Morto BJJ Online Academy
Library Paths

Legal

Privacy Policy

Last updated: 19/06/2026

1. Who We Are

ΖΟΥΓΑΝΕΛΗΣ ΕΜΜΑΝΟΥΗΛ ΚΑΙ ΝΙΚΟΛΑΟΣ ΟΕ ("we", "us", "our") operates the Morto Online Academy platform located at this website. We are based in Heraklion, Greece and are subject to the General Data Protection Regulation (GDPR), Regulation (EU) 2016/679.

For data protection enquiries, contact us at ManolisZou@gmail.com or via our contact page.

2. Data We Collect

  • Account data — first name, last name, email address, phone number (optional), belt colour (optional), profile picture (optional).
  • Purchase, account and billing data — single-payment / one-time course purchase records, subscription status, billing period, checkout waiver timestamps, subscription content access timestamps, Paddle customer, transaction, subscription and price identifiers, checkout records, Paddle payment status notifications, account activity records and billing records.
  • Usage data — lesson progress, video resume positions.
  • Newsletter preference and consent history — whether you opted in to marketing/newsletter emails, consent and unsubscribe timestamps, how the preference changed, IP address, user-agent and whether newsletter drop eligibility is active.
  • Communications — messages sent through the contact form.
  • Technical and security data — session identifiers, browser type, IP address, user-agent, request metadata, rate-limit signals, video delivery requests, payment and video processing notification metadata and server access/error logs collected through the hosting, application and video streaming environment.

3. How We Use Your Data

  • To provide access to single-payment / one-time purchased courses, active subscription content and track your progress.
  • To create Paddle checkouts, reconcile payment and subscription status, manage cancellations, handle refunds or chargebacks and protect against duplicate charges.
  • To send marketing newsletters and course updates — only if you have opted in.
  • To send service, legal, billing, price-change, security or account notices related to your account, purchases, subscriptions or platform use.
  • To respond to contact form enquiries.
  • To fulfil legal obligations (accounting, dispute resolution).

Legal basis: contract performance (Art. 6(1)(b) GDPR) for account creation, course access, subscription access, checkout creation and billing support; legal obligation (Art. 6(1)(c)) for tax, accounting and legally required notices; legitimate interest (Art. 6(1)(f)) for security logs, abuse prevention, fraud prevention, service reliability, account activity records, billing reconciliation, billing records, chargeback handling and dispute handling; consent (Art. 6(1)(a)) for marketing/newsletter communications and optional Mux playback analytics.

4. Cookies & Video Streaming

We use essential cookies and local browser storage required for authentication, account security, remembering your cookie choice, CSRF protection and checkout flows. These are necessary for the platform to work.

Our video player and video delivery are powered by Mux (Mux, Inc., USA). Mux receives the technical requests needed to stream videos, such as playback identifiers, IP address, browser/device information and request metadata.

If you accept optional cookies, we enable Mux playback analytics. In that case, Mux may receive playback analytics such as video start, watch events, playback quality, errors, device/browser information and a pseudonymous viewer identifier generated from your account ID using a one-way keyed hash. We do not send Mux your name, email address, phone number or raw account ID as viewer metadata. If you decline optional cookies, Mux playback analytics and Mux analytics cookies remain disabled while video playback still works.

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Paddle — checkout, payment processing, subscription management, tax handling, refunds, chargebacks and billing support. Paddle acts as Merchant of Record / authorised reseller for Paddle-processed transactions, and the Paddle entity shown at checkout or in Paddle's buyer terms handles payment data under Paddle's privacy notice, buyer terms and refund policy.
  • Mux, Inc. — video hosting, processing, streaming infrastructure and consent-based playback analytics (USA; Standard Contractual Clauses apply).
  • Top.Host — hosting and email infrastructure in Crete, Greece, including server logs and transactional/newsletter email delivery.
  • Server logs — hosting access and error logs used for security, troubleshooting, abuse prevention and service reliability. We do not currently use a separate third-party analytics or external logging provider.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete your local account profile, lesson progress, video resume positions, personal access tokens, avatar, local subscriptions, checkout records and local one-time order records tied directly to your account. Before deletion, we attempt to cancel any active paid subscription so you are not billed again.

Account deletion does not require us to erase every record where retention is required by law or is necessary and proportionate for legitimate interests. Some account activity records, billing records, payment notification status records, Paddle identifiers, newsletter consent/withdrawal history, tax/accounting records, refund records, chargeback records, security logs and support correspondence may be retained where necessary to resolve disputes, prove consent or withdrawal, prevent fraud, maintain service security, reconcile transactions, or prove transaction history. Where practical, these records are separated from the deleted account or no longer point to an active user profile. Paddle may also retain billing data as Merchant of Record under its own retention rules.

Security and server logs are normally kept only for as long as needed for security, abuse prevention, troubleshooting and service reliability. Billing, tax, refund, chargeback and account activity records are kept according to applicable legal limitation periods and business records obligations.

7. Your Rights (GDPR)

Under the GDPR you have the right to:

  • Access — request a copy of your account data (available via Dashboard → Privacy & Data → Download My Data; contact us if you need records not included in the self-service export).
  • Rectification — correct inaccurate data via your profile settings.
  • Erasure — delete your account via Dashboard → Privacy & Data → Delete Account, subject to limited records we must or may retain under the retention section above.
  • Restriction — ask us to restrict processing in specific circumstances.
  • Portability — receive your data in a machine-readable format (JSON download).
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — unsubscribe from marketing/newsletter emails at any time via the unsubscribe link in any newsletter email or in your profile settings. This does not stop service, legal, billing, security or account notices that do not rely on newsletter consent.

To exercise any right, use the tools in your dashboard or contact us. You may also lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.

8. Changes to This Policy

We may update this policy. Significant changes will be communicated via email or a notice in the platform. Continued use after the effective date constitutes acceptance.