Legal
Privacy policy
Bright & The Future, registered in the Netherlands, is the data controller for personal data we process via The School of Real Marketing. This policy describes what data we collect, why, how we use it, and what your rights are.
1. What data we process
Account data: name, email address, preferred language, account settings. Basis: performance of the contract (GDPR Art. 6(1)(b)).
Payment data: we do not process card numbers ourselves. Payments will go through Stripe, which acts as independent data controller for payment data. We then only receive confirmations of successful payments and transaction identifiers. Payments are not live yet: checkout currently runs on a test environment. Basis: performance of the contract.
Progress data: which lectures you have completed, quiz results, last-read lecture. Basis: performance of the contract.
Usage statistics: anonymised page views via Plausible Analytics. Plausible sets no cookies, does not retain IP addresses, and builds no profiles. Basis: legitimate interest (GDPR Art. 6(1)(f)) in improving the service.
Correspondence: if you email us, we retain your message to reply and to be able to look up past conversations. Basis: legitimate interest.
Newsletter: if you subscribe to the newsletter, we retain your email address so we can send it to you. Basis: consent (GDPR Art. 6(1)(a)). You can unsubscribe at any time.
Content reports: under every lecture you can anonymously report a content issue. We store no name, email address or IP address — only the lecture, the chosen category and an optional short note. That note is erased once the report is processed. Since no identity is attached, these are in principle not personal data.
2. What we use the data for
To manage your account, to give you access to the content you pay for, to show your progress, and where necessary to communicate about your subscription (confirmations, changes, outages). We also use aggregated statistics to see which modules work well and where we can improve. We do not use your data for advertising and do not share it with third parties for marketing purposes.
3. Who we share data with
We share only with processors we need in order to deliver the service, each under a data-processing agreement:
—Firebase Authentication (Google, US under EU SCCs): email, name, sessions.
—Cloud SQL and Cloud Run (Google Cloud, EU region europe-west4): progress data, account metadata, hosting and technical logs.
—Stripe (payments, US under EU SCCs): payment data. Stripe is an independent controller for that data. Payments are not live yet: checkout currently runs on a test environment and we do not yet collect real money.
—Plausible (analytics, EU): anonymised page statistics.
—AI assessment layer: for AI-graded assessments we grade the question and the open answer you write using the model Claude, which we run inside the EU via Google Cloud (Vertex AI) or AWS (Bedrock) in an EU region. Your answer stays inside the EU.
—Study assistant: when you ask the study assistant a question on a lecture page, we process that question with the model Claude, inside the EU via Google Cloud (Vertex AI, EU region). We do not store your questions or the answers; only the number of questions asked and the corresponding point deduction are recorded.
—SendGrid (Twilio, US under EU SCCs) and Firestore (Google): sending and storing newsletter subscriptions.
We do not provide data to governments unless legally required.
4. Transfer outside the EU
Some processors (Firebase/Google, Stripe, and SendGrid/Twilio) are based in the United States. Transfer happens under EU Standard Contractual Clauses and additional safeguards where those processors offer them. We deliberately run the AI assessment layer inside the EU, so your answers are not processed outside the EU.
5. How long we retain data
Account data for as long as you have an account, plus thirty days after cancellation for reactivation. Progress data the same. Payment transactions for seven years due to tax retention obligations. Email correspondence three years. Your newsletter email address until you unsubscribe. Plausible statistics are already anonymised and retained indefinitely.
6. Your rights
Under the GDPR you have the right to: access your data, correct it, delete it, restrict processing, object, and receive your data in portable form. Send a request to privacy@theschoolofrealmarketing.com. We respond within thirty days.
If you are unsatisfied with our handling, you have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or with the authority in your own EU country.
7. Cookies
The session cookie for login and session state is strictly necessary and needs no consent. For the referral cookie (srm_ref, thirty days), which remembers which invitation you arrived through, we ask your consent through a cookie notice; if you decline, we do not set it. We use no tracking cookies or third-party advertising cookies, and analytics (Plausible) works without cookies.
8. Security
Data is encrypted in transit (TLS) and at rest. Internal access is limited to people who need it for their work. We do not store passwords in readable form; authentication runs through Firebase Authentication, which supports hashing and secure storage.
9. Changes to this policy
Changes are published on this page. Material changes are announced by email.
10. Contact
For privacy questions: privacy@theschoolofrealmarketing.com. For general questions: info@theschoolofrealmarketing.com. The data controller is Bright & The Future, Kuper 2, 8447 GK Heerenveen, the Netherlands. Chamber of Commerce (KvK) number 68409362, VAT number NL857427878B01.