Privacy Policy

Updated

How Forward Engineer handles personal data: what we collect, why, for how long, and the rights you can exercise.

Who we are

Forward Engineer ("we") is an education initiative built and operated by the team behind the DevOpsify infrastructure platform (devopsify.net). Contact: support@forwardengineer.net. The registered legal entity name and address are added here at incorporation.

What we collect and why

DataPurposeBasisRetention
Email addressAccount creation and loginContract / legitimate useUntil account deletion
Learning progress, readiness quiz resultsProviding the free member featuresContractUntil account deletion
Authentication and abuse eventsAccount security and abuse preventionLegitimate interest30 days
Payment metadata (not card data)Exam orders in SQLite: order id, email, item, amount, currency, status, provider reference and timestamps.ContractKept while the purchase relationship stands; deletion workflow pending
Technical logs (IP, user agent)Security, abuse preventionLegitimate interest30 days
Support messagesHandling your requestsContract12 months
One-time email codesProving email ownership at signup and the admin second factorContract / legitimate interestCode valid 10 minutes; hashes pruned after 7 days

Card data is never collected by us. Exam payments run through Paddle (merchant of record) hosted checkout; card numbers and security codes go to Paddle only.

Third-party processors

Hosting and media (Pexels: public images only, no personal data). Resend delivers one-time sign-in codes (recipient address and code only). Paddle processes exam payments as merchant of record (buyer email, item and amount; card data stays with Paddle).

Your rights

Our privacy compliance baseline is the EU General Data Protection Regulation (GDPR): access, correction, deletion, portability, objection, and restriction of processing. Exercise any of them via account settings or support@forwardengineer.net; we aim to respond within 30 days. For users in Türkiye, the local supervisory authority is the KVKK.

International transfers

Hosting and processors are selected to meet GDPR transfer rules: EU adequacy or standard contractual clauses. Transfers involving Türkiye follow the same safeguards, with local requirements applied where they exist. The current processor list is in the section above.

Changes

We version this policy; material changes are posted on this page before taking effect.

Bu sayfanın Türkçesi

We use Google Analytics to count visits. No ads, no cross-site tracking. Cookie Policy