Existential Academy Privacy Policy

Version 1.0

Last Reviewed September 2026

General Information

The Existential Academy is a private limited Community Interest Company, company number 07058358, registered at 61-63 Fortune Green Road, London, England, NW6 1DR.

This notice explains how the Existential Academy (EA) collects, uses, stores and shares the personal data of applicants, students, workshop attendees, conference attendees and mailing list subscribers, the lawful bases on which we do so, your rights, and how to raise a concern or complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection.

EA processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our obligations seriously and ensure personal data is collected, handled, stored and shared in a secure manner.

Data controller and contact details

EA is the data controller for the personal data described in this notice.

If you have any questions about this notice or wish to exercise your rights, please contact:

Data Protection Lead: Prof Digby Tantam

Existential Academy, 61–63 Fortune Green Road, London NW6 1DR

Email: [email protected]

The lawful bases we rely on

For personal data, we rely on one or more of the following under Article 6 of the UK GDPR:

  • Contract: to provide event tickets and CPD records or to administer your application, enrolment, studies and award;
  • Legal obligation: to keep tax and payment records;
  • Legitimate interests: for example, administering services, securing our systems, and alumni relations, balanced against your rights;
  • Consent: for sending marketing communications where you have subscribed to our mailing list.

Special category and criminal-offence data

Some of the data we process for student applications is more sensitive, including health, disability, equality-monitoring data such as ethnicity; and criminal-conviction information, where you provide us with a DBS certificate you have obtained yourself for courses requiring a clinical placement. We process this under the additional conditions in Article 9 (and, for criminal-offence data, in line with Article 10) of the UK GDPR and Schedule 1 of the Data Protection Act 2018.

How we protect your data

Stripe handles all of your card data, meaning we never see your full card number. Your full name and email address are also stored securely on Stripe and on our own Microsoft 365 cloud services (including SharePoint and Dataverse), where data is currently stored in Microsoft’s United Kingdom data centres and encrypted both in transit and at rest.

Access to both is controlled on a least-privilege basis and protected by multi-factor authentication.

Data is backed up regularly to secure infrastructure, and our backup and restore procedures are tested at regular intervals by our IT providers. All company devices are protected by endpoint cyber-security software, and we hold Cyber Essentials certification, which we renew annually.

Your rights

Under data protection law you have the following rights, some of which apply only in certain circumstances:

  • the right to be informed about how we use your data;
  • the right of access to the personal data we hold about you;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure of your data;
  • the right to restrict our processing;
  • the right to object to our processing;
  • the right to data portability;
  • the right to withdraw consent, where our processing is based on consent.

These rights are not absolute, and we may be entitled to refuse a request where an exception applies. To exercise any of your rights, please contact our Data Protection Lead using the details above.

If you believe your request has not been handled properly, or you have any other data protection concern, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

How does EA collect your personal data?

We collect your personal data both directly and indirectly.

Directly from you:

  • through the Stripe payment links when booking a conference ticket or paying a course application fee;
  • through our online shop when booking a short course or workshop;
  • through our mailing list sign up form;
  • through our course application form.

Indirectly:

  • automatically through our website (see our Cookie Policy for details).

Conference Ticket Bookings

When you make a payment through Stripe, we will collect the following personal information:

  • Full Name;
  • Email Address;
  • Card Payment Detail which are processed directly by Stripe.

How long do we store your data for?

End of the conference + 6 years.

Who do we share your data with?

We share personal data with certain other organisations in order to meet statutory requirements or to provide services to attendees. Sharing is always undertaken in line with data protection law, using the relevant lawful basis, and is limited precisely to what the recipient needs.

Service providers (processors), under data processing agreements:

  • Microsoft: cloud hosting and productivity services (Microsoft 365, SharePoint, Dataverse);
  • Xero: accountancy software;
  • Stripe: for payments of application fees and deposits;
  • Little Fire Digital: development and maintenance of the EA website and Moodle;
  • Online Events: we will share your name and email address with our conference partners, online events, so that they can issue a CPD certificate and links to recordings.

Other individuals and organisations:

  • our insurers and legal advisers: for insurance cover or in the event of a claim;