Effective: 24 May 2018
Terms of Service
Thank you for using CodeGalaxy!
We want to show you that we handle your personal information in a confidential and responsible way and that any processing of your personal information takes place in compliance with the General Data Protection Regulation („GDPR“).
To avoid unauthorized access to your personal data and generally secure such data, we and our partners use encrypted transmission. Those safety measures are constantly revised to comply with the latest technological developments.
What You Agree to by Using Our Site
Please note that we rely on legitimate interests as the basis for processing your data in the limited circumstances set out below:
- - In situations where we obtain your personal data from a source other than you, we process your data on the basis of legitimate interests, until the earlier of (a) the point at which you provide your consent; or (b) the point at which you ask us to stop processing your data on the basis of our legitimate interests;
- - We will retain your student records relating to degrees or credit-bearing courses for our own compliance and verification purposes, even after you withdraw your consent to our processing of your data;
- - We will archive information about your use of our services, even after you withdraw your consent to our processing of your data. This information will only be used in very limited circumstances, such as for defending legal claims relating to contracts we have with you or a third party and retention for audit purposes relating to commercial contracts; and
- - We will use information relating to your use of our services for statistical analysis and research purposes, however we delete your name and email address from such information before we do so.
What Information We Collect
We gather two types of information about users through the Site:
1. Information relating to your use of our Site. When users come to our Site, we may track, collect and aggregate information indicating, among other things, which pages of our Site were visited, the order in which they were visited, when they were visited, and which hyperlinks were "clicked." We also collect information from the URLs from which you linked to our Site. Collecting such information may involve logging the IP address, operating system and browser software used by each user of the Site. We may be able to determine from an IP address a user’s Internet Service Provider and the geographic location of his or her point of connectivity.
If you visit the Websites, we process only Data that your browser communicates to our servers.
We collect the following Data, which is necessary for us in order to display the Website correctly and
guarantee the necessary stability and safety:
date and time stamp;
time difference to GMT;
access status/HTTP status code;
transmitted data volume;
site from which the request was sent;
operating system and interface; and
language and version of the browser software.
2. Personally Identifiable Information provided directly by you or via third parties. We collect Personally Identifiable Information that you provide to us when you register for an account, update or change information for your account, complete a survey, sign-up for email updates or Courses, participate in our public forums, discussions, send us email messages, and/or participate in Courses or other services on our Site. We may use the Personally Identifiable Information that you provide to respond to your questions, provide you the specific course and/or services you select, send you updates about Courses offered by CodeGalaxy or other CodeGalaxy events, and send you email messages about Site maintenance or updates.
Account Registration. If you register for an account on our Site, you may be required to provide us with
Personally Identifiable Information such as your name and email address.
Depending on your choice of registration, we process the following Data:
email address and full name.
Facebook single sign-on application:
email address, full name;
third-party ID; and
Google single sign-on application:
email address, full name, gender;
IP address; and
- - Updates. CodeGalaxy may offer you the ability to receive updates either via email or by posting on portions of the Site only accessible to registered users. In order to subscribe to these services, you may be required to provide us with Personally Identifiable Information such as your name and email address.
- - Participation in Courses. CodeGalaxy offers users the opportunity to participate in a Course on or through the Site. If you desire to participate in a course, you will be asked to provide us with certain information necessary to conduct such a course. This information may include, among other things, your name and email address.
If you participate in a course, we may collect from you certain student-generated content, such as answers you submit, peer-graded reviews, and peer grading contribution feedback. We also collect course data, such as student responses to quizzes, and surveys. You should not include any Personally Identifiable Information or other information of a personal or sensitive nature, whether relating to you or another person, on answers, or surveys, except for information required to participate or submit such answerd, or surveys.
- - Identity Verification. CodeGalaxy may offer you the ability to verify your identity for selected courses. In order to enroll for these services, you may be required to provide us or our third-party identity verification vendor with Personally Identifiable Information such as your name, address, date of birth, a headshot taken using a webcam, and a photo identification document.
- - Communications with CodeGalaxy. We may receive Personally Identifiable Information when you send us an email message or otherwise contact us.
- - Third Party Sites. We may receive Personally Identifiable Information when you access or log-in to a third party site, e.g., Facebook, Google+, from our Sites. This may include the text and/or images of your Personally Identifiable Information available from the third party site.
- - Surveys. We may receive Personally Identifiable Information when you provide information in response to a survey operated by us. This may include details about your race, your education history, and your employment.
- - Partner sites. Partner sites providing Course related tools and services to CodeGalaxy users may collect nonfinancial individual level user data regarding the individual’s use of that partner site while engaged with such Course related activities, and the partner sites may share that data with CodeGalaxy for the purpose of improving CodeGalaxy’s services, the partner site’s services, and the individual’s education experience. This data includes information such as the amount of time spent on the partner site and pages viewed.
Third Party Credit Card Processing. CodeGalaxy provides you with the ability to pay for Courses and other services
using a credit card through a third party payment processing service provider. Please note that our service
provider – not CodeGalaxy – processes and/or collects your credit card information.
When you make purchases in the Services, we process the following Data:
credit card information; and
When you use the Services, we process the following Data:
when you checked prices on subscription, and what subscription you were interested in;
when you purchase something in the Services; and
what kind of tracks, courses, and exercises you complete.
How We Use the Information
1. Information relating to your use of our Site. We use information relating to your use of the Site to build higher quality, more useful services by performing statistical analyses of the collective characteristics and behavior of our users, and by measuring demographics and interests regarding specific areas of our Site. We may also use this information to ensure the security of our services and the Site.
- - Providing the Site and our services. We use Personally Identifiable Information which you provide to us in order to allow you to access and use the Site and in order to provide any information, products or services that you request from us.
- - Technical support and security. We may use Personally Identifiable Information to provide technical support to you, where required, and to ensure the security of our services and the Site.
- - Updates. We use Personally Identifiable Information collected when you sign-up for our various email or update services to send you the messages in connection with the Site or a Course. We may also archive this information and/or use it for future communications with you, where we are legally entitled to do so. The processing of Data pursues the purpose of marketing for our own products (newsletters, push messages).
- - Discussions. You should not post any Personally Identifiable Information or other information of a personal or sensitive nature, whether relating to you or another person, within a Discussion post. If you choose to post Personally Identifiable Information, such Personally Identifiable Information may be collected during your use of the Discussions. We may publish this information via extensions of our Platform that use third-party services, like mobile applications. We reserve the right to reuse Discussion posts that contain Personally Identifiable Information in future versions of the courses we offer, and to enhance future course offerings. We may archive this information and/or use it for future communications with you and/or your designee(s), and/or provide it to the business partner associated with the courses you have taken. We may also use or publish posts submitted on the Discussions without using Personally Identification Information.
- - Participation in Courses. We use the Personally Identifiable Information that we collect from you when you participate in a Course through the Site for processing purposes, including but not limited to tracking attendance, progress, and completion of a Course. We may also share your Personally Identifiable Information and your performance in a given Course with the contributor or contributors who create the course, with teaching assistants or other individuals designated by the contributor or contributors to assist with the creation, modification or operation of the course, and with the institution or institutions with which they are affiliated. Also, we may archive this information and/or use it for future communications with you, where we are legally entitled to do so.
- - Identity Verification. For services that require identity verification, we use the Personally Identifiable Information that we collect for verifying your identity, and for authenticating that submissions made on the Site were made by you. This service may be provided through a third-party identity verification vendor. Your photo identification document will be deleted after successful verification of your profile information.
- - Communications with CodeGalaxy Business Partners. We may share your Personally Identifiable Information with business partners of CodeGalaxy so that CodeGalaxy business partners may share information about their products and services that may be of interest to you where they are legally entitled to do so.
- - Research. We may share general course data (including quiz or assignment submissions, grades, and comments/discussions), information about your activity on our Site, and demographic data from surveys operated by us with our business partners so that our business partners may use the data for research related to online education.
- - Disclosure to Acquirers. CodeGalaxy may disclose and/or transfer your Personally Identifiable Information to an acquirer, assignee or other successor entity in connection with a sale, merger, or reorganization of all or substantially all of the equity, business or assets of CodeGalaxy to which your Personally Identifiable Information relates.
The lawfulness of processing (Art. 6 GDPR) stems from
the consent pursuant para. 1 subpara. a GDPR upon registration;
the necessity for the performance of contract fulfillment pursuant para 1 subpara. b GDPR, as your Data is needed for a satisfactory use of the Services; and/or
the necessity for the purposes of the legitimate interests pursued by the CodeGalaxy or by a third party.
For some tasks we use the help of service providers (e.g. tax advisors or analytics services) which we have chosen and instructed carefully, or other third parties. Some service providers are situated in the United States. Therefore, Data is transferred to third parties in third countries, all of which adhere to the EU-US privacy shield (see https://www.privacyshield.gov/welcome for more information): Auth0, Inc., 10900 NE 8th Street Suite 700, Bellevue, WA 98004, USA; Facebook, Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA (“Facebook”); Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”); Yandex Oy Limited Company - Moreenikatu 6, 04600 Mantsala, Finland (“Yandex”); Mixpanel, Inc., 405 Howard St., Flr 2, San Francisco, CA 94105, USA (“Mixpanel”); 2Checkout.com, Inc., 855 Grandview Avenue, Suite 110, Columbus, OH 43215, USA (“2CO” or “2Checkout”); and Bing, Microsoft - https://privacy.microsoft.com/en-us/privacystatement#maincookiessimilartechnologiesmodule.
Retention of Personally Identifiable Information
If you reside or are located in the EEA, we keep your Personally Identifiable Information for no longer than necessary for the purposes for which the Personally Identifiable Information is processed. The length of time we retain Personally Identifiable Information for depends on the purposes for which we collect and use it and/or as required to comply with applicable laws and to establish, exercise or defend our legal rights.
Confidentiality & Security of Personally Identifiable Information
Updating or Deleting Your Personally Identifiable Information
You have certain rights in relation to your Personally Identifiable Information. You can access your Personally Identifiable Information and confirm that it remains correct and up-to-date or choose whether or not you wish to receive material from us or some of our partners by logging into the Site and visiting your user account page.
We store your Data as long as you are a registered user of the Services. Where we retain information for Service improvement and development during your membership, we take steps to eliminate information that directly identifies you and we only use the information to uncover collective insights about the use of our Services, not to specifically analyze personal details about you.
After you have deleted your account we only store Data if it is legally necessary (because of warranty, limitation or retention periods) or otherwise required.
Data will be deleted if you (a) revoke your consent to the storage (b) Data is not needed to fulfill the user contract concerning the Services anymore, or (c) the storage is or becomes legally impermissible. A deletion request does not affect Data, if the storage is legally necessary, for example for accounting purposes.
If you would like further information in relation to your rights or would like to exercise any of them, you may also contact us via [email protected] . If you reside or are located in the EEA, you have the right to request that we:
- - provide access to any Personally Identifiable Information we hold about you;
- - prevent the processing of your Personally Identifiable Information for direct-marketing purposes;
- - update any Personally Identifiable Information which is out of date or incorrect;
- - delete any Personally Identifiable Information which we are holding about you;
- - restrict the way that we process your Personally Identifiable Information;
- - provide your Personally Identifiable Information to a third party provider of services; or
- - provide you with a copy of any Personally Identifiable Information which we hold about you.
We try to answer every email promptly where possible, and provide our response within the time period stated by applicable law. Keep in mind, however, that there will be residual information that will remain within our databases, access logs and other records, which may or may not contain your Personally Identifiable Information. Please also note that certain Personally Identifiable Information may be exempt from such requests in certain circumstances, which may include if we need to keep processing your Personally Identifiable Information to comply with a legal obligation.
When you email us with a request, we may ask that you provide us with information necessary to confirm your identity.
You can revoke the consent for future data processing at any time. However, this does not affect the lawfulness of Data processing based on the consent before the revocation.
You have the right to obtain (i) confirmation as to whether or not your Data is being processed by us and, if so, (ii) more specific information on the Data. The more specific information concerns, among others, processing purposes, categories of Data, potential recipients or the duration of storage.
You have the right to obtain from us the rectification of inaccurate Data concerning you. In case the Data processed by us is not correct, we will rectify these without undue delay and inform you of this rectification.
Should you decide you do not want us to process your data any further, please contact us under our current contact details [email protected] . We will erase your Data immediately and inform you of this process. Should mandatory provisions of law prevent such erasure, we will inform you without undue delay thereof.
You have the right to (i) receive your Data in a structured, commonly used and machine-readable format and (ii) transmit those Data to another controller without hindrance from us.
You have the right to object at any time to the processing of Data based on our legitimate interests, including profiling and direct marketing purposes.
You have the right to lodge a complaint with a supervisory authority if you think that the processing of Data infringes applicable law, especially the GDPR.
Questions, Suggestions and Complaints
If you have any privacy-related questions, suggestions, unresolved problems, or complaints you may contact us via [email protected] .
If you reside or are located in the EEA, our Data Protection Officer and Privacy Team may assist with all queries regarding our processing of Personally Identifiable at [email protected] .
International Privacy Practices
CodeGalaxy’s Sites are primarily operated and managed on servers located and operated within the United States. In order to provide our products and services to you, we may send and store your Personally Identifiable Information (also commonly referred to as personal data) outside of the country where you reside or are located, including to the United States. Accordingly, if you reside or are located outside of the United States, your Personally Identifiable Information may be transferred outside of the country where you reside or are located, including to countries that may not or do not provide the same level of protection for your Personally Identifiable Information. We are committed to protecting the privacy and confidentiality of Personally Identifiable Information when it is transferred. If you reside or are located within the EEA and such transfers occur, we take appropriate steps to provide the same level of protection for the processing carried out in any such countries as you would have within the EEA to the extent feasible under applicable law. We participate in and commit to adhering to the EU-U.S. Privacy Shield Framework when transferring data from the EEA to the United States.
No Information from Children Under 13
CodeGalaxy strongly believes in protecting the privacy of children. In line with this belief, we do not knowingly collect or maintain Personally Identifiable Information on our Site from persons under 13 years of age, and no part of our Site is directed to persons under 13 years of age. If you are under 13 years of age, then please do not use or access this Site at any time or in any manner. We will take appropriate steps to delete any Personally Identifiable Information of persons less than 13 years of age that has been collected on our Site without verified parental consent upon learning of the existence of such Personally Identifiable Information.
We are acting as the controller for the data processing within the meaning of the GDPR.