Privacy Policy - Fili School

1. Controller

Controller under the GDPR is Maximus GmbH, Gottfriedstraße 1, 48151 Münster, Deutschland. Contact: [email protected].

2. Categories of data

  • Account data: name, email address, login details, language, subscription status.

  • Billing and transaction data: plan, payment status, invoice data, Stripe customer references, tax-related records.

  • Usage data: viewed content, course/activity progress, favorites, settings, support interactions, consent records.

  • Technical data: IP address, device, browser, operating system, log files, security events, cookie identifiers.

  • Voluntary communications: messages, feedback, support requests, uploaded files if such features exist.

3. Purposes and legal bases

  • Providing the service, accounts, subscriptions, and content access - performance of contract, Art. 6(1)(b) GDPR.

  • Payment, invoicing, tax and accounting - contract and legal obligations, Art. 6(1)(b) and (c) GDPR.

  • Security, fraud prevention, abuse detection and service reliability - legitimate interests, Art. 6(1)(f) GDPR.

  • Customer support and communication - contract or legitimate interests.

  • Analytics, marketing cookies, push/email marketing where used - consent, Art. 6(1)(a) GDPR and § 25 TDDDG where applicable.

  • Legal claims and compliance - legal obligations and legitimate interests.

4. Children and minors

Where the service is used by students or minors under an adult account, the adult account holder should avoid entering unnecessary personal data of minors.

5. Payment processing with Stripe

We use Stripe for payment processing, subscription management, fraud prevention, and payment-related records. Payment data is processed by Stripe and may be transferred to Stripe entities or processors outside the EU where legally permitted. We do not store full card numbers. Stripe's own privacy notices apply to Stripe's processing.

6. Hosting and technical providers

We may use hosting, database, email, analytics, customer support, app distribution, and security providers. These providers process data only as needed to operate, secure, and improve the service and, where required, under data processing agreements.

7. Cookies and similar technologies

Essential cookies and local storage may be used to provide login, security, language, consent and subscription functions. Non-essential analytics or marketing technologies are used only where legally permitted, usually after consent. Details are provided in the Cookie Settings page.

8. International transfers

Where data is transferred outside the EEA, we rely on appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions, technical safeguards, or other lawful transfer mechanisms.

9. Retention

We retain personal data only as long as necessary for the purposes described above. Account data is generally retained while the account exists. Billing, tax, and commercial records may be retained for statutory retention periods. Security logs are retained for a limited period unless needed for investigation or legal claims.

10. User rights

Users have the right to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Users also have the right to lodge a complaint with a supervisory authority, especially in their EU member state of residence or in Germany.

11. No sale of personal data

We do not sell personal data. We share data only with processors, payment providers, legal or tax advisors, authorities where required, or business partners where necessary and lawful.

12. Security

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

13. Contact

For privacy questions or to exercise rights, contact: [email protected]