1. Scope and contact
This policy explains how personal data is processed when you visit ARVAcademy, use its mobile application, create an account, purchase access or contact support. The service is operated by Benoît DARENNE, an individual established in Switzerland, who is the controller responsible for the processing described here. For privacy requests, contact arvacademy@etik.com.
The policy covers our own services. Authentication providers, payment merchants, app stores and external websites also process data under their own privacy notices. The Swiss Federal Act on Data Protection applies where relevant; the EU General Data Protection Regulation applies where its territorial conditions are met.
2. Information we process
Account and sign-in information: the account identifier, name, username, email address, email-verification status and provider identifier supplied by the sign-in service you choose. Available providers include Apple, GitHub, GitLab, Google and Microsoft. We receive authentication results and tokens, not your provider password.
Learning and account activity: chapters and parts read, exercise and quiz results, progress, learning streaks, preferences, access entitlements, purchase references and account activity needed to operate the service. We process messages, feedback and content reports that you submit, and saved projects or code where you use a saving feature.
Technical information: requests to our services, IP addresses, browser or device characteristics, timestamps, authentication events and diagnostic information. An error report may contain an error message, stack trace and incidental values included in the error. We cannot describe those reports as guaranteed anonymous.
Purchase information: transaction and product identifiers, purchase status, entitlement and expiry information and, for web billing, the customer reference supplied by the merchant. Payment details are entered with the payment provider or app store; ARVAcademy does not receive your complete card number or card security code.
3. Purposes and grounds for processing
We use account, progress and entitlement data to provide the service you request: authenticate you, deliver learning content, synchronise your progress, enable offline access and verify purchases. Where the GDPR applies, the basis is performance of our contract or steps you request before entering into it.
We process information required to meet applicable legal obligations, including accounting obligations and responding to lawful requests. We also process limited information for legitimate interests in securing accounts, preventing abuse, resolving disputes, answering support requests and diagnosing service failures, subject to your rights and interests.
Where consent is legally required for optional processing, consent is the applicable basis. Accepting these terms or reading this policy is not blanket consent to tracking. Withdrawing consent does not affect processing already lawfully carried out or processing supported by another applicable basis.
Providing account and purchase-verification information is necessary for the corresponding features. If you do not provide it, we may be unable to create your account, grant paid access or respond to your request. Optional features can be left unused.
4. Cookies and storage on your device
The website uses necessary authentication cookies and temporary sign-in state to keep sessions secure. In the current configuration, the access cookie expires after 15 minutes, the refresh cookie after 30 days and temporary OAuth cookies after 10 minutes; successful renewal can start a new validity period.
Browser storage can retain preferences and feature state. The mobile app uses the operating system’s secure storage for session credentials and a local database for downloaded lessons, progress, access information and pending synchronisation. Signing out clears account-specific mobile data; clearing browser or app storage can remove local settings and unsynchronised work.
You can manage cookies and site data through your browser, and app data through your device settings. Blocking necessary storage can prevent sign-in and offline features. These necessary storage operations are separate from the audience measurement described below.
5. Audience measurement and diagnostics
When enabled on the website, PostHog Cloud EU receives selected page-view, learning-action and performance events to help us assess usability and reliability. Our client configuration disables persistent analytics storage, automatic interaction capture, personal profiles and session replay, and honours the browser’s Do Not Track signal.
Events do not intentionally include your account identifier, name or email address. URL query strings and fragments are removed from URL properties. Network delivery and cookieless measurement may nevertheless involve technical identifiers and network information; absence of cookies does not mean absence of personal-data processing.
Unexpected errors may be reported to PostHog with their execution traces. The error body is not comprehensively redacted, so values contained in an error can be transmitted. Operational metrics and server logs may also be sent to Grafana Cloud for monitoring and incident investigation. These tools are used for measurement and technical diagnosis, not for advertising profiles.
6. AI assistance and external learning tools
When you ask the AI assistant a question, your question, relevant conversation context and selected course excerpts are sent to the model provider used for that request. AI usage and quota information may be associated with your account. If you configure a provider credential, it is processed to authenticate requests to that provider.
Depending on the available configuration, AI requests can involve Google Gemini, OpenRouter and the model providers it routes to, or a provider you select such as OpenAI, Anthropic, Mistral, DeepSeek, Groq or xAI. Their processing and retention depend on the provider, model and account terms. Do not include passwords, private keys or personal or confidential information that is unnecessary for the learning question.
Opening an external coding environment such as StackBlitz or loading externally hosted media can transmit your IP address, browser information and the material needed for that feature to its provider. Saving or sharing a project there follows that provider’s settings and terms.
7. Who receives information
Access is limited to people who need information to operate ARVAcademy, handle support, administer access or investigate incidents. Relevant service categories include hosting and infrastructure, authentication, payment processing, purchase validation, diagnostics and the optional learning tools described above.
The platform’s hosting provider is Infomaniak Network SA in Switzerland. PostHog supplies the EU analytics and error-reporting service; Grafana Cloud supplies monitoring. Paddle acts as the merchant of record for web purchases where Paddle checkout is offered. Apple or Google handles purchases made through its app store, and RevenueCat processes purchase and entitlement information to enable validation and restoration.
Some providers process data on our instructions, while authentication providers, merchants and app stores also act for their own purposes, such as account security, fraud prevention or tax compliance. We may disclose information where required by law or necessary to establish, exercise or defend legal claims. We do not sell your personal data.
8. Processing outside your country
Hosting in Switzerland does not mean that all processing remains in Switzerland. Authentication, payments, analytics, monitoring and AI features can involve providers and infrastructure in the European Economic Area, the United Kingdom, the United States and, depending on the AI provider you choose, other countries, including China.
The destination and protection available depend on the service used and its contractual arrangements. You can contact arvacademy@etik.com for information about the countries involved and the applicable transfer mechanism, including any adequacy decision or contractual safeguards. Choosing an external service does not remove the data-protection obligations that apply to ARVAcademy.
9. How long information is retained
Account and learning records are retained while needed to provide your account, synchronise progress and recognise your purchased access. If you request deletion, we assess which records can be erased and which must be retained for a specific legal obligation or a pending claim.
Purchase and accounting evidence can be retained for the applicable statutory period. Support correspondence and security records are retained according to the purpose of the exchange, incident or dispute; access is limited when a record is no longer needed for ordinary service operation.
Local downloads and preferences remain until cleared by the application or by you. Authentication data is subject to the validity periods described above. Copies held by external providers or in backups follow the relevant retention and recovery arrangements, so removal from every system may not be immediate. Contact arvacademy@etik.com to ask about the retention applicable to your data.
10. Your rights and how to exercise them
Subject to the law that applies, you may request access to your personal data, correction of inaccurate information, deletion, restriction of processing and a portable copy of eligible data. You may object to processing based on legitimate interests and withdraw consent for processing that relies on consent.
Send your request to arvacademy@etik.com, preferably from the email address associated with your account. We may request proportionate information to verify your identity. We normally respond within one month; if an extension or a legal exception applies, we explain it. Requests are normally free of charge.
You may complain to the Swiss Federal Data Protection and Information Commissioner or, where the GDPR applies, to the competent supervisory authority, including in your country of habitual residence. Contacting us first is welcome but is not a condition for making a complaint.
Learning scores, recommendations and access checks support the service; they are not decisions granting formal qualifications or employment. Contact us if you need a human review of an account or access issue.
11. Security and younger users
We use safeguards appropriate to the service, including encrypted network connections, access controls and secure storage for mobile session credentials. No system can guarantee absolute security. Report a suspected account compromise or data incident to arvacademy@etik.com.
ARVAcademy is intended for people learning software development. A user who lacks the legal capacity required to enter into the service agreement must involve a parent or legal guardian. If you believe a child has provided data without the required authorisation, contact us so we can assess and address the situation.
12. Changes to this policy
The date at the top of this policy identifies this version. We may update the policy to reflect changes in the service, providers or legal requirements. Where a change materially affects how your personal data is used, we will provide the notice or request the consent required by applicable law. This policy does not reduce your statutory rights.