Privacy Notice
Last updated: May 2026
1. Who we are
Ross & Associates Tax Office ("Ross & Associates", "we", "us") operates the Ross & Associates Tax Academy. We act as the data controller for personal data collected through the Academy.
2. Data we collect
- Account data: name, email, password (hashed), avatar.
- Lead data: name, email, phone (when you submit a form).
- Learning data: course enrollments, lesson progress, certificates earned.
- Support messages: any messages you send us.
- Technical data: IP address, device, browser, usage events for security and product improvement.
Payment data (card details, billing address) is collected and processed by our payment provider Paddle. We do not store card numbers.
3. How we use your data
- To create and manage your account (legal basis: contract).
- To deliver courses, track progress, and issue certificates (contract).
- To respond to support requests (contract / legitimate interests).
- To detect and prevent fraud and abuse (legitimate interests).
- To send transactional and marketing emails (consent for marketing — you can opt out anytime).
- To meet legal obligations (legal obligation).
4. Who we share data with
- Paddle — our Merchant of Record, for sale of memberships, subscription management, payments, tax compliance, and invoicing.
- Service providers — hosting, database, email delivery, analytics. They process data on our behalf under written agreements.
- Professional advisers — legal, accounting, where necessary.
- Authorities — when required by law.
We do not sell your personal data.
5. Data retention
We keep your account data while your account is active and for a reasonable period after to comply with legal obligations and resolve disputes. You can request deletion at any time (see Your Rights).
6. Security
We use appropriate technical and organisational measures including encryption in transit and at rest, access controls, and regular security reviews.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent at any time. To exercise these rights, contact us via the contact page. You also have the right to lodge a complaint with your local data protection authority.
8. Cookies
We use essential cookies required to operate the Service (authentication, session). We may also use analytics cookies to understand usage. You can manage cookies through your browser settings.
9. International transfers
Some of our service providers are located outside your country. Where required, we put appropriate safeguards in place (such as Standard Contractual Clauses).
10. Contact
Questions about this notice? Visit our contact page.
