Last updated: 2026-05-28
This Privacy Policy explains how Bourdak Corporation Ltd ("Bourdak", "we", "us") collects, uses, shares and protects your personal data when you use the Bourdak platform (bourdak.com and related services). It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018.
1. Who we are
Bourdak Corporation Ltd is a private limited company registered in England and Wales (Companies House number 16961184). Our registered office is 124 City Road, London EC1V 2NX, United Kingdom. We are the "controller" of your personal data for the purposes of UK GDPR. Our supervisory authority is the UK Information Commissioner's Office (ICO).
2. Data we collect
We collect the following categories of personal data:
- Account data: name, email address, password (stored as a hash by AWS Cognito), preferred language, optional avatar.
- Learning data: courses you view, lessons completed, quiz answers and scores, certificates earned, notes, bookmarks, discussions you post, ratings you give.
- Payment data: for paid plans, your card details are sent directly to Stripe and never stored on our servers. We store your subscription plan, status, dates, and the Stripe customer reference.
- Technical data: IP address, user-agent string, device/browser type, timestamps. Used for security, abuse prevention, and audit logging.
- Communication data: transactional emails sent to you (welcome, password reset, workshop reminders) and, if you opted in, newsletter subscription state.
- Cookies / similar technologies: see Section 8.
3. Lawful basis for processing
We rely on the following lawful bases under Article 6 UK GDPR:
- Contract (Article 6(1)(b)): to create and operate your account, deliver the courses you signed up for, process your payments, and provide customer support.
- Consent (Article 6(1)(a)): for marketing emails (newsletter), for non-essential cookies and analytics, and for any optional features you turn on. You can withdraw consent at any time without affecting the lawfulness of past processing.
- Legitimate interests (Article 6(1)(f)): to keep the platform secure, detect and prevent fraud and abuse, monitor errors (when you consent to analytics), and improve the service. We have weighed our interests against your rights.
- Legal obligation (Article 6(1)(c)): to keep certain financial records (tax law), respond to lawful requests, and meet our duties under UK GDPR itself.
4. How we use your data
We use your personal data to:
- Create and manage your account, authenticate you, and keep you signed in.
- Deliver the learning content you signed up for and track your progress.
- Issue certificates and other rewards you earn.
- Process payments and manage your subscription via Stripe.
- Send transactional emails (account, security, course-related).
- Send marketing emails — only if you opted in at signup or in your settings.
- Detect, investigate and prevent security incidents, fraud and abuse.
- Comply with our legal obligations (tax, accounting, lawful requests).
- Improve the platform (with your consent to analytics).
5. Who we share your data with (sub-processors)
We share personal data only with the following service providers, each under a written data processing agreement that requires them to protect your data and to act only on our instructions:
We do not sell your personal data. We do not share it with advertising networks. We may disclose data if compelled by a UK court order or to defend our legal rights, but we will resist over-broad requests.
- Amazon Web Services (AWS): all platform hosting and storage (Cognito for authentication, RDS for the database, S3 for files, CloudFront for content delivery, App Runner for the API, DynamoDB for caching, MediaConvert for video processing). Data is hosted in the AWS us-east-1 region (United States). See Section 6 on international transfers.
- Stripe Payments UK, Ltd.: payment processing and subscription billing.
- Resend (Resend, Inc.): delivery of transactional emails.
- Beehiiv, Inc.: newsletter subscription management. Only used if you have opted in to marketing emails.
- Google Analytics (Google Ireland Ltd / Google LLC): usage analytics. Only loaded if you accept analytics cookies. IP addresses are anonymised.
- Sentry (Functional Software, Inc.): error tracking and session replay. Only loaded if you accept analytics cookies. Session replays mask all text and block all media by default.
6. International data transfers
Some of our service providers are based outside the United Kingdom. In particular, our AWS infrastructure is currently hosted in the us-east-1 region (United States), and Stripe, Resend, Beehiiv, Google Analytics and Sentry process data in the US and/or EU. For transfers to the US, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (and, where applicable, the UK Extension to the EU–US Data Privacy Framework) signed with each provider. You can request a copy of the relevant safeguards by emailing undefined.
7. How long we keep your data
We keep personal data only as long as we need it for the purposes set out in this Policy. Specifically:
- Active account data: Until you delete your account
- Deleted account data: Purged from our database immediately on deletion. A minimal deletion record (no personal data) is kept for 24 months in our audit logs.
- Database backups: 7 days (rolling)
- Application & server logs: 30 days
- Audit logs (security events): 24 months
- Payment & invoicing records: 7 years (UK tax law requirement)
- Transactional emails: 12 months
- Newsletter subscribers: Until you unsubscribe
- Error tracking (Sentry): Per Sentry's default retention (typically 30–90 days)
8. Cookies and similar technologies
We use a small number of cookies and similar technologies, grouped into three categories:
You can change your choices at any time via the "Cookie preferences" link in the footer of every page.
- Strictly necessary: session cookies (httpOnly access and refresh tokens for authentication) and a small localStorage entry recording your cookie preferences. These cannot be disabled, as without them the site does not work.
- Analytics: Google Analytics (_ga, _gid) and Sentry. Only set if you accept analytics cookies. Help us understand usage and diagnose errors.
- Marketing: we do not currently set marketing cookies, but this category is reserved for future use and will only ever be activated with your prior consent.
9. Security
We use appropriate technical and organisational measures to protect your data:
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours, and we will notify you directly if the risk to you is high.
- Encryption in transit: all traffic uses HTTPS/TLS.
- Encryption at rest: the database, file storage and caches are encrypted on disk.
- Authentication: passwords are stored as one-way hashes by AWS Cognito, never in plaintext.
- Access control: production systems are accessible only to authorised personnel using least-privilege credentials.
- Monitoring: we maintain audit logs of authentication events, data access, and changes to personal data.
10. Your rights
Under UK GDPR you have the following rights. To exercise any of them, sign in to your account or email us at undefined. We will respond within one month.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk). We would, however, appreciate the chance to address your concerns first.
- Right of access: request a copy of the personal data we hold about you. You can also download it yourself from your account settings.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure: ask us to delete your account and associated data. You can do this yourself from your account settings.
- Right to restrict processing: ask us to stop using your data in certain circumstances.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format (JSON).
- Right to object: object to processing based on legitimate interests, including for direct marketing.
- Right to withdraw consent: where we rely on consent (e.g. marketing, analytics cookies), you can withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
11. Children
The Bourdak platform is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email and/or by an in-app notice. The date at the top of this page shows when it was last updated.
13. Contact us
Questions, requests, or complaints about this policy or your personal data can be sent to undefined. Postal mail can be addressed to: Bourdak Corporation Ltd, 124 City Road, London EC1V 2NX, United Kingdom.