Privacy Policy
Last updated: 26/8/2025
1. Introduction and Data Controller
Welcome to TMPI MERAKI LTD’s online training services. Your privacy is of utmost importance to us. This Privacy Policy aims to inform you clearly, transparently, and in detail about how we collect, use, protect, and process your personal data when you use our website https://cursos.tmpi-pimt.com/ and associated services (hereinafter, the “Services”).
The Data Controller of your personal data, within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws, is:
- Full Legal Name: TMPI MERAKI LTD
- Registered Address: Efesou 9, Paralimni 5280, Famagusta, Cyprus.
- Email for Privacy Matters: info@tmpi-pimt.com
This policy has been drafted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).1 Clearly identifying the responsible party is the first fundamental step to ensure transparency and accountability, allowing you, the user, to know who is in charge of your data and how you can communicate to exercise your rights.2 Designating a specific email address for privacy matters centralizes inquiries and demonstrates organized data protection management, a key aspect of the “privacy by design” principle.3
2. Principles of Processing and Data We Collect
The processing of your personal data is governed by the following fundamental principles established in GDPR 5:
- Lawfulness, fairness and transparency: We will treat your data lawfully, fairly and transparently.
- Purpose limitation: We will collect your data for specific, explicit, and legitimate purposes.
- Data minimization: We will only collect data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
- Accuracy: We will keep your data accurate and up-to-date.
- Limitation of the retention period: We will retain your data only for as long as necessary for the purposes of the processing.
- Integrity and confidentiality: We will guarantee the security of your personal data through appropriate technical and organizational measures.
We collect different categories of personal data to provide you with our Services effectively. The distinction between data you provide “directly” and data collected “automatically” is crucial for complete transparency, as it allows you to fully understand what information you consciously share and what data is generated through your interaction with the platform. 6
2.1 Data provided directly by the User
- Identity and Contact Information: When creating an account, you provide us with your first name, last name, and email address.
- Credentials Information: Your password to access your account. This information is stored securely and encrypted.
- Financial and Transaction Data: To process your purchases, we collect billing information and your location for tax calculation. It is important to note that we do not store your complete credit or debit card information. This is managed directly by our payment processing partners, who adhere to the highest security standards (PCI DSS). This decision to outsource payment data storage is a direct application of the data minimization principle, drastically reducing the company’s risk profile in the event of a security breach. 3
- User-Generated Content: Any information that you submit or post in interactive areas of our Services, such as comments, course reviews, questions, or projects.
- Communication Data: Information you provide to us when you contact our support team, including the content of your queries.
2.2 Automatically Collected Data
- Usage and Technical Data: When you access and use our Services, we automatically collect certain information. This includes your IP address, device and browser type, operating system, unique device identifiers, pages visited, and information about your interaction with our Services, such as the courses you view, your progress, time spent on lessons, and the features you use. The collection of this data is standard in the e-learning industry and allows us to justify our legitimate interest in analyzing and improving the functionality and user experience of our platform.
3. Purpose and Legal Basis of the Processing
The GDPR requires that all processing of personal data be based on a valid legal justification. Below is a table detailing each purpose for which we process your data, the types of data involved, and the legal basis that legitimizes our processing. This table format aims to provide maximum clarity and transparency, in line with the recommendations of data protection authorities. 2
Purpose of Treatment | Types of Data Processed | Legal Base (RGPD Art. 6.1) |
Creation and management of your user account to access the Services. | Identity, contact and credentials data. | (b) Performance of a contract: Necessary to comply with the Terms and Conditions that you accept. |
Providing access to purchased courses and monitoring academic progress. | Identity data and usage data. | (b) Execution of a contract: Necessary to provide the contracted educational service. |
Payment processing, transaction management, and fraud prevention. | Identity, contact and financial data. | (b) Contract execution: Necessary to complete the purchase of a course. |
Calculation and remittance of indirect taxes (VAT/GST) to the relevant tax authorities. | Billing and location information. | (c) Compliance with a legal obligation: Necessary to comply with international tax regulations. |
Sending transactional and service communications (purchase confirmations, notifications about your account, etc.). | Contact details. | (b) Execution of a contract: Necessary for the proper administration of the service. |
Sending marketing communications, newsletters and promotions about our courses. | Contact information and interests. | (a) Consent: It will only be done if you have given us your explicit consent to do so. |
Moderation and use of User-Generated Content to promote our Services (e.g., testimonials). | User-Generated Content. | (f) Legitimate interest: Our interest in promoting our services and maintaining an active and safe community. |
Data analysis to improve our services, understand user needs, and optimize our course offerings. | Usage data and technical data (aggregated and anonymized whenever possible). | (f) Legitimate interest: Our interest in developing and improving our business and the quality of our services. |
Attend to their support requests, resolve doubts and manage incidents. | Identity data, contact information and content of the communication. | (b) Performance of a contract or (f) Legitimate interest: Depending on the nature of the inquiry. |
4. Exchange and Disclosure of Data
We do not sell or rent your personal data to third parties. However, in order to operate our Services, we may share your information with the following categories of recipients: 9:
- Payment Processors: We share the necessary information with trusted payment processing companies to securely manage your transactions.
- Third-Party Service Providers: We work with providers who offer essential services, such as web hosting, data analytics (e.g., Google Analytics), email marketing services, and customer support tools. These providers only have access to the data necessary to perform their functions and are contractually obligated to protect it and not use it for any other purpose.
- Legal Authorities and Regulatory Compliance: We may disclose your information if required by law, a court order, or to respond to a valid legal request from public authorities.
- Public Content: You should be aware that any User-Generated Content you post in public areas of the platform (such as forums or comment sections) will be visible to other users. This action constitutes a voluntary disclosure of your own data. The processing of data that a user has made “manifestly public” has a specific legal basis under the GDPR (Art. 9.2.e), which mitigates our responsibility for the privacy of that information.
5. International Data Transfers
TMPI MERAKI LTD is headquartered in Cyprus, within the European Union. However, some of our service providers may be located outside the European Economic Area (EEA). When we transfer your personal data outside the EEA, we ensure that appropriate safeguards are in place to guarantee a level of data protection equivalent to that required by the GDPR.
These transfers are based on legally recognized mechanisms, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or on adequacy decisions by the European Commission that recognize that a third country offers an adequate level of data protection. This specification of the legal mechanism is a statement of due diligence, demonstrating that we are aware of the current complex legal landscape and that we have taken active steps to protect the data of our European users when they are processed abroad.
6. Data Retention
We will retain your personal data only for as long as strictly necessary to fulfill the purposes for which it was collected, as well as to comply with our legal obligations, resolve disputes, and enforce our agreements. The criteria used to determine retention periods are as follows:
- Account Details: We will retain the data associated with your account for as long as it remains active. If you decide to close your account, your data will be deleted or anonymized, except for data that we are required to retain for an additional period to comply with legal obligations (for example, billing information for tax purposes). 7
- Transaction Data: Information related to your purchases will be kept for the period required by applicable tax and accounting legislation in our jurisdiction (generally between 6 and 10 years).
- Marketing Consent Data: If you have consented to receive marketing communications, we will retain your data for this purpose until you withdraw your consent.
7. Your Data Protection Rights (GDPR)
As an EEA resident, the GDPR grants you a number of rights regarding your personal data. We are committed to making it easy for you to exercise these rights. They are listed and explained below. 2:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right of Rectification: You have the right to request the correction of any personal data that is inaccurate or incomplete.
- Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion of your personal data in certain circumstances (for example, if they are no longer necessary for the purpose for which they were collected).
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain situations.
- Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another data controller.
- Right of Opposition: You have the right to object to the processing of your personal data when it is based on our legitimate interest, including profiling. You also have the absolute right to object to processing for direct marketing purposes.
- Right not to be subject to Automated Individual Decisions: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Right to Withdraw Consent: When the processing of your data is based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of the processing based on the consent prior to its withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
To exercise any of these rights, you can contact us via the email address: info@tmpi-pimt.com.
8. Children’s Privacy
Our Services are intended for professionals and are not for use by individuals under the age of 18 to independently create an account. We strictly comply with regulations regarding children’s privacy, such as the Children’s Online Privacy Protection Act (COPPA) in the United States and the GDPR age requirements in the European Union. 7
If a minor below the age of digital consent in their country (e.g., 16 years in most EU countries) wishes to use our Services, a parent or legal guardian must create and manage the account on their behalf, acting as the account holder and responsible party. This mechanism is a practical and legally defensible solution that allows minors access to education while maintaining legal responsibility with the adult. If we become aware that we have collected personal data from a minor without verifiable parental consent, we will take the necessary steps to remove that information from our systems as soon as possible. 12
9. Data Security
We take the security of your information very seriously. We have implemented and maintain appropriate technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include, among others, data encryption, access controls and internal security policies.
You are also responsible for maintaining the confidentiality and security of your password and account. We urge you not to share your login credentials with any third party. 7
10. Cookies and Tracking Technologies Policy
Our website uses cookies and other similar tracking technologies to improve your user experience, analyze our site’s performance, and for marketing purposes. A cookie is a small text file that is stored on your device.
We use essential cookies (necessary for the site to function), performance cookies (for analytics), and marketing cookies (to personalize advertising). For detailed information about the cookies we use, their purposes, and how you can manage your consent preferences, please see our Cookies Policy.
11. Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you through a notice on our website or by email before the change takes effect. We encourage you to check this page periodically for updates. The “Last Updated” date at the top of this page will indicate when the last revisions were made. 10

