Privacy Policy
Last Updated: January 15, 2025
At Lernora Flow, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information when you interact with our AR/VR game development educational services. We operate in accordance with Serbian data protection laws and international best practices.
Information We Collect
When you engage with our educational programs, we collect several types of information to provide you with the best learning experience possible. We're transparent about what we gather and why.
Personal Information You Provide
This includes data you share directly with us when enrolling in our programs or contacting our team:
- Full name and contact details (email address, phone number)
- Billing address and payment information for course registration
- Educational background and professional experience relevant to AR/VR development
- Project submissions, assignments, and portfolio materials you create during courses
- Communication preferences and language settings
- Feedback, survey responses, and course evaluations
Technical Information
Our systems automatically collect certain technical data when you access our platform:
- IP address, browser type, and device information
- Learning platform usage patterns and course progress metrics
- Time spent on different modules and interaction with course materials
- Technical specifications of your development environment when relevant to coursework
- Login times and access frequency to our learning management system
How We Use Your Information
We process your data for specific, legitimate purposes related to delivering quality education in AR/VR game development. Here's what that actually means in practice.
| Purpose | Legal Basis |
|---|---|
| Delivering course content and tracking your progress | Contract performance |
| Processing payments and managing enrollments | Contract performance |
| Providing technical support and answering inquiries | Legitimate interest |
| Sending course updates and educational materials | Contract performance |
| Improving our curriculum based on student feedback | Legitimate interest |
| Maintaining security and preventing fraud | Legal obligation |
We don't sell your information to third parties or use it for purposes unrelated to your educational experience with us. When we send you updates about new programs or features, you can opt out at any time.
Data Sharing and Third Parties
Sometimes we need to share limited information with other organizations to run our programs effectively. We're careful about who we work with and what data they can access.
Service Providers We Work With
- Cloud hosting services that store course materials and student data securely
- Payment processors for handling course fees and transactions
- Email service providers for sending course notifications and updates
- Analytics tools that help us understand how students use our platform
- Video conferencing platforms for live instruction sessions
Each of these partners operates under strict data processing agreements. They can only use your information for the specific services we've contracted them to provide. They can't use it for their own purposes or share it further without our authorization.
Important: We may disclose your information if required by Serbian law, court order, or legal process. We'll notify you about such requests unless legally prohibited from doing so.
Your Rights Under Serbian Law
Serbian data protection regulations give you significant control over your personal information. You're not just agreeing to terms—you have enforceable rights.
What You Can Request
- Access: Get a copy of all personal data we hold about you, including course records and communications
- Correction: Update inaccurate information or complete incomplete records in your profile
- Deletion: Request removal of your data when it's no longer necessary for educational purposes
- Restriction: Limit how we process your information while we address concerns you've raised
- Portability: Receive your course data in a structured format you can transfer to another provider
- Objection: Oppose processing based on legitimate interests, particularly for marketing communications
To exercise any of these rights, contact us using the details at the end of this policy. We'll respond within 30 days and won't charge you for reasonable requests. If we need to verify your identity before processing your request, we'll explain why.
Data Security Measures
Protecting your information isn't just about meeting compliance requirements. We've implemented practical security measures because your trust matters to us.
- All data transmissions use TLS encryption to prevent interception
- Student records are stored on servers with restricted physical and network access
- Our staff receives regular training on data protection and privacy practices
- We maintain access logs and monitor systems for unauthorized access attempts
- Payment information is processed through PCI-DSS compliant providers—we don't store card details
- Regular security assessments help us identify and address potential vulnerabilities
Despite our precautions, no system is completely secure. If we detect a data breach affecting your information, we'll notify you and relevant authorities as required by Serbian law, typically within 72 hours of discovery.
Data Retention Periods
We don't keep your information forever. Our retention practices balance your privacy with legitimate needs like maintaining academic records and meeting legal requirements.
How Long We Keep Different Types of Data
- Course enrollment records: 7 years from program completion (Serbian educational record requirements)
- Financial transaction data: 5 years from last transaction (Serbian tax law requirements)
- Course materials you created: 2 years after program completion, unless you request earlier deletion
- Marketing communications data: Until you unsubscribe, then deleted within 30 days
- Technical logs and analytics: 12 months, then anonymized or deleted
- Support correspondence: 3 years from last interaction
When retention periods expire, we either delete your data permanently or anonymize it so it can't be linked back to you. You can request early deletion in most cases, though we might need to retain certain records for legal compliance.
International Data Transfers
Our primary servers are located within the European Economic Area, but some of our service providers operate globally. When your data crosses borders, we ensure it remains protected.
For services hosted outside Serbia or the EEA, we use:
- Standard contractual clauses approved by European data protection authorities
- Service providers certified under recognized international privacy frameworks
- Additional security measures for data transmitted to countries without adequate protection laws
You can request details about specific transfers and the safeguards we've implemented by contacting our privacy team.
Cookies and Tracking Technologies
Our learning platform uses cookies and similar technologies to function properly and improve your experience. Most of these are essential for basic operations.
Types of Cookies We Use
- Essential cookies: Keep you logged in and remember your course progress (required for platform functionality)
- Performance cookies: Help us understand which course materials work well and which need improvement
- Functional cookies: Remember your preferences like language settings and video playback quality
You can control cookie settings through your browser, though blocking essential cookies will prevent you from accessing the learning platform. We don't use advertising cookies or share browsing data with ad networks.
Children's Privacy
Our programs are designed for adults pursuing professional development in AR/VR game development. We don't knowingly collect information from anyone under 16 years old.
If you're under 16 and interested in our courses, please have a parent or guardian contact us to discuss appropriate enrollment options. If we discover we've unintentionally collected data from someone under 16, we'll delete it promptly.
Changes to This Policy
We update this privacy policy periodically to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we'll notify enrolled students via email and post the updated policy on our website at least 30 days before changes take effect.
The "Last Updated" date at the top tells you when we last revised this document. Continuing to use our services after changes take effect means you accept the updated terms.
Questions or Concerns?
If you have questions about this privacy policy or how we handle your data, we're here to help. You can reach us at:
Lernora Flow
Knez Mihajlova 20
Smederevo, Serbia
Email: support@lernoraflow.com
Phone: +381 63 666 314
You also have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (Serbian data protection authority) if you believe we've mishandled your information.