GDPR Privacy Policy
Last updated: March 17, 2025
This Privacy Policy describes how Dovlase ("we", "us", or "our"), operating at bem-v7.com, collects, uses, stores, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection legislation. By using our platform, you acknowledge the practices described in this document.
1. Data Controller
Dovlase acts as the data controller for personal data collected through bem-v7.com. Our registered address is Almendsberg 585, Almendsberg 1531, 9428 Walzenhausen, Switzerland. For all data protection matters, you may contact us at support@bem-v7.com or by telephone at +41 79 257 99 73.
2. Definitions
For the purposes of this Policy, the following definitions apply:
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure, or deletion. |
| Data Subject | The natural person whose personal data is being processed. |
| Processor | A third party that processes personal data on behalf of the controller. |
| Consent | Freely given, specific, informed, and unambiguous indication of agreement to processing. |
3. Data We Collect
3.1 Data You Provide Directly
We collect personal data that you voluntarily submit when registering an account, enrolling in courses, contacting our support team, or completing forms on our platform. This may include your full name, email address, billing information, communication preferences, and any content you submit during learning activities.
3.2 Data Collected Automatically
When you access bem-v7.com, we automatically collect certain technical data including your IP address, browser type and version, device identifiers, operating system, referring URLs, pages visited, session duration, and interaction patterns. This data is collected through cookies and similar tracking technologies as described in Section 9 of this Policy.
3.3 Data from Third Parties
We may receive personal data from third-party authentication providers if you choose to register or log in using a third-party service. We may also receive aggregated or anonymised data from analytics partners to improve our platform.
4. Legal Bases for Processing
We process your personal data only where a valid legal basis exists under Article 6 of the GDPR. The applicable bases are as follows:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and service delivery | Performance of a contract (Art. 6(1)(b)) |
| Payment processing and billing | Performance of a contract (Art. 6(1)(b)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (with opt-in) | Consent (Art. 6(1)(a)) |
| Platform security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Analytics and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Personalised learning experience | Consent or contract (Art. 6(1)(a)/(b)) |
Where we rely on legitimate interests, we have conducted a balancing assessment to ensure that our interests do not override your fundamental rights and freedoms.
5. How We Use Your Data
We use the personal data we collect for the following purposes:
Service provision: To create and manage your account, process enrolments, deliver course content, facilitate live sessions with instructors, and provide customer support.
Personalisation: To adapt learning paths, recommend relevant courses, and tailor the platform experience based on your activity and preferences.
Communications: To send transactional messages such as booking confirmations, session reminders, and account notifications. With your consent, we may also send promotional communications about new courses or features.
Security and integrity: To detect, investigate, and prevent fraudulent activity, unauthorised access, and abuse of our platform.
Analytics and improvement: To understand how users interact with our platform and to improve functionality, content quality, and overall user experience.
Legal compliance: To fulfil obligations under applicable law, respond to lawful requests from authorities, and enforce our Terms of Service.
6. Data Sharing and Disclosure
6.1 Service Providers
We engage trusted third-party processors to support our operations. These include cloud hosting providers, payment processors, email delivery services, video conferencing infrastructure, and analytics platforms. All processors are bound by data processing agreements requiring them to handle your data only on our documented instructions and in compliance with the GDPR.
6.2 Instructors
When you enrol in a session, limited profile information necessary for the delivery of that session may be shared with the relevant instructor. Instructors are contractually prohibited from using this data for any purpose other than delivering the agreed service.
6.3 Legal Requirements
We may disclose personal data where required to do so by law, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our rights, the safety of users, or the integrity of our platform.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred as part of that transaction. We will notify affected users prior to any such transfer and ensure continued protection under equivalent terms.
6.5 No Sale of Data
We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.
7. International Data Transfers
Dovlase operates as an international platform serving learners globally. As a result, your personal data may be transferred to and processed in countries outside your country of residence, including countries outside the European Economic Area. Where such transfers occur, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms as permitted under Chapter V of the GDPR.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and profile data | Duration of account plus 3 years after closure |
| Transaction and billing records | 10 years from transaction date |
| Course activity and progress | Duration of account plus 2 years after closure |
| Support correspondence | 3 years from last interaction |
| Marketing consent records | Until consent is withdrawn plus 1 year |
| Technical logs and access data | 12 months from collection |
Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use
Strictly necessary cookies are essential for the platform to function and cannot be disabled. They enable core features such as authentication, session management, and security.
Functional cookies remember your preferences and settings to provide a more personalised experience, such as language selection and display options.
Analytics cookies help us understand how users navigate the platform by collecting aggregated, anonymised data about page views and interactions.
Marketing cookies are used only where you have provided explicit consent and allow us to deliver relevant promotional content.
9.2 Managing Cookies
You may manage your cookie preferences at any time through our cookie consent tool, accessible from the platform footer. You may also configure your browser to refuse or delete cookies; however, disabling certain cookies may affect the functionality of our platform. Withdrawing cookie consent does not affect the lawfulness of processing based on consent before withdrawal.
10. Your Rights Under the GDPR
As a data subject, you have the following rights with respect to your personal data. To exercise any of these rights, please contact us at support@bem-v7.com.
| Right | Description |
|---|---|
| Right of access | You may request a copy of the personal data we hold about you and information about how it is processed. |
| Right to rectification | You may request correction of inaccurate or incomplete personal data. |
| Right to erasure | You may request deletion of your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful. |
| Right to restriction | You may request that we limit processing of your data in certain circumstances, such as while accuracy is contested. |
| Right to data portability | You may request your data in a structured, commonly used, machine-readable format for transfer to another controller. |
| Right to object | You may object to processing based on legitimate interests or for direct marketing purposes at any time. |
| Right to withdraw consent | Where processing is based on consent, you may withdraw it at any time without affecting prior processing. |
| Right to lodge a complaint | You have the right to lodge a complaint with a supervisory authority if you believe your data has been processed unlawfully. |
We will respond to all verified requests within 30 days. In complex cases, this period may be extended by a further 60 days, and we will notify you accordingly.
11. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include encryption of data in transit and at rest, access controls and authentication mechanisms, regular security assessments and audits, staff training on data protection obligations, and incident response procedures.
Despite these measures, no method of transmission over the internet or electronic storage is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, inform affected individuals without undue delay.
12. Children's Privacy
Our platform is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under this age without verifiable parental or guardian consent. If we become aware that we have collected data from a child without appropriate consent, we will take prompt steps to delete that data. If you believe we have inadvertently collected such data, please contact us immediately at support@bem-v7.com.
13. Automated Decision-Making and Profiling
We may use automated processes to personalise your learning experience, such as recommending courses based on your activity history. These processes do not produce legal or similarly significant effects and are designed solely to improve the relevance of content presented to you. Where any automated decision-making could produce significant effects, we will inform you and provide the opportunity to request human review.
14. Third-Party Links
Our platform may contain links to external websites or services operated by third parties. This Privacy Policy applies solely to data processed by Dovlase. We are not responsible for the privacy practices of third-party sites and encourage you to review their respective privacy policies before providing any personal data.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will notify registered users by email or through a prominent notice on the platform prior to the change taking effect. The date at the top of this document indicates when the Policy was last revised. Continued use of our platform after the effective date of any changes constitutes acceptance of the updated Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us through any of the following channels:
Email: support@bem-v7.com
Phone: +41 79 257 99 73
Postal address: Dovlase, Almendsberg 585, Almendsberg 1531, 9428 Walzenhausen, Switzerland
We are committed to resolving all data protection queries promptly and transparently. If you are not satisfied with our response, you retain the right to escalate your concern to the competent supervisory authority in your jurisdiction.