Privacy Policy
1. System Overview
The Practice Engine ("we", "us", "our") operates as a structured skill acquisition platform. This document outlines how we collect, process, and protect your data within our system architecture.
By accessing our services, you enter a formal data processing relationship governed by this policy and applicable regulations.
2. Data Collection Parameters
We collect only what is necessary for system operation and skill progression tracking:
2.1 Account Data
- Full name and email address
- Billing information (processed via encrypted third-party gateways)
- Account credentials (stored in hashed format)
2.2 Usage Metrics
- Exercise completion logs and timestamps
- Progress tracking data and assessment results
- Session duration and interaction patterns
2.3 Technical Data
- IP address and browser fingerprint (security protocols)
- Device type and operating system
- Session cookies (essential functionality only)
3. Processing Logic
Your data serves specific operational functions:
- Service delivery and personalized exercise recommendations
- Progress tracking and performance analytics
- Technical support and system optimization
- Legal compliance and fraud prevention
We do not sell your personal data. Period.
4. Data Storage & Retention
Data is stored on encrypted servers with geographic redundancy. Retention periods:
- Active accounts: data retained for duration of service + 30 days
- Deleted accounts: data purged within 90 days
- Backup archives: maximum 180 days retention
- Legal holds: as required by applicable law
5. Third-Party Processors
We engage verified partners for critical infrastructure:
- Payment processing: Stripe, PayPal (PCI-DSS compliant)
- Cloud infrastructure: AWS, Google Cloud (SOC 2 certified)
- Email delivery: SendGrid, Postmark
- Analytics: Plausible (privacy-focused, no cookies)
6. Your Access Rights
Under applicable regulations, you retain:
- Right to access your complete data archive
- Right to rectification of inaccurate information
- Right to deletion ("right to be forgotten")
- Right to data portability (structured format)
- Right to object to specific processing
Requests processed within 14 business days. Verification required.
7. Security Protocols
We implement industry-standard protections:
- 256-bit encryption for data in transit (TLS 1.3)
- AES-256 encryption for data at rest
- Multi-factor authentication for administrative access
- Regular third-party security audits
- 24/7 intrusion detection monitoring
8. Policy Updates
This policy may be updated to reflect operational changes. Material updates will be communicated via email 30 days prior to implementation. Continued use constitutes acceptance of revised terms.