacting us at privacy@diplomaedge.com. We will respond within 30 days.
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ("right to be forgotten").
Request that we limit how we process your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or for direct marketing.
Withdraw any consent you have given at any time, without affecting prior processing.
Lodge a complaint with your national supervisory authority.
If you are based in the EU or EEA, you may lodge a complaint with the supervisory authority in your country of residence. A full list of EU supervisory authorities is available at edpb.europa.eu. If you are based in the UK, you may contact the Information Commissioner's Office (ICO).
Section 08
Cookies
We use a minimal set of cookies necessary to operate the platform:
- Session cookies — used to keep you logged in. These are deleted when you close your browser.
- Authentication cookies — used to remember your logged-in state across sessions if you choose "Remember me".
We do not use tracking cookies, advertising cookies, or any analytics cookies that send data to third parties. Vimeo's embedded player may set its own cookies when videos load. You can review Vimeo's cookie practices at vimeo.com/cookie_policy.
You can control cookies through your browser settings. Disabling session cookies will prevent you from logging in.
Section 09
Intellectual Property & Content Rights
All content on DiplomaEdge is the exclusive intellectual property of DiplomaEdge. Unauthorised copying, distribution, or reproduction is strictly prohibited and may result in legal action.
All content available through DiplomaEdge — including but not limited to video lessons, written explanations, multiple choice questions, extended response worksheets, mark schemes, examiner tips, graphics, layout, and software — is the exclusive intellectual property of DiplomaEdge and is protected by copyright law.
What your subscription permits
A DiplomaEdge subscription grants you a personal, non-transferable, non-exclusive licence to access and use our content solely for your own private study. This licence is limited to the duration of your active subscription and does not transfer any intellectual property rights to you.
What is strictly prohibited
You may not, under any circumstances:
- Download, record, screenshot, or otherwise capture video lessons or written content for redistribution
- Share your login credentials with any other person
- Reproduce, copy, or duplicate any DiplomaEdge content on any other website, platform, social media, or document
- Sell, sublicense, or commercially exploit any DiplomaEdge content
- Use any DiplomaEdge content to create competing educational materials
- Remove or obscure any copyright notices or branding
Enforcement
DiplomaEdge actively monitors for unauthorised distribution of its content. Violations of these terms may result in immediate account termination without refund, and may give rise to civil and criminal liability under applicable copyright law, including the Copyright, Designs and Patents Act 1988 (UK), the EU Copyright Directive (2019/790), and equivalent legislation in other jurisdictions.
If you become aware of unauthorised use of DiplomaEdge content, please report it to legal@diplomaedge.com.
Section 10
Contact & Complaints
For any questions, requests, or concerns about your personal data or these terms, please contact us:
- Email: privacy@diplomaedge.com
- Response time: We aim to respond to all privacy requests within 30 days as required by GDPR.
If you feel your concern has not been adequately addressed, you have the right to lodge a complaint directly with your national data protection authority.
Have a question about your data?
We are committed to transparency and will respond to all privacy-related queries within 30 days.
privacy@diplomaedge.com