Privacy Policy
Draft pending legal review. This policy describes how the site actually processes data today; the exact wording, retention periods, and any jurisdiction-specific clauses should be confirmed by a qualified advisor before publication.
Who we are
This website (learnfromsaki.com) is operated by Cognare s.r.o., a company established in the European Union and registered for VAT. Cognare is the data controller for the personal data described in this policy. For data requests, contact us through the services page or the address listed in our Impressum.
What data we collect
- Account data — when you register, we store your email address, a display name, an optional username, and a securely hashed password. Accounts created through GitHub or Google instead store the identifier those providers return.
- Authentication data — login sessions, and, if you add one, WebAuthn passkeys (a public key and device metadata; never your biometrics).
- Content you submit — blog comments and any messages sent through the contact / service-request forms.
- Preferences — settings such as your chosen language. Your theme (light/dark) is stored only in a cookie on your own device.
- Technical data — for spam protection and security we record the IP address and user-agent attached to form submissions, and rate-limiting counters.
- Usage statistics — which pages are viewed, roughly where the visit came from, and the browser and device type, collected by our own self-hosted Matomo with your IP address anonymised. It sets no cookies, so it cannot follow you across visits or across other sites.
We do not sell your data, and we do not use it for advertising.
Why we process it, and the lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Operating your account and serving gated content | Performance of a contract |
| Sending transactional email (verification, password reset, receipts) | Performance of a contract |
| Spam, abuse, and fraud prevention on public forms | Legitimate interests |
| Cookieless, self-hosted usage statistics | Legitimate interests |
| Comments and other content you choose to publish | Consent |
| Non-essential cookies (e.g. third-party widgets) | Consent |
| Complying with tax and accounting law | Legal obligation |
Migration from the previous WordPress site
This platform replaces our previous WordPress-based site. The accounts of existing members (email address, display name, username, and password hash) were imported into the new system. The lawful basis for this migration is the continuity of the existing service relationship — i.e. performance of the contract / our legitimate interest in continuing to provide the service members already had. No new categories of data were created by the migration; legacy password hashes are re-hashed to a modern algorithm on your first successful login. If you no longer wish to keep your account, you can delete it at any time (see Your rights below).
Cookies
We use only strictly necessary cookies by default — your login session, your cookie-consent choice, and display preferences you set yourself (your light/dark theme, and how large the example cards are drawn). The one non-essential item on this site is the Cloudflare Turnstile check on the public contact forms and the sign-up form; it is loaded only with your consent, which you can give or withhold through the cookie banner, or give at the form itself when you need the check in order to submit. Until then no request is made to Cloudflare. Our usage statistics set no cookie at all and are therefore outside the banner — see the Cookie Policy for details.
Sharing and processors
We share data only with the processors needed to run the service: our email/SMTP provider (transactional email), Brevo (the newsletter list, if you subscribe), Cloudflare Turnstile (bot protection on public forms), and, when paid plans launch, a payment provider. Each processes data on our behalf under a data-processing agreement.
Analytics is not among them. Matomo runs on our own server in the EU, so usage statistics are never transferred to a third party and never leave the Union.
One transfer does leave the Union, and only if you allow it. Cloudflare is a provider in the United States, so loading the Turnstile check sends your IP address and browser information there. Nothing is sent unless you have consented to the check, and consent can be withdrawn at any time through the footer's "Cookie preferences" control. No other processing described here involves a transfer outside the EU/EEA.
Retention
We keep account data for as long as your account exists. Contact-form submissions are kept while they are relevant to handling your enquiry. When you delete your account, your personal data is erased or anonymised as described below.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. You can exercise the main rights directly from your account:
- Access / portability — download a machine-readable copy of your data from your account page ("Download my data").
- Erasure — delete your account from your account page; this cascades across your profile, preferences, sessions, credentials, and passkeys, and anonymises content you posted.
- Rectification — edit your display name, email, and password in your account.
For any other request, or to lodge a complaint, contact us — you also have the right to complain to your local data-protection authority.
Changes
We may update this policy; the "updated" date above reflects the latest version.
