Privacy Policy
Last updated: 30 August 2026 · Version 2026-08-30
1. Who we are
This privacy policy explains how Ihya Institute ("we", "us", "our") collects, uses, and protects personal data through IhyaPortal, our student and course management system.
Data controller: Ihya Institute
Address: Clemency House, Nugget St, Oldham OL4 1BN, United Kingdom
Contact for privacy queries: info@ihyainstitute.co.uk
2. What personal data we collect
- Account & login data: name, email address, hashed password, role, and sign-in activity for anyone with a portal account (students, parents/guardians, instructors, and staff).
- Student records: name, date of birth, contact email, phone and address (where given), enrolment and attendance history, course/section registrations.
- Family & guardian data: where a student is linked to a family, the name, email, phone number, and address of parents/guardians associated with that family.
- Payment data: course fee and subscription status, processed and stored via Stripe (see Section 6) — we do not store card numbers ourselves.
- Coursework and learning records: attendance records, grades and written feedback, work submitted for assignments (including uploaded files), and learning-journal entries recording a student's progress (for example Qur'an memorisation and revision).
- Messages and posts: direct messages between portal users (including attachments), comments on course streams, and announcements, together with reports made about a message.
- Notes and requests about a student: notes staff record about a student, and absence requests including the reason the family gives (which may mention health). Some notes are visible to the student's guardians; restricted notes are limited to staff. Because these can be sensitive, we treat them with particular care.
- Staff data: for instructors and staff, a staff profile (biography, qualifications, availability) and compliance documents uploaded for them, with any expiry dates. A staff profile may also hold a separate public headline and biography; those two are shown on this website, under the member of staff's name, but only after an administrator publishes them. Everything else in a staff profile stays inside the portal.
- Consent records: when you tick a consent box we record who agreed, what they were shown, the policy version, the date and time, and the IP address and browser it came from, so we can demonstrate consent later.
- Technical data: IP address and basic request logs generated automatically by our hosting infrastructure and security logs (for example sign-in attempts); the mobile app's push notification token for your device, if you use it; and the cookies described in Section 8.
3. Children's data and parental consent
Some of our students are under 18. Where a student is a minor, their enrolment, portal account (if any), and associated data are set up and managed by a parent or legal guardian, who provides consent on the child's behalf and is the primary point of contact for that student's data. Guardians can contact us at any time using the details in Section 1 to ask about, correct, or request removal of their child's data.
4. Why we process this data (lawful basis)
- Contract: to enrol students, run courses, and take payment for them.
- Legitimate interests: to record attendance, administer accounts, and keep the service secure.
- Legal obligation: to keep financial records required by UK tax law.
- Consent: from a parent/guardian, where processing relates to a minor student, as described in Section 3.
5. How we use this data
To provide portal accounts and course access; to record and report attendance and progress; to process course fee payments and subscriptions; to send account emails (welcome emails with sign-in details, and password-reset emails) and emails or push notifications about portal activity such as messages, announcements and absences, which you can control in your notification settings; and to keep the records required for our own administration and legal compliance. We do not use personal data for marketing, and we do not sell personal data to anyone.
6. Who we share data with
- Stripe, Inc. — processes course fee and subscription payments on our behalf. Stripe may store and process data outside the UK (including in the US), under its own privacy policy and appropriate safeguards (such as the UK's International Data Transfer Agreement / standard contractual clauses).
- Our email delivery provider — used solely to send account and password-reset emails triggered by actions on the portal.
- Google LLC (Google Workspace) — our database is backed up nightly to Google Drive within Ihya Institute's own Google Workspace account, for disaster-recovery purposes. This backup includes the full range of data described in Section 2, including children's data such as attendance records. Google may store and process this data outside the UK (including in the US), under its own privacy policy and appropriate safeguards for international transfers.
- Expo (Expo Application Services) — used to deliver push notifications to the IhyaPortal mobile app. Expo receives your device's push token so notifications can be routed to it and, where you have chosen to see message previews in your notifications, the text of the relevant direct message, stream comment, or announcement is also sent to Expo so it can be shown in the notification itself. If previews are switched off, only a generic notification (for example "You have a new notification") is sent instead. Expo may store and process this data outside the UK (including in the US), under its own privacy policy and appropriate safeguards for international transfers.
We do not share personal data with any other third party except where required by law.
7. How long we keep data
We keep student, family and account records for as long as the student is enrolled or the account is active, and afterwards so that attendance, progress and enrolment history stays accurate. These records are not deleted on a fixed timetable — instead, you can ask us to erase them at any time (see Section 10). Financial records (payments, invoices) are kept for at least 6 years to meet UK tax record-keeping requirements.
Some records are removed automatically on a fixed schedule:
- Sign-in attempt logs (including IP addresses) and family security audit logs: 12 months.
- Expired or signed-out session records: 30 days after they end.
- Records of successfully delivered notifications: 90 days.
- In-app notifications you have read: 12 months.
- Files uploaded for assignments: deleted 30 days after the work is marked. The grade and any written feedback are kept.
- Saved registration form drafts and rate-limiting records: minutes to hours.
8. Cookies
IhyaPortal uses a small number of first-party cookies: the session and security cookies that keep you signed in safely, and a few convenience cookies that only remember choices you make on this site (for example your display settings). We do not use any analytics, advertising, or third-party tracking cookies. Every cookie is listed, with its purpose and lifetime, in our Cookie Policy.
9. Security
Passwords are never stored in plain text — they are hashed using bcrypt before being saved. All traffic to the portal is encrypted with HTTPS/TLS. Access to student, family, and payment data is restricted by role, so only staff who need it for their role can see it.
10. Your rights under UK GDPR
You (or, for a minor student, their parent/guardian) have the right to:
- Ask us what personal data we hold about you and get a copy of it (right of access).
- Ask us to correct inaccurate or incomplete data (right to rectification).
- Ask us to delete your data, where we're not required to keep it (right to erasure).
When we carry out an erasure request, we anonymise the records rather than deleting the rows outright: every identifier — names, email addresses, phone numbers, addresses, notes written about you, and messages you sent — is removed or replaced, uploaded files are deleted, and any signed-in sessions are ended. Attendance, grade and enrolment history remains, but in a form that no longer identifies anyone, and financial records are kept for the statutory 6-year window described in Section 7.
You can also:
- Ask us to restrict or object to certain processing.
- Ask for your data in a portable, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at info@ihyainstitute.co.uk. We will respond within one month.
11. Complaints
If you're unhappy with how we've handled your data, please contact us first at info@ihyainstitute.co.uk so we can try to resolve it. You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk · 0303 123 1113
12. Changes to this policy
We may update this policy from time to time, for example as the portal gains new features. The "Last updated" date and version number at the top of this page will always reflect the most recent version. When you agree to this policy we record which version you agreed to, so we can always tell you exactly what you were shown.