Legal information

Privacy policy

This policy explains which personal data Your Learning Path processes, why it is needed, who may receive it and which choices and rights you have.

Last updated: 29 July 2026

1. Who is responsible?

HZE Ltd., established in Malta, operates Your Learning Path and Jouw Leerweg and is the controller for the personal data described in this policy. D.H.J. Hendriks is the CEO.

Questions and privacy requests can be sent to the contact address shown on this page. We may ask for information needed to verify your identity before completing a request.

2. Who may use the current service?

The current pilot and account environment are intended for adult learners and parents or guardians. Independent child accounts and parent-child account controls have not yet been implemented.

A minor should therefore not create or operate an account independently. A parent or guardian who uses the platform for home education remains responsible for supervision and compliance with applicable education rules.

3. Data we process

  • Account and security data, such as name, email address, password hash, chosen language, time zone, login and session data, passkeys, two-factor authentication data and account status.
  • Optional profile data, such as forum name, telephone number, address fields, biography, date and place of birth, gender and a private profile photo.
  • Learning data, including learning goals, plans, calendar entries, study time, private library materials, notebooks, flashcards, assignments, result versions, reflections, AI-support declarations, whiteboards, activity history and evidence-dossier records.
  • Communication data from public forum posts and attachments, private adult conversations, teacher-feedback prototypes, helpdesk messages and contact requests.
  • Identity and certificate data, including a user-redacted identity PDF, verification status, approved identity fields, certificate files and public verification tokens when those prototype functions are used.
  • Subscription test data, such as a Stripe customer reference, plan status and limited payment-method details. HZE Ltd. does not store complete card numbers.
  • Technical and security data, such as IP address, request time, browser or device information and server logs where these are generated by the web server, session system or security controls.
  • First-party analytics data, including a random analytics identifier, session identifier, event, route or feature name, time and limited properties. For a signed-in user, an event may be linked to the internal user ID.

4. Purposes and legal bases

Providing the service
We process account, learning, communication and security data to create and operate your account, store your work and provide the functions you request. The basis is performance of our agreement or steps requested before entering it.
Safety and integrity
We prevent abuse, secure accounts, investigate incidents, moderate public content and preserve the integrity of results and certificates. The basis is our legitimate interest in a safe and reliable service and, where applicable, a legal obligation.
Product improvement
We use limited first-party analytics to understand visits, activation, retention and feature use during the pilot. The basis we rely on is our legitimate interest in improving the service. You may object to this processing.
Communication and support
We answer questions, deliver service messages and operate the private helpdesk. The basis is performance of the service and our legitimate interest in providing support.
Legal duties
We may process or retain data when this is necessary for accounting, tax, regulatory requests, disputes or other duties imposed by law.
Consent
Where a function legally requires consent, we will request it separately. Consent can be withdrawn for the future without affecting earlier lawful processing.

5. Analytics and technical logs

The internal analytics system is active and uses a first-party identifier cookie. It does not store the visitor’s IP address, complete user agent, form values, message text or private learning content inside analytics events. IP addresses and user-agent details may still be processed separately in sessions and operational server or security logs.

Analytics events are visible only to authorised administrators in aggregated reports and are automatically eligible for deletion after 13 months. We do not use these events for advertising or sell them to data brokers.

6. When data is shared

  • Service providers may process data only where needed for hosting, infrastructure, email, security, support or other contracted operations.
  • Helpdesk messages and their attachment may be exchanged with a private Telegram support group when that integration is enabled. The integration does not deliberately send your name or email address as Telegram metadata.
  • Stripe processes checkout and payment data when the subscription test functions are used. Stripe’s own privacy information applies to its processing.
  • A third-party AI client can access or create data only when you create a scoped API token for that client. The platform currently has no built-in AI provider that automatically receives private learning content.
  • Other people see data only when you deliberately publish it on the forum or grant a specific supported access right. Private learning content is not made public by default.
  • We may disclose data to authorities or professional advisers where the law requires this or where necessary to establish, exercise or defend legal claims.

7. International processing

HZE Ltd. is established in Malta. A service provider may process data in another country. Where personal data leaves the European Economic Area, we require an appropriate transfer mechanism or another lawful basis for that transfer.

8. How long data is kept

  • Account, profile and private learning data are normally kept while the account exists. Account deletion removes the account and linked private files from the active application, except where retention is legally required.
  • Public forum content is associated with the account and is removed when the account is deleted under the current implementation. Moderation records may be retained where needed to handle abuse or disputes.
  • Private conversations, helpdesk content and attachments are retained while the related conversation or account exists.
  • An identity document remains in protected private storage while verification or the resulting administrative record is needed and is removed when the account is deleted. A shorter final retention schedule for identity verification is still being developed.
  • Analytics events are retained for no more than 13 months under the current automated retention setting.
  • Session, security and operational logs are retained only for their operational or security purpose. Residual copies may remain temporarily in protected backups until the normal backup cycle replaces them.

9. Security

We use server-side authorisation, private file storage, encrypted transport, hashed passwords, access controls and other technical and organisational measures appropriate to the service. No internet service can guarantee absolute security.

Keep your login details and recovery codes private. Notify us promptly if you suspect unauthorised account access or an accidental disclosure.

10. Your rights

Some rights are subject to legal conditions and exceptions. We will explain the outcome if we cannot fully comply with a request.

  • Request access to and a copy of your personal data.
  • Correct inaccurate or incomplete personal data.
  • Request erasure or restriction where the legal requirements are met.
  • Object to processing based on legitimate interests, including the current first-party analytics.
  • Receive data you supplied in a portable format where the right to data portability applies.
  • Withdraw consent for future processing where processing is based on consent.
  • Complain to the Office of the Information and Data Protection Commissioner in Malta or another competent supervisory authority.

11. Changes to this policy

We may update this policy when the service, providers or legal requirements change. The date at the top identifies the current version. Material changes will be communicated through an appropriate channel.