Policy center: Privacy · Refunds · Course cancellations

Legal policy

Privacy Policy

Effective Date: August 30, 2026Organization: 1Above Academy, LLC (“Provider”)

1. Purpose

1Above Academy, LLC is committed to protecting the privacy, confidentiality, and security of information collected from students, prospective students, instructors, and other individuals who interact with the Provider, its website, or its educational services.

This Privacy Policy describes the information we collect, how we use and disclose that information, and the measures we employ to safeguard it.

2. Information We Collect

The Provider may collect information necessary to register students, administer courses, verify identity and attendance, process payments, provide customer support, issue course completion documentation, and report course completion information as required by the Nationwide Multistate Licensing System & Registry (“NMLS”) and applicable law.

Information collected may include:

  • Name;
  • Mailing and billing address;
  • Telephone number and email address;
  • NMLS identification number;
  • Course registration and enrollment information;
  • Course attendance and participation information;
  • Assessment results and course completion information;
  • Login, logout, timing, and Learning Management System (“LMS”) activity;
  • Payment and transaction information;
  • Communications with the Provider;
  • Course evaluations and survey responses; and
  • Other information reasonably necessary to administer educational services or satisfy legal or regulatory requirements.

Payment card information may be collected and processed by third-party payment processors. The Provider will not intentionally retain complete payment card information except where necessary and permitted under applicable payment-card security requirements.

3. Use of Information

Information collected by the Provider may be used to:

  1. Register and enroll students in courses;
  2. Verify student identity, attendance, participation, and course completion;
  3. Administer educational content and assessments;
  4. Provide student support and respond to inquiries;
  5. Process payments, refunds, and other transactions;
  6. Issue certificates or other evidence of course completion;
  7. Report or “bank” course completion credits with NMLS as required;
  8. Maintain records required by NMLS, state regulators, or applicable law;
  9. Prevent fraud, academic misconduct, or unauthorized course participation;
  10. Improve course content and educational services;
  11. Maintain the security and functionality of the Provider’s website and LMS; and
  12. Comply with legal, regulatory, contractual, and audit requirements.

4. Disclosure of Information

The Provider does not sell student personal information.

The Provider may disclose information to:

  • NMLS, the State Regulatory Registry LLC (“SRR”), and governmental or regulatory authorities where required;
  • Service providers that support the Provider’s LMS, payment processing, communications, information technology, identity verification, or other business operations;
  • Professional advisers and auditors;
  • Law enforcement or governmental authorities when required by law; and
  • Other parties when disclosure is reasonably necessary to protect the Provider, its students, or the integrity of its educational programs.

Third-party service providers will be provided only the information reasonably necessary to perform their respective services.

5. NMLS Reporting and Regulatory Access

Students enrolling in NMLS-approved education acknowledge that certain information concerning their enrollment, participation, completion, and educational records may be reported to or made available to NMLS, SRR, and applicable state regulatory authorities.

The Provider will maintain NMLS course data and documents in accordance with applicable NMLS retention requirements and will make such information available to SRR or other authorized regulatory authorities when required.

6. Information Security

The Provider will maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, destruction, or loss.

Access to student information will be limited to personnel and service providers with a legitimate business, educational, regulatory, or technical need for such access.

No electronic information system can be guaranteed to be completely secure, and the Provider therefore cannot warrant the absolute security of information transmitted electronically.

7. Record Retention

Student and course records will be retained in accordance with the Provider’s Data and Document Retention Policy, applicable NMLS requirements, and applicable federal and state law.

NMLS course data and documents will generally be retained for at least five (5) years from the last date the applicable course is taught or administered, unless a longer period is required by law, regulatory instruction, litigation hold, or another applicable requirement.

8. Cookies and Electronic Information

The Provider’s website or LMS may use cookies, session identifiers, log files, IP addresses, device information, and similar technologies for authentication, security, course administration, analytics, and maintenance of the educational platform.

9. Changes to this Policy

The Provider may amend this Privacy Policy periodically to reflect changes in its operations, technology, legal obligations, or regulatory requirements. The current version will be made available through the Provider’s website or other appropriate means.

10. Contact Information

Questions concerning this Privacy Policy may be directed to:

1Above Academy, LLC
306 W Redwood St, Ste 200
Baltimore, MD 21201
Email: support@1aboveacademy.com