Privacy Policy

We are pleased about your visit to our website. Below we inform you about the processing of personal data when using this website.

1. Controller

The controller responsible for data processing on this website is:
Vahagn Arakelyan (Readanduseit)
Urbanstraße 16
73207 Plochingen, Baden-Württemberg
Email: vahag12102004@gmail.com

2. Delivery of the Website / Cloudflare

For the secure and efficient delivery of our website and to optimize loading times, we use Cloudflare (CDN / security service).

Provider:
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA

Technical connection and access data may be processed, in particular IP address, date and time of access, pages accessed, and browser information.

Processing is carried out to ensure the security, stability, and performance of the website.

Legal basis: Art. 6(1)(f) GDPR.

Data is stored only as long as technically necessary for the stated purposes.

If data is transferred to the USA, this is based on the EU-U.S. Data Privacy Framework (DPF). Cloudflare is certified under this framework, ensuring an adequate level of data protection.

3. Server Log Files

When accessing our website, technically necessary information is processed in server log files. This may include in particular:

  • IP address
  • Date and time of the request
  • Page / file accessed
  • Browser type and version
  • Operating system
  • Referrer URL (if transmitted)

Processing is carried out to ensure the stability and security of the website and for error analysis.

Legal basis: Art. 6(1)(f) GDPR.

Data is stored only as long as necessary to ensure the security and stability of the website.

4. Analytics and Tracking Tools

This website uses Google Analytics to analyze website usage and measure success.

Provider:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Processing is carried out solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG.

Google Analytics is activated only after you have explicitly consented via the cookie banner.

You can withdraw or adjust your consent at any time for the future via the cookie settings.

It cannot be ruled out that personal data may also be processed in third countries when using Google services.

If data is transferred to the USA, this is based on the EU-U.S. Data Privacy Framework (DPF). Google is certified under this framework, ensuring an adequate level of data protection.

5. Embedded YouTube Videos

Our website embeds YouTube videos.

The YouTube player loads only after an active click by the user. Before that, no content is loaded from YouTube servers.

Only after activation can personal data, in particular the IP address, be transmitted to YouTube and/or Google.

Provider:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

It cannot be ruled out that personal data is processed in third countries.

6. External Links to Platforms / Social Media

Our website contains only external links to our profiles/pages on the following platforms:

  • Telegram
  • Instagram
  • TikTok
  • YouTube
  • Udemy
  • Spotify

When merely visiting our website, these platforms are not loaded automatically. Only by actively clicking a link do you leave our website. From that point on, the privacy policies of the respective platform operators apply.

7. Contact (Email / Telegram)

If you contact us (e.g., by email or via Telegram), we process the data you provide to handle your request, schedule appointments, and deliver our services.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures/contract) and, where applicable, Art. 6(1)(f) GDPR.

Retention period: as long as required for collaboration/communication; beyond that only if legal obligations or legal claims require it.

8. Bot, orders, consent and access

This policy covers @b1_course_bot, course.readanduseit.com, purchases and private-channel access. Bot processing includes Telegram IDs, available names and usernames, commands, messages to the bot and join requests. Orders include course, amount, currency, dates, order and Stripe identifiers, payment, refund, dispute and access states.

Purchase evidence includes checkout email, exact terms and consent texts and versions, UTC consent time, Telegram callback identifier, a fixed contract record, email message identifier, sending state and technical errors. Incoming Telegram and Stripe events may temporarily contain additional contact and payment metadata. The bot database does not store full card numbers or CVCs.

Purposes and grounds: purchase, contract confirmation, access, technical assistance and refunds under Art. 6(1)(b) GDPR; statutory records under Art. 6(1)(c); security, abuse prevention and legal claims under Art. 6(1)(f). Consent to immediate supply is not consent to marketing.

Necessary data are required for purchase and automated access. You may request human review of an incorrect access denial by email. Assignments are not accepted for marking and learning results are not assessed.

Withdrawal requests involve your name, contract identification, contact email, statement, receipt time and acknowledgment sending record. These data are used to handle the request and fulfil related contractual and statutory obligations.

9. Stripe and email confirmation

Stripe receives the contact and payment information entered at checkout. We receive order details, email and payment confirmation. Depending on the operation, Stripe acts as processor or independent controller. See Stripe’s policy.

Contract confirmations and replies are sent through Gmail (Google). Google processes sender and recipient addresses, message content and sending metadata. Google Ireland Limited provides the service to EEA users, under Google’s policy. The mailbox is vahag12102004@gmail.com. Purchase does not subscribe you to marketing.

10. Recipients, infrastructure and international transfers

The bot and PostgreSQL run on the owner’s home computer in Germany. Only the owner has ongoing access to the operational database. Temporary setup access ends on completion. No separate retained database backups are currently maintained; this does not mean the external services listed here hold no data.

Cloudflare Tunnel carries requests and webhooks; Telegram supports messaging, invitations and channel membership. Recipients include Stripe, Cloudflare, Telegram and Google for the purposes described. Necessary records may be disclosed to tax advisers and competent authorities on a lawful basis.

Processing outside the EEA is possible. Cloudflare’s DPA provides for the EU–US Data Privacy Framework for covered transfers and EU standard contractual clauses (SCCs) for restricted transfers covered by that DPA. Stripe describes its mechanisms, including SCCs, in its DPA and Data Transfers Addendum.

Google describes transfers, including to the US, using applicable adequacy decisions/DPF and SCCs in its transfer frameworks. Sections 4.1 and 8.2 of Telegram’s policy describe Netherlands storage for users registered in the EEA and intra-group transfers to the British Virgin Islands and Dubai using SCCs. These are Telegram’s reported safeguards, not a claim that we concluded a separate agreement with it.

Request information and an available copy of safeguards relevant to our processing from the owner by email; provider safeguards are also linked above. The admin dashboard uses an essential security/login session cookie, not advertising cookies (Art. 6(1)(f) GDPR).

11. Course-data retention

Event payloads are erased after successful processing or manual closure of an investigated task. Completed inbox/outbox rows are deleted after 30 days from creation. Cleanup runs while the bot is operating, including after a restart.

Finalized unpaid or cancelled orders and related unpaid consents are removed 90 days after closure only if no open payment, refund, dispute, Payment Intent, unresolved task or entitlement is linked. Such a link requires individual review rather than indefinite purposeless storage.

Unresolved errors have no automatic expiry: the owner must investigate and remove unnecessary data once the cause is resolved. Paid orders, consent evidence, emails and owner audit records currently have no automatic deletion; applicable periods are managed manually.

Minimum access records remain while needed to honour promised access. Statutory record periods depend on category: for example, accounting vouchers generally 8 years, business correspondence 6 years, books and annual accounts 10 years where those obligations apply. Calculation generally starts at the end of the relevant calendar year; statutory extensions remain applicable.

Contract and consent evidence is retained as necessary for performance and legal claims. The general limitation period is normally 3 years, but commencement, suspension and special periods depend on the claim. This does not justify retaining all technical logs for that period. Once all applicable grounds end, the owner manually deletes or anonymizes data. Deleting the chat or bot does not itself delete order records; send requests by email.

12. Rights of Data Subjects

You have the following rights in particular:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR)

To exercise your rights, you can contact us using the contact details above.

13. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).

14. Changes to this Privacy Policy

We reserve the right to update this privacy policy so that it always complies with current legal requirements or reflects changes to our website or services.

Last updated: 23.09.2026