Legal

Privacy Policy

Effective Date: April 2026|Last Updated: May 2026

At Next Script ("Next Script", "we", "us", or "our"), protecting your personal data is a fundamental responsibility we take seriously. This Privacy Policy sets out how we collect, use, store, share, and protect your personal information when you interact with our website (nextscript.ai) and our educational services.

We are committed to full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). If you do not agree with this policy, please discontinue use of our services.

1. Who We Are

Next Script is the data controller responsible for your personal information. We provide online technology and coding education for students aged 6–21, operating globally with a primary presence in the United Kingdom.

If you have any questions about this policy or how we handle your data, please contact our Data Protection Lead:

Contact Us

Email: contact@nextscript.ai

Website: www.nextscript.ai

Subject line: ‘Data Protection Enquiry’

2. Information We Collect

We collect only the information that is necessary to deliver our educational services effectively and safely. This includes:

2.1 Parent / Guardian Information

  • Full name
  • Email address
  • Phone number (including WhatsApp, where applicable)
  • Billing address and payment method details (processed securely via third-party payment providers)

2.2 Student Information

  • Student first name (and surname where provided by the parent/guardian)
  • Age and date of birth (to assign appropriate tutors and curricula)
  • Learning interests, goals, and progress notes
  • Lesson attendance records and performance data

2.3 Technical & Usage Data

  • IP address and approximate geographic location
  • Device type, operating system, and browser
  • Pages visited, time spent on site, and click interactions
  • Session logs and diagnostic data for platform improvement

2.4 Communications Data

  • Messages sent through our contact forms or support channels
  • Email correspondence with our team
  • WhatsApp messages where you have chosen to communicate via that channel

3. How We Use Your Data

We use your personal data only for the purposes for which it was collected. Specifically, we use it to:

  • Schedule, deliver, and manage your child's tutoring sessions
  • Personalise the learning experience based on your child's pace, interests, and progress
  • Process payments and manage subscriptions or trial lesson bookings
  • Communicate updates, scheduling changes, and important service information
  • Send marketing communications and news about our services (only where you have given explicit consent)
  • Conduct internal analysis to improve our curriculum, tutor quality, and platform performance
  • Meet our legal, safeguarding, and regulatory obligations

4. Legal Basis for Processing

Under UK GDPR, we must identify a legal basis for every type of data processing. Our legal bases are as follows:

Legal BasisWhen We Rely On It
ConsentMarketing emails, cookie placement, and communications via WhatsApp
Contract PerformanceDelivering lessons and managing your account and subscriptions
Legitimate InterestsImproving our platform, preventing fraud, and analysing usage data
Legal ObligationSafeguarding obligations, financial record-keeping, and regulatory compliance

5. Children's Data

Our Commitment to Children's Privacy

We take the privacy and safety of children extremely seriously. We never collect data from children without verifiable parental or guardian consent.

Where a student is under 18 years of age:

  • All accounts are created and managed by a parent or guardian
  • Only the minimum necessary data about the student is collected
  • Parents and guardians retain full visibility and control over their child's account
  • We do not use children's data for profiling, advertising, or any purpose beyond delivering educational services
  • Student data is stored securely and access is restricted to authorised staff and assigned tutors only

6. Sharing Your Data

We do not sell, rent, or trade your personal data. We only share data with third parties where strictly necessary and always with appropriate safeguards in place:

  • Payment Providers: To process lesson fees and subscription payments securely (e.g., Stripe or equivalent)
  • Communication Platforms: Email providers and WhatsApp Business (where you have opted in), used to send booking confirmations and updates
  • Tutors: Assigned tutors receive limited student information (first name, age, learning goals) necessary to deliver sessions
  • Technology Infrastructure: Cloud hosting and platform tools that support the secure operation of our services
  • Legal Authorities: Where required by law, a court order, or to protect the safety of a child

7. International Data Transfers

Next Script operates across multiple regions, including the United Kingdom, the European Union, and parts of Africa. Where personal data is transferred outside the UK or EU, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the UK or EU
  • Use of Standard Contractual Clauses (SCCs) approved by the relevant authority
  • Compliance with the UK International Data Transfer Agreement (IDTA) where applicable

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our general retention periods are:

  • Account and lesson data: Retained for the duration of your engagement with Next Script, plus up to 3 years after the last interaction
  • Financial records: Retained for 7 years in accordance with HMRC requirements
  • Safeguarding records: Retained in line with statutory guidance
  • Marketing data: Retained until you withdraw consent

After the applicable retention period, data is securely deleted or anonymised.

9. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

Right of Access

Request a copy of the data we hold about you

Right to Rectification

Ask us to correct inaccurate or incomplete data

Right to Erasure

Request deletion of your data where there is no legitimate reason to retain it

Right to Restriction

Ask us to limit how we process your data in certain circumstances

Right to Portability

Receive your data in a machine-readable format and transfer it elsewhere

Right to Object

Object to processing based on legitimate interests or for direct marketing

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please email us at privacy@nextscript.ai. We will respond within 30 days in accordance with our legal obligations. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.

10. Cookies

We use cookies and similar tracking technologies on our website to enhance your experience and analyse usage patterns. You can manage your cookie preferences through our cookie consent banner when you first visit our site, or via your browser settings at any time.

11. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, disclosure, or destruction. These include encrypted data transmission (SSL/TLS), access controls, regular security reviews, and staff training on data protection. No method of transmission or storage is 100% secure; however, we are committed to applying best practices to keep your data safe.

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of significant changes by email or by posting a notice on our website. The effective date at the top of this document indicates when the policy was last revised.

We use cookies to improve your experience. Essential cookies are always active. You can choose which optional cookies to allow. Learn more