Skip to content
Data protection

Privacy policy

This policy states what personal data we process, why, who else sees it, and how you exercise your rights. The free courses ask for nothing at all.

The controller

The Provider operates the Devora site. The Provider decides why and how the personal data given on the site is processed, and is therefore the controller.

The processing is governed by the European Union's General Data Protection Regulation (GDPR) and by Hungarian data protection law.

Write to lamido.admin@gmail.com with any privacy question. We answer in writing.

What data we process

We process only what the service needs to work. The free courses ask for nothing: you take them without an account and without signing in, so we do not know who took them.

  • Account data: your name and your e-mail address. We hold no password, because there is no password.
  • Purchase data: what you bought, when, for how much, and what an invoice needs. We never see or store card details — the payment provider handles those.
  • Booking data: which session you claimed, and when you moved or released it.
  • Technical data: IP address, browser and device type, and the entries in our error logs.
  • Correspondence: what you write to us, and what we write back.

Why we process it, and on what basis

Every use we make of your data has a purpose we can name and a legal basis. The list below is complete: what is not on it, we do not do.

  • Performing the contract: creating your account, giving you the course you bought, booking your session, and sending you messages about the service.
  • Legal obligation: invoicing, and keeping accounting records.
  • Legitimate interest: the security of the site, preventing abuse, debugging, and measuring the service in aggregate, with nothing traced back to a person.
  • Consent: the course e-mails, and any cookie the site does not need to run. You may withdraw consent at any time, and withdrawal does not affect what came before it.

How long we keep it

We keep each kind of data for as long as its purpose lasts. After that we delete it, or aggregate it beyond recovery.

  • Account data: while your account exists. Deleting the account ends the access with it.
  • Invoicing data: for as long as accounting law requires, currently eight years. Deleting your account does not shorten this.
  • Course e-mail subscription: until you unsubscribe.
  • Technical logs: twelve months at most.

Who else sees it

We do not sell personal data, and we do not pass it to anyone for their marketing. Only the processors the service cannot run without see it, and each sees only what its own job needs.

We disclose data to an authority when law obliges us to. Where law allows it, we tell you first.

  • The hosting and infrastructure provider that serves the site.
  • The payment provider that takes the card payment.
  • The mail provider that carries the sign-in codes and the notifications.
  • The video provider the live session runs on.
  • Bookkeeping, legal and tax advice, to meet our obligations under law.

Transfers outside the European Union

We work with providers inside the European Union wherever we can. Where a processor operates outside it, the transfer rests on an adequacy decision of the European Commission or on its standard contractual clauses.

Cookies

The site uses the cookies it needs to work. They hold your sign-in and the state of your cart. They ask for no consent, because without them the service cannot be used.

Your choice of language is not in a cookie. It is in the address, which is why a page can be linked in the language you read it in, and why we do not have to remember which language that was.

Every other cookie — anything for measurement or marketing — reaches your device only after you consent. You may withdraw that consent at any time, and you may clear the cookies in your browser's own settings.

Your rights

The GDPR gives you the rights below. Ask for any of them at the address above, free of charge, and we answer within one month at the latest. If we refuse a request, we say why.

  • Access: ask what data we hold about you, and ask for a copy of it.
  • Rectification: ask us to correct data that is wrong.
  • Erasure: ask us to delete your data, where no legal basis requires us to keep it.
  • Restriction: ask us to stop using a disputed record until the dispute is settled.
  • Portability: ask for the data you gave us in a machine-readable form.
  • Objection: object to any processing that rests on legitimate interest.
  • Withdrawal of consent: leave the course e-mails with a single click.

Security

All traffic to the site travels over an encrypted channel. Only the few people whose work needs it can reach the data.

We store no password, because there is none: you sign in with a one-time code or a one-time link sent to your e-mail. So there is no password to steal.

Children

The service is for adults. We do not knowingly ask for or process the personal data of anyone under sixteen. If such data reaches us anyway, tell us and we delete it.

Complaints and remedies

If you believe our processing breaks the law, write to us first. Most questions are settled fastest that way.

You may also complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), and you may go to court. Both routes are open to you whether or not you wrote to us.

Changes to this policy

We change this policy when the service or the law changes. The revision date of the version in force is at the top of this page.

Where a change affects you materially, we also write to you before it takes effect.