Privacy Policy
EO School — Privacy PolicyEffective Date: August 17, 2025
1) Scope
This Privacy Policy describes how EO School (“we,” “us,” “our”) collects, uses, discloses, and protects personal information when you use our websites, apps, and Services, and your choices and rights.
2) Controller & Contact
EO Studio, Inc., 2300 Mason St, San Francisco 94133, USA, is the controller of your personal information for the purposes described here. Contact us at builders@eoeoeo.net.
3) Information We Collect
- Account & Profile Data: name, email, password hash, photo, organization, role, timezone, preferences.
- Transactional Data: purchases, subscription status, refunds, support interactions.
- Learning Activity: courses enrolled, progress, quiz scores, assignments, certifications, forum posts.
- Device & Usage Data: IP address, device identifiers, browser type, settings, pages viewed, referring/exit pages, timestamps, crash/diagnostic logs.
- Cookies & Similar Tech: cookies, pixels, local storage, SDKs for authentication, preferences, analytics, and marketing (see Cookies section).
- Third-Party Sources: single sign-on (e.g., Google, LinkedIn), payment processors, referral partners, publicly available sources.
- Payment Data: handled by our payment processors (e.g., Stripe). We receive limited information (e.g., last 4 digits, card type, status) and do not store full card numbers.
4) How We Use Personal Information
We use personal information to:
- Provide, operate, and improve the Services and Course Content.
- Process purchases, subscriptions, and refunds; send transactional messages.
- Personalize content, recommendations, and learner experience.
- Provide customer support and respond to inquiries.
- Monitor performance, debug, and prevent fraud, abuse, or security incidents.
- Conduct research and analytics to improve our offerings.
- Send marketing communications (where permitted) and measure campaign performance.
- Comply with legal obligations and enforce our Terms.
5) Legal Bases (EEA/UK)
Where GDPR applies, our processing is based on: contract (to provide Services), legitimate interests (to secure and improve Services, prevent fraud, personalize experience), consent (for certain cookies/marketing), and legal obligations.
6) Sharing & Disclosure
We share personal information with:
- Service Providers/Processors: cloud hosting, analytics, email/SMS delivery, customer support tools, payment processing, video hosting, identity/authentication.
- Instructors/Partners: to deliver programs and verify completion/certification, only as necessary.
- Business Transfers: in connection with a merger, acquisition, financing, or sale of assets.
- Legal/Compliance: to comply with law, enforce Terms, or protect rights, safety, and property. We do not sell personal information. We may share identifiers and internet activity with advertising/analytics providers for cross-context behavioral advertising where permitted; you can opt out (see “Your Choices”).
7) International Data Transfers
We operate globally and may transfer personal information to countries with different data protection laws. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) and implement supplementary measures.
8) Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Typical periods: account data for the life of the account; transaction records for 7 years; support tickets for 2 years; learning activity for life of account + 2 years. We delete or anonymize data when no longer needed.
9) Your Choices
- Marketing Preferences: opt out of marketing emails via unsubscribe links or by contacting us. Transactional communications are required for the Services.
- Cookies: manage preferences via our Cookie Settings link and your browser settings. Some features may not function without certain cookies.
- Analytics/Ads Opt-Out: use our Do Not Sell or Share My Personal Information link (California) and disable advertising cookies in Cookie Settings.
10) Your Rights
- EEA/UK: access, rectification, erasure, restriction, portability, and objection to processing (including profiling); withdraw consent at any time; lodge a complaint with your data protection authority.
- United States (including California): right to know/access, delete, correct, and opt out of sale/share of personal information; right to limit the use/disclosure of sensitive personal information (we do not use “sensitive” data for inferring characteristics). We do not discriminate for exercising rights.
- How to Exercise: email [privacy@eoschool.com] or use [web form]. We will verify your request and respond within the time required by law. You may use an authorized agent with proof of authorization.
11) Cookies & Tracking
We use first- and third-party cookies/pixels for authentication, preferences, analytics, and (where permitted) advertising. See our Cookie Policy for categories, purposes, and retention. You can change settings at any time via Cookie Settings.
12) Security
We implement administrative, technical, and physical safeguards appropriate to the risk (e.g., encryption in transit, access controls, regular security reviews). No method of transmission or storage is 100% secure.
13) Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. In the EEA/UK, we do not knowingly collect data from children under 16 without verifiable parental consent. If you believe a child provided us data, contact us to delete it.
14) Third-Party Sites & Services
Our Services may link to third-party sites and services. Their privacy practices are governed by their own policies, not this one.
15) Changes to This Policy
We may update this Policy. Material changes will be notified via email or in-product notice at least 14 days before they take effect, unless required sooner by law. Continued use after the effective date constitutes acceptance.
16) Contact Us
EO School Privacy Team2300 Mason St, San Francisco, USA 94133
builders@eoeoeo.net
California Notice at Collection (Summary)
We collect the following categories of personal information for the purposes described above: identifiers (e.g., name, email), commercial information (purchases), internet or network activity (usage data), approximate geolocation (based on IP), and inferences (course interests). We do not collect “sensitive” personal information for the purpose of inferring characteristics. We do not sell personal information; we may share for cross-context behavioral advertising where permitted. See sections 3, 4, 6, 9, and 10 above for details.
Data Processing Addendum (Optional Summary for B2B/Enterprise)
If EO School processes personal data on behalf of a business customer as a processor, EO School’s DPA with Standard Contractual Clauses will apply. Contact builders@eoeoeo.net to request a copy.