Privacy Policy

Last updated: 24 July 2026

This policy explains what personal data On-Off Academy collects, why, who we share it with, and the rights you have. It covers both the businesses that subscribe to Academy and the people those businesses train.

1. Who we are

On-Off Academy is a training platform operated by On-Off Group UK Ltd (“we”, “us”, “On-Off”), a company registered in England and Wales, company number [company registration number], registered office [registered address]. If you have any question about this policy or your data, contact us at privacy@onoffgroup.com.

2. Controller and processor — an important distinction

Academy is a business-to-business service. Who is responsible for personal data depends on whose data it is:

  • For account and billing data (the admin who signs up, and payment records), On-Off is the data controller.
  • For the people a business trains — the staff a subscribing company adds and assigns courses to — the subscribing company is the controller and On-Off is the processor, handling that data on the company’s instructions to provide the service. Businesses using Academy are responsible for having a lawful basis to add their staff and for telling their staff how their data is used. We make a data processing agreement available to subscribing companies on request.

3. What we collect and why

DataWhy we hold it
Admin name, work email, company nameTo create and secure your account and log you in (we use one-time email login links — no passwords).
Plan, subscription status, billing currency, Stripe customer/subscription referencesTo manage your subscription and access. We never see or store card numbers — payment details are handled entirely by Stripe.
Staff name, work email, and optional branch/location (added by a subscribing company)To assign courses, send course links, and report completion to the company.
Course assignments, completion status, scores, and survey responses (e.g. confidence ratings, feedback)To run the training, produce the results dashboard, and let the company measure the effect of training.
Content you upload to build a course (documents, notes, PDFs)To generate a course from your material using AI (see section 5).
Technical data: IP address, browser type, and functional browser storageKept in server logs for security and to keep you signed in and remember preferences (see section 7).

4. Our legal bases (UK/EU GDPR)

  • Performance of a contract — to provide the service you or your employer subscribed to, including running courses and sending course, login and reminder emails.
  • Legitimate interests — to secure the service, prevent abuse, and improve how it works, balanced against your rights.
  • Legal obligation — to keep records we are required by law to keep, such as for tax.
  • Consent — where we ask for it, such as optional feedback. You can withdraw consent at any time.

5. AI and your uploaded content

When you create a course from your own material, the text of that material is sent to a third-party AI provider (see section 6) to draft the course, and course text is sent to a text-to-speech provider to produce narration. We use these providers’ business APIs, under terms which state they do not use the content to train their models. You should not upload material you do not have the right to use, or that contains personal data you have no lawful basis to process. Do not upload special-category data (such as health information) into course-creation.

AI-generated course drafts may contain mistakes. You review and edit every course before publishing it, and you are responsible for the content you publish to your team.

6. Who we share data with (subprocessors)

We do not sell personal data. We share it only with the service providers we need to run Academy:

ProviderPurposeWhere
StripePayment processing and subscription managementEU / US
Brevo (Sendinblue)Sending transactional email (login links, course invites, reminders)EU
ElevenLabsGenerating course narration from course textUS
OpenAI, Anthropic, Google, Microsoft AzureDrafting and checking courses from uploaded materialUS / EU
OVHHosting the application and databaseEU / Canada

We may also disclose data if required by law, or to protect our rights, safety, or the integrity of the service.

7. Cookies and browser storage

Academy does not use advertising or analytics cookies, and does not track you across other websites. We use a small amount of functional browser storage that is essential to the service: to keep you signed in, and to remember your language, currency and playback preferences. Because this storage is strictly necessary to provide the service you asked for, it does not require a consent banner.

8. International transfers

Some of our providers are located outside the UK. Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses, or an adequacy decision where one applies. [Confirm the specific transfer mechanism for each provider with your adviser.]

9. How long we keep it

  • Account and course data is kept while your subscription is active.
  • After a subscription ends, we keep account data for a limited period so it can be reactivated or exported, then delete it. A subscribing company can ask us to delete their staff’s data sooner.
  • Encrypted database backups are retained for up to 14 days and then overwritten.
  • We keep billing records for as long as the law requires.

10. Your rights

Depending on where you are, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy of it, restrict or object to how we use it, and withdraw consent. If you are a member of staff trained through Academy, the first place to exercise these rights is your employer, who controls your data; we will support them in responding.

To make a request, contact privacy@onoffgroup.com. You also have the right to complain to a data protection authority — in the UK, the Information Commissioner’s Office (ICO); in the Philippines, the National Privacy Commission (NPC).

11. Security

We protect data with encryption in transit, restricted access to systems, and regular backups. No system is perfectly secure, but we take reasonable steps to protect your data and to notify you and the relevant authority if a breach occurs that is likely to affect you.

12. Children

Academy is a workplace training tool and is not intended for children. We do not knowingly collect data from anyone under 16.

13. Changes to this policy

We may update this policy from time to time. We will change the “last updated” date above and, for significant changes, tell affected account holders by email.

14. Contact

On-Off Group UK Ltd · [registered address] · privacy@onoffgroup.com