Privacy & Cookies
Last updated:
Who is responsible for your data?
Sainar Academy is responsible for the personal data we use to operate this website, respond to enquiries and organise course bookings and related communications. This notice explains that use; it does not ask you to consent simply by browsing.
Sainar AcademyFaas Wilkesstraat 159E
1095 MD Amsterdam, Netherlands
Email: natalia@sainaracademy.com
Information we use
- Enquiries: your name, email address, message and subsequent correspondence when you contact us. Please do not include payment credentials or unnecessary sensitive information.
- Bookings: course and dates, deposit or full-payment selection, agreed amounts, booking/payment references, status and timestamps. Confirmed bookings also record the customer name and email supplied through Stripe.
- Payments: Stripe Checkout collects payment information, billing address and phone number as well as contact details. We can access relevant transaction information through Stripe. Our booking database does not store full card numbers or card security codes.
- Accounts: when you sign in, WorkOS processes account identifiers, email and authentication/session information. If you choose Google sign-in, your name, email and profile picture may be supplied by Google. We do not receive your Google password or access to your Gmail messages through this sign-in.
- Existing learning records: account-linked purchases and any previously recorded chapter progress. New online-learning progress saving is currently disabled.
- Confirmation emails: recipient address, booking details, sending attempts, delivery-provider reference and send status. Our confirmation template has no tracking pixel.
- Technical information: hosting, security and media services process information such as IP address, browser/request details and timestamps. Application diagnostics record request identifiers, event names and errors to help investigate problems.
Information comes from you, your chosen sign-in/payment providers, and requests made by your browser. You can browse public course information without an account. Without the details required for a particular enquiry, login or payment, we may not be able to provide that service.
Why we use it and our legal bases
- Steps before a contract and performance of a contract: answering course-booking enquiries, reserving places, administering payments and accounts, and sending booking confirmations and practical communications.
- Legal obligations: keeping records required for accounting, taxation and responding to legally binding requests.
- Legitimate interests: responding to general enquiries, protecting the website and accounts, preventing duplicate bookings and fraud, troubleshooting delivery problems, and handling disputes. These interests must be balanced against your rights.
- Consent, where required: for optional uses that require consent, we must ask separately and explain the purpose. Booking a course or reading this notice is not consent to advertising or unrelated marketing.
The booking system automatically checks dates, availability and payment status. If a result appears incorrect, contact us for a review. Payment providers may perform their own fraud or eligibility checks, including for instalment methods, under their own notices.
Services involved and data sharing
We do not sell your personal data. Relevant information is handled by the services needed for the features you use:
- Cloudflare: hosting, security, database storage, video delivery and outbound booking email.
- WorkOS: account authentication and session management.
- Stripe and your selected payment provider: checkout, payment processing, fraud prevention and payment-related obligations.
- Web3Forms: forwarding contact-form messages to our inbox.
- Google: our incoming email service and, if you choose it, Google sign-in. Directions links open Google Maps only when followed.
Some providers process data on our behalf; others, including payment and identity providers, may also act independently for purposes explained in their own notices. We may disclose relevant records where legally required or necessary to establish, exercise or defend legal claims.
Cookies and browser storage
This website is not cookie-free. Login uses cookies to maintain and protect your session. Checkout uses browser session storage to remember your selection and recognise a retry, helping avoid duplicate booking attempts.
- Authentication: WorkOS session cookies (normally named
wos-session) and short-lived login-security cookies. Session cookies may persist between visits; their expiry is separate from the validity of the sign-in tokens they contain. - Checkout storage: keys beginning
booking-attempt:andbooking-last-selection:store a random attempt identifier and course/date/payment-option selection, not card details. Session storage normally lasts for the browser tab session; browser session-restore behaviour can affect this. - Security and external services: Cloudflare security features may use challenge or bot-protection cookies. Hosted sign-in and payment services have their own storage practices. Loading video content connects your browser to Cloudflare media services.
Strictly necessary storage for a service you request does not require cookie consent. This does not make every third-party cookie exempt. Non-essential storage that requires consent must not be enabled before that consent is obtained.
Our website application does not currently include Google Analytics, Google Tag Manager or advertising-pixel integrations. We use Google Search Console reports about visibility in Google Search; these do not require us to add an analytics script to your browser.
You can clear or block site storage in your browser and sign out of your account. Blocking necessary storage may prevent login or interrupt booking recovery. Clearing storage does not cancel a booking, payment or seat hold. Contact us if you need help.
Retention and security
Retention depends on the purpose of each record, rather than one period for all information:
- Enquiries and correspondence are assessed according to whether the conversation is resolved, a booking follows, or a complaint remains open.
- Booking, payment and accounting records are assessed against course administration, applicable statutory record-keeping duties and the need to resolve refunds, disputes or legal claims.
- Account and existing learning records are assessed against the continuing account/service relationship and deletion requests, while preserving records we must lawfully retain.
- Email delivery and diagnostic records are assessed against troubleshooting, preventing duplicate confirmations, security incidents and related booking obligations. Backups and provider logs have separate retention cycles.
Closing a browser or account does not automatically erase booking or accounting records. Contact us about the retention of your specific information or to request deletion. We use access controls, encrypted connections and restricted administrative access; no online service can guarantee absolute security.
International processing
Our providers operate internationally, so information may be processed outside the European Economic Area, including in the United States. Cloud hosting does not mean all information stays in the Netherlands.
Transfers outside the EEA require a lawful transfer mechanism, such as an applicable European Commission adequacy decision or standard contractual clauses with any necessary additional safeguards. The provider notices linked above describe their arrangements. Contact us to request details of the destinations and safeguards relevant to your data and how to obtain a copy of applicable safeguards.
Your rights and complaints
Subject to the conditions in data-protection law, you can request access, correction, deletion, restriction of processing and portability of your data. You can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting the lawfulness of processing before withdrawal.
Email natalia@sainaracademy.com to make a request. We may need proportionate information to verify your identity; please do not send identity documents unless we explain why they are needed. We normally respond within one month. If a lawful extension is needed, we will explain it within that period. Some records may need to be retained despite a deletion request; we will explain the reason.
You can complain to the Dutch Autoriteit Persoonsgegevens or another competent supervisory authority, including in the EU country where you live or work. You do not have to contact us first.
Changes to this notice
We update this notice when our services or data practices change and show the latest revision date above. Where required, we will notify you of material changes or ask for consent separately. Continued browsing does not amount to consent to a new purpose.