Back to Home

    Privacy Policy

    Lernaura ApS • CVR 46170164 • Denmark

    1. Introduction

    Welcome to Lernaura. We respect your privacy and are committed to protecting your personal data. This Privacy Statement explains how Lernaura ApS ("Lernaura", "we", "us") collects, uses and safeguards your personal data when you visit our website, engage with us as a prospect, seller or buyer, or use our services, including our merchant-of-record (MoR) platform, payment processing, global tax determination and remittance, invoicing, fraud prevention, subscription billing and payout services (the "Services").

    Controller and processor roles. Lernaura operates as a Merchant of Record. This means that when a buyer purchases a product or subscription through a seller who uses the Services, Lernaura (and not the seller) is the legal seller of record to the buyer. As a consequence:

    • Lernaura as controller. Lernaura is the data controller for (i) our website, marketing and business relationships; (ii) the sales transaction between Lernaura and the buyer (including order, billing, tax, payment and fraud-prevention data); (iii) our statutory records (accounting, tax, anti-money-laundering and sanctions compliance); and (iv) the onboarding, due-diligence (KYC/KYB), risk and payout relationship with sellers.
    • Lernaura as processor. Where a seller uses the Services to process personal data about its own end users, employees or suppliers beyond what is necessary for Lernaura's MoR role (for example, storing additional customer attributes in a seller dashboard), the seller is the controller and Lernaura acts as processor under the Data Processing Agreement (DPA) between Lernaura and the seller.
    • Joint responsibility. In limited cases (for example, shared checkout analytics), Lernaura and a seller may be joint controllers. Where that applies, the respective responsibilities are set out in the seller agreement.

    2. Data We Collect

    We collect information that you provide directly to us or that we generate when you interact with us, including:

    • Account and contact information (e.g., name, email address, phone number, job title, company name, VAT number).
    • Profile and authentication information (e.g., user name, role, hashed credentials, multi-factor authentication data).
    • Seller due-diligence information (KYC / KYB), where you are (or represent) a seller: company registration details, beneficial-ownership information, government-issued identity documents, proof of address, bank account information for payouts, tax residency information and tax identification numbers.
    • Buyer and transaction information: billing name and address, shipping address (where relevant), email address, country and IP-derived location for tax determination, order details, currency, amount, applicable VAT/GST/sales tax, invoice data, subscription status and renewal dates.
    • Payment data: truncated card number (BIN and last four digits), card brand, expiry, tokenised card references, bank or wallet identifiers, authorisation, settlement, refund and chargeback data. Full card numbers and CVV/CVC are handled exclusively by PCI-DSS compliant payment service providers and are not stored by Lernaura.
    • Fraud-prevention and risk data: device fingerprint, IP address, browser and operating system information, behavioural signals, velocity metrics, risk scores, sanctions and PEP screening results, and related decisioning outputs.
    • Content you create and upload in connection with the Services (e.g., product descriptions, tax configurations, invoices, support attachments).
    • Communications with us (e.g., emails, support tickets, meeting notes, chat messages, call recordings where permitted by law).
    • Usage data and analytics (e.g., log data, device and browser information, IP address, pages visited, features used).
    • Marketing preferences and consents.

    3. How We Use Your Data

    We use the information we collect to:

    • Provide, maintain and improve the Services and the website.
    • Create and administer seller and buyer accounts and manage the relationship.
    • Act as Merchant of Record: conclude and perform the sale with the buyer, issue invoices and receipts, determine and collect applicable indirect taxes (VAT, GST, sales tax and similar), remit taxes to the relevant tax authorities, and make payouts to sellers.
    • Process payments: authorise, capture, settle, refund and reconcile transactions through our payment service providers.
    • Prevent fraud, chargebacks and abuse and manage disputes, including chargeback representment with card networks.
    • Comply with financial-crime and regulatory obligations: carry out KYC/KYB, sanctions, PEP and adverse-media screening, monitor transactions for unusual activity, file reports where required (e.g., SAR/STR under applicable AML rules) and respond to lawful requests from authorities.
    • Send technical notices, security alerts, transactional communications (e.g., order confirmations, receipts, renewal reminders) and support messages.
    • Respond to your enquiries, comments and support requests.
    • Send marketing communications, where permitted by law or based on your consent, and measure their effectiveness.
    • Analyse usage patterns and trends to improve the Services.
    • Comply with legal obligations, including bookkeeping, tax and reporting duties.

    Legal bases. We rely on the following legal bases under the General Data Protection Regulation (GDPR):

    • Performance of a contract (Art. 6(1)(b)) — to conclude and perform the sale with the buyer, and to perform the services agreement with the seller.
    • Compliance with a legal obligation (Art. 6(1)(c)) — for accounting (Danish Bookkeeping Act / Bogføringsloven), tax remittance and reporting, AML, sanctions and consumer-protection obligations.
    • Legitimate interests (Art. 6(1)(f)) — to operate, secure and improve the Services, prevent fraud and abuse, pursue chargeback representment, carry out direct marketing to business contacts and protect our legal rights.
    • Consent (Art. 6(1)(a)) — where required, e.g., for non-essential cookies and certain marketing communications.

    4. Cookies and Tracking

    We use cookies and similar tracking technologies to operate the Services, secure transactions and enhance your experience. You can manage your preferences at any time through the cookie banner or your browser settings. See our separate Cookie Policy for details.

    Strictly Necessary Cookies

    These cookies are essential for the website and checkout to function properly. They include authentication cookies, session integrity cookies, device fingerprints used for fraud prevention at checkout, and your cookie consent preference. They cannot be disabled.

    Functional Cookies

    These cookies remember your preferences, such as currency, language and sidebar state. They are only set if you accept cookies.

    Analytics and Marketing Cookies

    Where used, these cookies help us understand how the website and checkout are used and measure the effectiveness of marketing. They are only set if you consent.

    5. Data Sharing and Disclosure

    We may share your personal data in the following circumstances:

    • With your consent or at your direction.
    • With sellers. Where you are a buyer, we share a limited set of transaction data (e.g., order details, buyer name, email, billing country, tax status and, where relevant, shipping address) with the seller whose product you purchased, so that the seller can provide the underlying product or service and handle support.
    • With service providers and sub-processors who perform services on our behalf, including: payment service providers and card networks, acquiring banks, tax determination and filing engines, KYC/KYB and identity verification providers, fraud and risk decisioning platforms, cloud hosting and storage, email and customer support tools, analytics and monitoring providers, electronic invoicing platforms, and professional advisors.
    • With our group companies and advisors, where necessary for the purposes described in this Privacy Statement.
    • With tax, customs and regulatory authorities, where required to remit taxes, file returns or respond to lawful requests.
    • With card networks (e.g., Visa, Mastercard, American Express) and issuing banks, for authorisation, settlement, chargebacks and fraud monitoring.
    • Where required to comply with legal obligations, court orders, AML/CFT obligations or requests from supervisory authorities.
    • To establish, exercise or defend legal claims, and to protect our rights and prevent fraud.
    • In connection with a business transaction (such as a merger, acquisition, reorganisation or sale of assets).

    International transfers. The Services are operated from and primarily hosted in the EU/EEA. Where we transfer personal data outside the EU/EEA (for example, to global payment networks, sub-processors in third countries, or authorities in jurisdictions where Lernaura is tax-registered), we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, and carry out transfer impact assessments where required.

    6. Your Rights (GDPR)

    Under the GDPR and the Danish Data Protection Act, you have the right to:

    • Access your personal data.
    • Rectify inaccurate or incomplete data.
    • Request erasure of your data ("right to be forgotten").
    • Restrict processing of your data.
    • Receive your data in a portable format and have it transmitted to another controller.
    • Object to processing based on legitimate interests or for direct marketing.
    • Withdraw any consent at any time (without affecting the lawfulness of processing before withdrawal).
    • Lodge a complaint with a supervisory authority, in Denmark the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk).

    To exercise any of these rights, please contact us using the details in Section 12.

    Limits on erasure and restriction. Because Lernaura is the legal seller of record and is subject to statutory bookkeeping, tax, AML and sanctions obligations, we are generally required to retain transaction, invoice, payment and KYC data for the periods set by law (see Section 8) even where you request erasure. We will, however, restrict further processing and delete data that is not subject to a retention obligation.

    Requests concerning data we process for our sellers. If your personal data is processed through the Services on behalf of one of our sellers (for example, where a seller uses a dashboard to maintain additional customer attributes beyond what is needed for the MoR role), please direct your request to that seller as the data controller. We will support the seller in responding in accordance with the DPA.

    7. Data Security

    We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These include access controls, multi-factor authentication, encryption in transit and at rest, network segmentation and segregation of environments, tokenisation of card data, logging and monitoring, vulnerability management, regular penetration testing, and a PCI-DSS compliant handling model for payment data. We also maintain a documented incident response plan. However, no method of transmission over the internet is 100% secure.

    8. Data Retention

    We retain personal data only for as long as necessary for the purposes set out in this Privacy Statement, unless a longer retention period is required or permitted by law. In particular:

    • Accounting and tax records (including invoices, receipts and transaction data): retained for at least the period required by the Danish Bookkeeping Act (Bogføringsloven) and applicable foreign tax laws, which is typically five years from the end of the financial year, and longer where local tax rules require.
    • KYC/KYB and AML records: retained for at least five years after the end of the business relationship, in accordance with applicable anti-money-laundering legislation.
    • Payment and chargeback data: retained for the periods required by card network rules and to allow chargeback and dispute handling.
    • Support tickets and communications: retained for a reasonable period to allow follow-up and quality assurance.
    • Marketing data: retained until you object or withdraw consent.
    • Data relating to legal claims: retained for the applicable limitation periods.

    9. Third-Party Services

    Our website and Services may contain links to third-party websites or services or may integrate with third-party systems (for example, payment service providers, card networks, tax engines, KYC providers, fraud-prevention platforms, accounting systems and seller-operated websites). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.

    10. Children's Privacy

    Our Services are intended for business use and for adult buyers. We do not knowingly collect personal data from children under the age of 16 (or the equivalent age of digital consent in your jurisdiction). If you believe that a child has provided us with personal data, please contact us so that we can take appropriate action.

    11. Changes to This Policy

    We may update this Privacy Statement from time to time. We will post the updated version on our website and, where changes are material, provide additional notice (e.g., by email or in-product notice). The "Last Updated" date below indicates when the Statement was last revised.

    12. Contact Us

    If you have questions about this Privacy Statement or our data practices, or would like to exercise your rights, please contact us:

    Lernaura ApS

    Vesterbrogade 82 2 th

    1620 Copenhagen V

    Denmark

    Email: privacy@lernaura.eu

    Last Updated: April 23, 2026