Revision Date: Oct 13, 2025
1. Introduction
1.1 This Privacy Policy outlines how the Operator collects, uses, stores, shares, and protects personal data obtained through its online platforms, digital products, and related services (collectively referred to as “the Services”).
1.2 The Operator respects the privacy rights of all individuals and complies with applicable international data protection and privacy standards. These include, but are not limited to, the General Data Protection Regulation (GDPR), the Personal Data Protection Acts (PDPA) of relevant jurisdictions, the Privacy Act 1988, and the Personal Data (Privacy) Ordinance (PDPO).
1.3 This document is intended to be read in conjunction with the Terms of Use governing the Services.
2. Definitions
For clarity and consistency, the following terms shall have the meanings assigned below:
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation or set of operations performed on Personal Data, whether by automated means or otherwise.
- “Controller” refers to the Operator, which determines the purposes and means of Processing Personal Data.
- “Processor” means any third party engaged by the Operator to process data on its behalf.
- “User” refers to any individual accessing or using the Services.
- “Applicable Laws” means all privacy and data protection laws relevant to the Operator’s activities and the jurisdictions of its Users.
3. Scope of Application
3.1 This Privacy Policy applies to all Personal Data collected through the Services, including but not limited to:
- Website visits and analytics;
- Account registrations, subscriptions, and purchases;
- Email communications;
- Customer support interactions; and
- Any related data processing activities conducted by the Operator or its authorized Processors.
3.2 The Policy applies globally to all Users, regardless of location.
4. Types of Data Collected
4.1 The Operator may collect the following categories of information:
- Identification Data: name, email address, contact details, or account credentials.
- Transactional Data: payment identifiers, purchase history, and subscription preferences (processed via third-party providers).
- Technical Data: IP addresses, browser types, operating systems, device information, time zone settings, and referring URLs.
- Usage Data: page interactions, time spent, click behavior, and general analytics metrics.
- Marketing and Communication Data: newsletter subscriptions, communication preferences, and marketing opt-ins.
4.2 Data is collected directly from the User or automatically through cookies, scripts, analytics, or integrated third-party platforms.
5. Lawful Basis for Processing
5.1 The Operator processes Personal Data under one or more of the following lawful bases:
- Consent: where Users have provided clear permission for specific processing purposes.
- Contractual Necessity: to fulfill obligations arising from a contract or digital purchase.
- Legitimate Interests: for business improvement, fraud prevention, and product optimization.
- Legal Obligations: where processing is required by applicable law.
5.2 Where consent is relied upon, Users may withdraw it at any time through the channels described in Section 12.
6. Purpose of Processing
6.1 Personal Data may be processed for the following purposes:
- To operate, maintain, and improve the Services;
- To manage account access, authentication, and subscriptions;
- To deliver purchased or subscribed digital products;
- To respond to User inquiries or support requests;
- To send administrative or marketing communications (subject to consent);
- To perform analytics, research, and service enhancement;
- To comply with regulatory, tax, or audit requirements;
- To protect the integrity, security, and lawful operation of the Services.
7. Data Retention
7.1 Personal Data shall be retained only for as long as necessary to fulfill the purposes described in this Policy, or as required by Applicable Laws.
7.2 Data that is no longer required will be securely deleted, anonymized, or archived in accordance with industry best practices.
7.3 Users may request deletion of their data as described in Section 12.
8. Cookies and Tracking Technologies
8.1 The Services may use cookies, tracking pixels, and analytics tools to enhance user experience and analyze behavior.
8.2 Users will be informed of cookie usage through a banner or pop-up and may manage preferences via browser settings or opt-out mechanisms.
8.3 Types of cookies used include:
- Essential Cookies: required for basic site functionality;
- Analytics Cookies: used to monitor and improve website performance;
- Marketing Cookies: employed to deliver targeted or relevant promotions.
8.4 The Operator uses Clicky Analytics to collect anonymized metrics on site performance and visitor behavior.
9. Data Sharing and Disclosure
9.1 The Operator does not sell or rent Personal Data.
9.2 Personal Data may be disclosed to:
- Authorized employees or contractors bound by confidentiality;
- Third-party Processors (see Section 16);
- Legal authorities, where disclosure is mandated by law.
9.3 Data shared with Processors is limited to the minimum necessary to perform contracted services.
10. International Data Transfers
10.1 Due to the global nature of online services, Personal Data may be transferred to and processed in countries outside the User’s jurisdiction.
10.2 The Operator ensures that such transfers comply with Applicable Laws through mechanisms such as:
- Standard Contractual Clauses (SCCs) under GDPR;
- Adequacy decisions by data protection authorities;
- Contractual obligations ensuring equivalent data protection standards.
10.3 Users acknowledge that cross-border transfers are essential for the provision of the Services.
11. Data Security
11.1 The Operator implements appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction.
11.2 Security controls may include encryption, pseudonymization, limited data access, firewalls, and regular vulnerability assessments.
11.3 While the Operator strives for a high level of security, absolute protection against all threats cannot be guaranteed.
12. User Rights
12.1 Users may exercise the following rights under Applicable Laws:
- Access: obtain a copy of their Personal Data held by the Operator;
- Rectification: correct inaccuracies or incomplete information;
- Erasure: request deletion (“right to be forgotten”);
- Restriction: limit data processing under certain conditions;
- Portability: request transfer of data to another controller;
- Objection: oppose processing based on legitimate interests;
- Withdrawal of Consent: revoke consent previously granted.
12.2 Requests should be made through the contact channel provided in Section 15.
12.3 The Operator will respond to verified requests within the timeframe prescribed by Applicable Laws.
13. Children’s Privacy
13.1 The Services are not directed toward children under the age of 18.
13.2 The Operator does not knowingly collect Personal Data from minors. If such data is discovered, it will be deleted promptly.
14. Marketing Communications
14.1 The Operator may send marketing communications to Users who have explicitly opted in.
14.2 Recipients may opt out at any time by following unsubscribe instructions or contacting the Operator directly.
14.3 Marketing lists are maintained in compliance with consent requirements and anti-spam regulations.
15. Contact and Complaints
15.1 For privacy-related inquiries, data requests, or complaints, Users may contact the Operator via secure web form.
15.2 Complaints will be investigated and resolved in accordance with Applicable Laws and fair handling procedures.
16. Third-Party Processors (Data Processing Addendum)
16.1 The Operator engages the following processors to support the Services:
- AWeber Systems, Inc. — email marketing and list management provider;
- Clicky Analytics — web analytics and behavioral tracking service;
- ClickBank — payment processing and digital commerce platform.
16.2 Each Processor operates under a data processing agreement ensuring compliance with international data protection standards.
16.3 These Processors are contractually obligated to:
- Process Personal Data only on documented instructions from the Operator;
- Maintain confidentiality and security of data;
- Assist in fulfilling User rights requests;
- Notify the Operator of any data breach incidents without undue delay.
17. Liability and Disclaimer
17.1 The Operator shall not be held liable for:
- Any unauthorized access resulting from the User’s failure to maintain account security;
- Data loss or corruption arising from external network failures or service interruptions;
- Acts or omissions of independent third-party processors beyond the Operator’s reasonable control.
17.2 The Services are provided “as is” without warranties of any kind, whether express or implied.
17.3 Users access and utilize the Services at their own discretion and risk.
18. Policy Updates and Version Control
18.1 This Privacy Policy may be revised periodically to reflect legal developments, technological changes, or operational adjustments.
18.2 All modifications will be posted on the same page with an updated “Effective Date.”
18.3 Continued use of the Services after such updates constitutes acknowledgment of the revised terms.
19. Governing Principles
19.1 The Operator’s data protection practices are guided by principles of fairness, transparency, proportionality, and accountability.
19.2 Where conflicting legal obligations exist across jurisdictions, the Operator shall adopt the higher or more protective standard applicable to the User.
