Ocira — Privacy Policy
Effective date: 2026-06-29 · Last updated: 2026-06-29
This Privacy Policy explains how your personal data is handled when you visit the Ocira
website, buy the Ocira course and reference repository (the "Materials"), or contact us. It is
written to meet the EU/EEA GDPR (Regulation (EU) 2016/679) and Portuguese Lei n.º 58/2019
as the baseline, and applies to buyers worldwide (including the US, Ukraine and elsewhere).
1. Who is responsible (data controller)
Yevgen ("Eugene") Nayshtetik — individual entrepreneur (empresário em nome individual),
NIF 325061653, Lisbon, Portugal. Contact: e.nayshtetik@gmail.com.
For payments, our payment provider Lemon Squeezy acts as Merchant of Record and is an
independent controller of the payment transaction (see their privacy policy).
2. What data we process, why, and on what legal basis
| Data | Why we use it | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, e-mail, country, order ID, licence key (from the purchase) | Deliver the Materials, issue the licence, support you | Art. 6(1)(b) — performance of our contract |
Per-purchaser watermark / fingerprint embedded in the repository (LICENSE_KEY.txt) |
Trace unauthorised redistribution; protect the product | Art. 6(1)(f) — legitimate interest (anti-piracy); assessed and recorded |
| Course-viewing data (via our video host) | Provide and improve the course | Art. 6(1)(b) / 6(1)(f) |
| Support correspondence | Answer your questions, keep records | Art. 6(1)(b) / 6(1)(f) |
| Marketing e-mails (product updates), if you opt in | Tell you about updates and new material | Art. 6(1)(a) — consent (withdraw any time) |
| Website analytics / non-essential cookies, if used | Understand site usage | Art. 6(1)(a) — consent |
We do not sell your personal data, and we do not use it for automated decision-making or
profiling that produces legal or similarly significant effects.
3. Where your data comes from
Most data comes from you (purchase, contact). Purchase and payment data also reach us via
Lemon Squeezy after a completed transaction.
4. Who we share it with (processors and recipients)
We use the following service providers, who process data on our behalf under data-processing
agreements:
- Lemon Squeezy — checkout, payment, licence keys, invoicing, and the transactional e-mail
that delivers your receipt, licence key, and access links (Merchant of Record).
- Cloudflare — website hosting/CDN (Cloudflare Pages) and course-video streaming
(Cloudflare Stream, access-gated with short-lived signed playback tokens).
We do not currently use a separate marketing/newsletter provider; if we add one, this notice
will be updated before any marketing e-mail is sent.
We disclose data to authorities only where legally required.
5. International transfers
Some providers are located outside the EU/EEA (e.g. in the United States). Where data is
transferred internationally, we rely on an adequacy decision or on Standard Contractual
Clauses (SCCs) with appropriate safeguards. You may request a copy of the relevant safeguard via
e.nayshtetik@gmail.com.
6. How long we keep it
- Order, invoice and tax data: for the statutory accounting/tax retention period (in Portugal,
generally 10 years). - Licence/watermark records: for as long as the licence is valid plus the applicable
limitation period (to handle disputes/breach). - Support correspondence: up to [2] years.
- Marketing data: until you withdraw consent or unsubscribe.
7. Your rights
Subject to applicable law, you may access, rectify, erase, restrict, or object
to processing of your data, request portability, and withdraw consent at any time (without
affecting prior processing). To exercise any right, contact e.nayshtetik@gmail.com. We respond within
the legal time limit (one month under GDPR).
- EU/EEA & Portugal: you may lodge a complaint with the CNPD (Comissão Nacional de
Proteção de Dados, www.cnpd.pt) or your local supervisory authority. - United States: depending on your state, you may have rights under laws such as the CCPA/CPRA;
we honour verifiable requests where those laws apply. We do not "sell" or "share" personal
data as those terms are defined. - Ukraine and elsewhere: you may have rights under your local data-protection law; contact us
and we will assist.
8. Cookies
The Ocira website uses only strictly necessary cookies required to operate. If and when we
introduce analytics or other non-essential cookies, we will ask for your consent first and
publish a separate Cookie Notice. See COOKIE_NOTICE.md.
9. Children
The Materials are intended for adults/professionals. We do not knowingly process data of children
under [16]. If you believe a child has provided data, contact us and we will delete it.
10. Security
We use reasonable technical and organisational measures to protect your data. No method of
transmission or storage is perfectly secure; we cannot guarantee absolute security.
11. Changes
We may update this Policy. Material changes will be posted here with a new "Last updated" date.
12. Contact
Questions or requests: e.nayshtetik@gmail.com.