Legal
Privacy Policy
Last updated: 10 August 2026
This policy explains what personal information Ascendra collects, why we collect it, who we share it with, and the rights you have under UK data protection law.
1. Who we are
Ascendra is an online learning and exam-preparation service operated from the United Kingdom. For the purposes of UK data protection law we are the controller of the personal information described in this policy. You can reach us using the contact details in section 17.
2. Information we collect
We collect the following categories of information, where they apply to how you use the service:
- Account and profile information — such as your email address and any profile or study preferences you set, including the certifications you choose to study.
- Authentication information — credentials and session information used to sign you in and keep your account secure.
- Learning activity and progress — objectives studied, mastery and readiness indicators, and analytics derived from your activity.
- Exam and test activity — the tests you generate or sit, the answers you give, scores, timings and test history.
- User-generated inputs — questions, notes or other content you submit.
- AI feature interactions — the prompts or requests you send to AI-supported features, and records of usage used to apply fair-use allowances.
- Subscription status — your plan, entitlements, renewal status and related billing state.
- Transaction and payment-related information — records of purchases, invoices, amounts, currency and subscription identifiers.
- Device, technical and security information — information generated when you use the service, such as log and diagnostic data used for reliability and abuse prevention.
- Support communications — messages you send us and our replies.
Full payment-card details are handled by Stripe, our payment processor. Ascendra does not store your card number; we hold only the billing and subscription records needed to manage your plan.
3. How we use information
- To create and operate your account and provide learning functionality.
- To process subscriptions, payments, renewals, upgrades and cancellations.
- To provide AI-supported features you request.
- To measure usage and enforce fair-use quotas and plan entitlements.
- To personalise your learning, produce recommendations and generate analytics.
- To maintain security, prevent fraud and abuse, and diagnose faults.
- To provide customer support.
- To meet legal, accounting and regulatory obligations.
4. Lawful bases
- Contract — to provide the service you have signed up for, including accounts, learning features and subscription billing.
- Legitimate interests — to keep the service secure and reliable, prevent abuse and fraud, enforce usage allowances, and improve and develop our features, balanced against your rights and interests.
- Legal obligation — to comply with accounting, tax and other legal requirements.
- Consent — where we rely on it, for example for optional communications or any non-essential cookies or similar technologies. You may withdraw consent at any time.
5. Stripe
Payments are processed by Stripe. When you subscribe, payment and billing information is collected and processed by Stripe, which handles that information as a payment provider under its own privacy terms as well as on our instructions. Ascendra receives back the billing and subscription records it needs to manage your plan.
6. AI providers
Some Ascendra features are powered by artificial intelligence. Where you use those features, the content of your request — and, where needed to answer it, related study context — may be transmitted to third-party AI and infrastructure providers so the feature can be delivered. We use these providers only as necessary to provide the functionality you have asked for.
Please avoid entering unnecessary personal information, and in particular special-category or highly sensitive information, into AI prompts.
7. Service providers
We work with providers who process information on our behalf, which may include hosting, database, authentication, payment, email, analytics and AI infrastructure providers. They are permitted to use the information only to provide services to us and are bound by appropriate contractual obligations.
8. International transfers
Some of our processors may operate, or store data, outside the United Kingdom. Where personal information is transferred internationally, we rely on appropriate safeguards recognised under UK data protection law — for example adequacy regulations or standard contractual clauses with the UK addendum.
9. Retention
We keep personal information only for as long as it is reasonably necessary for the purposes described in this policy — principally for as long as your account is active — and afterwards where we need it for legal, accounting, tax, security or dispute-resolution reasons. When information is no longer needed, it is deleted or anonymised.
10. Security
We use reasonable technical and organisational measures to protect personal information, including access controls, encryption in transit and database-level authorisation rules. No online service can be completely secure, so we cannot guarantee absolute security, but we take our responsibilities seriously and will notify you and the regulator where required if a reportable breach occurs.
11. Your rights
Under UK GDPR you have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- request erasure of your information in certain circumstances;
- request that we restrict processing in certain circumstances;
- object to processing based on our legitimate interests;
- request portability of information you provided to us, where applicable;
- withdraw consent where our processing relies on consent.
To exercise any of these rights, contact us using the details in section 17. We may need to verify your identity before acting on a request.
12. Complaints to the ICO
If you are in the UK and believe your data protection rights have been infringed, you can complain to the Information Commissioner's Office (ICO). We would appreciate the chance to address your concern first.
13. Analytics
We use Plausible Analytics, an EU-hosted, privacy-focused analytics service, to understand how people find and use Ascendra. Plausible acts as our processor and the data is processed on servers in the European Union.
Our Plausible configuration does not use cookies, browser local storage, device fingerprinting or any other persistent identifier, and it does not follow you across other websites. It records aggregate measurements only: page URL, referrer, approximate country derived from your IP address (the IP address itself is not stored by us), and coarse browser, operating system and device-type information.
In addition to page views we record a small, fixed set of product events so we can measure the sign-up and study funnel: sign-up started and completed, course started, lesson started and completed, assessment and mock exam started and completed, pricing page viewed, checkout started, and subscription started. These events carry no personal data. The only additional information attached to them is a short, non-identifying code such as a certification code (for example SY0-701), an objective code (for example 1.2), the type of assessment, or a billing interval.
We do not send Plausible your name, email address, account identifier, question or answer content, recall responses, scores, weakness data or any other learner-generated information, and we do not use session recording, heatmaps or similar behavioural recording tools. Because the analytics events are not linked to an identifier, we cannot use them to identify you.
Our lawful basis for this processing is our legitimate interest in understanding aggregate usage of the service so we can operate and improve it. Because no cookies or similar technologies are stored on or read from your device for analytics, we do not ask for consent for it under the UK Privacy and Electronic Communications Regulations.
14. Cookies and similar technologies
Ascendra uses cookies, browser local storage or similar technologies where they are necessary to sign you in, keep your session secure and make core functionality work. Our analytics (section 13) is configured so that it does not set cookies or store or read any similar identifier on your device, so we do not show a cookie banner for it. If we ever introduce non-essential cookies or similar technologies, we will ask for your consent first.
15. Children
Ascendra is designed for people preparing for professional certification examinations. Where the service is used by children, additional data protection requirements can apply, and we will comply with applicable law — including any requirements relating to consent and to the design of services likely to be accessed by children. If you believe a child has provided us with personal information in circumstances that concern you, please contact us.
16. Changes to this policy
We may update this policy as the service changes or as legal requirements evolve. The "last updated" date at the top of this page shows when it was last revised, and we will tell you about material changes where required.
17. Contact
For privacy questions or to exercise your rights, contact gansoventures@gmail.com. You may also wish to read our Terms of Service and Refund & Cancellation Policy.