Legal

Privacy Policy

Effective date: July 12, 2026

1. Data Controller

Networkdone (“we,” “us,” or “our”) is the data controller responsible for your personal information collected through our website and learning platform located at networkdone.com.

For questions about this Privacy Policy or your personal data, contact us at [email protected].

2. Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, username, and hashed password when you register an account.
  • Profile data: Career path, optional profile picture URL, and other preferences you choose to provide.
  • Usage data: Lab sessions, scenario progress, quiz results, XP events, learning streaks, and module completion records.
  • Payment data: Billing address, subscription tier, and payment status. Full card numbers are processed by Stripe and never stored on our servers.
  • Technical data: IP address, browser type and version, operating system, device identifiers, pages visited, and session duration collected via server logs and analytics.
  • Communications: Support emails, feedback submissions, and any messages you send us.

3. How We Use Your Data

We use your personal data to:

  • Create and manage your account and authenticate your access
  • Deliver the learning platform, track progress, and issue certificates
  • Process subscription payments and manage billing
  • Personalize your learning experience and recommend content
  • Send transactional emails (password resets, subscription receipts, certificate notifications)
  • Send optional marketing communications if you have opted in
  • Detect and prevent fraud, abuse, and security incidents
  • Analyze usage patterns to improve the platform
  • Comply with legal obligations

5. Sharing & Disclosure

We do not sell your personal data. We share data only with:

  • Service providers: Stripe (payment processing), cloud hosting providers, transactional email services, and analytics tools — each bound by data processing agreements.
  • Legal authorities: When required by law, court order, or governmental authority, or to protect our rights or the safety of others.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, in which case the acquiring entity will be bound by this Privacy Policy or will provide advance notice of any changes.

Certificates of completion that you choose to share publicly will display your name and completion date. You control the visibility of your certificate.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account and profile data: retained while your account is open, then deleted within 30 days of account deletion.
  • Learning progress and certificates: retained for 5 years after account deletion to allow re-issuance of certificates.
  • Payment records: retained for 7 years as required by Turkish and EU tax regulations.
  • Server logs and technical data: retained for 90 days, then automatically purged.
  • Marketing consent records: retained for 3 years from the last interaction.

You may request earlier deletion of your data — see Your Rights below.

7. Your Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure (Right to be Forgotten): Request deletion of your personal data, subject to our legal retention obligations.
  • Portability: Receive your data in a structured, machine-readable format.
  • Restriction: Ask us to pause processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Unsubscribe from marketing emails at any time; manage cookie consent in the banner.
  • KVKK rights: Turkish residents may exercise all rights under KVKK Article 11 by contacting us directly.

To exercise any of these rights, email [email protected]. We respond within 30 days. You may also lodge a complaint with your local supervisory authority (e.g., CNIL, ICO, or the Turkish KVKK Board).

8. Cookies

We use the following categories of cookies:

  • Essential cookies: Required for authentication, session management, and core platform functionality. These cannot be disabled.
  • Analytics cookies: Collected with your consent to understand how visitors interact with the platform. We use anonymized data only.
  • Preference cookies: Store your theme (light/dark), language, and other UI preferences.

You can manage your cookie consent at any time using the banner shown on your first visit or by clearing the nwd_cookie_consent key from your browser's local storage.

9. Security

We implement industry-standard security measures including TLS encryption for data in transit, bcrypt hashing of passwords, regular security reviews, and access controls that limit data access to authorized personnel only.

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant authorities within the timeframes required by applicable law (72 hours under GDPR).

10. International Data Transfers

Our servers are located in the European Union. Some of our service providers (including Stripe) may process data outside the EEA. Where data is transferred internationally, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms.

11. Children

The Service is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us immediately at [email protected] and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by email or a prominent notice on the platform at least 14 days before the changes take effect. The “Effective date” at the top of this page indicates when the current version was last revised.

13. Contact

For any questions, requests, or concerns regarding this Privacy Policy or your personal data:

Networkdone Privacy Team
[email protected]