cove-verse
Home About Courses Contact
This site contains promotional content

GDPR Compliance

Last updated: August 2026

Our Commitment to Data Protection

We are committed to protecting your personal data and respecting your privacy rights in accordance with the General Data Protection Regulation (GDPR) and UK data protection laws.

Data Controller Information

For the purposes of data protection legislation, the data controller is:

cove-verse
142 Kensington High Street
London, W8 7RG
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis:

Contract Performance

Processing necessary to fulfill our contractual obligations when you enroll in educational programmes, including:

  • Managing enrollments and course delivery
  • Providing course materials and communications
  • Processing payments and maintaining financial records

Legitimate Interests

Processing necessary for our legitimate business interests, including:

  • Website analytics to improve user experience
  • Fraud prevention and security measures
  • Internal record keeping and administration

Consent

Processing based on your explicit consent for:

  • Marketing communications about new programmes
  • Optional cookies beyond strictly necessary ones

Legal Obligations

Processing required to comply with legal requirements, such as:

  • Tax and accounting obligations
  • Responding to lawful requests from authorities

Your Rights Under GDPR

Right to Access

You have the right to request copies of your personal data. We will provide this information within one month of your request.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw consent and no other legal basis exists
  • You object to processing and no overriding legitimate grounds exist
  • The data has been unlawfully processed

Note that we may need to retain certain information to comply with legal obligations.

Right to Restrict Processing

You have the right to request restriction of processing in certain situations, such as when you contest the accuracy of data or object to processing.

Right to Data Portability

You have the right to request transfer of your personal data to another service provider where technically feasible.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Rights Related to Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts.

How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected] with:

  • Clear description of your request
  • Proof of identity to protect against fraudulent requests
  • Specific information or records you are requesting, if applicable

We will respond within one month. In complex cases, we may extend this by two additional months and will inform you of the extension.

Data Security Measures

We implement appropriate technical and organizational measures to ensure data security, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls limiting who can view personal data
  • Staff training on data protection responsibilities
  • Incident response procedures for potential data breaches

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the appropriate supervisory authority within 72 hours
  • Notify affected individuals without undue delay if the breach poses a high risk
  • Document the breach and our response measures

Data Protection Officer

For data protection inquiries, contact our designated data protection contact at [email protected].

Third-Party Processors

We work with carefully selected third-party service providers who process data on our behalf. These processors are contractually bound to:

  • Process data only according to our documented instructions
  • Implement appropriate security measures
  • Assist with fulfilling data subject rights requests
  • Delete or return data when services conclude

International Data Transfers

When we transfer personal data outside the UK or European Economic Area, we ensure appropriate safeguards are in place through:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Other legally approved transfer mechanisms

Children's Data

When processing personal data of children enrolled in our programmes, we obtain verifiable parental or guardian consent. Parents have the same rights regarding their child's data as outlined above.

Retention Periods

We retain personal data only as long as necessary for the purposes collected or as required by law:

  • Student enrollment records: 3 years after course completion
  • Financial records: 7 years as required by law
  • Marketing consent records: until consent is withdrawn
  • Website analytics: 26 months maximum

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe we have violated data protection laws.

UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk

Updates to This Statement

We review and update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website and direct notification where appropriate.

cove-verse

Financial education that transforms lives across generations.

Quick Links

  • About Us
  • Our Courses
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • Cookies Policy
  • GDPR Compliance

© 2026 cove-verse. All rights reserved.