Datenschutz
This policy explains what personal data AlgoPath collects, why, and what rights you have. It follows the EU General Data Protection Regulation (GDPR).
Controller
algopath.pro - Elman Huseynov
c/o Online-Impressum #9942
Europaring 90
53757 Sankt Augustin, Deutschland
Email: contact@elman.group
Hosting
The site is hosted on shared web hosting by Hostinger International Ltd. The provider processes the server log data described below on our behalf under a data processing agreement.
Account data
You sign in either with Google or GitHub, or with an email address and a password. When you use Google or GitHub we receive your name and email address from that provider; we never receive your password there. When you use email and password, the password is stored only as a cryptographic hash.
You can optionally add profile details such as a display name and links to your profiles on other services. These are voluntary and not needed to use the course.
Legal basis: performance of a contract (Art. 6 (1)(b) GDPR); for the optional profile fields, your consent (Art. 6 (1)(a) GDPR).
Learning progress
We store which steps you have opened, passed and completed, your streak of active days, your review schedule, and your position on the leaderboard. This lets the course continue across visits.
Legal basis: performance of a contract (Art. 6 (1)(b) GDPR).
Payments
Paid access is handled by Stripe, which sells it in its own name as merchant of record. You enter your payment details on Stripe only; we never see or store a card number.
For a purchase we store the amount paid, the currency, the Stripe checkout identifier, the country of your billing address and the tax Stripe reported. Country and tax are needed for our own bookkeeping.
Before payment we ask you to agree to performance starting immediately. For that consent we store the time and the IP address, because we must be able to prove that the right of withdrawal expired early.
Legal basis: performance of a contract (Art. 6 (1)(b) GDPR) and legal obligation (Art. 6 (1)(c) GDPR) for record-keeping. Stripe privacy policy: https://stripe.com/privacy.
Withdrawal from a contract
If you use the "Vertrag widerrufen" button we store your name, email address, order reference, and the times the request was received and confirmed. We do not ask for a reason.
Legal basis: legal obligation (Art. 6 (1)(c) GDPR).
Forms and messages
What you send through the contact form and the bug-report form is stored so the request can be handled. You may optionally attach a screenshot to a bug report; images are re-encoded on upload, which drops any embedded metadata.
For the newsletter we store your email address until you unsubscribe. Every message carries an unsubscribe link.
Legal basis: legitimate interest in answering enquiries (Art. 6 (1)(f) GDPR); for the newsletter, your consent (Art. 6 (1)(a) GDPR).
Code you write
Your solutions to the exercises run entirely in your browser through WebAssembly. The code is not sent to or executed on our servers. If you ask for it to be saved, the current state of your solution is stored so you can carry on later.
Cookies and consent
Necessary cookies keep the site working: a session cookie keeps you signed in, one cookie remembers your language, and a "cookie_consent" cookie stores your choice on the consent banner. These need no consent (Art. 6 (1)(f) GDPR). We use no advertising or tracking cookies.
The contact and bug-report forms use Google reCAPTCHA to block spam. reCAPTCHA is a non-essential third party, so we load it only after you accept non-essential cookies in the banner. If you decline, reCAPTCHA is never loaded and the forms are protected by a hidden field and rate limiting instead.
Legal basis for reCAPTCHA: your consent (Art. 6 (1)(a) GDPR). You can withdraw consent at any time by clearing the "cookie_consent" cookie in your browser; the banner then appears again. reCAPTCHA is provided by Google Ireland Ltd - see https://policies.google.com/privacy.
Error monitoring
When something fails on the server, the application reports it to Sentry (Functional Software, Inc., through Sentry GmbH, Berlin) so we can fix it. What goes out is the technical error report, the route that was requested and the time.
We use Sentry's European region, so the error reports are processed inside the EU.
No personal data is sent with it: the send_default_pii option is switched off, so no IP address, no account details and no form contents are transmitted. We cannot rule out entirely that an individual error message contains personal data.
Legal basis: legitimate interest in a working and secure service (Art. 6 (1)(f) GDPR). Sentry privacy policy: https://sentry.io/privacy.
Server log files
The hosting provider automatically records standard access data (IP address, date and time, page requested, browser and operating system). This data is used to keep the service secure and running and is not combined with other data about you.
Legal basis: legitimate interest (Art. 6 (1)(f) GDPR).
Third parties your data reaches
Google (login and reCAPTCHA on forms), GitHub (login), Stripe (payments) and Hostinger (hosting). Each processes data under its own privacy policy. We share only what each service needs for its function.
Transfers to the United States
Google, GitHub and Stripe belong to groups headquartered in the United States, so data can reach that country. The transfer rests on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the standard contractual clauses under Art. 46 (2)(c) GDPR.
Even on those grounds, access by US authorities cannot be ruled out entirely. Fonts and every other design asset on this site are served from our own server, so simply opening a page sends nothing to a third party.
How long we keep data
Account and progress data are kept while your account exists. Purchase records and withdrawals are kept as long as tax and commercial law require. When you delete your account, we delete your personal data except records we must retain by law.
Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing. To exercise any of these, email us at contact@elman.group.
You also have the right to complain to a data protection supervisory authority - in Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.