Privacy Notice
What AHC CoreX collects, why, how long it is kept, and what you can ask us to do about it.
Last updated 13 August 2026
NEXT_PUBLIC_LEGAL_* environment variables and this notice disappears on its own.Who is responsible
The controller of your personal data is [registered company name], [registered address]. For any question about this notice, or to exercise a right below, write to ahcheha01@gmail.com.
What we collect, and why
| Email address, and name if you give one | To identify your account, sign you in, verify the address and send you notices about your account. Required β the service cannot work without it. |
| Password | Stored only as an Argon2 hash. We cannot read it, and nobody who obtains the database can either. |
| Two-factor secret, if you enable 2FA | Stored encrypted, used only to check the six-digit codes you enter. |
| Google account identifier and profile picture, if you sign in with Google | To link the sign-in to your account. We do not receive your Google password and request no access to your Google data beyond your basic profile. |
| Files, folders and their names | They are the service. File contents are encrypted at rest with a per-file key; names and folder structure are stored so you can find them. |
| Course progress, enrolments and certificates | To show you where you left off and to issue certificates. |
| Payment requests, receipts you upload, and the note you attach | To confirm a payment and open the access you paid for, and to keep a record of the sale. We never see or store card numbers β there is no card form. |
| Audit log: the action taken, when, and the IP address it came from | Security. It is how an intrusion is detected and how a dispute about who did what is settled. Kept for sensitive actions such as signing in, sharing a file, or confirming a payment. |
| Meeting participation, and recordings a host makes | To run the meeting and to store a recording for the host who made it. |
| Session tokens in your browser | To keep you signed in. Strictly necessary β we set no advertising or analytics cookies and there are no third-party trackers on this site. |
Legal basis
Where the GDPR or a comparable law applies, we rely on: performance of a contract for everything needed to run your account and deliver what you bought; legitimate interests for security, fraud prevention and audit logging; legal obligation for keeping records of sales; and consent where we ask for it specifically, which you can withdraw at any time.
Who else sees it
- Our hosting provider (Amazon Web Services), in [hosting region], which stores the database and the encrypted files on our instructions.
- Our email provider, to send verification, password-reset and notification emails.
- The instructor who sells a course, when you buy it: they see that you bought it and the payment note or receipt you attached, so they can confirm it.
- People you share a file or a meeting with β that is your choice, not ours.
- Authorities, where we are legally obliged to disclose.
We do not sell personal data, and we do not share it for advertising.
Where it is stored
Data is hosted in [hosting region]. If you are in the European Economic Area and data is processed outside it, that transfer is covered by the European Commissionβs standard contractual clauses.
How long we keep it
- Your account and files β until you delete them, or until you close your account.
- Deleted files β removed from active storage on deletion; they may persist in encrypted backups for up to [backup retention, e.g. 30 days] before those expire.
- Audit logs β [e.g. 12 months], then deleted.
- Records of payments β as long as accounting law requires, typically [e.g. 10 years], even after the account is closed.
- Password-reset and verification tokens β hours, then they expire and are cleared.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also complain to your data-protection authority β [supervisory authority]. We answer within one month.
Some of this you can do without asking: your files are yours to download and delete, and you can change your name, password and two-factor settings in Settings at any time.
Security
Files are encrypted at rest with AES-256-GCM under per-file keys, and in transit with TLS. Passwords are hashed with Argon2. Two-factor authentication is available on every account and we recommend it. Sensitive actions are logged. Uploads are screened before they are stored.
No system is perfect. If we discover a breach that puts you at risk we will tell you and the relevant authority as the law requires.
Children
The service is not directed at children under [age, e.g. 16]. If you believe a child has given us personal data without the consent of a parent or guardian, write to us and we will remove it.
Changes
If this notice changes materially we will say so in the application before the change takes effect, not only by editing this page.
