Privacy Policy

Effective date: 25 August 2026
Last updated: 26 August 2026

This Privacy Policy explains how Boxing Blueprint Limited, trading as Blueprint Courses ("Blueprint Courses", "we", "us" or "our"), collects, uses, shares and protects personal information when you visit blueprintcourses.com, create an account, purchase or access a course, contact us, participate in a promotion, or otherwise use our websites, course platform, content and related services (together, the Services).

Boxing Blueprint Limited is the controller of the personal information described in this Privacy Policy unless we state otherwise. We are a company registered in England and Wales under company number 15367053, with our registered office at 18 Regency Mews, Isleworth, England, TW7 7LX.

Please read this Privacy Policy carefully. If you do not wish to provide information that we need to supply, secure or administer the Services, we may be unable to create or administer your account, process your purchase, provide course access, investigate misuse, verify entitlement to use the Services, or respond to your request. Where reasonably necessary to protect the Services, our users, our content or our legal rights, we may restrict, suspend or terminate access while we carry out appropriate security, payment, fraud, piracy or account-integrity checks.

This Privacy Policy describes our processing of personal information. It does not restrict any rights or remedies that Blueprint Courses may have under applicable law or under our Terms and Conditions, and it does not give you contractual rights beyond those provided by applicable law or any express contractual commitment we make elsewhere.

1. Information we collect

The information we collect depends on how you interact with us and which parts of the Services you use.

Information you provide to us

We may collect:

  • Account and identity information, such as your name, email address, username, password or other login credentials, age or date of birth where relevant, and account preferences.

  • Contact information, such as your email address, telephone number, postal address and the content of communications you send to us.

  • Transaction information, such as the courses or products purchased, purchase date, price, currency, discount code, billing address, payment status, refunds and transaction identifiers. Payments may be collected directly by our payment providers. We do not ordinarily receive or retain complete payment-card details.

  • Course and activity information, such as enrolments, lessons viewed, viewing progress, completion status, downloads, saved items, quiz or assessment responses, and other interactions with course content.

  • User content, such as reviews, ratings, testimonials, comments, survey responses, photographs, videos, competition entries, questions, feedback and any other material you choose to submit.

  • Customer-support information, including enquiries, complaints, call or message records, attachments and information used to verify your identity or resolve an issue.

  • Marketing preferences, including whether you wish to receive marketing and how you interact with our emails and campaigns.

  • Information about another person, where you purchase a gift or otherwise ask us to provide something to them. You must have authority to provide their information and should direct them to this Privacy Policy.

  • Any other information you choose to provide to us.

Please do not send us health information, biometric information, information about criminal convictions, or other special-category or highly sensitive personal information unless we specifically request it and explain why it is needed. If you voluntarily include such information in a message, review or other submission, we will process it only as permitted by law and may delete it where it is not needed.

Information collected automatically

When you use the Services, we and our providers may automatically collect:

  • IP address and approximate location derived from it;

  • device identifiers, browser type, operating system, language and device settings;

  • referring and exit pages, URLs, date and time of access, session duration and clicks;

  • pages, videos, lessons and features viewed or used, course progress and playback information;

  • cookie identifiers, advertising identifiers and similar online identifiers;

  • diagnostic, security, crash and error information;

  • account-access and security information, such as login dates and times, session identifiers, failed login attempts, device and network information, concurrent or unusual access patterns and indicators of suspected account sharing, fraud, scraping, piracy or other misuse; and

  • information about how you interact with our emails, such as whether an email was opened or a link was selected.

We collect some of this information through cookies, pixels, tags, local storage, scripts and similar technologies. See section 7 below.

Information from other sources

We may receive information from:

  • our course platform, website host, payment providers and other service providers;

  • social-media or third-party login services, where you choose to connect an account;

  • advertising, analytics and marketing partners, where permitted by law;

  • course instructors, creators, affiliates, referral partners and business partners;

  • publicly available sources;

  • fraud-prevention, identity-verification and security providers; and

  • payment processors, banks, card schemes and other financial-service providers in connection with payments, refunds, disputes, chargebacks, fraud checks and transaction risk.

We may combine information received from different sources with information we already hold.

2. How we use personal information

We may use personal information to:

  • create, authenticate, maintain and administer accounts;

  • process and administer purchases, payments, refunds, discounts, credits, invoices, chargebacks and payment disputes;

  • provide and manage course access, playback, progress, downloads and other Service features;

  • personalise the Services, remember preferences and recommend content, courses or products;

  • communicate about purchases, accounts, course access, service changes, security and support;

  • respond to enquiries, complaints, rights requests and technical problems;

  • send marketing, promotional offers, abandoned-basket reminders, surveys and news where permitted;

  • measure campaign performance and understand whether communications are opened or selected;

  • operate, test, monitor, analyse, maintain, improve and develop the Services, content, pricing, promotions and business;

  • conduct research, reporting, audience analysis, forecasting, segmentation, attribution, A/B testing, product development and commercial planning;

  • create aggregated or anonymised statistics, insights and business intelligence;

  • protect accounts, users, instructors, Blueprint Courses and others from fraud, abuse, piracy, unauthorised account sharing, credential sharing, scraping, circumvention of access controls, cyberattacks and other unlawful, unauthorised or harmful activity, including by analysing account, session, device, network and usage patterns;

  • monitor, investigate and enforce our terms, licences, access restrictions and other agreements; detect or evidence breaches; protect our intellectual property, confidential information, revenue and other commercial interests; and take or support enforcement action where appropriate;

  • verify identity, entitlement, eligibility, age, payment status, account ownership or authority where reasonably necessary, and require re-authentication or additional verification where we reasonably consider this appropriate;

  • moderate, publish and manage reviews, comments, testimonials and other user content in accordance with the circumstances in which it was provided and any applicable terms;

  • comply with tax, accounting, consumer-protection, data-protection and other legal obligations;

  • establish, exercise, investigate, preserve evidence for or defend legal claims, complaints, disputes, chargebacks and enforcement matters, and obtain professional advice;

  • support a sale, investment, financing, restructuring, merger, acquisition or other business transaction, including related due diligence; and

  • carry out any other purpose that we explain when the information is collected or that you authorise.

Where reasonably possible, we use aggregated or anonymised information for research, analytics, reporting, product development and commercial planning. Information that is genuinely anonymised is not personal information, and we may retain and use it for any lawful purpose.

3. Our lawful bases

UK data-protection law requires us to have a lawful basis for each use of personal information. Depending on the circumstances, we rely on:

  • Contract: where processing is necessary to enter into or perform a contract with you, including administering your purchase, account and course access.

  • Legitimate interests: where processing is necessary for our or another person's legitimate interests and those interests are not overridden by your rights. These interests include operating, developing and growing our business; understanding customers and audiences; improving, testing and personalising the Services; analytics, attribution and performance measurement; appropriate direct marketing; protecting our network and information systems; protecting paid content and intellectual property; detecting and preventing fraud, piracy, account sharing and misuse; recovering debts and handling chargebacks; enforcing agreements; maintaining evidence of transactions and misuse; protecting legal and commercial interests; and managing corporate transactions and legal claims. Direct marketing, certain intra-group administrative transfers and network and information-system security may constitute legitimate interests under UK data-protection law, although we will still apply the requirements that are relevant to the particular processing.

  • Consent: where you have made a freely given, specific and informed choice, including for certain marketing and non-essential cookies or similar technologies. You may withdraw consent at any time, but this will not affect processing already carried out lawfully.

  • Legal obligation: where processing is necessary to meet an obligation imposed on us by law, regulation, court order or a competent authority.

  • Recognised legitimate interests: where necessary and permitted by UK law for a statutory recognised purpose, such as preventing, detecting or investigating crime (including fraud), safeguarding, responding to qualifying emergencies, or responding to a qualifying request from an organisation performing a public task or official function. We will rely on this basis only where the relevant statutory condition applies.

  • Vital interests: in rare cases where processing is necessary to protect someone's life or physical safety.

If we need to use personal information for a materially different purpose, we will consider whether the new use is compatible with the original purpose and provide further information or obtain consent where required.

4. When information is required

Some information is required to enter into or perform our contract with you, verify that you remain entitled to use the Services, protect the integrity of the Services, or comply with law. For example, we need sufficient account, contact and transaction information to process a purchase and provide course access. If required information is not provided, cannot be verified, or appears inconsistent with our security or payment records, we may, where lawful and appropriate, decline or cancel a transaction, withhold or suspend access, require further verification, close an account, preserve relevant records, or be unable to respond to a request.

5. Marketing

We may send you marketing about Blueprint Courses and our similar courses, content, products, services, events and offers where you have consented or where the law otherwise permits us to do so, including under the customer "soft opt-in" where its requirements are met. Where permitted by law, we may use information about purchases, course interests, engagement and campaign interactions to select or tailor the marketing we send and to measure its effectiveness.

You can opt out at any time by selecting the unsubscribe link in an email, changing available account preferences, or contacting us. We may retain identifying and contact information on a suppression list for as long as reasonably necessary to ensure that your opt-out is honoured, prevent accidental re-subscription, demonstrate compliance and resolve disputes. Opting out of marketing will not stop non-marketing messages that we reasonably need to send about your account, purchase, security, course access, changes to the Services, our terms, suspected misuse, legal matters or our legal obligations.

We will not send third-party electronic marketing to you without the permission required by law. We may, however, promote courses, bundles, events, products or services featuring instructors, creators, affiliates, sponsors or commercial partners where they form part of Blueprint Courses' own offering or marketing. Where permitted and subject to any required consent, we may also use advertising-platform tools to measure campaigns, suppress existing customers from campaigns, create audiences or reach people with relevant Blueprint Courses advertising.

6. Reviews, testimonials and public areas

If you submit information for publication, post in a public area, or agree that we may use a review or testimonial, the relevant information may be visible to other users and the public and may be indexed by search engines or redistributed outside our control.

Subject to applicable law, the context in which the content was submitted, and any separate terms or permissions, we may display, reproduce, format, excerpt, edit for length or clarity, and use submitted reviews, ratings, feedback and testimonials to operate, improve and promote Blueprint Courses. Do not include information that you do not want made public. A request to remove or alter public content will be considered in accordance with applicable law and our contractual rights. Even where content is removed from public display, we may retain a non-public copy where reasonably necessary for moderation history, fraud prevention, evidence, dispute resolution, legal claims, compliance or protection of our rights. Removal from our Services may not remove copies, quotations, screenshots, caches, archives or other reproductions previously made by third parties outside our control.

7. Cookies and similar technologies

We and our providers may use cookies, pixels, tags, local storage, scripts and similar technologies to:

  • keep the website and course platform secure and functioning;

  • remember settings and account sessions;

  • understand and measure use of the Services;

  • diagnose errors and improve performance;

  • personalise content and recommendations;

  • measure emails and marketing campaigns; and

  • deliver or measure advertising, where permitted.

We may use storage and access technologies without consent where an applicable legal exception allows us to do so. Depending on the technology and purpose, this may include technologies used for transmission of communications, technologies strictly necessary to provide a service you request, qualifying statistical or analytics purposes, qualifying appearance or functionality purposes, or another applicable statutory exception. Where an exception requires us to provide information or a simple means of objecting, we will do so. We will request consent before using technologies for purposes for which consent is required, including non-exempt personalised or behavioural advertising. You can make available choices through our cookie banner or settings tool and, where relevant, through your browser or device settings. Withdrawing consent or objecting will not affect prior lawful use, and refusing or blocking some technologies may reduce, disable or adversely affect certain features or functionality.

Further information, including the technologies and providers in use, should be set out in our Cookie Policy or cookie settings tool. Where a third party independently determines how it uses information collected through its technology, its own privacy policy will also apply.

8. How we share personal information

We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy to:

  • Service providers that support hosting, course delivery, cloud storage, payments, accounting, email, customer support, analytics, advertising, security, fraud prevention, identity verification, anti-piracy, content protection, content delivery, video playback, monitoring, back-ups and other business operations.

  • Instructors, creators and production partners where needed to deliver a course, answer course-related questions, manage a collaboration, measure performance, or protect relevant rights. We will not give an instructor unrestricted access to customer information unless this is necessary and lawful.

  • Affiliates and group companies, including any entity that controls, is controlled by, or is under common control with us in the future, where the sharing is necessary for administration, service delivery, security, business operations or the other purposes described in this Privacy Policy.

  • Advertising, analytics and marketing partners where permitted by law and, for cookies or similar technologies, subject to any required consent.

  • Professional advisers and insurers, including lawyers, accountants, auditors, bankers and insurance providers.

  • Authorities, payment participants and other third parties where we reasonably believe disclosure is necessary or appropriate to comply with law or legal process; respond to a lawful request; protect rights, property, safety or security; investigate suspected wrongdoing; prevent, detect or evidence fraud, piracy, account sharing, abuse or cyber incidents; handle payment disputes or chargebacks; recover amounts owed; or establish, exercise or enforce an agreement or legal claim.

  • Parties to a business transaction, including actual or prospective buyers, sellers, investors, lenders, advisers and other participants in a financing, investment, reorganisation, merger, acquisition, sale of assets, insolvency or similar event. Information may be disclosed during confidential due diligence and transferred as a business asset, subject to applicable law.

  • Other persons at your direction or with your permission, or where you intentionally make information public.

We do not sell personal information for money. Some advertising-related disclosures may be treated as a "sale", "sharing" or targeted advertising under laws outside the UK. Where such laws apply, we will provide any required notice and choice.

Where a recipient acts as our processor, it is required to process personal information for the relevant services under appropriate contractual and security requirements. Some recipients, including payment providers, advertising platforms, professional advisers or authorities, may act as independent controllers and may determine their own purposes and means of processing. In those cases, their own privacy information may also apply. We are not responsible for an independent controller's compliance except to the extent applicable law provides otherwise.

9. International transfers

Some providers and recipients may be located outside the United Kingdom, including in the United States, or may access information from another country. Those countries may have different data-protection laws.

Where UK law treats a disclosure as a restricted international transfer, we will use a permitted transfer mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, another approved safeguard, or a statutory exception where applicable. We may also carry out any transfer-risk assessment required by law.

You may contact us for further information about the safeguards relevant to your information. We may provide a summary or a redacted copy where necessary to protect confidential or commercially sensitive information.

10. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, taking account of the nature of the information, the purposes for which it is used, legal and regulatory requirements, limitation periods, the risk of fraud or piracy, the need to protect paid content and intellectual property, the possibility of complaints, chargebacks or disputes, and our need to establish, exercise or defend legal rights. The periods below are general guidelines rather than promises that a particular record will be deleted on a specific date.

Our usual approach is to retain:

  • account, entitlement, access and course records while an account is active and for up to six years after closure or the end of the customer relationship, and longer where a limited record is reasonably necessary to prevent repeated abuse, enforce an account restriction or establish or defend legal rights;

  • transaction, invoice, tax and accounting records for at least the period required by law, which will commonly be six years from the end of the relevant financial year;

  • customer-service, complaint, refund, chargeback, security, fraud, anti-piracy and dispute records for up to six years after the matter is closed, or longer where a claim, investigation, repeated misuse concern or legal hold applies;

  • marketing-contact information until you opt out or we determine it is no longer useful, with limited suppression information retained for as long as reasonably necessary to honour your choice;

  • cookie and analytics information for the period shown in the cookie settings tool or the relevant provider's retention controls; and

  • public content, course activity and records relevant to our intellectual-property or contractual rights for as long as reasonably necessary for the applicable purpose.

We may retain information for longer if reasonably required or permitted by law, regulation, litigation, an investigation, a legal hold, security concerns, fraud or piracy prevention, chargeback or payment disputes, the protection of intellectual property, enforcement of account restrictions, or the establishment, exercise or defence of legal rights. Following account closure or a deletion request, we may retain a limited record where necessary to document the transaction or request, honour an opt-out, prevent fraud or repeated misuse, maintain security, enforce our terms, or demonstrate compliance. We may delete information earlier where it is no longer needed. Back-up, disaster-recovery, audit and security copies may remain for a limited period and may not be immediately removed from every system, provided they remain appropriately protected and are not used for incompatible purposes.

We may retain aggregated or genuinely anonymised information indefinitely.

11. Security

We use technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised access and disclosure. These measures may include access controls, provider due diligence, authentication, encryption where appropriate, monitoring, back-ups and staff or contractor confidentiality obligations.

No website, account, storage system, payment method or internet transmission can be guaranteed to be completely secure. You are responsible for using a strong, unique password, keeping login details confidential, preventing unauthorised account sharing, maintaining the security of your devices and networks, signing out of shared devices, and notifying us promptly if you suspect unauthorised access. To protect the Services, paid content, users and our rights, we may use automated or manual security and fraud controls and may require re-authentication, reset credentials, limit concurrent sessions, restrict functionality, block devices or network addresses, or suspend access while we investigate suspected compromise, fraud, piracy or misuse, where lawful and proportionate.

12. Children

The Services are not directed at children under 13, and we do not knowingly permit a child under 13 to create an account or provide personal information directly to us. A person under 18 should use the Services only with the involvement and permission of a parent or guardian, and purchases for them should be made or authorised by an adult.

We may take reasonable steps to verify age, parental involvement or authority where we consider this necessary. If we learn or reasonably suspect that we have collected personal information directly from a child in circumstances where parental authorisation or another lawful basis was required but not obtained, we may restrict access, require further verification, close the account and delete or restrict the information, subject to any legal need to retain limited records. Parents or guardians may contact us if they believe a child has provided information improperly.

13. Your rights

Depending on the circumstances and applicable law, you may have the right to:

  • receive information about how we use your personal information;

  • request access to personal information we hold about you;

  • ask us to correct inaccurate or incomplete information;

  • ask us to delete personal information;

  • ask us to restrict processing;

  • object to processing based on legitimate interests, including profiling based on those interests;

  • object at any time to processing for direct marketing;

  • receive certain information in a structured, commonly used and machine-readable format and ask that it be transferred where technically feasible;

  • withdraw consent at any time where we rely on consent; and

  • complain to us or to the Information Commissioner's Office.

You have an absolute right to object to the use of your personal information for direct marketing.

These rights are not absolute and do not necessarily require us to delete, disclose, stop using or transfer every item connected with you. We may retain, withhold, redact or continue to process information where the law permits or requires it, including to perform a contract, comply with a legal obligation, protect the rights and freedoms of other people, protect confidential information or intellectual property, prevent fraud or misuse, establish or defend legal claims, or rely on another applicable exemption.

To protect personal information and avoid disclosing it to the wrong person, we may ask for information reasonably needed to verify your identity, locate the relevant records, understand the scope of your request and confirm the authority of anyone acting for you. Where a request is broad or unclear, we may ask you to specify the information or processing concerned where the law allows. We are not required to create information that does not exist or retain information solely because you may exercise a right in the future. We may withhold or redact information relating to other people, legally privileged material, confidential business information or other material where an applicable exemption, restriction or protection permits us to do so. We may refuse to act on, or charge a reasonable fee for, a request where the law permits, including where a request is manifestly unfounded or excessive. We will respond within the time required by law and will explain any lawful extension, limitation or refusal.

We may use automated tools, rules, scoring or profiling for recommendations, personalisation, fraud indicators, security, account-integrity checks, payment-risk indicators, analytics and enforcement triage. At present, we do not generally use solely automated processing to make decisions about you that produce legal or similarly significant effects. UK law now permits certain significant automated decisions on a wider range of lawful bases where the required safeguards are provided. If we introduce processing of that kind, we will provide any information, human-review opportunity and other safeguards required by law.

14. Data-protection complaints

You can raise a concern or complaint about our use of personal information by emailing [email protected] or writing to us at the address in section 18. Please include enough information for us to understand the issue and identify the relevant account or interaction, but do not send unnecessary sensitive information.

We will provide the assistance required by law with making a complaint, acknowledge it within 30 days, make appropriate enquiries without undue delay, keep you informed as required and communicate the outcome without undue delay. We may request evidence or information reasonably necessary to verify identity, understand the complaint, locate relevant records, confirm authority to act for another person, or investigate the matter. We may consider related or overlapping complaints and rights requests together where appropriate, while continuing to meet the applicable legal requirements for each.

You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

We would appreciate the opportunity to address your concern first, but this does not limit your right to contact the ICO.

15. Third-party services and links

The Services may contain links to, integrations with, embedded services from, or content hosted by third parties. Independent third parties may collect information directly from you or your device under their own terms and privacy notices. We do not control independent third parties and, except to the extent the law provides otherwise, are not responsible for their privacy, security, availability, content or data-handling practices. Your decision to use a third-party service, follow a link or connect an account is subject to that third party's terms and privacy information, which you should review before providing information or enabling the connection.

16. Changes to ownership or control

If we explore, negotiate or complete an investment, financing, restructuring, merger, acquisition, sale of shares or assets, insolvency, joint venture, reorganisation or transfer of all or part of our business, courses, platform or operations, personal information may be disclosed under appropriate confidentiality arrangements to prospective or actual counterparties, investors, lenders, advisers and service providers for evaluation, due diligence, negotiation and completion. Personal information may then be transferred as part of the relevant business or assets. A successor, purchaser or reorganised entity may continue to process the information for the purposes described in this Privacy Policy or other compatible purposes, subject to applicable law and any further notice required by law.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Services, our practices, providers, technology, security measures, business, corporate structure or the law. Non-material changes may take effect when the revised policy is posted. Where a change materially affects how we use personal information, we will take any additional steps required by law, which may include providing a prominent notice, contacting you or requesting consent.

You should review this Privacy Policy periodically. Unless the law requires otherwise, the version published on our website is the current version. Continued use of the Services after an update does not remove any rights you have under applicable law and will not be treated as consent where consent is legally required.

18. Contact us

For privacy questions, rights requests or data-protection complaints, contact:

Boxing Blueprint Limited, trading as Blueprint Courses
Company number: 15367053
18 Regency Mews
Isleworth
England
TW7 7LX
Email: [email protected]