Privacy Policy
Last updated: 2026-08-01
This policy explains how we handle your personal data when you use Mr. Kriss Essentials at essentials.mrkriss.com. We follow the EU General Data Protection Regulation (GDPR).
1. Data controller
The controller is Kristián Mensa (“Mr. Kriss”), Malá Strana 46, 252 41 Dolní Břežany, Czech Republic, business ID (IČO) 08069671. Privacy contact: kriss@mrkriss.com.
2. What we collect
- Account: your name, email address, and a securely hashed password.
- Consent records: the version of the Terms and Privacy Policy you accepted and when.
- Purchase: what you bought, the amount, currency, and Stripe payment references (we do not receive or store your full card number).
- Course usage: your lesson progress and completion.
- Devices & security: a short device label (e.g. “Chrome · macOS”), approximate country, and limited access logs, used to enforce the two-device limit and protect against abuse.
- Approximate location: derived from your IP address to show the right currency and tax at checkout.
3. Why we use it, and our legal basis
- To provide the Course and your account — performance of our contract with you (Art. 6(1)(b)).
- To take payment and issue invoices — contract, and our legal obligation to keep tax records (Art. 6(1)(b) and (c)).
- To secure accounts, enforce the device limit, and prevent piracy/fraud — our legitimate interests (Art. 6(1)(f)).
- To send service emails (account, payment, password) — contract.
- To record your consent to these documents — our legal obligation and legitimate interest in demonstrating compliance.
4. Who we share it with (processors)
We use trusted providers who process data only on our instructions:
- Supabase — account database and authentication (hosted in the EU).
- Stripe — payment processing and invoicing.
- Mux — secure video streaming.
- Vercel — website hosting and delivery.
- Resend — sending service emails.
We do not sell your data or share it for advertising. Some providers are based in the United States; where data leaves the EU it is protected by appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
5. Cookies
We use only strictly necessary cookies to keep you signed in and secure. We do not use advertising or analytics cookies or third-party trackers, so no cookie-consent banner is needed.
6. How long we keep it
We keep your account data while your account exists. If you delete your account, we remove your profile, consents, progress, and device records. We keep purchase and invoice records for as long as tax and accounting law requires [CONFIRM: retention period — typically up to 10 years under Czech law]. We also keep limited security and access logs to protect accounts and prevent abuse; video access logs are deleted automatically after 90 days.
7. Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests, and withdraw consent at any time. You can delete your account and its data yourself at any time from your account page. To exercise any other right, email kriss@mrkriss.com. You also have the right to complain to your data-protection authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).
8. Security
Passwords are hashed, access to your data is restricted by row-level security, video is served through short-lived signed tokens, and secrets are held server-side only. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Children
The Course is not intended for children under 18, and we do not knowingly collect their data without parental consent.
10. Changes
We may update this policy. Material changes are posted here with a new “last updated” date, and where required we will ask you to re-accept.
This is a draft prepared for review. It is not legal advice and should be checked by a qualified lawyer before launch.