Help Center Privacy Statement

Privacy Statement

Currently viewing information for:

Fielse Commerce - FZCO

IFZA Business Park, DDP, 001 - 80378, Dubai Silicon Oasis, United Arab Emirates

Data Protection Contact: [email protected]

This Privacy Policy ("Policy") explains how Fielse Commerce - FZCO ("Fielse", "we", "us", or "our") collects, uses, stores, discloses, and protects your personal information in connection with your use of the Fielse platform, including our website (www.fielse.com), mobile applications, and all associated educational content and services (collectively, the "Service").

 

 

Fielse is the sole data controller for all personal information processed in connection with the Service. No other entity, including our local payment representatives, acts as a data controller in relation to your personal information.

 

This Policy applies to all users of the Service regardless of their country of residence. Where applicable, jurisdiction-specific supplements are provided in Sections 12 (European Economic Area, UK and Switzerland), 13 (Turkey — KVKK), and 14 (California — CCPA/CPRA).

 

By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please discontinue use of the Service and contact us to close your account.

 

Table of Contents

1. Data Controller and Contact Information

2. Information We Collect

3. How We Use Your Information — Purposes and Legal Bases

4. Disclosure of Your Information to Third Parties

5. Third-Party Service Providers

6. International Data Transfers

7. Data Retention

8. Security Measures

9. Your Rights and How to Exercise Them

10. Cookies and Tracking Technologies

11. Children and Minors

12. EEA, UK and Switzerland — GDPR Supplement

13. Turkey — KVKK Supplement

14. California — CCPA/CPRA Supplement

15. Changes to This Policy

16. Contact Us

 

1. Data Controller and Contact Information

The data controller responsible for your personal information is:

 

Fielse Commerce - FZCO

IFZA Business Park, DDP, 001 - 80378, Dubai Silicon Oasis, United Arab Emirates

TRN: 105395213900001

Privacy / Data Protection: [email protected]

General Support: [email protected]

Help Centre: https://fielse.com/help

 

For all questions relating to this Policy, the exercise of your data subject rights, or any concern regarding our data practices, please contact us at [email protected]. We aim to respond to all privacy enquiries within 30 days.

2. Information We Collect

We collect and process the following categories of personal information:

 

2.1 Information You Provide Directly

       Account Registration Data: Your name, email address, and password when you create a Fielse account.

       Payment Information: Billing details such as your name, billing address, and payment instrument details (e.g., card type and last four digits). Full payment card numbers are processed exclusively by our payment processor, Stripe, and are never stored on Fielse systems.

       Communications: Any information you provide when contacting our support team, including the content of your messages, feedback, and survey responses.

 

2.2 Information We Collect Automatically

       Usage Data: Information about your interactions with the Service, including courses accessed, content viewed, progress and completion metrics, assessment results, time spent per session, and engagement patterns within interactive lessons.

       Device and Technical Information: IP address, device type, device identifiers, operating system version, browser type and version, language settings, time zone, and app version.

       Log Data: Server logs recording access times, pages visited, error reports, and system activity.

       Location Data: General geographic location inferred from your IP address (country/city level). We do not collect precise GPS location data.

       Session Data: Information about the duration and frequency of your sessions, and the features you interact with.

 

2.3 Information from Third Parties

       Payment Processors: Stripe provides us with transaction confirmations, billing status, and limited payment metadata (e.g., last four digits of card, expiry month/year). We do not receive full card numbers.

       Analytics and Infrastructure Partners: Aggregated and pseudonymised data from Cloudflare (security and performance), Gumlet and Bunny.net (video delivery metrics), and Google Analytics (usage analytics).

       Customer Support: Interaction records from Tawk.to if you use the live chat feature.

 

2.4 Information We Do Not Collect

       We do not collect sensitive personal data (e.g., health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, or criminal records).

       We do not collect or store precise GPS or real-time location data.

       We do not collect user-generated content, as the Service does not include features for users to upload, post, or share content with other users.

       We do not collect payment card numbers, CVV codes, or full banking details — these are handled exclusively by Stripe.

 

3. How We Use Your Information — Purposes and Legal Bases

The table below sets out all purposes for which we process your personal information, the categories of data involved, and the legal basis relied upon under applicable data protection law (including UAE PDPL, GDPR, and KVKK).

 

Purpose

Data Categories

Legal Basis

Providing and operating the Service (account creation, authentication, content delivery, subscription management)

Account data, Usage data, Device/Technical data, Payment data

Performance of contract (GDPR Art. 6(1)(b); PDPL; KVKK Art. 5(2)(c))

Processing payments and managing billing cycles

Account data, Payment data

Performance of contract

Customer support and responding to enquiries

Account data, Communication data, Usage data

Performance of contract; Legitimate interests

Personalising your learning experience (e.g., tracking course progress, recommending next steps within your enrolment)

Usage data, Account data

Performance of contract; Legitimate interests

Security, fraud prevention, and platform integrity (bot detection, DDoS mitigation, abuse prevention)

Device/Technical data, IP address, Usage data

Legitimate interests (GDPR Art. 6(1)(f)); Legal obligation

Analytics and service improvement (understanding how users interact with the platform to improve content and features)

Usage data, Device data (pseudonymised/aggregated)

Legitimate interests

Sending transactional communications (receipts, billing notifications, account alerts, service updates)

Account data, Payment data

Performance of contract; Legitimate interests

Sending marketing communications about Fielse services and promotions

Account data (email)

Consent (GDPR Art. 6(1)(a)); KVKK explicit consent — opt-in only; withdrawable at any time

Compliance with legal obligations (responding to lawful requests from public authorities, regulators, or courts)

All categories as required

Legal obligation (GDPR Art. 6(1)(c)); PDPL; KVKK

Establishment, exercise, or defence of legal claims

All categories as required

Legitimate interests; Legal obligation

Future AI/machine learning features (if and when introduced — subject to separate notice and, where required, consent)

Usage data, Account data (anonymised or aggregated where possible)

Consent (where required); Legitimate interests — will be communicated in advance of any such processing

 

We will never use your personal information for purposes incompatible with those listed above without first providing you with clear notice and, where required by law, obtaining your consent.

 

4. Disclosure of Your Information to Third Parties

Fielse does not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes. We may share your information in the following limited circumstances:

 

4.1 Service Providers

We engage trusted third-party companies to perform services on our behalf. These parties act as data processors and are contractually obligated to process personal information only on our instructions and in accordance with applicable data protection law. See Section 5 for a full list.

4.2 Legal Requirements

We may disclose personal information where we reasonably believe disclosure is required by applicable law, regulation, court order, or request from a competent public authority, including data protection regulators, tax authorities, or law enforcement agencies.

4.3 Protection of Rights

We may disclose information where necessary to protect the rights, property, or safety of Fielse, our users, or third parties, including for the purposes of fraud prevention, security investigations, and enforcement of our Terms of Use.

4.4 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency, your personal information may be transferred to the relevant successor entity, subject to the same or equivalent privacy protections. We will notify you of any such transfer before it takes effect, where required by law.

4.5 Aggregated and Anonymised Data

We may share aggregated, anonymised, or pseudonymised information that cannot reasonably be used to identify you, for purposes such as analytics, research, or business reporting. Such data is not personal information.

 

5. Third-Party Service Providers

The following table identifies our key third-party service providers, the nature of their role, and the data they access:

 

Category

Details

Stripe (Stripe, Inc.)

Payment processing. Processes payment card data directly. Receives billing name, email, and transaction metadata. Privacy Policy: stripe.com/privacy

Cloudflare (Cloudflare, Inc.)

Content delivery network, DDoS protection, bot mitigation, and security. Processes IP addresses and request metadata. Privacy Policy: cloudflare.com/privacypolicy

Gumlet (Gumlet, Pte. Ltd.)

Video encoding, delivery, and performance analytics. Processes video playback data and device/IP information. Privacy Policy: gumlet.com/privacy

Bunny.net (BunnyWay d.o.o.)

High-speed video and asset delivery, playback statistics, and CDN services. Processes IP and playback metadata. Privacy Policy: bunny.net/privacy

Vimeo (Vimeo, Inc.)

Video hosting and streaming for educational content. Processes playback data. Privacy Policy: vimeo.com/privacy

Google Analytics (Google LLC)

Website and app usage analytics (anonymised). Processes pseudonymised usage data. Privacy Policy: policies.google.com/privacy

Tawk.to (Tawk.to Inc.)

Live customer support chat. Processes chat content and basic device/session data. Privacy Policy: tawk.to/privacy-policy

Facebook / Meta Pixel (Meta Platforms, Inc.)

Advertising effectiveness measurement. Receives pseudonymised event data (page views, actions). Marketing cookies only — subject to consent. Privacy Policy: facebook.com/policy

Vade Enterprises (Turkey)

Authorised local payment representative for renewal payment collection from existing Turkish subscribers only. Does not process personal data as a data controller or processor.

 

All service providers with whom we share personal data are required to implement appropriate technical and organisational security measures and to process data only for the purposes specified in their agreement with us.

 

6. International Data Transfers

Fielse is a global service operated from the United Arab Emirates. Your personal information may be transferred to and processed in countries other than your country of residence, including the UAE, the United States, and countries within the European Economic Area (EEA), depending on where our service providers are located.

 

We ensure that all international transfers of personal data are conducted in accordance with applicable data protection laws, using one or more of the following safeguards:

 

       Adequacy Decisions: Where the European Commission has issued an adequacy decision for the destination country under GDPR Article 45.

       Standard Contractual Clauses (SCCs): We rely on the Standard Contractual Clauses adopted by the European Commission under GDPR Article 46(2)(c) for transfers to countries not covered by an adequacy decision.

       Turkish KVKK Transfers: For transfers of data belonging to Turkish residents, we rely on Standard Contractual Clauses issued by the Turkish Personal Data Protection Authority (KVKK) pursuant to Article 9(4)(c) of the KVKK, and/or explicit consent where required.

       UAE PDPL: Transfers of data processed under UAE PDPL are conducted in accordance with the data transfer requirements of UAE Federal Decree-Law No. 45 of 2021 and associated regulations.

       Supplementary Measures: Where required, we implement supplementary safeguards including encryption of data in transit and at rest, data minimisation, pseudonymisation, and ongoing Transfer Impact Assessments (TIAs).

 

You may request a copy of the applicable transfer safeguards by contacting us at [email protected].

 

7. Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, or reporting requirements. The following retention periods apply:

 

Category

Details

Account and profile data

For the duration of your active subscription, plus 3 years following account closure or cancellation, unless a longer period is required by law.

Payment and billing records

7 years from the date of the transaction, in accordance with applicable financial record-keeping obligations (UAE, Turkish, and EU requirements).

Usage and engagement data

Aggregated/pseudonymised after 24 months. Raw usage logs retained for up to 12 months for security and service improvement purposes.

Customer support communications

3 years from the date of the last interaction.

Security and fraud prevention logs

Up to 12 months, unless retention is required for an ongoing investigation or legal proceeding.

Marketing consent records

For the duration of your consent, plus 3 years following withdrawal, to demonstrate compliance.

Legal hold data

For the duration of the relevant legal proceeding or regulatory investigation, plus any applicable limitation period.

 

Where you request deletion of your account through the self-service option on the platform, we will delete or anonymise your personal data within 30 days, subject to any legal obligations requiring us to retain certain records. Anonymised or aggregated data derived from your information may be retained indefinitely as it can no longer be used to identify you.

 

8. Security Measures

We implement comprehensive technical and organisational security measures to protect your personal information against unauthorised access, disclosure, alteration, loss, or destruction. Our measures include:

 

8.1 Technical Measures

       Encryption: All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using industry-standard cryptographic methods.

       Content Protection: Educational video content is protected using dynamic tokenised HLS (HTTP Live Streaming) encryption and digital rights management (DRM) to prevent unauthorised extraction or redistribution.

       Firewall and DDoS Protection: Our infrastructure is protected by Cloudflare's enterprise-grade firewall, DDoS mitigation, and bot detection systems.

       Access Controls: Access to personal data is restricted to authorised personnel on a strict need-to-know basis. Role-based access controls and audit logging are implemented across all systems.

       Two-Factor Authentication: Administrative access to production systems requires multi-factor authentication.

       Vulnerability Management: We conduct regular penetration testing and vulnerability assessments. Identified issues are remediated on a risk-prioritised basis.

       Backups: Data is backed up regularly using secure, geographically distributed backup systems.

       Logging and Monitoring: All access to and processing of personal data is logged and monitored. Security events trigger automated alerts to our technical team.

8.2 Organisational Measures

       Data Protection Training: All personnel who handle personal data receive regular privacy and security training.

       Confidentiality Obligations: All employees and contractors with access to personal data are bound by confidentiality obligations.

       Vendor Due Diligence: Third-party service providers are assessed for security and data protection compliance before engagement and are required to maintain appropriate safeguards.

       Incident Response: We maintain a data breach response procedure. In the event of a personal data breach, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law (72 hours under GDPR; without undue delay under UAE PDPL and KVKK).

 

No method of transmission over the Internet or electronic storage is 100% secure. While we take rigorous measures to protect your data, we cannot guarantee absolute security. We encourage you to use a strong, unique password for your Fielse account and to keep your login credentials confidential.

 

9. Your Rights and How to Exercise Them

Regardless of your location, Fielse provides all users with the following data subject rights. Additional rights applicable to users in specific jurisdictions are set out in Sections 12, 13, and 14.

 

Category

Details

Right of Access

You may request a copy of the personal information we hold about you, along with information about how we process it.

Right to Rectification

You may request correction of inaccurate or incomplete personal information. You can update most account information directly via your Account page.

Right to Erasure (Right to be Forgotten)

You may request deletion of your personal information. You can initiate account deletion directly via the self-service option on the platform. We will process deletion requests within 30 days, subject to legal retention obligations.

Right to Restriction of Processing

You may request that we restrict processing of your data in certain circumstances (e.g., while a rectification request is pending).

Right to Data Portability

Where processing is based on your consent or on a contract, you may request your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON), or request direct transfer to another provider where technically feasible.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes at any time. We will cease direct marketing immediately upon receipt of an objection.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time via your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right not to be subject to automated decision-making

We do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects. If we introduce such features in the future, we will inform you and provide appropriate rights.

 

How to Exercise Your Rights

To exercise any of the above rights, you may:

       Use the self-service account management features available on the Fielse platform (for account deletion and preference updates).

       Submit a written request to [email protected]. Please include your full name, registered email address, and a clear description of the right you wish to exercise.

 

We will respond to all verifiable requests within 30 days. In complex cases, we may extend this period by a further 30 days, in which case we will notify you. We will not charge a fee for reasonable requests but reserve the right to charge a reasonable administrative fee for manifestly unfounded or excessive requests.

 

We may need to verify your identity before processing your request in order to protect the security of your personal information.

 

10. Cookies and Tracking Technologies

We use cookies, SDKs, and similar tracking technologies to operate and improve the Service. For detailed information about the specific cookies and tracking technologies we use, the purposes for which they are used, their duration, and how to manage your preferences, please refer to our separate Cookie Policy available on the Fielse platform.

 

In summary, we use the following categories of cookies:

       Essential Cookies: Required for the basic technical operation of the Service (e.g., session management, security, consent memory). These cannot be disabled without affecting Service functionality.

       Analytical Cookies: Used to understand how users interact with the platform (e.g., Google Analytics). These are set on a pseudonymised basis.

       Marketing Cookies: Used to measure the effectiveness of our marketing activities (e.g., Facebook/Meta Pixel). These are only set with your prior consent via our cookie consent mechanism.

 

You may withdraw or modify your cookie preferences at any time through the cookie settings available on our website.

 

11. Children and Minors

The Service is intended for users who are at least 18 years of age. In jurisdictions where the age of majority exceeds 18, the higher age applies. Fielse does not knowingly collect personal information from children under the age of 18.

 

If we become aware that we have inadvertently collected personal information from a person under 18 without appropriate parental or guardian consent, we will take immediate steps to delete that information from our systems. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us at [email protected].

 

Individuals under 18 may only access the Service with the express consent and under the active supervision of a parent or legal guardian, who by permitting such access agrees to these Terms and this Policy on the minor's behalf.

 

12. Supplement for EEA, UK and Switzerland (GDPR)

This section applies to you if you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland. It supplements the information set out in the rest of this Policy and should be read alongside it.

 

12.1 Legal Bases

The legal bases on which we process your personal data are set out in Section 3. Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests are not overridden by your fundamental rights and freedoms. You may request further information about our legitimate interest assessments by contacting us.

12.2 Your GDPR Rights

In addition to the rights set out in Section 9, under the GDPR you have the following rights:

       Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with the data protection supervisory authority in your country of residence. A list of EEA supervisory authorities is available at: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en

       UK: You may contact the Information Commissioner's Office (ICO) at https://ico.org.uk/

       Switzerland: You may contact the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch/

       Automated Decision-Making (Article 22 GDPR): We do not currently make solely automated decisions that produce legal or similarly significant effects. Should this change, we will update this Policy accordingly and provide the required rights.

12.3 Data Transfers from the EEA/UK/Switzerland

For transfers of EEA, UK, or Swiss personal data to countries not covered by an adequacy decision, we rely on the Standard Contractual Clauses adopted by the European Commission (Module 2 for controller-to-processor transfers) and, for UK transfers, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. Copies of applicable transfer mechanisms are available upon request.

12.4 Representative

Fielse does not currently have a designated EU/UK representative. If this changes, we will update this section accordingly. In the meantime, all enquiries from EEA, UK, or Swiss residents should be directed to [email protected].

 

13. Supplement for Turkey (KVKK)

This section applies to users located in Turkey and supplements this Policy in accordance with the Law on Personal Data Protection No. 6698 (Kişisel Verilerin Korunması Kanunu — "KVKK") and related secondary legislation.

 

13.1 Data Controller

The data controller (veri sorumlusu) for Turkish residents is Fielse Commerce - FZCO, IFZA Business Park, DDP, 001 - 80378, Dubai Silicon Oasis, United Arab Emirates. Vade Enterprises Bilişim Hizmetleri Tic. Ltd. Şti. is not a data controller or data processor in relation to your personal data and has no role in data processing activities.

13.2 Legal Bases under KVKK

We process your personal data on the following legal bases under KVKK Article 5(2):

       Explicitly provided for by law (Kanunda açıkça öngörülmesi).

       Directly related to the establishment or performance of a contract (Sözleşmenin kurulması veya ifasıyla doğrudan ilgili olması).

       Necessary for our legitimate interests, provided that your fundamental rights are not harmed (Meşru menfaatlerimiz için zorunlu olması).

       Compliance with a legal obligation (Hukuki yükümlülüğün yerine getirilmesi).

       Explicit consent (Açık rıza) — for marketing communications and, where applicable, for the transfer of your data abroad.

13.3 Your Rights under KVKK Article 11

You have the following rights under KVKK:

       To learn whether your personal data is processed.

       To request information about how your data is processed.

       To learn the purpose of processing and whether data is used in accordance with that purpose.

       To know the third parties to whom your data has been transferred, domestically or abroad.

       To request rectification if your data is incomplete or inaccurate.

       To request deletion or destruction of your data if the reasons for processing have ceased.

       To request notification to third parties of any rectification, deletion, or restriction.

       To object to results that arise against you from automated processing systems.

       To claim compensation for damages suffered due to unlawful processing.

       To withdraw explicit consent at any time.

 

To exercise these rights, please contact us at [email protected]. We will respond to your request within 30 days in accordance with KVKK Article 13.

13.4 Data Transfers Abroad (KVKK Article 9)

We transfer your personal data abroad in accordance with KVKK Article 9, relying on Standard Contractual Clauses issued by the Turkish Personal Data Protection Authority (KVKK Kurulu), or on your explicit consent where required. Transfers are made to countries that the KVKK Board has determined provide adequate protection, or to recipients that have provided adequate protection commitments approved by the KVKK Board.

13.5 Supervisory Authority

If you believe your rights under KVKK have been violated, you may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK Kurumu) at https://kvkk.gov.tr.

 

14. Supplement for California Residents (CCPA/CPRA)

This section applies to California residents and supplements this Policy in accordance with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

 

14.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

       Identifiers: Name, email address, IP address, device identifiers.

       Personal information under California Civil Code § 1798.80(e): Name, billing information (name and partial card details).

       Internet or other electronic network activity: Usage data, browsing history within the Service.

       Geolocation data: General location inferred from IP address (country/city level only).

       Inferences: Preferences and interests derived from usage data for personalisation of the learning experience.

14.2 Sale or Sharing of Personal Information

We do not sell your personal information for monetary consideration. However, our use of certain advertising and analytics tools (such as the Meta/Facebook Pixel) may constitute "sharing" of personal information under the CPRA for cross-context behavioural advertising. California residents may opt out of such sharing by adjusting their cookie preferences via our cookie consent tool or by contacting us at [email protected].

14.3 Your California Rights

       Right to Know: The right to know what personal information we collect, use, disclose, and share.

       Right to Delete: The right to request deletion of personal information we have collected, subject to certain exceptions.

       Right to Correct: The right to request correction of inaccurate personal information.

       Right to Opt Out of Sale/Sharing: The right to opt out of the sale or sharing of your personal information for cross-context behavioural advertising.

       Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.

       Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

 

To exercise your California privacy rights, please contact us at [email protected]. We will verify your identity before processing your request. Authorised agents may submit requests on your behalf with appropriate written authorisation.

 

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, technology, legal requirements, or other factors. The date of the most recent update is always displayed at the top of this document.

 

Where we make material changes — that is, changes that significantly affect your rights or the way we handle your personal data — we will notify you at least 30 days before the changes take effect by:

       Sending a notification to the email address associated with your account, and/or

       Displaying a prominent notice on the Fielse platform when you next log in.

 

Your continued use of the Service after the effective date of the revised Policy constitutes your acknowledgment of the changes. Where applicable law requires a different form of acceptance (e.g., explicit consent for certain changes), we will obtain that consent before the changes take effect.

 

16. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:

 

Fielse Commerce - FZCO

IFZA Business Park, DDP, 001 - 80378, Dubai Silicon Oasis, United Arab Emirates

TRN: 105395213900001

Privacy / Data Protection Officer: [email protected]

General Support: [email protected]

Help Centre: https://fielse.com/help

 

We are committed to working with you to resolve any concerns about your privacy. If you feel that your concern has not been adequately addressed, you have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence, as described in Sections 12, 13, and 14 above.

© Fielse Commerce - FZCO. All rights reserved.