- Home
- Privacy Policy
Privacy Notice
Silicon Valley Futures Institute LLC
Silicon Valley Futures Institute LLC
Effective date: August 17, 2026
Last updated: August 17, 2026
Version: 1.0
1. Purpose and who we are
This Privacy Notice explains how Silicon Valley Futures Institute LLC (“SVFI,” “the Institute,” “we,” “us,” or “our”) collects, uses, shares, and protects information about you when you use our websites, learning platforms, assessment and proctoring systems, digital credentialing services, and related programs.
SVFI is a limited liability company organized under the laws of the State of California, with its principal place of business at 3000 El Camino Real, Building 4, Suite 200, Palo Alto, California 94306, United States.
We take privacy seriously for a specific reason. Much of what we hold is not casual browsing data: it is educational performance data, assessment records, identity verification material, and — in some programs — information about children. Those categories deserve stronger handling than a standard website policy provides, and this Notice reflects that.
If any part of this Notice is unclear, contact our Privacy Officer at privacy@thefuture.institute. Our Terms of Use and Cookie Notice also apply to your use of our Services. Capitalized terms not defined here have the meaning given in the Terms of Use.
2. Scope
This Notice applies to the following, together the “Services”:
- thefuture.institute and its online learning environment, including course delivery, enrollment, and learner accounts
- Any other website, portal, subdomain, or online interface operated by SVFI
- VeriCert digital credentialing services, including credential issuance, hosting, and public verification
- KidGeeniers program registration, family accounts, and program communications
- SVFI assessment services, including remote and in-person proctored examinations
- Live, hybrid, and in-person workshops, executive education programs, and events operated by SVFI
- Our marketing, newsletter, support, and social media communications
This Notice does not cover: independent affiliated organizations that determine their own purposes for processing and publish their own privacy notices; third-party websites and platforms we link to or where our content appears; and sponsoring organizations, which are independent controllers of the data they hold about you and apply their own policies to it.
3. Our role: controller, processor, or joint arrangement
Our legal role depends on how you reach us, and this determines how you exercise your rights.
| Situation | SVFI’s role | What it means for you |
|---|---|---|
| You register directly as an individual learner | Controller (GDPR) / Business (CCPA) / Responsable (Mexico) | Exercise your rights directly with us |
| Your employer, university, or a chamber sponsors your enrollment under a written agreement | Processor / Service Provider for the records covered by that agreement; Controller for our own account and billing records | Direct access and deletion requests to the sponsoring organization first; we support them and notify you where required |
| A school or institution contracts SVFI to deliver a program to its students | Processor, and where applicable a “school official” with a legitimate educational interest under FERPA | The institution controls the education records |
| We issue you a digital credential you requested | Controller for the credential record and verification infrastructure | See Section 8 |
| An affiliate and SVFI jointly design a program and both determine purposes | Joint controllers under a written allocation of responsibilities | You may exercise rights against either party |
If you are unsure which applies to you, ask us and we will tell you in writing.
4. Information we collect
4.1 Information you provide
Account and profile data. Name, email address, password credentials, country and city, preferred language, professional title, organization, and any optional profile details, photograph, or biography you choose to add.
Enrollment and registration data. Program selected, cohort, start date, prior education or experience where a program requires prerequisites, and any accommodation request you submit.
Payment data. Billing name, billing address, tax identification where an invoice requires it, and the last four digits and expiry date of a payment card. We do not collect or store full payment card numbers. Payments are processed by third-party payment processors that handle card data under their own policies and applicable PCI DSS obligations.
Identity verification data. For proctored examinations and certain credentials: a government-issued identification document, a webcam-captured photograph, and, where required, date of birth. Section 7 explains exactly how this is handled and for how long.
Learning and assessment data. Assignment submissions, project files, quiz and exam responses, scores, attempts, completion status, instructor and peer feedback, forum and discussion contributions, and time-on-task data.
Communications. Support tickets, emails, chat messages, call notes, survey and feedback responses, and event registrations.
Media and content you contribute. Where you participate in a recorded session, testimonial, showcase, or case study: the audio, video, images, or written material you provide, always subject to a separate release where one is required.
4.2 Information collected automatically
IP address, approximate geographic location derived from IP address, device type, operating system, browser, language settings, referring URL, pages viewed and the order viewed, timestamps, session duration, clickstream within the learning platform, video playback events, and error logs. This is collected through server logs, cookies, pixels, tags, and similar technologies described in our Cookie Notice.
4.3 Information from third parties
- Sponsoring organizations — employee or student roster data, eligibility, cohort assignment, and reporting identifiers
- Single sign-on providers — the identity fields you authorize them to release to us
- Payment processors — transaction status, chargeback and fraud signals
- Proctoring and integrity vendors — session recordings and flagged events, as described in Section 7
- Advertising, referral, and affiliate partners — attribution and campaign data where you arrive through a campaign
- Publicly available sources — professional profiles and organizational information used for business development, where permitted by law
4.4 Sensitive information
We limit sensitive information to what a program genuinely requires:
- Government identification documents — only for identity verification, as described in Section 7
- Accessibility and accommodation information — including health-related detail you voluntarily provide to support an accommodation request. Used only to arrange the accommodation, kept separately from academic records, and disclosed only to staff who must act on it.
- Demographic data — where collected, always optional, clearly labeled as optional, and used only in aggregate for equity reporting, scholarship administration, or grant compliance
- Images captured during identity verification and proctored examinations, handled as described in Section 7. These are stored as photographs; we do not derive facial geometry or any other biometric identifier from them.
We do not use sensitive personal information to infer characteristics about you.
5. How we use information, and our legal bases
Where the GDPR or UK GDPR applies, we rely on the legal bases indicated below. Where we rely on legitimate interests, we conduct and record a balancing assessment.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Services | Create accounts, deliver courses, grade work, issue credentials | Contract |
| Verify identity and protect assessment integrity | Proctoring, identity checks, plagiarism review | Contract; legitimate interests in credential validity; consent where required by local law |
| Process payments and prevent fraud | Billing, refunds, chargeback defense | Contract; legal obligation; legitimate interests |
| Support and communicate | Answer tickets, send service notices | Contract; legitimate interests |
| Maintain credential integrity | Verification records, revocation registry | Contract; legitimate interests in public trust in credentials |
| Improve and secure the Services | Analytics, testing, incident response | Legitimate interests |
| Research and program evaluation | Aggregated and de-identified outcome studies | Legitimate interests; consent where identifiable |
| Marketing and advertising | Newsletters, event invitations, online advertising | Consent where required; otherwise legitimate interests, with opt-out always available |
| Accreditation, standards, and regulatory reporting | Reporting to accreditation and certification bodies | Legal obligation; legitimate interests |
| Legal compliance and defense | Records retention, responding to lawful requests | Legal obligation; legitimate interests |
Service communications are not marketing. Enrollment confirmations, examination scheduling, credential issuance, security alerts, and policy changes are sent to all learners and cannot be unsubscribed while your account is active.
6. Artificial intelligence and automated processing
Because SVFI’s mission concerns responsible technology, we state our standard here rather than leaving it implicit.
- We use AI-assisted tools for translation, content drafting, support triage, learning recommendations, and the detection of anomalies in assessment sessions.
- No decision that materially affects you is made by automated means alone. Determinations about examination integrity, credential issuance, credential revocation, program admission, and disciplinary outcomes are reviewed, authorized, and decided by a qualified human being in every case. AI output is treated as a signal for human review, never as a verdict.
- You may request an explanation of any such decision, present your position, and appeal it. Contact the Privacy Officer to begin an appeal.
- We do not sell your content to AI developers, and we do not permit third-party providers to train their general-purpose models on learner submissions, assessment responses, or proctoring recordings. Where we use a third-party AI service, we contract for no-training and limited-retention terms.
- We may use de-identified and aggregated learning data to improve our own instructional design, item banks, and program quality. De-identified means direct identifiers are removed, and we commit not to attempt re-identification.
7. Assessment integrity and proctoring
This section applies whenever you sit a proctored SVFI or VeriCert examination.
Before an examination. You receive advance notice of the proctoring method and provide informed, written consent before any capture begins. Where a secure browser such as Safe Exam Browser is required, we tell you before you register. If you do not wish to consent to remote proctoring, contact us about an alternative arrangement, such as an in-person supervised sitting, where one is available for your program.
What is collected. An identity verification image and identification document captured before the session begins; periodic webcam still captures taken at intervals during the examination; screen activity within the examination environment; a limited set of system signals used to detect prohibited software; and timestamps of session events such as leaving the examination window, pasting text, or loss of the camera signal.
What is not collected. We do not access files, browsing history, or applications outside the examination environment. We do not activate your camera or microphone outside a scheduled session.
We do not use facial recognition, and we do not create biometric identifiers. Your identification document and your session captures are never compared to one another by software, neither in your browser nor on our servers. We do not perform facial recognition, facial geometry scanning, biometric templating, biometric categorization, emotion or attention detection, or voiceprint analysis. We do not collect or store biometric identifiers as those terms are defined under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, or comparable statutes. This is a deliberate architectural decision: automated comparison of a webcam image against a printed identification photograph has low reliability and documented demographic bias, and a false rejection would exclude a student from an examination they are entitled to sit.
Identity is verified by a person. A trained reviewer compares the two images and records a determination, which becomes part of the session record and is subject to appeal.
What is automated, and what it cannot do. The system calculates an integrity index from a weighted set of behavioral signals — for example, how many times the examination window lost focus, whether text was pasted, or whether the camera signal was interrupted. This calculation runs on session events, never on your image or your appearance. The index is indicative only: it orders sessions for review and is displayed to the reviewer alongside the underlying events. It never determines an outcome. One hundred percent of integrity determinations are made, authorized, and recorded by a qualified human reviewer, who may disregard the index entirely.
We do not sell, lease, trade, or otherwise profit from your examination images, and we do not disclose them except to the service providers who operate the proctoring system on our documented instructions, or where disclosure is required by law or by a valid warrant or subpoena.
Retention and destruction. Identity verification images and identification documents are kept only until the identity review is resolved, and are then deleted. Session captures and event evidence are retained for twelve (12) months from the date of the examination, or until an open academic integrity case is resolved, whichever is later, and are then permanently destroyed. After destruction we retain only a record that verification occurred, the method used, and the date, which supports the validity of the credential.
Access. You may request a copy of your own proctoring recording, subject to the redaction of any third party who appears in it.
8. Digital credentials and public verification
When SVFI or VeriCert issues you a digital credential, verification by third parties is the entire point of the credential. That requires deliberate handling.
What the credential record contains. Your name as you have asked it to appear, the credential title and version, the issuing body, the issue date, the expiry date where applicable, the competency standard or scheme, and a unique verification identifier.
What is publicly visible. Anyone holding your credential link or identifier can view the credential and confirm that it is authentic. Your email address, contact details, assessment scores, and answer-level data are never published on a verification page.
Your control. You choose whether to share the credential link, publish it to a professional profile, or export it to a wallet. You may request at any time that a credential be made non-public or withdrawn from public verification. Note that a credential that is no longer publicly verifiable has limited practical value, and any relying party that previously verified it will have retained its own record.
Revocation and integrity. If a credential is revoked for cause, including proven examination misconduct or falsified prerequisites, we maintain a record of the revocation and its date, because the integrity of the credential system depends on it. This record is retained for the life of the credential system and is not deleted on request, on the legal basis of our legitimate interest in maintaining trustworthy certification and in accordance with the requirements of the certification scheme and any accreditation body. Where you dispute a revocation, the appeal process in Section 6 applies.
Institutional issuers. Where SVFI operates credentialing infrastructure on behalf of a university, chamber, or other issuing body, that body is the controller of its credential data and SVFI acts as processor under a written data processing agreement.
9. Children’s and students’ privacy
This section is central to KidGeeniers and to any program serving minors, and takes precedence over anything more general in this Notice.
9.1 Accounts and consent
Children do not hold independent SVFI accounts. All registration, payment, and account administration for participants under 18 is performed by a parent, legal guardian, or an authorized school or program partner.
Children under 13 (United States — COPPA). We do not knowingly collect personal information online from a child under 13 without first providing direct notice to a parent or guardian and obtaining verifiable parental consent, or, for school-based delivery, without the school’s authorization acting on behalf of parents for the educational purpose. The consent request states what we collect, how we use it, and that the parent may refuse any further collection. We never condition a child’s participation in an activity on the disclosure of more information than is reasonably necessary for that activity.
Minors elsewhere. In the EEA and the United Kingdom, where consent is the basis for an information society service, we require parental consent below the applicable age of digital consent. In Mexico and other Latin American jurisdictions, processing of a minor’s data follows the heightened standard of the applicable law and requires the consent of the person exercising parental authority or guardianship.
9.2 What we collect about a child, and what we deliberately do not
We collect the minimum necessary: first name and last initial or a program alias, age or grade band, program cohort, attendance, progress and completion within the program, work products the child creates as part of the activity, and any accommodation or safety information the parent chooses to provide, such as an allergy or a custody restriction.
We do not:
- serve behavioral or targeted advertising to children, or permit any partner to do so
- deploy advertising, retargeting, or social media tracking technologies on pages, registration flows, or program areas directed to children
- sell, or share for cross-context behavioral advertising, the personal information of any person under 16, under any circumstances
- build advertising or marketing profiles of children
- require a child to have a public profile or to post publicly
- use children’s data to train third-party AI models
- collect precise geolocation from a child
- publish a child’s image, full name, or work publicly without a separate, specific, written parental release, which may be withdrawn at any time
KidGeeniers is designed as a screenless program for children aged 6 to 14. The volume of online data generated about a child is therefore limited by design, which is the strongest privacy control available.
9.3 Parent and guardian rights
A parent or guardian may, at any time: review the personal information we hold about their child; request its correction or deletion; refuse to permit any further collection or use; and withdraw a media release. Write to privacy@thefuture.institute with the subject line “Child Data Request.” We verify the requester’s relationship to the child before acting, and we do not require more information for that verification than is necessary. Exercising these rights may end the child’s ability to continue in a program where the data is essential to delivering it, and we will tell you clearly if that is the case.
9.4 School-delivered programs
Where SVFI delivers a program under contract with a school or district, we act as a school official with a legitimate educational interest under FERPA. We use education records only to perform the contracted service, we do not re-disclose them except as the contract or the law permits, and we return or delete them at the end of the engagement. Applicable state student-privacy laws, including California’s Student Online Personal Information Protection Act, are honored as a floor and not a ceiling.
9.5 Participants aged 13 to 17
Where an adolescent participates in a program directly with guardian permission, we apply the protections in Section 9.2 in full — no targeted advertising, no sale or sharing, no profiling — and we limit optional data collection.
10. How and with whom we share information
We do not sell personal information for money. However, as explained in Section 11, our use of advertising and analytics technologies may constitute “sharing” for cross-context behavioral advertising or “targeted advertising” under certain U.S. state privacy laws, and you have the right to opt out.
Service providers and sub-processors. Vendors acting on our documented instructions under written contract, in the following categories: website and platform hosting; software plugins and platform extensions; customer relationship management; help desk and support ticketing; web and product analytics; video hosting, streaming, and conferencing; payment processing; email delivery and SMTP services; proctoring and secure examination technology; credential issuance and verification infrastructure; and external developers and technical contractors engaged to build and maintain our systems. A current list of our sub-processors is available on request from the Privacy Officer.
Instructors, evaluators, and assessors. Faculty, coaches, and certified evaluators receive the learner data necessary to teach, evaluate, or assess you, under confidentiality obligations.
Sponsoring organizations. Where an organization pays for your participation, we report enrollment, attendance, completion, and credential status to that organization, and we tell you at enrollment what will be reported. We do not disclose your individual assignment content, forum posts, or accommodation details to a sponsor unless you consent or the law requires it.
Accreditation, certification, and standards bodies. Where a program is accredited or a credential is recognized by an external body, we provide the records those bodies require in order to audit the validity of the scheme.
Affiliated organizations. Where a program is co-delivered with an affiliated organization, we share only the data necessary for that program, under written arrangements.
Advertising and analytics partners. As described in Section 11.
Legal and protective disclosures. In response to a lawful subpoena, court order, or governmental request; to establish or defend legal claims; to enforce our Terms of Use; or where we believe in good faith that disclosure is necessary to prevent serious harm to any person. Where we are legally permitted to notify you of a request for your data, we will.
Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this Notice continuing to apply to the transferred data.
Public areas. Content you post in forums, showcases, or public profiles is visible to others. Do not post information you would not want to be public, whether about yourself or anyone else.
11. Cookies, advertising, and your choices
We use cookies and similar technologies for authentication, security, preferences, analytics, and advertising. Full detail is in our Cookie Notice.
Advertising technologies. Our public marketing pages use third-party advertising and measurement technologies, including the Meta Pixel, Google Ads conversion and remarketing tags, and the LinkedIn Insight Tag. These technologies allow those platforms to receive information about your visit — such as your device identifiers, IP address, and the pages you viewed — and to show you SVFI advertising on their own services.
What this means legally. We receive no money for this. Nevertheless, under the California Consumer Privacy Act and comparable state laws, this activity may be considered “sharing” of personal information for cross-context behavioral advertising, or “targeted advertising.” We disclose it plainly rather than rely on the absence of payment.
How to opt out. You may opt out at any time by: rejecting non-essential cookies in our consent banner; using the “Your Privacy Choices” control on our website; enabling a Global Privacy Control signal in your browser, which we honor as a valid opt-out request; or emailing privacy@thefuture.institute. Opting out does not affect your access to any course, examination, or credential.
Where these technologies are never used. We do not deploy advertising or retargeting technologies on pages, registration flows, or program areas directed to children, and we never share the personal information of anyone under 16 for advertising purposes.
Disabling essential cookies will prevent login and examination functionality from working.
12. International data transfers
SVFI operates principally from the United States, and our systems and service providers are located in the United States and other jurisdictions. We serve learners across the United States, Mexico, and Latin America, so personal data commonly crosses borders.
Our Services are directed to learners in the United States and Latin America and are not targeted at residents of the European Economic Area or the United Kingdom. We have not appointed a representative under Article 27 of the GDPR. Silicon Valley Futures Institute LLC is the controller of your personal data worldwide and is the point of contact for all privacy matters, at the address in Section 16. Where a learner in the EEA or the United Kingdom does use our Services, we honor the rights described in Section 14.2 as a matter of policy.
Where we transfer personal data internationally, we apply appropriate safeguards, which may include Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum, written transfer agreements with the recipient, or the exceptions permitted where transfer is necessary for the performance of a contract with you or where you have given explicit consent. You may request information about the safeguards we apply by contacting the Privacy Officer.
13. Retention
We keep personal data only as long as necessary for the purposes for which it was collected, plus any period required by law, by accreditation obligations, or for the defense of legal claims.
| Category | Retention period |
|---|---|
| Account and profile data | Life of the account, then 24 months |
| Learning and assessment records | 7 years from completion, to substantiate the credential |
| Credential and verification records | Credential lifecycle plus 7 years |
| Credential revocation records | Retained for as long as the credential system operates |
| Proctoring recordings and session captures | 12 months, or until an integrity case closes |
| Identity verification images and identification documents | Deleted once the identity review is resolved |
| Payment and tax records | 7 years, per tax and accounting law |
| Support communications | 36 months |
| Marketing contact data | Until you opt out, plus a suppression record kept indefinitely so that we do not contact you again |
| Children’s program data | 12 months after the child’s last program, unless a parent requests earlier deletion |
| Server and security logs | 12 months |
Backups are overwritten on a rolling cycle. Data deleted from live systems may persist in backups for up to 90 days before being overwritten.
14. Your rights
14.1 Everyone
Regardless of where you live, you may ask us to access, correct, or delete your personal data, and you may opt out of marketing at any time using the unsubscribe link or by contacting us. We will not discriminate against you for exercising a privacy right.
14.2 EEA, United Kingdom, and Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection, including the right to object to processing based on legitimate interests and, absolutely, to direct marketing. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal. You may lodge a complaint with your supervisory authority, though we would appreciate the opportunity to resolve the matter first.
14.3 United States — state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may request: to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; deletion; correction; a portable copy; and to opt out of the sale of personal information, of sharing for cross-context behavioral advertising, of targeted advertising, and of profiling that produces legal or similarly significant effects.
California specifics. In the preceding 12 months we have collected the categories of personal information listed in Section 4, corresponding to the following CCPA categories: identifiers; customer records; commercial information; internet or other electronic network activity; approximate geolocation; audio, electronic, and visual information; professional or employment information; education information; and inferences. We disclose these categories to the classes of recipients listed in Section 10 for the business purposes listed in Section 5.
We do not sell personal information for monetary consideration. We do share personal information for cross-context behavioral advertising as described in Section 11, and you may opt out through the mechanisms set out there. We do not sell or share the personal information of consumers under 16 under any circumstances. We use sensitive personal information only for the purposes permitted under the CCPA regulations and not to infer characteristics about you. We honor Global Privacy Control signals as a valid opt-out request. California residents may also request the disclosure described in California Civil Code section 1798.83.
Authorized agents may submit requests with proof of authorization. We verify identity before acting, in a manner proportionate to the sensitivity of the request. We respond within the statutory period, generally 45 days, extendable once where permitted. If we deny a request you may appeal by replying to our decision; we will respond to the appeal within 45 days and, where required, tell you how to contact your state Attorney General.
14.4 Mexico and Latin America — derechos ARCO
Where Mexican law applies to our processing, you have the rights of Access, Rectification, Cancellation, and Opposition (ARCO), and the right to revoke your consent and to limit the use or disclosure of your data. Requests may be submitted to privacy@thefuture.institute and must include your name and contact details, proof of identity or of representation, a clear description of the data concerned, and any element that helps us locate it. A Spanish-language Aviso de Privacidad is available on our website.
14.5 How to exercise your rights
Email privacy@thefuture.institute with “Privacy Request” in the subject line, or write to us at the postal address in Section 16. Some rights can also be exercised directly in your account settings. We aim to acknowledge requests within 5 business days.
15. Security
We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including encryption in transit, access controls on a least-privilege basis, role-based permissions in the learning and credentialing platforms, multi-factor authentication for administrative access, vendor due diligence, logging, and confidentiality obligations and training for staff and contractors.
No system is perfectly secure. You are responsible for protecting your own login credentials and for notifying us promptly at privacy@thefuture.institute if you believe your account has been compromised. Where a breach affecting your personal data creates a risk to you, we will notify you and the relevant authorities within the timeframes required by law.
16. Contact us
Silicon Valley Futures Institute LLC
Attn: Privacy Officer
3000 El Camino Real, Building 4, Suite 200
Palo Alto, California 94306
United States
Privacy inquiries, rights requests, and security reports: privacy@thefuture.institute
17. Governing law and changes to this Notice
This Notice is governed by the laws of the State of California, without regard to its conflict of laws principles. The state and federal courts located in Santa Clara County, California have exclusive jurisdiction over any dispute arising from it, except where applicable law grants you the right to bring a claim in your place of residence.
We review this Notice periodically. Non-material changes take effect on posting. For material changes — a new category of data, a new purpose, or a new category of recipient — we will provide at least 30 days’ advance notice by email to account holders and by prominent notice on the Services, and where the law requires consent for the change, we will obtain it.