Privacy Policy
Version 1.0 — Effective Date: 15/03/2026
1. Data Controller
Julien Aldo Albert Poggioli
Micro-entrepreneur
Trade name: SkyGuided
5 allée Eugène Ionesco
79200 Parthenay – France
Email: contact@skyguided.org
2.Data Collected
2.1 Identification Data
- Name
- Email address
2.2 Contractual Data
- Purchase history
- Amount paid
- Purchase date
- Stripe transaction identifier
- Version of the Terms and Conditions of Sale accepted
- Timestamp of acceptance of the Terms and Conditions of Sale
- Timestamp of waiver of the right of withdrawal
- IP address at the time of payment
2.3 Educational Data
- Course progress (LearnDash)
2.4 Technical Data
- IP address
- Server logs (retained for a maximum of 1 year)
- Simultaneous sessions limited to 2
Important
- No affiliate tracking
- No marketing tracking
- No behavioral advertising
- No newsletter in Version 1
- No external CRM
3. Purposes of Processing
The data are used exclusively for:
- execution of the contract (course access)
- accounting and invoicing management
- platform security
- fraud prevention
- technical management of user access
4. Legal Basis
Article 6(1)(b) GDPR — performance of a contract
Article 6(1)(c) GDPR — legal accounting obligations
Article 6(1)(f) GDPR — legitimate interest (website security)
No processing based on marketing consent is carried out in Version 1.
5. Data Processors
- o2switch — website hosting and professional email hosting
- Stripe — payment processing
- Brevo — transactional email sending (SMTP)
- Bunny.net (Bunny Stream) — secure hosting of educational videos
- WooCommerce PDF Invoices Plugin — automatic invoice generation
- UptimeRobot — external monitoring of website availability
No other processors are active in Version 1.
6. Transfers Outside the European Union
Certain service providers (notably Stripe) may involve data transfers outside the European Union.
These transfers are governed by Standard Contractual Clauses compliant with GDPR requirements.
7. Data Retention Periods
In accordance with GDPR:
- Accounting data: 10 years
- Contractual data: minimum 6 years
- Contractual evidence (acceptance of terms, withdrawal waiver): minimum 6 years
- Technical server logs: maximum 1 year
- User account: retained as long as necessary for contractual purposes
Deletion of a user account does not result in deletion of invoices, due to legal accounting obligations.
8. Security Measures
The following measures are implemented:
- secure hosting infrastructure
- SSL certificate
- daily backups
- connection logging
- limitation of simultaneous sessions (2)
- anti-brute-force protection
- restricted administrator access
- video protection through domain restriction and token security (Bunny)
9. Data Subject Rights
You have the following rights:
- right of access
- right to rectification
- right to erasure (within legal limits)
- right to restriction of processing
- right to object
- right to data portability
Requests should be sent to:
Maximum response time: 1 month.
Identity verification may be requested.
You may also file a complaint with the French Data Protection Authority (CNIL):
www.cnil.fr
10. GDPR Procedure
Requests for data export or deletion are processed using:
- native WordPress tools (data export / deletion)
- manual verification of associated data in Stripe if necessary
Regular compliance checks are conducted.
11. Absence of Automated Profiling
No automated decision-making producing legal effects is implemented.
12. Modifications
This Privacy Policy may be updated at any time.
The applicable version is the version published on the website at the time of consultation.
