Legal

Privacy Policy

What we process, why, and the rights you have over it.

Last updated 2026-09-01

1. Who is responsible

The controller for the processing described here is MAS Solutions Group LLC, 3833 Powerline Rd, STE 601-P, Fort Lauderdale, FL 33309, United States, represented by Adnan Mustedanagic.

For any privacy matter — access, correction, deletion or a question — write to office@massolutions.io.

2. What we process, and why

Account and sign-in
Your email address and the data needed to authenticate you and keep you signed in. We use a one-time sign-in link rather than a password. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
Orders and payment
The volumes you buy, the amount, the status of the order and a reference to the payment. Card details are entered with our payment provider and are not stored by us. Legal bases: performance of a contract, Art. 6(1)(b), and compliance with legal obligations such as tax and accounting rules, Art. 6(1)(c) GDPR.
Access to purchased content
Which volumes your account is entitled to, and records of access to them. This is needed to give you what you paid for and to protect the works against unauthorised redistribution. Legal bases: Art. 6(1)(b) and our legitimate interest in protecting our content, Art. 6(1)(f) GDPR.
Progress in the journey
Which volumes you have completed and when, so the journey can continue where you left it. Legal basis: Art. 6(1)(b) GDPR.
Waitlist
If you join the waitlist, your email address, so we can tell you when a volume is released. Legal basis: your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time; that does not affect messages already sent.
Technical and security data
Data such as your IP address, device and browser information, and records of requests to our systems. We use it to operate the site securely, to keep it available, and to detect and prevent abuse. Legal basis: our legitimate interest in the security and integrity of the service, Art. 6(1)(f) GDPR.

Where we rely on a legitimate interest, you may object under Art. 21 GDPR.

3. Payments

Payments are processed by Stripe. You enter your payment details on Stripe’s own checkout, and we receive back the outcome of the payment and a reference to it, not your card data. Stripe processes that data as its own controller under its own privacy policy.

4. Cookies and similar technologies

We use cookies and similar technologies that are necessary to operate the site — in particular to sign you in, keep your session, and protect the service against abuse. We do not use advertising or analytics cookies. If that changes, we will ask for your consent where the law requires it.

Our payment provider sets its own cookies on its checkout page when you go there to pay.

5. Service providers

We use service providers to run the site. They process personal data on our behalf, under contract and on our instructions, and only as far as their role requires:

Supabase
Database, authentication and storage of purchased content.
Stripe
Payment processing. Card details are entered on Stripe's own checkout and do not reach our servers.
Hostinger
Website hosting and server logs.
Cloudflare
Bot protection on our forms, where that protection is enabled.
Email delivery provider
Sending transactional email such as sign-in links and service notices, where such a provider is configured.

We do not sell personal data and we do not share it for third-party advertising. We disclose data to authorities only where a law that binds us requires it.

6. International transfers

We are established in the United States, and some of our providers operate internationally. Where personal data is transferred outside the EEA, appropriate safeguards are used where required by applicable law. You can ask us which safeguard applies in a given case.

7. How long we keep data

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires:

  • Account, entitlement and progress data: while your account is active, and afterwards only as long as needed to close it properly.
  • Order and payment records: for the periods that tax and accounting law require.
  • Waitlist data: until you unsubscribe or ask us to remove you.
  • Technical and security data: for a limited period necessary for security and abuse prevention.

8. Your rights

Under the GDPR you have the right to access your personal data and to request its rectification or erasure, the right to restriction of processing, the right to data portability, and the right to object to processing based on a legitimate interest. Where processing rests on consent, you can withdraw it at any time with effect for the future.

To exercise any of these, write to office@massolutions.io. We respond within the periods the GDPR sets.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, where you work, or where you believe an infringement occurred.

9. Security

We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, and we review them as the service develops. No online service can be made entirely risk-free.

10. Children

This site is not directed at children, and accounts are intended for people aged 16 and over. If you believe a child has provided us with personal data, please contact us and we will remove it.

11. Changes to this policy

We may update this policy as the service changes. The current version is always the one published here, with the date shown at the top. If a change materially affects you, we will notify you where the law requires it.