Privacy Policy

What personal data Uppcoder collects, why we collect it, where it is held, how long we keep it, and the rights you have over it.

PRIVACY POLICY

Uppcoder — a service of WEBSSON d.o.o.

Last updated: 30 August 2026

1. Introduction

WEBSSON d.o.o., trading as Uppcoder ("we", "us", "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store and share your personal data when you use the Uppcoder platform (the "Service").

2. Data Controller

The data controller is WEBSSON društvo s ograničenom odgovornošću za usluge (WEBSSON d.o.o.), a company registered in the Republic of Croatia at the Commercial Court in Pazin under registration number (MBS) 130153327, OIB 13733716553, with its registered seat at Voltićeva ulica 9, 52100 Pula, Croatia.

For data protection enquiries, contact privacy@uppcoder.com.

3. When we are a controller, and when we are a processor

This distinction matters, because different rules apply:

  • We are the data controller for your account, billing, support and usage data — the data described in section 4 below. This Policy governs it.
  • We are a data processor for any personal data you place inside your workspaces, repositories or other content ("Your Content"). There, you are the controller and you decide what is collected and why. The terms on which we process it are in Appendix 1 of our Terms and Conditions, not in this Policy.

4. Data We Collect

Account Information — Name, email address, and organization (if applicable), collected during registration.

Usage Data — Resource consumption (CPU, RAM, disk), workspace activity, and feature usage for billing and platform operation.

Technical Data — IP address, browser type, and device information collected automatically for security and service improvement.

Website Measurement — On our public marketing pages we count page views and clicks so we can tell which pages and referral sources are useful. This is anonymous, uses no cookies, and never stores your IP address. See Website Analytics below.

Payment Data — Payment information is processed by Stripe. We do not store card numbers on our servers.

User Content — Code, files and configurations stored in your workspaces. We do not access your content except as necessary to provide the Service or as required by law. See section 3 above.

5. How We Use Your Data

  • To provide, maintain and improve the Service
  • To process billing and manage your subscription
  • To communicate with you about your account, updates and support
  • To enforce our Terms and Conditions and prevent abuse
  • To comply with legal obligations

6. Legal Basis (GDPR)

  • Contract performance – to provide the Service you subscribed to
  • Legitimate interest – for security, fraud prevention and service improvement
  • Legal obligation – to comply with applicable laws
  • Consent – for optional marketing communications, which you can withdraw at any time

7. Data Sharing

We do not sell your personal data. We share data with the following categories of recipient:

| Recipient | Purpose | Location |

|---|---|---|

| Hetzner Online GmbH | Hosting and compute infrastructure | European Union |

| Keycloak (self-hosted by us) | Authentication and identity | European Union |

| Auth0 / Okta | Enterprise single sign-on, where your organization elects to use it | EU / United States |

| Stripe | Payment processing and fraud prevention | EU and United States |

| GitHub | Source code repositories, where you connect a repository or use course repositories | United States |

| Your learning platform | Where the Service is used inside Moodle, Canvas or another LTI platform | As determined by your institution |

| Law enforcement | Where required by law, or to protect rights and safety | — |

Artificial intelligence

The AI features we supply run on our own inference infrastructure in the Netherlands. Content you send to them is not passed to any third party model provider, and does not leave the European Economic Area.

If you install your own AI tools or extensions in your workspace, or supply your own credentials for a third party model provider, that processing is yours and not ours — we cannot control or guarantee where that data goes. See clause 4 of our Terms and Conditions.

International transfers

Hosting and authentication run within the EU/EEA. Transfers to the United States (Stripe, GitHub, and Auth0 where used) are safeguarded under the EU–US Data Privacy Framework and/or Standard Contractual Clauses. We do not load fonts, scripts or analytics from third-party CDNs that would transmit your data abroad.

8. Data Retention

Account data is retained while your account is active. After account deletion or subscription cancellation, data is retained for 30 days before permanent deletion, during which you may request an export.

If your account is inactive for six months, we may delete your content after giving you at least 30 days' notice by email.

Billing records are retained as required by tax and accounting regulations.

9. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), isolated workspace environments and access controls.

10. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Data portability
  • Lodge a complaint with a supervisory authority — ours is the Croatian Personal Data Protection Agency, Agencija za zaštitu osobnih podataka (AZOP), azop.hr. You may also complain to the authority in your own country of residence.

To exercise these rights, contact privacy@uppcoder.com.

11. Cookies & Local Storage

We use only cookies and browser storage that are strictly necessary to run the Service, or that remember your own preferences. We do not use analytics, advertising or cross-site tracking cookies, and our website measurement (see Website Analytics below) stores nothing at all on your device. Because of this, no cookie-consent banner is required.

Strictly necessary

  • access_token – keeps you signed in (expires after about 24 hours)
  • _gate_session – secure (HttpOnly) session cookie used by our access gateway
  • Keycloak session cookies – set by our authentication provider during sign-in
  • LTI cookies – only when the Service is embedded inside a learning platform (e.g. Canvas, Moodle), to maintain the session inside the iframe

Functional (stored in your browser only, never transmitted)

  • Display preferences such as light/dark theme and menu state
  • Authentication refresh and device tokens used to keep you signed in

Third-party

When you make a payment, Stripe sets its own cookies for fraud prevention and to process the transaction. These are used only on the checkout flow.

12. Website Analytics

On our public pages (the home page and the Education, Developer and Enterprise pages) we record which pages are viewed, which buttons and links are clicked, and whether a product film is played. We do this ourselves, on our own servers in the EU. We do not use Google Analytics, or any other third-party analytics service, and no data about your visit is sent to any other company.

What is recorded

  • The page path (for example /education) – never the query string
  • The name of the button or link clicked, and whether a film was played
  • The website that referred you, and any campaign tag in the link you followed
  • Your browser family, operating system family, and desktop / tablet / phone

What is not recorded

  • No cookies, and no browser storage of any kind. Nothing is written to your device
  • No IP address. It is used only, in the instant of the request, as an input to an irreversible hash, then discarded
  • No account link. These records contain no user ID, email address or name, and are never joined to your account
  • No full User-Agent string, no device fingerprint, and no cross-site tracking

How visits are counted without identifying you

So that one person reading three pages counts as one visit rather than three, each visit gets a short code derived from your IP address and browser type combined with a random secret we generate daily and destroy after two days. Once destroyed, the code cannot be recalculated or traced back to an IP address by anyone, including us — and the same visitor on two different days appears as two unrelated codes.

Legal basis, retention and opt-out

This runs under our legitimate interest (GDPR Art. 6(1)(f)) in knowing which pages and referral sources work. With no cookies or device storage and no personal identifiers, it does not require consent under the ePrivacy Directive. Individual records are deleted after 180 days; only anonymous daily totals are kept beyond that. If your browser sends a Do Not Track or Global Privacy Control signal we record nothing at all — no request is even sent.

13. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect data from children. Educational accounts for minors must be set up by an authorized educator or institution, which is responsible for obtaining any consent required. See clause 8 of our Terms and Conditions.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified by email or platform notification. Continued use of the Service constitutes acceptance of the updated Policy.

15. Contact

For privacy-related questions, or to exercise your data rights, contact privacy@uppcoder.com.

WEBSSON d.o.o., Voltićeva ulica 9, 52100 Pula, Croatia.