Privacy Policy
Last updated: 24 August 2026
This notice explains how Okyanusi Ltd collects, uses, shares and protects personal data when you visit okyanusi.com, create an account, buy or access a course, membership, digital product or service, contact support, or receive communications from us. It is intended to meet the transparency requirements of the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and—where our offering or monitoring falls within its territorial scope—the EU GDPR. Turkish-law information is also included where Law No. 6698 applies.
1. Controller and contact
Okyanusi Ltd
Company number: 12043593
Registered office: 45B Meads Road, London, England, N22 6RN
Email: [email protected]
Okyanusi Ltd is the controller for the processing described in this notice. Privacy requests may be sent to the email above. We have not appointed a data protection officer because our current processing does not require one.
2. Data we collect
- Identity and account data: name, username, account identifiers and password reset status.
- Contact data: email address, telephone number, billing address and communication preferences.
- Order and contract data: products or services purchased, price, tax, order status, access records, consent records and support history.
- Payment data: payment status, payment method type, limited card details such as last four digits, and payment or refund identifiers. Full card details are handled by payment providers and are not stored by us.
- Technical and usage data: IP address, browser and device information, security logs, pages or lessons accessed, timestamps, progress and interactions.
- Communications: emails, support requests, complaints, reviews and other messages you send us.
- Marketing and cookie data: consent choices, campaign interactions and non-essential analytics or advertising data where you have consented.
3. Sources
We obtain data directly from you, from your use of our website and learning systems, and from service providers such as payment processors, security tools, email providers and analytics platforms. If we receive personal data from another source, we provide the required information within the applicable period.
4. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Create and manage accounts; deliver purchases, memberships, courses and support | Contract |
| Take payments, issue refunds, keep tax and accounting records | Contract and legal obligation |
| Prevent fraud, secure accounts, enforce terms and defend legal claims | Legitimate interests and legal obligation |
| Improve products, troubleshoot and produce aggregated business analytics | Legitimate interests; consent where non-essential cookies are used |
| Send transactional messages about orders, access and security | Contract and legitimate interests |
| Send marketing by email or use advertising cookies | Consent, or the PECR soft opt-in where lawfully available; you can opt out at any time |
| Comply with regulators, courts and lawful requests | Legal obligation and legitimate interests |
Where we rely on legitimate interests, those interests are operating and securing the service, preventing abuse, improving customer experience and protecting legal rights. We balance them against your interests and rights.
5. When data is required
Identity, contact, billing and order information is normally required to enter into and perform a purchase contract. If it is not provided, we may be unable to create the account, take payment or supply the product or service. Marketing consent is optional and is not a condition of purchase.
6. Recipients and processors
We share only what is necessary with categories of providers that help us operate: hosting and content delivery, WordPress and learning-platform services, payment processors such as Stripe or PayPal, email and customer-communication services such as Brevo, analytics and advertising providers such as Google or Meta where consent applies, fraud and security providers, professional advisers, and public authorities where legally required. Providers act under appropriate contractual and confidentiality duties. We do not sell personal data.
7. International transfers
Some providers may process data outside the United Kingdom or European Economic Area. A restricted transfer is made only where a lawful mechanism applies, such as a UK or EU adequacy decision, the UK International Data Transfer Agreement/Addendum, EU Standard Contractual Clauses, another appropriate safeguard, or a permitted exception. Information about the relevant safeguard is available on request. Where Turkish data-protection law applies, cross-border transfers must also use a mechanism permitted by Article 9 of Law No. 6698.
8. Retention
- Order, invoice, tax and payment records: normally 6 years after the end of the relevant financial year.
- Account and course-access records: while the account or access remains active, then normally up to 3 years, unless a longer period is needed for a contract or claim.
- Support and complaint records: normally 3 years after closure; longer where a dispute, chargeback or legal claim is active.
- Security and technical logs: normally up to 12 months, unless needed to investigate abuse or an incident.
- Marketing records: until you opt out; we may retain a minimal suppression record so we do not contact you again.
- Consent and contract-version evidence: normally 6 years after the relevant transaction or withdrawal.
We may retain data longer where law, a regulator, litigation or fraud prevention requires it. Data is then deleted or anonymised securely.
9. Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent. Withdrawing consent does not affect earlier lawful processing. Send requests to the contact above. We may verify identity and will respond within the applicable legal period. You may complain to the UK Information Commissioner’s Office at ico.org.uk. Where the EU GDPR applies, you may also complain to the supervisory authority in the EU/EEA country of your habitual residence, work or the alleged infringement. If Turkish law applies, you may exercise the rights in Article 11 of Law No. 6698.
10. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects about course access or customer support. Payment and fraud providers may use automated checks under their own notices; we review matters where appropriate.
11. Children
Our paid products are not directed to children. A person under 18 should purchase only through a parent or legal guardian. Contact us if you believe a child has provided personal data improperly.
12. Security
We use proportionate technical and organisational measures, including HTTPS, access controls, backups, software updates and provider due diligence. No internet service is completely risk-free.
13. Cookies and marketing choices
Non-essential analytics and advertising technologies are used only after the required consent. You can reject them or change your choice through the cookie controls. See our Cookie Policy. Every marketing email includes an unsubscribe method; service messages may still be sent where necessary.
14. Changes
We may update this notice when our services, providers or law change. The current version and date will be published here. Material changes will be highlighted or communicated where required.
Your Rights and Data Subject Requests
You have the right to request access to, correction of, or erasure of your personal data, to object to or restrict its processing, and to data portability. Requests can be sent to [email protected] and are handled free of charge within one month. For your security, information about a request is only disclosed in connection with the verified contact address it was submitted from.
After an erasure request is completed, your e-mail address may be retained solely on a suppression list to prevent any future communications being sent to you; it is not used for any other purpose and will also be removed on request. The request and our response are retained as evidence of compliance. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.