Legal
Privacy Policy
This policy explains what personal information Protak collects when you interact with our site, why we collect it, and the choices you have.
Last updated: 18 August 2026
Who we are
Protak — Tactical Protection Academy is a private civilian tactical training provider operating primarily in the Republic of Moldova. When we refer to "Protak", "we", or "us" in this policy, we mean the organisation responsible for this site and for delivering the training program.
For the purposes of the EU General Data Protection Regulation (GDPR), Protak is the data controller for personal information collected through this site.
What we collect
We only collect the information we need to respond to enquiries, process enrollments, and run the training program safely.
- Enrollment form data: first and last name, email address, phone number, country of residence, prior experience level, and any notes you choose to share (medical conditions, dietary requirements, questions).
- Cohort preference: which upcoming cohort you selected during registration.
- Website usage: standard server logs (IP address, browser type, pages visited, timestamps), retained for troubleshooting and security.
- Session cookies: a language preference cookie and a Laravel session cookie used to keep you logged in to administrative areas. No third-party advertising cookies are used.
How we use it
- To confirm your enrollment and communicate about upcoming cohorts.
- To ensure your medical, dietary, and safety needs can be accommodated on the training ground.
- To send program-related email (confirmations, logistics, changes to the schedule).
- To meet legal, tax, and safety-recordkeeping obligations.
- To improve the program based on aggregated, non-identifying feedback.
Legal basis for processing
Under GDPR, we rely on the following lawful bases: (a) performance of a contract — processing enrollment data to deliver the training you signed up for; (b) legitimate interest — running the site securely and communicating with people who have voluntarily contacted us; (c) legal obligation — retaining records where local law requires it; (d) consent — for any optional marketing communications, which you can withdraw at any time.
Who we share it with
We do not sell personal information. We share it only with the processors we need to operate the service:
- Resend (email delivery) — to send transactional emails such as enrollment confirmations.
- Cloudinary (media hosting) — to store training photos and images. No enrollment data is sent to Cloudinary.
- NeonDB (managed database, hosted in the EU) — for the storage of enrollment records and site content.
- Instructors and program staff — on a need-to-know basis, for safety planning and delivering the training.
Where your data is stored
Personal data is stored on servers located within the European Union. Some sub-processors listed above may operate infrastructure outside the EU; in those cases, standard contractual clauses or equivalent safeguards apply.
How long we keep it
Enrollment records are retained for as long as necessary to fulfill the training contract and afterwards for a period consistent with local tax, safety, and civil-liability requirements — typically no longer than six years after your last participation.
Server logs are retained for up to 90 days.
You may request earlier deletion where no overriding legal obligation applies.
Your rights
Under GDPR you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your data, where no overriding legal obligation prevents it.
- Restrict or object to specific uses of your data.
- Receive a portable copy of your data.
- Withdraw consent for optional processing at any time.
- Lodge a complaint with your national data protection authority.
Security
We take reasonable technical and organisational measures to protect your information — encrypted transport (HTTPS), encrypted storage of sensitive fields, access controls on administrative areas, and least-privilege access for staff. No system is perfectly secure, and we cannot guarantee absolute security, but we treat your data with the level of care that a small, purpose-built organisation reasonably can.
Changes to this policy
We may update this policy from time to time. When we do, we will change the "last updated" date at the top of this page. Material changes will be communicated to enrolled participants by email.
Questions about your data or this policy? Write to info@protak.me and we will respond within 30 days as required by GDPR.