Privacy policy
We teach by looking closely at your work — not by collecting more of your data than we need. This policy explains, in plain language, what we hold, why we hold it, and the control you keep over it.
LAST UPDATED: July 1, 2026
Cohestra Learning, LLC (“Cohestra,” “we,” “us”) runs an online design school. This Privacy Policy covers the website at example.com, the course platform, and the critique sessions we host. By using them you agree to what is described here.
Who we are
Cohestra Learning, LLC is a limited liability company registered in New York, with its principal office at 123 Example Street, Suite 4B, New York, NY 10001 (Company No. LLC-2024-0198432). For the purposes of the GDPR we are the data controller for the information described here.
What we collect
We collect only what we need to run the school and the account you hold with us. That falls into four groups:
- Account details — your name, email address, password (stored only as a salted hash), and the time zone you study in.
- Membership & purchase records — which courses or membership you hold, start and cancellation dates, and invoices. Card numbers are handled by our payment processor and never reach our servers.
- Course activity — lessons completed, homework you submit, the written feedback your curator returns, and attendance at live critiques.
- Technical data — IP address, device and browser type, and pages visited, collected in aggregate to keep the platform secure and working.
How we use it
We use your information to:
- Give you access to the courses and membership you’ve paid for, and route your homework to the right curator.
- Process payments, send invoices, and manage renewals or cancellations.
- Send service messages — critique schedules, curator feedback notifications, and account or security notices.
- Send occasional updates about new courses or cohorts, only if you’ve opted in. You can unsubscribe from any such email in one click.
- Understand how the platform is used, so we can improve it, and keep it secure and free of abuse.
Your course work
The work you submit for critique is the heart of what we do, so we treat it carefully.
- Homework and portfolio pieces you upload are visible to your assigned curator and, where a session is a group critique, to the members of your cohort.
- Curators’ written feedback belongs to you: it stays in your account and remains available to you even after a subscription ends.
- We do not use your submitted work to promote Cohestra, in marketing or as teaching examples, without your specific written permission.
Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
- Contract — to deliver the courses, membership, and reviews you’ve signed up for.
- Legitimate interests — to secure the platform, prevent abuse, and improve our service, balanced against your rights.
- Consent — for marketing emails and non-essential cookies, which you can withdraw at any time.
- Legal obligation — to keep tax and accounting records as the law requires.
How long we keep it
- Account & course work — for as long as your account is open, and for 24 months after it closes, so you can return to your progress and feedback.
- Payment & tax records — for 7 years, as accounting law requires.
- Marketing preferences — until you unsubscribe or ask us to erase them.
When a retention period ends, we delete or irreversibly anonymize the data.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — a copy of the data we hold about you.
- Correction — to fix anything inaccurate or incomplete.
- Erasure — to have your data deleted, subject to records we must keep by law.
- Portability — a machine-readable export of data you gave us.
- Objection & restriction — to object to or limit certain processing.
- Withdraw consent — at any time, for anything based on consent.
To exercise any of these, email privacy@example.com. We respond within 30 days. If you’re in the EEA or UK and unhappy with our response, you may complain to your local data protection authority.
How we protect it
We use encryption in transit (TLS) and at rest, role-based access so staff see only what their work requires, and regular reviews of our security practices. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant regulator without undue delay.
Your Next Creative Chapter Starts Here.
Whether you’re building your first portfolio or leading international teams, the right guidance changes how you think—and what you’re capable of creating.