Privacy Policy - Fili School
1. Controller
Controller under the GDPR is Maximus GmbH, Gottfriedstraße 1, 48151 Münster, Deutschland. Contact: [email protected].
2. Categories of data
Account data: name, email address, login details, language, subscription status.
Billing and transaction data: plan, payment status, invoice data, Stripe customer references, tax-related records.
Usage data: viewed content, course/activity progress, favorites, settings, support interactions, consent records.
Technical data: IP address, device, browser, operating system, log files, security events, cookie identifiers.
Voluntary communications: messages, feedback, support requests, uploaded files if such features exist.
3. Purposes and legal bases
Providing the service, accounts, subscriptions, and content access - performance of contract, Art. 6(1)(b) GDPR.
Payment, invoicing, tax and accounting - contract and legal obligations, Art. 6(1)(b) and (c) GDPR.
Security, fraud prevention, abuse detection and service reliability - legitimate interests, Art. 6(1)(f) GDPR.
Customer support and communication - contract or legitimate interests.
Analytics, marketing cookies, push/email marketing where used - consent, Art. 6(1)(a) GDPR and § 25 TDDDG where applicable.
Legal claims and compliance - legal obligations and legitimate interests.
4. Children and minors
Where the service is used by students or minors under an adult account, the adult account holder should avoid entering unnecessary personal data of minors.
5. Payment processing with Stripe
We use Stripe for payment processing, subscription management, fraud prevention, and payment-related records. Payment data is processed by Stripe and may be transferred to Stripe entities or processors outside the EU where legally permitted. We do not store full card numbers. Stripe's own privacy notices apply to Stripe's processing.
6. Hosting and technical providers
We may use hosting, database, email, analytics, customer support, app distribution, and security providers. These providers process data only as needed to operate, secure, and improve the service and, where required, under data processing agreements.
7. Cookies and similar technologies
Essential cookies and local storage may be used to provide login, security, language, consent and subscription functions. Non-essential analytics or marketing technologies are used only where legally permitted, usually after consent. Details are provided in the Cookie Settings page.
8. International transfers
Where data is transferred outside the EEA, we rely on appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions, technical safeguards, or other lawful transfer mechanisms.
9. Retention
We retain personal data only as long as necessary for the purposes described above. Account data is generally retained while the account exists. Billing, tax, and commercial records may be retained for statutory retention periods. Security logs are retained for a limited period unless needed for investigation or legal claims.
10. User rights
Users have the right to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Users also have the right to lodge a complaint with a supervisory authority, especially in their EU member state of residence or in Germany.
11. No sale of personal data
We do not sell personal data. We share data only with processors, payment providers, legal or tax advisors, authorities where required, or business partners where necessary and lawful.
12. Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
13. Contact
For privacy questions or to exercise rights, contact: [email protected]
