1. Who We Are

    Megabit d.o.o., Hrvojeva 11, 21204 Dugopolje, Croatia, trading as Blazorise ("Blazorise", "we", "us"), is the controller of the personal data described in this policy. This policy applies where we decide why and how personal data is processed. It does not cover data that a customer independently processes in an application built with Blazorise.

  2. Personal Data We Collect

    The data we collect depends on how you interact with us. It may include:

    • Contact data: normally your email address and, where provided or available, your first and last name. You may also provide a company name, job title, phone number, or postal address.

    • Account and license data: username, authentication information, license key, product token, subscription, entitlements, educational license status, linked account information, and related account activity.

    • Educational eligibility data: your university-issued email address, university or educational institution, student or teacher status, academic affiliation and relevant dates, verification status, an ISIC or ITIC card number that you provide, GitHub account or Student Developer Pack redemption information, and supporting documents that we request or you submit, such as a student or teacher identification card or proof of current enrollment or employment.

    • Learning data: courses you enroll in, lesson and module progress, exercise submissions and associated code or files, assessment responses, attempts and results, feedback, completion status, and related timestamps linked to your Account.

    • Classroom administration data: institution and administrator contact details, institutional applications, invitations and invitee email addresses, classroom membership, assigned seats and entitlements, assignment and removal dates, and related administrative and security activity. Where necessary for a minor's participation, this may include confirmation of required institutional or parent or guardian authorization.

    • Expert-services data: project requirements, quotes and booking details, support or development communications, source code, logs, sample data, and other materials you provide for an engagement. During live meetings, this may include your participant name, audio or video you enable, messages, screen-shared content, and connection information.

    • Purchase data: product, order, invoice, payment status, billing contact, and tax information received from Paddle, Azure Marketplace, or provided for an invoiced purchase. We do not store your full payment card details.

    • Communications: messages, support requests, form responses, meeting details, feedback, and any files or information you choose to send us.

    • Technical and usage data: IP address, browser and device information, requested pages, timestamps, referring page, diagnostics, security events, and cookie or similar identifiers.

    • Marketing activity: subscription preferences and email delivery, open, click, reply, bounce, and unsubscribe information.

    Please do not send us sensitive personal data unless it is necessary and we have specifically requested it.

  3. How We Collect Data
    • Directly from you: when you create an Account, make a purchase, apply for or renew an Educational License or Classroom License, enroll in a course, submit an exercise or assessment, administer classroom access, subscribe, submit a form, request support, book a meeting or expert service, or otherwise communicate with us.

    • Educational eligibility information: you may provide a university-issued email address, an ISIC or ITIC card number, or supporting documents. Blazorise stores ISIC and ITIC card numbers directly and does not submit them to the ISIC Association or use an ISIC or ITIC verification service. We may verify a university email domain and receive eligibility or verification results from an educational institution, GitHub through the GitHub Student Developer Pack, or another verification provider identified to you.

    • From your institution: an authorized administrator may provide your email address and classroom or seat information to invite you and manage your institution-provided access, including before you create an Account. Once you participate, we link the relevant membership and entitlement to your Account.

    • From resellers and service providers: we receive limited account, purchase, transaction, communication, delivery, and verification information needed to provide and administer the Services.

    • Automatically: we collect technical and usage data when you use our websites and online services, including through cookies and similar technologies as described below.

    • From public and professional sources: for business communications, we may obtain professional contact data from publicly accessible business sources or service providers where permitted by law.

  4. Why We Use Personal Data
    • To provide the Services and perform our contract: create and administer accounts, issue and validate licenses, deliver products, provide support, and communicate about your purchase or account.

    • To operate and improve our business based on legitimate interests: answer inquiries, maintain customer relationships, understand service usage, improve our products and website, prevent fraud and abuse, protect our rights, and keep appropriate business records.

    • To administer the Educational Licensing Program: take steps requested before granting an individual license, verify and review eligibility, link the license to your Account, issue and renew one-year licenses, enforce educational-use restrictions, prevent duplicate or fraudulent applications, and suspend or revoke licenses that no longer meet the program requirements. We rely on steps necessary to provide the requested license and on our legitimate interests in protecting and fairly administering the program.

    • To deliver courses and manage classroom access: provide learning content, process exercises and assessments, save progress and results, administer institutional applications and invitations, assign or remove seats, and communicate about access. We rely on performance of our contract with you where the processing is necessary for that contract, or on our legitimate interests in delivering and administering institution-provided access where the contract is with your institution. Where we act solely as a processor, we follow the institution’s documented instructions under the applicable data-processing agreement.

    • To provide expert services and custom work: assess requests, prepare quotes, schedule sessions, investigate technical issues, carry out agreed work, and maintain appropriate delivery and billing records. We rely on contractual necessity for services requested by you, or legitimate interests in providing services to the organization you represent, as appropriate.

    • To send marketing communications: with your consent where required, or based on our legitimate interests where applicable law permits. You may opt out at any time.

    • To comply with legal obligations: meet accounting, tax, consumer-protection, sanctions, and other legal requirements, and respond to lawful requests.

    • For other purposes you authorize: where we ask for and receive your consent. You may withdraw consent at any time without affecting earlier lawful processing.

  5. Marketing Communications

    We use business communication and email platforms to manage contacts, send newsletters and product information, and communicate with prospective and existing customers. The contact data placed in these systems is normally limited to your email address and, where available, first and last name. The platforms may also create delivery and engagement records. You can unsubscribe using the link in a marketing email or by contacting support@blazorise.com. Opting out of marketing does not stop necessary transactional, security, licensing, or support messages.

  6. Purchases and Payments

    Paddle acts as our merchant of record and authorized reseller for purchases completed through Paddle. Paddle collects and processes the information needed to complete a transaction, handle taxes, prevent fraud, and provide billing support. Paddle processes payment information under its own privacy policy. See the Paddle Privacy Policy for details.

    If you purchase through Azure Marketplace or an accepted quote or purchase order, the applicable billing arrangements may differ. We process the contact, order, entitlement, tax, and invoice information needed to fulfill and administer that purchase. Microsoft's privacy information for the marketplace route is linked on our Third-Party page.

  7. Educational Licensing Program

    Students and teachers who apply for an individual Educational License must verify a current university-issued email address. We may also request documents reasonably necessary to confirm current student or teacher status when email verification alone is inconclusive or requires additional review. Please redact identification numbers, grades, photographs, and other unrelated information unless we specifically request them.

    Verification may include automated checks of the email address, domain, application, Account, and prior license activity; review of an ISIC or ITIC card number that you provide; confirmation that a student is eligible for or has redeemed the Blazorise offer through the GitHub Student Developer Pack; validation through another provider identified to you; and manual review by authorized Blazorise personnel. We store ISIC and ITIC card numbers in our own systems and do not send them to the ISIC Association for verification. GitHub independently determines eligibility for its Student Developer Pack and generally provides Blazorise only the account, offer, eligibility, or redemption information needed to provide and protect the Blazorise benefit, rather than the documents used for GitHub's own review. Automated tools may assist our review, but we do not make a final adverse eligibility decision based solely on automated processing. We may contact you or your institution for clarification where appropriate.

    We link the application, verification result, and Educational License to your Blazorise Account so that we can issue the license, confirm continued eligibility at renewal, prevent duplicate applications and misuse, and enforce the non-commercial educational-use restrictions. If you use the GitHub Student Developer Pack route, we may also link the relevant GitHub account or offer-redemption reference to your Blazorise Account for those purposes. Educational eligibility data and submitted documents are not used to send marketing communications unless you separately choose to receive them.

  8. Courses and Classroom Access

    Public course previews do not require an Account; ordinary website technical data may still be processed when you browse them. When you sign in and start a course, we associate learning activity, submissions, results, and progress with your Account to provide the learning experience and preserve your records. Access to a course may depend on a separate subscription, individual entitlement, or institution-assigned classroom seat.

    For institution-provided access, authorized administrators may receive the identifying and membership information needed to manage invitations and seats, such as your name or email address, invitation status, assigned entitlement, and assignment or removal status. Administrative access is limited to the institution and classroom responsibilities concerned; it does not provide general access to your unrelated Account activity or another institution’s records.

    Authorized administrators of your classroom can also view your course progress, completion status, and assessment results associated with that classroom. This reporting enables the institution to supervise learning, provide educational support, and administer its program. It is limited to the relevant classroom relationship and is not general access to learning records unrelated to that classroom. The institution must explain its use of those reports in its own privacy information, including information appropriate for learners who are minors and their parents or guardians where required.

    The institution is responsible for its own decisions about inviting participants and using information received for its educational activities, and its own privacy notice applies to those activities. Blazorise remains responsible for processing whose purposes and means we determine, such as our own account administration and service security. Where we process classroom data solely on the institution’s documented instructions, our role and obligations are governed by the relevant data-processing agreement. This policy does not replace that agreement.

    Learning submissions and results are not public merely because you take a course or join a classroom. They are not used to send marketing communications unless you separately choose to receive them. If you separately choose to post material in a public support or community area, the public-submission notice below applies.

  9. Expert Support, Meetings, and Customer Materials

    When you request expert support or custom work, we process the business contact, project, booking, and technical information needed to assess and deliver the engagement. Microsoft Teams may be used for live meetings and screen sharing as described on our Third-Party page. Information you choose to share during a session is available to the meeting participants and the provider operating the meeting.

    Please use test data, redact unnecessary personal information, and avoid exposing passwords, private keys, production credentials, or unrelated records in code, logs, attachments, or shared screens. You must have authority to provide customer or third-party information. We limit access to personnel and providers who need it for the agreed work, and apply confidentiality and security measures appropriate to the engagement.

    Where the work requires processing personal data on your organization’s behalf rather than for our own purposes, the relevant responsibilities, instructions, security measures, and return or deletion arrangements must be covered by an appropriate data-processing agreement before that processing takes place.

  10. Service Providers and Other Recipients

    We share personal data only when needed for the purposes described in this policy. Recipients may include hosting and infrastructure providers, customer relationship and email platforms, educational eligibility verification providers, professional advisers, and public authorities where disclosure is legally required. Our key providers, their purposes, and links to their privacy information are listed on our Third-Party page.

    We require providers acting on our behalf to process personal data only for the agreed services and to protect it appropriately. We may also disclose data to protect our rights or the safety and integrity of our users and Services, or as part of a merger, acquisition, financing, reorganization, or sale of assets subject to appropriate confidentiality and legal safeguards. We do not sell personal data.

    If you submit an issue, comment, profile, or other content to a publicly accessible support or community area, the account name and content you choose to submit may be visible to other users and the public. Do not include confidential, sensitive, or unnecessary personal data in public submissions.

  11. Cookies and Website Technologies

    Our websites use cookies and similar technologies for essential functions, preferences, security, and audience measurement. Some services embedded in the website may receive technical data such as your IP address, browser information, and the page you visit. You can control cookies through the cookie notice and your browser settings. Blocking essential storage may affect website functionality.

  12. International Data Transfers

    Some providers may process personal data outside Croatia or the European Economic Area. When required, we use safeguards recognized by applicable law, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and apply supplementary measures where appropriate. Provider locations and practices can change; consult the provider links on our Third-Party Services page for current information.

  13. Data Retention

    Account, purchase, and business records: we retain data only for as long as needed for its purpose. Account and license records are generally retained while an account or entitlement is active; communications and customer relationship records while relevant to the relationship; and financial records for the period required by tax and accounting law.

    Educational verification: eligibility details, card numbers, and verification results are generally retained while an individual Educational License is active and as reasonably needed for renewal, eligibility records, fraud prevention, and disputes. Supporting documents are retained only as reasonably necessary to complete verification or manual review and handle related questions, unless a suspected fraud investigation, legal claim, or legal obligation requires longer retention.

    Learning records: progress, submissions, assessment results, and completion records are retained as needed to provide the learning service, maintain relevant Account history, handle support questions, and meet applicable institutional arrangements. The end of course access or removal of a classroom seat does not by itself mean all learning records are immediately deleted. You may request erasure subject to applicable exceptions; data processed on an institution’s behalf is handled under its instructions and the agreed return or deletion provisions.

    Classroom administration: invitation and seat-assignment records are retained as needed to manage pending invitations and active access, document administrative changes, and resolve access or abuse issues. We delete or anonymize expired invitation and former-membership information when it is no longer needed for those purposes or the applicable institutional arrangement.

    Expert services: customer code, diagnostic files, and other working materials are retained only as reasonably necessary to perform the engagement, handle related support or acceptance questions, and comply with the agreed return or deletion arrangements. Contract, delivery, and billing records may have separate retention requirements.

    Exceptions and deletion: limited records may be kept longer to establish, exercise, or defend legal claims, prevent fraud, honor opt-outs, or comply with law. We then delete or anonymize data. Where immediate removal from backups is not practicable, access remains restricted and the data is removed through the applicable backup-retention cycle.

  14. Data Security

    We use reasonable technical and organizational measures designed to protect personal data against accidental loss and unauthorized access, use, alteration, or disclosure. Access is limited to people and providers who need it for their work and who are subject to appropriate confidentiality obligations. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

  15. Your Privacy Rights

    Depending on the law that applies to you, you may have the right to access, correct, erase, or receive a portable copy of your personal data; restrict or object to processing; and withdraw consent. You also have the right to object at any time to direct marketing.

    To exercise a right, email support@blazorise.com. We may need to verify your identity and may retain information needed to document and fulfill the request. These rights can be subject to legal exceptions. If you are in the EEA, you may also lodge a complaint with your local supervisory authority or the Croatian Personal Data Protection Agency.

  16. Children and Institution-Managed Learning

    Classroom Licenses may include learners who are minors, including children under 16. Their participation must be arranged through an approved institution with the authorization required by applicable law. This classroom route does not create unrestricted independent registration for children or remove the contractual capacity requirements in our Terms of Service.

    For these learners, we process the Account, invitation, entitlement, and learning information necessary to provide and protect the classroom service, including progress and assessment results visible to authorized classroom administrators as described above. We do not use children's classroom or learning records for direct marketing. Privacy information provided during institutional onboarding must be clear and appropriate to the learners' age and understanding.

    The lawful basis and the responsibilities of Blazorise and the institution depend on the processing concerned. Where we determine the purposes and means, we are responsible for establishing an appropriate lawful basis and safeguards; where we act as a processor, we follow the institution's documented instructions. If processing relies on consent and applicable law requires authorization by a parent or holder of parental responsibility, that authorization must be obtained and reasonably verified before the consent-based processing begins. A school invitation or acceptance of these Terms does not itself supply that consent.

    Institutions must provide the notices and obtain the permissions required for their own use of learner information. A learner, parent or guardian, or institution may contact support@blazorise.com about a child's data or suspected unauthorized participation. We may need to verify the requester's authority and coordinate with the institution; access, correction, deletion, and other requests are handled according to the applicable rights, our role, and legal obligations. Where required authorization is missing, we will review the situation and restrict access or remove data as appropriate.

  17. External Links and Customer Applications

    Our websites may link to third-party sites that we do not control. Their privacy practices are governed by their own notices. Blazorise is also a software component library: applications created by customers using our Software are controlled by those customers, and their privacy notices apply to data collected through their applications.

  18. Changes to This Policy

    We may update this policy as our practices, Services, or legal obligations change. We will publish the new version and effective date on this page and provide additional notice when a change materially affects your rights or our use of previously collected personal data.

  19. Contact Us

    For privacy questions or requests, contact support@blazorise.com or write to Megabit d.o.o., Hrvojeva 11, 21204 Dugopolje, Croatia. Sales questions may be sent to sales@blazorise.com.