Privacy Policy
Effective Date: 3 Sep 2026
Version 1.0
At Sura Academy (accessible exclusively at https://sura-academy.com), protecting your personal data is a top priority. This Privacy Policy informs you about the type, scope, and purpose of personal data processing under the European General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and the German Federal Data Protection Act (BDSG).
1. Data Controller Information (Art. 4(7) GDPR)
Falco Wisskirchen
Darmstädter Str. 30, 64521 Groß-Gerau, Germany
Phone: 017638852652 | Email: [email protected]
Sales Tax ID (USt-IdNr.): DE862417593
2. Categories of Personal Data Processed
- Account & Identity Data: Full name, first name, username, email address, password hash (encrypted via bcrypt), avatar image, biographical details, language, and timezone.
- Educational & Telemetry Records: Enrolled courses, lesson video progress logs, timestamp records, quiz attempts, submitted assignments, and certificate validation hashes.
- Communications & Newsletter: First name and email address provided voluntarily when subscribing to educational newsletters or resource series.
- Financial & Billing Information: Order numbers, purchased items, transaction amounts, billing address country, invoice records, and payment provider tokens. (Raw card details are processed directly by PCI-DSS certified processors and never stored on our servers.)
- Technical & Connection Logs: IP address, device specifications, browser type, operating system, session cookies, and login timestamps to enforce platform security and prevent account takeover.
3. Legal Bases for Processing (Art. 6(1) GDPR)
- Performance of a Contract (Art. 6(1)(b) GDPR): Account registration, delivery of course videos, course progress tracking, certificate generation, and customer support.
- Legitimate Interests (Art. 6(1)(f) GDPR): Cyber security, bot defense, anti-fraud prevention, account protection, performance optimization, and learning analytics.
- Legal Obligations (Art. 6(1)(c) GDPR): Compliance with statutory tax, commercial bookkeeping, and legal invoicing duties (§ 147 AO, § 257 HGB).
- Consent (Art. 6(1)(a) GDPR): Optional newsletter marketing or non-essential cookies and third-party script integrations. You may revoke consent at any time.
4. Bot Protection & Security (Cloudflare Turnstile Privacy Disclosure)
To protect our registration, contact, and newsletter forms from automated abuse, credential stuffing, and malicious spam bots, we utilize Cloudflare Turnstile provided by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA).
Cloudflare Turnstile evaluates browser telemetry, visitor behavior patterns, and non-interactive cryptographic proof-of-work to verify human visitors without displaying intrusive puzzles. In accordance with Cloudflare's operating requirements for invisible verification mode, please refer directly to the Cloudflare Turnstile Privacy Addendum and the general Cloudflare Privacy Policy for full details regarding Cloudflare's independent data processing practices.
5. Data Retention Periods & Schedule
We store personal data strictly in accordance with statutory retention schedules:
| Data Category |
Retention Period |
Legal Grounds / Justification |
| User Account & Learning Progress |
Duration of active account relationship; permanently purged within 30 days upon verified account erasure request. |
Art. 6(1)(b) GDPR (Contractual service delivery & lifelong certificate validation). |
| Financial, Invoices & Transaction Records |
10 Years |
Statutory commercial & fiscal retention under § 147 AO (German Fiscal Code) and § 257 HGB (German Commercial Code). |
| Consent Audit Logs |
3 Years |
Proof of consent compliance under Art. 7(1) GDPR & statutory limitation period under § 195 BGB. |
| Web Server & Security Logs |
7 to 30 Days |
Art. 6(1)(f) GDPR (Server protection, DDoS mitigation, and log rotation). |
6. Data Processors & Infrastructure
We never sell or rent your personal data. Data is shared solely with vetted processors under Art. 28 GDPR Data Processing Agreements:
- Hosting & Server Infrastructure: Hetzner Online GmbH (European data centers with TLS 1.3 encryption and automated security backups).
- Security & Bot Mitigation (Cloudflare Turnstile): Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) for DDoS protection, content delivery, and bot verification to safeguard forms without invasive CAPTCHA challenges.
- Payment Providers: Stripe Payments Europe Ltd. and PayPal (Europe) S.à.r.l. for tokenized payment processing.
7. Email Communications & 1-Click Unsubscribe (GDPR)
When you subscribe to our newsletter or opt-in to marketing communications upon registration, we may send you educational updates, course launches, and articles. Every email contains an immediate 1-click unsubscribe link in the footer and complies with List-Unsubscribe header standards. You can also withdraw consent or adjust email notification preferences at any time in your account settings or by emailing [email protected].
8. Your Rights Under the GDPR
As a data subject, you have the following rights under GDPR Articles 15–22:
- Right of Access (Art. 15 GDPR): Request confirmation and details of personal data processed.
- Right to Rectification (Art. 16 GDPR): Correct inaccurate profile data directly from your account settings.
- Right to Erasure (Art. 17 GDPR): Request complete deletion ("Right to be Forgotten") from your account dashboard or by emailing [email protected].
- Right to Data Portability (Art. 20 GDPR): Download your complete personal and learning history in a machine-readable JSON format.
- Right to Object & Revoke Consent (Art. 7(3) & 21 GDPR): Adjust or withdraw cookie consent anytime via the "Cookie & Privacy Preferences" footer link.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a competent supervisory authority (e.g. Der Hessische Beauftragte für Datenschutz und Informationsfreiheit).