Privacy Policy
Last Updated: February 2025
CodeForge Academy is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our educational services.
Data Controller Information
Company: CodeForge Academy
Address: 48 Strovolos Avenue, 2018 Nicosia, Cyprus
Email: privacy@domain.com
Phone: +357 22 758394
Scope: This policy covers our website and all educational services provided by CodeForge Academy.
Information We Collect
Personal Information
- Contact Information: Name, email address, phone number, postal address
- Educational Data: Course enrollment information, academic progress, completion certificates
- Account Information: Username, password (encrypted), profile preferences
- Payment Information: Billing details, transaction history (payment processing handled by secure third parties)
- Communication Data: Messages sent through contact forms, support tickets, course discussions
Technical Information
- Usage Data: IP address, browser type, pages visited, time spent on pages
- Device Information: Operating system, screen resolution, device type
- Cookie Data: Website preferences, session information, analytics data
- Learning Analytics: Course progress, quiz results, engagement metrics
How We Collect Data
- Directly from you when you register, enroll in courses, or contact us
- Automatically through your use of our website and learning platform
- From third-party services like payment processors and analytics providers
- Through cookies and similar tracking technologies
How We Use Your Information
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: For marketing communications and optional analytics
- Contract: To provide educational services you have enrolled in
- Legitimate Interest: For business operations, security, and website improvement
- Legal Obligation: For tax records, regulatory compliance, and legal requirements
Purposes of Data Processing
- Service Delivery: Provide courses, track progress, issue certificates
- Communication: Send course updates, respond to inquiries, provide support
- Payment Processing: Handle enrollment fees and billing
- Website Improvement: Analyze usage patterns and optimize user experience
- Marketing: Send promotional content about new courses (with consent)
- Security: Protect against fraud, unauthorized access, and security threats
- Legal Compliance: Meet regulatory requirements and tax obligations
Marketing Communications
We may send you marketing emails about:
- New course offerings and educational programs
- Industry insights and learning resources
- Special promotions and early-bird discounts
- Alumni success stories and networking events
Opt-out: You can unsubscribe from marketing emails at any time by clicking the unsubscribe link or contacting us directly.
Data Protection and Security
Security Measures
- Encryption: All data transmitted to our servers is encrypted using SSL/TLS protocols
- Secure Storage: Personal data stored on encrypted servers with restricted access
- Access Controls: Multi-factor authentication and role-based access for our staff
- Regular Audits: Periodic security assessments and vulnerability testing
- Staff Training: Regular privacy and security training for all employees
- Backup Protection: Encrypted backups stored in secure, geographically distributed locations
Data Breach Procedures
In the event of a data breach:
- We will notify relevant authorities within 72 hours as required by GDPR
- Affected individuals will be informed without undue delay
- We will take immediate steps to contain and remedy the breach
- A thorough investigation will be conducted to prevent future incidents
Data Minimization
We collect only the minimum amount of personal data necessary to provide our educational services effectively. Data is regularly reviewed and deleted when no longer needed for legitimate business purposes.
Data Retention Periods
We retain your personal data for the following periods:
- Contact Form Submissions: 3 years from last contact
- Student Records: 5 years after course completion for academic verification
- Financial Records: 7 years as required by Cyprus tax law
- Marketing Data: Until consent is withdrawn or 3 years of inactivity
- Website Analytics: 26 months (Google Analytics default)
- Account Information: Until account deletion is requested
Note: Some data may be retained longer if required by legal obligations or for resolving disputes.
Third-Party Services and Data Sharing
Service Providers We Use
- Google Analytics: Website traffic analysis and user behavior insights
- Payment Processors: Secure payment handling (PayPal, Stripe, bank transfers)
- Email Services: Course notifications and marketing communications
- Cloud Hosting: Website and data hosting with enterprise-grade security
- Learning Management System: Course delivery and progress tracking
Data Sharing Principles
- We never sell your personal data to third parties
- Data is shared only with trusted service providers under strict contracts
- All third parties must comply with GDPR and equivalent data protection standards
- We conduct due diligence on all data processors we work with
- Data sharing is limited to what is necessary for service delivery
International Data Transfers
Some of our service providers are located outside the European Union. When transferring data internationally, we ensure:
- Adequacy decisions by the European Commission are in place, or
- Standard Contractual Clauses (SCCs) are implemented, or
- Other appropriate safeguards are established
Your Privacy Rights
Under GDPR, You Have the Right To:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct any inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restrict Processing: Limit how we use your personal data
- Data Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Withdraw consent for data processing at any time
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: privacy@domain.com
Phone: +357 22 758394
Address: 48 Strovolos Avenue, 2018 Nicosia, Cyprus
We will respond to your request within 30 days. Some requests may require identity verification for security purposes.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with data protection laws, you have the right to lodge a complaint with the Cyprus Data Protection Commissioner or your local supervisory authority.
Children's Privacy
Our educational services are designed for individuals aged 18 and older. We do not knowingly collect personal information from children under 18 years of age.
If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information immediately. If you believe we have collected information from a child under 18, please contact us immediately.
For users aged 16-17 in EU countries, parental consent may be required for certain data processing activities in accordance with local GDPR implementations.
Updates to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes to this policy, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email if you have provided us with your email address
- Post a notice on our website highlighting the changes
- For significant changes, we may seek your renewed consent
We encourage you to review this policy periodically to stay informed about how we protect your information.