Privacy
Policy.
We take your privacy seriously. Learn how we collect, use, and protect your personal information.
Privacy and data protection
Version 1.1 · Effective date: 8 October 2026
1. Scope of this policy and the data controller
This policy explains how ALA Core UG (haftungsbeschränkt), the operator of the ALA Academy Platform, handles the data of visitors, learners and programme applicants. It covers registration, purchases, live learning, session replays and support. Provisions concerning standalone recorded courses, subscriptions or artificial intelligence tools apply only when those services are offered and disclosed.
We collect data for a specific purpose, limit it to what is necessary, keep it accurate, protect it, and delete it when there is no longer a legitimate need to retain it. We do not sell learners' data or give advertisers independent access to it. Reading this policy or accepting the learning terms is not blanket consent to marketing, photography or filming, or any optional processing.
Legal operator and contact details
| Item | Details |
|---|---|
| Commercial name of the Platform | ALA Academy |
| Service provider and data controller | ALA Core UG (haftungsbeschränkt) |
| Correspondence address | Flughafenstraße 62, 22415 Hamburg, Germany |
| Platform website | academy.alacore.net |
| Legal representative shown in the trade registration document | Louay Chalabi |
| Trade registration reference (Gewerbeamt) | IGN 01385110 |
| Trade registration authority | Freie und Hansestadt Hamburg – Bezirksamt Hamburg-Nord |
| Business contact telephone | +49 176 21812212 |
| Support, complaints, cancellation, refunds and withdrawal | [email protected] |
| Privacy enquiries and requests | [email protected] |
| Effective date | 8 October 2026 |
Engaging an instructor or a technical service provider does not change our responsibility for our obligations to the learner.
2. Data, its sources and the purposes of processing
We identify mandatory fields when collecting data and explain the consequences of not providing it; without essential information it may not be possible to create an account or complete a purchase. Refusing to provide optional data will not result in denial of the core service. We do not request sensitive data or identity documents merely for general registration.
| Data | Source | Purpose | Legal basis (where the GDPR applies) |
|---|---|---|---|
| Name, contact details and account information | Provided by you when registering or updating your account | Creating the account, completing registration and essential communications | Art. 6(1)(b) GDPR: performance of a contract or steps you request before entering into one |
| Course, attendance, assignments, results and certificate | Your participation, the learning system and the instructor | Providing education, assessment and the agreed verification service | Art. 6(1)(b), to the extent necessary to perform the service |
| Order, payment, refund and invoice information | You and the payment provider | Completing the transaction, accounting and compliance with legal obligations | Art. 6(1)(b) for completing the transaction; Art. 6(1)(c) for retention required by law |
| Enquiries, cancellation requests and support requests | Your correspondence and our support team | Responding, resolving service issues and carrying out the request | Art. 6(1)(b); and Art. 6(1)(f) where necessary to establish or defend a claim |
| Connection address, login and error logs, necessary fraud indicators | The technical operation of the Platform | Protecting accounts, investigating incidents and preventing fraud | Art. 6(1)(f): legitimate interests, following a necessity and balancing assessment |
| Your image or voice in a recording | Your optional participation in a recorded session | Providing replays within the disclosed scope | Art. 6(1)(a): separate, optional consent that may be withdrawn |
| Marketing preferences and optional cookies | Your explicit choices | Sending offers or running disclosed optional analytics | Art. 6(1)(a); rules on access to your device (TDDDG §25) also apply |
| Records of consent and requests to exercise rights | Your choices and the requests you submit | Demonstrating consent and fulfilling obligations relating to your rights | Art. 6(1)(c) where the GDPR requires this; Art. 6(1)(f) where necessary to defend claims |
If we obtain your data from an organisation that nominates you for training, or from a parent or guardian in a programme intended for minors, we explain the source, data, purpose and legal basis within the required period, or upon the first communication or disclosure if earlier. We use special-category data about health or disability only for a necessary, disclosed purpose and where an appropriate legal condition is met, with restricted access.
3. Payments and communications
The payment page identifies the transaction provider and how payment information is entered, and the vendor table below specifies which data reaches the Platform. We do not ask you to send your full card number or security code by email or chat. Do not include this information in a refund request; the order reference and the information needed to identify the transaction are sufficient, and we request further information only when necessary.
Messages about schedules, access, invoices, security and refunds form part of delivering the service. Marketing offers are optional and require separate consent. You can stop them using the unsubscribe method in the message or through the Contact page, without affecting your learning. We do not add you to a group that reveals your phone number or other data to others without explaining this and providing a suitable alternative for educational communications.
4. Recorded sessions and participant privacy
Before and during a session we explain whether it is being recorded, what will appear in the recording, who can view it, and how long it will remain available. We focus recordings on the instructor and the content and do not include a learner's image or voice without separate consent. You may learn with your camera switched off and ask questions in writing in a way that does not add your identity to the recording; declining to appear does not affect your right to education or assessment.
Replays are restricted to authorised learners, the instructor and staff whose duties require access. Recordings that include participants must not be republished, or downloaded and shared outside the permitted scope. Consent to recording does not cover advertising or public publication; each requires separate permission. If you withdraw consent to appear, we stop future use based on that consent and delete the relevant portion or conceal your identity, without affecting educational rights that can be fulfilled through a suitable alternative.
5. Learners' work and artificial intelligence
You retain the rights to your work, and your permission to the Platform is limited to storing it, displaying it to those who need access, assessing it and providing the agreed service. We do not publish projects in a public showcase or advertisement without additional permission. This policy does not grant an unrestricted licence to train general-purpose artificial intelligence models on your data or work.
If we make an artificial intelligence tool available, we explain the provider, the data sent, the purpose, retention and international transfers before you use it. We minimise the data and select controls that prevent its use outside the approved purpose. If the tool is optional, a suitable alternative is available without requiring additional consent to obtain the core educational service. A decision with a significant impact, such as withholding a certificate or ending enrolment, will not be made solely on the basis of automated processing; a qualified person reviews the decision and considers your objection.
6. Minors
As a general rule the services are intended for people aged 18 or over. Anyone younger is accepted only into a programme expressly advertised as suitable for their age, under a clear contractual arrangement with a parent, guardian or other legal representative. We explain the minor's data, the purposes for which it is used and the required consent process in age-appropriate language, and we do not assume that a guardian's consent authorises every form of processing. We use the minimum age-related information necessary and do not target minors with marketing based on tracking their behaviour.
8. Retention periods and deletion
We apply the following periods separately to each category; retaining a necessary invoice does not justify keeping all assignments or recordings. When the purpose ends, we delete the data or convert it into information that cannot identify you. Any extension due to a dispute or legal obligation is limited to the necessary data, with restrictions on its use and reviews of whether the reason continues to apply.
| Category | Period or starting point | What happens at the end |
|---|---|---|
| Account | While active; after 24 months of inactivity we send a notice 30 calendar days before closure, taking account of any agreed ongoing service | The account is closed and data no longer needed is deleted; or the account is retained if you ask to continue |
| Learning data, assignments and assessments | 24 months from the end of the programme | Deletion, with the limited certificate record and outstanding claims handled separately |
| Session replays | Throughout the programme and for 90 calendar days after it ends, or a longer period agreed before purchase | Recordings that reveal learners' identities are deleted within 30 calendar days after availability ends |
| Raw security logs | 90 calendar days from creation of the log | Deletion; only what is necessary for a specific incident is isolated and retained until it is resolved |
| Complaint and contract settlement files | 3 years from the end of the year in which the case is closed, unless a longer requirement applies to the material | Deletion, unless specific retention is required by law or for a documented claim |
| Evidence of marketing consent and its withdrawal | As long as consent is relied upon; then 3 years from the last message or withdrawal, whichever is later, subject to any longer statutory minimum | Deletion; during retention, use is restricted to evidential purposes |
| Invoices, books and tax records | Invoices and accounting documents: 8 years; books and financial statements: 10 years; commercial correspondence: 6 years, according to the record's classification (HGB §257, AO §147, UStG §14b) | Deletion once the period and any legal proceedings requiring continued retention have ended |
| Certificate verification | 5 years from issue: name, certificate number, programme, date and status only | Deletion or renewal of the service through your clear choice, without automatic extension |
| Backups | A cycle of no more than 90 calendar days | Deleted data is removed from backups within the cycle and kept separate from ordinary use in the meantime |
We carry out a deletion request that meets the applicable conditions without undue delay and within 30 calendar days of receipt as an operational maximum, or within a shorter statutory deadline where applicable. If the law permits an extension because of complexity or the number of requests, we notify you of the reasons within the required period. Backups complete their specified cycle, and deletion instructions are reapplied if a backup is restored.
The certificate verification service does not allow public searches by a learner's name. If a verification code is made available, it is optional and displays only the minimum data necessary. You may request that visible verification be disabled or object to retention of the verification record, without affecting the validity of a properly issued certificate.
Retention periods for German records begin at the end of the calendar year in which the event specified by law occurs, such as issuing an invoice, creating an accounting document or sending or receiving correspondence. The period may be extended because of tax proceedings. Deleting the account does not change the statutory starting point. After you opt out of marketing we may keep a limited suppression record (contact detail and opt-out status) to prevent you being added again by mistake; it is kept separate from advertising lists and is not used to send offers.
9. Security and incidents
We apply technical and organisational measures proportionate to the risks, including access controls, reviews of staff permissions, and management of vendors, deletion and incidents. If a breach occurs, we assess its impact, take measures to mitigate it, and notify the competent authority and affected individuals where required and within the statutory deadlines. Please tell us promptly if you suspect unauthorised access to your account.
10. Your rights and how to submit a request
- Request information about your data and a copy of it, and have inaccurate data corrected or incomplete data completed.
- Request deletion or restriction of processing where the conditions are met, and obtain portable data in a structured format where that right applies.
- Withdraw consent easily without affecting the lawfulness of earlier processing; object to processing based on legitimate interests for reasons relating to your situation; object to direct marketing without giving a reason.
- Request human intervention and review of an automated decision with a significant impact, and lodge a complaint with the competent authority.
Send your request to [email protected], explaining what you want and providing the contact details associated with your account. No special form or copy of an identity document is automatically required; we request proportionate additional verification only where there are reasonable doubts. We respond without undue delay and within one month of receipt where the GDPR applies, or within a shorter mandatory period. The deadline is extended only as far as permitted, by no more than two additional months, and we inform you of the reasons within the first month.
Exercising your rights is free of charge as a general rule. We explain the reason for any partial refusal or legal exception and how to lodge a complaint. Deleting an account does not cancel a refund request or an existing financial entitlement. If you object to processing based on legitimate interests, we stop it unless we demonstrate compelling legitimate grounds that override your rights or a need related to a legal claim, and we inform you of the outcome.
You may complain directly, without waiting for an internal process, to the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI): datenschutz-hamburg.de. You may also contact another competent supervisory authority, including the Egyptian Personal Data Protection Center where its jurisdiction applies: pdpc.gov.eg.
11. Policy updates
We display the effective date and version number and explain material changes a reasonable time before applying them. We do not repurpose earlier consent for a new purpose it did not cover. If a change requires new consent, we request it separately and preserve your accrued rights. You may request a copy of the policy that applied when you registered.
Cookie policy
Request forms
The following forms are optional aids. You may submit a clear request through any available contact method, and acceptance of your request does not depend on completing fields we do not need. Where necessary we ask for the minimum information needed to identify the account or transaction and protect your data, without requesting your password, verification code or full payment-card details.
Privacy request form
Send to [email protected]. Your name and a safe contact method for our response: __________.
Email address associated with your account, or sufficient information to identify your relationship with the platform: __________.
The right you wish to exercise (access, rectification, erasure, restriction, objection, data portability or withdrawal of consent): __________.
The relevant data or period, if you wish to specify it: __________.
Details that may help us understand your request, optional: __________.
Date of the request: __________. Do not send an identity document unless we request proportionate verification for a specific reason.
Legal references
- [1] Data protection principles and transparency. European Commission guidance on GDPR principles, required information, data necessity and retention.
- [2] Data subjects' rights. European Data Protection Board guidance on individual rights, response periods and conditions.
- [3] Obligations of organisations processing personal data. European Commission guidance on notification, data protection, incident handling and processing obligations.
- [4] Personal data protection in Egypt. Egyptian Personal Data Protection Center: Law No. 151 of 2020, Executive Regulations No. 816 of 2025, where applicable.
- [5] Cookies and access to a device. German Telecommunications Digital Services Data Protection Act (TDDDG), section 25.
- [6] Right of withdrawal and its basic period. German Civil Code (BGB), section 355.
- [7] Withdrawal for services and digital content. BGB section 356, particularly subsections 5 and 6.
- [8] Effects of withdrawal and reimbursement. BGB section 357.
- [9] Value of services supplied before withdrawal. BGB section 357a, including the rule for digital content.
- [10] Online withdrawal function. BGB section 356a.
- [11] Service provider information. German Digital Services Act (DDG), section 5.
- [12] Pre-contractual information. EGBGB Article 246a, section 1, including information for distance contracts.
- [13] Consumer rights and services in Egypt. Egyptian Consumer Protection Law No. 181 of 2018, particularly Articles 25, 28 and 37–41.
- [14] Data protection complaints in Hamburg. Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).
- [15] Consumer complaints in Egypt. Egyptian Consumer Protection Agency (cpa.gov.eg).
- [16] Consumer dispute resolution. German Consumer Dispute Resolution Act (VSBG), sections 36 and 37.
- [17] Retention of commercial and tax records. German Commercial Code (HGB) §257; Fiscal Code (AO) §147; VAT Act (UStG) §14b.
Let's talk.
We're here to help.
Have questions about how we handle your data? Reach out to our team and we'll be happy to clarify.