Legal
Privacy Policy
We take the protection of your personal data seriously. This policy explains what we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
Last updated: June 2026
Controller
LETO SPACE GmbH, Stremayrgasse 16, 8010 Graz, Austria.
Data protection contact: privacy@leto.space.
What we process
Account data: name, email address, password (stored only as a hash), and authentication identifiers (including Google sign-in if you use it).
Learning data: course enrolments, lesson progress, quiz attempts and certificates.
Payment data: purchases and subscription status. Card details are entered on Stripe's systems and are never stored by us.
Technical data: server logs (IP address, timestamp, request) needed to operate and secure the service.
Purposes and legal bases
Providing your account, courses and certificates: performance of a contract (Art. 6(1)(b) GDPR).
Processing payments and meeting tax-retention duties: contract and legal obligation (Art. 6(1)(b),(c) GDPR).
Operating, securing and improving the platform: legitimate interest (Art. 6(1)(f) GDPR).
Sending transactional emails (verification, password reset, certificate): contract performance.
Cookies
We set only one strictly necessary cookie: your login session. It is required for the service to function and stores no tracking or advertising data.
We do not use analytics, advertising or third-party tracking cookies, so no cookie-consent banner is required. Should we introduce such tools in future, we will ask for your consent first.
Processors and recipients
Amazon Web Services (AWS), eu-central-1 (Frankfurt): hosting, database, transactional email (SES) and certificate-file storage (S3).
Stripe Payments Europe: payment processing.
Google: only if you choose to sign in with Google.
Mux: video delivery, where a course includes video. We do not sell your data.
International transfers
Our infrastructure is hosted in the EU (Frankfurt). Where a provider may process data outside the EEA, transfers are safeguarded by the EU Standard Contractual Clauses or an adequacy decision.
Retention
Account and learning data are kept while your account exists and deleted within 30 days of account deletion, unless longer retention is required by law.
Invoice and payment records are retained for 7 years to meet Austrian tax-law obligations.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR). To exercise them, contact privacy@leto.space.
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at).
Security
We protect data in transit with TLS, restrict access on a need-to-know basis, and apply HTTP security headers. No method of transmission is perfectly secure, but we work to protect your data appropriately.