KURSEonline
Courses Business Trending Calendar
Log in Sign up

Privacy Policy

This translation is provided for information purposes only. The German version is legally binding. Go to the German version

As of: February 18, 2026

1. Data Controller

Digitale Projekte RF GmbH
Franzensdorf 55, 2301 Groß-Enzersdorf, Austria
Commercial Register: FN 668519 t
Email: kiara@digitaleprojekte.at
Website: kurseonline.at

Line of Business: Development and operation of websites for online courses and shops, development and sale of AI-supported software.

Responsible for the processing of personal data on the KURSEonline platform within the meaning of the General Data Protection Regulation (GDPR).

2. Principles of Data Processing

We process personal data exclusively within the scope of legal provisions (GDPR, DSG, TKG 2021). Data is only passed on to third parties if it is strictly necessary for the fulfillment of the contract – in particular for payment processing via Stripe. Beyond this, we do not pass on any personal data to third parties.

3. Data We Collect

3.1 Registration and User Account

Email address, first and last name. Optional: profile picture, billing address, phone number, company name.

Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).

3.2 Usage Data

Learning progress, course enrollments, quiz results, and certificates.

Legal basis: Art. 6(1)(b) GDPR.

3.3 Payment Data

For paid courses, payment information is processed exclusively by Stripe. We do not store payment method details ourselves – only a reference ID and the invoice amount.

Legal basis: Art. 6(1)(b) GDPR.

3.4 Session Data

A technically required session cookie (ko_session) containing a randomly generated session ID, which is automatically deleted after a maximum of 5 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

4. Third-Party Providers and Data Processors (Agreements pursuant to Art. 28 GDPR)

4.1 Stripe – Payment Processing

Stripe Payments Europe, Ltd., Ireland.
Purpose: Handling of payments and invoicing.
Data transferred: Email address, name, billing address, Stripe customer ID.
Legal basis: Art. 6(1)(b) GDPR.
Storage duration: 7 years under Austrian tax laws.

4.2 Brevo – Transactional Emails

Sendinblue GmbH, Germany.
Purpose: Sending system emails (login links, confirmations).
Data transferred: Recipient's email address.
Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.
No marketing use.

4.3 Bunny.net – Video Streaming and Hosting

BunnyWay d.o.o., Slovenia (EU).
Purpose: Hosting of course videos and PDFs.
Data transferred: IP address (technical requirement).
Legal basis: Art. 6(1)(f) GDPR.
Servers located in the EU.

4.4 IONOS – Server Hosting

IONOS SE, Germany.
Purpose: Hosting the application and database.
All data is stored on IONOS servers in Germany (EU).
Legal basis: Art. 6(1)(f) and Art. 28 GDPR.

5. No Disclosure to Third Parties for Marketing Purposes

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

6. Cookies

We exclusively use one technically necessary session cookie: ko_session for authentication and session management (max. duration 5 days). According to § 165(3) TKG 2021, consent is not required. No tracking or marketing cookies are used.

7. Your Rights

You have the right to: Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction of processing (Art. 18), Data portability (Art. 20), and Objection (Art. 21).

Contact: kiara@digitaleprojekte.at.

8. Storage Duration

User account: Until account deletion.
Payment data: 7 years pursuant to § 132 BAO.
Session data: Max. 5 days.
Learning progress: Until account deletion.

9. Data Security

We employ TLS/HTTPS encryption, HttpOnly cookies, passwordless login (Magic Links), and regular security updates.

10. Data Transfer to Third Countries

Stripe processes data within the EU; any transfer to the USA is covered by the EU-U.S. Data Privacy Framework. All other processors (Brevo, Bunny.net, IONOS) process data exclusively within the EU.

11. Right to Lodge a Complaint

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna
Email: dsb@dsb.gv.at
Website: dsb.gv.at

12. Changes to this Privacy Policy

We reserve the right to update this privacy policy. The current version is always available on this page.

KURSEonline
FAQ Legal notice Privacy Terms and Conditions