Política de Privacidade
1. Data Controller
Controlador de dados: CoreMind Systems, CVR 45753255, Juvelvej 80, 8700 Horsens, Dinamarca.
2. Data We Collect
Coletamos: endereço de email, nome (opcional), dados de pagamento (processados pelo Stripe), progresso nos cursos e resultados de exames.
3. Legal Basis
Base legal: Execução de contrato (Art. 6.1.b) para acesso ao curso, interesse legítimo (Art. 6.1.f) para melhoria da plataforma.
4. Data Processors (Sub-processors)
We use the following sub-processors to deliver the service. Changes are notified with at least 30 days' written notice. Cloudflare processes web requests on their global network (330+ cities). Your database is stored in Western Europe (Cloudflare D1). Data transfers are covered by the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs).
| Sub-processor | Purpose | Jurisdiction | Transfer basis |
|---|---|---|---|
| Stripe, Inc. | Payment processing | USA | EU-US DPF + SCCs |
| Cloudflare, Inc. | CDN, DNS, D1 database, Workers | USA/EU | EU-US DPF + SCCs |
| Proton AG | Transactional emails | Switzerland | EU adequacy decision |
5. No Tracking
Não usamos cookies de rastreamento, analytics ou publicidade de terceiros. Apenas cookies essenciais.
6. On-device AI and TTS
The AI assistant (Anker) and read-aloud feature (Anker TTS) run 100% locally in your browser. No conversation data, text, or audio is sent to our servers. The AI model (Llama 3.2 3B via WebLLM) and TTS model (Piper WASM) are downloaded once and stored in your browser's cache (Cache API/OPFS). You can delete the models via browser settings.
7. Your Rights (GDPR Art. 15-22)
Seus direitos (Art. 15-22): Acesso, retificação, exclusão, restrição, portabilidade, oposição. Contato: privacy@coremindx.com
8. Referral Program
When you share your referral link and a friend signs up, we store the relationship (your user ID + their user ID) under legitimate interest (GDPR Art. 6(1)(f)) for credit calculation. Your friend sees that you invited them. A referral cookie (ae_ref) is stored for 30 days. Credits expire after 90 days.
9. Data Breach Notification
In the event of a personal data breach, we will notify affected users without undue delay and within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33-34 and the Danish Data Protection Act (LBK no. 289/2024).
10. Deletion
You can request deletion of your account and all associated data at any time by contacting privacy@coremindx.com. We delete all personal data within 30 days. Excepted is data we are legally required to retain (Danish Bookkeeping Act: 5 years for transaction data).
11. Data Retention
| Data category | Retention period | Basis |
|---|---|---|
| Account data (email, name) | Until deletion request + 30 days | Contract |
| Course progress | Account lifetime | Contract |
| Transaction records | 5 years (Bookkeeping Act) | Legal obligation |
| Exam results | Account lifetime | Contract |
| Server logs (IP) | 90 days | Legitimate interest |
12. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you (GDPR Art. 22). The AI assistant (Anker) is a decision-support tool. Exams are graded automatically against predefined answer keys, but you can always retake an exam.
13. International Rights
In addition to your GDPR rights, additional rights may apply depending on your location:
Your data is protected under UK GDPR. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. Data transfers Denmark-UK are covered by the EU adequacy decision (renewed December 2025, valid until December 2031).
We do not sell or share your personal information as defined by the California Consumer Privacy Act (CCPA/CPRA). We do not use tracking technologies for cross-context behavioral advertising. Contact privacy@coremindx.com for questions about your California privacy rights.
Your data is protected under the LGPD. You have the right to access, correction, anonymization, deletion, and portability (LGPD Art. 17-22). Complaints may be directed to the ANPD (Autoridade Nacional de Proteção de Dados). Contact: privacy@coremindx.com.
Your personal information is transferred to Denmark (EU) for processing. This transfer is protected by contractual safeguards. You may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Your data is processed in accordance with the Australian Privacy Principles (APPs). Personal information is transferred to Denmark (EU), USA (Stripe, Cloudflare), and Switzerland (Proton) with contractual safeguards. You have the right to access and correction. The AI assistant (Anker) runs locally in your browser and sends no data to servers. Complaints may be directed to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Your data is protected under the Act on the Protection of Personal Information (APPI). Personal information is transferred to: Denmark (EU — Japan adequacy decision), USA (Stripe, Cloudflare — contractual safeguards), and Switzerland (Proton — adequacy decision). You have the right to disclosure, correction, and cessation of use. Complaints may be directed to the Personal Information Protection Commission (PPC).
Your data is protected under the Personal Information Protection Act (PIPA). Personal information is transferred to Denmark (EU) for processing with contractual safeguards. You have the right to access, correction, deletion, and suspension of processing. The AI assistant runs locally and does not process personal information on servers. Complaints may be directed to the Personal Information Protection Commission (PIPC).
14. Complaints
Reclamações: Agência Dinamarquesa de Proteção de Dados (Datatilsynet). — Datatilsynet
Last updated: 2026-04-06