1. Who is responsible for your information?
ORION SKY LABS LTD is the controller of the personal information described in this policy.
Company number: 17370366
Registered in: England and Wales
Privacy contact:
[email protected]
2. Information we may collect
Identity and contact information
Your name, email address and any other contact information you choose to provide.
Free-guide and consent information
Details of the guide requested, date and time of the request, acceptance of required terms, your marketing choice and records showing when that choice was made or changed.
Purchase and transaction information
Product purchased, amount, currency, Stripe customer and transaction identifiers, payment status, discount information, order date and refund or dispute information.
Stripe processes complete payment-card details. We do not ordinarily receive or store your full card number or card security code.
Course delivery and customer-service information
Delivery status, access records, emails, questions, complaints, technical-support information and correspondence.
Website and technical information
Internet Protocol address, browser and device type, requested pages, timestamps, security events, referral information and cookie or similar technology data where used.
3. How we collect information
We collect information:
- directly from you through forms, checkout and correspondence;
- from Stripe when a payment is attempted or completed;
- automatically through hosting, security and server systems; and
- from service providers acting on our instructions.
4. Why we use information and our lawful bases
| Purpose | Information used | Lawful basis |
|---|---|---|
| Deliver a requested free guide | Name, email, request and delivery information | Steps requested by you and our legitimate interest in delivering and securing the resource |
| Process an order and deliver the paid course | Identity, contact, transaction and delivery information | Performance of our contract with you |
| Provide support and respond to complaints | Contact, order and correspondence information | Contract and legitimate interests in customer service and dispute management |
| Maintain tax, accounting and company records | Transaction, invoice and relevant correspondence information | Legal obligation |
| Prevent fraud, abuse and security incidents | Transaction, device, network and security information | Legitimate interests in protecting customers, our systems and our business |
| Send optional marketing emails | Name, email, consent and engagement information | Your consent, where required |
| Improve website and delivery performance | Technical, usage, error and aggregated information | Legitimate interests, and consent where non-essential cookies require it |
| Establish or defend legal claims | Relevant transaction, consent, access and correspondence information | Legitimate interests and legal obligation where applicable |
5. Marketing emails and your choices
Downloading the free guide does not require you to agree to marketing. Where you actively select the optional marketing checkbox, we may send beginner education, security updates and information about Crypto Made Simple products and offers.
You can unsubscribe at any time using the link in an email or by contacting us. Withdrawing marketing consent does not affect delivery of a product you purchased or the lawfulness of earlier processing.
You have an absolute right to object to the use of your personal information for direct marketing. Once you object, we will stop using it for that purpose, although we may retain a minimal suppression record so that we do not contact you again by mistake.
6. Who we may share information with
We do not sell personal information to advertisers. We may share only the information reasonably necessary with:
- Stripe, for payment processing, fraud prevention, receipts, refunds and disputes;
- Zoho, for business email and course-delivery communications;
- Hetzner, which hosts our server and automation infrastructure;
- Cloudflare, for domain, network, performance and security services;
- automation and course-delivery systems operating for us;
- professional advisers such as accountants, lawyers and insurers;
- regulators, courts, tax authorities or law enforcement where legally required; and
- a purchaser or successor if our business or relevant assets are reorganised or sold.
Our service providers are required to handle information only for the relevant service and subject to appropriate contractual and security obligations.
7. International transfers
Some technology and payment providers operate internationally and may process information outside the United Kingdom.
Where a restricted international transfer occurs, we take steps intended to ensure that it is covered by UK adequacy regulations, approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism where applicable.
8. How long we retain information
| Information | Typical retention approach |
|---|---|
| Purchase, transaction and accounting records | Normally six years from the end of the relevant company financial year, or longer where legally required |
| Course delivery, access and customer-support records | For the customer relationship and normally up to six years afterwards where needed for support or legal claims |
| Free-guide delivery records where marketing was not accepted | Normally up to 12 months, unless needed for security, consent evidence or a legal issue |
| Marketing contact and consent records | Until consent is withdrawn, the data is no longer needed, or after an appropriate period of inactivity |
| Unsubscribe and suppression records | A minimal record may be retained for as long as reasonably needed to honour the opt-out |
| Routine server and security logs | Normally up to 12 months, unless an incident requires longer investigation |
We may delete or anonymise information sooner when it is no longer required. We may retain it longer where a legal obligation, dispute, fraud concern or regulatory request requires us to do so.
9. Cookies and similar technologies
We may use technologies required for security, form operation, checkout and website delivery. Where we introduce non-essential analytics, advertising or marketing cookies, we will request consent where the law requires it.
Stripe-hosted checkout may use technologies governed by Stripe's own privacy and cookie information. Further details appear in our Cookie Policy.
10. Security
We use reasonable organisational and technical measures intended to protect information against accidental loss, unauthorised access, alteration or disclosure. These measures include access controls, encrypted connections, restricted administrative access, security monitoring and reputable payment processing.
No internet or storage system can be guaranteed completely secure. Do not send passwords, complete card numbers or identity documents by ordinary email unless we have specifically provided a secure method.
11. Your data-protection rights
Depending on the circumstances, you may have the right to:
- be informed about our use of your information;
- request access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask for deletion in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain information in a portable format;
- withdraw consent at any time where processing relies on consent; and
- complain to a data-protection regulator.
These rights are not absolute and may depend on the reason we process the information. To make a request, email [email protected]. We may need to verify your identity before releasing or changing personal information.
12. Complaints
Please contact us first so that we have the opportunity to address your concern.
You also have the right to complain to the UK Information Commissioner's Office. Information about making a complaint is available from the ICO website.
13. Children
Our paid course is intended for adults aged 18 or over. We do not knowingly seek to collect personal information from children for course purchases or direct marketing.
14. External websites
Our pages may link to third-party websites. Those organisations control their own privacy practices, and you should review their notices before giving them personal information.
15. Changes to this policy
We may update this policy where our products, systems, service providers or legal obligations change. The current version will be published on this page with an updated date.