Legal
Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how Body Imaging Course (“we”, “us”) collects, uses and protects your personal data when you visit bodyimagingcourse.com (“the Site”) and use the online course. This policy complies with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and the Italian Privacy Code (D.Lgs. 196/2003 as amended).
1. Data controller
The data controller is the owner of this Site, whom you can contact through our contact form. For any privacy-related request you can also write to the email address listed on the contact page.
2. Data we collect
- Account data — your name and email address when you register, managed through our authentication provider (Appwrite).
- Payment data — subscriptions and payments are processed by Stripe. We do not store your card details; Stripe handles them securely.
- Course data — your progress through lessons and any reports you write.
- Contact data — the name, email address and message you submit through the contact form.
- Usage data — anonymous analytics collected via Google Tag Manager and Google Analytics, and advertising measurement via the Meta Pixel, only if you consent via the cookie banner.
3. Legal basis for processing (art. 6 GDPR)
We process your personal data on the following legal bases:
- Performance of a contract (art. 6.1.b) — to provide the course you registered for, manage your account, process payments, and deliver course content.
- Consent (art. 6.1.a) — for analytics and advertising cookies (Google Tag Manager / Google Analytics, Meta Pixel), set only after you click “Accept All” on the cookie banner. You can withdraw consent at any time by clearing your browser data for this Site.
- Legitimate interest (art. 6.1.f) — to respond to enquiries sent via the contact form, to send follow-up emails about the course you signed up for, and to maintain the security and proper functioning of the Site.
4. How we use your data
We use your data to provide and improve the course, manage your account and access, process payments, respond to your enquiries, send relevant follow-up emails about the course, and — only with your consent — measure how the Site is used. We do not sell your personal data, and we do not use it for automated decision-making or profiling.
5. Third-party services
We rely on trusted providers to run the service. Each processes data on our behalf under their own privacy terms:
- Appwrite — authentication, user database, and course data storage (hosted in the EU).
- Stripe — payment processing (PCI-DSS Level 1 certified).
- Resend — transactional and follow-up email delivery.
- Cloudflare R2 — video content storage and delivery (hosted in the EU).
- Google (Tag Manager / Analytics) — website analytics, only with your consent.
- Meta Platforms (Meta Pixel) — measures which visits follow a Facebook or Instagram ad, only with your consent.
- Render — hosting platform for the web application (hosted in the EU, Frankfurt).
6. Data retention
- Account data — retained for as long as your account is active. If you request deletion, your account is removed within 30 days.
- Payment records — retained for the period required by tax and accounting laws (typically 10 years under Italian law).
- Contact form messages — retained for up to 2 years after the last exchange.
- Analytics data — Google Analytics retains data for 14 months by default.
- Email logs — we keep a record of which follow-up emails were sent, to avoid sending duplicates. These logs contain only a user identifier and the type of email sent, not the content.
7. International data transfers
Some of our providers (Stripe, Google, Cloudflare) may transfer data outside the European Economic Area. When this happens, we ensure adequate safeguards are in place — such as Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission — as required by articles 44–49 of the GDPR.
8. Your rights under the GDPR
Under the GDPR you have the following rights:
- Right of access (art. 15) — you can ask us what personal data we hold about you and receive a copy.
- Right to rectification (art. 16) — you can ask us to correct inaccurate or incomplete data.
- Right to erasure (art. 17 — “right to be forgotten”) — you can ask us to delete your personal data, subject to legal obligations that require us to keep certain records (e.g. payment records for tax purposes).
- Right to restriction of processing (art. 18) — you can ask us to limit how we use your data in certain circumstances.
- Right to data portability (art. 20) — you can ask us to transfer your data to another service in a structured, commonly used format.
- Right to object (art. 21) — you can object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent (art. 7.3) — where processing is based on your consent (e.g. analytics cookies), you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
9. Right to lodge a complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The Italian Data Protection Authority (“Garante per la protezione dei dati personali”) can be contacted at garanteprivacy.it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The latest version is always available at this page. Significant changes will be communicated via email or a notice on the Site.
11. Contact
For any privacy question or to exercise your rights, please use our contact form. We will respond within 30 days as required by the GDPR.