SOVISART PRIVACY POLICY
Document Ref: SOV-PRIV-2026-V1 Effective Date: October 10, 2026 Merchant Status: Pre-incorporation individual business (self-employed / sole-proprietor status)
This Privacy Policy explains what personal data Sovisart collects when you visit sovisart.com, enroll in a course, or purchase a digital product; why we collect it; how we use it; and what rights you have over it. It should be read alongside the Sovisart Terms of Service.
SECTION 1 // WHO WE ARE
1.1. Sovisart (sovisart.com) operates under the trading name Sovisart — Design School ("Sovisart", "we", "us", "our") and acts as the data controller for personal data collected directly through the Site, as described in this Policy. Paddle acts as a separate, independent data controller for payment data, as described in Section 4.
1.2. Contact for all privacy matters: info@sovisart.com
SECTION 2 // DATA WE COLLECT
2.1. Account and Contact Data. The email address and name you provide at checkout or account creation, and any correspondence you send us, such as support requests.

2.2. Transaction and Access Entitlement Data. A record of which courses and products you have purchased, your enrollment status, instalment-payment status where applicable, and the access entitlements tied to your account, used to deliver and manage your course access.

2.3. Technical and Usage Data. Standard technical data generated when you use the Site or access course materials: IP address, browser and device type, and timestamps of key actions such as login and lesson access. A limited subset is used to detect and prevent abuse of access limits (e.g. credential sharing), as described in Section 7 of the Terms of Service. This data is not used for any purpose beyond platform security, abuse prevention, and service delivery.

2.4. Consent Log Data. At checkout, you confirm your agreement to Sovisart's legal documents via a mandatory checkbox. The timestamp of this confirmation, the document version references accepted, and your associated email address are logged and retained as a record of your informed consent, as required by applicable data protection law.

2.5. Digital Identification Metadata. As described in Section 5.4 of the Terms of Service, Sovisart may embed unique order-reference and delivery identifiers or watermarks within delivered course materials. This metadata does not contain personal financial data. Its sole purpose is to identify the origin of files in the event of unauthorized redistribution and to support intellectual property enforcement.

2.6. Payment Data. We do not collect, process, or store your card number, billing address, or other raw payment credentials. This data is collected and processed directly and exclusively by Paddle — see Section 4.

2.7. Cookies. We use two categories of cookies: — Essential cookies: strictly necessary for session management, secure checkout, and platform functionality. These are set without requiring consent, as they are required for the Site to operate. — Analytics cookies: used to understand aggregate, anonymized Site usage patterns. These are not essential to Site operation and, where required by applicable law (including for visitors from the EU, EEA, and UK), are only set following your active consent via the cookie management tool on the Site. You can select "Essential Only" to decline analytics cookies while retaining full Site functionality. You may withdraw or change your consent at any time via the cookie settings link in the Site footer.

2.8. We do not intentionally collect health data, biometric data, or other special-category personal data as defined under GDPR Article 9.
SECTION 3 // HOW AND WHY WE USE YOUR DATA
3.1. Sovisart exercises full creative and editorial discretion over the content, format, and schedule of its courses, as described in Section 8.4 of the Terms of Service. Requests for a refund based solely on subjective dissatisfaction with teaching style, creative content, or stylistic choices are not eligible for a refund. Clients are encouraged to use the available free preview resources at sovisart.com prior to purchase.

3.2. Requests for a refund based on technical requirements outside Sovisart's control — including your own internet connection, device, browser, or third-party platform availability, as described in Section 8.3 of the Terms of Service — are not eligible for a refund, as these fall outside Sovisart's control once working access has been delivered.
SECTION 4 // MERCHANT OF RECORD — PADDLE
4.1. All payments are processed by Paddle.com Market Limited and its applicable affiliates ("Paddle"), acting as Merchant of Record and as an independent data controller for the billing and payment data it collects directly from you at checkout. Paddle's processing of this data is governed by Paddle's own privacy policy, not this one.

4.2. Where our systems detect a confirmed violation of the access-abuse or fair-use limits described in Section 7 of the Terms of Service, we may share relevant account identifiers and supporting technical data — including digital identification metadata from delivered files — with Paddle to assist with fraud prevention and chargeback defense, consistent with our obligations under the Paddle merchant agreement.
SECTION 5 // OTHER SERVICE PROVIDERS
5.1. We use third-party infrastructure providers — including our site/course platform (e.g. Tilda), video hosting, cloud hosting, and Site analytics services — to operate the Site, Store, and course delivery. These providers act as data processors on our behalf under written data processing agreements, are bound to protect your data, and are not permitted to use it for their own purposes.
SECTION 6 // DATA RETENTION
6.1. Account, transaction, and access-entitlement data is retained for as long as your account is active and for as long as necessary to manage your course access and satisfy applicable tax and accounting obligations (typically up to 7 years for financial records, in line with standard accounting retention requirements).

6.2. Consent log data is retained for a minimum of 3 years from the date of the associated transaction, consistent with standard data protection audit requirements.

6.3. Technical and usage data collected for abuse-prevention purposes (Section 2.3) is retained for a limited period sufficient for its security purpose — ordinarily no longer than 90 days — except where specific records are retained as evidence of a confirmed and documented policy violation.

6.4. Digital identification metadata embedded in delivered files remains with those files as part of the material and is not separately stored or processed by Sovisart beyond the initial delivery record.

6.5. If you request erasure of your account (Section 8), we will delete your account and associated personal data subject to the qualifications in Section 8.4.
SECTION 7 // INTERNATIONAL DATA TRANSFERS
7.1. Sovisart and its service providers may store and process data in countries outside your own, including outside the EU, EEA, and UK. Where personal data of EU/EEA/UK users is transferred internationally, we rely on recognized legal safeguards such as the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism to ensure an adequate level of data protection.
SECTION 8 // YOUR RIGHTS
8.1. Subject to applicable law, you may have the following rights regarding your personal data: (a) Access — request a copy of the personal data we hold about you. (b) Rectification — request correction of inaccurate or incomplete data. (c) Erasure — request deletion of your personal data ("right to be forgotten"), subject to Section 8.4. (d) Objection or Restriction — object to processing based on legitimate interest, or request that we restrict processing in certain circumstances. (e) Portability — receive your data in a structured, commonly used format where technically feasible.

8.2. If you are located in the United States, you may have additional rights under applicable state privacy law (including the California Consumer Privacy Act/CPRA and equivalent legislation in other states). These rights may include the right to know what categories of personal data we collect, to request deletion, and to opt out of the sale of personal data. Sovisart does not sell personal data to third parties.

8.3. To exercise any right under Section 8.1 or 8.2, contact info@sovisart.com. We will respond within 30 days of a verified request.

8.4. Effect of Account Erasure. Deleting your account will permanently end your ability to access your personal-cabinet course materials — including any remaining course access period — and cannot be reversed. We may retain limited transaction and consent-log records after erasure where required by applicable tax, accounting, or legal-compliance obligations.

8.5. Right to Lodge a Complaint. If you are located in the EU, EEA, or UK and believe we are processing your personal data in violation of applicable law, you have the right to lodge a complaint with your local data protection supervisory authority.
SECTION 9 // SECURITY
9.1. We implement industry-standard technical and organizational safeguards, including encryption in transit (TLS/SSL) and access controls on our internal systems, to protect personal data against unauthorized access, loss, alteration, or disclosure.

9.2. Data Breach Notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required under GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals directly without undue delay, as required under GDPR Article 34, using the contact information on file.
SECTION 10 // CHILDREN'S PRIVACY
10.1. Sovisart is not directed to persons under 18 years of age, consistent with the eligibility requirement in Section 3.1 of the Terms of Service. We do not knowingly collect personal data from anyone under this age. If we become aware that we have inadvertently collected data from a person under 18, we will delete it promptly.
SECTION 11 // CHANGES TO THIS POLICY
11.1. We may update this Policy from time to time. Material changes will be reflected by an updated Effective Date and Document Ref at the top of this document. For significant changes, active account holders will be notified by email prior to the change taking effect. Continued use of the Site after an update constitutes acceptance of the revised Policy.
SECTION 12 // MISCELLANEOUS
12.1. Severability. If any provision of this Policy is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.

12.2. Jurisdiction Update. These terms currently reflect Sovisart operating as a pre-incorporation individual business. In the event that Sovisart incorporates as a registered legal entity, the data controller details and governing law provisions will be updated and active users notified.
SECTION 13 // CONTACT
For privacy inquiries or to exercise your rights: info@sovisart.com
SECTION 14 // LANGUAGE
This Policy is executed in English. Any translated version is provided for convenience only; the English version governs in the event of any conflict.