Privacy Policy
Effective date: August 2, 2026 Last updated: August 2, 2026
1. Scope
This Privacy Policy explains how CertiAcademy Corp collects, uses, discloses, and protects personal information through certiacademy.com and any United States-facing CertiAcademy service that links to this Policy. The German website and the HPP product are covered by the separate German privacy notice available at certiacademy.de/datenschutz.
2. Company responsible for your information
CertiAcademy Corp A Florida C-Corporation 7901 4TH ST N, STE 300 ST. PETERSBURG, FL 33702 United States Florida Document Number: P26000033924
Privacy requests: privacy@certiacademy.com General contact: contact@certiacademy.com Phone: +1 (855) 666-6007
3. Information we collect
Website and technical information: IP address, date and time of access, requested page or file, response status, browser and device information, referring page, and security or diagnostic events.
Contact information: name, email address, telephone number if provided, message content, and our correspondence with you.
Account and authentication information: email address, account identifier, login and session information, account status, and security events.
Learning and product information: selected product, access period, learning progress, answers, results, saved settings, optional exam date, device assignment, and last-use information.
Transaction information: product, price, currency, transaction identifier, purchase date, payment status, refund or revocation status, and provider. We do not store complete payment-card numbers.
Information you choose to provide, including support requests, feedback, or material submitted through a product feature.
4. Sources of information
We obtain information directly from you, automatically from your browser or device when you use our services, from our own systems, and from service providers involved in authentication, hosting, payment, app-store distribution, fraud prevention, or customer support.
5. How we use information
To provide, personalize, and maintain the website, accounts, apps, learning functions, and purchased access.
To authenticate users, preserve learning progress across authorized devices, and provide offline and synchronization functions.
To process and document purchases, refunds, revocations, and entitlement changes.
To answer inquiries, provide support, and send service-related messages.
To prevent fraud, account sharing, automated extraction, attacks, and other misuse; investigate security incidents; and enforce our terms.
To comply with legal obligations, protect legal claims, and improve the reliability and learning effectiveness of our services.
6. Cookies, local storage, and analytics
We use only cookies or similar local-storage technologies that are reasonably necessary for functions such as authentication, security, language selection, purchased access, and remembering progress or settings. We do not currently use advertising trackers or cross-context behavioral advertising on certiacademy.com. If we introduce optional analytics or advertising technologies, we will update this Policy and provide any legally required notice or choice before using them.
7. How we disclose information
We disclose personal information only as reasonably necessary to operate our services, complete transactions, comply with law, or protect rights and security. Recipients may include:
STRATO, which hosts our websites, email, application interfaces, databases, and related infrastructure in Germany.
Paddle for eligible web purchases, and Apple or Google for purchases made through their app stores. These providers may act as independent businesses for their own payment, tax, fraud-prevention, receipt, and store-compliance activities.
Technical, email, security, professional, and support providers that process information under appropriate contractual or legal obligations.
Government authorities, courts, advisers, or other parties when reasonably necessary to comply with law, protect users, establish or defend legal claims, or investigate fraud or security incidents.
A successor or transaction partner in a merger, financing, reorganization, sale of assets, or similar corporate transaction, subject to appropriate confidentiality and legal safeguards.
8. No sale of personal information
CertiAcademy does not sell personal information for money and does not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising. If these practices change, we will provide the notices and opt-out mechanisms required by applicable law, including recognition of qualifying opt-out preference signals where required.
9. International processing
CertiAcademy Corp is located in the United States, while our primary hosting and email infrastructure is located in Germany. Payment and app-store providers may process information in the United States, the European Economic Area, the United Kingdom, and other countries. Privacy laws may differ between countries. Where required, we use contractual, organizational, and other lawful safeguards for international transfers.
10. Retention
We keep personal information only for as long as reasonably necessary for the purposes described above, required by law, or needed to establish, exercise, or defend legal claims. In general:
Hosting logs are available for approximately six weeks; our own routine application and security logs are generally deleted after 30 days unless an incident requires longer preservation.
Learning progress is generally retained until a deletion request or for up to 24 months of complete inactivity after the end of the last access period.
Device assignments are generally deleted 30 days after the end of the last paid access period, unless needed for a documented misuse or security matter.
Privacy correspondence is generally deleted three years after closure. Ordinary support correspondence is generally retained for three years; transaction, tax, and business records may be retained longer as required by law.
Confirmed account-deletion requests are generally implemented in active systems within 30 days. Temporary backup copies may remain until the applicable backup cycle expires.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport, access controls, server-side verification of purchases, hashed authentication tokens, account separation, logging, backups, and security monitoring. No method of transmission or storage is completely secure, and we cannot promise absolute security.
12. Your privacy rights
Depending on where you live and whether the relevant law applies, you may have the right to confirm whether we process your information; access or obtain a portable copy; correct inaccuracies; request deletion; opt out of a sale, targeted advertising, or certain profiling; restrict or object to certain processing; withdraw consent; and appeal a denied request. We will not unlawfully discriminate against you for exercising a privacy right.
Submit a request to privacy@certiacademy.com. Describe the right you wish to exercise and the account or email address involved. We may take proportionate steps to verify your identity or an authorized agent. If we deny a request, you may appeal by replying to our decision with the word “Appeal.” You may also contact the competent state regulator or attorney general.
13. California notice
For California residents, the categories collected during the preceding 12 months are described in Section 3; sources are described in Section 4; business and commercial purposes are described in Section 5; and recipient categories are described in Section 7. We do not sell or share personal information as those terms are used for cross-context behavioral advertising under California law. We do not knowingly sell or share the personal information of consumers under 16.
14. Children
Our services are intended for adults and are not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information to us, contact privacy@certiacademy.com so that we can investigate and delete it as appropriate.
15. Third-party services
Paddle, Apple, Google, and other linked services maintain their own privacy policies and control information they collect for their independent purposes. We encourage you to review their notices before using those services.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes in our services, providers, or legal obligations. We will post the updated version here and revise the date above. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required by law.
17. Contact
Privacy questions and requests: privacy@certiacademy.com General support: support@certiacademy.com CertiAcademy Corp, 7901 4TH ST N, STE 300, ST. PETERSBURG, FL 33702, United States