Конфиденциальность

What we collect and why

  • Email address (you provide it when you register) — to log in (email plus password, and reset-password links) and to send subscription and renewal notices.
  • A password hash (never the password itself) — to check logins.
  • Billing country (returned by Paddle after payment) — to apply the right tax. It does not decide which language of the course you can watch.
  • Subscription and purchase records (from Paddle) — to decide what you can watch.
  • Watch history (created as you use the service) — for the continue-watching feature.
  • Referral codes (URL parameters when you arrive via a dealer link) — to calculate dealer commission.
  • Comments and tickets you submit — to show other members and to answer you.
  • If you subscribe to practice-reminder email: the address, language, time of consent and IP at that moment — to prove the consent exists.

We do not collect: plaintext passwords, payment-card details (Paddle handles those; we never see them), or health information.

Legal bases (GDPR Article 6)

  • Providing the service you bought: contract (Art. 6(1)(b)).
  • Transactional email (login, renewal reminders, invoices, purchase confirmation): contract.
  • Keeping accounts and tax records: legal obligation (Art. 6(1)(c)).
  • Marketing email: your consent (Art. 6(1)(a)), which you can withdraw at any time.
  • Showing comments you wrote: your consent (Art. 6(1)(a)).
  • Moderating comments: legitimate interests (Art. 6(1)(f)) — to keep false claims about disease and results off the site.
  • Dealer attribution: legitimate interests (Art. 6(1)(f)) — to calculate commission we owe dealers. You may object.

Cookies

We use only two cookies. One is an httpOnly session cookie that keeps you logged in; without it login cannot work. The other stores the interface language you chose on the home page, as a language code only (for example de), so you do not have to choose again; you can change it on any page. Both are strictly necessary, so we do not ask for consent.

We do not use tracking, advertising or third-party analytics cookies. Dealer attribution does not use cookies either — the referral code travels in the URL, or is the discount code you actually used.

Processors and where data lives

  • Paddle — payments, tax, invoices.
  • Supabase — database, stored in the EU (Frankfurt, eu-central-1).
  • Bunny — video delivery, stored in the EU (Frankfurt).
  • Render — the website, in the EU (Frankfurt).
  • Resend — transactional email, EU region (Ireland).
  • MailerLite — practice-reminder and similar marketing mail, data centres in Germany and the Netherlands. Only if you subscribed to those emails.

Each processor is bound by a data-processing agreement (Supabase's DPA takes effect with its terms). Where a transfer outside the EU is needed, we rely on Standard Contractual Clauses.

How long we keep data

Account data is kept while the account exists. After you delete it there is a 30-day window to undo accidental deletion, then it is erased except where law requires otherwise. Accounting records are kept for 10 years from the end of the relevant year.

Your rights

You may access, correct or delete your data, restrict or object to processing, and obtain a portable copy. Email service@hxfdaoyin.com. We reply within 30 days.

We are established outside the EU and are appointing an EU representative under GDPR Article 27. Until that appointment is published here, send related requests to service@hxfdaoyin.com. After appointment, the representative's name and contact details will appear in this section.

The operator of this service may change in future. We will email you if it does.