Privacy policy
Last updated 2 August 2026
This policy explains what personal data UN Career Academy collects, why, and what rights you have. We collect only what we need to run the Course and we do not sell your data.
1. Who is responsible
The data controller for your account, your progress and the other personal data described in this policy is UN Career Academy. You can reach the controller at help@uncareeracademy.org. Payment data is handled by Paddle, which is a separate controller for the sale.
For any privacy question or to exercise your rights, contact help@uncareeracademy.org.
2. What we collect and why
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Email and login identifier | To create your account and let you log in | Performance of our contract with you |
| Login session details (IP address, device/browser) | To keep your account secure and detect misuse | Our legitimate interest in account security |
| Country (from your billing details or IP) | Regional pricing and tax | Contract / legal obligation (tax) |
| Payment record (order reference, never your card details) | Fulfilment, accounting, and tax | Contract / legal obligation |
| Progress and completion data | To deliver the Course features, including resume and your certificate | Performance of our contract with you |
| Your answers to the in-course self-audit | To generate your personalised self-audit result | Performance of our contract with you |
| Gift purchases: your email, the redemption code, and the email of whoever redeems it | To create the code, send it to you, and let it be redeemed once | Performance of our contract with you |
| Feedback you submit | To improve the Course | Legitimate interest; your consent for any testimonial use |
We send only transactional email— your secure login links and your purchase confirmation. We do not run a marketing list and will not email you marketing.
To revisit our regional pricing we measure checkout conversion in aggregate, by country and price tier only. That measurement carries no identifier and does not store your IP address.
We do not publish your feedback as a testimonial without your separate, specific consent.
Gifts. If you buy the Course as a gift we do notask for or store the recipient’s email address. We send the redemption code to you, and you pass it on however you like. We only learn who received it if and when they redeem it, at which point they are creating their own account.
3. Who else handles your data
Paddle is not one of our providers; it is the seller. Paddle is our Merchant of Record, which means that when you buy the Course your purchase contract is with Paddle rather than with us. Paddle decides for itself how it handles your data for the sale, including payment processing, fraud checks, tax and its own record-keeping, and it is a separate data controller for those purposes, not a supplier acting on our instructions. Your card details go to Paddle and never reach our systems. Paddle passes us what we need to give you access and to keep the records tax law requires. What Paddle does with your data is covered by Paddle’s privacy policy, and you can exercise your rights against Paddle directly as well as against us.
The remaining providers below are ours. Each runs under a data-processing agreement and is permitted to use your data only on our instructions:
- Video hosting — Bunny.net: to stream the Course lessons to you.
- Email delivery — Resend: to send your secure login links and purchase confirmation.
- Database hosting — Neon: our managed Postgres provider, hosted in the EU, which stores your account, progress, and records.
- Website hosting and infrastructure — Cloudflare: which runs the website, stores downloadable resources, and processes technical data such as IP addresses in its logs.
We do not sell or rent your personal data to anyone.
4. International transfers
We host data in the EU where offered. Where a provider is based outside the EU, that transfer relies on an approved safeguard (Standard Contractual Clauses or the EU–US Data Privacy Framework), so your data keeps an equivalent level of protection. Paddle is not one of those providers: as the seller it decides its own transfers, and these are covered by Paddle’s privacy policy.
5. Cookies and browser storage
We keep this to a minimum, and we would rather describe it accurately than claim it is smaller than it is.
On our own pages we set two things: a secure cookie that keeps you logged in, and your light or dark theme choice, stored locally so the site remembers it. Cloudflare, which serves this site, also sets a security cookie (cf_clearance, which lasts a year) that protects it from automated abuse. We use no analytics, advertising or tracking cookies of our own.
On the checkout page only, and only once you choose to buy, Paddle, the seller of record, loads the secure payment window. Paddle is the seller of record for your purchase, and its script also brings in Stripe, which Paddle uses for payment processing and fraud checks, and Sentry, which Paddle uses to catch errors. These run on Paddle’s and Stripe’s own domains rather than ours, and what they store is governed by Paddle’s privacy policy.
Most of what they store is needed to take a payment: which checkout you are in, how the window should be displayed, whether Apple Pay is available, where to send you afterwards, your language, and identifiers Stripe uses to detect fraud, including a device fingerprint. Some of it is not needed for the payment itself: Paddle also keeps a count of visits, timings for how long the checkout took to load, and its own error metrics. That measurement is set by Paddle on its own domains and is not shared with us.
Nothing here loads until you actively start a purchase. What loads then is, for the most part, storage Paddle needs to complete a payment you have asked for, which does not require your consent; the remainder is the measurement described above, which Paddle sets on its own domains and is responsible for as the seller of record, though we accept that choosing to embed its payment window on our own page is our decision and not only Paddle’s. On that basis we do not show a consent banner. We keep this under review, and if we add analytics or advertising, or if consent becomes required for anything on this page, we will ask you first.
We checked this ourselves on 2 August 2026, recording everything stored in a browser before and after the payment window opened. At that point no third party had set a cookie of any kind. We have not yet examined what is stored once a payment is completed.
6. How long we keep it
We keep your account, progress, and self-audit data for as long as your access is active, and delete it when you close your account. We keep purchase records for seven yearsafter the relevant tax year, because tax and accounting law requires it — so these are retained even after you close your account. Feedback is kept to improve the Course; if you close your account we anonymise it rather than delete it. Lifetime access to the Course does not mean we retain all of your activity data indefinitely.
7. Your rights
Under the GDPR and equivalent laws you have the right to access, correct, erase, port, and object to the processing of your personal data, and to withdraw any consent you have given. Once signed in you can delete your account and personal data yourselffrom your account page (Your course → Account); this erases your data immediately, subject to records we are required to keep by law. To exercise any other right, email help@uncareeracademy.org.
You also have the right to complain to your data-protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
8. How we protect your data
- Encrypted connections (TLS) across the site.
- Passwordless login: we never store a password, removing the highest-value target in a breach.
- No card data on our systems: payment is handled by Paddle as seller of record.
- Encryption at rest and least-privilege access to personal data.
9. California residents
We do not sell or share your personal information as those terms are used under the CCPA/CPRA. You have the right to know what we hold, to request deletion, and not to be discriminated against for exercising those rights. Use the contact address above to make a request.
10. Children
The Course is intended for adults and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. The version in force is the one published here on the date shown above; where a change is significant we will tell you.
12. Contact
Privacy questions or requests: help@uncareeracademy.org.