Privacy Notice
Last updated: June 2026
This Privacy Notice explains how Sandaii LLC ("Sandaii", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit our website, purchase a course, or otherwise use our services (the "Service").
1. Who We Are
Sandaii LLC is the data controller for personal data collected through the Service. You can reach us via our contact page for any privacy-related questions or requests.
2. Personal Data We Collect
- Account data: name, email address, password (hashed), and login credentials.
- Order data: products purchased, order history, and limited billing metadata received from Paddle (such as country, last four digits of the payment method, and invoice references). Full payment card details are collected and processed by Paddle, not by us.
- Support data: messages, attachments, and other information you provide when contacting us.
- Usage & device data: pages visited, course progress, referring URLs, browser type, device identifiers, approximate location, and IP address.
- Cookies and similar technologies: as described below.
3. How We Use Personal Data
- To create and manage your account and deliver the courses you purchased;
- To provide customer support and respond to your inquiries;
- To process orders, fulfill our contract with you, and prevent fraud;
- To improve and secure the Service, including troubleshooting and analytics;
- To send transactional emails (e.g., receipts, account notices) and, where permitted, marketing emails you can opt out of at any time;
- To comply with legal obligations and enforce our Terms.
4. Legal Bases
We rely on the following legal bases, depending on the activity:
- Performance of a contract — to provide the Service you purchased;
- Legitimate interests — to secure the Service, prevent fraud, and improve our products;
- Consent — for non-essential cookies and optional marketing communications;
- Legal obligation — to comply with tax, accounting, and other laws.
5. How We Share Personal Data
We share personal data only with the categories of recipients below:
- Merchant of Record — Paddle.com: we use Paddle as our reseller and Merchant of Record. Paddle processes payments, manages subscriptions, calculates and remits applicable taxes, issues invoices, and handles refunds and chargebacks. Paddle is an independent data controller for the payment information it processes.
- Service providers / subprocessors: hosting, database, email delivery, analytics, and customer-support tooling, acting on our instructions.
- Professional advisers: legal, accounting, and audit advisers, where necessary.
- Authorities: where required by law, court order, or to protect our rights.
We do not sell your personal data.
6. Data Retention
We retain personal data only as long as necessary for the purposes described above — typically for the duration of your account plus a reasonable period to comply with legal, tax, and accounting obligations. When data is no longer needed, we delete or anonymize it.
7. Your Rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to certain processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights, contact us via our contact page. You also have the right to lodge a complaint with your local data protection authority.
8. International Transfers
Your personal data may be processed in countries other than the one in which you reside. Where required, we and our subprocessors use appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) for cross-border transfers.
9. Security
We implement appropriate technical and organizational measures — including encryption in transit, access controls, and least-privilege practices — to protect personal data against unauthorized access, alteration, disclosure, or destruction. No system is 100% secure, but we work to keep risks low.
10. Cookies
We use cookies and similar technologies that are essential for the Service to function (e.g., authentication and session management), and we may use analytics cookies to understand how the Service is used. You can manage cookies through your browser settings; disabling essential cookies may limit functionality.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can remove it.
12. Changes to This Notice
We may update this Privacy Notice from time to time. Material changes will be posted on this page with a new effective date.
13. Contact
Privacy questions or requests can be sent through our contact page.