Legal

Privacy Policy

Green Drumming Academy is a modern drum education platform. This policy explains what personal information we collect, why we collect it, how long we keep it, and the choices you have.

Last updated · 10 August 2026

01

Who we are

Green Drumming Academy ("the Academy", "we", "us") operates the learning platform at academy.greendrumming.com, including the student, trainer, academy and administrator portals. We are the data controller for the personal information described in this policy.

Questions, requests or complaints about privacy can be sent to contact@greendrumming.com.

02

Information we collect

  • Account data — name, email address, password hash, selected role (student or trainer), and email confirmation status.
  • Learning data — course enrolments, lesson completions, assessment submissions and scores, progress percentages and certificates issued to you.
  • Teaching data — courses, lessons, rhythm charts, assessments and rosters created by trainers and academy staff.
  • Content creation data — the prompts and parameters you submit to our generators and the content returned, stored so it can be reviewed, edited and attached to a course.
  • Communications — messages you send through the contact form and the transactional emails we send you (welcome, enrolment, certificate and course update notices).
  • Technical data — sign-in timestamps, and limited log data needed to keep the service secure and reliable.
03

How we use your information

  • To create and secure your account and give you access to the correct portal for your role.
  • To deliver courses, record progress, grade assessments and issue verifiable certificates.
  • To create lesson material, exercises and assessments when you use the smart toolbox.
  • To send service emails that are necessary to the running of your account.
  • To detect misuse, prevent fraudulent certificates and keep the platform available.

We do not sell your personal information, and we do not use your learning data for advertising.

04

Smart content processing

When a trainer or student uses a smart tool, the prompt and the relevant course context are sent to a third-party model provider through our content gateway so that content can be produced. Created output is returned to the Academy and stored against the course or the requesting account. Do not paste sensitive personal information into tool prompts. All created output is intended as a draft for a qualified human instructor to review before it is published to students.

05

Certificates and public verification

Certificates are designed to be independently verifiable. A public verification page displays the holder name, course title, programme, level, issue date, certificate number and verification code, plus the number of times the record has been checked. No email address, contact detail or assessment score is ever shown on a public verification page. If you need a certificate revoked or a name corrected, contact us.

06

Service providers

We rely on a small number of processors who handle data strictly on our instructions: a cloud database and authentication provider for accounts and course records, an email delivery provider for transactional messages, an content gateway for created content, and our hosting provider. Each is bound by contractual confidentiality and security obligations.

07

Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in and to remember interface preferences. We do not use advertising or cross-site tracking cookies.

08

Retention

Account and learning records are kept for as long as your account is active. Certificate records are kept indefinitely so that issued credentials remain verifiable, unless you ask for a specific record to be revoked. Contact-form correspondence is kept for up to 24 months. Deleting your account removes your enrolments, submissions and completions.

09

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal information, and to object to certain processing. Email contact@greendrumming.com and we will respond within 30 days. We may need to verify your identity before acting on a request.

10

Children

Learners under 16 should only use the Academy through a school, studio or parent-managed account. If we learn that a child has created an independent account without appropriate consent, we will remove it.

11

Security

Access to data is enforced at the database level by row-level security policies scoped to your account and role. Passwords are hashed, traffic is encrypted in transit, and administrative operations are restricted to a small number of named accounts.

12

Changes to this policy

We may update this policy as the platform evolves. Material changes will be announced by email or by an in-app notice before they take effect. The date at the top of this page always reflects the current version.