top of page

Privacy Policy

1. Introduction
The Learning Fort is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679), the Irish Data Protection Act 2018, and all other applicable laws and codes of conduct.
 
2. Who We Are — Data Controller
The Learning Fort is an Irish-based organisation offering free and paid subscription services to support child development in the Irish education system.

 
If you have any questions about how your data is handled, please contact us at the address above.
 
3. What Data We Collect

  • Information You Provide: When you register or purchase a subscription, we collect your name, email address, role (e.g., teacher, parent), and payment information. Payment transactions are processed securely by our payment processor — we do not store card details ourselves.

  • Usage Data: We collect information about how you use our platform, including pages visited, features used, and device/browser information. This is collected via cookies — see our Cookie Policy for full details.

  • Sensory Indicator Data: When using the TLF Sensory Indicator, you may input observational information about a child. We require all users (teachers and parents) to use non-identifiable names (e.g., pseudonyms, initials, or student IDs) when creating profiles. This information is used solely to generate the personalised output for that child. We do not collect, store, or process the true identity of any child. No data about children is retained on our systems beyond the active session.

 
4. Legal Bases for Processing
We process your personal data on the following legal bases under GDPR Article 6:

  • Contract performance (Article 6(1)(b)): Processing your name, email, and subscription details is necessary to provide the service you have purchased or registered for.

  • Legitimate interests (Article 6(1)(f)): We use usage data to improve our platform and services, where this does not override your rights and interests.

  • Legal obligation (Article 6(1)(c)): We may process data where required to comply with Irish or EU law.

  • Consent (Article 6(1)(a)): Where we rely on consent (for example, for marketing communications), you may withdraw this at any time by contacting us.

 
5. Third-Party Processors

We use the following third-party services which may process your data on our behalf. Each operates under its own privacy policy and GDPR-compliant data processing agreements:

  • Wix.com Ltd — our website platform. Data may be stored and processed by Wix within the EEA and in accordance with their privacy policy at wix.com/about/privacy.

  • Supabase — provides our database, user authentication, and application infrastructure. All user data processed via Supabase is securely hosted on servers in Ireland (West EU region), in compliance with strict EU data residency requirements.

  • Stripe — securely processes all payment and subscription transactions. We do not store payment card data on our servers.

 

We do not sell your data to any third party. We will only share your data beyond the above where required by law or with your explicit consent.
 
6. Data Storage and Retention
Your data is primarily stored within the European Economic Area (EEA). Where data is transferred outside the EEA, appropriate safeguards are in place in accordance with GDPR Chapter V.
We retain your account data for the duration of your subscription. If you request deletion of your account, your personal data will be permanently removed within 30 days of that request. Some data may be retained for a short period beyond this where required by law (for example, financial records for tax purposes, typically 7 years under Irish law).

Last updated August 2026

  • LinkedIn
  • Instagram
  • Facebook
bottom of page