We use cookies and similar technologies

Coursfy uses essential cookies and browser storage to run the site. The optional categories stay off until you switch them on: analytics turns on error monitoring, and marketing and cross-device analytics load nothing today. You can accept all, reject non-essential, or manage each category. AI and voice processing are set in Privacy settings. Privacy Policy · Cookie Policy

Skip to main content
Coursfy
HomeAcademiesCoursesPricingLuminaCreate an academy
Coursfy

Turn your expertise into a thriving online academy — courses, community, and payments in one place.

BROWSE

  • All academies
  • Free academies
  • By category
  • New this week

LEARNERS

  • Use an invite
  • Certificates
  • Help Center
  • FAQs

CREATORS

  • Request a call
  • White-label & SSO
  • Payouts & fees
  • Success stories

Company

  • About us
  • Blog
  • Careers
  • Contact Us

© 2026 Coursfy. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibility Statement
Back to home

Processing register & retention

Last updated: June 2026


This page documents lawful bases under GDPR Article 6 and default retention periods for Coursfy processing activities.

Data controller

Coursfy is the controller for consumer accounts. Academy owners are controllers for their community member data; Coursfy acts as processor under a DPA.

Your rights

Access, rectification, erasure, restriction, portability, and objection — exercise via Settings → Privacy or privacy@coursfy.com.

Lawful basis register

ActivityData categoriesLawful basisRetention
Account registration & authenticationName, email, password hash, IP, user agentContract (Art. 6(1)(b)) — necessary to provide the serviceUntil account deletion + 30 days operational backup
Academy membership & course enrolmentProfile, progress, payment referencesContract (Art. 6(1)(b))Duration of membership + statutory accounting periods
Payment processingBilling metadata via Stripe; no full PAN on CoursfyContract + legal obligation (tax/accounting)Per Stripe and local accounting law (typically 7 years for invoices)
Marketing newsletterEmail, consent timestampConsent (Art. 6(1)(a)) — withdraw anytimeUntil unsubscribe or 24 months inactivity
Analytics / error monitoring (Sentry)Pseudonymous events, scrubbed stack tracesConsent (Art. 6(1)(a))90 days default Sentry retention
AI assistant (academy/course)Questions, answers, optional conversation IDsConsent for personalization; contract for core Q&A when enabled by academyPer academy settings; default 12 months conversation logs
Security & audit logsUser ID, action type, timestamp, IP (hashed where possible)Legitimate interest (Art. 6(1)(f)) — security of processing12 months rolling (see retention policy)

Data retention schedule

CategoryPeriodAction after period
Active user accountWhile account is activeFull profile and content access
Deleted user account30 days after erasure requestHard delete or anonymize PII; backups expire per cycle
Consent preferences3 years after last updateProof of consent for regulatory requests
Security / access audit logs12 monthsAppend-only store; then aggregate or delete
Payment & invoice records7 years (or local statutory minimum)Anonymize where possible after legal hold ends
Marketing contactsUntil unsubscribe + 30 daysRemove from mailing lists
AI conversation logs12 months defaultAcademy owners may request shorter window
Server/application logs90 daysPII redacted at ingestion
Back to home

Processing register & retention

Last updated: June 2026


This page documents lawful bases under GDPR Article 6 and default retention periods for Coursfy processing activities.

Data controller

Coursfy is the controller for consumer accounts. Academy owners are controllers for their community member data; Coursfy acts as processor under a DPA.

Your rights

Access, rectification, erasure, restriction, portability, and objection — exercise via Settings → Privacy or privacy@coursfy.com.

Lawful basis register

ActivityData categoriesLawful basisRetention
Account registration & authenticationName, email, password hash, IP, user agentContract (Art. 6(1)(b)) — necessary to provide the serviceUntil account deletion + 30 days operational backup
Academy membership & course enrolmentProfile, progress, payment referencesContract (Art. 6(1)(b))Duration of membership + statutory accounting periods
Payment processingBilling metadata via Stripe; no full PAN on CoursfyContract + legal obligation (tax/accounting)Per Stripe and local accounting law (typically 7 years for invoices)
Marketing newsletterEmail, consent timestampConsent (Art. 6(1)(a)) — withdraw anytimeUntil unsubscribe or 24 months inactivity
Analytics / error monitoring (Sentry)Pseudonymous events, scrubbed stack tracesConsent (Art. 6(1)(a))90 days default Sentry retention
AI assistant (academy/course)Questions, answers, optional conversation IDsConsent for personalization; contract for core Q&A when enabled by academyPer academy settings; default 12 months conversation logs
Security & audit logsUser ID, action type, timestamp, IP (hashed where possible)Legitimate interest (Art. 6(1)(f)) — security of processing12 months rolling (see retention policy)

Data retention schedule

CategoryPeriodAction after period
Active user accountWhile account is activeFull profile and content access
Deleted user account30 days after erasure requestHard delete or anonymize PII; backups expire per cycle
Consent preferences3 years after last updateProof of consent for regulatory requests
Security / access audit logs12 monthsAppend-only store; then aggregate or delete
Payment & invoice records7 years (or local statutory minimum)Anonymize where possible after legal hold ends
Marketing contactsUntil unsubscribe + 30 daysRemove from mailing lists
AI conversation logs12 months defaultAcademy owners may request shorter window
Server/application logs90 daysPII redacted at ingestion