Legal
Last updated: 26 April 2026
InCorr Method Ltd(“InCorr”, “we”, “our”) is the data controller for personal data collected through the InCorr membership platform. Our registered address and contact for all privacy matters is privacy@incorrmethod.com.
| Data | Why we collect it | Lawful basis |
|---|---|---|
| Name, email, role | Account creation and login | Contract (Art. 6(1)(b)) |
| Password (hashed) | Authentication — you log in securely | Contract (Art. 6(1)(b)) |
| Learning progress | Gating, progress tracking, curriculum position | Contract (Art. 6(1)(b)) |
| Session tokens | Keeping you signed in | Legitimate interest (Art. 6(1)(f)) |
We do not collect special category data (health, biometric, etc.) and we do not use your data for advertising or sell it to third parties.
We use a single authentication session cookie (HttpOnly, Secure, SameSite=Lax) to keep you signed in. This cookie is strictly necessary for the service to function and does not require consent under ePrivacy rules. We do not use any tracking, analytics, or advertising cookies.
We keep your account data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Backups are purged within 60 days. You can delete your account at any time from Settings → Danger zone.
Under UK/EU GDPR you have the right to:
To exercise any of these rights, email privacy@incorrmethod.com or use the controls in your account settings. We will respond within 30 days.
We use the following sub-processors, each with a signed Data Processing Agreement:
Passwords are hashed using bcrypt and never stored in plain text. All data is transmitted over HTTPS. Session cookies are HttpOnly and Secure. We conduct regular security reviews and will notify affected users within 72 hours of becoming aware of a personal data breach, in line with GDPR Article 33.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with your national supervisory authority. In the UK that is the Information Commissioner's Office (ICO). In Ireland it is the Data Protection Commission (DPC).
We will notify you by email of any material changes to this policy at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.