Privacy & Data Protection

How Pathways Academy handles personal information when you visit VirtualLearning365.com or work with us.

Last updated: September 9, 2026

1. Who is responsible for your data?

Pathways Academy: An International Educational Community, LLC is a Delaware limited liability company headquartered at 17 Osprey Cir, Palm Coast, Florida 32137, United States. Pathways Academy is the data controller for personal data that Pathways collects and decides how to use.

Privacy requests can be sent to tatiana.b.gilliam@gmail.com.

2. What personal data may we collect?

Depending on how you interact with Pathways, we may process:

  • Contact information such as your name, email address, telephone/WhatsApp details and country or time zone.
  • Information you provide when asking about services, booking a consultation or communicating with us.
  • Student and family information needed for educational planning, enrollment support, college guidance, career planning or relocation support.
  • Academic information such as school history, courses, grades, transcripts, testing, university interests, application documents and deadlines.
  • Information needed to coordinate enrollment with an educational provider when you ask us to do so.
  • Scheduling information submitted through Calendly.
  • Website usage information collected by Google Analytics only after you consent to analytics.
  • Business, invoicing and payment records where applicable.

3. Information about children and students

Pathways works with K–12 students, so some information we process may relate to children. Our services are generally arranged by a parent, guardian or other responsible adult. We do not rely on a child clicking a website consent button as the basis for providing our educational services.

A family may sometimes choose to share information about learning needs, disability, health or other sensitive circumstances because it is relevant to educational planning. We ask families to provide only what is reasonably necessary. Where special-category personal data is processed and the law requires consent, we rely on explicit consent or another lawful basis permitted by applicable law and apply additional care to that information.

4. Why we use personal data and our legal bases

PurposeTypical legal basis
Responding to inquiries and discussing possible servicesSteps requested before entering a contract and, where appropriate, legitimate interests in responding to inquiries
Providing educational consulting, planning, support and coordinationPerformance of a contract or steps requested in connection with a contract
Coordinating enrollment with an educational provider at your requestPerformance of a contract and your requested instructions
Maintaining invoices, accounting and required business recordsLegal obligations and legitimate business administration
Protecting our systems, preventing misuse and maintaining securityLegitimate interests in operating a secure website and business
Google AnalyticsConsent. Analytics is not loaded unless you choose “Accept analytics.”

5. Who may receive personal data?

We do not sell personal data. We may disclose or make data available only where reasonably necessary for the service, including to:

  • Calendly, when you use our scheduling service.
  • Google, for email services and, only after consent, Google Analytics.
  • Netlify, which hosts this website and may process technical hosting and security information.
  • Educational providers, such as ASU Prep Global Academy, when a family asks Pathways to coordinate enrollment or support and the information is needed for that purpose.
  • Professional advisers, accountants, legal advisers or public authorities where necessary or legally required.

Educational providers may act as independent controllers for information they receive under their own enrollment, educational and legal responsibilities. Their own privacy notices also apply.

6. International data transfers

Some service providers used by Pathways operate or store data outside the European Economic Area, including in the United States. When GDPR-protected personal data is transferred internationally, we rely on the safeguards made available under applicable law and the relevant provider terms, which may include adequacy decisions, the EU–U.S. Data Privacy Framework and/or European Commission Standard Contractual Clauses.

Calendly states that invitee data is stored in U.S.-based data centers and that its Data Processing Addendum includes Standard Contractual Clauses for EEA transfers. Netlify states that it uses legal transfer mechanisms including Standard Contractual Clauses where needed. Google provides GDPR data-processing terms and international-transfer safeguards for Google Analytics.

7. How long do we keep personal data?

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to legal and administrative requirements. Our general approach is:

  • Initial inquiries that do not become a client relationship: generally up to 12 months after the last meaningful contact, unless there is a reason to keep them longer or you ask us to delete them sooner.
  • Active student/client records: for the duration of the relationship and for a reasonable period afterward when needed to answer follow-up questions, document services provided, resolve disputes or support continuing educational planning.
  • Financial and tax records: retained for the period required by applicable U.S. federal, state and other relevant accounting and tax laws.
  • Consent preferences: retained as necessary to remember your website privacy choice.
  • Analytics: subject to the retention settings in our Google Analytics account and only for visitors who consented.

Where there is a legal claim, safeguarding issue or legal requirement, relevant data may be kept longer when necessary.

8. Cookies, local storage and analytics

The site uses necessary browser storage to remember your privacy choice. Google Analytics is optional and does not load until you actively accept analytics.

You can reject analytics when the banner first appears or later reopen Cookie Settings from the footer and change your choice. If you withdraw consent, the site disables further Google Analytics collection from that browser and attempts to remove Google Analytics cookies set for this site.

See our Cookie & Analytics Notice for more detail.

9. Calendly scheduling

Calendly does not load inside this website until you click the button to load the scheduler. If you choose to load or open Calendly, information you enter is processed through Calendly so that your appointment can be scheduled.

Calendly acts as a processor for customer scheduling data in many customer-use contexts and publishes its own privacy notice, Data Processing Addendum and international-transfer information. You can review those documents before using the scheduler.

10. Your GDPR rights

Subject to the circumstances and applicable law, you may have the right to:

  • Be informed about how your personal data is used.
  • Access personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Request erasure of personal data where the legal conditions are met.
  • Request restriction of processing in certain circumstances.
  • Receive certain personal data in a portable format.
  • Object to processing based on legitimate interests in certain circumstances.
  • Withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that was lawful before withdrawal.
  • Complain to a data-protection supervisory authority.

To exercise a right, email tatiana.b.gilliam@gmail.com. We may need enough information to verify your identity before acting on a request. GDPR requests are normally answered within one month, subject to lawful extensions for complex requests.

11. Complaints and supervisory authorities

If GDPR applies to the processing of your personal data, you may have the right to lodge a complaint with a data-protection supervisory authority, including in the EU or EEA country where you habitually reside, where you work, or where you believe an infringement occurred.

If you are in the EU or EEA, the appropriate supervisory authority will generally depend on where you live, work, or where the issue occurred.

12. EU representative

Article 27 of the GDPR can require organizations established outside the EU that offer goods or services to people in the EU, or monitor their behavior, to appoint a representative in the EU unless a legal exception applies. Pathways Academy will maintain any representative appointment required by applicable law. If an EU representative is formally appointed, this notice will be updated with the representative’s contact details.

13. Automated decision-making

Pathways does not use the website to make decisions about students or families solely by automated means that produce legal or similarly significant effects.

14. Security

We use reasonable technical and organizational measures appropriate to a small educational consulting business, including HTTPS on the website, limited access to records, password-protected systems and established third-party service providers. No internet or storage system can be guaranteed to be completely secure.

15. Changes to this notice

We may update this notice when our services, providers or legal obligations change. The date at the top shows when the notice was last updated.

16. Contact

Privacy questions and requests:
tatiana.b.gilliam@gmail.com