AHC CoreXAHC CoreX
PricingSign inGet started

Privacy Notice

What AHC CoreX collects, why, how long it is kept, and what you can ask us to do about it.

Last updated 13 August 2026

To the operator: complete the bracketed fields with your registered details and hosting region, and have this reviewed against the data-protection law that applies to you before launch. Set them through the NEXT_PUBLIC_LEGAL_* environment variables and this notice disappears on its own.

Who is responsible

The controller of your personal data is [registered company name], [registered address]. For any question about this notice, or to exercise a right below, write to ahcheha01@gmail.com.

What we collect, and why

Email address, and name if you give oneTo identify your account, sign you in, verify the address and send you notices about your account. Required β€” the service cannot work without it.
PasswordStored only as an Argon2 hash. We cannot read it, and nobody who obtains the database can either.
Two-factor secret, if you enable 2FAStored encrypted, used only to check the six-digit codes you enter.
Google account identifier and profile picture, if you sign in with GoogleTo link the sign-in to your account. We do not receive your Google password and request no access to your Google data beyond your basic profile.
Files, folders and their namesThey are the service. File contents are encrypted at rest with a per-file key; names and folder structure are stored so you can find them.
Course progress, enrolments and certificatesTo show you where you left off and to issue certificates.
Payment requests, receipts you upload, and the note you attachTo confirm a payment and open the access you paid for, and to keep a record of the sale. We never see or store card numbers β€” there is no card form.
Audit log: the action taken, when, and the IP address it came fromSecurity. It is how an intrusion is detected and how a dispute about who did what is settled. Kept for sensitive actions such as signing in, sharing a file, or confirming a payment.
Meeting participation, and recordings a host makesTo run the meeting and to store a recording for the host who made it.
Session tokens in your browserTo keep you signed in. Strictly necessary β€” we set no advertising or analytics cookies and there are no third-party trackers on this site.

Legal basis

Where the GDPR or a comparable law applies, we rely on: performance of a contract for everything needed to run your account and deliver what you bought; legitimate interests for security, fraud prevention and audit logging; legal obligation for keeping records of sales; and consent where we ask for it specifically, which you can withdraw at any time.

Who else sees it

  • Our hosting provider (Amazon Web Services), in [hosting region], which stores the database and the encrypted files on our instructions.
  • Our email provider, to send verification, password-reset and notification emails.
  • The instructor who sells a course, when you buy it: they see that you bought it and the payment note or receipt you attached, so they can confirm it.
  • People you share a file or a meeting with β€” that is your choice, not ours.
  • Authorities, where we are legally obliged to disclose.

We do not sell personal data, and we do not share it for advertising.

Where it is stored

Data is hosted in [hosting region]. If you are in the European Economic Area and data is processed outside it, that transfer is covered by the European Commission’s standard contractual clauses.

How long we keep it

  • Your account and files β€” until you delete them, or until you close your account.
  • Deleted files β€” removed from active storage on deletion; they may persist in encrypted backups for up to [backup retention, e.g. 30 days] before those expire.
  • Audit logs β€” [e.g. 12 months], then deleted.
  • Records of payments β€” as long as accounting law requires, typically [e.g. 10 years], even after the account is closed.
  • Password-reset and verification tokens β€” hours, then they expire and are cleared.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also complain to your data-protection authority β€” [supervisory authority]. We answer within one month.

Some of this you can do without asking: your files are yours to download and delete, and you can change your name, password and two-factor settings in Settings at any time.

Security

Files are encrypted at rest with AES-256-GCM under per-file keys, and in transit with TLS. Passwords are hashed with Argon2. Two-factor authentication is available on every account and we recommend it. Sensitive actions are logged. Uploads are screened before they are stored.

No system is perfect. If we discover a breach that puts you at risk we will tell you and the relevant authority as the law requires.

Children

The service is not directed at children under [age, e.g. 16]. If you believe a child has given us personal data without the consent of a parent or guardian, write to us and we will remove it.

Changes

If this notice changes materially we will say so in the application before the change takes effect, not only by editing this page.