Skip to content

Privacy policy

Version of August 27, 2026

This document explains which of your data we collect, why we need it, who we pass it to and what you can do about it. We sell online courses (video lessons) on design and web development, and we need the data above all in order to give you access to the materials you have paid for.

The document is written with the requirements of the EU General Data Protection Regulation (GDPR) in mind, since some of our buyers live in the European Union.

Who is responsible for your data

The data controller is Forma, a project registered in Moldova. For any question about data, write to vulpeanat@gmail.com. The controller's registration details will be published here before payments are accepted.

What data we collect and why

We do not collect or store your card details. Payment happens entirely on the payment provider's side; only the fact of a successful payment and minimal transaction data come back to us.

On what basis we process data

Who we pass data to

We do not sell your data. We pass it only to contractors who process data on our instructions and are bound to us by a data processing agreement:

Besides that, we may disclose data to an accountant or an auditor, and to state authorities — but only where the law requires it.

Transfers of data outside the EU

We are in Moldova, and some of our contractors are in other countries, including the USA. This means that data of EU residents may leave the European Economic Area. In such cases we rely on European Commission adequacy decisions or on the EU Standard Contractual Clauses. On request to vulpeanat@gmail.com we will tell you which mechanism applies to a particular contractor.

How long we keep data

Your rights

If the GDPR applies to you, you can:

To exercise a right, write to vulpeanat@gmail.com from the address the account is registered to. We reply within one month; if the request is complex we may extend the period and will tell you so. The service is free, but for clearly unfounded or repetitive requests we may charge a reasonable fee.

If you believe we are processing data incorrectly, you can lodge a complaint with a supervisory authority for data protection — in the country where you live, where you work or where you believe the breach took place. We would be grateful if you wrote to us first: the question is often resolved faster that way.

Cookies and analytics

We use two kinds of cookies. Necessary ones keep you signed in after you follow the link, remember the cart and protect forms; without them the site does not work, and they do not require consent. Analytics ones help us understand how many people visit the pages and where they abandon their learning; they are set only with your consent, which you give in the banner on your first visit and can change later. Cookie settings can also be changed in your browser, but then some functions of the site may break.

Security

We transmit data over HTTPS, limit access to the database to those who need it for their work, choose contractors with security measures of their own and make backups. Signing in by one-time link removes the risks associated with passwords, but it means that access to your mailbox = access to your account — look after your mailbox. There is no absolute security on the internet; if a breach does affect your data and creates a serious risk for you, we will notify you and the supervisory authority within the periods set by the GDPR.

Children

Our courses are meant for adults. We do not knowingly collect children's data. If it turns out that an account was created by a child without their parents' consent, we will delete the data.

Changes to this policy

We may update this document — for instance if our contractors change or new features appear. The current version is always on this page, with the date of the update at the top. We will announce material changes by email or with a visible banner on the site. Date of the last update: August 27, 2026.