This Privacy Policy explains how Ziqqle EOOD collects, uses, stores and protects personal data in connection with its website, checkout, online course, support and related marketing activities.

1. Who we are

The data controller is Ziqqle EOOD, a company registered in Bulgaria.

2. Scope of this policy

This policy applies when you visit our website, create an account, buy or access our online course, communicate with us, subscribe to updates, interact with our advertisements or otherwise use our digital products and services.

3. Personal data we may collect

Depending on how you interact with us, we may collect the following categories of personal data:

4. How we collect personal data

We may collect personal data directly from you, automatically through cookies and similar technologies, from service providers involved in checkout and course access, and from advertising, analytics, email, hosting or support tools that we use.

5. Why we process personal data and legal bases

Purpose Examples Legal basis
Providing the course and related services Account creation, access to digital content, support, service messages Performance of a contract or steps before entering into a contract
Payments, tax and accounting Billing records, invoices, VAT, refunds, fraud checks Contract, legal obligation and legitimate interest
Customer support Responding to questions, troubleshooting access, handling complaints Contract and legitimate interest
Website security and fraud prevention Security logs, abuse prevention, chargeback investigation Legitimate interest and legal obligation where applicable
Analytics and improvement Understanding traffic, improving content, fixing issues Consent where required; otherwise legitimate interest where permitted
Marketing and advertising Email marketing, remarketing, pixels, conversion tracking Consent where required; legitimate interest for limited direct marketing where permitted
Legal protection Record keeping, dispute handling, enforcement of Terms & Conditions Legitimate interest and legal obligation

6. Cookies, analytics and advertising technologies

We use necessary cookies to operate the website, checkout, consent tools, security functions and course access. With your consent, we may also use preference, analytics and marketing cookies, including tools such as Google Analytics, Microsoft Clarity and Meta Pixel. You can manage non-essential cookies through our Cookie Policy and cookie banner.

7. Email marketing

We may send marketing emails only where we have a valid legal basis to do so. You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting us at office@ziqqle.com. Service emails related to your purchase, account, access, security or legal notices may still be sent where necessary.

8. Payment providers and course platforms

Payments may be processed by Stripe. Course access may be delivered through Thinkific. These providers may process personal data as independent controllers or processors depending on their role, terms and applicable law.

9. Processors and service providers

We share personal data with the following providers. "Processor" means the provider acts only on our instructions. "Independent controller" means the provider decides its own purposes for part of the processing. "Joint controllers" means we and the provider decide certain purposes together.

Recipient What it is used for Role
Stripe Processing card payments, refunds, chargebacks and payment fraud prevention. Independent controller for payment processing, fraud prevention and its own regulatory obligations
Thinkific Hosting the course, creating your account and delivering access and course emails. Processor
Cloudflare Running the automated service that grants course access after a confirmed payment. Processor
Google Google Analytics (website statistics, with your consent) and Google Workspace / Google Sheets, where enquiry and order details are recorded. Processor
Meta Meta Pixel for advertising measurement and audiences, with your consent. Joint controllers with us for the collection and transmission of pixel data; Meta is an independent controller for its own later use
Microsoft Microsoft Clarity for heatmaps and session replays showing how visitors use the site, with your consent. Processor
Our hosting provider Serving this website and its server logs. Processor
Accountants, lawyers and auditors Bookkeeping, tax filing and legal advice in Bulgaria. Independent controllers under their own professional obligations

We require appropriate confidentiality, data protection and security commitments from these providers. We do not sell your personal data.

9a. Advertising audiences and automated analysis

Where you consent to marketing cookies, Meta may match your visit to a Meta account and include you in advertising audiences, including audiences of people similar to our visitors or customers. Where you consent to analytics cookies, Google Analytics produces aggregated statistics about how the website is used, and Microsoft Clarity records how you move through and interact with the page — such as mouse movement, scrolling and clicks — to produce heatmaps and session replays. Clarity is set to mask the text you type into fields, so it does not capture the contents of the checkout form.

We use this only for advertising and website measurement. We do not use it to make automated decisions that produce legal effects for you or similarly significantly affect you. Stripe carries out automated fraud scoring on payments as part of its own service; if a payment is declined for that reason, you can contact us and we will look into it.

You can withdraw consent at any time through the "Cookie settings" link at the bottom of this page.

9b. Why we ask for your phone number

The phone number field at checkout is mandatory. We ask for it so that we can reach you if there is a problem with your payment or with granting your course access, and because it helps us and Stripe verify that an order is genuine when a payment is queried or disputed.

Providing the number does not mean you agree to marketing calls or messages. Contact by phone, SMS or WhatsApp about the programme happens only if you tick the separate, optional checkbox at checkout, and you can withdraw that at any time by contacting us.

10. International transfers

Some of the providers listed in section 9 process personal data outside the European Economic Area, including in the United States and Canada.

Transfers from the EU/EEA. We rely on European Commission adequacy decisions where one covers the destination country — this includes Canada for commercial organisations, which covers Thinkific. For other transfers we rely on the European Commission's Standard Contractual Clauses together with a transfer risk assessment and the provider's technical safeguards.

Transfers from the United Kingdom. UK transfers are covered separately. We rely on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement, or the UK Addendum to the Standard Contractual Clauses, together with a transfer risk assessment.

You can ask us for more detail about the safeguards used for a particular provider by contacting office@ziqqle.com.

11. Data retention

We keep personal data only for as long as necessary for the purposes described in this policy. Our retention periods are:

Data How long we keep it Why
Account and course access data For as long as your account exists, then 3 years To support you while you have access, and to defend legal claims afterwards
Billing, tax and accounting records 10 years from the end of the financial year Required by Bulgarian accounting and tax law
Enquiry form submissions that did not lead to a purchase 24 months from submission To follow up on your enquiry; deleted after that
Support messages 3 years after the matter is closed To handle follow-up questions and disputes
Consent records (terms, immediate access, marketing, phone contact) While the consent applies, then 3 years after it is withdrawn or the purchase ends To prove that consent was validly obtained, as data protection and anti-spam rules require
Security and server logs 12 months Security monitoring and fraud prevention

We may keep data for longer where we are required to do so by law, or where it is needed for an ongoing investigation, dispute or legal claim. When a period ends, we delete the data or anonymise it so that it can no longer identify you.

12. Security

We use reasonable technical and organisational measures to protect personal data, including access controls, secure service providers, encryption where appropriate, backups, monitoring and internal procedures. No online service is completely secure, and you should protect your account credentials and devices.

13. Your rights

Subject to applicable law, you may have the right to:

To exercise your rights, contact us at office@ziqqle.com. We may need to verify your identity before responding.

13a. If you are in the United Kingdom

If you are in the United Kingdom, your personal data is protected by the UK GDPR and the Data Protection Act 2018, and the rights listed in section 13 apply to you.

If you are not satisfied with how we have handled your personal data, you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. You may also complain to the data protection authority in Bulgaria, where we are established.

13b. If you are in Canada

If you are in Canada, your personal data is protected by the Personal Information Protection and Electronic Documents Act (PIPEDA) or, in some provinces, by equivalent provincial privacy legislation.

You may ask us what personal information we hold about you, how it is used and to whom it has been disclosed, and you may ask us to correct it. We rely on your consent to collect and use your personal information for the purposes described in this policy, and you may withdraw that consent at any time, subject to legal and contractual limits — for example, we must keep payment records for tax purposes even after you withdraw consent.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial privacy commissioner where one has jurisdiction.

Commercial emails we send to recipients in Canada are subject to Canada's Anti-Spam Legislation (CASL). We send marketing emails only where you have given consent, and every marketing email contains our identity, contact details and a working unsubscribe link.

14. Children's privacy

Our course and services are intended for adults aged 18 or older. We do not knowingly sell courses to children or knowingly collect personal data from children for these services.

15. Third-party links and services

Our website, course or emails may contain links to third-party websites, platforms, social networks or payment services. Their own privacy notices apply to their processing activities.

16. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will be posted on this page with the updated date.

17. Contact

For privacy questions or requests, contact us at office@ziqqle.com.