Privacy Notice
Last updated: April 2026
1. Controller
Vasilisa Zhukova
Contact email: vasilisa.zhukova.neuro@gmail.com
2. What personal data do I collect and why?
When you purchase my digital content, I receive from PayPal your name and email address for the purpose of fulfilling your order.
I do not collect or store:
- Payment card details
- Bank account information
- Billing addresses (unless PayPal shares them, which is rare)
3. Lawful basis
Under the GDPR (Article 6(1)(b)), the lawful basis for this processing is:
Performance of a contract – processing is necessary to sell and deliver the digital product you have purchased.
I do not rely on your consent for this processing. This means you cannot «withdraw consent» for order processing – but you have other rights (see section 7 below).
4. How PayPal processes your data (important)
To process your payment, your data is transferred to PayPal.
For the purpose of the payment transaction, PayPal acts as an independent data controller (not as my processor). This means:
- PayPal determines its own purposes and means of processing your data (fraud prevention, anti-money laundering compliance, etc.)
- I do not control how PayPal processes your data
- PayPal has its own legal obligations to you
You must read PayPal‘s Privacy Statement:
https://www.paypal.com/privacy
5. Retention period
I keep your name and email address for 2 years from the date of purchase to comply with tax and accounting obligations under German / EU law (e.g., §147 AO – 10 years for accounting records, but I minimize to 2 years for personal data unless legally required otherwise).
After this period, your data is deleted from my records.
6. Your rights under GDPR
You have the following rights:
| Right | What it means |
|---|---|
| Access | Request a copy of all data I hold about you |
| Rectification | Correct inaccurate data |
| Erasure | Request deletion of your data («right to be forgotten») |
| Restriction | Limit how I use your data |
| Objection | Object to processing based on legitimate interests |
| Data portability | Receive your data in a machine-readable format |
| Lodge a complaint | Complain to your local supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany) |
To exercise these rights, email me at:
vasilisa.zhukova.neuro@gmail.com
I will respond within 30 days as required by GDPR.
7. No consent – no withdrawal possible for contract processing
Because my processing is based on contract performance (not consent), you cannot “withdraw consent” for the basic processing required to complete your purchase.
However, you may request deletion of your data after the purchase is complete and any applicable retention periods have expired.
8. International data transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (where PayPal is headquartered). PayPal relies on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for such transfers.