Privacy Policy
Effective 1 September 2026 · Last updated 1 September 2026
1. Controller
TukeWIN s. r. o. (trading as TukeWIN), Kukučínova 15854/10A, 080 05 Prešov, Slovak Republic. Registered in Obchodný register Okresného súdu Prešov, oddiel Sro, vložka č. 48211/P. IČO 56 356 749, DIČ 2122289312, IČ DPH SK2122289312. Managing director: Oliver Javorský.
Contact for privacy matters: javorsky@tukewin.com. Postal contact: as above. We have not appointed a Data Protection Officer because our processing does not meet the criteria of Article 37(1) GDPR.
2. Scope
This Policy covers (a) tukewin.com and its subdomains including ai.tukewin.com, (b) the client area at tukewin.com/client, (c) the course platform at tukewin.com/webpanel and the checkout flow for the paid AI course.
3. Personal data we process, purposes, and legal bases
3.1 Marketing website
Data: IP address, User-Agent, requested URL, timestamp,
referrer, response status (transient server and Cloudflare edge logs).
Purpose: security, abuse detection, service
operation.
Legal basis: legitimate interest, Article 6(1)(f)
GDPR.
Retention: Cloudflare edge logs per Cloudflare
retention (currently up to 30 days on the default Analytics tier); our
origin does not persist raw access logs beyond 30 days.
3.2 Contact form (/contact)
Data: whatever you send (typically your email or phone
number, and the free-text message); your IP address at submission time;
timestamp.
Purpose: reply to your enquiry and keep a record
of the conversation.
Legal basis: pre-contractual measures at your
request, Art. 6(1)(b); otherwise legitimate interest, Art. 6(1)(f).
Retention: 3 years from the last message, then
deleted.
3.3 AI course purchase (Stripe Checkout)
Data collected by us: email address, purchase amount,
currency, Stripe checkout session ID, Stripe payment intent ID, purchase
status, timestamps.
Data collected by Stripe on our behalf: your name,
billing address, card details, other payment data. We never see your
card number. Stripe is the controller for those fields; see
https://stripe.com/privacy.
Purpose: conclude and perform the course-access
contract, invoice you, comply with Slovak accounting law.
Legal basis: performance of contract, Art. 6(1)(b);
legal obligation, Art. 6(1)(c) (Act No. 431/2002 Z. z. on accounting,
10-year record-keeping).
Retention: purchase and invoicing records 10 years
from the end of the accounting year; marketing metadata 24 months.
3.4 Course account and sessions (/webpanel)
Data: email; bcrypt password hash; invite-code SHA-256
hash only (raw code was emailed once); session ID, IP address, User-Agent,
created/expires/revoked timestamps; last-login timestamp; concurrent-session
events; playback progress (video ID + last position seconds).
Purpose: authenticate you, protect the account,
allow you to resume videos, enforce the single-user licence.
Legal basis: performance of contract, Art. 6(1)(b);
legitimate interest, Art. 6(1)(f) (anti-sharing prohibited in the Terms).
Retention: duration of account + 24 months after
last login, then deletion. You may request deletion at any time (section 8).
3.5 Course video access log (DRM / anti-tamper)
Data: user ID, video ID, event kind (manifest / key /
segment / stream / denied), IP, User-Agent, timestamp.
Purpose: enforce anti-sharing terms, detect
concurrent-session abuse, incident response.
Legal basis: legitimate interest, Art. 6(1)(f).
Balancing test: narrow interest (paid single-user licence), short
retention, minimal data.
Retention: 12 months.
3.6 Client area (business clients, /client)
Does not apply to buyers of the 199.99 EUR course. For clients under a service contract we process: name, company details, email, password hash, sessions, uploaded files, project updates, invoices (including IBAN/BIC), onboarding acknowledgements. Legal bases: performance of contract, legal obligation, legitimate interest. Retention: accounting records 10 years; other data duration of contract + 3 years.
3.7 Course-access alerts (anti-sharing)
What: when the system detects a shared account (more
concurrent sessions than allowed, or too many distinct IPs in a short
window), an alert is sent to our internal operations channel on Discord.
The alert contains an internal account identifier and the session IPs.
Purpose: intervene against suspected account
sharing before it escalates.
Legal basis: legitimate interest, Art. 6(1)(f).
Recipient: Discord Inc. (see section 5). Retention
on Discord: 30 days rolling; our channel retention is manual.
Optional processor: disabled by default; runs only
when a webhook URL is configured.
4. Automated decision-making
We do not carry out automated decision-making with legal or similarly significant effects under Article 22 GDPR. Suspected account sharing is flagged automatically but every action against the account is reviewed by a human.
5. Recipients and processors
- Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (US). SCCs in place under the Stripe DPA.
- Cloudflare, Inc. (US) and Cloudflare Germany GmbH. CDN, DDoS protection, TLS termination, edge network. SCCs plus EU-US Data Privacy Framework certification. Your browser is also asked by Cloudflare to report network errors to https://a.nel.cloudflare.com via the standard NEL / Report-To mechanism.
- Seznam.cz, a.s. (Czech Republic). Outbound SMTP relay for invite codes and receipts; inbound mail routing for @tukewin.com. Intra-EU.
- Namecheap, Inc. (US). Domain registrar. SCCs.
- Evoxt Limited (Hong Kong / United Kingdom). Application hosting, database, and file storage on a dedicated Ubuntu VPS. SCCs plus supplementary measures (encrypted at-rest storage; access limited to the operator).
- Discord Netherlands B.V. and Discord, Inc. (US). Internal operator alert channel, conditional (only when the anti-sharing webhook is enabled). SCCs.
- Let's Encrypt / Internet Security Research Group (US). TLS certificate issuance for the origin; no visitor personal data.
- Slovak tax authority, financial administration, auditors, and courts, where required by law.
We do not sell or rent your data.
6. International transfers
Transfers to processors outside the EU/EEA (Stripe US, Cloudflare US, Namecheap US, Discord US, Evoxt HK/UK, Let's Encrypt US) rely on Standard Contractual Clauses (Commission Decision 2021/914) plus the supplementary measures those providers publish. Copies available on request.
7. Retention (summary)
| Category | Retention |
|---|---|
| Access / edge logs | up to 30 days |
| Contact form | 3 years from last message |
| Purchase & invoice records | 10 years (Act 431/2002 Z. z.) |
| Course account & sessions | account duration + 24 months |
| Course video access log | 12 months |
| Login attempts | 90 days |
| Discord alerts | 30 days |
8. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to invoicing retention), restriction (Art. 18), portability (Art. 20), object (Art. 21), withdraw consent (Art. 7(3)). You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, https://dataprotection.gov.sk, +421 2 3231 3214).
Send requests to javorsky@tukewin.com; we reply within one month.
9. Cookies
Only strictly necessary cookies (session cookies at /webpanel, /client,
/blog/admin used to keep you signed in and to protect against CSRF, plus
Cloudflare's __cf_bm bot-mitigation cookie). No analytics,
advertising, or third-party tracking. No cookie banner is required
(Recital 66 and Article 5(3) ePrivacy Directive as implemented in
Section 55 Act 452/2021 Z. z.).
10. Security
Passwords hashed with bcrypt; TLS terminated at Cloudflare and re-encrypted to origin (Full Strict) with a Cloudflare Origin Certificate; HSTS max-age 31,536,000 with includeSubDomains; sessions with fixed lifetime and sign-out invalidation; video keys server-side only and served via short-TTL signed URLs bound to session and IP.
11. Changes
We publish the effective date at the top. Material changes are notified to registered users by email.