Privacy policy
Last updated: 15 September 2026
This policy explains what personal data Tokkoacad collects, why, who else handles it, how long it is kept and what rights you have. It applies to www.tokkoacad.com, the lesson area and the emails linked to your purchase.
1. Who is responsible
The controller of your personal data is the seller:
- Name
- Everson Claudio Bispo dos Santos Junior
- Legal form
- Sole trader (individual, not a company)
- NIF
- 312607555
- Address
- Rua Adriano Correia de Oliveira, n.º 69, 8, 2810-149 Almada, Portugal
- Privacy contact
- privacy@tokkoacad.com
We apply the General Data Protection Regulation (EU) 2016/679 (GDPR) and Law 58/2019, which implements it in Portugal.
We have not appointed a data protection officer. Article 37 of the GDPR only requires one for public bodies and for organisations whose core activity is large-scale, regular monitoring of people or large-scale processing of sensitive data. A small online course does neither. Every privacy question goes to privacy@tokkoacad.com.
2. What data we collect
- When you buy: Stripe collects the payment details. From Stripe we receive your name, email, billing country, the plan, the amount, the date, the payment status and limited card details (card type and last four digits), plus the tax number if you enter one. We never see your full card number or security code.
- For invoices: your name, tax number if given, and country, as recorded on the invoice issued through the Portal das Finanças or certified software.
- When you use the course: your access token, a signed proof of purchase stored in your browser under tk.access and checked by our server.
- When you contact us: what you send through the contact form or by email (name, email, message, attachments), including links and content sent for Max reviews.
- When you visit: server logs kept by our hosting provider (IP address, browser, page requested, time), used to deliver pages, stop abuse and fix errors.
- Your cookie choices: stored in your browser under tk.consent. See the cookie policy.
3. Why we use it and the legal basis
- Selling and delivering the course (payment, access link, access checks, Max reviews, community invite): performance of the contract, article 6(1)(b) GDPR.
- Invoices and tax records: legal obligation, article 6(1)(c).
- Answering messages: performance of the contract when it concerns a purchase; otherwise our legitimate interest in replying, article 6(1)(f).
- Security, fraud prevention and detecting shared access links: legitimate interest.
- Refunds, complaints, chargebacks and legal claims: legal obligation and legitimate interest in defending our rights.
- Analytics or advertising tools, if ever added: your consent only.
We only send emails about your purchase and your requests, never newsletters without consent. We do not sell your data, and we make no decisions about you based solely on automated processing, including profiling.
4. Who else handles your data
- Vercel Inc. (United States): hosts the site and the server that checks access. Processor. Privacy policy.
- Stripe Payments Europe, Limited (Ireland): processes payments and sends receipts. It acts as an independent controller for fraud prevention, anti-money laundering checks and its own legal duties. Privacy policy.
- Resend (Plus Five Five, Inc., United States): sends transactional emails such as the access link. Processor. Privacy policy.
- Community platform (Max plan only): named in the invite email before you join. You join with your own account and it handles your data under its own policy. Joining is optional.
Processors act only on our instructions under data processing agreements (article 28 GDPR). We may also share data with authorities when the law requires it, such as the Tax Authority, and with an accountant or lawyer we work with, who is bound by professional secrecy.
5. International transfers
Vercel and Resend are in the United States, and Stripe may process data there. Transfers rely on the EU-US Data Privacy Framework, when the recipient is certified under it, or on the European Commission's standard contractual clauses. Ask privacy@tokkoacad.com for a copy of the relevant safeguards.
6. How long we keep it
- Invoices and billing records: 10 years, as Portuguese tax law requires (article 52 of the Código do IVA and the Personal Income Tax Code, CIRS), even after a refund.
- Support emails and contact form messages, including review requests and material: 3 years from the last message, then deleted. You can ask for earlier deletion when no legal duty applies.
- Access token and cookie choices: in your browser until you clear them. We can cancel a token on our side, for example after a refund.
- Server logs: the short period set by the hosting provider, then deleted automatically.
7. Your rights
You can ask for access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interest. Where we rely on consent, you can withdraw it at any time. Write to privacy@tokkoacad.com. It is free, and we answer within one month; for complex requests this can be extended by two months, and we will tell you why. We may ask you to confirm your identity, usually with an email from the purchase address.
You can complain to the Portuguese supervisory authority, the CNPD, Comissão Nacional de Proteção de Dados, or to the data protection authority of the EU country where you live or work.
8. Security and minors
The site uses encrypted connections (HTTPS), access tokens are signed so they cannot be forged, and only the seller can see buyer data. Keep your access link private. The course is sold only to adults aged 18 or over, and we do not knowingly collect data from minors. If you think a minor has sent us data, write to privacy@tokkoacad.com and we will delete it.
9. Changes
We update this policy when our services, providers or the law change. The date at the top shows the last update. For significant changes, such as a new provider using your data for a new purpose, we tell buyers by email before they apply and ask for consent where required.