Legal
Privacy Policy
Plain-language summary of what personal data we collect, why we collect it, and the choices you have.
Last updated 15 August 2026
This policy explains what personal data Datacenter Training collects, how we use it, and the choices you have.
Who is responsible
The controller for the processing described here is Datacenter Training, a sole proprietorship in 8001 Zürich, Switzerland. For any question about your data, or to exercise the rights listed below, write to getdatacentertraining@gmail.com.
What we collect
- Email address, when you subscribe to the newsletter or contact us. A subscription only counts once you open the confirmation link we send; before that, nothing is sent to the address.
- Account data, if you create one: email address, login method, your training progress and your plan status. The first mission runs in guest mode without an account, with progress stored only in your browser; from the second mission on an account is required.
- Payment data, if you buy a plan: handled by Stripe. We never see or store card numbers; we receive only the plan, payment status and a customer reference.
- Reach analytics: pages viewed, referring site, approximate region, device type. Collected in aggregate and not used to identify you.
- Learning analytics: how the course itself is going; which missions and scenes you open, how many attempts a task takes, how long a scene takes, whether an automatic hint appeared. Recorded per event, under a random identifier stored on your device, and linked to your account only while you are signed in. Never a name, an address or free text, and never anything about payments. Described in full under “How we measure the course”.
- Anything you choose to include in a message you send us.
Why we use it
- To send occasional product updates and tell you when new missions ship.
- To answer questions you send us.
- To understand which pages are useful so we can improve them.
Accounts, payments and disputes
- Account: your email address, a hashed password (or your Google sign-in), and your training progress; the missions you have completed with their scores, the answers you typed, and any name you enter for your training record. Without an account none of this progress reaches our servers: guest progress stays in your browser. The learning analytics described below are the one exception; they run without an account too, under a random identifier and never under your name.
- Purchase: Stripe processes the payment and holds the card data; we never see it. We keep the customer and subscription identifier, the plan, the amount, the date and the country needed for tax, plus the confirmation that you accepted the terms and asked for immediate access.
- Disputes and chargebacks: if you open a dispute with your bank, we may pass Stripe the evidence of your purchase; order data, the terms you accepted, and whether the content was accessed. This is how a dispute is defended and it is the reason we keep the acceptance record.
- Administrative log: when access is granted or withdrawn, a payment is refunded, a second factor is reset or an account is deleted, we record who did what, to which account and when. Deletion records deliberately outlive the account; otherwise we could not prove that we deleted it. They hold the account identifier and the email address, never progress or payment details.
- Retention: account and progress data until you delete the account; administrative log entries for three years; payment and tax records for as long as accounting law requires (in Switzerland ten years). The record of the terms you accepted outlives the account for the same reason the deletion record does: it is what we would have to show if a payment were disputed afterwards. It holds the date, the version you accepted and what you bought; no progress, no payment details.
How we measure the course
To find out where a course is confusing we record what happens while you work through it: which mission and scene you open, how many attempts a task takes, how long a scene takes, whether you retry after falling below the pass mark, and whether an automatic hint appeared. This is our own measurement on our own servers; no cookie, no advertising network, no third country.
It is pseudonymous. Each browser gets a random identifier that we generate and that means nothing outside this service; while you are signed in, the record also carries your account so that one person is counted once rather than twice. We never record a name, an email address, free text you typed, or anything about a payment; what you bought is known from the payment records, never from your browser. Analyses in our operator console show counts and rates only, and anything covering fewer than five learners is withheld.
Twelve months after an event was recorded we remove the link to your account and replace the random identifier on those records with a fresh one, so that nothing ties them back to you or to the browser you still use; only the anonymous row remains, and the course statistics survive while the connection to you does not. Deleting your account removes these records for you straight away, and you can request a copy of them at any time. This measurement is separate from the Google Analytics banner below, which covers a third-party service with cookies; turning that off does not turn this off.
Your certificate is public
If you buy a certificate, it carries the full name you enter and confirm in the issuance step; not a name taken from your profile, and not one we guess. That name, together with the course, the issue date and whether the certificate is still valid, is shown by the public verification address printed on the certificate itself. Anyone holding that address can see it, which is the point: a certificate nobody can check is worth nothing. We publish nothing else there; no email address, no account identifier, no payment details and no score.
The basis for publishing it is your own confirmation at issuance, which is why we ask for it in a separate step and say plainly what happens. The name cannot be changed afterwards, because a credential that can be silently rewritten is not a credential; a correction means we revoke the certificate and issue a new one. If a certificate is refunded or revoked, the verification address reports it as no longer valid and stops offering the file. Your progress and your free Training Record are separate and are not affected.
Deleting your account
You delete your account yourself, in the account screen: we ask you to sign in again, then cancel an active subscription, remove your entitlement and your synced progress, and delete your login. Time already paid for is forfeited, so cancel instead of deleting if you want to use the rest of the period. Progress stored only in your browser is cleared on that device as well; export it first if you want to keep it. Payment and tax records stay with Stripe for the statutory period; that is a legal obligation we cannot waive.
Legal basis and retention
Where the GDPR or the UK GDPR applies, we rely on your consent for newsletter emails and for Google Analytics and the Google Ads conversion measurement described below, on our legitimate interest in improving the course for the first-party learning analytics described above, on the performance of our contract with you for the account and the paid plan, on our legitimate interest in defending payment disputes, and on legal obligation for accounting records. Your consent is recorded when you open the confirmation link we email you: until then your address is stored but never written to, and if you never confirm, it never receives anything. Addresses are kept until you unsubscribe or ask us to delete them, and for no more than 24 months of inactivity after that.
Processors
We use third-party providers, each bound by a data processing agreement and processing data only on our instructions: Vercel (hosting), Supabase (accounts, progress sync and entitlements), Stripe (payment processing), Resend (transactional email), Google Ireland Limited (analytics and advertising measurement, and only if you allow it) and cookieless analytics. A current list with regions is available on request.
Your rights
- Access a copy of the data we hold about you; signed-in users can download it themselves, in machine-readable form, from Account → Data and account. No request, no waiting.
- Correct anything inaccurate.
- Delete your data, including every waitlist record.
- Withdraw consent at any time: every email has a one-click unsubscribe link.
- Lodge a complaint with your local data protection authority.
Cookies and analytics
We set no cookies of our own: your theme preference, your analytics choice, your sign-in session, your course progress and the random learning-analytics identifier (stored as “dc-analytics-id”, with “dc-analytics-session” and “dc-analytics-started”) are all kept in your browser's local storage, on your own device. Cookies can still reach you through the services we embed; Google Analytics and Google Ads only after you allow it, as described below, and Stripe on the pages where you enter card details, where the payment form is provided by Stripe and any cookies are theirs, not ours. While you are signed in, that same progress is also synced to your account on our servers, so you can pick it up on another device; it is stored only for you and is never sold or shared for advertising.
We also run Google Analytics 4 to see which pages help people learn, and Google Ads conversion tracking to see which ads lead to a purchase. Both store data on your device only if you allow it. Until you do, Google Consent Mode keeps analytics and advertising storage denied, so no _ga cookie is set and no identifier is stored. The measurement tag itself does load on every page, and until you allow it, it sends only cookieless signals: click identifiers are stripped from those requests, and the click information is passed through the address bar instead. Choosing “Allow” in the banner sets that cookie and sends usage data to Google Ireland Limited; you can take the choice back at any time with the button below, which brings the banner back. When you complete a purchase, we also report that purchase to Google Ads: the amount, the currency, an identifier for the product and the payment reference, so that a sale can be attributed to an ad. When you create an account or complete a purchase, and you have allowed advertising measurement, we additionally send Google a one-way fingerprint of your email address: it is scrambled in your browser with SHA-256 before it leaves, so Google receives a string of letters and digits and never the address itself. This helps Google recognise that an advert led to that sign-up or sale. If you have not allowed advertising measurement, we do not send it at all. We never send your name, your actual email address or your card details. Alongside all of this we use cookieless analytics (Vercel, Ahrefs) that never identifies individuals.
Contact
Most requests need no request at all: if you have an account, you can download your data and delete your account yourself, at any time, under Account → Data and account. For anything else (correction, objection, or a question about this notice) use the contact form; it reaches the operator directly (see the legal notice). We answer as soon as we can and in any case within the statutory deadline, which is one month.