на главную
PRIVACY POLICY
Finance Sugarfree Ltd
Cyprus, 2025
1. INTRODUCTION
Finance Sugarfree Ltd (the “Company,” “We,” “Us,” or “Our”) is committed to protecting your privacy and securing your personal data (as defined below). As part of this commitment, we aim to be transparent about the information we collect, when we collect it, and how we use it.
This Privacy Policy (“Policy”) explains how we collect, use, and process personal data when you use our information platform/website and services, including any products or features provided by the Company (collectively, the “Services”). By accessing or using our information platform/website or Services, you confirm that you have read and understood this Policy. Where we rely on your consent for any processing, we obtain it from you separately and explicitly.
“Personal Data” refers to any information relating to an identified or identifiable individual. This includes data that, alone or in combination with other information, could be used to identify you.
2. WHO CONTROLS YOUR PERSONAL DATA AND HOW TO CONTACT US
The Controller responsible for processing your personal data is Finance Sugarfree Ltd, registered under company number HE 476071, with its registered office at: [REGISTERED OFFICE ADDRESS].
If you have any questions regarding the processing of your personal data or wish to exercise your rights under applicable data protection laws, you can contact the Company at:
Address: [REGISTERED OFFICE ADDRESS]
Email: [CONTACT EMAIL]
3. PERSONAL DATA WE COLLECT
This section outlines the categories of personal data we process. If we collect personal data from sources other than you directly, we also specify the origin and type of such data.
Contact Data: We may process data that enables us to contact you, including your name, email address, and telephone number. This data is provided by you.
Profile Data: We may process the personal information you provide in your account or profile, including your name, email address, telephone number, and country or region. This data is provided by you.
Customer Relationship Data: We may process information related to our interactions with you as a customer, including your name, contact details, classification within our customer relationship system, and records of communications between us. This data is provided by you.
Service Data: We may process personal data provided and generated through your use of our Services, including records of previous purchases. This data originates from you and/or our systems.
Transaction Data: We may process data related to transactions made with us or via our website, including your name, contact details, payment details (or other payment methods), and transaction details. This data is provided by you.
Communication Data: We may process data contained in or related to communications between you and us, including message content and associated metadata. Metadata from website contact forms is generated automatically.
Usage Data: We may process data related to how you interact with our website and Services, including IP address, geographical location, browser type and version, operating system, referral source, visit duration, page views, navigation paths, and usage patterns. This data is collected through our analytics tracking system and through cookies and similar technologies, as described in our Cookie Policy, and (where required) on the basis of your consent.
Third-Party Data: Please do not provide us with personal data belonging to other individuals unless we explicitly request it.
You are not obligated to provide us with any personal data about you. However, in some instances, not providing such personal data will prevent us from providing you with the Services you requested and will prevent your use of the Services or a part thereof.
Personal Data of Minors
Our Services are not intended for individuals under the age of 18. We do not knowingly collect or solicit personal information from minors. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately so we can delete the information from our records.
4. PURPOSES OF PROCESSING AND LEGAL BASES
We process your personal data for one or more of the purposes outlined in this section and according to the appropriate legal basis. We will not process personal data about you unless there is a legal basis for such processing.
The legal bases according to which the Company may process personal data about you are as follows:
- Legitimate Interests. Processing is necessary for the provision of the Services or for any other legitimate interests pursued by the Company or by a third party.
- Consent. Your consent that the Company will process personal data about you for one or more specific purposes.
- Performance of a Contract. Processing is necessary for the performance of a contract with you (for example, to provide the course or services you have purchased) or to take steps at your request before entering into such a contract.
- Compliance with a Legal Obligation. Processing is necessary for compliance with a legal obligation to which the Company is subject (for example, accounting, tax, or anti-money-laundering record-keeping).
- Vital Interests. Processing is necessary to protect your vital interests or those of another natural person.
We may use personal data about you for the following purposes:
Operations – to operate our website, fulfil orders, provide Services, generate invoices, and manage payments. The legal basis is our legitimate interest in the proper administration of our business, or the necessity of processing for the performance of a contract with you or in preparation for entering into such a contract at your request.
Publications – we may process account data, profile data, and service data for publication on our website or other platforms in accordance with your express instructions.
Relationships and Communications – to manage relationships, communicate with you (excluding direct marketing), provide support services, and handle complaints. The legal basis is our legitimate interest in maintaining business relationships and administering our business properly.
Personalisation – we process account data, service data, and usage data to personalise content, ensuring that you see only relevant material. The legal basis is our legitimate interest in providing an optimal user experience.
Direct Marketing – we process contact data, account data, profile data, customer relationship data, and transaction data to send you direct marketing communications, primarily by email. Where required by applicable law, we send such communications only on the basis of your prior consent (opt-in), and you may withdraw your consent and unsubscribe at any time using the link included in every message or by contacting us. Where we are permitted to rely on a legitimate interest (for example, in relation to our existing customers and similar products or services), we will do so only in a manner consistent with applicable law and with your right to object at any time.
Research and Analysis – we process usage data, service data, and transaction data to analyse the use of our website and Services. The legal basis is our legitimate interest in monitoring, improving, and securing our business operations.
Record Keeping – we process personal data to create and maintain business records, including backup copies of databases. The legal basis is our legitimate interest in ensuring efficient business operations.
Security – we process personal data to maintain security, prevent fraud, and mitigate criminal activities. The legal basis is our legitimate interest in protecting our website, Services, business, and stakeholders.
Insurance and Risk Management – we process personal data as necessary for obtaining or maintaining insurance coverage, managing risks, and obtaining professional advice. The legal basis is our legitimate interest in protecting our business against potential risks.
Legal Claims – we process personal data as necessary for establishing, exercising, or defending legal claims. The legal basis is our legitimate interest in protecting and asserting legal rights.
Legal Compliance and Vital Interests – we may process personal data to comply with legal obligations or to protect your vital interests or those of another natural person.
5. SHARING YOUR PERSONAL DATA
Data Storage on our Platform/Website
Your personal data is stored in our platform/website database.
Disclosure to Third-Party Suppliers and Service Partners
We may share your personal data with third-party suppliers and service partners that support our educational platform and the delivery of our Services.
Financial Transactions and Payment Processing
We may share your personal data with our payment service providers only to the extent necessary for processing payments, issuing refunds, and handling related queries or complaints.
Legal and Compliance-Related Disclosures
In addition to the above, we may disclose your personal data if required to comply with a legal obligation, protect your vital interests or those of another person, or establish, exercise, or defend legal claims.
We do not sell, rent, or lease your personal data to third parties for their marketing purposes.
International Data Transfers
Safeguards are implemented to ensure the security and integrity of your data, particularly during international transfers. Your personal data may be transferred to and processed by our service providers located outside Cyprus, including our payment provider Stripe (United States), our course platform GetCourse (whose servers may be located in the Russian Federation), and our email and marketing service provider. Where personal data is transferred to a country that does not benefit from an adequacy decision, we put in place appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, together with technical and organisational measures such as encryption and pseudonymisation, and contractual commitments from recipients to uphold data protection standards. You may contact us for further information about these transfers and the safeguards in place.
6. RETAINING AND DELETING PERSONAL DATA
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
We will retain your personal data for a maximum of 5 years from the end of your last contract with us or until you object or unsubscribe from business communications; where we need to fulfil our legal obligations, we keep your personal data for the period set out by the relevant law.
Personal data is stored on computers and other devices in an encrypted database. Organisational and technical safeguards have been put in place to protect the data we collect and handle from unauthorised access, modification, disclosure, or destruction. We may store your data on servers provided by third-party hosting vendors with whom we have contracted.
Where your personal data is no longer required by us, we will either securely delete or anonymise it.
7. DATA SECURITY
We have implemented appropriate technical and organisational precautions and security policies, rules, and procedures to secure your personal data under our control from unauthorised access, improper use or disclosure, unauthorised modification, or unlawful destruction, and to prevent the loss, misuse, or alteration of your personal data.
To comply with the law, we employ industry-standard encryption techniques to encrypt data during transit and at rest, ensuring confidentiality and integrity.
In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a need-to-know business requirement. They will only process your personal data on our instructions or on a lawful ground, and subject to their duty of confidentiality.
You acknowledge that the transmission of unencrypted (or inadequately encrypted) data over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
We cannot provide absolute assurance against unauthorised access or breaches. In the event of a data breach, we will conduct a risk assessment and notify impacted individuals in accordance with applicable laws.
8. USE OF AUTOMATED CHATBOTS
We may use chatbots as an initial point of contact between the Company and its users to facilitate customer service interactions.
9. YOUR RIGHTS UNDER THE GENERAL DATA PROTECTION REGULATION (“GDPR”)
In accordance with the GDPR, you have the right to request confirmation from us regarding the processing of your personal data, and we will provide you, at reasonable intervals, with access to the following information:
• what personal data we hold about you;
• the reasons why we are processing your data;
• the recipients to whom your data may have been disclosed;
• the duration for which we intend to keep your data (where possible);
• whether we transfer your data and the safeguards we have in place;
• your rights with respect to your personal data;
• the process for making a complaint;
• the source of your personal data;
• whether we have used any automated decision-making or profiling and any related information.
Right to Rectification – although all reasonable efforts will be made to keep your personal data updated, you are kindly requested to inform us of any changes. You have the right to ask us to rectify inaccurate personal data and to complete incomplete personal data concerning you. We may seek to verify the accuracy of the data before rectifying it.
Right to Erasure – you have the right to ask us to delete your personal data, and we shall comply without undue delay, but only where: the personal data are no longer necessary for the purposes for which they were collected; you have withdrawn your consent (where we process on the basis of consent) and we have no other legal ground; you have successfully exercised your right to object; your personal data have been processed unlawfully; or there is a legal obligation to erase the data.
Right to Restriction – you have the right to ask us to restrict processing (store but not further process) your personal data, but only where: the accuracy of your personal data is contested, for a period enabling us to verify it; the processing is unlawful and you oppose erasure; we no longer need the personal data but you need it for legal claims; or you have exercised your right to object and verification of our overriding legitimate grounds is pending.
Right to Data Portability – you can request that we give you your personal data in a machine-readable format, or transfer it directly to another controller where technically feasible and without harming others’ rights. This right only applies where: the processing is based on your consent or on the performance of a contract with you; and the processing is carried out by automated means.
Right to Object – where we process your personal data for the performance of a task carried out in the public interest or on the basis of our (or a third party’s) legitimate interest, you have the right to object. Where your data is processed for direct marketing, you have the right to object at any time, including profiling related to such direct marketing.
Right to Withdraw Consent – where we handle your personal data based on your consent, you have the right to withdraw it at any time, and the process of doing so will be as straightforward as providing it. If you withdraw your consent, we will check whether we have an alternative legal basis (such as a legal obligation); if we do, we may continue to process your data and will inform you accordingly.
Right to lodge a Complaint – you are entitled to file complaints with the relevant Data Protection Supervisory Authority. The supervisory authority for the Company is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). If you reside in an EU member state, you can file a complaint with the Data Protection Authority of that state. We request that you first attempt to resolve any issues with us before contacting the competent authority, although you have the right to do so at any time.
10. CHANGES TO THE POLICY
We may amend the terms of this Policy from time to time. Whenever we amend this Policy, we will notify you by publishing the updated Policy on our portal. In addition, when we make significant amendments, we will strive to inform you through means of communication we believe are reasonably appropriate and by publishing a notice on our portal/website. Unless stated otherwise, all amendments enter into force upon publication of the updated Policy.
11. CONTACT US
For inquiries relating to the retention period of the data you provide to us, or for any other questions related to data privacy, please direct your correspondence to our customer support at [CONTACT EMAIL].
This Privacy Policy is provided to inform you about how we process your personal data. Where we rely on consent as the legal basis for processing, we obtain it from you separately and explicitly, and you may withdraw it at any time.