Legal
GDPR Notice
Last Updated: January 01, 2023
This GDPR Notice applies to individuals located in the European Economic Area (EEA) or the United Kingdom who use the services of LUNERA for Digital Solutions (doing business as Sa3a Coaching Academy). It explains how we process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR.
1. Data Controller
The data controller responsible for your personal data is:
- Entity: LUNERA for Digital Solutions
- Trading name: Sa3a Coaching Academy
- Address: 24 Khalid Ibn Wallid, Alexandria, Egypt
- Email: support@sa3acoaching.com
2. What Personal Data We Collect
We collect the following categories of personal data:
- Identity data: full name, National ID document (for identity verification)
- Contact data: email address, phone number, WhatsApp number
- Authentication data: hashed passwords, OAuth provider identifiers
- Payment data: payment confirmation records (we do not store raw card numbers)
- Usage data: course progress, session attendance, assignment submissions
- Technical data: IP address, browser type, session cookies
- Audio/video data: application recordings, coaching session recordings (with explicit consent)
3. Legal Bases for Processing
We rely on the following legal bases under Article 6 GDPR:
- Contract performance (Art. 6(1)(b)): Processing necessary to deliver the educational services you enrolled in, including account management, session scheduling, and progress tracking.
- Legal obligation (Art. 6(1)(c)): Processing required to comply with applicable law, including identity verification requirements.
- Legitimate interests (Art. 6(1)(f)): Fraud prevention, platform security, and service improvement — where these interests are not overridden by your rights.
- Consent (Art. 6(1)(a)): For optional processing such as marketing communications and audio/video recording of sessions. You may withdraw consent at any time.
4. Special Category Data
We collect National ID documents for identity verification purposes. This constitutes special category data under certain interpretations of Article 9 GDPR. We process this data solely to verify your identity and comply with our platform security requirements. ID documents are stored securely and are accessible only to authorised administrators.
5. International Data Transfers
Sa3a Coaching Academy is based in Egypt. If you are located in the EEA or UK, your personal data will be transferred to and processed in Egypt. Egypt is not currently designated as an adequate country by the European Commission. We rely on Standard Contractual Clauses (SCCs) and appropriate safeguards when transferring data to Egypt.
We use the following third-party processors who may process your data in non-EEA countries:
- Supabase / PostgreSQL: Cloud database hosting (EU region where available)
- Microsoft SharePoint: Video and file hosting
- Google OAuth: Authentication provider
- ClickUp: Internal task management (administrative data only)
6. Retention Periods
- Account data: Retained for the duration of your enrollment plus 3 years
- Payment records: Retained for 7 years for tax and accounting purposes
- National ID photos: Deleted within 6 months of identity verification, unless required by law
- Session recordings: Retained for 12 months, then deleted unless you request earlier deletion
- Application recordings: Retained for 6 months from application date
7. Your Rights Under GDPR
You have the following rights under the GDPR:
- Right of access (Art. 15): Request a copy of all personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your data (subject to legal retention requirements)
- Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time where processing is consent-based
- Right not to be subject to automated decisions (Art. 22): We do not make solely automated decisions that significantly affect you
To exercise any of these rights, contact us at support@sa3acoaching.com. We will respond within 30 days.
8. Cookies and Tracking
We use essential session cookies for authentication and platform functionality. We do not use third-party advertising or tracking cookies. For full details, see our Cookie Policy.
9. Supervisory Authority
If you are located in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
If you are located in the UK, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.
10. Contact Us
For any GDPR-related queries or to exercise your rights, contact:
- Email: support@sa3acoaching.com
- Post: LUNERA for Digital Solutions, 24 Khalid Ibn Wallid, Alexandria, Egypt
