Last updated: [REVIEW — insert date]
The data controller responsible for the processing of your personal data on this website is:
[REVIEW — Company name]
[REVIEW — Street address]
[REVIEW — City, postal code, Germany]
Email: [REVIEW — privacy@kursa.ai]
When you create an account, we collect your email address, name, and password (stored as a cryptographic hash). If you sign in via a third-party provider (e.g. Google), we receive your name and email from that provider.
During onboarding and in your account settings, you may provide your nationality, current country of residence, study level, and subject interests. This data is used to personalise your experience.
We collect information about how you interact with our website, including pages visited, courses and universities viewed, search queries, and clicks. This data is collected via server-side logging and, where you have given cookie consent, client-side analytics.
When you visit our website, your browser automatically transmits certain technical data, including your IP address, browser type, operating system, and referring URL. This data is processed for security purposes and to ensure the functionality of our services.
If you consent to lead sharing (offered during onboarding or in your account privacy settings), we may share your name, email, nationality, study level, and subject interests with universities that offer programs matching your profile. Universities may use this information to contact you with relevant course information.
You can withdraw this consent at any time in your Account > Privacy settings. Upon withdrawal, we will stop sharing your data with new universities. Data already shared with universities is subject to their own privacy policies.
We use cookies that are essential for our website to function, such as session authentication and onboarding state. These do not require your consent.
We log basic page view data on our servers to understand how our service is used and to improve it. For anonymous visitors, we create a temporary session identifier by hashing your IP address and browser type with a daily rotating key. This hash cannot be reversed to reveal your identity and expires every 24 hours, so we cannot track you across days. For logged-in users, page views are associated with your account as part of the service we provide. No data is stored on your device for this purpose. Legal basis: legitimate interest (Art. 6(1)(f)) for anonymous visitors; contract performance (Art. 6(1)(b)) for authenticated users.
With your consent, we set additional cookies to personalize your experience — for example, remembering your preferences across visits and providing more relevant course suggestions. We request your consent via our cookie banner before any such cookies are set. You can change your preference at any time via the “Cookie Preferences” link in our footer.
Under the GDPR, you have the right to:
To exercise any of these rights, contact us at [REVIEW — privacy@kursa.example.com].
We retain your account data for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, except where retention is required by law. Consent records are retained for documentation purposes as required by Art. 7(1) GDPR.
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (TLS), hashed passwords, and access controls.
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is:
[REVIEW — Insert relevant German state data protection authority, e.g. “Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg”]
We may update this privacy policy from time to time. We will notify registered users of material changes via email. The current version is always available at this URL.