Privacy Policy
Last updated: 2026-06-25
This Privacy Policy explains how SIA "Ballery", registration number 40203285423, registered at Gunāra Astras iela 8 k-1 – 63, Rīga, LV-1082, Latvia ("Ballery", "we") collects, uses, shares and protects personal data of users of the Ballery platform (the "Service").
For the purposes of the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR, Ballery is the data controller of your personal data. For California residents, terms used below have the meaning given by the California Consumer Privacy Act, as amended by the CPRA ("CCPA").
1. Personal data we collect
- Account data: email address, password (hashed), display name, locale, marketing-opt-in flag, role.
- Profile data: avatar image, any optional information you choose to add.
- Billing data: subscription status, plan, billing cycle, invoice history, country and (where required) tax/VAT identifiers, last 4 digits and brand of payment card. Full card data is processed directly by Stripe and never reaches our systems.
- Usage data: lessons viewed, watch position, completion status, course progress, login timestamps, device, browser type, language and IP address.
- Communications: support requests, email interactions and content you submit through forms.
- Cookies and similar tech: see our Cookie Policy.
2. How we use personal data and legal bases
- Provide and operate the Service (account creation, lesson access, progress tracking) — performance of a contract (Art. 6(1)(b) GDPR).
- Process payments and prevent fraud — contract; legal obligation; legitimate interest.
- Customer support — contract; legitimate interest.
- Security, abuse prevention and integrity — legitimate interest; legal obligation.
- Service improvement and analytics — legitimate interest, or consent where required.
- Marketing communications — consent (you may withdraw at any time); for existing customers, legitimate interest with opt-out where permitted.
- Legal compliance and dispute resolution — legal obligation; legitimate interest.
3. Sharing of personal data — subprocessors
We share personal data with the following categories of recipients only as necessary for the purposes above and under contractual safeguards:
- Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) — payment processing and fraud prevention.
- BunnyWay d.o.o. (Slovenia, "Bunny.net") — video storage and delivery (HLS / CDN).
- Cloudflare, Inc. (USA) — CDN, DNS, DDoS protection, WAF.
- Hetzner Online GmbH (Germany) or equivalent EU hosting provider — VPS hosting of our self-hosted Supabase stack (database, authentication, storage, edge functions).
- Transactional email provider (e.g. Postmark / Resend / Amazon SES) — delivery of account and service emails.
- Professional advisers (lawyers, accountants, auditors) and government bodies where required by law.
- Successors in case of merger, acquisition or sale of assets, under equivalent protections.
We do not sell your personal data and do not share it for cross-context behavioral advertising.
4. International transfers
Some recipients are located outside the EEA, including the United States. When we transfer personal data outside the EEA/UK, we rely on Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-US Data Privacy Framework, together with supplementary measures (e.g. encryption in transit). You may request a copy of the applicable safeguards by emailing support@school-ballery.com.
5. Retention
- Account data: while your account is active and up to 24 months after closure, unless longer retention is required by law.
- Billing and tax records: at least 5 years (Latvian Law on Accounting) or longer where required.
- Usage and security logs: typically up to 12 months.
- Marketing data: until you withdraw consent or object.
- Support communications: up to 36 months from last interaction.
6. Security
We implement appropriate technical and organizational measures including encryption in transit (TLS), encryption at rest, access controls, role-based permissions, RLS (row-level security) at the database layer, hardened infrastructure, audit logging, principle of least privilege and regular backups. No method of transmission or storage is 100% secure; we cannot guarantee absolute security but we work to protect your data.
7. Your rights (EU/EEA, UK)
Subject to applicable law, you have the right to:
- access your personal data and receive a copy;
- request rectification of inaccurate data;
- request erasure ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent at any time (without affecting prior lawful processing);
- lodge a complaint with a supervisory authority — in Latvia: Data State Inspectorate (www.dvi.gov.lv).
To exercise your rights, email support@school-ballery.com. We may need to verify your identity. We will respond within one month (extendable by two further months for complex requests).
8. Your rights (California — CCPA / CPRA)
If you are a California resident, you have the right to:
- know the categories and specific pieces of personal information we collect, use and disclose;
- delete your personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information;
- limit the use of sensitive personal information;
- non-discrimination for exercising your rights.
We do not "sell" or "share" personal information as defined by the CCPA. We have not done so in the preceding 12 months. To exercise your rights, email support@school-ballery.com. Authorized agents must provide written authorization. We will not discriminate against you for exercising your rights.
9. Children
The Service is not directed at children. We do not knowingly collect personal data from children under 16 (EU/UK) or under 13 (US) without verifiable parental consent. If you believe a child has provided us with personal data without such consent, contact us and we will delete it.
10. Automated decision-making
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects concerning you.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-product before they take effect. The "Last updated" date at the top reflects the latest revision.
12. Contact and DPO
Data controller: SIA "Ballery", Gunāra Astras iela 8 k-1 – 63, Rīga, LV-1082, Latvia. Privacy contact: support@school-ballery.com. We have not appointed a Data Protection Officer because we are not required to do so under Art. 37 GDPR; the email above is your point of contact for all privacy matters.
