Our courses will go live on October 26, 2026.
Privacy policy
Last updated: 29 September 2026
S.A.F.E. Academy exists so that the people who meet fraud victims — in banks, investigations, first response and victim support — are trained for the human side of the crime, not only the financial one. This page explains what personal data we collect when you use our website, shop and courses, why we collect it, and what rights you have.
If you only wanted the short version: we collect what we need to run your account, deliver the programme, take payment and answer your messages. Course reflections stay on your device. Classroom polls are anonymous. We do not sell your data.
1. Who is responsible
The controller for personal data on this website is S.A.F.E. by Ayleen Charlotte.
- Email: info@safe-academy.org
- Postal address: Postbus 97, 1930AB Egmond aan Zee, the Netherlands
- Chamber of Commerce (KvK): 87233541
The website is hosted and technically managed by Surver B.V. (surver.nl). Surver acts as a processor on our instructions for hosting, email delivery and site maintenance.
Questions about privacy go to info@safe-academy.org. We answer those messages ourselves.
2. Whose data we process
This policy applies if you:
- browse the public site, including Learn & Protect
- create an account, log in or reset a password
- buy a module or the full twelve-week programme
- enrol in a LearnDash course and complete lessons, topics and practice
- send the contact form, or email us about a team, a founding partnership or the Implementation Toolkit
- download a free guide
The programme is built for professionals. It is not aimed at children. We do not knowingly collect data from anyone under 16.
3. What we collect
Account and enrolment
Name, email address, password (stored as a hash), login times, and which courses you may access. If you register through our registration pages, we also keep the details you submit there.
Orders and payment
Billing name, organisation if you give one, address, email, order contents (Module 1, Module 2, Module 4 and/or the full S.A.F.E. Certified Professional programme), amounts in euro, and payment status. Card payments are handled by Stripe. We do not store full card numbers on our servers.
Learning progress
Which lessons and topics you have opened, marked complete or left unfinished, quiz and knowledge-check results, and certificates when those are issued. This is how the course knows where you are, and how a module can be a condition for the next one.
Reflections, polls and in-lesson exercises
Some lessons ask you to write a short reflection. The words you type stay in your browser. We only store that you completed the reflection so the lesson can continue. We do not read, score or share that text.
Hands-up polls are anonymous. We store one response per logged-in user so the group totals can be shown. Peers never see who chose what.
“Myth vs fact” prompts are not saved at all. Optional notes you type there stay on your device, then we show the evidence.
Please do not paste names of victims, case files or special-category data into free-text fields. The course is written so you can practise without doing that.
Messages you send us
Whatever you include in the contact form or in an email: typically your name, work email, organisation and what you want to discuss (a team, licensing, white-label, or the Implementation Toolkit). Elementor sends those messages to us by email. Treat anything you write as confidential; so do we.
Downloads
If you download a Learn & Protect guide, the download tool may log that a file was requested (time and technical data such as IP address) so we can keep the library working and see that a file is not being abused.
Technical data
IP address, browser type, device, pages viewed, and cookies as described in our Cookie policy. We use this to keep the site secure, remember your basket and session, and diagnose faults.
4. Why we use the data (legal bases)
Under the GDPR we rely on:
- Contract — creating your account, taking payment, giving you access to the module or programme you bought, and delivering the course.
- Legitimate interests — keeping the site secure, understanding which parts of the public site are used, answering B2B enquiries, and improving the training. You can object to this; see “Your rights” below.
- Legal obligation — keeping invoice and transaction records for tax and accounting (in the Netherlands this is typically seven years).
- Consent — where we ask for it, for example optional marketing email if we ever add that. You can withdraw consent at any time. We do not currently run a marketing newsletter from this site.
5. Who we share data with
We do not sell personal data. We share it only with parties who help us run the Academy:
- Surver B.V. — hosting, WordPress, email (messages from noreply@safe-academy.org go out via hostingsecure.email) and technical support.
- Stripe — card payments. Stripe is an independent controller/processor for payment data. See Stripe’s own privacy notice.
- LearnDash, WooCommerce and Uncanny Toolkit — these run on our own site. They are software, not a separate company we send your file to.
- Riskoria / HeartOSINT — HeartOSINT is a practice tool included with the programme and published by Riskoria. If you use it, that tool may process what you paste there under Riskoria’s terms. We do not need you to paste personal data of victims into HeartOSINT.
We may also disclose data if the law requires it, or to protect someone’s vital interests in a genuine emergency. Course pages that mention crisis support point to public resources such as Find A Helpline; following those links is your choice and happens on those organisations’ sites.
6. How long we keep it
- Account and course progress — for as long as the account is active, and a reasonable period afterwards if you may still need access or a certificate.
- Orders and invoices — seven years, as required for administration and tax.
- Contact messages — as long as needed to handle the enquiry and any follow-up, then delete or archive with restricted access.
- Reflection text — not stored on our servers. Completion flags follow the course record.
- Anonymous poll totals — kept with the course so later learners still see the group picture; they cannot be traced back to you from the totals alone.
- Download and security logs — a short period, unless we need them to investigate abuse.
7. Security and transfers
The site is served over HTTPS. Passwords are hashed. Access to the WordPress admin is limited. No method of transmission is perfectly secure; if we become aware of a breach that affects you, we will inform you and the Autoriteit Persoonsgegevens where the law requires it.
Some processors (notably Stripe) may process data outside the EEA. Where that happens, they use approved transfer tools such as the European Commission’s standard contractual clauses.
8. Your rights
You can ask us to:
- access the personal data we hold about you
- correct it if it is wrong
- delete it, where the law allows
- restrict or object to certain processing
- receive a copy in a portable format (for data you provided, where processing is based on contract or consent)
- withdraw consent, where we relied on it
Email info@safe-academy.org. We may need to confirm it is you before we act. You also have the right to complain to the Autoriteit Persoonsgegevens.
You can update some account details yourself under My account.
9. Changes
If this policy changes in a way that matters, we will update this page and the date at the top. For material changes we may also email account holders.