Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can require us to do about it.
Last updated 10 July 2026
Who controls your data
Data for this website and the Academy programme is controlled by Global Executive Marketing, trading as GEM The Agency, which manages the digital assets of the Academy on behalf of Genesis1 One LLC — corporate trustee of iRise Nations, commissioner of the faith-based iRise Academy. The detailed controller and processor arrangements between those parties are governed by a non-disclosure agreement, so they are not published here; requests and questions are answered through the channels on our Contact page.
Trust administration is carried out through Morpheus, our own sovereign AI, managed by GEM The Agency. Data you provide for trust administration is handled under that separate arrangement rather than as part of the educational programme.
What we collect
We collect only what the service requires:
- Account data: name, email, password hash, and enrolment status.
- Transaction data: what you purchased, when, and the payment reference. Card details are handled by our payment processor and never reach our servers.
- Learning data: module progress, assessment responses, and material you upload to case support.
- Technical data: IP address, device and browser type, and pages visited — used for security and, with your consent, analytics.
- Correspondence: what you send us and our replies.
Why we are allowed to use it
Contract: to deliver the programme you enrolled in and to support your use of it.
Legitimate interests: to secure the platform, prevent fraud and content piracy, and improve teaching — balanced against your rights and recorded.
Consent: for non-essential cookies, analytics, and marketing email. You can withdraw consent at any time without affecting your access to the course.
Legal obligation: to keep accounting records and to respond to lawful requests.
Who we share it with
We do not sell personal data. We share it only with processors acting on our instructions: hosting and platform infrastructure, payment processing, email delivery, video delivery, and — with your consent — analytics.
Processors are bound by contract to use the data only as we direct. A current list is available on request via our contact page.
International transfers
Some processors operate outside the UK and EEA. Where that happens, transfers rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
Account and learning data: for the life of your account and 24 months after closure, so certificates and progress can be reissued.
Transaction records: six years, as required for accounting.
Case support material: 24 months after the support engagement closes, unless you ask us to delete it sooner.
Marketing consent records: 24 months from the last interaction.
Your rights
You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent where we rely on it.
Exercise any of these through our data subject rights page. We respond within one calendar month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
Security
Access to personal data is restricted to staff who need it, transmission is encrypted in transit, and passwords are stored hashed. No system is perfectly secure, and we do not claim otherwise; we will notify you and the regulator where a breach requires it.
Children
The programme is intended for adults. We do not knowingly enrol anyone under 18 or collect their data.