Last updated: 2026-07-21 Effective: 2026-07-21
This Privacy Policy applies to the courses storefront at courses.instilligent.com and to purchases of digital courses ("Courses") sold through it.
[email protected][email protected]Instilligent Limited is the Privacy Act agency responsible for the personal information described in this policy. We are a New Zealand company registered under the Companies Act 1993.
This document is the courses-storefront-specific privacy policy. It is a narrowed and re-scoped version of the parent Instilligent Limited Privacy Policy published at instilligent.com/pages/privacy. Where the parent policy and this document overlap, the more specific terms in this document apply to your use of courses.instilligent.com. For our other products (Modular Compliance, BossBoard, CodeHumanist, ProofOnce) the relevant product-specific notice or the parent policy applies.
This policy describes how we collect, use, store, share, and protect personal information in connection with:
courses.instilligent.com, where you browse and purchase Courses.[email protected].[email protected].This policy does not cover:
This policy works alongside the Terms and Conditions (T&Cs), Refund Policy, and Product Disclaimer that are separately published on the storefront.
We collect only what we need to sell, deliver, and support the Courses you buy. The categories of personal information involved are:
[email protected] or [email protected], including the content of the message, your email address, any attachments you send, and any reply thread.We do not intentionally collect special-category or sensitive information (such as health information, biometric data, or information about ethnicity, religion, or political views) through the storefront or the Course flow. If you send sensitive information to us in support correspondence we treat it with the same care described in §3.4 and §11.
We also ask, in the Product Disclaimer §2, that you do not send us confidential examination content that you may be bound to keep confidential under a third-party exam-taker NDA. If you do send it, we will not retain it or use it.
We collect personal information in the following ways:
[email protected] or [email protected].We use your personal information for the following purposes, consistent with Information Privacy Principles 1, 2, 3, and 10 of the New Zealand Privacy Act 2020:
[email protected] or [email protected].We do not use Course-buyer data for broad-market direct-marketing campaigns that are unrelated to either the Courses you bought or the Instilligent Limited product family.
We share personal information only with the third-party providers we need to run the storefront, deliver the Courses, take payment, and support you. We do not sell personal information.
| Provider | Purpose | Data shared | Jurisdiction | Their privacy policy |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, fraud screening, chargeback handling | Name (if given), email, card details (held by Stripe, not us), purchase amount, currency, IP, billing country | United States | stripe.com/privacy |
| EzyCourse | Course delivery, account hosting, progress tracking, in-platform messaging | Name, email, account credentials, Course progress, downloads | United States (AWS US-East per EzyCourse documentation) | ezycourse.com/privacy-policy |
| Microsoft Corporation (Microsoft 365) | Inbound email for [email protected] and [email protected]; reply-thread storage | Your email address, message content, attachments | United States (with regional sub-processing) | privacy.microsoft.com |
| Cloudflare, Inc. | CDN, DNS, edge security in front of courses.instilligent.com | IP address, request metadata, security signals | United States (global edge) | cloudflare.com/privacypolicy |
| Chatbase, Inc. | AI chat widget embedded on the storefront (embed.min.js) — handles in-page customer questions | Chat message content you type, IP address, browser fingerprint, page URL | United States | chatbase.co/legal/privacy-policy |
In addition:
We do not share Course-buyer data with advertising networks, data brokers, or third-party marketing platforms for their own purposes.
Under Information Privacy Principle 12 of the New Zealand Privacy Act 2020, we are required to be transparent when personal information is sent overseas and to take reasonable steps to ensure the overseas recipient is subject to privacy obligations comparable to those of the New Zealand Privacy Act.
Personal information collected through courses.instilligent.com is processed outside New Zealand. The principal offshore processing locations are:
support@ and privacy@.For each provider we take reasonable steps to confirm they are subject to privacy obligations comparable to the NZ Privacy Act 2020, including by:
If you would like more information about the safeguards we have in place for offshore transfers, contact [email protected].
We keep personal information only for as long as we need it, or as long as the law requires. The retention picture for course-storefront data is:
[email protected]) — generally up to 3 years from the last contact, to maintain context across follow-up enquiries and to support fraud and chargeback investigation.[email protected]) — generally up to 3 years from resolution, to demonstrate Privacy Act 2020 compliance.When personal information is no longer required, we take reasonable steps to destroy or de-identify it in a secure manner (Information Privacy Principle 9).
These periods are best-effort operational targets and may be shortened on your request where we are not required to retain the information by law.
You have the following rights in relation to personal information we hold about you:
You may request a copy of the personal information we hold about you. We will respond within 20 working days. We may charge a reasonable fee in limited circumstances (for example, very large or repeated requests).
If you believe information we hold about you is inaccurate, incomplete, misleading, or out of date, you may ask us to correct it. We will respond within 20 working days and either make the correction or, if we decline, explain why and attach a statement of your view to the record.
You may ask us to delete personal information we hold about you. We will comply unless we are required to retain it (for example, transaction records under the 7-year tax retention rule in §8, or records reasonably needed to defend a current dispute). Some data is held by EzyCourse on our behalf — we will pass your deletion request to EzyCourse and let you know the outcome.
You may opt out of the §13 cross-promotion and funnel-attribution matching at any time. See §13 for the opt-out mechanism.
If you believe we have breached the Privacy Act 2020 you may:
[email protected]. We aim to acknowledge complaints within 5 working days and to substantively respond within 20 working days.To exercise any of these rights, contact [email protected]. We may need to verify your identity before acting on a request, particularly for access and deletion.
The following cookies and similar technologies are in use on courses.instilligent.com at the date of this policy. We will update this section when the inventory changes.
| Cookie / token | Set by | Purpose | Duration |
|---|---|---|---|
| `NEXT_LOCALE_V2` | Storefront (Next.js framework) | Remembers your language/locale preference | 1 year |
| EzyCourse session cookies | EzyCourse (after login) | Maintain your authenticated session, prevent cross-site request forgery, route requests to the right tenant | Session (cleared on logout) |
| Cloudflare security cookies (e.g. `__cf_bm`) | Cloudflare | Bot detection, DDoS protection, edge security in front of the storefront | Up to 30 minutes |
| Chatbase tokens | Chatbase (only if you start a chat) | Maintain your conversation context during a chat session | Session |
| Stripe checkout cookies | Stripe (during the Stripe-hosted checkout flow only) | Payment session, fraud prevention | Per Stripe; see their privacy policy |
The storefront does not currently set Google Analytics, GTM, Facebook Pixel, advertising-network, or other behavioural-tracking cookies pre-login. The parent Instilligent corporate site (instilligent.com) uses Google Analytics 4 with a Klaro consent UI; equivalent analytics may be added to the courses storefront in future, in which case this section will be updated and (where required) consent will be sought via a banner.
You can control cookies through your browser settings (block, delete, or be notified). Disabling strictly-necessary cookies will break the checkout and login. If a consent banner is shown on the storefront, your choices in that banner override the defaults described above.
Our Courses are designed for adults and business users. Consistent with T&Cs §3, you must be at least 18 years old to purchase or use a Course (or have the consent of a parent or legal guardian who agrees to the T&Cs on your behalf).
We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information through courses.instilligent.com without parental consent, please contact [email protected] and we will delete that information promptly.
The Courses do not include games, advertising-funded content, or features specifically designed to appeal to children.
Course material is produced using an automated AI pipeline operated by Instilligent Limited, as described in Product Disclaimer §6. This raises two distinct AI-related privacy considerations that we address here directly:
Personal information you give us — your name, email, support correspondence, Course progress, payment details — is not used to train, fine-tune, or evaluate any third-party machine-learning or artificial-intelligence model. We use AI tooling to produce Course content, not to train AI on you.
Where we use AI-assisted internal tooling (for example, to triage support email or to summarise a complaint thread for our own analysis), any third-party AI provider we use is bound to not retain or train on the content we send for that purpose. We select providers on this basis. We do not currently route customer support correspondence through any AI provider that retains content for training.
This is a contractual prohibition set out in T&Cs §7 and reinforced in Product Disclaimer §6 — see those documents for the substantive restriction and remedies. We mention it here only so you can see how the AI boundary works in both directions (you don't train on us; we don't train on you).
Aggregated, de-identified Course-progress data and aggregated support-correspondence themes may be used to improve future Course material — including via internal AI-assisted analysis. This use does not identify you individually.
Instilligent Limited operates several other software products in addition to the Courses sold through this storefront, currently including Modular Compliance, BossBoard, and Mastering Moss. Some Courses are designed to introduce concepts that those other products help with, and may include calls-to-action inviting you to try them. This relationship is also disclosed in Product Disclaimer §11.
The cross-promotion has two parts, and each is governed by a different consent rule:
(a) Email-to-email attribution matching — under Information Privacy Principle 10 of the NZ Privacy Act 2020 (use of information for a directly related purpose), we may match the email address you used to buy a Course against the email address on Instilligent SaaS Stripe customer records, to attribute SaaS trial signups and paid conversions to a preceding Course purchase. The match is email-to-email only; we do not import wider personal information from one product into another. This is performed by Instilligent Limited on its own records — no third party sees a combined dataset.
(b) Outbound cross-promotion email — sending you a promotional email about another Instilligent product (e.g. "you bought the BossBoard prep course — try BossBoard free for 30 days") is a commercial electronic message under the Unsolicited Electronic Messages Act 2007 ("UEMA"). UEMA requires express or inferred consent before any such message is sent. Purchasing a Course does not by itself give us inferred consent to email you about unrelated SaaS products.
Because of (b) above, we do not send cross-promotion emails unless you have explicitly opted in.
Current practice (as of the Effective date): the checkout opt-in control is not yet live. Until it is, we do not send any cross-promotion email about other Instilligent products. You will only receive transactional emails about Courses you have bought (receipts, access, course-update notices required by T&Cs §6) and replies to support correspondence you have initiated.
When the opt-in control ships, it will be offered:
Purchasing a Course alone never opts you in. If you have not explicitly opted in, you will not receive cross-promotion email.
Even after opting in, you may opt out at any time. Either:
[email protected] with subject line "opt out of cross-promotion" — we will remove your email address from the cross-promotion send list immediately and from cross-promotion attribution matching within 10 working days.Opting out of cross-promotion does not affect transactional emails about Courses you have bought, replies to support or privacy correspondence you have initiated, or your access to any Course you have already purchased.
In-Course recommendations of other Instilligent products (banner messages inside the Course, post-purchase pages on the storefront, calls-to-action embedded in the Course content itself) are not "commercial electronic messages" under UEMA — they are part of the Course product you have purchased and are governed by the Product Disclaimer §11 (commercial-relationship disclosure). These in-product surfaces are shown to all Course buyers regardless of opt-in status, but you can ignore them with no impact on your Course access.
We may update this Privacy Policy from time to time — for example, when we add a new provider, change a retention period, or adapt to a change in law. When we make a change we will:
courses.instilligent.com or in EzyCourse).[email protected] for at least 12 months after the change date.Continued use of the Courses or the storefront after a material change takes effect constitutes acceptance of the updated policy. Material changes do not retroactively reduce your rights in respect of personal information collected before the change date.
The New Zealand Privacy Act 2020 (Part 6) requires us to notify the Office of the Privacy Commissioner and any affected individuals when we become aware of a "notifiable privacy breach" — broadly, a privacy breach that is reasonably likely to cause serious harm (financial, physical, emotional, or reputational) to one or more affected individuals.
If we become aware that a privacy breach affecting personal information described in this policy is reasonably likely to cause serious harm — for example, unauthorised access to account credentials, exposure of payment-token records, leakage of support correspondence, or any other event meeting the Privacy Act's serious-harm threshold — we will:
We aim to make notifications without undue delay. If you believe you have been affected by a privacy breach we have not yet notified you about, please contact [email protected] immediately.
The right to be notified is separate from and in addition to your other rights under §9 — exercising one does not affect the others.
For any privacy-related query, access request, correction request, deletion request, complaint, or general question about this policy:
[email protected]For operational matters about the Courses themselves (course content, refunds, account access, billing) — see the Terms and Conditions and the Refund Policy and email [email protected].
We aim to respond to privacy enquiries within 5 working days and to resolve complaints within 20 working days. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner at privacy.org.nz.
*This policy is published for the courses storefront. Questions for external counsel review are maintained separately in legal/DOUGAL-REVIEW-BRIEF.md (not customer-facing).*