Privacy Policy
At MS Endpoint Academy, your privacy and digital security are our highest priority. This Privacy Policy details the data we collect, how we use it to power your certification training, and your rights under GDPR.
1. Data Controller
The data controller responsible for the processing of your personal data on MS Endpoint Academy is Souhaiel MORHAG (MS Endpoint Academy). For any questions regarding your personal data or to exercise your GDPR rights, you can contact us directly at contact@msendpoint.com.
2. Personal Data We Collect
We only collect data strictly necessary to provide and enhance our educational services:
- Account Data: Full name, professional email address, and encrypted credentials when registering.
- Learning & Exam Telemetry: Quiz responses, certification exam scores, question streaks, response times, and domain competency progression.
- Payment & Billing Data: Payment details (credit card, billing address, VAT number) are processed directly and securely by Stripe Inc. under PCI-DSS Level 1 compliance. We never store your full payment card details on our servers.
- Technical & Security Telemetry: IP address, browser type, operating system, and session security logs to prevent account fraud and protect against unauthorized bot scraping.
3. Purpose & Legal Basis for Processing
Your personal data is processed under the following legal bases recognized by the General Data Protection Regulation (GDPR):
- Contract Performance (Art. 6(1)(b) GDPR): Delivering access to MD-102 question banks, simulating live exams, issuing completion certificates, and providing customer support.
- Legitimate Interest (Art. 6(1)(f) GDPR): Preventing platform abuse, securing against automated attacks, and refining the pedagogical accuracy of our training simulations.
- Legal Compliance (Art. 6(1)(c) GDPR): Retaining tax and commercial invoicing records as required by European and French accounting laws.
4. Third-Party Subprocessors
We partner exclusively with trusted enterprise vendors that guarantee strict data protection compliance:
- Stripe Inc.: PCI-DSS Level 1 payment processing and subscription billing.
- Hostinger International Ltd.: Secure European cloud infrastructure, managed databases, and encrypted backups.
- AI Cognitive Partners (OpenAI / Anthropic): Used solely to generate pedagogical question hints and personalized explanations. Queries are processed anonymously without transmitting user PII.
5. Data Retention Periods
We retain active learner account data for the duration of your active subscription plus 24 months following account inactivity to preserve your exam progress and credentials. Invoicing and financial transaction records are retained for 10 years in compliance with statutory commercial obligations.
6. Your Rights Under GDPR
Under Articles 15 to 22 of the GDPR, you have comprehensive rights regarding your personal information:
- Right of Access & Portability: Obtain a copy of all learning telemetry and profile records associated with your account.
- Right to Rectification: Update inaccurate or incomplete profile information directly from your settings or via support.
- Right to Erasure ("Right to Be Forgotten"): Request the complete deletion of your account and learning history.
- Right to Restriction & Objection: Object to specific data processing activities or request restriction of processing.
7. Cookies & Local Storage
We use only strictly necessary session cookies and local storage tokens (e.g., PHPSESSID, lang, active theme preferences) required for authentication and language switching. We do not use third-party behavioral advertising trackers.
8. Security Measures
All communications are protected using modern TLS/SSL (256-bit encryption). Databases are safeguarded with strict firewall rules, daily backups, and role-based administrative access controls.