General Data Protection Regulation (GDPR) Compliance
Last Updated: May 3, 2025
Harl Vokas is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This policy explains how we collect, use, store, and protect your personal information when you use our educational platform at harlvokas.com.
1. Data Controller Information
The data controller responsible for your personal data is:
Harl Vokas
Oleksy Novaka St, 75
Rivne, Rivne Oblast
Ukraine, 33000
Email: support@harlvokas.com
Phone: +380508034045
2. Legal Basis for Processing Personal Data
We process your personal data based on the following legal grounds:
- Consent: You have given explicit consent for processing your personal data for specific purposes
- Contract Performance: Processing is necessary to fulfill our contractual obligations to provide educational services
- Legal Obligation: Processing is required to comply with applicable laws and regulations
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided your rights do not override these interests
3. Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Information You Provide
- Account registration details (name, email address, username, password)
- Profile information (education level, learning preferences, profile picture)
- Payment and billing information (credit card details, billing address, transaction history)
- Course enrollment and completion data
- Communications with our support team
- Survey responses and feedback
- Forum posts and discussion contributions
3.2 Information Collected Automatically
- Technical data (IP address, browser type, device information, operating system)
- Usage data (pages visited, time spent on platform, course progress, learning patterns)
- Cookies and similar tracking technologies
- Log files and analytics data
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- Providing access to our educational platform and course materials
- Creating and managing your user account
- Processing payments and maintaining transaction records
- Personalizing your learning experience and recommending relevant courses
- Tracking course progress and issuing certificates
- Communicating with you about your account, courses, and platform updates
- Providing customer support and responding to inquiries
- Sending promotional materials and newsletters (with your consent)
- Improving our platform through analytics and user behavior analysis
- Ensuring platform security and preventing fraud
- Complying with legal and regulatory requirements
5. Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
5.1 Service Providers
We share data with third-party service providers who perform services on our behalf, including:
- Cloud hosting and storage providers
- Payment processors and financial institutions
- Email delivery and communication platforms
- Analytics and performance monitoring services
- Customer support platforms
- Content delivery networks
5.2 Legal Requirements
We may disclose your personal data when required by law, regulation, legal process, or governmental request.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity.
5.4 With Your Consent
We may share your data with other parties when you have given explicit consent for such sharing.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions recognizing equivalent data protection standards
- Binding corporate rules for intra-group transfers
- Your explicit consent for specific transfers
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account existence plus 3 years after closure |
| Course progress and completion data | Duration of account existence plus 7 years |
| Payment and transaction records | 7 years from transaction date |
| Marketing consent records | Until consent is withdrawn plus 3 years |
| Technical and usage logs | 12 months |
| Support communications | 3 years from last contact |
8. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
8.1 Right to Access
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of your data.
8.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data under certain circumstances, including:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required to comply with a legal obligation
8.4 Right to Restriction of Processing
You have the right to request restriction of processing in specific situations, such as when you contest the accuracy of the data or object to processing.
8.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
8.6 Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
8.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
9. Exercising Your Rights
To exercise any of your rights under GDPR, please contact us using the following methods:
- Email: support@harlvokas.com
- Phone: +380508034045
- Mail: Harl Vokas, Oleksy Novaka St, 75, Rivne, Rivne Oblast, Ukraine, 33000
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
We may request additional information to verify your identity before processing your request.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection practices
- Regular backups and disaster recovery procedures
- Monitoring and logging of system access
- Incident response and breach notification procedures
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing information about:
- The nature of the personal data breach
- The likely consequences of the breach
- The measures taken or proposed to address the breach
- Contact information for further inquiries
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our platform. You can manage your cookie preferences through your browser settings or our cookie consent tool.
For detailed information about our use of cookies, please refer to our Cookie Policy.
13. Children's Privacy
Our platform is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent.
If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that information as quickly as possible.
If you believe we have collected personal data from a child under 16, please contact us immediately at support@harlvokas.com.
14. Automated Decision-Making and Profiling
We may use automated decision-making and profiling to:
- Recommend courses based on your learning history and preferences
- Personalize content and learning pathways
- Detect and prevent fraudulent activities
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. If you wish to contest an automated decision, please contact us.
15. Third-Party Links
Our platform may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
16. Changes to This Policy
We may update this GDPR Compliance Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
When we make material changes to this policy, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email or through a prominent notice on our platform
- Obtain your consent where required by law
We encourage you to review this policy periodically to stay informed about how we protect your personal data.
17. Contact Information
If you have any questions, concerns, or requests regarding this GDPR Compliance Policy or our data processing practices, please contact us:
Harl Vokas
Oleksy Novaka St, 75
Rivne, Rivne Oblast
Ukraine, 33000
Email: support@harlvokas.com
Phone: +380508034045
18. Supervisory Authority
If you have concerns about our data processing practices and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
Acknowledgment: By using our platform, you acknowledge that you have read and understood this GDPR Compliance Policy and agree to the collection, use, and disclosure of your personal data as described herein.