1.Who is responsible for your data
The controller of your data is the entity that operates ataa, commercially registered in the United Arab Emirates. When you join a teacher's academy, that teacher becomes a joint controller for a limited slice of data about your activity inside their community and courses — set out in the sharing section below.
For any privacy question or to exercise your rights, use the contact page and pick the privacy topic; the request reaches our data protection lead directly.
2.What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Full name, email, phone number, language and time zone, profile picture if you upload one | You enter it |
| Payment data | An encrypted card token from the payment provider, last four digits, card brand, transaction status and reference | Payment provider |
| Learning data | Courses purchased, completion percentage per lesson, last playback position, quiz results, certificates issued | Your use of the player |
| Community data | Your posts, comments and reviews, your points and level, the academies you joined | You post it |
| Device data | Browser and operating system, truncated IP address, session identifier, error logs and response times | Collected automatically |
| Teacher data | Identity verification documents, commercial registration where applicable, encrypted IBAN, tax invoicing details | The teacher provides it |
3.Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Creating your account, verifying identity and securing sign-in | Performance of the contract |
| Completing purchases, issuing invoices and processing refunds | Contract and legal obligation |
| Saving your course progress and issuing certificates | Performance of the contract |
| Transactional notifications (receipts, session starting, refund status) | Performance of the contract |
| Fraud detection, preventing account sharing and protecting content | Legitimate interest |
| Measuring performance and improving the product with aggregate statistics | Legitimate interest |
| Marketing messages and offers | Your consent, withdrawable at any time |
| Keeping accounting and tax records | Legal obligation |
We take no purely automated decisions that produce a legal effect on you. Refund requests outside the policy, and account suspension decisions, are reviewed by a human before they take effect.
5.International transfers
Your core data is hosted in data centres inside the Gulf region or the nearest available region, to keep latency low. Some processors — the video network and the email provider in particular — run global infrastructure, so your data may be processed in other countries.
- Every transfer outside the region happens under a processing agreement containing standard contractual data-protection clauses.
- We do not use a processor that fails to encrypt data in transit and at rest.
- Identity verification documents and IBANs stay field-level encrypted and do not leave our primary region.
6.How long we keep it
| Data type | Retention |
|---|---|
| Active account data | For as long as the account stays open |
| Account data after deletion | Thirty days as a recovery window, then permanent deletion |
| Invoices and accounting entries | Ten years, per commercial record-keeping requirements |
| Identity verification documents | Five years from the end of the teacher relationship |
| Progress data and certificates | For the life of the account; certificates stay verifiable by serial |
| Technical server logs | Ninety days |
| Fraud detection records | Two years |
7.How we protect it
- Encryption in transit over HTTPS is mandatory on every request, and encryption at rest is applied at the database layer.
- Extra field-level encryption for the most sensitive data: IBANs, identity document references and phone numbers.
- Internal access is role-based and least-privilege; reading a user's order data is written to an append-only audit log.
- Passwords are stored hashed with a modern algorithm and cannot be read by anyone here.
- We keep an incident response plan: if a breach affects your personal data we notify you and the competent authority within seventy-two hours of becoming aware of it.
8.Your rights
- Access: ask for a copy of the data we hold about you.
- Rectification: correct anything inaccurate, from your account settings or through support.
- Erasure: ask us to delete your account and data, except what we must keep by law, such as invoices.
- Portability: receive your data in a structured, machine-readable format (JSON) to take elsewhere.
- Objection and restriction: object to processing based on legitimate interest, or ask us to restrict it while we review your objection.
- Withdraw consent: stop marketing messages at any moment from notification settings or the unsubscribe link in every message.
Export and deletion requests go through the contact page today. A self-service export and delete button inside account settings is scheduled for a later phase and will produce the file immediately, with no human round trip.
10.Children's privacy
The platform is not aimed at anyone under thirteen and we do not knowingly collect their data. If we learn of an account belonging to a child under that age we delete it and its data. Learners aged thirteen to eighteen use the platform under a guardian's supervision and through the guardian's account.
11.Changes to this policy
We update this policy whenever we add a service or change a processor. Material changes — a new processing purpose, or a new processor with access to sensitive data — are notified by email and in-product thirty days before they take effect, and the “last updated” date at the top is refreshed in every case.