This document sets forth the global privacy principles governing all websites, learning management systems, web platforms, and mobile applications operated by Premier Academy. Whether you are accessing our courses from the European Union, United States, United Kingdom, Pakistan, or globally, we adhere strictly to transparent data collection, robust encryption, non-surveillance principles, and explicit user control over personal data.
Data Controller Identification & Scope
For the purposes of applicable data protection laws, including the European Union General Data Protection Regulation (EU GDPR 2016/679), the UK Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA), the designated Data Controller responsible for your personal data is:
Founder & Executive Instructor: Raja Gulfam
Response Guarantee: Within 30 Calendar Days
This policy applies to all registered students, course attendees, website visitors, mobile application users, and prospective applicants seeking professional accreditation through Premier Academy.
Categories of Personal Data We Process
We collect personal data directly provided by you, as well as data generated automatically during your interaction with our learning infrastructure:
Full name, email address, phone number, national tax identification/CNIC (where required for certified tax compliance reporting), profile photo, user account password hashes (salted Argon2/bcrypt).
Course enrollments, quiz submission scores, video watch progress, live Zoom seminar attendance records, assignment attachments, and digital certificate verification tokens.
Payment card metadata, billing address, transaction IDs, payment status. Note: Full payment card details are processed directly by PCI-DSS Level 1 certified payment gateways (Stripe/Bank Gateways) and are NEVER stored on Premier Academy servers.
Dynamic video overlay session metadata including user email, active session timestamp, IP address, and playback token used exclusively to prevent unauthorized copying of proprietary tax materials.
IP address, browser type and version, operating system, system language, geographic country code, referring URLs, device identifiers, and server diagnostic access logs.
Lawful Bases for Processing (GDPR Article 6)
We only collect and process personal data when we have an explicit lawful basis under International Privacy Law:
Processing necessary to deliver enrolled course modules, issue certificates, process course payments, and provide student support.
Preventing fraud, safeguarding intellectual property, watermarking proprietary lecture content, and optimizing platform performance.
Fulfilling corporate tax audits, financial recordkeeping obligations, and responding to lawful subpoenas or court orders.
Sending promotional updates, newsletters, or third-party partner offers. Consent may be revoked at any time via settings.
Forensic Screen Protection & Anti-Piracy Watermarking
To protect the proprietary tax models, financial frameworks, and confidential curriculum created by Raja Gulfam, Premier Academy embeds a dynamic, semi-transparent forensic watermark during video stream rendering.
The watermark displays the logged-in student's email address and current IP address across random coordinates on the video player. This telemetry:
- Is used strictly for deterrence against screen recording and illegal redistribution.
- Is dynamically generated in-memory and is never sold or shared with external advertisers.
- Operates under Premier Academy's legitimate interest (GDPR Art. 6(1)(f)) to protect intellectual property against illegal piracy.
Third-Party Sub-Processors & Data Sharing
We engage trusted third-party service providers (sub-processors) to perform operational infrastructure functions. All sub-processors are bound by strict Data Processing Agreements (DPAs) incorporating standard contractual clauses:
| Sub-Processor | Role / Function | Data Center Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Server Hosting & Encrypted Database Storage | US / EU Regions | EU-US DPF / SCCs |
| Cloudflare Inc. | CDN, DDoS Mitigation & Web Security Firewall | Global Edge Network | ISO 27001 / SCCs |
| Stripe & Local Gateways | PCI-DSS Payment Processing & Invoicing | US / Global | PCI Level 1 / SCCs |
| Zoom Video Communications | Live Masterclass Webinar Broadcasting | Global Network | SOC 2 Type II / SCCs |
| Postmark / SendGrid | Transactional Email & Admission Notifications | US East | TLS 1.3 / SCCs |
International Cross-Border Data Transfers
As a global tax and accounting academy serving students worldwide, personal data may be accessed or transferred across international borders. Whenever cross-border transfers occur, we implement European Commission-approved Standard Contractual Clauses (SCCs) alongside technical measures (end-to-end TLS encryption and AES-256 data at rest) to guarantee equivalent data protection.
Data Retention & Automated Purge Schedules
Personal data is retained only for the duration necessary to fulfill the purposes outlined in this policy or to comply with statutory legal requirements:
Maintained to enable course re-access and certification verification.
Invoices, payment receipts, and tax reporting logs.
Server access logs and security diagnostic telemetry.
Your Data Subject Rights (GDPR & CCPA Framework)
Under European Union GDPR, UK GDPR, and California CCPA/CPRA, you are entitled to execute the following enforceable privacy rights without fee or penalty:
Protection of Minors (COPPA Compliance)
Premier Academy provides professional accounting, tax strategy, and audit training designed for adults. We do not knowingly collect personal data from individuals under 16 years of age. If we learn that a user under 16 has submitted personal data without verified parental consent, we will purge the account immediately.
Security Protocols & Breach Notification
We employ industry-leading administrative, technical, and physical safeguards including AES-256 database encryption at rest, TLS 1.3 encrypted network transit, strict role-based authorization, and automated vulnerability scanning. In the unlikely event of a security breach affecting your personal data, we guarantee notification to affected users and supervisory authorities within 72 hours as mandated by GDPR Article 33.
DPO Office Contact & Regulatory Recourse
If you have questions, concerns, or unresolved grievances regarding our processing of your personal data, please contact our Data Protection Officer directly:
If you are residing in the European Economic Area (EEA) or UK and feel your privacy grievance has not been satisfactorily addressed, you retain the statutory right to lodge a formal complaint with your local Data Protection Authority (e.g., the UK Information Commissioner's Office - ICO or EU EDPB Member State Authorities).