Privacy Policy (Datenschutzerklärung) Effective Date: June 19, 2026
This Privacy Policy explains how Andrei Kurylovich, operating as Aurora Machina (“we,” “us,” or “our”), collects, uses, and protects your personal data when you visit our school platform, enroll in our courses, and interact with our digital content (collectively, the "School").
This policy is designed to comply with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications-Digital Services Data Protection Act (TDDDG).
1. The Data Controller
The entity responsible for the processing of your personal data is: Andrei Kurylovich (Aurora Machina) Adresse: [Insert Address Here] Email: [Insert Email Address]
2. Information We Collect
We collect personal data only when strictly necessary to provide our services or when you have explicitly consented to it.
- Account & Profile Data: When you enroll, we collect your name, email address, and account credentials.
- Transaction Data: When you make a purchase, billing information (such as your geographic location for tax compliance) and payment processor transaction IDs are collected. Note: We do not process or store your raw credit card data. This is handled entirely by our third-party payment processors.
- Course Usage Data: We track your progress through the course, quiz results, and login history to personalize your learning experience.
- Communication Data: If you contact us for support or participate in community boards, we collect the contents of those communications.
- Technical Data: Our hosting platform automatically collects IP addresses, browser types, and device information for security and platform optimization.
- Marketing & Analytics Data: If you consent to our use of tracking technologies, we collect data regarding your interaction with our website, such as pages visited, clicks, purchase conversions, and ad referral sources.
3. Legal Basis and Purpose of Processing
Under GDPR (Article 6) and TDDDG (§ 25), we process your data based on the following lawful grounds:
- Contract Fulfillment (Art. 6(1)(b) GDPR): Processing Account, Transaction, and Course Usage data to deliver the course materials and manage your enrollment.
- Legal Obligation (Art. 6(1)(c) GDPR): Retaining certain billing and transaction data to comply with German commercial and tax laws.
- Legitimate Interest (Art. 6(1)(f) GDPR / § 25 (2) TDDDG): Processing Technical Data and setting "essential" cookies to ensure platform security, prevent fraud, monitor unauthorized credential sharing, and protect our intellectual property.
- Consent (Art. 6(1)(a) GDPR / § 25 (1) TDDDG): Processing your email address for marketing communications, as well as deploying non-essential tracking cookies (Meta Pixel, Google Ads) for analytics and advertising. This processing only occurs if you explicitly click "Accept" on our cookie banner. You may revoke this consent at any time.
4. Third-Party Data Processors & International Transfers
To operate the School, we utilize trusted third-party service providers. By enrolling in the School or accepting cookies, you acknowledge that your data will be processed by:
- Teachable, Inc. (Platform Host): Stores your account data, tracks course progress, and handles technical infrastructure.
- Payment Gateways (Stripe / PayPal): Used to securely process your payments.
- Analytics & Marketing Providers: Google Ireland Limited and Meta Platforms Ireland Limited (if you consent to tracking).
Because Teachable, our payment processors, and the parent companies of our marketing providers are located in the United States, your data may be transferred outside the European Economic Area (EEA). These transfers are strictly safeguarded by the European Commission’s Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
- Teachable Privacy Policy: https://teachable.com/privacy-policy
- Teachable DPA: https://teachable.com/dpa
5. Cookies, Analytics, and Tracking Technologies
We use a Consent Management Platform (CMP) provided by Silktide to manage your cookie preferences. Essential cookies are loaded automatically to ensure core site functionality. Non-essential technologies are entirely disabled by default and are only activated if you click "Accept Cookies" in our pop-up banner.
If you provide your consent, we utilize the following tools:
- Google Tag Manager (GTM): We use GTM to centrally manage tracking scripts on our site. GTM itself does not set cookies or process personal data; it merely triggers other tags (like Google Ads and Meta Pixel) based on your consent preferences.
- Google Ads Conversions: Provided by Google Ireland Limited. We use this tool to measure the effectiveness of our advertising campaigns by tracking actions you take on our site (such as a course purchase) after clicking on a Google Ad.
- Meta Pixel: Provided by Meta Platforms Ireland Limited. This tool tracks your behavior after you have been redirected to our site by clicking on a Facebook or Instagram ad. It helps us measure ad effectiveness, understand user behavior, and build targeted audiences. For the collection and transmission of this data to Meta, we act as Joint Controllers with Meta under Art. 26 GDPR. If you have a Meta account, Meta may link this data to your profile for its own advertising purposes.
You can manage or withdraw your consent for these tracking technologies at any time by accessing the Silktide cookie settings on our website or adjusting your browser settings.
6. Data Security & Automated Decision Making
We implement appropriate technical and organizational measures to protect your personal data, such as encryption and access controls. However, no system is completely secure. We do not use your personal data for automated individual decision-making or profiling.
7. Children’s Privacy
Our School is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from anyone under these age thresholds without verifiable parental consent. If you are under 18, you must have a parent or guardian's permission to use the platform. If we become aware that we have inadvertently collected data from a child below the legal age of digital consent, we will delete it immediately.
8. Data Retention
We keep your personal data only for as long as necessary to fulfill the purposes for which it was collected.
- Account Data: Kept for the lifetime of your account to ensure ongoing access to the Course Materials.
- Financial Records: Retained for up to 10 years to comply with German statutory tax requirements. If you request the deletion of your account, we will erase your personal data, excluding information we are legally required to retain.
9. Your GDPR Rights
As a resident of the EU or EEA, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request the deletion of your personal data, subject to our legal retention obligations.
- Right to Restrict Processing: Ask us to pause the processing of your data.
- Right to Data Portability: Request your data in a structured, commonly used format.
- Right to Object: Object to data processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent for marketing emails or tracking cookies at any time via our cookie banner or by contacting us.
To exercise any of these rights, please contact us at [Insert Email Address].
10. Right to Complain to a Supervisory Authority
If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a data protection supervisory authority. The competent authority for our jurisdiction is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de
11. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy to reflect changes in legal requirements or platform operations. We will notify active students of any material changes via email or an announcement within the School. Your continued use of the School following the posting of changes constitutes your acceptance of the revised policy.