Privacy at AcademyBase

Clear privacy roles, from platform to academy.

AcademyBase protects the information used to operate its platform. Each academy remains responsible for its own learners, staff and business use of personal information.

Current version 2026-08-29

AcademyBase Privacy Notice

Version: 2026-08-29 · Effective date: 29 August 2026

This Privacy Notice explains how AcademyBase (AcademyBase, we, us or our) collects and uses personal information when people visit our public website, create or use an AcademyBase customer account, apply for or operate an academy, join an AcademyBase program, contact us, or interact with services that AcademyBase operates for its own business purposes.

AcademyBase is operated from South Africa and provides software and related platform services to independent academies. This notice is intended to meet the transparency requirements that apply to AcademyBase under South Africa's Protection of Personal Information Act (POPIA) and, where applicable, other privacy laws such as the EU or UK General Data Protection Regulation. A right or legal ground mentioned below applies only where the relevant law provides it.

Important academy boundary. Every Academy is an independent business. An Academy decides how it teaches, which learner, parent, guardian and staff information it needs, who may use that information, and how it communicates and markets to those people. Each Academy must publish its own privacy notice covering those choices. This AcademyBase notice does not replace an Academy's notice.

1. Scope and who this notice covers

This notice applies to personal information processed by AcademyBase through:

  • academybase.co.za and related AcademyBase marketing pages;
  • AcademyBase customer, affiliate and operator account services;
  • academy applications, setup, onboarding and platform administration;
  • AcademyBase billing, support, service communications and security operations;
  • platform-level classroom, translation and AI lesson-building services where enabled; and
  • limited information received from an Academy runtime for billing, support, reliability, security or service administration.

It covers information about identifiable people and, where POPIA applies, identifiable organisations. It does not govern an Academy's independent collection or use of information in its own academy website, learner portal, classroom or business records, except to explain AcademyBase's limited role as a service provider.

2. Our role and the Academy's role

Privacy law uses terms such as responsible party or controller for the party that decides why and how personal information is processed, and operator or processor for a service provider that processes information on that party's instructions.

AcademyBase acts as the responsible party or controller for information used for our own purposes, including public-site operations, customer and affiliate accounts, academy applications, our contracts and billing, direct communications, optional AcademyBase analytics, fraud prevention, platform security, legal compliance and service administration.

The Academy acts as the responsible party or controller for the information it collects or uses to run its education business, including learner, parent, guardian, teacher, staff, booking, attendance, lesson, payment, classroom and marketing information. The Academy determines its lawful grounds, notices, permissions, access rules, retention and responses to those individuals.

AcademyBase acts as the Academy's operator or processor when it handles Academy-controlled information only to host and provide the configured platform, maintain the service, follow the Academy's lawful instructions, or assist with support. AcademyBase may separately process limited security, diagnostic, billing and legal records as a responsible party where we decide that processing is necessary for AcademyBase's own legitimate and lawful purposes.

If your question concerns information held by an Academy about its learners, parents, guardians, teachers or staff, contact that Academy first. We will reasonably assist the Academy with a valid request and will forward a request when it clearly relates to Academy-controlled information.

3. Personal information we collect

The information we collect depends on how you interact with AcademyBase.

Public website and technical information

We may receive the page or link used, referral source, date and time, IP address, browser and device information, approximate location inferred from technical data, cookie or consent preference, and security or request logs.

AcademyBase uses a limited first-party measurement channel on its own public website to count page views, visits, traffic categories and approximate visitors. It does not set an analytics cookie or use local storage. The collection service removes query strings from page paths, keeps only the referring site or search engine rather than the referring page, shortens the network address, reduces browser information to a broad browser and device category, and immediately converts those inputs into rotating aggregate counters. Raw IP addresses, full browser strings and individual visitor identifiers are not retained in the audience-measurement records, and the counters cannot be used to follow a visitor from one month to another. A Global Privacy Control or Do Not Track signal prevents the approximate-visitor and traffic-source steps for that view.

Optional Google Analytics is separate and is activated only after the visitor chooses analytics cookies.

Customer accounts and access

We process an account identifier, email address, display name, email-verification state, authentication provider and security information supplied by or generated through Firebase Authentication. We also keep customer-account memberships, roles, invitations, acceptance of current platform terms, and related access and audit records.

Academy applications, onboarding and management

We process contact name and email, academy name, logo, intended learner audience, operating currency, brand colours, service interests, whether the Academy is starting or migrating, descriptions of current operations or software, application notes, communications consent, quotes, internal review notes, onboarding status and associated technical configuration.

For an active Academy, platform administration may also contain owner and staff contact details, domains and branding, enabled services, configuration status, Academy-supplied legal documents, provider-readiness information, project identifiers and an audit history of administrative actions.

Affiliate and referral program

We process an affiliate applicant's name or business name, email address, country, proposed promotion methods, optional public profile, application source, consent record, application-delivery status and operator review state. If approved, we also process the affiliate's verified account details, program acceptance, referral code, link and click records, application attribution, reward status, PayPal payout email, payment history and operator review notes. Referral records may include landing page, referring page, browser information and timestamps.

Solo-teacher waitlist

If you join the solo-teacher waitlist, we process your email address, the source and date of your request, the consent version, confirmation and launch-message delivery records, and your unsubscribe status and token. We use this information to confirm your request, send relevant availability or launch updates, and honour your unsubscribe choice.

Billing, usage and AcademyBase payments

We process the Academy identity and billing contacts, invoice recipients, accepted pricing or quote, completed-lesson usage events, lesson duration, scheduled or completion time, source event and booking identifiers, applied rate snapshots, credits or corrections, invoice line items, invoice status, payment references and related accounting or dispute records.

Learner payments for an Academy's educational services go to that Academy or its chosen payment provider. AcademyBase does not ordinarily receive or hold those learner funds. We may process the minimum transaction context and payment status needed to provide the integration, support the Academy or secure the platform.

Communications, support and platform inbox

When someone contacts an AcademyBase address or uses a support channel, we may process names, email addresses, sender and recipient details, subject lines, message bodies, attachments, delivery metadata, case notes, priority and status, linked account or Academy records, and an audit trail of replies or administrative action.

Service, classroom, reliability and security information

We process limited runtime and service information such as Academy and project identifiers, software version, health heartbeat, service readiness, signed request metadata, classroom session or token requests, user role and pseudonymous or platform identifiers, usage counts, booking-visibility events, support tickets, email-delivery failures and error reports. Error reports can include route, action, browser details, technical stack information and the last affected user's account identifier or email when available.

For live classroom services, the Academy and its users may also process participant identity, attendance, chat, audio, video and translations. The Academy must explain that processing in its own privacy notice. AcademyBase and the real-time communications provider process the session data needed to connect and protect the classroom. AcademyBase does not record a live classroom unless the feature is expressly enabled and the Academy has implemented the required notice and lawful basis.

AI lesson builder and content services

If an Academy enables the AI lesson builder, AcademyBase may process the authorised staff member's account identifier, prompts and chat messages, course and lesson context, teacher notes, Academy branding, uploaded source or reference files, generated text, images, audio, lesson packages, validation results, job status and usage metadata. Some content is sent to the configured AI provider, currently Google Gemini, to generate or evaluate the requested lesson material.

Users must not submit personal information that is unnecessary for lesson creation, and must have permission to use uploaded material. Temporary access links expire and temporary references are marked for cleanup under the service workflow. Generated lesson content and deliberately retained course material remain part of the Academy's workspace until removed under the Academy's retention choices or the service lifecycle.

Sensitive or special personal information

AcademyBase does not ask customer-account holders to provide health, biometric, criminal, religious or similarly sensitive information for ordinary account use. An Academy may need certain sensitive information for its own learners or staff. The Academy must limit that collection, establish an appropriate legal basis, apply stronger access controls and comply with any additional rules for children or special personal information. Do not send sensitive information to AcademyBase support unless it is necessary and the channel is appropriate.

4. Where information comes from

We obtain information:

  • directly from you when you browse, register, apply, configure a service, join a program or contact us;
  • from an Academy owner or authorised staff member who creates an invitation, account relationship, support request or configuration;
  • from an Academy runtime through authenticated service events and support or reliability reports;
  • from authentication, hosting, classroom, payment, email, analytics, security and AI service providers involved in a requested service;
  • from referral links or affiliates when an application is attributed; and
  • from public sources where reasonably necessary to verify a business, domain, professional role or security concern.

If someone gives us information about another person, that person must be authorised to do so and must provide any required notice.

5. Why we process information and our legal grounds

Depending on the person, service and applicable law, we process personal information for the following purposes and grounds:

  • Contract and requested steps: to create an account, assess an application, provide a quote, onboard and operate an Academy, deliver enabled services, provide support, administer an affiliate relationship, bill for platform usage and enforce the customer agreement.
  • Legitimate operational interests: to secure accounts and infrastructure, prevent fraud and abuse, diagnose failures, maintain service quality, understand privacy-minimised aggregate website and service performance, keep business and audit records, improve AcademyBase and protect AcademyBase, Academies and users. We consider the effect on the individual and use proportionate safeguards.
  • Legal obligations and claims: to comply with tax, accounting, consumer, privacy, law-enforcement and court requirements, respond to lawful process, and establish, exercise or defend legal claims.
  • Consent: for optional Google Analytics website measurement, the solo-teacher waitlist, and marketing where consent is required. Consent may be withdrawn for future processing without affecting earlier lawful processing.
  • Academy instructions: where AcademyBase acts as operator or processor for Academy-controlled information, the Academy determines the lawful ground and AcademyBase processes the information to provide the contracted service and follow documented lawful instructions.
  • Protection of people and systems: where necessary to protect a person's vital interests, investigate a serious safety or security issue, or prevent immediate harm, as permitted by law.

We will not use personal information for a materially incompatible new purpose without establishing a lawful ground and providing any further notice required by law.

6. Required and optional information

Information marked as required is needed to provide the requested account, application, security, billing or service function. If it is not provided, we may be unable to create the account, assess or onboard an Academy, pay an affiliate reward, provide a feature, investigate a support request or meet a legal obligation.

Optional profile, marketing, migration-context and Google Analytics information may be declined unless it later becomes reasonably necessary for a specifically requested service. Operational, authentication, security and strictly limited aggregate audience records are not controlled by the optional Google Analytics choice.

7. Cookies, local storage, analytics and referrals

AcademyBase uses a small number of browser storage technologies:

  • a consent cookie and local-storage value remember whether you chose essential-only or optional analytics storage, normally for up to one year;
  • authentication providers may use essential storage to sign you in, keep a session secure and complete a selected sign-in redirect;
  • referral cookies store a validated referral code and click identifier for up to 90 days so that a legitimate affiliate introduction can be credited; and
  • strictly necessary security and routing technologies may be used to deliver and protect the site.

The limited first-party audience counters described above operate without cookies, local storage, advertising identifiers or cross-site tracking. They provide AcademyBase with aggregate page, traffic-source, visit and approximate-visitor figures needed to understand whether the public website is useful. Approximate visitor counts use rotating daily and monthly anonymous bitmaps, so a returning person is not given a lasting profile and counts across longer periods are deliberately estimates rather than exact identities.

Optional Google Analytics events are sent only after an analytics choice is recorded, and AcademyBase configures IP anonymisation in its analytics integration. You can select “Reject optional” when the cookie notice appears, use “Manage choices” for the detailed controls, or reopen “Cookie settings” from the website footer later. Clearing referral cookies can prevent an affiliate from receiving credit for an introduction.

AcademyBase does not use the public site to sell personal information or run cross-site behavioural advertising.

8. Communications, waitlists and direct marketing

We send service messages needed for an account or contract, such as verification, invitations, security alerts, application updates, invoices, service notices and material legal changes. These are not optional marketing messages, although a person can close or stop using the relevant service subject to contractual and retention requirements.

Marketing, affiliate and waitlist messages are sent where the recipient requested them or another lawful basis permits them. Each applicable message will provide an unsubscribe method or explain how to object. An unsubscribe does not delete records that we need to prove the preference, prevent further marketing or meet legal and accounting duties.

An Academy is responsible for its own learner, parent, guardian and staff marketing, including collecting consent where required, respecting objections and maintaining suppression records. AcademyBase may provide delivery tools as the Academy's operator, but does not give the Academy an independent right to market to anyone.

9. How we share information

We disclose personal information only when reasonably necessary for the purposes in this notice, including to:

  • the relevant Academy owner and authorised staff for Academy operations;
  • AcademyBase personnel and contractors who need access for their assigned work and are subject to confidentiality and access controls;
  • infrastructure, authentication, storage, communications, classroom, analytics, security, payment and AI service providers;
  • professional advisers, insurers, auditors and collection providers where necessary;
  • regulators, courts, law-enforcement bodies or other recipients when disclosure is legally required or reasonably necessary to protect rights, safety and security; and
  • a buyer, successor or relevant adviser in a genuine financing, restructuring, sale or transfer of all or part of AcademyBase, subject to appropriate confidentiality and lawful processing.

We do not sell personal information. We do not permit a service provider to use Academy-controlled information for its own unrelated marketing merely because the provider helps deliver AcademyBase.

10. Main service providers and subprocessors

Providers can change as AcademyBase develops. The main provider categories currently include:

  • Google services, including Firebase and Google Cloud, for authentication, databases, storage, hosting, application services, security, logs, translation and infrastructure; Google Analytics for optional public-site analytics; reCAPTCHA where enabled for abuse prevention; and Google Gemini for enabled AI lesson-building functions;
  • Agora for real-time classroom audio, video and related session connectivity;
  • email and delivery providers, including AcademyBase's delivery infrastructure and an Academy's own configured SMTP provider, for transactional messages, invitations and support communications;
  • payment providers selected by an Academy, such as PayPal where configured, to process the Academy's learner payments directly; and
  • PayPal or another disclosed payout method for AcademyBase affiliate rewards.

These providers may receive identifiers, network information, content or transaction details needed for the specific function. Their own privacy terms may also apply when a user or Academy contracts with them directly, particularly for learner payments and external accounts.

An Academy that needs a current provider list, data-processing terms or reasonable transfer information for its compliance review may contact security@academybase.co.za.

11. International processing and transfers

AcademyBase accepts customers internationally and uses service providers with infrastructure and support operations in more than one country. Personal information may therefore be stored or processed outside South Africa or outside the country where the individual is located.

Where cross-border transfer rules apply, AcademyBase uses a legally recognised transfer ground and appropriate safeguards for the circumstances. These may include a recipient subject to comparable data-protection rules, contractual protections, approved standard contractual clauses, the person's consent where valid, or a transfer necessary to perform a contract or respond to the person's request. We also apply technical and organisational controls appropriate to the information and service.

An Academy remains responsible for deciding whether its own instructions and international use of learner or staff information are lawful. AcademyBase will provide reasonable information about relevant processing locations and safeguards to support that assessment.

12. Retention and deletion

We keep personal information only for as long as reasonably needed for the purpose collected, an active account or service, legitimate operational and security needs, or a legal, tax, accounting, dispute or enforcement requirement. Retention is determined by the type of record, sensitivity, risk, relationship, provider lifecycle and applicable law.

In general:

  • account, application, Academy configuration and contract records are kept while the relationship or application is active and for a reasonable period afterward;
  • invoices, accepted prices, usage events, payout and transaction records are kept for applicable accounting, tax, audit, collection and dispute periods;
  • support messages and platform-inbox records are kept while needed to handle the issue and maintain an appropriate operational, security or legal history;
  • waitlist records are kept while the waitlist purpose remains active or until unsubscribe, after which minimal suppression and consent evidence may be retained;
  • referral and affiliate records are kept while needed to attribute applications, prevent abuse, pay rewards and meet accounting or dispute duties;
  • security, request and technical logs are kept for bounded operational periods or longer where needed to investigate an incident or legal claim;
  • first-party audience totals and anonymous counting bitmaps may be kept as de-identified business statistics, while the rotating design prevents them from becoming a lasting visitor history; and
  • temporary AI access links expire, temporary references follow cleanup workflows, and deliberately retained source or generated course material follows the Academy workspace and service lifecycle.

Each Academy sets lawful retention for its Academy-controlled learner and staff records. When an Academy account ends, AcademyBase will handle Academy-controlled information according to the customer agreement, lawful Academy instructions, technical deletion cycles and backup limitations. Deleted information may remain in restricted backups until those backups rotate, and some records may be preserved where law or a genuine claim requires it.

We may retain information that has been reliably de-identified so that it no longer identifies a person.

13. Security

AcademyBase uses proportionate technical and organisational safeguards designed to protect confidentiality, integrity and availability. Measures include authenticated access, role and ownership checks, separate Academy runtime projects, signed service requests, encrypted network transport, protected and encrypted credential storage, restricted operator access, audit records, provider security controls, monitoring, backups and incident-response practices.

Academy owners control which staff members may access their Academy and must remove access promptly when it is no longer authorised. Users must protect sign-in methods, use accurate contact information and report suspected compromise.

No internet service can promise absolute security. AcademyBase reviews and improves safeguards as the platform, risks and available controls develop.

14. Personal-information incidents

If AcademyBase reasonably believes personal information has been accessed or acquired by an unauthorised person, we will investigate, contain and document the incident and provide notifications required by applicable law.

For Academy-controlled information, AcademyBase will notify the responsible Academy without undue delay after becoming aware of a qualifying breach and provide reasonable information and assistance so that the Academy can meet its duties. For information AcademyBase controls, AcademyBase will notify affected people and the relevant regulator when the law requires it, subject to any lawful delay requested by an investigating authority.

Suspected security or privacy incidents should be sent promptly to security@academybase.co.za.

15. Your privacy rights

Depending on the law that applies, a person may have rights to:

  • be informed about processing and ask whether AcademyBase holds personal information about them;
  • request access to the information and available details about its use;
  • request correction or completion of inaccurate information;
  • request deletion or destruction where retention is no longer lawful or necessary;
  • object to certain processing, including direct marketing, or request restriction;
  • withdraw consent for future processing where consent is the ground used;
  • receive certain information in a portable form;
  • complain to the relevant privacy regulator; and
  • request human consideration of a qualifying decision made solely by automated processing.

To exercise a right concerning AcademyBase-controlled information, email security@academybase.co.za with enough detail for us to identify the relevant account, interaction and request. We may verify identity and authority before disclosing or changing information. We will respond within the period required by applicable law and may refuse or limit a request where the law permits, explaining the reason where required.

For learner, parent, guardian, teacher, staff, booking, classroom or payment information controlled by an Academy, contact that Academy first. If AcademyBase receives the request, we may refer it to the Academy and assist the Academy as its operator.

16. Children and young learners

AcademyBase customer accounts are for people aged 18 or older who can enter a business agreement. AcademyBase does not knowingly invite a child to create an AcademyBase customer or affiliate account.

An Academy may choose to teach children or young learners through its own service. The Academy is responsible for age-appropriate notices, guardian authority or consent where required, safeguarding, staff access, marketing restrictions and any legal permission needed to process a child's information. AcademyBase processes that information for the Academy only as needed to provide and protect the platform, unless AcademyBase has a separate legal duty or purpose explained in this notice.

If a child has submitted information directly to an AcademyBase customer or affiliate account without proper authority, contact security@academybase.co.za.

17. Automated decisions and AI

AcademyBase does not currently make a decision about a customer account using solely automated processing where that decision produces legal or similarly significant effects. Automated controls may block suspicious requests, enforce rate limits, validate service events or flag records for review, but material customer decisions can be reviewed by a person.

AI lesson-builder output assists authorised Academy staff with content creation. It is not an AcademyBase decision about a learner, does not replace the Academy's professional review, and must not be used as the sole basis for a high-impact decision about a person. If AcademyBase introduces qualifying automated decision-making, we will provide the information and choices required by applicable law.

18. Academy responsibilities when using the platform

An Academy must:

  • publish and keep current its own privacy notice for learners, parents, guardians, teachers, staff and website visitors;
  • collect only information it reasonably needs and establish a lawful ground for each purpose;
  • give AcademyBase lawful instructions and avoid uploading data that the service does not need;
  • control staff permissions, exports, downloads and off-platform use;
  • configure retention, marketing, classroom, recording, payment and child-data practices lawfully;
  • respond to privacy requests and complaints for information it controls; and
  • tell AcademyBase promptly when assistance is needed for a request, incident, deletion, export or legal restriction.

AcademyBase may provide configuration fields, document tools or operational guidance, but those tools do not transfer the Academy's legal responsibilities to AcademyBase.

19. Changes to this notice

We may update this notice when the platform, providers or legal requirements change. The current version and effective date appear at the top. We will publish the updated notice and, where a change is material, use a reasonable additional notice method such as an account or email notice before or when the change takes effect.

Earlier processing remains governed by the notice and law applicable at the time, unless a lawful new ground and notice permit another use.

20. Contact and complaints

For privacy requests, privacy questions or security concerns, contact security@academybase.co.za. For customer-account or invoice matters, contact accounts@academybase.co.za. For ordinary platform support, contact support@academybase.co.za.

Please identify the relevant Academy if the request concerns an Academy service. Do not send passwords, full payment credentials or unnecessary sensitive information by email.

You may also complain to the privacy regulator responsible for your location or the processing. In South Africa, this is the Information Regulator. People covered by EU or UK data-protection law may complain to their local supervisory authority. We encourage you to contact us first so that we can try to resolve the concern, but doing so does not remove a legal right to approach a regulator.