Back to home

Privacy Policy

Version of September 21, 2026

This page explains what personal data the fryai.club website collects, why it is needed, how long it is kept and what rights the people whose data we process have.

This is a translation. In the event of any discrepancy, the Ukrainian version of the document prevails.

1. General provisions

This Policy applies to all data we receive from visitors to the fryai.club website, including the private section at fryai.club/watch (the “Member area”), where Customers watch the Course materials.

The data controller is sole proprietor Горевой Дмитро Геннадійович, taxpayer registration number 3674711511, e-mail [email protected].

Processing is carried out in accordance with the Law of Ukraine “On Personal Data Protection”, the Law of Ukraine “On Electronic Commerce” and, where applicable, the General Data Protection Regulation (GDPR).

By submitting any form on the Website or by placing an order, a visitor confirms that they have read this Policy and consents to their data being processed on the terms described here.

2. What data we collect

We deliberately collect the minimum: to open access to the lessons or reply to a message, a single e-mail address is enough.

  • E-mail address — it also identifies the Account in the Member area: sign-in links and codes and the access notification are sent to it.
  • Name — as the visitor entered it, if the form asks for it.
  • A contact from the “Contacts” form — one of: e-mail, or a Telegram or Instagram handle.
  • Message text — if the visitor sent one through the “Contacts” form.
  • The language of the page the request came from — so that we reply in the same language.
  • Order data: order number, the name of the Package paid for, the amount, the currency, the payment status and the date. Card details are not among them.
  • Member area usage data: the term of access and marks showing which lessons have been watched.
  • Session technical data: the authentication cookie, the time of sign-in and the time of last activity.
  • Technical request data: IP address, browser and device type, time of the request. These enter the service logs of the hosting provider and the video delivery service automatically.

We do not collect payment data. Payment takes place on the side of the WayForPay payment service, and card details never reach us and are not stored by us.

There is no password in the Member area, so we store no passwords. One-time sign-in codes and links are stored in transformed form and expire quickly.

We do not collect sensitive data: health, religious or political views, ethnic origin, or biometric data.

3. Why we process data

  • to send the free lesson or other materials the visitor asked for;
  • to create an Account in the Member area, recognise the visitor when they sign in and maintain their session;
  • to accept payment, confirm it and open access to the paid Package;
  • meet the obligations set by tax law;
  • to keep marks showing which lessons have been watched, so that the visitor can see their progress;
  • to protect the Course materials from copying — in particular by displaying the e-mail address over the video;
  • to reply to a message from the “Contacts” form;
  • to comply with the law — primarily tax and accounting requirements;
  • to protect the Website from automated submissions and abuse.

We do not pass contacts on to advertisers, do not use them to promote third-party companies and do not sell them.

4. Legal bases for processing

  • consent of the data subject — for sending materials and replying to enquiries;
  • performance of a contract to which the data subject is a party — for accepting payment, granting access to the Course and running the Member area;
  • compliance with a legal obligation of the controller — for tax and accounting records;
  • the legitimate interest of the controller — for protecting the Website and the Course materials from abuse and keeping service logs.

5. Cookies, fonts and analytics

The Website uses no advertising or tracking cookies and passes no data to advertising networks.

The only cookie the Website itself sets is the strictly necessary session cookie “fry_session”. It records the fact of signing in to the Member area, is inaccessible to page scripts (httpOnly), is transmitted only over HTTPS and lasts up to 30 days. The Member area cannot work without it, so no separate consent is requested for it.

For visitors who do not sign in to the Member area, the Website sets no cookies.

Fonts are served from our own domain — the page does not request them from third-party CDNs.

Strictly necessary cookies may be set by the hosting provider and the attack protection service for load balancing and filtering malicious traffic, and by the video delivery service for lesson playback. They do not identify the visitor as a person.

If web analytics services are added to the Website, this section will be updated before they go live.

6. Who we share data with

We do not sell personal data and do not share it with third parties except in the cases listed below.

  • WayForPay — the payment service: accepts card payments and passes us the order number, amount and payment status;
  • Bunny Stream (BunnyWay d.o.o., Slovenia) — stores and delivers the video lessons: receives the IP address, device type and technical player data;
  • Resend — the e-mail service: delivers messages with sign-in links and codes to the address given;
  • Telegram — notifications about new requests and payments reach the operators through it;
  • Cloudflare — filters traffic and speeds up delivery of the Website: requests to the Website pass through it;
  • Amazon Web Services — the hosting provider: the Website runs and the database is stored on its servers;
  • public authorities — on the basis of a lawful request.

These services process the data on our instructions and only to the extent needed to perform their function.

Some of these services are located outside Ukraine. Transfers are made to countries that ensure an adequate level of personal data protection, or under contracts containing the appropriate safeguards.

7. How long we keep data

  • contacts from forms — up to 3 years from the last communication or until consent is withdrawn;
  • the Account in the Member area and the marks showing which lessons have been watched — for the term of access and up to 12 months after it ends, so that access can be restored or renewed;
  • records of paid Packages and primary accounting documents — 1,095 days, as required by tax law;
  • one-time sign-in codes and links — until they expire; sessions — up to 30 days from signing in;
  • server service logs — up to 12 months.

Once the period expires, the data is deleted or anonymised.

8. How we protect data

The Website runs over HTTPS. Access to submitted requests and to the database is limited to people who need it for their work, and correspondence with operators is protected by the means of the relevant services.

There are no passwords in the Member area: signing in is done with a one-time code or a one-time link, both of which expire quickly, and only one session is active in an Account at a time.

No transmission of data over the internet is completely secure. We take reasonable technical and organisational measures, but cannot guarantee protection against every possible attack.

9. Your rights

Under Article 8 of the Law of Ukraine “On Personal Data Protection”, every person has the right to:

  • know who processes their data and for what purpose;
  • receive a copy of their personal data;
  • request that inaccurate or incomplete data be corrected;
  • request erasure of the data or restriction of its processing;
  • withdraw consent to processing at any time;
  • object to the processing of their data;
  • lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights.

To exercise any of these rights, simply write to [email protected]. We will reply within 30 calendar days.

Deleting the Account data ends access to the Member area, including to paid materials. We are obliged to keep payment records for the period required by tax law, so they cannot be erased.

Withdrawing consent does not affect the lawfulness of processing carried out beforehand and may make it impossible to continue providing the services.

10. Children

The Website is not intended for persons under 18, and we do not knowingly collect their data. If we learn that a child’s data has reached us without the consent of a legal representative, we will delete it on first request.

11. Changes to this Policy

We may update this Policy. The current version is always published on this page, and its date is shown at the top.

If the changes materially affect visitors’ rights, we will notify them separately, using the contact provided earlier.

Details

Sole proprietor Горевой Дмитро Геннадійович

Tax number: 3674711511

E-mail: [email protected]