Privacy Policy
Last Updated: November 11, 2025
This Privacy Policy (“Policy”) sets out the terms under which Ayham Shakra, owner of GMATBuddy (“we,” “our,” “us”), processes personal data of users (“you,” “your”) of the website https://gmatbuddy.com (“Website”) in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Data Controller
- Name: Ayham Shakra
- Address: Barcelona, Spain (Postal Code 08010)
- Email: ayham@gmatbuddy.com
- Website: https://gmatbuddy.com
2. Categories of Personal Data
The following categories of personal data may be collected and processed:
- Identification data (first name, last name)
- Contact data (email address)
- Account data (username, password)
- Financial and transactional data (processed through SureCart, Stripe, and PayPal)
- Academic or course activity data (via LearnDash LMS and associated plugins)
- Communication preferences and correspondence (via FluentCRM and Fluent Forms)
- Usage and technical data (cookies, IP address, browser type, analytics)
3. Purpose and Legal Basis for Processing
Your personal data is processed for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Account registration, course access, and coaching services | Performance of a contract |
| Payment processing | Performance of a contract |
| Customer support and communications | Legitimate interest / Contract performance |
| Marketing communications (newsletter, updates) | Consent |
| Website analytics and improvements | Legitimate interest |
| Compliance with legal and tax obligations | Legal obligation |
Where processing is based on consent, you may withdraw such consent at any time without affecting the lawfulness of prior processing.
4. Data Retention
Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, and to comply with applicable legal, accounting, or reporting obligations.
After this period, data will be securely deleted or anonymized.
5. Data Sharing and International Transfers
Personal data may be shared with third-party service providers acting as data processors, including but not limited to:
- SureCart, Stripe, PayPal: payment processing
- LearnDash LMS and related extensions: course and quiz management
- FluentCRM, Fluent Forms, FluentSMTP: customer communication management
- Google Analytics: web analytics
- Akismet Anti-Spam, Uncanny Automator, Presto Player, WPSocial Ninja: site operation and integrations
Certain providers (e.g., Google, Stripe, PayPal) may transfer data outside the European Economic Area (EEA). In such cases, adequate safeguards (e.g., Standard Contractual Clauses approved by the European Commission) are implemented.
6. Security Measures
Appropriate technical and organizational measures are applied to ensure a level of security appropriate to the risk, including encryption, access control, and secure data storage.
Despite these measures, absolute security of information transmitted via the internet cannot be guaranteed.
7. Rights of Data Subjects
Pursuant to GDPR and LOPDGDD, users have the following rights:
- Access: obtain confirmation whether data concerning them is being processed.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of data when it is no longer necessary.
- Restriction: request limitation of processing in certain cases.
- Portability: receive data in a structured, commonly used format.
- Objection: object to processing based on legitimate interests or direct marketing.
Requests to exercise these rights should be directed to ayham@gmatbuddy.com.
If you believe your rights have been infringed, you may lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at https://www.aepd.es.
8. Cookies and Tracking Technologies
This Website uses cookies and similar technologies to ensure proper functioning, analyze usage, and personalize user experience.
Types of cookies:
- Essential cookies: required for navigation and access to secure areas.
- Analytics cookies: measure traffic and usage patterns (Google Analytics).
- Preference cookies: store user settings.
- Marketing cookies: enable personalized advertising.
Users may configure or disable cookies at any time through their browser settings or the on-site Cookie Notice and Compliance (GDPR/CCPA) tool.
For more information, consult the Cookie section on the Website.
9. Minors
Our services are not directed to individuals under 18 years of age. If we become aware that data has been collected from a minor without parental consent, such data will be deleted promptly.
10. Updates to the Policy
We reserve the right to amend this Policy at any time. Substantial modifications will be notified by publication on the Website or via email.
The effective date will correspond to the “Last Updated” date indicated above.
11. Contact
For any inquiries or to exercise your data protection rights, please contact:
Email: ayham@gmatbuddy.com
Address: Barcelona, Spain (Postal Code 08010)