Privacy hub

Legal Bases Matrix

A purpose-by-purpose reference for the legal bases relied on where GDPR applies.

This appendix forms part of the Brain-Shot Academy privacy hub.

Privacy hub documents: Main Privacy Notice, Cookie Policy, Cookie Inventory, Processor Appendix, International Transfers Appendix, Retention Appendix, Legal Bases Matrix, and Required and Optional Data Matrix.

It provides a purpose-by-purpose view of the legal bases that Brain-Shot Academy relies on under the GDPR, where the GDPR applies, using broader public-facing categories rather than system-by-system technical detail.

Purpose-by-purpose matrix

Processing purpose / activityMain data involvedMain legal basis or basesDescription
Account access, authentication, recovery, and service continuityaccount, identity, contact, and access dataPerformance of a contract or steps at the user’s request before entering into a contractCovers sign-in, session handling, account recovery, routing, permissions, and shared account continuity
Service delivery, entitlements, and protected accessaccount, access, profile, and service dataPerformance of a contractCovers Airport, protected services, entitlements, and related access control. Security-specific protective processing is addressed separately in the security and fraud-prevention row.
Learning delivery, participation, progress, and learner supportaccount, access, learning, participation, and support dataPerformance of a contract; legitimate interestsCovers courses, progress, completion, live participation, downloads, and learner continuity
Partner and public profile functionspartner profile, certification, interaction, and related service dataPerformance of a contractCovers partner pages, badges, partner interactions, and related features. Partner profile information is provided by the partner directly, and user traffic may go from Brain-Shot Academy to the partner if the user chooses to visit the partner's website.
Purchases, orders, payments, refunds, and entitlement administrationidentity, contact, billing, transaction, and entitlement dataPerformance of a contractCovers checkout, payment handling, refunds, entitlement fulfilment, and related transaction administration
Accounting, tax, audit, and statutory financial recordkeepingidentity, contact, billing, transaction, and accounting recordsLegal obligationsCovers accounting, tax, statutory retention, auditability, and related required financial administration
Support, service communications, and continuitycontact, correspondence, support, and service relationship dataPerformance of a contract; legitimate interests for general relationship continuityCovers enquiries, support handling, operational notices, continuity records, and communication through email, WhatsApp, or platform-based tools where relevant
Website enquiries, bookings, calls, consultations, and related pre-contract stepscontact, request, registration, scheduling, and enquiry dataSteps at the user’s request before entering into a contractCovers contact forms, registrations, consultations, calls, meetings, and similar pre-service administration
Event, webinar, and enrolled-service participationcontact, registration, participation, event, and recording-related participation dataPerformance of a contractCovers event administration and live-session participation once the person is enrolled, booked into the service, or attending as part of the service. Where sessions are recorded, participants are warned before recording starts.
CRM contact management and customer relationship administrationcontact, relationship, communication, and preference dataLegitimate interestsCovers lead management, segmentation, follow-up, and customer continuity
Marketing and campaign communicationscontact details, marketing preferences, consent records, and campaign interaction dataConsentOpt-out is available through the unsubscribe link for non-account holders and through account settings where the recipient has a Brain-Shot Academy account
Consent, cookie, and preference managementconsent and preference records, identifiers needed to apply choicesLegal obligations; legitimate interests; consentNeeded to evidence and respect choices
Security, fraud prevention, anti-abuse, telemetry, and platform protectiondevice, browser, usage, security, audit, and risk dataLegitimate interests; legal obligations where applicableCovers misuse detection, challenge-response controls, temporary protective measures such as challenge steps, rate limiting, or short-term restrictions, supportability, and platform integrity; more serious actions are generally subject to human review
Public-site analytics and campaign measurementwebsite, device, usage, consent, and analytics dataConsent where required; legitimate interests for strictly necessary technical measurement where applicableOptional analytics or campaign technologies are kept separate from essential processing
Internal administration, governance, and legal protectionoperational, audit, compliance, and dispute-related recordsLegitimate interests; legal obligations where mandatoryCovers protected internal functions, moderation, governance, legal defense, and rights protection