Privacy policy

This privacy policy applies to the website certification-course.com and to the course area of the CertPath app.

1. Controller

For data protection enquiries, contact us at support@certification-course.com. No data protection officer has been appointed, as the statutory conditions for a mandatory appointment are not met.

2. Overview and principles

We process personal data only to the extent necessary to provide the website, the courses and the services connected with them (data minimisation). The legal bases are Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interest, e.g. secure operation) and Art. 6(1)(a) GDPR (consent, e.g. statistics). Where a provider processes personal data on our behalf, a data processing agreement under Art. 28 GDPR is in place; for providers outside the EU we base transfers on EU standard contractual clauses or the EU-US Data Privacy Framework (details in section 7).

In short: without an account, visiting this website only involves technically necessary connection data plus, where applicable, our reach measurement (Google Analytics). In the EEA, the United Kingdom and Switzerland that measurement runs only after you consent; elsewhere it is on by default and you can switch it off at any time — section 6 explains both cases. With an account, the data needed for your purchase and for running the course is added.

3. Hosting and delivery

4. Account, purchase and running the course

These processing activities concern you once you buy a course or an account is created for you (legal basis in each case Art. 6(1)(b) GDPR unless stated otherwise):

5. Recipients (processors at a glance)

Provider Purpose Location / processing region
Cloudflare, Inc. Website hosting (Pages), DNS/CDN USA
Fly.io, Inc. App and database hosting USA / Frankfurt region (EU)
Clerk, Inc. Account and sign-in USA
Stripe Payments Europe, Ltd. Payment (one-time purchase), invoices Ireland (EU)
Resend, Inc. Transactional email (purchase receipt, withdrawal confirmation) USA / EU region
Anthropic, PBC AI assistant (course area, buyers only) USA
Google Ireland Ltd. Google Analytics 4 statistics and Google Ads conversion measurement (whether a visit from a Google ad led to a purchase). Inside the EEA/UK/Switzerland only with your consent; elsewhere enabled by default with an opt-out — see section 6 Ireland / USA

Beyond measuring whether our own ads led to a purchase, we do not pass data to third parties for advertising purposes, and we do not run remarketing or build advertising profiles about you. Section 6 explains when that measurement is based on your consent and when it is on by default with an opt-out.

6. Cookies, local storage and analytics

Where you are decides how this works. We apply two different regimes:

We use Google's Consent Mode v2. The starting point is always denied for all four consent signals (analytics storage and the three advertising signals); signals are then granted either because you chose them, or — outside the regions named above — because measurement is on by default.

Analytics. If you accept Analytics, we load Google Analytics 4 to understand how our site is used, with IP anonymisation (anonymize_ip) enabled. This grants the analytics-storage signal only. Google Analytics then sets its own cookies (_ga) in your browser.

Ads & marketing. With this category we grant advertising signals (ad_storage, ad_user_data) so that Google can measure whether a visit that arrived from one of our Google ads led to a purchase (conversion measurement). We use this only to measure the effectiveness of our own advertising. ad_personalization is only ever granted if you actively choose the Ads & marketing category yourself. Where measurement is on by default (outside the EEA/UK/Switzerland), that signal stays denied — so no advertising profiles are built about you and no remarketing takes place. Legal basis inside the EEA/UK/CH: Art. 6(1)(a) GDPR and § 25(1) TDDDG (your consent); outside: our legitimate interest in measuring our own advertising, Art. 6(1)(f) GDPR, with the opt-out described above. You can change your choice at any time via "Privacy settings" in the footer (and on the purchase pages), with effect for the future.

How we recognise your region. When you open our website, our content delivery network (Cloudflare) tells us the country your request comes from. We store only that two-letter country code in a temporary cookie on our domain (certpath-geo, deleted when you close your browser) so that both our marketing website and the purchase pages apply the same rules. We do not store your IP address for this and cannot identify you from it. Legal basis: § 25(2) TDDDG and Art. 6(1)(f) GDPR (applying the correct privacy regime).

Measuring which ad led to a purchase. If — and only if — advertising signals are granted (see above), we store the click identifier Google appends to our ad links (gclid) and, where present, the utm_source parameter in a cookie on our domain (certpath-gclid, up to 30 days). If you then buy, we pass that identifier plus a coarse channel label (for example "google-cpc") to our payment provider Stripe as part of the order data, so that we can see which advertising channel a purchase came from. Nothing else is passed. Declining Ads & marketing deletes this cookie, and no such data is attached to your order.

Your consent decision is stored in a cookie on our domain (certpath-consent, your decision plus a timestamp), so that a single choice applies across both our marketing website and the purchase pages of the app and you are not asked twice. Where measurement is on by default, no such cookie is written until you actually make a choice — the default is not treated as your consent, and any choice you make always overrides it. It stays until you decide again or clear your browser storage. Legal basis: § 25(2) TDDDG (strictly necessary to honour your choice).

Practice progress without an account. If you try practice questions without an account, your progress is stored in your browser's local storage only. It is not transmitted to us. If you later buy the course, that progress is imported into your account so it is not lost. Legal basis: § 25(2) TDDDG and, for the import, Art. 6(1)(b) GDPR.

The course area itself uses cookies that are strictly necessary for signing in and keeping you signed in (Clerk). With the sole exception of the purchase pages (the buy and order-confirmation pages), which are part of the same funnel as the marketing website and, only with your consent, use the analytics and ads tools described above, there is no tracking in the course area.

7. Transfers to third countries

Some of the providers named above are based in the USA. Where data is transferred there, we base this on adequacy decisions (EU-US Data Privacy Framework, where the provider is certified) and/or EU standard contractual clauses (Art. 44 et seq. GDPR). Where a provider offers an EU processing region, we use it (Fly.io: Frankfurt · Resend: EU region).

8. Storage duration and deleting your account

We store personal data only for as long as the purpose we collected it for lasts, or as long as statutory retention duties require. This table is the full picture:

Data How long we keep it Why
Your account, your course access and your learning progress (practice attempts and answers) For as long as you keep the account. Access to a purchased course is permanent, and we never delete a paid account because you have not used it Performing our contract with you (Art. 6(1)(b) GDPR) — this is the lifetime access you bought
Free accounts that never bought anything Deleted after 24 months without any activity — no sign-in and no practice in that time. Accounts with a purchased course, or one we granted you ourselves, are never affected Our legitimate interest in not keeping data nobody uses (Art. 6(1)(f) GDPR)
Purchase and settlement records: the purchase event we receive from Stripe (including the timestamp at which you accepted our terms) and any refund For the statutory retention periods Legal obligation (Art. 6(1)(c) GDPR) — these records document the conclusion of the contract and how it was settled
Payment and invoice data Kept by Stripe for the statutory commercial and tax retention periods (for example ten years, § 147 AO) Legal obligation (Art. 6(1)(c) GDPR); this data sits with Stripe, not with us
Server and access logs 30 days Operating and securing the service (Art. 6(1)(f) GDPR)
Your conversations with the AI assistant Not stored at all
Analytics and ad-conversion measurement on the marketing website and the purchase pages (Google Analytics 4 and Google Ads conversion measurement) 2 months in Google Analytics; ad-conversion data at Google per its retention; the advertising click identifier in your browser up to 30 days Your consent (Art. 6(1)(a) GDPR) inside the EEA/UK/Switzerland; outside, our legitimate interest with an opt-out (Art. 6(1)(f) GDPR) — see section 6

If you declare a withdrawal, we keep the record of it — what you declared and the time it reached us — as evidence that you withdrew in time and that we confirmed receipt to you, and for as long as the statutory retention duties for the related payment require.

You can ask us to delete your account at any time — write to support@certification-course.com. We will delete your account, your course access and your learning data. If you bought a course, deleting your account ends that access permanently and we cannot restore it, so we will ask you to confirm once before we go ahead. The purchase and settlement records listed above, and the invoice data held by Stripe, are kept for as long as statutory retention duties require.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority — for example the authority responsible for your place of residence, or the authority responsible for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.