Privacy Policy


YoomTen.com

PRIVACY NOTICE

Version: 1.1

Publication date: 16 March 2026

Effective date: 16 March 2026

Data Controller: Yoomten.com Online Oktatási és Szolgáltató Kft.

Contact: info@yoomten.com

Data processing rules of the YoomTen.com online education platform

Table of Contents

  1. Introduction and Scope of the Notice
  2. The Role of YoomTen: a Platform, Not a Training Provider
  3. Details of the Data Controller
  4. Applicable Legislation
  5. Definitions
  6. Data Processing Principles
  7. Sources and Main Categories of Data
  8. Registration, User Account and Login
  9. Processing of Student Data
  10. Processing of Instructor Data
  11. Data Processing and Reporting under DAC7
  12. Course Purchases, Payments, Invoicing and Refunds
  13. Business Clients and Corporate Users
  14. AI-Based Services
  15. Videos, Audio Materials and Educational Content
  16. Certificates and Proofs of Completion
  17. Customer Service, Complaints and Communications
  18. Marketing Communications and Personalised Recommendations
  19. Cookies, Mobile Identifiers and Similar Technologies
  20. Logging, Fraud Prevention and Information Security
  21. Processors, Recipients and Other Controllers
  22. International Data Transfers
  23. Data Retention Periods
  24. Automated Decision-Making and Profiling
  25. Processing of Minors’ Data
  26. Rights of Data Subjects
  27. Personal Data Breaches
  28. Remedies and Data Protection Contact
  29. Amendments to the Notice and Final Provisions
  30. Annex 1 – Summary Matrix of Data Processing Activities
  31. Introduction and Scope of the Notice

The YoomTen online education platform (hereinafter: “YoomTen”, the “Platform” or the “Service”) places particular emphasis on the protection of personal data, transparency of data processing and respect for the rights of data subjects.

This Privacy Notice (hereinafter: the “Notice”) explains what personal data YoomTen processes, for what purposes and on what legal bases, where the data originate, who may have access to them, how long we retain them, what international data transfers may take place, and what rights and remedies are available to data subjects.

This Notice applies in particular to the following categories of data subjects:

visitors to the yoomten.com website and the YoomTen mobile applications;

registered users and students;

instructors, course creators and natural-person contact persons of instructor organisations;

Business Clients, their contact persons, employees and other designated users;

newsletter subscribers and recipients of marketing communications;

persons contacting customer service;

all other natural persons whose data we process in the course of operating the Platform.

This Notice covers the website, mobile applications, access to online courses, AI-based functions, payment and payout processes, the Business interface, customer service, marketing, and the secure operation of the Platform.

This Notice must be read together with the General Terms and Conditions, the Instructor Terms, the Business Terms, the Cookie Policy, the AI Privacy Notice and the Register of Processors. In data protection matters, this Notice and the provisions of any specific notice applicable to the relevant processing activity shall govern.

  1. The Role of YoomTen: a Platform, Not a Training Provider

Material classification: YoomTen is an online marketplace and technology service provider. It is not an adult education provider, school, higher education institution or training establishment, and it does not carry out adult education activities in respect of courses available on the Platform.

YoomTen provides a technological environment in which independent instructors and instructor organisations may upload, present and sell their own courses, while students may purchase or otherwise access those courses. Among other things, YoomTen may provide hosting, video playback, payment infrastructure, translation and AI functions, learning records and a business user interface.

As a general rule, the instructor is responsible for the professional content and lawfulness of educational content published on the Platform, for statements made by the instructor, and for the instructor’s own sector-specific or regulatory obligations. If, by virtue of their own activities, an instructor qualifies as an adult education provider or another provider of regulated training, the instructor shall independently fulfil the resulting registration, information and reporting obligations.

Unless expressly stated otherwise, an electronic document issued by YoomTen in connection with course completion is a platform-level proof of completion and does not constitute a state-recognised qualification, vocational qualification, adult education certificate or official certificate.

  1. Details of the Data Controller

Name of the Data Controller: YoomTen.com Online Oktatási és Szolgáltató Kft.

Registered office and postal address: 8200 Veszprém, Szent István utca 45, Hungary

Company registration number: 19-09-516726

Tax number: 24744890-2-19

Email: info@yoomten.com

Website: https://www.yoomten.com

Data protection contact: info@yoomten.com

YoomTen has not currently appointed a Data Protection Officer. Data protection questions, data subject requests and complaints may be sent to the data protection contact.

YoomTen regularly assesses and documents whether the mandatory appointment of a Data Protection Officer is required under Article 37 of the GDPR, with particular regard to activities involving regular and systematic monitoring of data subjects on a large scale, including the continuous logging of learning progress, user behaviour and AI interactions. YoomTen records the outcome of the assessment and the reasons for its decision in an internal register.

YoomTen acts as a data controller for all processing activities for which it determines the purposes and essential means. In certain Business processes or other partner services, it may also act as a data processor; detailed rules are set out in Sections 13 and 21.

  1. Applicable Legislation

YoomTen’s data processing is based in particular on the following legislation and requirements:

Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);

Directive 2002/58/EC on privacy and electronic communications and its applicable national implementing rules, in particular the provisions of the legislation on electronic communications concerning consent to cookies;

Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information;

Hungarian Act CVIII of 2001 on Electronic Commerce Services;

Hungarian Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities;

Hungarian Act C of 2000 on Accounting and the applicable tax and invoicing legislation;

Hungarian Act XXXVII of 2013 on International Administrative Cooperation in Tax and Other Public Charges, in particular its rules applicable to DAC7 platform operators;

Council Directive 2011/16/EU and the DAC7 provisions introduced by Directive (EU) 2021/514;

Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), in particular Article 50 thereof concerning interaction with AI systems and the labelling of artificially generated or manipulated content;

the applicable consumer protection, civil law and information security requirements.

Where YoomTen provides services to a user residing in another EEA Member State, it also takes into account the mandatory data protection, electronic marketing and child protection rules of that Member State.

  1. Definitions

Data Subject: the natural person to whom the personal data processed relate.

Personal Data: any information relating to an identified or identifiable natural person.

Processing: any operation performed on personal data, including in particular collection, recording, organisation, storage, alteration, retrieval, use, transmission, restriction, erasure or anonymisation.

Data Controller: the person or entity that determines, alone or jointly with others, the purposes and means of processing.

Data Processor: the person or entity that processes personal data on behalf of the data controller and on the basis of its documented instructions.

Instructor: a natural person, entrepreneur or organisation that makes available or sells on the Platform educational content owned by it or lawfully available for its use.

Student: a person who purchases, views or completes a course, or uses it under Business access.

Business Client: a company, institution or organisation that provides access to its employees, members or other designated persons.

AI Service: a function using artificial intelligence, such as translation, subtitling, speech recognition, lip-syncing, a learning assistant, or the generation of notes, presentations or quizzes.

Reportable Seller: an instructor or instructor organisation subject to reporting under the DAC7 rules.

Recipient: a person or organisation to whom personal data are disclosed, irrespective of whether it is a third party.

  1. Data Processing Principles

Lawfulness, fairness and transparency: YoomTen processes personal data only on an appropriate legal basis, fairly and in a manner understandable to data subjects.

Purpose limitation: We collect data for specified, explicit and legitimate purposes and do not use them for purposes incompatible with those purposes.

Data minimisation: We request and process only data that are necessary and proportionate for the relevant purpose.

Accuracy: We take reasonable measures to rectify or erase inaccurate data. Users are required to keep the data provided in their accounts up to date.

Storage limitation: We retain data only for as long as justified by the processing purpose, the contract, a legal obligation or legal claims.

Integrity and confidentiality: We protect data against unauthorised access, alteration, disclosure, loss and destruction by means of appropriate technical and organisational measures.

Accountability: YoomTen demonstrates the compliance of its processing through records, contracts, internal policies and controls. For processing based on legitimate interests, YoomTen carries out and documents a legitimate interest assessment (LIA), which includes identifying the legitimate interest, assessing necessity, and balancing that interest against the rights and interests of data subjects.

Data protection by design and by default: Data protection considerations are incorporated from the design stage when developing and configuring the Platform, and by default only the necessary processing is carried out.

  1. Sources and Main Categories of Data

7.1. Sources of Data

Personal data may originate in particular from the following sources:

directly from the data subject, for example during registration, purchase, completion of a profile, course upload or contact with customer service;

from a Business Client, where the organisation designates an employee or member to use the Platform;

from an instructor, where the instructor provides student data or other personal data in connection with a course;

from a payment, invoicing, identification, social login or other technology service provider;

from logs, device data and cookie identifiers automatically generated during use of the Platform;

from a public or official register or a tax identifier validation service, where necessary for DAC7 due diligence or another legal obligation;

from other users, for example in connection with a review, complaint, report or communication.

7.2. Main Categories of Data Processed

Identification and contact data: name, username, email address, telephone number, postal address, profile picture and language settings.

Account and authentication data: encrypted password, OAuth identifiers, two-factor authentication data, session logs and login logs.

Contractual and transactional data: order, course, access, coupon, amount paid, currency, refund, invoicing and settlement data.

Learning data: courses viewed, progress status, playback events, test and examination results, notes, favourites, reviews and proofs of completion.

Instructor and professional data: profile description, professional profile, qualifications, courses, reviews, revenue statements and payout statements.

DAC7 and tax data: tax residence, primary address, tax identification number, tax number, issuing state, birth data, company register data, payout account identifier, quarterly consideration and platform fees.

AI and content data: uploaded video, audio, subtitles, presentation, document, prompt, question, AI response, generated notes, presentation and quiz.

Technical and security data: IP address, browser, operating system, device identifier, approximate location data, cookie identifier, API call, error code and security event.

Communication data: email, chat message, support ticket, complaint, error report, review and feedback.

7.3. Special Categories of Data and Data of Third Parties

As a general rule, YoomTen does not request health data, biometric identification data, religious or political data, or other special categories of personal data under Article 9 of the GDPR. Users and instructors must not upload such data unless doing so is strictly necessary and lawful, the data subject has been appropriately informed, and the applicable separate legal basis is ensured.

Video, audio and lip-syncing functions process a person’s image and voice for the purpose of creating and modifying content, and not for the purpose of uniquely identifying that person biometrically. If the Platform were to introduce biometric identification in the future, it would provide separate information and ensure the necessary legal basis.

  1. Registration, User Account and Login

8.1. Purpose and Data Processed

The purpose of creating and maintaining an account is to identify the user, enable login, manage access rights, perform the contract, ensure account security and communicate with the user.

name or display name;

email address and, where necessary, telephone number;

encrypted password or identifier of an external login provider;

user role, language, country and settings;

login and security logs;

consents and versions of documents accepted.

8.2. Legal Basis

The legal basis for processing necessary for an account is entering into and performing a contract (Article 6(1)(b) GDPR). Security logging, prevention of misuse and protection of the account are based on the legitimate interests of YoomTen and its users (Article 6(1)(f) GDPR). Evidence of acceptance of mandatory documents may be based on a legal obligation or legitimate interests.

8.3. Social Login

If the user logs in with a Google, Apple or other external account, YoomTen may receive from the selected provider the identifier, name, email address and other data authorised by the data subject that are necessary for login. The external provider is independently responsible for its own processing.

8.4. Account Deletion

Deletion of an account terminates ordinary access, but does not automatically result in the immediate erasure of all data. YoomTen continues to retain data required for invoicing, taxation, DAC7, complaint handling, fraud prevention, contractual access or the establishment, exercise or defence of legal claims. As a general rule, technical deletion of the account is carried out within 30 days; removal from backups may take until the end of the backup cycle.

  1. Processing of Student Data

9.1. Purposes of Processing

purchasing courses and making them available;

recording learning progress and course completion;

operating tests, quizzes and examination-type tasks;

providing AI-based learning functions;

issuing a proof of completion or platform certificate;

managing reviews, favourites and personal notes;

customer service, refunds, fraud prevention and security.

9.2. Learning Data Processed

courses purchased, started and completed;

video views, progress percentage, last viewing point and usage time;

test, quiz and assignment results;

questions submitted to AI and responses or supporting materials generated by AI;

downloads, favourites, notes, reviews and feedback;

proofs of completion, unique verification identifiers and QR codes.

9.3. Legal Basis

Processing necessary for the course and learning functions is based on the performance of the contract. Aggregated or pseudonymised analyses intended to improve the quality, security and usability of the Platform are based on YoomTen’s legitimate interests. Non-essential tracking for personalisation or marketing purposes is based on consent where required by law.

9.4. Sharing Data with the Instructor

In relation to their own course, an instructor may receive aggregated statistics and limited personal data necessary for operating and supporting the course and improving its quality. YoomTen does not provide the instructor with students’ contact or payment data for marketing purposes unless the data subject has separately consented or the transfer is based on another appropriate legal basis.

  1. Processing of Instructor Data

10.1. Purposes of Processing

creating an instructor account and providing permissions and a profile;

uploading, publishing, selling and moderating courses;

verifying the instructor’s identity, tax status and entitlement to receive payouts;

accounting for revenues, commissions, refunds and payouts;

performing due diligence, record-keeping and reporting under DAC7;

fulfilling contractual, tax, accounting and legal obligations;

quality assurance, fraud prevention and handling copyright and misuse reports.

10.2. Data Processed

name, email address, telephone number and postal address;

profile picture, biography, professional experience, qualifications and social links;

business, company register, invoicing and tax data;

payout account or Stripe Connect identifiers and payout status;

courses, uploaded content, course statistics, reviews and quality indicators;

revenue, commission, refund and payout statements;

DAC7 data in accordance with Section 11;

contractual declarations, verification results and customer service communications.

10.3. Publicly Displayed Instructor Data

To the extent necessary for providing the Service, the instructor’s name or selected professional name, profile picture, biography, professional description, courses, reviews, average score and badges awarded by the Platform may be displayed publicly. Bank account details, home address, tax identifier, birth data and other confidential information are not public.

10.4. Legal Basis and Mandatory Provision of Data

Processing necessary for the instructor profile, course sales and payouts is based on performance of the contract. Processing of accounting, tax and DAC7 data is necessary for compliance with legal obligations. Fraud prevention, moderation, handling copyright claims and disputes are based on the legitimate interests of YoomTen and the Platform community.

Providing instructor identification data and DAC7 identification data may be a condition for entering into the contract, selling courses or receiving payouts. If the instructor does not provide or verify the mandatory data, YoomTen may restrict publication of the course, sales or payouts to the extent necessary for legal compliance.

  1. Data Processing and Reporting under DAC7

Application of DAC7: As a digital platform operator subject to reporting obligations, YoomTen performs due diligence on instructors specified by law, keeps records of their data and transmits the reportable data to the Hungarian National Tax and Customs Administration.

11.1. Purpose and Legal Basis of Processing

The purpose of DAC7 processing is to identify instructors, determine their tax residence, establish whether they qualify as reportable sellers, record consideration earned and paid or credited through the Platform, and comply with the statutory annual reporting obligation.

The legal basis for processing is compliance with a legal obligation applicable to YoomTen (Article 6(1)(c) GDPR), in particular under Chapter II/A and Annex 5 of Hungarian Act XXXVII of 2013 and the DAC7 provisions of Directive 2011/16/EU.

11.2. DAC7 Data Processed

Depending on whether an instructor qualifies as reportable and on the applicable statutory requirements, YoomTen may process in particular the following data:

family name and given name of an instructor who is a natural person; official name of an instructor organisation;

primary residence or registered office, country and Member State or Member States of tax residence;

tax identification number or tax number and the issuing state; where unavailable, the place of birth required by law;

date of birth of an instructor who is a natural person;

company registration number or other registration number of an organisation;

EU VAT number or other value added tax identifier, where available;

financial account or other financial account identifier used for payouts;

name of the holder of the financial account where different from the instructor’s name, and the available related financial identification data;

total consideration paid or credited in each quarter of the reporting period;

number of relevant activities or transactions, broken down by quarter;

fees, commissions and taxes withheld or charged by YoomTen in each quarter;

documents, verification results, electronic identification data and declarations used for due diligence;

technical identifiers, status, corrections and log data relating to reporting.

11.3. Data Source and Verification

The primary source of DAC7 data is the instructor. YoomTen may verify the validity of the data in a manner permitted by law by using official or public registers, tax identifier validation services, electronic identification systems, payment service provider information and documents.

The instructor must keep the data provided accurate and up to date and notify changes without delay. YoomTen may request additional data or documents if a discrepancy, omission or reasonable doubt arises during due diligence.

11.4. Recipients and International Exchange of Information between Authorities

YoomTen transmits reportable data to the Hungarian National Tax and Customs Administration (NAV). Under the DAC7 rules, NAV may transmit the data through automatic exchange of information to the competent tax authority of another EEA Member State in which the instructor is tax resident. YoomTen’s appointed accountants, tax advisers, IT processors and technical service providers involved in statutory reporting may also access the data to the extent necessary for their tasks.

11.5. Retention Period

YoomTen retains documentation relating to DAC7 due diligence, record-keeping and reporting for 10 years from the deadline for the relevant reporting obligation. If an official proceeding, audit or legal dispute is pending, the related data may be retained for longer, until the proceeding has been finally concluded.

11.6. Mandatory Nature of Providing Data

Providing the data required by DAC7 is a statutory and contractual condition. Without the data, YoomTen cannot fulfil its due diligence and reporting obligations and may therefore, in accordance with the law and the Instructor Terms, refuse or suspend instructor registration, course sales or payouts until the required data are available.

11.7. Rectification and Information

The instructor is entitled to request rectification of their DAC7 data. If YoomTen has already submitted a report and subsequently identifies an inaccuracy, it may submit a corrected or amending report in accordance with the law. YoomTen informs the instructor about the reporting and the main categories of data reported in the manner required by applicable legislation.

  1. Course Purchases, Payments, Invoicing and Refunds

12.1. Data Processed and Purposes

order and transaction identifier;

name of the course, package or subscription purchased;

date and time of purchase and access;

amount paid, currency, discount, coupon and tax data;

billing name, address, tax number and invoice details;

payment status, payment service provider identifier, refund data and disputed transaction data.

The purpose of processing is to perform the contract, provide access, process payment, issue invoices, settle accounts with instructors, provide refunds and prevent financial fraud.

12.2. Payment Service Providers

YoomTen does not store complete bank card details. Card and other electronic payments may be processed by a contracted payment service provider, such as Stripe. The payment service provider may act as an independent controller for certain aspects of payment, fraud prevention, customer identification and legal compliance, and as a processor for other technical operations. The exact roles and services are set out in the Register of Processors.

12.3. Legal Basis

Processing purchase and payment data is based on performance of the contract. Processing invoices, tax documents and accounting data is necessary for compliance with legal obligations. Handling payment fraud, chargebacks, misuse and legal claims may be based on legitimate interests.

  1. Business Clients and Corporate Users

13.1. Data Processed

name, company details, billing data and contractual data of the Business Client;

name, position, business email address and telephone number of the contact person;

name, corporate email address, organisational unit and job role of a designated user, where provided by the organisation;

assigned training courses, progress data, completions, test results and proofs of completion;

login, security and administrator logs;

assignments made and reports requested by the Business administrator.

13.2. Controller Roles

YoomTen acts as an independent controller in relation to its own contract management, invoicing, account security, legal compliance, fraud prevention and service development.

The Business Client acts as an independent controller when determining which employees or other persons receive access, which training courses are assigned to them, which completion data it wishes to access, and for what employment-related or organisational purposes those data are used.

Where YoomTen processes corporate users’ data solely on the documented instructions of the Business Client—for example, when producing a training report specified by the employer—YoomTen acts as a processor and the parties enter into a data processing agreement under Article 28 of the GDPR.

13.3. Reports and Data Minimisation

A Business Client may access only reports concerning its own designated users and the service ordered. YoomTen limits report content to the necessary data and uses aggregated data where possible. The employer is responsible for ensuring that its use of reports complies with employment law, data protection and sector-specific rules.

  1. AI-Based Services

14.1. AI Functions

intelligent learning assistant and course-based question answering;

automatic subtitling, speech recognition and translation;

video and audio dubbing and lip-syncing;

generation of notes, summaries, presentations and quizzes;

learning suggestions and relevant course recommendations;

automated tools supporting content moderation, quality control or security.

14.2. Data and Purpose of AI Processing

Depending on the selected function, AI systems may process video, audio, subtitles, course descriptions, educational documents, user questions, prompts, learning progress, language settings and AI-generated content. Processing is carried out solely to provide the function requested by the user, ensure the security of the Service and perform the necessary quality control.

14.3. Legal Basis

Providing an AI function requested by the user is generally based on performance of the contract. Optional, non-essential personalisation may be based on consent or—subject to an appropriate balancing assessment and the possibility of objection—on legitimate interests. Special categories of personal data may be processed by AI only where an appropriate condition under Article 9 of the GDPR applies.

14.4. Training AI Models

By default, YoomTen does not use content, questions, audio or video materials uploaded by instructors or students to train its own or a third party’s general-purpose AI model. YoomTen applies provider contracts and settings that prohibit or disable the use of customer data for model training. Any different use may take place only after prior, clear information has been provided and on an appropriate legal basis.

14.5. AI Providers and Data Transfers

YoomTen may use external AI and cloud service providers. The names, roles and countries of the providers, the categories of data processed and the safeguards for transfers to third countries are set out in the Register of Processors. YoomTen uses data processing agreements, appropriate confidentiality and information security conditions, and, where necessary, standard contractual clauses and a transfer impact assessment.

14.6. AI-Generated Content

An AI-generated summary, note, presentation, quiz, translation or response is an automated output that may be inaccurate, incomplete or misleading. Users and instructors must review the content using their own professional judgement. YoomTen does not make any decision producing legal effects or similarly significant effects for a user solely on the basis of AI-generated content.

14.7. Transparency under the AI Act

The transparency obligations under Article 50 of Regulation (EU) 2024/1689 (AI Act) apply from 2 August 2026. Accordingly, YoomTen informs the user when they are interacting with an AI system and labels artificially generated or manipulated audio, image or video content—including, in particular, the output of video dubbing and lip-syncing functions—in the manner required by law, or informs the user of its artificial nature. YoomTen provides information on the implementation and details of the relevant technical and labelling requirements in the AI Privacy Notice or in a separate communication.

  1. Videos, Audio Materials and Educational Content

15.1. Upload and Storage

Videos, audio recordings, presentations, documents, subtitles and other learning materials uploaded by instructors form the basis for providing the Service. YoomTen processes them for storage, encoding, playback, access protection, backup, translation, AI processing and sale of the course.

15.2. Images, Voices and Data of Third Parties

The instructor is responsible for lawfully using the image, voice, name or other personal data of natural persons appearing in uploaded content, appropriately informing those persons and, where necessary, obtaining their consent or another legal basis. YoomTen may request evidence of authorisation, restrict access or remove unlawful content.

15.3. Copyright and Data Protection Roles

As a general rule, copyright in uploaded educational content belongs to the instructor or the rights holder. The licence to use copyright-protected material is governed by the General Terms and Conditions and the Instructor Terms. If the instructor determines the purposes and manner of processing third-party data contained in the content, the instructor acts as an independent controller in that respect. YoomTen may act as a processor for certain technical storage and processing operations.

15.4. Content Deletion and Access for Previous Purchasers

After termination of an instructor account or course, a previously purchased course may remain available on a limited basis until the end of the contractual access period. For this purpose, YoomTen may retain the course content and the necessary instructor identification data for as long as it is required to provide access to previous purchasers or while a legal claim or mandatory retention obligation remains in force.

  1. Certificates and Proofs of Completion

The Platform may issue an electronic proof of completion or platform certificate for completion of a course. It may contain the student’s name, the name of the course and instructor, the completion date, the result achieved, a unique identifier, a QR code and a verification link.

The purpose of processing is to document completion and to create, download and verify the authenticity of the certificate. The legal basis is performance of the contract. Only the minimum data necessary for verification are displayed on the public verification interface. The user decides whether to share the certificate.

A certificate issued by YoomTen is not an adult education certificate or a state-recognised document unless separate, explicit and legally substantiated information is provided for a particular service.

  1. Customer Service, Complaints and Communications

17.1. Customer Service Enquiries

Customer service may process the enquirer’s name, email address, account identifier, the content of the enquiry, attachments, technical circumstances and the steps taken in handling the matter. The purposes of processing are to answer the question, troubleshoot errors, perform the contract, investigate misuse and document the case.

17.2. Consumer Complaints

In the event of a consumer complaint, YoomTen processes the complaint, the response, related evidence, purchase data and the data recorded in the complaint report in order to comply with consumer protection legal obligations, investigate the complaint and handle legal claims. The complaint report and a copy of the response are retained for three years in accordance with the applicable consumer protection rules, or until the conclusion of any legal dispute.

17.3. Service Notifications

Notifications concerning account security, transactions, course access, contractual matters, legal requirements and system operation do not constitute marketing. YoomTen sends them on the basis of performance of the contract, a legal obligation or legitimate interests, and users may not in every case disable them without making operation of the Service impossible.

  1. Marketing Communications and Personalised Recommendations

18.1. Newsletter and Electronic Direct Marketing

As a general rule, YoomTen sends marketing content to natural persons by email, push notification or another individual electronic communication channel only on the basis of the data subject’s prior, clear and explicit consent. Consent is handled separately from use of the Service, and refusal to consent does not prevent use of the Platform’s basic functions.

Where the mandatory law of a recipient’s Member State expressly permits a narrow exception—such as communications concerning similar services based on an existing customer relationship—YoomTen may apply that exception only where compliance with the local conditions has been documented. For natural persons residing in Hungary, YoomTen makes electronic direct marketing subject to prior consent.

18.2. Evidence and Withdrawal of Consent

YoomTen records the date and source of subscription, the email address provided, the version of the consent wording, and confirmation and withdrawal data. Consent may be withdrawn at any time, without giving reasons and free of charge, by using the unsubscribe link in the message, through the account settings or by emailing info@yoomten.com.

18.3. Recommendations within the Platform

YoomTen may recommend relevant courses within the Platform based on the selected language, categories, previous courses, searches, favourites and learning progress. Basic recommendations may be based on legitimate interests in improving the Service and user experience. Users may object to personalisation based on legitimate interests and, where technically available, disable it.

18.4. Business Contacts

Processing professional contact details of business contacts may be based on performance of a contract or on the legitimate interest in business communication between YoomTen and the recipient’s organisation. Electronic communications intended purely for advertising are subject to the conditions of the applicable marketing legislation, and the recipient may object at any time.

  1. Cookies, Mobile Identifiers and Similar Technologies

The website and mobile application may use cookies, local storage, mobile SDKs, device identifiers, pixels and similar technologies. An up-to-date list of the technologies actually used, providers, purposes and lifetimes is contained in the Cookie Policy and the cookie settings interface.

Strictly necessary technologies: login, session management, security, load balancing, consent settings and operation of the payment process. Consent is not required for these technologies.

Preference technologies: remembering language, appearance, subtitles, playback and accessibility settings. Depending on local law, their use may be subject to consent.

Analytics technologies: analysis of traffic, performance, errors and usage patterns. Non-essential analytics may be activated only after prior consent.

Marketing technologies: campaign measurement, audience building and advertising personalisation. They operate exclusively on the basis of prior consent.

Users may accept or reject non-essential technologies or configure them by category, and may change their decision at any time. YoomTen logs the consent decision to demonstrate compliance.

  1. Logging, Fraud Prevention and Information Security

20.1. Log Data

The Platform may log logins and logouts, IP addresses, browsers, operating systems, device identifiers, timestamps, sessions, API calls, administrator actions, errors, transaction events, content access and security alerts.

20.2. Purpose and Legal Basis

The purposes of logging are stable operation of the Platform, troubleshooting, auditability, detection of unauthorised access and fraud, prevention of misuse, incident management, clarification of contractual disputes and IT security. The legal basis is the legitimate interests of YoomTen, users and instructors and, in certain cases, a legal obligation.

20.3. Security Measures

encrypted data transmission using modern TLS protocols;

one-way hashing of passwords using modern methods;

role-based access control and the principle of least privilege;

multi-factor authentication for administrative access and where available;

logging, monitoring, alerting and an incident management procedure;

regular backups, recovery testing and business continuity measures;

vulnerability management, security updates and access reviews;

data protection and information security agreements, training and confidentiality.

No system can guarantee complete freedom from risk. YoomTen regularly reviews its measures and adapts them to the risks of processing, the state of technology and the costs of implementation.

  1. Processors, Recipients and Other Controllers

21.1. Categories of Processors

cloud, hosting, database, CDN and security providers;

video, audio, subtitling, translation and AI providers;

payment, payout, invoicing and accounting providers;

email, newsletter, push notification and customer service systems;

analytics, error tracking and consent management providers;

legal, tax, audit and information security advisers and service providers.

Processors act in accordance with YoomTen’s documented instructions, subject to confidentiality and under a contract compliant with Article 28 of the GDPR. A sub-processor may be engaged only under appropriate contractual conditions.

21.2. Recipients Acting as Independent Controllers

Personal data may be transferred to independent controllers such as payment service providers, banks, tax authorities, courts, the police, other authorities, consumer protection bodies, legal representatives or external service providers selected by the data subject. These recipients act under their own legal obligations and data processing rules.

21.3. Register of Processors

YoomTen publishes a separate, up-to-date list identifying the service providers actually used in its Register of Processors. The register contains the provider’s name, activity, data protection role, registered office or country of processing, the main categories of data and the legal basis for transfers to third countries.

21.4. Business Transformation

In the event of a transformation, merger, acquisition, investment, transfer of assets or transfer of a business line, personal data may be disclosed to advisers participating in negotiations and bound by confidentiality, or to a legal successor or purchaser, where necessary and subject to appropriate safeguards. Data subjects are informed in advance of any material change of controller.

  1. International Data Transfers

YoomTen seeks to process personal data within the European Economic Area. However, as a result of using certain cloud, payment, AI, video or communication service providers, personal data may be transferred to a country outside the EEA or made accessible from such a country.

Transfers to third countries take place only under the conditions laid down in Chapter V of the GDPR, in particular:

on the basis of an adequacy decision of the European Commission;

on the basis of the EU–US Data Privacy Framework, where the US recipient is duly certified;

by applying the standard contractual clauses (SCCs) adopted by the European Commission;

on the basis of another appropriate safeguard or exceptional legal basis recognised by the GDPR.

Where necessary, YoomTen conducts a transfer impact assessment, applies supplementary technical or organisational measures and verifies the recipient’s safeguards. Data subjects may request information about a specific transfer and the safeguards applied by contacting info@yoomten.com.

  1. Data Retention Periods

YoomTen retains data for the principal periods set out below. Where more than one period applies, the longer lawfully justified period shall prevail. In the event of official proceedings, a legal dispute, suspected fraud, a legal retention obligation or a legal hold, erasure may be suspended until the matter is concluded.

Data category / process // Main retention period

Registration and account data: For the duration of the account; after deletion, as a general rule, for no more than 30 days, except for data required by law or for legal claims.

Authentication and login data: For the duration of the account; security logs generally for 12 months and, in the case of a justified high-risk event, for no more than 24 months.

Course access and learning progress: For the duration of the account, contractual access or Business relationship, followed by no more than 30 days; for legal claims or certification, for no more than 5 years.

Instructor profile and contractual data: For the duration of the legal relationship and thereafter for the general limitation period applicable to civil claims, generally 5 years.

Course and media content: For as long as the course is available and for the contractual access period of previous purchasers; after deletion, generally within 30 days from technical systems and within no more than 90 days from backups.

AI questions, responses and generated supporting materials: Until deleted by the user or for the duration of the related account or course; temporary processing copies generally for no more than 30 days, unless a shorter provider period or a legal or security need applies.

Invoices and accounting documents: For at least 8 years in accordance with accounting rules.

Payment and refund records: For 8 years where they constitute accounting documents; other contractual transaction data generally for 5 years.

DAC7 due diligence and reporting documentation: For 10 years from the deadline for the reporting obligation.

General customer service correspondence: For 2 years after the case is closed; in the event of a legal claim, for no more than 5 years.

Consumer complaint report and response: For 3 years after the complaint is closed, or until the conclusion of a legal dispute.

Evidence of marketing consent: Until consent is withdrawn and thereafter for no more than 5 years for the purposes of demonstrating compliance and legal claims.

Minimum unsubscribe / suppression-list data: For the duration of marketing activities or until the data subject gives new valid consent, solely to prevent further communications.

Cookie consent logs: Generally for 5 years from the decision or withdrawal; the lifetime of individual cookies is set out in the Cookie Policy.

Data subject requests and documentation of their fulfilment: For 5 years after the request is closed.

Personal data breach documentation: For 5 years after the breach is closed or until the end of official or legal proceedings.

Backups: Generally for no more than 90 days under a rolling backup schedule; where data are restored, erasure requests are applied again.

Anonymised statistical data that can no longer be linked to a natural person may be retained indefinitely because they do not constitute personal data for the purposes of the GDPR.

  1. Automated Decision-Making and Profiling

YoomTen may use automated tools for course recommendations, fraud prevention, content moderation, learning suggestions, search ranking and service optimisation. These processes may analyse previous courses, searches, language settings, learning progress, reviews and technical risk indicators.

YoomTen does not make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect them, unless this is lawful and necessary and appropriate safeguards under Article 22 of the GDPR are provided. If such a new function is introduced, YoomTen provides separate information about the logic involved, its significance, the expected consequences and the possibility of human review.

The data subject may object to recommendation profiling based on legitimate interests. Personalisation based on consent may be disabled by withdrawing consent.

  1. Processing of Minors’ Data

YoomTen’s services are primarily intended for adult users, professional instructors, participants in higher education and businesses. A person under the age of eighteen may use the Platform under the conditions specified in the General Terms and Conditions and, where necessary, with the permission of their legal representative.

The age rule under Article 8 of the GDPR applies only to processing based on consent in connection with an information society service offered directly to a child. In such cases, the age threshold between 13 and 16 years established by the Member State in which the user resides shall apply, and the consent of a person below that age requires authorisation by a legal representative. For users residing in Hungary, the age threshold is 16 years under the Hungarian Information Act; a lower age threshold may not be applied even with parental or legal-representative approval. A user under 16 residing in Hungary may use a consent-based information society service offered directly to children only with the consent of their legal representative.

YoomTen may request an age declaration, approval from a legal representative or data necessary for reasonable verification of that approval. YoomTen does not apply verification that collects more data than necessary. Where appropriate authorisation is absent, we may restrict or delete the account.

Where a minor user is designated by an educational institution or Business Client, the institution or organisation is responsible for its own legal basis for processing and information obligations; YoomTen’s role is determined by the contract and data processing agreement between the parties.

  1. Rights of Data Subjects

Data subject rights may be exercised depending on the legal basis and circumstances of the relevant processing. Requests may be sent to info@yoomten.com or to the postal address of the Data Controller.

Right of access: The data subject may request confirmation as to whether we process their data and may request a copy and detailed information about the processing.

Right to rectification: The data subject may request correction of inaccurate data and completion of incomplete data.

Right to erasure: The data subject may request erasure of their data, for example where the purpose of processing has ceased, consent has been withdrawn and there is no other legal basis, or the processing is unlawful. Erasure does not apply where the data are required for a legal obligation, contractual access or legal claims.

Right to restriction: The data subject may request restriction of processing where they contest the accuracy of the data, the processing is unlawful, the data are required for a legal claim, or an objection is under examination.

Right to data portability: For automated processing based on consent or a contract, the data subject may request the data they have provided in a structured, commonly used and machine-readable format.

Right to object: The data subject may object, on grounds relating to their particular situation, to processing based on legitimate interests. They may object to direct marketing at any time and without giving reasons; in that case, processing for such purposes is discontinued.

Withdrawal of consent: Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Rights relating to automated decisions: If in the future a solely automated decision with significant effects were made, the data subject may be entitled to request human intervention, express their point of view and contest the decision.

26.1. Handling Requests

YoomTen responds to a request without undue delay and, as a general rule, within one month. The period may be extended by a further two months due to the complexity and number of requests; the data subject is informed of the extension and the reasons within the first month.

Exercising rights is generally free of charge. In the event of a manifestly unfounded or excessive request, in particular because of its repetitive character, YoomTen may charge a reasonable fee or refuse to act on the request. Where necessary, we request proportionate identification to prevent unauthorised disclosure of personal data.

Exercise of the rights of access and erasure must not adversely affect the rights of other persons, trade secrets, copyright or the security of the Platform. Where necessary, YoomTen redacts data or partially limits fulfilment of the request.

  1. Personal Data Breaches

A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data.

YoomTen investigates and documents breaches without delay, assesses their risks and takes measures necessary to mitigate damage and prevent recurrence. Where a breach is likely to result in a risk to the rights and freedoms of data subjects, YoomTen notifies the competent supervisory authority within 72 hours of becoming aware of it, unless notification is not required under the GDPR.

Where there is a high risk, YoomTen also informs data subjects without undue delay in clear and plain language, unless an exception under the GDPR applies.

  1. Remedies and Data Protection Contact

28.1. Contacting YoomTen

For data protection questions, complaints or data subject requests, the data subject may contact YoomTen at:

Email: info@yoomten.com

Postal address: 8200 Veszprém, Szent István utca 45, Hungary

Website: https://www.yoomten.com

28.2. Complaint to a Supervisory Authority

The data subject is entitled to lodge a complaint with the supervisory authority competent for their place of residence, habitual residence, place of work or the place of the alleged infringement. In Hungary, the competent authority is:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary

Postal address: 1363 Budapest, P.O. Box 9, Hungary

Email: ugyfelszolgalat@naih.hu

Telephone: +36 (1) 391-1400

Website: https://www.naih.hu

28.3. Judicial Remedies and Compensation

The data subject may bring proceedings before a court if they consider that the processing of their personal data infringes the GDPR or other applicable legislation. Subject to the conditions of the GDPR, they may claim compensation for material or non-material damage.

  1. Amendments to the Notice and Final Provisions

29.1. Amendments

YoomTen may amend the Notice due to changes in legislation, regulatory or judicial practice, a new service, a new AI function, a change of processor, information security requirements, the DAC7 process or business operations.

The amended Notice applies from the stated effective date. If a change materially affects data subjects’ rights or the substance of processing, YoomTen provides separate information in an appropriate manner, for example by email, account message or a prominent website notice.

29.2. Related Documents

General Terms and Conditions;

Instructor Terms;

Business Terms and data processing agreement;

Cookie Policy;

AI Privacy Notice;

Register of Processors;

Copyright and Notice & Takedown Policy;

Acceptable Use Policy;

internal data retention, incident management and information security policies.

29.3. Effect and Version History

Version: 1.0. // Internal draft, not publicly published.

Version: 1.1 // First effective, publicly published version. It contains detailed rules on YoomTen’s platform role, AI processing, DAC7 due diligence and reporting, marketing consent, specific retention periods, Business roles and international data transfers.

Publication and effective date of this Notice: 16 March 2026.

Annex 1 – Summary matrix of data processing activities

The table is a summary. For detailed provisions, the relevant section and the related specific policies shall apply.

Processing activity

Data subjects and key data

Purpose and legal basis

Main recipients

Retention

Technical operation of the website

Visitors; IP address, device, browser, session, necessary cookie

Operation and security; legitimate interests / necessity for electronic communications

Hosting, CDN and security provider

Logs: 12 months; necessary cookie in accordance with the Cookie Policy

Registration and account

Users; name, email address, password hash, role, settings

Account and access; contract

Cloud, authentication and email provider

Duration of account + 30 days, subject to exceptions

Social login

Users; external identifier, name, email address

Login; contract

Google, Apple or another selected provider

Duration of account + 30 days

Course purchase and access

Students; order, course, price, access

Performance of contract

Payment, invoicing and cloud service providers

Contract and access; 5 years for claims

Payment and refund

Purchasers; transaction identifier, amount, status, refund

Contract, accounting obligation, fraud prevention

Stripe/bank, accountant, tax authority

Accounting data: 8 years; other data: 5 years

Invoicing

Purchasers and instructors; name, address, tax number, accounting document

Legal obligation

Invoicing service provider, accountant, NAV

At least 8 years

Learning progress

Students; viewing, progress, result, note

Course functions; contract

Cloud, instructor on a limited basis, Business Client according to authorisation

Account/access + 30 days; certificate/claim: 5 years

Rating and feedback

Students and instructors; name/username, rating, text

Quality, information to the community; contract and legitimate interests

Public, moderation service provider

Until publication ends; 30 days after deletion, 5 years for claims

Instructor profile and course

Instructors; profile, professional data, course, statistics

Publication, sale, settlement; contract

Students, cloud, video and AI service providers

Relationship + 5 years; content until the end of access

Instructor payout

Instructors; payout identifier, revenue, commission, status

Payout and settlement; contract and legal obligation

Stripe/bank, accountant, tax authority

8 years, or 10 years under DAC7

DAC7 due diligence

Instructors; address, tax residence, TIN, birth/company data, account identifier

Identification of the Reportable Seller; legal obligation

NAV, verification service providers, advisers

10 years from the reporting deadline

DAC7 reporting

Reportable instructors; quarterly consideration, number of transactions, fees/taxes

Reporting to authorities; legal obligation

NAV and other tax authorities through automatic exchange

10 years from the reporting deadline

Business administration

Contacts and designated users; workplace data, access

Contract, organisational training; independent controllership / processing

Business Client, cloud, support provider

Term of contract + 5 years; user data as instructed

Business reporting

Corporate users; progress, completion, result

Reporting as instructed by the client; processing or legitimate interests/contract

Authorised administrator of the Business Client

Under the contract/DPA; as a rule, relationship + 30 days

AI assistant

Users; question, course extract, answer, language

Requested function; contract

AI and cloud providers

For as long as user content exists; temporary copy max. 30 days

Video translation and lip-sync

Instructors and persons appearing; video, audio, image, subtitles

Requested technology service; contract

Video, audio, translation and AI providers

For the duration of the course; temporary copy max. 30 days

AI-generated note, presentation, quiz

Users; learning material, prompt, generated output

Requested function; contract

AI and cloud providers

Until deletion by the user/account closure; temporary max. 30 days

Certificate of completion

Students; name, course, instructor, date, result, identifier

Documentation of completion; contract

Verification interface, Business Client according to authorisation

Duration of account; no more than 5 years for certification/legal purposes

Customer service

Enquirers; contact details, message, attachment, technical data

Support; contract and legitimate interests

Customer service and email provider

Closure of case + 2 years; 5 years for claims

Consumer complaint

Consumers; complaint, purchase, response, evidence

Legal obligation and claims management

Authority, legal representative

3 years; until the end of the dispute

Service notification

Users; email/push identifier, message status

Contract, legal obligation or legitimate interests

Email and push provider

Duration of account; delivery log as a rule 12 months

Newsletter and direct marketing

Subscribers; name, email address, consent log

Marketing; consent

Newsletter and email provider

Until withdrawal + evidence for 5 years

Suppression list

Unsubscribers; minimum email/identifier data and suppression status

Preventing further sending; legitimate interests/legal compliance

Newsletter provider

Until the end of marketing activities or until new consent

In-platform recommendation

Users; courses, searches, language, favourites

Relevance and user experience; legitimate interests or consent

Recommendation/analytics provider

Duration of account; until objection/deactivation

Analytics cookies

Visitors; cookie, event, device, approximate location

Usage analysis; consent

Analytics providers

In accordance with the Cookie Policy

Marketing cookies

Visitors; cookie, campaign, advertising identifier

Advertising and campaign measurement; consent

Advertising partners

In accordance with the Cookie Policy

Cookie consent log

Visitors; decision, time, identifier, version

Evidence of consent; legal obligation/legitimate interests

Consent management provider

5 years

Security logging

Users; IP address, device, action, alert

Security, fraud prevention; legitimate interests

Security, cloud and incident response providers

12 months; 24 months for high-risk events

Data subject request

Requesters; identification, request, response, fulfilment

GDPR obligation

Legal adviser, processor where necessary

5 years from closure

Personal data breach

Data subjects; breach data, risk, notification

GDPR obligation and security

NAIH, data subjects, experts

5 years from closure / until the end of the proceedings