Legal

Privacy Policy

Last updated: April 1, 2025

1. Who We Are

This Privacy Policy applies to sarrahellal.com, operated by Dr. Sarra Hellal ("we", "us", or "our"). We provide online medical education courses and digital learning resources.

If you have any questions about this policy, you can contact us at the email address listed on our Contact page.

2. Information We Collect

We collect information you provide directly when you:

  • Create an account — name, email address, and password.
  • Make a purchase — billing details processed securely by Stripe. We do not store your card number.
  • Contact us — name, email, and message content.
  • Use the platform — lesson progress, exam attempts, and course completion data.

We also automatically collect certain technical data including IP address, browser type, pages visited, and referral URLs through standard server logs and session cookies.

3. How We Use Your Information

  • To provide, operate, and maintain your account and purchased courses.
  • To process payments and send order confirmations.
  • To track your learning progress and issue certificates of completion.
  • To respond to your support requests and contact form messages.
  • To send transactional emails (purchase receipts, password resets, email verification).
  • To improve the platform and understand how content is used.

We do not sell your personal data to third parties.

4. Third-Party Services

We use trusted third-party services to operate the platform:

  • Stripe — payment processing. Your card details are handled entirely by Stripe and subject to their Privacy Policy.
  • Bunny CDN — secure video streaming for course content.
  • Email provider — sending transactional emails (order confirmations, account emails).

Each of these services processes your data only as necessary to deliver the functionality they provide.

5. Cookies

We use essential cookies to keep you logged in, remember your cart, and protect against request forgery (CSRF). These are strictly necessary for the platform to function and cannot be disabled.

We do not use advertising cookies or tracking cookies from third-party ad networks.

6. Data Retention

We retain your account and purchase data for as long as your account is active, and for a reasonable period thereafter to comply with legal obligations. You may request deletion of your account and associated data at any time by contacting us.

7. Your Rights

Depending on your location, you may have rights to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict certain types of processing.

To exercise any of these rights, please contact us.

8. Security

We take reasonable technical and organisational measures to protect your data, including HTTPS encryption, hashed passwords, and secure payment handling via Stripe. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.