Legal
Privacy Policy
This Privacy Policy explains how Ziqqle EOOD collects, uses, stores and protects personal data in connection with its website, checkout, online course, support and related marketing activities.
1. Who we are
The data controller is Ziqqle EOOD, a company registered in Bulgaria.
- Company name: Ziqqle EOOD
- EIK/UIC: 208725814
- VAT number: BG208725814
- Registered address: 2700 Bulgaria, Blagoevgrad, 11 Nikolay Petrini St., floor 4, apt. 7
- Contact email: office@ziqqle.com
2. Scope of this policy
This policy applies when you visit our website, create an account, buy or access our online course, communicate with us, subscribe to updates, interact with our advertisements or otherwise use our digital products and services.
3. Personal data we may collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact data: name, email address, country, language, account details and communication details.
- Billing and transaction data: billing details, payment status, invoices, purchase history, refund status, chargeback status and tax-related information. Payment card data is normally processed by Stripe, not by us directly.
- Course access data: course enrolment, access status, lessons viewed, progress, support requests, technical logs and platform activity from Thinkific.
- Support and communication data: messages, support tickets, feedback, complaints, survey responses and related attachments.
- Marketing data: newsletter preferences, campaign source, ad interactions, consent records, unsubscribe status and similar marketing information.
- Technical and usage data: IP address, device data, browser type, operating system, pages visited, approximate location, cookie identifiers, analytics events and security logs.
- User submissions: reviews, testimonials, comments, case studies, photos, screenshots, social media handles or other content you voluntarily submit to us.
4. How we collect personal data
We may collect personal data directly from you, automatically through cookies and similar technologies, from service providers involved in checkout and course access, and from advertising, analytics, email, hosting or support tools that we use.
5. Why we process personal data and legal bases
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the course and related services | Account creation, access to digital content, support, service messages | Performance of a contract or steps before entering into a contract |
| Payments, tax and accounting | Billing records, invoices, VAT, refunds, fraud checks | Contract, legal obligation and legitimate interest |
| Customer support | Responding to questions, troubleshooting access, handling complaints | Contract and legitimate interest |
| Website security and fraud prevention | Security logs, abuse prevention, chargeback investigation | Legitimate interest and legal obligation where applicable |
| Analytics and improvement | Understanding traffic, improving content, fixing issues | Consent where required; otherwise legitimate interest where permitted |
| Marketing and advertising | Email marketing, remarketing, pixels, conversion tracking | Consent where required; legitimate interest for limited direct marketing where permitted |
| Legal protection | Record keeping, dispute handling, enforcement of Terms & Conditions | Legitimate interest and legal obligation |
6. Cookies, analytics and advertising technologies
We use necessary cookies to operate the website, checkout, consent tools, security functions and course access. With your consent, we may also use preference, analytics and marketing cookies, including tools such as Google Analytics, Microsoft Clarity and Meta Pixel. You can manage non-essential cookies through our Cookie Policy and cookie banner.
7. Email marketing
We may send marketing emails only where we have a valid legal basis to do so. You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting us at office@ziqqle.com. Service emails related to your purchase, account, access, security or legal notices may still be sent where necessary.
8. Payment providers and course platforms
Payments may be processed by Stripe. Course access may be delivered through Thinkific. These providers may process personal data as independent controllers or processors depending on their role, terms and applicable law.
9. Processors and service providers
We share personal data with the following providers. "Processor" means the provider acts only on our instructions. "Independent controller" means the provider decides its own purposes for part of the processing. "Joint controllers" means we and the provider decide certain purposes together.
| Recipient | What it is used for | Role |
|---|---|---|
| Stripe | Processing card payments, refunds, chargebacks and payment fraud prevention. | Independent controller for payment processing, fraud prevention and its own regulatory obligations |
| Thinkific | Hosting the course, creating your account and delivering access and course emails. | Processor |
| Cloudflare | Running the automated service that grants course access after a confirmed payment. | Processor |
| Google Analytics (website statistics, with your consent) and Google Workspace / Google Sheets, where enquiry and order details are recorded. | Processor | |
| Meta | Meta Pixel for advertising measurement and audiences, with your consent. | Joint controllers with us for the collection and transmission of pixel data; Meta is an independent controller for its own later use |
| Microsoft | Microsoft Clarity for heatmaps and session replays showing how visitors use the site, with your consent. | Processor |
| Our hosting provider | Serving this website and its server logs. | Processor |
| Accountants, lawyers and auditors | Bookkeeping, tax filing and legal advice in Bulgaria. | Independent controllers under their own professional obligations |
We require appropriate confidentiality, data protection and security commitments from these providers. We do not sell your personal data.
9a. Advertising audiences and automated analysis
Where you consent to marketing cookies, Meta may match your visit to a Meta account and include you in advertising audiences, including audiences of people similar to our visitors or customers. Where you consent to analytics cookies, Google Analytics produces aggregated statistics about how the website is used, and Microsoft Clarity records how you move through and interact with the page — such as mouse movement, scrolling and clicks — to produce heatmaps and session replays. Clarity is set to mask the text you type into fields, so it does not capture the contents of the checkout form.
We use this only for advertising and website measurement. We do not use it to make automated decisions that produce legal effects for you or similarly significantly affect you. Stripe carries out automated fraud scoring on payments as part of its own service; if a payment is declined for that reason, you can contact us and we will look into it.
You can withdraw consent at any time through the "Cookie settings" link at the bottom of this page.
9b. Why we ask for your phone number
The phone number field at checkout is mandatory. We ask for it so that we can reach you if there is a problem with your payment or with granting your course access, and because it helps us and Stripe verify that an order is genuine when a payment is queried or disputed.
Providing the number does not mean you agree to marketing calls or messages. Contact by phone, SMS or WhatsApp about the programme happens only if you tick the separate, optional checkbox at checkout, and you can withdraw that at any time by contacting us.
10. International transfers
Some of the providers listed in section 9 process personal data outside the European Economic Area, including in the United States and Canada.
Transfers from the EU/EEA. We rely on European Commission adequacy decisions where one covers the destination country — this includes Canada for commercial organisations, which covers Thinkific. For other transfers we rely on the European Commission's Standard Contractual Clauses together with a transfer risk assessment and the provider's technical safeguards.
Transfers from the United Kingdom. UK transfers are covered separately. We rely on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement, or the UK Addendum to the Standard Contractual Clauses, together with a transfer risk assessment.
You can ask us for more detail about the safeguards used for a particular provider by contacting office@ziqqle.com.
11. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy. Our retention periods are:
| Data | How long we keep it | Why |
|---|---|---|
| Account and course access data | For as long as your account exists, then 3 years | To support you while you have access, and to defend legal claims afterwards |
| Billing, tax and accounting records | 10 years from the end of the financial year | Required by Bulgarian accounting and tax law |
| Enquiry form submissions that did not lead to a purchase | 24 months from submission | To follow up on your enquiry; deleted after that |
| Support messages | 3 years after the matter is closed | To handle follow-up questions and disputes |
| Consent records (terms, immediate access, marketing, phone contact) | While the consent applies, then 3 years after it is withdrawn or the purchase ends | To prove that consent was validly obtained, as data protection and anti-spam rules require |
| Security and server logs | 12 months | Security monitoring and fraud prevention |
We may keep data for longer where we are required to do so by law, or where it is needed for an ongoing investigation, dispute or legal claim. When a period ends, we delete the data or anonymise it so that it can no longer identify you.
12. Security
We use reasonable technical and organisational measures to protect personal data, including access controls, secure service providers, encryption where appropriate, backups, monitoring and internal procedures. No online service is completely secure, and you should protect your account credentials and devices.
13. Your rights
Subject to applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- request data portability;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent;
- object to direct marketing;
- lodge a complaint with a competent data protection authority.
To exercise your rights, contact us at office@ziqqle.com. We may need to verify your identity before responding.
13a. If you are in the United Kingdom
If you are in the United Kingdom, your personal data is protected by the UK GDPR and the Data Protection Act 2018, and the rights listed in section 13 apply to you.
If you are not satisfied with how we have handled your personal data, you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. You may also complain to the data protection authority in Bulgaria, where we are established.
13b. If you are in Canada
If you are in Canada, your personal data is protected by the Personal Information Protection and Electronic Documents Act (PIPEDA) or, in some provinces, by equivalent provincial privacy legislation.
You may ask us what personal information we hold about you, how it is used and to whom it has been disclosed, and you may ask us to correct it. We rely on your consent to collect and use your personal information for the purposes described in this policy, and you may withdraw that consent at any time, subject to legal and contractual limits — for example, we must keep payment records for tax purposes even after you withdraw consent.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial privacy commissioner where one has jurisdiction.
Commercial emails we send to recipients in Canada are subject to Canada's Anti-Spam Legislation (CASL). We send marketing emails only where you have given consent, and every marketing email contains our identity, contact details and a working unsubscribe link.
14. Children's privacy
Our course and services are intended for adults aged 18 or older. We do not knowingly sell courses to children or knowingly collect personal data from children for these services.
15. Third-party links and services
Our website, course or emails may contain links to third-party websites, platforms, social networks or payment services. Their own privacy notices apply to their processing activities.
16. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be posted on this page with the updated date.
17. Contact
For privacy questions or requests, contact us at office@ziqqle.com.