Skip to content
LumiereAcademy
  • Courses
  • Pricing
  • For clinics
  • Resources
  • About
  • Contact
ENLanguage
  • English
  • Norsk
  • Svenska
  • Dansk
  • Deutsch
  • Nederlands
  • Français
  • Español
  • Türkçe
  • Polski
  • Latviešu
  • Lietuvių
  • Eesti
  • Русский
  • Українська
CartMy page

Privacy policy

Last updated: October 9, 2026

Draft: this text has not yet been legally reviewed.

1. Who is responsible

Lumiere Systems AS, organisation number [ORG NO.], [ADDRESS], Norway, is the controller for the personal data described here. Contact for privacy questions: [EMAIL].

2. What we collect and why

Data Why Legal basis (GDPR)
Name, email address, password (stored only as a secure hash), preferred language To create and run your account Contract (Art. 6(1)(b))
Purchases: courses, amounts, VAT, country, payment reference To deliver what you bought, bookkeeping and VAT Contract; legal obligation (Art. 6(1)(c))
Learning data: progress, quiz answers and scores, certificates To run the course and issue your certificate Contract
Name, course and dates on your certificate So that others can check your certificate with its number Legitimate interest (Art. 6(1)(f)) and your choice to share the number
Technical data: IP address, browser, security logs To run the site securely and stop misuse Legitimate interest
Statistics and marketing cookies To understand use of the site and measure our ads Consent (Art. 6(1)(a)), see the cookie page

We do not receive your card details: payments are handled by Stripe.

3. Who processes data for us

  • Cloudflare (hosting, database and file storage in the EU, video streaming): data processor.
  • Stripe (payments): Stripe is responsible for the payment data it processes.
  • Resend (sending emails such as order confirmations and password reset links, sent from the EU): data processor. It receives your email address, name and the content of the email.
  • Google, Meta and TikTok: only if you consent to statistics or marketing cookies.

Some of these companies may process data outside the EU/EEA, for example in the USA. Such transfers are based on the EU–US Data Privacy Framework or the EU standard contractual clauses. [CHECK the current basis for each provider.]

4. How long we keep data

  • Account and learning data: as long as you have an account. You can ask us to delete it.
  • Purchases: for as long as accounting law requires (in Norway currently 5 years after the end of the financial year).
  • Certificates: [PERIOD], so that they can still be verified. After deletion, the verification page shows that no certificate exists.
  • Security logs: [PERIOD].

5. Your rights

You can ask for access to your data, correction, deletion, restriction, a copy in a common format (portability), and you can object to processing based on legitimate interest. You can withdraw consent to cookies at any time under "Cookie settings" at the bottom of the page.

Contact us at [EMAIL]. You can also complain to the Norwegian Data Protection Authority (Datatilsynet) or the data protection authority where you live.

6. Customers in Turkey

For customers in Turkey, a separate information notice under the Personal Data Protection Law No. 6698 (KVKK) will be published. [TO BE PREPARED WITH TURKISH LEGAL ADVICE.]

7. Changes

We update this policy when our processing changes. The date at the top shows the latest version.

LumiereAcademy

Online training in aesthetic treatments. Part of the Lumiere group.

  • Terms
  • Privacy policy
  • Cookies
  • Verify a certificate
  • Contact

Our certificates confirm that a course has been completed. They are not a licence to practise. Rules for performing treatments differ from country to country.

© 2026 Lumiere Systems AS