Skip to content

Privacy Policy

This policy explains what personal data Neda eCampus collects, why, where it is kept, who else sees it, and what you can do about it. It covers every part of the platform: the website and shop at nedaecampus.com, the learning platforms at learn.nedaecampus.com and openedx.nedaecampus.com, the account service at auth.nedaecampus.com, and the creator workspace. It is written to be read, not skimmed; if anything in it is unclear, ask us.

1. Who is responsible

The controller is Neda eLearning Solutions, Austria — full details in the Imprint. For anything about your data, write to info@neda-els.com with “Privacy” in the subject line. We have not appointed a data protection officer, because we are not required to; [CONFIRM with counsel].

Course creators who publish on Neda eCampus see some information about learners enrolled in their own courses — names, progress, submissions and grades — because teaching requires it. [CONFIRM with counsel: whether creators act as independent controllers, joint controllers with us, or as our processors for that data. The Creator Agreement is drafted on the basis that they are processors acting on our instructions, which is the reading that gives learners one responsible party.]

2. Where your data is kept

Every system that makes up Neda eCampus runs on a server we control at Hetzner Online GmbH in Germany. Your data does not leave the European Union except in the specific cases listed in section 6, each of which you can avoid.

3. What we collect, and why

Your account

Name, email address, a password (stored only as a hash), and a confirmation that you are 18 or over. If you sign in through Google or LinkedIn, we receive your name, email and profile picture from them; the picture is copied to our server so that later page loads do not contact Google or LinkedIn at all. Basis: performance of our contract with you (GDPR Art. 6(1)(b)). We do not collect a date of birth or an identity document.

Your learning

Which courses you are enrolled in, your progress, things you submit, grades, forum posts, and certificates. The learning platforms also keep an activity log — which pages you opened and when — which teachers use to see where learners get stuck and we use to investigate problems. Basis: contract (Art. 6(1)(b)) for enrolment, progress and certificates; our legitimate interest in running a working platform (Art. 6(1)(f)) for the activity log, which is why the log is kept for no longer than twelve months.

Your purchases

What you bought, when, for how much, your billing address, and the payment provider’s reference. We never see your full card number. Basis: contract (Art. 6(1)(b)), and the legal obligation to keep accounting records (Art. 6(1)(c)).

Where you were when you bought. EU VAT law requires us to determine and be able to prove the country a customer is in at the moment of sale, using evidence that does not come from the customer alone (Council Implementing Regulation 282/2011, Art. 24b and 24f). So for every order we record your IP address and the country it resolves to, your billing country, your browser’s language setting, and — once payments are live — the country of the card used. The IP address is resolved to a country on our own server against a locally held database; it is not sent to any geolocation service. Basis: legal obligation (Art. 6(1)(c)). Because the law requires it, you cannot opt out, and because it is part of the tax record it is kept for the same seven years as the invoice — including after you close your account.

If you contact us

The contact form stores your name, email, chosen topic and message, and the page you sent it from. It does not store your IP address. The only exception is a rate limit that keeps a salted, truncated hash of the address for one hour so that one sender cannot flood the inbox; the hash cannot be turned back into an address and is never written to a permanent record. Messages are kept for up to 24 months after our last reply, then deleted. Basis: legitimate interest in answering you (Art. 6(1)(f)).

If you are a course creator

In addition to the above: your business name and address, VAT number if you have one, and — once payouts are live — the identity and bank details you give to our payment provider for their onboarding. We send a VAT number you give us to the European Commission’s VIES service to confirm it is registered, and keep the answer. Basis: contract (Art. 6(1)(b)) and tax law (Art. 6(1)(c)). Platform reporting under the DAC7 directive [CONFIRM with accountant — not expected to apply while the catalogue is pre-recorded only].

Technical records

Our web server keeps access logs — IP address, page requested, time, browser — for 14 days, for security and to diagnose faults. Basis: legitimate interest (Art. 6(1)(f)). The Cookie Policy lists every cookie we set. We run no analytics service, no advertising, and no tracking pixels; this was measured, not assumed.

4. What we do not do

  • We do not sell, rent or trade personal data.
  • We do not profile you, and we make no decision about you by automated means that has a legal or similarly significant effect.
  • We do not send marketing email unless you have asked for it, and every such email has an unsubscribe link.
  • We do not use your data, or course content, to train AI models.

5. Who else sees your data

Only companies that provide part of the service, each under a contract that restricts what they may do with it. The current list, with what each receives and where it is, is maintained on the Sub-processors page, and we update that page before adding a new one. In summary: hosting in Germany; email delivery; the payment provider, once live; and, only if you choose to use them, Google and LinkedIn for sign-in and Google for page translation.

We disclose data to authorities only where the law requires it, and we keep a record of any such request.

6. Transfers outside the EU

Three things can send data to the United States, and each is in your hands:

  • Signing in with Google or LinkedIn. If you use a password instead, neither is contacted.
  • Using the language switcher. Translation is performed by Google, and the text of the page you are viewing is sent to Google only when you pick a language. Until then, the page makes no request to Google at all.
  • Email. Our outgoing email — receipts, notifications, replies to the contact form — is currently relayed by a provider in the United States under the EU–US Data Privacy Framework. We have decided to move this to a provider inside the EU and will update this policy when that is done.

7. How long we keep things

DataKept for
Account, enrolments, progress, certificatesUntil you close your account, then deleted within 30 days
Purchase records, invoices, VAT location evidence7 years after the year of the purchase (§ 132 BAO)
Platform activity logs12 months
Contact-form messages24 months after our last reply
Web-server access logs14 days
Archived course contentRetention conditions currently being finalised — see the Retention Policy
BackupsRolling; the newest copy is retained for up to 90 days. Deleted data leaves the backups as they cycle out.

8. Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. You can withdraw any consent you have given at any time. Write to info@neda-els.com; we will reply within one month and will not charge you. We may ask you to confirm your identity, normally by replying from the email address on the account.

When you ask us to delete your account we remove it from all four systems that make up the platform, not just the one you can see. Two things survive deletion because the law says they must: purchase and tax records for seven years, and the VAT location evidence that belongs to them. We keep only what those obligations require and nothing else.

If you are unhappy with how we have handled your data, you can complain to the Austrian data protection authority: Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb.gv.at — or to the authority in the country where you live.

9. Security

All connections are encrypted. Passwords are stored as salted hashes and are never visible to us. Access to the server is by key only, from named accounts. Backups are encrypted and a copy is kept off the main server. If a breach ever affects your data in a way that puts you at risk, we will tell you directly and without undue delay, as Article 34 GDPR requires. If you find a security problem, the Security page tells you how to report it.

10. Changes to this policy

When this policy changes in a way that matters — a new sub-processor, a new purpose, a change to retention — we will email account holders before it takes effect and note the change at the bottom of this page. Minor wording changes are made in place.

Version 1.0 — 22 August 2026.