Privacy Policy

The SpaceInfo Club — spaceinfo.club

Version: 2.2 — updated 21 September 2026 · Effective date: 21 September 2026 · Replaces: the version dated 09 September 2026

1. Who is responsible for your data

The SpaceInfo Club – Email: [email protected]

We have not appointed a Data Protection Officer; we are not required to. Write to the address above for anything concerning your data, and a person will read it.

2. What this policy covers

This policy explains how we handle personal data when you visit spaceinfo.club, register for a free webinar or masterclass, subscribe to our newsletter, create an account, take one of our courses, or contact us.

It sits alongside our Cookie Policy, which explains the trackers themselves, and our Terms and Conditions.

3. What we collect, and where it comes from

You give us directly:

  • your first name and email address, when you register for a webinar, subscribe, or create an account;
  • your account credentials;
  • billing details, when you purchase through our store — processed by WooCommerce and our payment provider, see §5;
  • anything you write to us, post in a course, or ask during a live session;
  • optionally, what you tell us about your background, your studies or your goals.

We collect automatically:

  • usage data: pages visited, time on page, referrer, approximate location derived from IP, device and browser type;
  • your progress inside a course: which modules you opened and completed. We use this to run the course and, where relevant, to handle a First Orbit Guarantee request;
  • identifiers set by cookies and similar technologies, subject to your consent — see the Cookie Policy.

We receive from third parties:

  • aggregated advertising and audience data from Google and Meta, where you interacted with our ads.

We do not buy personal data, and we do not collect special categories of data (health, beliefs, political opinions and so on). Please do not send them to us.

4. Why we use it, and our legal basis

What we doLegal basis
Deliver a course, membership or masterclass you registered or paid for; give you access; handle refundsContract — Art. 6(1)(b) GDPR
Send service messages: joining links, reminders, receipts, access details, changes to a ProgrammeContract — Art. 6(1)(b)
Send our newsletter and marketing emailsConsent — Art. 6(1)(a). Freely given, separate from any purchase, withdrawable at any time
Email our existing customers about our own similar productsLegitimate interest / soft spam — Art. 130(4) Italian Privacy Code. Every message carries a one-click opt-out
Analytics, to understand what works on the siteConsent — Art. 6(1)(a), collected through the cookie banner
Advertising, remarketing and audience building on Google and MetaConsent — Art. 6(1)(a), collected through the cookie banner. See §8 on profiling
Keep the site secure, prevent fraud and abuseLegitimate interest — Art. 6(1)(f)
Invoicing, tax and accounting recordsLegal obligation — Art. 6(1)(c)
Establish, exercise or defend legal claimsLegitimate interest — Art. 6(1)(f)

Providing your data is not a statutory obligation. For a purchase or a registration it is a contractual necessity: without a name and an email we cannot give you access or send you the joining link. For marketing it is entirely optional, and refusing has no effect on anything you have bought.

Withdrawing consent is always possible and takes effect for the future. It does not make what we did before unlawful.

5. Who else sees your data

We do not sell your personal data and we do not share it for anyone else’s independent marketing.

A note that matters for accuracy: much of our stack runs on our own website, not on someone else’s cloud. Our course platform (Tutor LMS), our funnel and opt-in forms (WPFunnels) and our email automation (Mail Mint) are software installed on our own hosting. The plugin makers do not receive your data. What matters for you is therefore who hosts, who transmits, who processes payment or who tracks — and that is this list:

WhoWhat they doWhere
HostingerWeb hosting and databases — where the site and its data physically liveEU
CloudflareDNS, CDN, security and bot protection in front of the siteUS / global
WooCommerceRuns our store, order and checkout process — software installed on our own hosting, like Tutor LMS and WPFunnels aboveRuns on our own server (Hostinger)
WooCommerce Stripe GatewayActually takes your card or other payment and holds your billing data. Live and processing real payments as of 21 September 2026 (confirmed by Sebastiano) — it was still in test/sandbox mode when we last checked, on 9 September 2026.US (Stripe)
BrevoTransmits the emails our automation generates — confirmed 9 September 2026 as the SMTP/API service configured in Mail MintEU (France)
beehiivRuns our newsletter; holds subscriber names and email addressesUS
Google (Analytics, Ads, Tag Manager, Fonts, reCAPTCHA)Site analytics, advertising, remarketing, form protection and web fontsUS
Meta (Facebook/Instagram pixel and ads)Advertising, conversion measurement and audience buildingUS / Ireland
WEBINAR PLATFORMHosts the live sessionsRef. To Google above

We may also disclose data to our accountant, our lawyers, or a public authority where the law requires it.

Each of the above acts as our processor under a data processing agreement, except Google and Meta, which act as independent or joint controllers for parts of their advertising activities under their own terms.

6. Transfers outside the EEA

Some of the recipients above are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on:

  • the EU–US Data Privacy Framework, where the recipient is certified under it; or
  • the European Commission’s Standard Contractual Clauses, with a transfer impact assessment and, where necessary, additional technical and organisational measures.

You may ask us for a copy of the safeguards in place for a specific transfer by writing to [email protected].

7. How long we keep it

DataRetained
Account and course dataWhile the account is open, then 12 months, unless a longer period is required for legal claims
Purchase, invoice and tax records10 years, as required by Italian law
Newsletter and marketing dataUntil you withdraw consent or unsubscribe, then a minimal suppression record so we do not email you again
Webinar registration data (if you never became a customer)24 months from the event
Recordings of live sessionsWhile the replay is available, and thereafter in our archive unless you ask for removal — see §9
Analytics dataPer the tool’s setting; Google Analytics is set to 14 months
Server and security logs30–90 days
Refund and guarantee correspondence10 years, as part of the contract record

8. Profiling and advertising

We use Google and Meta advertising tools that build audiences and show you our ads based on your behaviour on our site — including remarketing and lookalike-style audiences. This is profiling for direct marketing purposes.

Two things follow, and they are unconditional:

  1. You can object at any time, and we must stop. No reason required, no balancing test (Art. 21(2)–(3) GDPR).
  2. It only happens if you consented through the cookie banner. Decline marketing cookies, or change your choice later through the banner’s preferences, and it does not happen at all.

We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone (Art. 22 GDPR). Nothing we automate decides whether you get access, a refund, or a place on a course; a person does that.

9. Live sessions and recordings

Our live sessions are recorded, and we say so at the start of each one.

  • If you attend with camera and microphone off and do not post in the chat, you do not appear in the recording. That is the default.
  • If you turn on your camera or microphone, or write in the chat, that participation may be captured and included in the replay we make available to registrants.
  • You can ask us to remove you — write to [email protected] and we will edit you out or remove the recording. You do not have to explain why.
  • If we ever want to use a clip of an identifiable participant in advertising, we ask that person specifically and in advance. We never treat your acceptance of our Terms as permission for that.

10. Your rights

Under the GDPR you have the right to: access your data; have it rectified; have it erased; restrict processing; object to processing based on legitimate interest, and object absolutely to direct marketing; receive your data in a portable format; and withdraw consent at any time.

How to exercise them: email [email protected]. There is no charge.

How fast we respond: we reply without undue delay and in any event within one month of receiving your request. Where a request is complex or where you have made several, we may extend by up to two further months — and if we do, we will tell you within the first month and explain why. This is the standard set by Article 12(3) GDPR.

If you are unhappy with how we handled it, you may lodge a complaint with a supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali (garanteprivacy.it); or, if you live or work elsewhere in the EU, with the supervisory authority of your own country, which Article 77 GDPR entitles you to do. You may also go to court.

11. Marketing: how to stop hearing from us

Every marketing email carries a one-click unsubscribe link. You can also write to [email protected] and simply say stop.

Unsubscribing from marketing does not cancel a course you have paid for, and does not stop the service messages you need — access details, receipts, and notices about a Programme you hold.

12. Children

Our services are not directed to anyone under 16, and we do not knowingly collect their data. To purchase a Programme you must have reached the age of majority in your country, or have the consent of a parent or guardian — see §9 of our Terms and Conditions.

If you believe a child has given us personal data, write to [email protected] and we will delete it.

13. Security

We use HTTPS across the site, access controls on the administrative back end, a security and bot-protection layer in front of the site, and regular backups. No system is perfectly secure; if a breach occurs that is likely to result in a high risk to your rights, we will notify you and the Garante as Articles 33 and 34 GDPR require.

14. Changes to this policy

We may update this policy. The version number and effective date at the top change when we do. Where a change materially affects how we use data about you, we will tell you by email before it takes effect. We keep dated copies of previous versions and will provide one on request.

15. Contact

[email protected] — for privacy requests, put Privacy in the subject line.

The SpaceInfo Club

Shopping Cart