What we collect and why
- Email address (you provide it when you register) — to log in (email plus password, and reset-password links) and to send subscription and renewal notices.
- A password hash (never the password itself) — to check logins.
- Billing country (returned by Paddle after payment) — to apply the right tax. It does not decide which language of the course you can watch.
- Subscription and purchase records (from Paddle) — to decide what you can watch.
- Watch history (created as you use the service) — for the continue-watching feature.
- Referral codes (URL parameters when you arrive via a dealer link) — to calculate dealer commission.
- Comments and tickets you submit — to show other members and to answer you.
- If you subscribe to practice-reminder email: the address, language, time of consent and IP at that moment — to prove the consent exists.
- A digest of the IP address of a page view — to count unique visitors. We do not store the IP address itself and we do not set a cookie for this. The same address produces the same digest within a UTC day. Digests are kept for at most 40 days.
We do not collect: plaintext passwords, payment-card details (Paddle handles those; we never see them), or health information.
Legal bases (GDPR Article 6)
- Providing the service you bought: contract (Art. 6(1)(b)).
- Transactional email (login, renewal reminders, invoices, purchase confirmation): contract.
- Keeping accounts and tax records: legal obligation (Art. 6(1)(c)).
- Marketing email: your consent (Art. 6(1)(a)), which you can withdraw at any time.
- Showing comments you wrote: your consent (Art. 6(1)(a)).
- Moderating comments: legitimate interests (Art. 6(1)(f)) — to keep false claims about disease and results off the site.
- Dealer attribution: legitimate interests (Art. 6(1)(f)) — to calculate commission we owe dealers. You may object.
- Counting unique visitors: legitimate interests (Art. 6(1)(f)) — seeing how many people came. We keep a digest of the IP address, not the address itself. You may object.
Cookies
We use only two cookies. One is an httpOnly session cookie that keeps you logged in; without it login cannot work. The other stores the interface language you chose on the home page, as a language code only (for example de), so you do not have to choose again; you can change it on any page. Both are strictly necessary, so we do not ask for consent.
We do not use tracking, advertising or third-party analytics cookies. Dealer attribution does not use cookies either — the referral code travels in the URL, or is the discount code you actually used. Unique visitors are not counted with a cookie: we turn the IP address of the visit into a digest and do not store the address itself. Digests are kept for at most 40 days.
Processors and where data lives
- Paddle — payments, tax, invoices.
- Supabase — database, stored in the EU (Frankfurt, eu-central-1).
- Bunny — video delivery, stored in the EU (Frankfurt).
- Render — the website, in the EU (Frankfurt).
- Resend — transactional email, EU region (Ireland).
- MailerLite — practice-reminder and similar marketing mail, data centres in Germany and the Netherlands. Only if you subscribed to those emails.
Each processor is bound by a data-processing agreement (Supabase's DPA takes effect with its terms). Where a transfer outside the EU is needed, we rely on Standard Contractual Clauses.
How long we keep data
Account data is kept while the account exists. After you delete it there is a 30-day window to undo accidental deletion, then it is erased except where law requires otherwise. Accounting records are kept for 10 years from the end of the relevant year.
Your rights
You may access, correct or delete your data, restrict or object to processing, and obtain a portable copy. Email service@hxfdaoyin.com. We reply within 30 days.
EU Representative (per Article 27 GDPR)
FGND Core GmbH
Hauptstrasse 151, 10827 Berlin, Germany
Email: hxfdaoyin@core-privacy.eu
This contact is for GDPR-related privacy matters and requests from EU supervisory authorities and individuals in the EU.
UK Representative (per Article 27 UK GDPR)
FGND Core GmbH
167-169 Great Portland St, London W1W 5PF, UK
Email: hxfdaoyin@core-privacy.eu
This contact is for UK GDPR-related privacy matters and requests from UK supervisory authorities and individuals in the UK.
The operator of this service may change in future. We will email you if it does.