Privacy Policy
ZAYNO PTE. LTD. is the data controller for personal data processed in connection with ProMongoDB. This policy explains what we collect, why, how long we keep it, and how you can exercise your rights.
1. Data controller
ZAYNO PTE. LTD. — 12 Woodlands Square, Woods Square, Singapore 737715. Contact: privacy@promongodb.pro.
2. What we collect
- Account data: name, email, hashed password, role, preferences.
- Order data: billing name, billing address, items purchased, amounts, invoices.
- Learning data: course progress, quiz results, cohort participation, certificates.
- Support data: messages you send through the contact form or email.
- Technical data: IP address, user-agent, device type, coarse geolocation, and event logs — used for security and product analytics.
We do not knowingly collect data from children under 16.
3. Why we use it (legal bases under GDPR)
- Contract: to provide the courses, cohorts and account features you buy.
- Legal obligation: to issue invoices, keep tax records, and respond to lawful requests.
- Legitimate interest: to secure the service, prevent fraud, and improve the product; you can object at any time.
- Consent: for optional marketing emails and non-essential cookies; withdraw any time.
4. Cookies and analytics
We use strictly necessary cookies for authentication and cart state, and privacy-respecting analytics to understand aggregate usage. We do not sell personal data and we do not run advertising trackers.
5. Sharing with processors
We share data with a small set of vetted processors, only to the extent needed to run the service:
- Cloud hosting and database providers (EU/US regions, with SCCs where applicable).
- Payment processors for card and invoice payments.
- Email delivery for transactional messages.
- Customer support and error-monitoring tooling.
A current list of subprocessors is available in our Data Processing Addendum.
6. International transfers
Some processors are located outside your country. Where personal data leaves the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses and additional safeguards where required.
7. Retention
- Account: for as long as you keep an account, then up to 12 months after deletion for backups.
- Order and invoicing records: up to 7 years, as required by tax law.
- Support conversations: up to 3 years.
- Server logs: up to 90 days.
8. Your rights
Subject to applicable law, you have the right to:
- access your personal data and receive a copy;
- correct inaccurate data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with your local supervisory authority.
Send any request to privacy@promongodb.pro. We respond within 30 days.
9. Security
We use TLS for data in transit, encryption at rest for databases and backups, role-based access controls, audit logging and least-privilege principles. No system is perfectly secure — report suspected vulnerabilities to security@promongodb.pro.
10. Changes to this policy
We will notify you of material changes at least 14 days before they take effect via email or in-app notice.