Privacy Policy

Version 1.0 — Effective Date: 15/03/2026

1. Data Controller

Julien Aldo Albert Poggioli
Micro-entrepreneur
Trade name: SkyGuided

5 allée Eugène Ionesco
79200 Parthenay – France

Email: contact@skyguided.org

2.Data Collected

2.1 Identification Data

  • Name
  • Email address

2.2 Contractual Data

  • Purchase history
  • Amount paid
  • Purchase date
  • Stripe transaction identifier
  • Version of the Terms and Conditions of Sale accepted
  • Timestamp of acceptance of the Terms and Conditions of Sale
  • Timestamp of waiver of the right of withdrawal
  • IP address at the time of payment

2.3 Educational Data

  • Course progress (LearnDash)

2.4 Technical Data

  • IP address
  • Server logs (retained for a maximum of 1 year)
  • Simultaneous sessions limited to 2

Important

  • No affiliate tracking
  • No marketing tracking
  • No behavioral advertising
  • No newsletter in Version 1
  • No external CRM

3. Purposes of Processing

The data are used exclusively for:

  • execution of the contract (course access)
  • accounting and invoicing management
  • platform security
  • fraud prevention
  • technical management of user access

4. Legal Basis

Article 6(1)(b) GDPR — performance of a contract
Article 6(1)(c) GDPR — legal accounting obligations
Article 6(1)(f) GDPR — legitimate interest (website security)

No processing based on marketing consent is carried out in Version 1.

5. Data Processors

  • o2switch — website hosting and professional email hosting
  • Stripe — payment processing
  • Brevo — transactional email sending (SMTP)
  • Bunny.net (Bunny Stream) — secure hosting of educational videos
  • WooCommerce PDF Invoices Plugin — automatic invoice generation
  • UptimeRobot — external monitoring of website availability

No other processors are active in Version 1.

6. Transfers Outside the European Union

Certain service providers (notably Stripe) may involve data transfers outside the European Union.

These transfers are governed by Standard Contractual Clauses compliant with GDPR requirements.

7. Data Retention Periods

In accordance with GDPR:

  • Accounting data: 10 years
  • Contractual data: minimum 6 years
  • Contractual evidence (acceptance of terms, withdrawal waiver): minimum 6 years
  • Technical server logs: maximum 1 year
  • User account: retained as long as necessary for contractual purposes

Deletion of a user account does not result in deletion of invoices, due to legal accounting obligations.

8. Security Measures

The following measures are implemented:

  • secure hosting infrastructure
  • SSL certificate
  • daily backups
  • connection logging
  • limitation of simultaneous sessions (2)
  • anti-brute-force protection
  • restricted administrator access
  • video protection through domain restriction and token security (Bunny)

9. Data Subject Rights

You have the following rights:

  • right of access
  • right to rectification
  • right to erasure (within legal limits)
  • right to restriction of processing
  • right to object
  • right to data portability

Requests should be sent to:

contact@skyguided.org

Maximum response time: 1 month.

Identity verification may be requested.

You may also file a complaint with the French Data Protection Authority (CNIL):
www.cnil.fr

10. GDPR Procedure

Requests for data export or deletion are processed using:

  • native WordPress tools (data export / deletion)
  • manual verification of associated data in Stripe if necessary

Regular compliance checks are conducted.

11. Absence of Automated Profiling

No automated decision-making producing legal effects is implemented.

12. Modifications

This Privacy Policy may be updated at any time.

The applicable version is the version published on the website at the time of consultation.