This Privacy Policy (the “Policy”) describes how MORARU ALEXANDRU VICTOR PERSOANA FIZICA AUTORIZATA an authorized natural person (persoană fizică autorizată – “PFA”) organized under the laws of Romania, with its professional registered address at Bucuresti Sectorul 3, Bulevardul CORNELIU COPOSU, Nr.5, Bl.103, Scara B, Etaj 1, Ap. 26, Romania, holding Unique Registration Code (CUI) 52494101, registered with the Romanian Trade Registry under no. F2025034077000, contact e-mail address support@cloudsecdefender.com (referred to herein as the “Operator”, the “Controller”, or, in the first person plural, “We”/“Us”/“Our”), collects, uses, stores, discloses and otherwise processes personal data in connection with:
(a) the marketing/landing page located at training.cloudsecdefender.com (the “Landing Page”), hosted on the Operator's e-mail marketing and/or website-building platform, referred to herein as the “Landing Page Platform”; and
(b) the checkout process, account creation, and delivery of the online course entitled “The Cybersecurity Abundance Machine” (the “Course”), all of which take place on the Thinkific technology platform (the “Hosting Platform”).
This Policy applies to any natural person who visits the Landing Page, visits the Hosting Platform pages associated with the Course, creates an account, purchases the Course, subscribes to the Operator's e-mail list, or otherwise communicates with the Operator (referred to herein as the “User”, the “Data Subject”, or, in the second person, “You”).
The Operator acts as the data controller, within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”), with respect to the processing described in this Policy. Where the User is located outside the European Economic Area, the Operator applies the standards set out in this Policy as a matter of policy and, where applicable, in compliance with the mandatory data-protection law of the User's jurisdiction, including, where relevant, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), to the extent such law applies to the Operator's processing activities.
This Policy should be read together with the Terms and Conditions of Use and the Cookie Policy, both available on the Site, which form an integral part of the contractual relationship between the Operator and the User. For the purposes of this Policy, the term “Site” refers collectively to the Landing Page and to the Course-related pages on the Hosting Platform.
Article no. 1- Identity of de data controller
1.1. The Controller responsible for determining the purposes and means of processing Personal Data is:
MORARU ALEXANDRU VICTOR PERSOANA FIZICA AUTORIZATA PFA
Registered Office: Bucuresti Sectorul 3, Bulevardul CORNELIU COPOSU, Nr.5, Bl.103, Scara B, Etaj 1, Ap. 26, Romania
Trade Register No.: F2025034077000
Fiscal Identification Code (CUI): 52494101
Email: support@cloudsecdefender.com
1.2. The Controller determines, independently and in accordance with applicable legislation, the purposes for which Personal Data is processed, the categories of Personal Data collected, the technical and organizational safeguards implemented to protect such data, the duration of storage, the categories of recipients to whom Personal Data may be disclosed, and the legal basis upon which each processing activity is performed.
1.3. Where the Controller engages third-party service providers for the provision of technological, payment, hosting, analytics, marketing, customer support or similar services, such providers shall process Personal Data only to the extent required for the performance of the relevant services and subject to appropriate contractual safeguards where required by law.
1.4. The Operator has not designated a Data Protection Officer (DPO), as such designation is not mandatory under art. 37 of the GDPR for an entity of this size and nature of activity. Should this change, this Policy will be updated accordingly.
1.4. Users may contact the Controller regarding any matter relating to this Policy or the processing of Personal Data by using the contact details specified above.
Article no. 2 – Categories of personal data processed
2.1. We collect the following categories of personal data, depending the User’s interaction with the Landing Page and the Hosting Platform:
a) Account and identification data: full name; e-mail address; password (created and stored, in encrypted/hashed form, by the Hosting Platform); country of residence; and, where voluntarily provided, billing details necessary for the issuance of a tax invoice (e.g., billing name, billing address, tax identification number).
b) Payment data: payment for the Course is processed through Thinkific Payments, Thinkific's integrated payment solution, which relies on Stripe, Inc. as the underlying payment infrastructure provider. Payment card data and related transaction details are collected and processed directly by Thinkific Payments/Stripe. The Operator does not receive, store, or have access to full payment card numbers, CVV codes, or other sensitive authentication data; the Operator only receives confirmation of payment, the amount paid, and, where applicable, the last four digits of the card and the transaction identifier, for accounting and support purposes. The Operator does not use PayPal or any separate, privately held Stripe account outside of the Thinkific Payments integration.
c) Usage, advertising and analytics data ( tracking pixels and similar technologies): IP address; device and browser type; operating system; referring/exit pages; course-progress data (e.g., lessons started or completed, quiz results, if applicable); log-in timestamps; and data collected through cookies and similar tracking technologies deployed on the Landing Page and/or the Hosting Platform, including, where enabled, the Meta (Facebook) Pixel, the TikTok Pixel, and Google Analytics. These tools may collect data such as pages visited, actions taken (e.g., viewing the Landing Page, initiating checkout, completing a purchase), device identifiers, and advertising identifiers, for the purposes described in Section 3 below and in the Cookie Policy. Further detail on these technologies, including how to manage Your preferences, is provided in the Cookie Policy.
d) Communication data: any information the User’s provide when contacting the Operator by e-mail or through any support channel, including the content of the correspondence and any attachments.
e) Marketing and newsletter data: e-mail address and, where provided, first name, collected through opt-in forms on the Landing Page and/or the Hosting Platform, where the User have subscribed to the Operator's newsletter or otherwise agreed to receive marketing communications; the User’s engagement with such communications (e.g., opens, clicks, unsubscribes), as tracked by the Landing Page Platform's e-mail functionality; and the User responses to nurture sequences, promotional campaigns, and reminder e-mails relating to the Course.
Article no. 3 – Legal basis and purposes of processing
3.1. We process the User’s personal data only where We have a valid legal basis to do so under art. 6 of the GDPR, as follows:
a) Performance of a contract (art. 6(1)(b) GDPR)
To create and administer the User’s Account; to process the User’s order and payment through Thinkific Payments/Stripe; to grant and maintain the User’s access to the Course; to issue invoices; and to provide customer support related to the Course.
b) Compliance with a legal obligation (art. 6(1)(c) GDPR)
To comply with applicable accounting, tax, and financial-reporting obligations under Romanian law; to respond to lawful requests from public authorities; and to comply with consumer-protection obligations, including those relating to the right of withdrawal described in the Terms and Conditions.
(c) Legitimate interests (art. 6(1)(f) GDPR)
To maintain the security and proper functioning of the Landing Page and the Hosting Platform; to prevent fraud and unauthorized account sharing; to analyze aggregated usage patterns (e.g., through Google Analytics) in order to improve the Landing Page and the Course; and to enforce the Terms and Conditions, including Our intellectual-property rights over the Course materials. Where We rely on legitimate interest, We have balanced Our interest against the Users rights and freedoms and consider that Our interest does not override them.
(d) Consent (art. 6(1)(a) GDPR)
To send the User marketing communications, newsletters, nurture sequences, and promotional/reminder campaigns regarding the Course, where You have separately opted in; and to use non-essential cookies and tracking pixels, including the Meta Pixel, the TikTok Pixel, and Google Analytics, for advertising and analytics purposes, as described in the Cookie Policy. Where required by applicable law (in particular, for Users located in the European Economic Area and the United Kingdom), these tools are activated only after You have given Your consent through the cookie-consent banner described in Section 11. You may withdraw Your consent at any time, as described in Section 7 below, without affecting the lawfulness of processing carried out before such withdrawal.
Article no. 4 – Recipients of personal data
4.1. We do not sell the User’s personal data. We disclose personal data only to the following categories of recipients, strictly to the extent necessary for the purposes described in this Policy:
(a) Thinkific Labs Inc., as the operator of the Hosting Platform, which processes Account data, course-progress data, and payment-related data on Our behalf and, in certain respects, as an independent controller for its own platform-operation purposes, under its own privacy policy;
(b) Thinkific Payments and its underlying payment infrastructure provider, Stripe, Inc., which process payment data as independent controllers/processors, subject to their own privacy policies and to applicable payment-industry security standards;
(c) the Landing Page Platform used by the Operator (Kit (formerly ConvertKit), operated by Kit.com, Inc.), which processes e-mail addresses and related engagement data for newsletter and marketing purposes, and, in the case of Carrd, may also process basic visitor/analytics data for the Landing Page;
(d) Meta Platforms, Inc. (Meta Pixel) and TikTok Inc./TikTok Pty Ltd (TikTok Pixel), which receive certain usage and device data from the Landing Page and/or the Hosting Platform for advertising measurement and ad-targeting purposes, each acting as an independent controller with respect to its own advertising network, subject to its own privacy policy;
(e) Google LLC (Google Analytics), where enabled, which processes usage data for website-analytics purposes, subject to Google's own privacy policy and, where applicable, Google's data-processing terms for Google Analytics;
(f) professional advisors (accountants, auditors, legal counsel), where necessary for the Operator's legitimate business and compliance purposes;
(g) competent public authorities, where disclosure is required by applicable law, by a court order, or by a lawful request from a regulatory or law-enforcement authority.
4.2. Where any of the recipients above process personal data on Our behalf as processors, We have entered into, or will enter into, data-processing agreements with such recipients containing the safeguards required under art. 28 of the GDPR. Where a recipient (such as Meta, TikTok, or Google, with respect to advertising/analytics data) acts as an independent controller, the Users are encouraged to also review that recipient's own privacy policy.
Article no. 5 - International data transfers
5.1. Given that the Operator is established in Romania (European Union) and the Hosting Platform (Thinkific), the payment provider (Thinkific Payments/Stripe), the Landing Page Platform, and the advertising/analytics providers referenced in Section 4 (Meta, TikTok, Google) are established in, or process data in, countries outside the European Economic Area (“EEA”), including the United States of America and Canada, Your personal data may be transferred to and processed in countries that do not benefit from an adequacy decision of the European Commission under art. 45 of the GDPR.
5.2. Where such transfers occur, We rely on the safeguards implemented by each respective recipient in accordance with art. 46 of the GDPR, in particular the European Commission's Standard Contractual Clauses, and, where applicable, a recipient's certification under an approved transfer mechanism (e.g., the EU-U.S. Data Privacy Framework, where the recipient is certified thereunder). Information on the specific safeguards adopted by Thinkific, Stripe, Meta, TikTok, Google, and the Landing Page Platform is available in each provider's respective privacy policy and data-processing terms.
5.3. You may request further information about the safeguards applicable to a specific international transfer by contacting Us at the address indicated in Section 1.
Article no. 6– Data retention
6.1. We retain the User’s personal data only for as long as necessary to fulfil the purposes described in this Policy, taking into account the following criteria:
a) Account and Course-access data are retained for as long as the User’s Account remains active, and for a reasonable period thereafter to allow the User to regain access, resolve disputes, and enforce Our legal rights;
b) invoicing and accounting data are retained for the minimum period required under Romanian fiscal and accounting legislation (currently up to 10 years for certain financial records, subject to change under applicable law);
c) newsletter and marketing data are retained until the User unsubscribe or withdraw the consent, plus a reasonable period thereafter to record such withdrawal and to suppress future sends to the User’s address;
d) advertising/analytics data collected via the Meta Pixel, TikTok Pixel, and Google Analytics are retained in accordance with the default or configured retention periods of each respective platform, as further described in the Cookie Policy;
e) communications data are retained for as long as reasonably necessary to resolve the matter to which they relate and for a reasonable period thereafter for record-keeping purposes.
6.2. Upon expiry of the applicable retention period, We will securely delete or anonymize the User’s personal data, unless a longer retention period is required or permitted by applicable law.
Article no. 7 – The User’s rights
7.1. To the extent the GDPR applies to the processing of the User’s personal data, the User have the following rights, which the User may exercise by contacting Us at the address indicated in Section 1:
(a) Right of access (art. 15 GDPR) – to obtain confirmation as to whether We process the User’s personal data, and, where so, to obtain a copy of such data and related information;
(b) Right to rectification (art. 16 GDPR) – to obtain the correction of inaccurate personal data and the completion of incomplete personal data;
(c) Right to erasure (art. 17 GDPR) – to obtain the deletion of the User’a personal data, subject to the exceptions provided by law (e.g., data We are required to retain for accounting or legal-compliance purposes);
(d) Right to restriction of processing (art. 18 GDPR) – to obtain the restriction of processing, in the circumstances set out in the GDPR;
(e) Right to data portability (art. 20 GDPR) – to receive the personal data the User have provided to Us, in a structured, commonly used, machine-readable format, and to have such data transmitted to another controller, where technically feasible;
(f) Right to object (art. 21 GDPR) – to object, on grounds relating to the User particular situation, to processing based on Our legitimate interest, and to object at any time, free of charge, to processing for direct-marketing purposes, including any related profiling, such as audience-building for advertising campaigns via the Meta Pixel or TikTok Pixel;
(g) Right to withdraw consent (art. 7(3) GDPR) – where processing is based on consent (e.g., newsletter sign-up or non-essential cookies/pixels), to withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
(h) Right not to be subject to automated individual decision-making, including profiling, which produces legal effects concerning the User or similarly significantly affects the user (art. 22 GDPR); the Operator does not engage in such automated decision-making;
(i) Right to lodge a complaint with a supervisory authority (art. 77 GDPR) – in particular, with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – “ANSPDCP”), at www.dataprotection.ro, or with the supervisory authority of Your habitual residence, place of work, or place of the alleged infringement, within the European Union.
7.2. You may unsubscribe from marketing/newsletter e-mails at any time by using the “unsubscribe” link included in every marketing e-mail, without needing to send a separate request.
7.3. We will respond to the User’s request within the timeframes required under the GDPR (in principle, within one month of receipt, extendable by a further two months for complex or numerous requests, in which case We will inform the User of the extension and the reasons for the delay).
7.4. We may request additional information reasonably necessary to confirm the User’s identity before acting on a request, in order to protect the User’s personal data against unauthorized access or disclosure.
Article no. 8 – Additional rights for residents of the United States
8.1. Where required by applicable state law (including, without limitation, the CCPA/CPRA in California and similar comprehensive privacy laws enacted in other U.S. states), residents of the applicable state have rights that are substantially similar to those described in Section 7, including the right to know what personal information is collected, the right to request deletion, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information and of targeted advertising, where applicable.
8.2. The Operator does not sell personal data in exchange for money. However, the use of the Meta Pixel and the TikTok Pixel for advertising purposes may constitute “sharing” of personal information for cross-context behavioral advertising under certain U.S. state privacy laws. Where applicable, We will provide a mechanism for opting out of such sharing (for example, through the cookie/consent management tool described in Section 11, or, where required, a “Do Not Sell or Share My Personal Information” link).
8.3. Residents of applicable U.S. states may exercise their rights by contacting Us at support@cloudsecdefender.com. We will not discriminate against You for exercising any right described in this Section.
Article no. 9 – Age restriction
9.1. The Landing Page, the Course, and the newsletter/marketing communications described in this Policy are directed exclusively at adults and are not intended for, and should not be used by, individuals under the age of 18. By providing the User’s personal data to Us (including by subscribing to Our newsletter, creating an Account, or purchasing the Course), the User represent and warrant that the User is at least 18 years of age.
9.2. We do not knowingly collect personal data from individuals under the age of 18. If We become aware that We have inadvertently collected personal data from a person under the age of 18, We will take reasonable steps to delete such data promptly. If You believe that a person under the age of 18 has provided Us with personal data, please contact Us at the address indicated in Section 1.
Article no. 10 – Security measures
10.1. We implement appropriate technical and organizational measures designed to protect the User’s personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks to the User’s rights and freedoms, in accordance with art. 32 of the GDPR.
10.2. Such measures include, where applicable, restricting access to personal data to personnel and service providers who need it for the purposes described in this Policy, and relying on the security measures implemented by Thinkific, Thinkific Payments/Stripe, and the Landing Page Platform for data hosted or processed on Our behalf, including encryption in transit, where implemented by such providers.
10.3. Notwithstanding the measures described above, no method of electronic transmission or storage is entirely secure, and We cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to the User’s rights and freedoms, We will notify the competent supervisory authority and, where required, the User, in accordance with articles 33 and 34 of the GDPR.
Article no. 11 – Cookies, pixels and similar technologies
11.1. The Landing Page and the Hosting Platform use cookies and similar tracking technologies, including the Meta Pixel, the TikTok Pixel, and, where enabled, Google Analytics, to operate, secure, and improve the Landing Page and the Hosting Platform, to measure the performance of Our advertising campaigns, and, where The User consent, for analytics and marketing/retargeting purposes.
11.2. Where required by applicable law (in particular, Directive 2002/58/EC, as amended (the “ePrivacy Directive”), as implemented in Romania and other EEA/UK jurisdictions), non-essential cookies and pixels — including the Meta Pixel, the TikTok Pixel, and Google Analytics — are not activated until You have given Your prior, informed, and freely given consent through a cookie-consent banner displayed on the Landing Page and/or the Hosting Platform. You may withdraw or modify Your consent at any time through the same banner or through Your browser settings.
11.3. Detailed information about the specific categories of cookies and pixels used, their individual purposes, their duration, the identity of each third-party recipient, and how to manage the User’s preferences is available in Our separate Cookie Policy, available on the Site, which forms an integral part of this Policy.
Article no. 12 - Policy changes and contact information
12.1. We use Deadline Funnel to facilitate personalized countdown timers and time-limited offers in connection with our marketing communications. In order to provide these functionalities, Deadline Funnel may use cookies and similar tracking technologies to record the date and time of your initial visit to a webpage. This information may be used to establish and maintain an individualized countdown timer across subsequent visits and, where applicable, in marketing emails.
12.2. For further information regarding Deadline Funnel’s collection, use, and processing of personal data, including its applicable terms and privacy practices, please refer to its Terms of Service and privacy information. You can find more information about it here: app.deadlinefunnel.com
Article no. 13- Policy changes and contact information
13.1. We may update this Policy from time to time to reflect changes in Our data-processing practices (including, in particular, once the final Landing Page Platform is selected, or if additional tracking/marketing tools are introduced) or in applicable law. The updated version will be published on the Site, indicating the date of the last update. Where the changes are material, We will provide additional notice, where required by applicable law (for example, by e-mail or through a prominent notice on the Site).
13.2. This Policy was last updated on 04 September 2026.
13.3. For any question, request, or complaint relating to this Policy or to the processing of the User’s personal data, please contact Us at support@cloudsecdefender.com, or by post at Bld. Corneliu Coposu, Nr.5, Bl.103, St. B, Fl. 1, Ap. 26, Bucharest 030602, Romania.
Moraru Alexandru Victor PFA · CUI 52494101 · Registered address: Bucureşti Sectorul 3, Bulevardul CORNELIU COPOSU, Nr.5, Bl. 103, Scara B, Etaj 1, Ap. 26 · Trade Registry No. F2025034077000 · (EUID): ROONRC.F2025034077000 · Contact: support@cloudsecdefender.com
Terms and Conditions | Privacy Policy | Cookie Policy | Cookie Settings
© 2026 MORARU ALEXANDRU VICTOR PERSOANA FIZICA AUTORIZATA. All rights reserved.
ANPC — Solutionarea Alternativa a Litigiilor