Free beta: 60 days of full access, no card needed.120 seats leftSign up free

We use necessary cookies to run the site (sign-in and language). If you accept, we also load Google Analytics to see which pages are used, and Google reCAPTCHA to keep spam off the contact and bug-report forms. Privacy policy

Datenschutz

This policy explains what personal data AlgoPath collects, why, and what rights you have. It follows the EU General Data Protection Regulation (GDPR).

Controller

algopath.pro - Elman Huseynov

c/o Online-Impressum #9942

Europaring 90

53757 Sankt Augustin, Deutschland

Email: contact@elman.group

Hosting

The site is hosted on shared web hosting by Hostinger International Ltd. The provider processes the server log data described below on our behalf under a data processing agreement.

Account data

You sign in either with Google or GitHub, or with an email address and a password. When you use Google or GitHub we receive your name and email address from that provider; we never receive your password there. When you use email and password, the password is stored only as a cryptographic hash.

You can optionally add profile details such as a display name and links to your profiles on other services. These are voluntary and not needed to use the course.

Legal basis: performance of a contract (Art. 6 (1)(b) GDPR); for the optional profile fields, your consent (Art. 6 (1)(a) GDPR).

Learning progress

We store which steps you have opened, passed and completed, your streak of active days, your review schedule, and your position on the leaderboard. This lets the course continue across visits.

Legal basis: performance of a contract (Art. 6 (1)(b) GDPR).

Payments

Paid access is handled by Stripe, which sells it in its own name as merchant of record. You enter your payment details on Stripe only; we never see or store a card number.

For a purchase we store the amount paid, the currency, the Stripe checkout identifier, the country of your billing address and the tax Stripe reported. Country and tax are needed for our own bookkeeping.

Before payment we ask you to agree to performance starting immediately. For that consent we store the time and the IP address, because we must be able to prove that the right of withdrawal expired early.

Legal basis: performance of a contract (Art. 6 (1)(b) GDPR) and legal obligation (Art. 6 (1)(c) GDPR) for record-keeping. Stripe privacy policy: https://stripe.com/privacy.

Withdrawal from a contract

If you use the "Vertrag widerrufen" button we store your name, email address, order reference, and the times the request was received and confirmed. We do not ask for a reason.

Legal basis: legal obligation (Art. 6 (1)(c) GDPR).

Forms and messages

What you send through the contact form and the bug-report form is stored so the request can be handled. You may optionally attach a screenshot to a bug report; images are re-encoded on upload, which drops any embedded metadata.

For the newsletter we store your email address until you unsubscribe. Every message carries an unsubscribe link.

Legal basis: legitimate interest in answering enquiries (Art. 6 (1)(f) GDPR); for the newsletter, your consent (Art. 6 (1)(a) GDPR).

Code you write

Your solutions to the exercises run entirely in your browser through WebAssembly. The code is not sent to or executed on our servers. If you ask for it to be saved, the current state of your solution is stored so you can carry on later.

Newsletter

For the newsletter we store your email address, your name and the moment you agreed. We store the moment because we have to be able to prove the consent (§ 7 (2) no. 2 UWG). We also record which message went to you and when - without that we could send you the same message twice.

Legal basis: your consent (Art. 6 (1)(a) GDPR). You can withdraw it at any time, through the unsubscribe link in every message or the checkbox in your profile. Withdrawing does not affect the lawfulness of what was processed before. Messages are sent from our own server at Hostinger; we use no external marketing service.

When delivery measurement is switched on, a message carries a 1×1 pixel and links that route through our server, which shows us whether it was opened and whether a link was clicked. Those numbers are approximate and we treat them as such: anyone who blocks images never registers as an open, and some mail programs fetch images on their own without anybody reading the message. Blocking remote images in your mail program prevents open measurement entirely. When measurement is switched off, messages carry no pixel and no redirected links.

Cookies and consent

Necessary cookies keep the site working: a session cookie keeps you signed in, one cookie remembers your language, and a "cookie_consent" cookie stores your choice on the consent banner. These need no consent (Art. 6 (1)(f) GDPR). We use no advertising cookies. Analytics cookies are set only if you accept them in the banner - see "Web analytics" below.

The contact and bug-report forms use Google reCAPTCHA to block spam. reCAPTCHA is a non-essential third party, so we load it only after you accept non-essential cookies in the banner. If you decline, reCAPTCHA is never loaded and the forms are protected by a hidden field and rate limiting instead.

Legal basis for reCAPTCHA: your consent (Art. 6 (1)(a) GDPR). You can withdraw consent at any time by clearing the "cookie_consent" cookie in your browser; the banner then appears again. reCAPTCHA is provided by Google Ireland Ltd - see https://policies.google.com/privacy.

Public leaderboard

AlgoPath keeps a leaderboard. Anyone who has completed steps appears on it with the name and picture from their own account, the points they earned, how many steps they completed and the level they reached. The same details are shown on their player card. Both are readable without an account.

Search engines are told not to index these pages. That does not stop a visitor from reading them.

You can opt out at any time from your profile ("Hide me from the leaderboard"). After that you appear neither in the table nor in its rankings, and your player card is no longer reachable. Your own progress is unaffected.

Legal basis: our legitimate interest in a visible comparison between learners (Art. 6 (1)(f) GDPR), together with the opt-out that is available at any time.

Traffic sources

We keep a count of where visitors arrive from, so we know which of our posts and links actually bring people here. This is our own measurement - no third party is involved and no additional cookie is set.

Once per browsing session we store a single record: the source name (for example "reddit"), the kind of link (social network, search, referral, direct), a campaign name if the link carried one, the domain the visit came from (the domain only, never the full address), the page that was opened first, and the time. We do not store your IP address, and we do not store your browser's user agent. The record is tied only to your current session, which ends after two hours of inactivity; a later visit is counted as a new and unconnected one.

If you create an account during that session, the record is linked to your account so we can see which channel the account came from. You can ask us to remove that link at any time, and it is deleted together with your account in any case.

Legal basis: our legitimate interest in understanding which of our own publications work (Art. 6 (1)(f) GDPR). No consent is required for this, because nothing is stored on or read from your device beyond the session cookie that is strictly necessary for the site to work. Anonymous records are deleted after 13 months.

Web analytics

When web analytics is switched on, we load Google Analytics 4 (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) - and only after you have accepted non-essential cookies in the banner. If you decline, or if analytics is switched off, nothing is loaded and no analytics cookie is set.

What is processed: the pages you open, the time and length of the visit, an approximate location derived from a shortened IP address, device type, browser, and the page you arrived from. Google Analytics 4 does not store the IP address. We use no Google Tag Manager container, so no further third-party scripts can be loaded through it.

Legal basis: your consent (Art. 6 (1)(a) GDPR, § 25 (1) TTDSG). You can withdraw it at any time by clearing the "cookie_consent" cookie in your browser; the banner then appears again. Google privacy policy: https://policies.google.com/privacy.

Error monitoring

When something fails on the server, the application reports it to Sentry (Functional Software, Inc., through Sentry GmbH, Berlin) so we can fix it. What goes out is the technical error report, the route that was requested and the time.

We use Sentry's European region, so the error reports are processed inside the EU.

No personal data is sent with it: the send_default_pii option is switched off, so no IP address, no account details and no form contents are transmitted. We cannot rule out entirely that an individual error message contains personal data.

Legal basis: legitimate interest in a working and secure service (Art. 6 (1)(f) GDPR). Sentry privacy policy: https://sentry.io/privacy.

Server log files

The hosting provider automatically records standard access data (IP address, date and time, page requested, browser and operating system). This data is used to keep the service secure and running and is not combined with other data about you.

Legal basis: legitimate interest (Art. 6 (1)(f) GDPR).

Third parties your data reaches

Google (login, reCAPTCHA on forms and, with your consent, web analytics), GitHub (login), Stripe (payments) and Hostinger (hosting). Each processes data under its own privacy policy. We share only what each service needs for its function.

Transfers to the United States

Google, GitHub and Stripe belong to groups headquartered in the United States, so data can reach that country. The transfer rests on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the standard contractual clauses under Art. 46 (2)(c) GDPR.

Even on those grounds, access by US authorities cannot be ruled out entirely. Fonts and every other design asset on this site are served from our own server, so simply opening a page sends nothing to a third party.

How long we keep data

Account and progress data are kept while your account exists. Purchase records and withdrawals are kept as long as tax and commercial law require. When you delete your account, we delete your personal data except records we must retain by law.

Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to processing. To exercise any of these, email us at contact@elman.group.

You also have the right to complain to a data protection supervisory authority - in Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.