Privacy policy
Updated 13 September 2026
This page explains what data we collect on jewelryart.education, why, who else can access it and how you stay in control. We only collect what we need to teach you and run the school.
Who is responsible for your data
Jewelry Art Education is run by EI Bohdana Shkin (sole trader, France; SIRET 952 749 992 00022), who decides how and why your data is processed. For any question, write to jewelryart.education@gmail.com.
What we collect
- Account: email, name, site language, sign-up and last sign-in dates. There are no passwords — you sign in with a one-time link sent by email.
- Payment: name, email, phone, country, course and tier, amount and date. Card details are entered in Stripe's form and never reach us.
- Post-purchase questionnaire: your answers (age, occupation, motivation, topics of interest, how you heard about us).
- Learning: which lesson videos you watched and where you stopped, so your dashboard remembers your progress.
- Site statistics: pages viewed, time on page, scroll depth, where you came from (search, social media, UTM tags), device type, language, country and city. Country and city are derived from your IP address; the address itself is not stored.
- Newsletter: name, email and phone if you subscribed to news or the free course.
- Correspondence: whatever you write to us.
If you give us someone else's details (for example, when paying for a course for another person), make sure they agree.
Why, and on what legal basis
- Giving you access to the course, sending sign-in links, service emails and support replies — performance of our contract.
- Keeping payment and invoice records — a French legal obligation.
- Anonymous audience measurement, fraud and abuse prevention, internal student records — our legitimate interest.
- The statistics cookie that recognises your device between visits and shows where a student came from, Microsoft Clarity session recordings, plus news and special offers — your consent, which you can withdraw at any time.
We do not sell data, show ads, make pushy sales calls or send spam. Your phone number is only used to contact you about the course you signed up for.
Who else processes data
Only these services, and only to the extent they need:
- Hetzner Online GmbH (Germany) — web server and database.
- Stripe Payments Europe Ltd (Ireland) — payments.
- Resend (USA; sending from a data centre in Ireland) — sign-in links and service emails.
- Cloudflare, Inc. (R2 storage) — storing and streaming lesson videos, and off-site database backups.
- Notion Labs, Inc. (USA) — an internal copy of student and payment records.
- Telegram — notifications to the school owner about new payments and questionnaires.
- Microsoft (Clarity) — anonymous session recordings and heatmaps that show where the site is hard to use; only if you allowed cookies, with form fields hidden.
- YouTube (Google) and Vimeo — videos embedded in lessons and articles; they receive data only when you play a video.
Data you left on the school's previous website (the Tilda platform) has been moved here. Where data leaves the EU, it is protected by the European Commission's standard contractual clauses or the EU-U.S. Data Privacy Framework.
How long we keep it
- Account and course access — for as long as the course is available to you, plus 3 years after your last activity.
- Payments and accounting records — 10 years, as French law requires.
- Questionnaires — 3 years.
- Visit statistics — 25 months, then deleted automatically.
- Database backups — up to 90 days, then deleted automatically.
- Newsletter — until you unsubscribe.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, and withdraw your consent. Write to jewelryart.education@gmail.com — we reply within one month. If you believe your rights have been breached, you can complain to the CNIL (www.cnil.fr), the French data protection authority.
To stop receiving our newsletter, click “Unsubscribe” at the bottom of any email or write to us.
Security
We work to minimise the risk of your data being lost, stolen or misused: only the school owner can access it, sign-in uses one-time links instead of passwords, and the database is backed up regularly. No system is risk-free, so if you notice anything suspicious, please tell us as soon as possible.
Children
We do not knowingly collect data from children under 15 and will delete it if we find out we have. If you are under 18, please get permission from a parent or guardian before sharing your contact details.
Changes to this policy
If anything changes, we will update this page and the date at the top, and email you about significant changes.