PRIVACY POLICY AND PERSONAL DATA PROCESSING

Effective date: 22.08.2026

This Privacy Policy (hereinafter - "Policy") describes the procedure for collecting, using, storing, and disclosing information when using the website and purchasing the online course.

The Policy applies subject to the mandatory requirements of the legislation applicable to a specific user or the relevant data processing.

1. Data Controller

Personal Data Controller:

Olha Dudka

Email: balletik.lady@gmail.com

Correspondence address:

Studio 527, 5th Floor, 151 Ave. Jean-Paul II, Port-au-Prince, Haiti

Depending on the applicable legislation, Olha Dudka may act as a data controller, controller, or another person responsible for the relevant processing of personal data.

2. What Information May Be Collected

Depending on how the user interacts with the website and the Course, the following information may be processed:

2.1. Data Provided by the User

- first and last name;

- email address;

- phone number;

- WhatsApp data;

- data provided during registration or when placing an order;

- messages and requests sent to customer support;

- other information that the user voluntarily provides to the Controller.

2.2. Order Data

- information about the purchased Course;

- date and time of the order;

- order value;

- order identifier;

- payment status;

- information about refunds;

- information about requests and claims.

2.3. Course Usage Data

- the fact that access has been provided;

- date and time access was provided;

- account logins;

- opening and viewing of materials;

- technical events related to the use of the Course;

- information about the termination or restriction of access.

2.4. Technical Data

Depending on the website settings and the services used, the following may be collected automatically:

- IP address;

- device type;

- operating system;

- browser type and version;

- browser language;

- date and time of the visit;

- pages and materials with which the user interacted;

- source from which the user accessed the website;

- technical identifiers;

- cookies and similar technologies.

2.5. Payment Data

Payment data may be processed directly by the selected payment provider.

If the Controller does not store full bank card details, such data is not stored by the Controller.

The processing of payment information is also governed by the privacy policy of the relevant payment provider.

3. Sources of Information

Information may be received:

- directly from the user;

- automatically when using the website;

- from the payment provider;

- from the platform on which the Course is provided;

- from technical, analytical, and other services used to operate the website;

- from other lawful sources, if necessary for the performance of the agreement, ensuring security, or complying with the law.

4. Purposes for Which Data Is Used

Personal data may be used to the extent necessary for the following purposes:

4.1. Performance of the Agreement

- placing an order;

- processing payment;

- providing access to the Course;

- managing the account;

- technical support;

- providing the purchased digital content.

4.2. Administration

- processing requests;

- processing refunds;

- reviewing claims;

- contacting the user regarding the order;

- maintaining necessary records.

4.3. Security and Prevention of Abuse

- detecting fraudulent transactions;

- preventing unauthorized access;

- detecting the transfer of accounts to third parties;

- preventing unlawful copying or distribution of materials;

- protecting the website, platform, users, and the rights of the Controller.

4.4. Confirmation of Legally Significant Actions

Data may be used to confirm:

- placing an order;

- payment;

- acceptance of the terms of the Agreement;

- provision of access;

- use of the Course;

- submission of requests;

- other user actions.

4.5. Compliance with the Law

Data may be processed to fulfill the Controller's legal obligations, respond to lawful requests from government authorities, and protect the lawful rights and interests of the Controller.

4.6. Analytics and Website Improvement

Where the relevant tools are available, data may be used for:

- analyzing the operation of the website;

- analyzing the use of the Course;

- identifying technical problems;

- improving the user interface;

- optimizing the operation of the website and digital services.

4.7. Marketing Communications

If permitted by applicable law and where there is an appropriate legal basis, data may be used to send informational or marketing communications.

The user may opt out of receiving marketing communications using the provided method.

5. Legal Bases for Processing

Depending on the applicable legislation, data processing may be carried out on the basis of one or more of the following grounds:

- the necessity to enter into and perform the agreement;

- the user's consent;

- compliance with legal obligations;

- protection of the legitimate interests of the Controller or third parties;

- prevention of fraud and ensuring security;

- other grounds provided for by applicable law.

If the user's consent is required for specific processing, such consent is requested in the prescribed manner.

6. Transfer of Data to Third Parties

The Controller does not sell users' personal data.

Personal data may be transferred or access to it may be provided to the following categories of recipients to the extent necessary:

- payment providers;

- banks and financial organizations to the extent necessary;

- platforms and services providing the Course;

- hosting providers;

- email services;

- customer support services;

- analytics services;

- security and fraud prevention services;

- IT contractors;

- legal, accounting, and other professional consultants;

- government authorities and law enforcement agencies when disclosure is required or permitted by law;

- other service providers if their involvement is necessary for the operation of the website or performance of the agreement.

Such persons may process data only within the scope of the relevant purposes and their contractual or legal authority.

7. Third-Party Services

The website and Course may use third-party technical services.

Such services may include:

- payment systems;

- online course platforms;

- hosting;

- email services;

- analytics systems;

- fraud protection systems;

- authorization systems;

- communication systems;

- other technical services.

The use of third-party services may result in the processing of data by the respective providers independently of the Controller.

Users are advised to review the privacy policies of the relevant services.

8. International Transfer and Processing of Data

The user understands that the Controller and the service providers used by the Controller may be located in different countries.

Accordingly, personal data may be transferred, stored, or processed outside the user's country of residence, including in countries whose legislation may differ from the legislation of the user's country.

Such transfers are carried out to the extent permitted by applicable law.

If the legislation of a particular jurisdiction requires the use of special mechanisms for international data transfers, the Controller takes the measures provided for by law to the necessary extent.

9. Data Retention

The Controller stores personal data for no longer than is reasonably necessary for the purposes for which it was collected, taking into account:

- the term of the agreement;

- the need to provide access to the Course;

- processing of refunds and claims;

- tax and accounting requirements;

- limitation periods;

- the need to protect lawful rights and interests;

- legal requirements;

- prevention of fraud and abuse.

Certain information about orders, payments, consents, access, and other legally significant actions may be retained after the termination of use of the Course if necessary to comply with the law or protect the rights of the Controller.

10. Electronic Records and Evidence

The Controller has the right to retain electronic information related to the use of the website and the purchase of the Course, including:

- date and time of the order;

- payment information;

- order identifier;

- the fact of acceptance of the Agreement;

- the fact that consents were provided;

- date and time access was provided;

- date and time materials were opened;

- information about account login;

- technical data;

- requests and correspondence;

- information about refunds and chargebacks;

- information related to fraud prevention.

Such data may be used for:

- performance of the agreement;

- confirmation of legally significant actions;

- resolution of disputes;

- protection of the rights of the Controller;

- prevention of fraud;

- compliance with legal requirements.

11. Cookies and Similar Technologies

The website may use cookies, pixels, web beacons, local storage, and other similar technologies.

They may be used for:

- ensuring the operation of the website;

- authorization;

- saving settings;

- providing access to the Course;

- ensuring security;

- analyzing traffic;

- analyzing the use of the website;

- improving the operation of the website;

- measuring the effectiveness of marketing campaigns, if applicable.

Some cookies may be installed by third-party services.

If applicable law requires the user's prior consent for certain categories of cookies or similar technologies, such consent is requested in the prescribed manner.

12. Advertising and Analytics

If analytics, advertising, or tracking services are used on the website, they may receive certain technical data about the user's interaction with the website.

The use of such technologies is carried out in accordance with applicable law and, where necessary, on the basis of the user's prior consent.

The user may have the ability to restrict the relevant processing through browser settings, a cookie banner, or the tools of a specific service.

13. Data Security

The Controller takes reasonable technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, destruction, or other unlawful use.

However, no method of transmitting or storing data over the Internet can guarantee absolute security.

The Controller does not guarantee absolute protection of information against all possible threats, including attacks, failures of third-party services, and other circumstances beyond the Controller's reasonable control.

14. User Rights

Depending on the applicable legislation, the user may have the right to:

- access their personal data;

- request correction of inaccurate data;

- request deletion of data;

- request restriction of processing;

- object to certain types of processing;

- withdraw previously provided consent where processing is based on consent;

- request data portability if such a right is provided by law;

- opt out of marketing communications;

- file a complaint with a competent data protection authority;

- exercise other rights provided for by applicable law.

The scope and procedure for exercising such rights depend on the specific jurisdiction and the circumstances of the processing.

15. User Request for Access to or Deletion of Data

To submit a request, it is necessary to use:

balletik.lady@gmail.com

To protect the user's data, the Controller has the right to request additional information necessary for reasonable verification of the identity of the applicant.

The Controller has the right to refuse to fulfill a request or limit its fulfillment in the cases and to the extent provided for by applicable law.

In particular, certain data may be retained if its retention is necessary to fulfill a legal obligation, protect the rights of the Controller, prevent fraud, resolve a dispute, or fulfill other lawful purposes.

16. Withdrawal of Consent

If certain processing is carried out on the basis of the user's consent, the user has the right to withdraw such consent in the manner provided for by applicable law.

Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Withdrawal of consent does not necessarily result in the deletion of data if the Controller has another lawful basis for its continued storage or processing.

17. Children and Minors

The website and Course are not intended for independent use by persons who, under applicable law, do not have the right to independently enter into the relevant agreement.

If a minor obtains access to the Course with the consent or participation of a parent or legal representative, such parent or legal representative is responsible for providing such consent and for the minor's use of the Course to the extent provided by law.

The Controller does not knowingly seek to collect children's personal data in cases where such processing is prohibited by applicable law.

If a parent or legal representative believes that a minor has provided data in violation of applicable requirements, they may contact:

balletik.lady@gmail.com

18. Changes to the Policy

The Controller has the right to periodically amend this Policy.

The new version shall enter into force on the date specified therein, unless another procedure is required by applicable law.

Continued use of the website after the new version enters into force constitutes acknowledgment of the updated Policy only to the extent that such provision is permitted by applicable law.

If certain changes require separate notice to or consent from the user, the Controller takes the appropriate actions.

19. Applicable Law

This Policy applies subject to the mandatory requirements of the legislation applicable to the specific processing of personal data and the relevant user.

No provision of this Policy is intended to restrict any user rights that cannot be lawfully restricted.

If any provision of the Policy is found to be invalid or unenforceable in a particular jurisdiction, the remaining provisions shall remain in force.

20. Contacts

Olha Dudka

Email: balletik.lady@gmail.com

Correspondence address:

Studio 527, 5th Floor, 151 Ave. Jean-Paul II, Port-au-Prince, Haiti