Skip to main content

Privacy Policy

Privacy Policy

This page says what we know about you, why we know it, who else sees it, and how to make us stop. It names our actual suppliers rather than describing them in the abstract, because a policy you cannot check is not worth reading.

Last updated:
7 September 2026
In effect from:
7 September 2026

1. Who is responsible for your data

Alakademia decides what personal data is collected on alakademia.com and why, which makes us the data controller for it. You can reach us about anything on this page at info@alakademia.com.

We are a small operation and we do not have a separate data protection officer. Privacy requests go to the same address and are handled by the founder.

2. Which law applies

Two regimes apply to us at once, and we write to both rather than picking the convenient one.

  • Saudi Arabia's Personal Data Protection Law (PDPL), because most of our students are in Saudi Arabia and we collect their data there.
  • The EU General Data Protection Regulation (GDPR), because our servers are in Germany and some of our students live in the EU.

Where the two differ, we apply whichever gives you more.

3. What we collect

Grouped by why it exists, not by how it is stored.

  • Account — your name, email address, password (stored only as a cryptographic hash, never in readable form), preferred language, and any profile photo you upload.
  • Placement and assessment — your answers to the written placement quiz, your assessed CEFR level, and the notes an instructor makes during a spoken assessment.
  • Voice recordings — spoken assignments and oral assessments are recorded through your browser and stored so an instructor can mark them. We use them to teach and assess you, and for nothing else. We do not use voice data to identify you.
  • Learning — which courses you are enrolled in, your progress, quiz scores, assignment submissions, certificates earned, and attendance at live classes.
  • Live classes — your name and email are passed to Zoom so you can join, and Zoom returns a record of whether you attended and for how long.
  • Payment — the amount you transferred, the reference you quoted, the date, and the credit balance we hold for you. We never see or store your full bank account number or any card number.
  • Onboarding preferences — the answers you give when setting up your learning profile, which we use to recommend a starting level and course.
  • Support — the content of emails and contact-form messages you send us.
  • Technical — IP address, browser and device type, pages visited, and the time of each visit. This is collected for every visitor, including ones who never register.

4. Why we use it, and on what legal basis

  • To deliver the teaching you paid for — enrolment, access, marking, certificates, live class scheduling. Legal basis: performance of our contract with you.
  • To take payment and keep financial records. Legal basis: performance of our contract, and our legal obligation to keep accounting records.
  • To keep accounts secure — rate limiting, two-factor authentication, blocking attacks. Legal basis: our legitimate interest in a platform that is not overrun.
  • To answer you when you write to us. Legal basis: performance of our contract, or our legitimate interest in replying to people who ask us things.
  • To send you course news and offers by email. Legal basis: your consent, which you give by subscribing and withdraw with the unsubscribe link in every message. Emails about a course you are already enrolled in are not marketing and are sent on the contract basis.
  • To understand how the site is used. Legal basis: your consent.

We do not make decisions about you by automated means that have a legal or similarly significant effect. Your placement level is suggested by a scored quiz, and an instructor can and does override it.

5. Cookies and tracking

Some cookies are needed for the site to work at all: they keep you logged in, remember your language, and hold your basket. Those are set without asking, because without them there is no site.

One is not necessary and belongs to a third party. We name it, because that is the only useful way to list it.

  • Jetpack — site statistics provided by Automattic, which records page views and visitor counts.

You can clear cookies and block them in your browser settings at any time. Blocking the necessary ones will stop you being able to log in.

6. Who else receives your data

We do not sell personal data and we never will. These are the suppliers who process it on our behalf, what each one gets, and where they are.

  • Hetzner (Germany) — hosts the servers. All of our data sits there. Every student record passes through this supplier.
  • Zoom Video Communications (United States) — runs the live classes. Receives your name and email, returns attendance.
  • Bunny.net (Slovenia) — delivers course video and audio. Receives your IP address when you play a lesson.
  • Automattic (United States) — receives page-view statistics through Jetpack.
  • Google (United States) — if you choose to sign in with Google, Google confirms your identity to us and we receive your name and email address.
  • Our bank in Saudi Arabia — sees your transfer and the reference you quote, as the receiving bank.

We also disclose data where the law requires it, or to establish or defend a legal claim.

Email is sent from our own mail server, which we run ourselves. Your email address is not handed to a third-party bulk sending service.

7. Data leaving your country

Our servers are in Germany, so if you are in Saudi Arabia your data is stored outside the Kingdom. Some suppliers named above are in the United States.

For transfers out of the EU we rely on the European Commission's standard contractual clauses, or on an adequacy decision where one covers the recipient. For transfers out of Saudi Arabia we rely on the PDPL provisions permitting transfer where it is necessary to perform a contract with you.

8. How long we keep it

  • Account and learning records — for as long as your account is open, and for one year after you close it, so a returning student does not lose their progress and their certificates.
  • Voice recordings and assignment submissions — until one year after the course ends, then deleted.
  • Payment and credit records — seven years, because accounting law requires it. This is the one category we cannot delete on request while the period is running.
  • Attendance records — three years, so a certificate can be re-verified.
  • Support emails — three years.
  • Administrative activity logs — 30 days.
  • Marketing consent records — until you unsubscribe, then a minimal record that you did, so we do not email you again by accident.

9. How we protect it

  • Everything travels over encrypted connections. Passwords are stored only as hashes and cannot be read back, by us or by anyone.
  • Administrator and instructor accounts must use two-factor authentication.
  • Login attempts are rate limited and repeated failures are blocked at the network edge.
  • The financial ledger is append-only at the database level: rows recording money can be added but not silently edited or deleted, including by us.
  • Backups run daily.

No system is perfectly secure. If a breach happens that puts you at risk, we will tell you and the relevant regulator, without waiting to be asked.

10. Your rights

You have all of these under the GDPR, and PDPL gives Saudi residents the equivalent. You do not need a reason and you will not be charged.

  • See what we hold about you, and get a copy.
  • Correct anything wrong. You can fix most of it yourself on your account page.
  • Have it deleted, except records we are legally required to keep — which in practice means the payment records in section 8.
  • Get your data in a portable, machine-readable file.
  • Object to processing we do on the basis of legitimate interest.
  • Withdraw consent at any time, for marketing or for tracking. Withdrawing it does not undo what was already done with your agreement.
  • Ask us to restrict processing while a dispute about accuracy is sorted out.

Write to info@alakademia.com from your registered email address. We reply within 30 days. If we need longer because the request is complex, we will tell you why before the 30 days are up.

11. If you are not satisfied

Tell us first — most complaints are a misunderstanding we can fix the same week.

If we do not resolve it, you can complain to a regulator: in Saudi Arabia, the Saudi Data and Artificial Intelligence Authority (SDAIA); in the European Union, the data protection authority for the country you live in.

12. Children

Students under 16 must have a parent or guardian hold the account, and we deal with that adult. We do not knowingly collect data directly from a child under 16. If you believe we have, write to us and we will delete it.

13. Changes to this policy

When we change this policy the date at the top changes. If the change affects what we do with data we already hold, we email every registered student before it takes effect rather than relying on you to re-read the page.