Skip to main content

Privacy Policy

Last updated 19 September 2026

Fast Track Impact is run by the Institute for Methods Innovation. This policy explains what personal information we hold when you use this website, book or attend training, buy something from us or receive our emails, and what we do with it.

Your records are stored in the European Union and handled under the General Data Protection Regulation (GDPR), wherever in the world you are. Most of what this page describes you can see and change for yourself on your data page: what we hold, where each detail came from, what we send you, and how to correct, download or erase it.

Each section below opens when you click it. If anything is unclear, write to privacy@fasttrackimpact.com.

Who we are and how to reach us

Fast Track Impact (FTI) operates as a single brand under the Institute for Methods Innovation (IMI). While services are delivered seamlessly under the FTI identity, underlying operations are handled by two distinct legal entities.

Data protection and GDPR responsibilities are managed by Institute for Methods Innovation, a company limited by guarantee registered in Ireland (company number 670879; 77 Camden Street Lower, Dublin, D02 XE80). Standard invoices and receipts are issued by the US company, Methods Innovation, Inc. (4160 E 2nd Street #1309, Casper, WY 82609). Both entities also handle financial administration and invoicing, depending on customer preferences.

For anything about customer data or personal information:

Where your information is kept

Regardless of which entity issues billing documentation, all underlying records are stored securely within the European Union on servers in Frankfurt, Germany. This includes all operational and personal data.

Everything we record about you is stored on

  • the website's own database, which holds accounts, orders, training sign-ups and progress. It runs on Neon, a database provider, in its Frankfurt region;
  • our contact and mailing system, which holds who you are, what you have asked us for, and which emails you receive. It is our own system, hosted by DigitalOcean in Frankfurt;
  • backups of both, also held by DigitalOcean in Frankfurt.

What we collect and where it comes from

Most of the data we hold comes from when you create an account, sign up for training, book a workshop, buy something, ask us a question, or subscribe to our mailings. This can include your name, email address, organization, job title, country, billing details, and information you provide when submitting a form on this website.

Some data is recorded as you use while you are signed in and using this website. For example, we store waiting lists when you're signed in so that you don't sign up multiple times; orders in your shopping cart are stored so you can take your time and review products and services.

Other data may come from the institution that booked training for you, such as when a training lead provides us with a list of attendees and asks us to share post-training materials directly.

How we use it, and our lawful basis

We will use personal information to run the website and your account; take and fulfil orders, and issue invoices and receipts; deliver workshops, webinars, courses, consultations and digital resources, including joining instructions and course access; answer your questions and support you in training; manage bookings made by a training lead, including who has taken up a seat and who wishes to attend a masterclass; send you the mailings you have signed up for; understand which pages and resources are useful, as counts, so we can improve them; keep the records that tax, contract and accounting law require; protect the site, accounts and payments from misuse.

Under the GDPR each of these rests on one of four bases. A contract with you, for orders, accounts and the training you booked. Your consent, for mailings, which you can withdraw at any time. A legal obligation, for financial records. Our legitimate interest in running and improving a training business, for the rest, weighed against your interests each time.

All data is collected to provide you with the best services we can offer. We do not sell personal information, and we do not use it for paid advertising services. We will not ask for any sensitive personal information as part of providing services to you. If you tell us about an accessibility requirement so that we can make an adjustment, we use it solely for that purpose.

Accounts, bookings and payments

Your customer account contains your profile, bookings, orders, and training progress. You sign in using a link we email you or with an existing account from another provider.

Payments are processed through Stripe. Your card information is sent directly to Stripe and is not stored on our servers; we only maintain records of the order, invoice, and receipt.

An invoice is a financial document we must retain for six years after the month it was issued, even if you later request that we delete everything else. The items you purchased remain on the invoice because an invoice without line items doesn't record anything.

If your training lead paid for a masterclass seat on your behalf, the lead can see if you used it and whether you attended the session.

Workshops, webinars and online training

When you register for a workshop, webinar, course, or consultation, we use your information to organize the session, including sending joining instructions, maintaining the register, sharing materials, and following up afterward.

Live sessions are conducted via Zoom. Zoom collects the name and email address you use to join and logs your attendance according to its privacy policy.

We only record a live session if we have specified this beforehand or it is obvious from the service’s nature. In cases where a session is recorded, we clarify who can view it and the duration of its availability.

The 5-week impact training program is delivered via an email sequence: you sign up, consent to receive emails for each lesson, and access each lesson via the website. Your data page shows the lessons sent to you and lets you stop them.

Newsletters and other emails

We send two types of emails.

Service emails are those you receive upon request, such as order confirmations, invoices, joining instructions, sign-in links, and your data page link. These are not marketing emails and are sent only while the related service is active.

Mailings are emails you opt in to, like the newsletter, training updates, and free lessons. Each includes an unsubscribe link, and your data page lets you cancel any or all subscriptions, with the option to re-subscribe later.

Emails are sent through Resend, an email delivery service, which receives your address and the message. We record whether each email was delivered or bounced.

Cookies and analytics

This website does not display a cookie banner because it does not set any tracking cookies. It uses two services to cross-reference site usage, and both are configured so that no data is stored on your device to personally identify or track you across visits.

  • Google Analytics, operated by Google LLC, uses consent mode configured to deny all storage signals; it neither reads nor writes cookies or any other identifiers on your device.
  • Vercel Web Analytics, offered by Vercel Inc. as part of the hosting service, tracks visits in aggregate.

Both collect technical data for each visit, including network address, page details, and browser and device info. This data isn’t used for profiling, paid ads, or third-party services. We only track overall page views daily without identifying individual visitors.

Three elements on this website use your browser's storage, each serving a specific feature:

  • Signing in places a cookie that keeps you logged in, essential for your account to function. Signing out deletes this cookie.
  • Accessing your data page via the emailed link sets a cookie for that session, allowing the page to recognize you while you're using it.
  • Your basket and any training notes are stored locally in your browser, so they remain available when you return. They do not leave your device.

Embedded videos are streamed from YouTube in privacy-enhanced mode, which does not set any cookies until you click play.

Who we share information with

Within IMI, access to your details is limited to our staff, facilitators conducting your training, and contractors working under confidentiality agreements. When an institution arranges staff training, the lead can view who booked a spot and who attended.

All services that operate through this website and handle data are covered by a functional contract limiting their data use.

  • Vercel (United States): hosts the website and monitors visits.
  • Neon (Frankfurt): manages the website's database.
  • DigitalOcean (Frankfurt): manages our contact form, mailing system, and backups.
  • Stripe: processes payments.
  • Resend: manages email delivery.
  • Zoom: enables live sessions.
  • Google: provides analytics, as mentioned above.
  • YouTube: hosts embedded videos.

The website temporarily records the number of requests from each network address, storing this data for several minutes to help prevent abuse of forms and sign-in processes.

Neon and DigitalOcean run servers in Frankfurt, ensuring their data remains within the European Union. Conversely, companies like Stripe, Resend, Zoom, Google, and Vercel host their servers outside the EU, including in the United States, and handle data in line with their contractual data protection agreements with IMI.

IMI may share information with professional advisors, insurers, and auditors, disclose it to public authorities or courts when legally necessary, and transfer data to a successor organization if Fast Track Impact changes ownership. IMI does not share personal data for marketing by other organizations.

How long we keep your data

We retain personal information only as long as necessary for its original purpose.

  • Your account stays active during your use and can be closed anytime via your data page.
  • Mailing records are kept until you unsubscribe or request their removal.
  • Training registration and progress are stored while the training is ongoing and deleted upon request.
  • Invoices and order details are retained for six years after the issuance month due to legal requirements.
  • Attendance logs record participant counts with personal names removed, ensuring accurate tallies.
  • Your questions are stored during the active conversation and for a reasonable period afterward.

Upon your request to erase data, we confirm within 30 days by email. Backups are overwritten periodically, so data removal from backups occurs within 120 days.

How we protect your data

Your personal details are accessible only to authorized IMI staff. All communications between the website and its database are encrypted. IMI does not handle card information unless explicitly authorized. Sign-in is via a link sent to your email, so we do not store passwords on our servers. After updates, IMI verifies database integrity and maintains backups elsewhere to detect and fix any technical or operational issues.

We acknowledge that no website or email system is entirely secure. Protect your email account and contact us immediately if you suspect any unauthorized access.

Your rights, and how to use them

Under the GDPR, you have the right to access, correct, delete, restrict the use of, or object to the personal data we hold about you. You can also request a copy in a portable format and withdraw consent at any time. You can oppose direct marketing activities at any time.

We store your records in the European Union and handle them under the General Data Protection Regulation (GDPR), wherever in the world you are. We have built a fast, convenient way to access the information we hold in this dedicated portal: your data page. From here, you can access it by signing in or requesting a link sent to your email. Only the person who can read that email can access it, so we can verify your identity. It shows the details we have and their sources, and lets you update or correct your name and organization. You can view all mailing lists and change your subscription for any mailings. You can download a copy of the data or request deletion.

If you encounter limitations on the page, please contact privacy@fasttrackimpact.com.

Children and other websites

Our training and website are designed for adults: researchers, professionals, students, and the institutions they belong to.

We do not intentionally collect personal data from anyone under 16. If you think a child has shared their information with us, please inform us, and we will remove it promptly. For events aimed at younger audiences, we will implement suitable consent and safeguarding procedures beforehand.

This website includes links to other websites, publications, and social media platforms. These have their own privacy policies, which we do not control. Please review their privacy notices before sharing any personal details.

See what we hold about you

Your data page shows every detail, where it came from and what we send you, and lets you correct, download or erase it.

Open your data page