Legal
Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains how Neuroradiology Course Online (“we”, “us”) collects, uses and protects your personal data when you visit neuroradiologycourseonline.com (“the Site”) and use the online course. This policy complies with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and the Italian Privacy Code (D.Lgs. 196/2003 as amended).
1. Data controller
The data controller is the owner of this Site, whom you can contact through our contact form. For any privacy-related request you can also write to the email address listed on the contact page.
2. Data we collect
- Account data — your name and email address when you register, managed through our authentication provider (Supabase).
- Payment data — subscriptions and payments are processed by Stripe. We do not store your card details; Stripe handles them securely.
- Course data — your progress through lessons and any reports you write.
- Contact data — the name, email address and message you submit through the contact form.
- Email preference and checkout data — whether you consented to course offers and whether a Stripe Checkout Session was started, completed or left unpaid. We do not receive or store card details.
- Usage data — pseudonymous analytics collected via Google Tag Manager and Google Analytics, and advertising measurement via the Meta Pixel and Conversions API, only if you consent via the cookie banner. This can include page and funnel events, UTM parameters, Google Ads click identifiers, Meta click/browser identifiers, IP address and user agent. For completed registration, contact and payment events, email and account identifiers are normalized and SHA-256 hashed before they are sent to Meta.
3. Legal basis for processing (art. 6 GDPR)
We process your personal data on the following legal bases:
- Performance of a contract (art. 6.1.b) — to provide the course you registered for, manage your account, process payments, and deliver course content.
- Consent (art. 6.1.a) — for analytics and advertising cookies (Google Tag Manager / Google Analytics, Meta Pixel / Conversions API), activated only after you click “Accept All” on the cookie banner. You can withdraw consent at any time from the Cookie Policy page; and for promotional course offers, only after you select the optional email consent.
- Legitimate interest (art. 6.1.f) — to respond to enquiries sent via the contact form, to send account-related follow-up emails and one non-promotional reminder about an incomplete checkout, and to maintain the security and proper functioning of the Site.
4. How we use your data
We use your data to provide and improve the course, manage your account and access, process payments, respond to your enquiries, send relevant account follow-up emails, and — only with your specific email consent — send occasional course offers, which may include a promotional offer in an incomplete-checkout reminder. Every such reminder includes a preference link. Only with cookie consent do we measure how the Site is used and attribute registrations, enquiries or confirmed purchases to advertising campaigns. We do not sell your personal data, and we do not use it for automated decision-making or profiling.
5. Third-party services
We rely on trusted providers to run the service. Each processes data on our behalf under their own privacy terms:
- Supabase — authentication, user database, and course data storage (hosted in the EU).
- Stripe — payment processing (PCI-DSS Level 1 certified).
- Resend — transactional and follow-up email delivery.
- Cloudflare R2 — video content storage and delivery (hosted in the EU).
- Google (Tag Manager / Analytics) — website analytics, only with your consent.
- Meta Platforms (Meta Pixel / Conversions API) — measures which consented visits and completed funnel actions follow a Facebook or Instagram ad. Browser and server events share an event identifier so Meta can deduplicate them.
- Render — hosting platform for the web application (hosted in the EU, Frankfurt).
6. Data retention
- Account data — retained for as long as your account is active. If you request deletion, your account is removed within 30 days.
- Payment records — retained for the period required by tax and accounting laws (typically 10 years under Italian law).
- Contact form messages — retained for up to 2 years after the last exchange.
- Analytics data — Google Analytics retains data for 14 months by default.
- Meta event ledger — we retain only the event identifier, a one-way source digest, event type, delivery status and timestamps needed to prevent duplicate conversions. The ledger does not store email, IP address, browser identifiers, access tokens or event payloads.
- Email logs — we keep a record of which follow-up emails were sent, to avoid sending duplicates. These logs contain only a user identifier and the type of email sent, not the content.
- Promotional email consent — retained until you withdraw it. The withdrawal timestamp is retained to ensure that no further checkout reminder or offer is sent.
7. International data transfers
Some of our providers (Stripe, Google, Meta, Cloudflare) may transfer data outside the European Economic Area. When this happens, we ensure adequate safeguards are in place — such as Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission — as required by articles 44–49 of the GDPR.
8. Your rights under the GDPR
Under the GDPR you have the following rights:
- Right of access (art. 15) — you can ask us what personal data we hold about you and receive a copy.
- Right to rectification (art. 16) — you can ask us to correct inaccurate or incomplete data.
- Right to erasure (art. 17 — “right to be forgotten”) — you can ask us to delete your personal data, subject to legal obligations that require us to keep certain records (e.g. payment records for tax purposes).
- Right to restriction of processing (art. 18) — you can ask us to limit how we use your data in certain circumstances.
- Right to data portability (art. 20) — you can ask us to transfer your data to another service in a structured, commonly used format.
- Right to object (art. 21) — you can object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent (art. 7.3) — where processing is based on your consent (e.g. analytics cookies), you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
9. Right to lodge a complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The Italian Data Protection Authority (“Garante per la protezione dei dati personali”) can be contacted at garanteprivacy.it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The latest version is always available at this page. Significant changes will be communicated via email or a notice on the Site.
11. Contact
For any privacy question or to exercise your rights, please use our contact form. We will respond within 30 days as required by the GDPR.