Privacy Policy
Effective date: July 22, 2026
GMFT Services Ltd, having its address at Syrakouson 9, Office 106, 3077, Limassol, Cyprus (“us”, “we”, “our” or the “Company”), operates the website www.gmfteducation.com (the “Website”). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Website and the choices you have associated with that data. We use your data to provide and improve the Website.
By using the Website, you agree to the collection and use of information in accordance with this Policy. Unless otherwise defined in this Privacy Policy, the terms used here have the same meanings as in our Terms and Conditions. The Company respects the privacy of its online visitors and customers and complies with applicable laws for the protection of your privacy, including, without limitation, the European Union General Data Protection Regulation (“GDPR”).
1. Information collection and use
We collect several different types of information for various purposes to provide and improve our Website to you.
2. Types of data collected
Personal Data
While using our Website, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Cookies and Usage Data
- Transaction and Payment Data
Usage Data
When you access the Website with a mobile device, we may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data (“Usage Data”).
3. Use of data
The Company uses the collected data for various purposes:
- To provide and maintain the Website
- To notify you about changes to our Website
- To allow you to participate in interactive features of our Website when you choose to do so
- To provide customer care and support
- To provide analysis or valuable information so that we can improve the Website
- To monitor the usage of the Website
- To detect, prevent and address technical issues
4. Tracking & cookies data
We use cookies and similar tracking technologies to track the activity on our Website and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Website. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.
Non-essential cookies (including Preference and any analytics or marketing cookies) are only set with your prior, opt-in consent, obtained via our cookie consent banner. You may withdraw or change your consent at any time by contacting us at [email protected]. Essential/Session and Security Cookies do not require consent as they are strictly necessary for the Website to function.
5. Legal bases for processing under GDPR
If you are from the European Economic Area (EEA), our legal basis for collecting and using your Personal Data depends on the data concerned and the context:
- Performance of a contract: processing is necessary to fulfil our contract with you (e.g., providing access to purchased books/courses and handling billing).
- Legitimate interests: processing is necessary for our legitimate business interests (e.g., preventing fraud, securing our platform, and analyzing usage to improve services).
- Legal obligation: processing is required to comply with applicable laws (e.g., retaining transaction records for tax compliance).
- Consent: where you have given us explicit consent (e.g., subscribing to marketing newsletters or accepting non-essential cookies).
6. Transaction and payment data
In order to make a transaction on the Website (e.g. to purchase content and services), you may need to provide payment data to the Company to enable the transaction. If you pay by credit card, you need to provide typical credit card information (name, address, credit card number, expiration date, and security code) to the Company, which the Company will process and transmit to the payment service provider of your choice to enable the transaction and perform anti-fraud checks. Likewise, the Company will receive data from your payment service provider for the same reasons.
7. Information required to detect violations
We collect certain data that is required for our detection, investigation, and prevention of fraud, cheating, and other violations and applicable laws (“Violations”). This data is used only for the purposes of detection, investigation, prevention, and, where applicable, acting on such Violations, and stored only for the minimum amount of time needed for this purpose. If the data indicates that a Violation has occurred, we will further store the data for the establishment, exercise or defense of legal claims during the applicable statute of limitations or until a legal case related to it has been resolved. Please note that the specific data stored for this purpose may not be disclosed to you if the disclosure will compromise the mechanism through which we detect, investigate, and prevent such Violations.
8. Transfer and sharing of data
We do not sell your Personal Data. We may share your Personal Data with trusted third-party Service Providers (such as payment processors, hosting providers, and customer support tools) solely to operate our Website and deliver our services. These third parties are bound by Data Processing Agreements (DPAs) to process your data securely and strictly according to our instructions.
We will only share your data with third parties for their own marketing purposes if you have given us your explicit, opt-in consent to do so.
Some of our Service Providers may be located outside the European Economic Area (“EEA”). Where we transfer your Personal Data outside the EEA, we ensure an adequate level of protection through one or more of the following safeguards:
- Transfer to a country recognized by the European Commission as providing an adequate level of data protection;
- Standard Contractual Clauses approved by the European Commission;
- Other legally recognized transfer mechanisms.
9. Data retention
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, retaining accounting and transaction records for up to 7 years), resolve disputes, and enforce our legal agreements.
10. Disclosure of data & legal requirements
The Company may disclose your Personal Data in the good faith belief that such action is necessary to:
- comply with a legal obligation;
- protect and defend the rights or property of the Company;
- prevent or investigate possible wrongdoing in connection with the Website;
- protect the personal safety of users of the Website or the public;
- protect against legal liability.
11. Security of data
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
12. Service providers
We may employ third-party companies and individuals to facilitate our Website (“Service Providers”), to provide the services on our behalf, to perform Website-related services, or to assist us in analyzing how our Website is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
13. Links to other sites
Our Website may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
14. Your rights and control mechanisms
The data protection laws of the European Economic Area and other territories grant their citizens certain rights in relation to their Personal Data. While other jurisdictions may provide fewer statutory rights, we make the tools designed to exercise such rights available to our customers worldwide. As a resident of the European Economic Area you have the following rights in relation to your Personal Data:
- Right of access. You have the right to access the Personal Data we hold about you, i.e. the right to require free of charge (i) information on whether your Personal Data is retained, (ii) access to and/or (iii) duplicates of the Personal Data retained. You can exercise this right by contacting us at [email protected]. If the request affects the rights and freedoms of others or is manifestly unfounded or excessive, we reserve the right to charge a reasonable fee or refuse to act on the request.
- Right to rectification. If your Personal Data is inaccurate or incomplete, you can change the information you provided by contacting us at [email protected].
- Right to erasure. You have the right to obtain the deletion of Personal Data concerning you if the reason for which we collected it no longer exists, or if there is another legal ground for its deletion. To request deletion of individual items or your entire account, please contact us via the Company email. As a result, you will lose access to the Company’s services.
- Right to object. Where our processing is based on legitimate interests under Article 6(1)(f) GDPR (Section 5 of this Policy), you have the right to object. If you object, we will no longer process your Personal Data unless there are compelling and prevailing legitimate grounds, as described in Article 21 GDPR; in particular, if the data is necessary for the establishment, exercise or defense of legal claims. You also have the right to lodge a complaint with a supervisory authority.
- Right to restriction of processing. You have the right to obtain restriction of processing of your Personal Data under the conditions set out in Article 18 GDPR.
- Right to data portability. You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller under the conditions set out in Article 20 GDPR.
- Right to withdraw consent. Where our processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. You may withdraw consent by contacting us at [email protected].
15. Children’s privacy
Our Website does not address anyone under the age of 18 (“Children”). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children have provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
16. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Commissioner for Personal Data Protection without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.
17. Changes to this Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. We will let you know via email and/or a prominent notice on our Website prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact us
If you have any questions about this Privacy Policy, please contact us: