Privacy Policy

Last updated: May 20, 2025

1. Introduction

Welcome to MrLearny ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website and tell you about your privacy rights and how the law protects you.

This privacy policy applies to personal data we process when you:

  • Visit our website at https://mrlearny.com
  • Create an account and use our interactive learning tools
  • Upload and transform learning materials
  • Contact us for support or information
  • Subscribe to our newsletter or marketing communications

Our service is designed to comply with GDPR and other applicable data protection laws. We act as a data controller when processing your personal data.

2. The Data We Collect

2.1 Personal Data

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

Category Examples Purpose
Identity Data First name, last name, username To create and manage your account
Contact Data Email address To communicate with you and provide support
Technical Data IP address, browser type and version, device information To improve our website and ensure security
Usage Data Information about how you use our website and services To analyze trends and improve our services
Content Data Learning materials you upload, quizzes, flashcards To provide our interactive learning tools
Profile Data Your preferences, feedback, and survey responses To personalize your experience
Marketing Data Your preferences in receiving marketing from us To send relevant information about our services

2.2 Special Categories of Personal Data

We do not collect any special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, etc.) unless you explicitly choose to include such information in your uploaded content.

2.3 Content You Upload

When you upload learning materials to our platform, we process that content to provide our services. You retain ownership of all content you upload. We do not use your uploaded content for purposes other than providing our services to you, except as otherwise described in this policy.

3. How We Collect Your Data

We use different methods to collect data from and about you, including:

3.1 Direct Interactions

You may provide us with your Identity, Contact, and Profile Data by filling in forms or by corresponding with us. This includes personal data you provide when you:

  • Create an account
  • Subscribe to our services
  • Request marketing to be sent to you
  • Give us feedback or contact us

3.2 Automated Technologies

As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.

3.3 Third Parties

We may receive personal data about you from various third parties such as:

  • Analytics providers such as Google Analytics
  • Payment processors for subscription management
  • Identity verification services, if applicable

4. How We Use Your Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Contract Performance: Where we need to perform the contract we are about to enter into or have entered into with you.
  • Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Legal Obligation: Where we need to comply with a legal obligation.
  • Consent: Where you have provided your consent.

Here is a description of all the ways we plan to use your personal data and which legal bases we rely on to do so:

Purpose Data Used Legal Basis
Account registration and management Identity, Contact Performance of Contract
Processing your learning materials Content Data Performance of Contract
Providing customer support Identity, Contact, Technical Performance of Contract
Analyzing usage to improve our services Technical, Usage Legitimate Interests
Personalization of services Profile, Usage Legitimate Interests
Marketing communications Identity, Contact, Marketing Consent
Detecting and preventing fraud Technical, Usage Legitimate Interests

4.1 Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. You can update your marketing preferences at any time in your account settings or by contacting us.

If you opt-in to receive our marketing communications, you will receive promotional information about our products and services. You can opt-out at any time by clicking the "unsubscribe" link in any of our communications or by contacting us.

5. Cookies

We use cookies and similar tracking technologies to track the activity on our service and store certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.

We use the following types of cookies:

  • Essential Cookies: Required for the operation of our website. They include, for example, cookies that enable you to log into secure areas.
  • Analytical/Performance Cookies: Allow us to recognize and count the number of visitors and see how visitors move around our website when they are using it.
  • Functionality Cookies: Used to recognize you when you return to our website, enabling us to personalize our content for you.
  • Targeting Cookies: Record your visit to our website, the pages you have visited, and the links you have followed.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service.

For more information about the cookies we use, please see our Cookie Policy.

6. Data Sharing

We may share your personal data with the following categories of recipients:

6.1 Service Providers

We share your data with service providers who perform services on our behalf, such as:

  • Hosting and cloud infrastructure providers
  • Payment processors
  • Email service providers
  • Analytics providers
  • Customer support services

All our third-party service providers are required to take appropriate security measures to protect your personal data.

6.2 Legal Requirements

We may disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

6.3 Business Transfers

If we are involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different Privacy Policy.

6.4 With Your Consent

We may disclose your personal data for any other purpose with your consent.

We do not sell your personal data to third parties.

7. International Transfers

Your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.

If we transfer your personal data to countries outside the European Economic Area (EEA), we ensure a similar degree of protection is afforded to your data by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe (Standard Contractual Clauses).
  • Where we use providers based in the US, we may transfer data to them if they are part of the EU-US Privacy Shield or similar frameworks that ensure an adequate level of data protection.

8. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed in an unauthorized way. These measures include:

  • Encryption of sensitive data
  • Regular security assessments
  • Access controls and authentication measures
  • Secure backup procedures
  • Staff training on data security

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider:

  • The amount, nature, and sensitivity of the personal data
  • The potential risk of harm from unauthorized use or disclosure
  • The purposes for which we process your personal data
  • Whether we can achieve those purposes through other means
  • The applicable legal requirements

In some circumstances, we may anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Account information is retained until you delete your account. You can delete your account at any time in your account settings.

10. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it.
  • Object to processing of your personal data where we are relying on a legitimate interest and you feel it impacts your fundamental rights and freedoms.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in certain scenarios.
  • Request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time where we are relying on consent to process your personal data.

If you wish to exercise any of these rights, please contact us using the details provided in the "Contact Us" section below.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of your personal data infringes on the GDPR.

11. Children's Privacy

Our service is not intended for children under the age of 16 without parental consent. We do not knowingly collect personally identifiable information from children under 16. If you are a parent or guardian and you are aware that your child has provided us with personal data without your consent, please contact us so that we can take necessary actions.

If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.

12. Third-Party Links

Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. For significant changes, we will make reasonable efforts to provide notification, such as an email notification if you have an account with us.

Your continued use of our service after we post any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:

MrLearny
Radnička cesta 80
10000 Zagreb
Croatia

Our Data Protection Officer can be contacted at: dpo@mrlearny.com

If you are located in the European Union, you have the right to make a complaint at any time to your local data protection authority.

15. GDPR Specific Information

For users residing in the European Economic Area (EEA), we are committed to processing your data in compliance with the General Data Protection Regulation (GDPR).

15.1 Data Controller

For the purposes of the GDPR, MrLearny (registered at Radnička cesta 80, 10000 Zagreb, Croatia) is the data controller responsible for your personal data.

15.2 Legal Basis for Processing

We have outlined the legal bases we rely on for processing your data in Section 4 of this policy. Where we rely on consent as a legal basis, you have the right to withdraw your consent at any time.

15.3 Data Protection Impact Assessment

For processing activities that may result in a high risk to your rights and freedoms, we conduct Data Protection Impact Assessments (DPIAs) to identify and minimize these risks.

15.4 Data Protection by Design and Default

We implement appropriate technical and organizational measures to ensure data protection principles are integrated into our processing activities from the earliest stage, and that by default, only personal data necessary for each specific purpose is processed.