Privacy policy
This policy explains what personal data ScandiNaturePass ("we") collects when you buy or take a course, why, and what your rights are. The data controller is Näshultakök, Ollonborrstigen 7, SE971124765101. Contact for all privacy questions: (contact email).
What we collect and why
- Name and email address — to sell and deliver the course, send your access link and certificate, and issue the certificate in your name. Legal basis: performing the contract (GDPR art. 6(1)(b)).
- Course progress and quiz results — to let you continue where you left off and to decide when you qualify for the certificate. Legal basis: performing the contract.
- Order and payment records (amount, date, reference) — to meet accounting and tax obligations. Legal basis: legal obligation (art. 6(1)(c)).
- If you buy a certificate for someone else: that person's name and email address, which you provide to us, so we can send them the certificate. You are responsible for having a reason to share their details.
- Security records (IP address and timestamps of administrator logins and actions; short-lived technical logs) — to protect the service against abuse. Legal basis: legitimate interest (art. 6(1)(f)).
We do not collect payment card details — payment is handled entirely by Stripe. We do not use advertising or analytics trackers, and we do not make decisions about you by automated means.
Who receives your data
- Stripe Payments Europe, Ltd. (and Stripe, Inc.) process payments as an independent controller/processor; see stripe.com/privacy. Transfers outside the EEA rely on the EU–US Data Privacy Framework or standard contractual clauses.
- Our hosting provider, which stores the website and database on servers we rent, and our email provider, which delivers the emails we send you. They act as processors under data-processing agreements.
- Authorities or advisers (for example our accountant) where the law requires or where needed to defend legal claims.
We do not sell your data.
How long we keep it
- Abandoned (unpaid) checkouts: 30 days.
- Learner records, progress and certificates: until 36 months after your last activity, or until you ask us to delete them.
- Paid orders: 7 years, as required by accounting law; afterwards they are anonymised. If you ask us to erase your data, we keep the order record but remove your name and email.
- Administrator security logs: 12 months.
Cookies
We only use strictly necessary cookies: one that remembers your chosen language, and (for administrators only) a secure login session cookie. No consent banner is needed because nothing is used for tracking or marketing. Fonts are served from our own server.
Your rights
You can ask us for access to your data, to correct it, to erase it, to restrict or object to its processing, and to receive it in a portable format. Write to (contact email) and we will answer within one month. You also have the right to lodge a complaint with your national data protection authority (in Sweden: Integritetsskyddsmyndigheten, imy.se).
Security
Data is transmitted over HTTPS. Administrator access requires individual accounts with two-factor authentication, access is limited by role, and administrative actions are logged. Secrets such as payment keys are stored encrypted. Course access links are long random codes — keep them private.
Changes
We will update this policy when our processing changes. Current version: 1.0.