Privacy Policy
Last updated: March 7, 2026
Available in English. Portuguese version coming soon.
1. Who We Are
StudyMaps is a Brazilian company that creates and sells digital study materials (PDF visual study maps) for professional certification exams worldwide at studymaps.work.
For the purposes of applicable data protection legislation, StudyMaps is the data controller (GDPR) / controlador (LGPD) for personal data collected through our website and lead magnet forms.
For purchases, Paddle.com Market Ltd (for non-US transactions) or Paddle.com Inc (for US transactions) acts as the Merchant of Record and is an independent data controller for payment and billing data. StudyMaps never receives or stores your payment card information.
2. What We Collect
We collect only the minimum data necessary to deliver our products and services:
- Email address — provided by you when downloading a free sample (lead magnet) or completing a purchase.
- Consent records — timestamp, IP address, page URL, and consent text version when you opt in to marketing communications.
- Analytics data — we use Plausible Analytics, a cookie-free, privacy-focused analytics service. Plausible does not collect personal data, does not use cookies, and does not track individual visitors. All data is aggregated. No personal data is shared with Plausible.
We do not collect: payment card details, government IDs, health data, biometric data, or any special category data.
3. Why We Collect It (Purposes)
- Lead magnet PDF delivery — to send you the free study map sample you requested. Legal basis: contract performance (GDPR Art. 6(1)(b) / LGPD Art. 7, V).
- Email marketing — to send study tips, new product announcements, and promotional offers, only if you have opted in via a separate, unchecked consent checkbox. Legal basis: consent (GDPR Art. 6(1)(a) / LGPD Art. 7, I).
- Purchase fulfillment — to deliver purchased PDF products to your email. Paddle handles payment processing as an independent controller. Legal basis: contract performance.
- Website analytics — to understand aggregate traffic patterns and improve our website. Legal basis: legitimate interest (GDPR Art. 6(1)(f) / LGPD Art. 7, IX). We use Plausible Analytics, which collects no personal data.
4. Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Free PDF delivery | Contract performance |
| Purchase fulfillment | Contract performance (via Paddle) |
| Email marketing | Consent (opt-in checkbox) |
| Analytics | Legitimate interest (no personal data processed) |
5. Who We Share Your Data With
We share personal data only with the following service providers, each operating under a Data Processing Agreement (DPA) or as an independent controller:
- Paddle (Merchant of Record) — independent data controller for all payment and billing data. Paddle collects and processes payment information directly. We never see your card details. See Paddle's Privacy Policy.
- Resend (transactional and marketing email) — data processor operating under a DPA with EU Standard Contractual Clauses (SCCs) for international transfers (Resend DPA Section 6.2, Module Two: Controller to Processor).
- Cloudflare (website infrastructure, CDN, security) — data processor operating under a DPA. International transfers covered by Cloudflare's Privacy Policy (Section 7) and EU SCCs.
- Plausible Analytics — cookie-free analytics. No personal data is shared. Plausible processes only aggregated, anonymous usage statistics.
We do not sell, rent, or trade your personal data to any third party.
6. International Data Transfers
StudyMaps is based in Brazil. Your data may be processed in the United States by Resend (email delivery) and Cloudflare (infrastructure). These transfers are protected by:
- EU/EEA transfers — EU Standard Contractual Clauses (SCCs) incorporated in the Resend DPA (Section 6.2) and Cloudflare Privacy Policy (Section 7).
- UK transfers — UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs, as applicable.
Brazil does not currently have an EU adequacy decision. We rely on the contractual safeguards described above to ensure appropriate protection for transferred data.
7. Data Retention
- Marketing email list — retained until you unsubscribe, plus 90 days for suppression list maintenance. Contacts inactive for 24 months are removed.
- Consent records — retained for a minimum of 3 years (CASL limitation period) to demonstrate valid consent.
- Purchase records — retained for 5 years for tax and accounting compliance.
- Analytics data — Plausible retains only aggregated statistics. No personal data is retained.
8. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your personal data.
- Restriction — request that we limit processing of your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest, or object to direct marketing at any time.
- Withdraw consent — withdraw marketing consent at any time by clicking "unsubscribe" in any email or by contacting us. Withdrawal does not affect the lawfulness of prior processing.
These rights are provided under GDPR Arts. 15-22, UK GDPR Arts. 15-22, and LGPD Art. 18.
To exercise any right, contact: privacy@studymaps.work
We will respond within 15 days (LGPD, Art. 19) or 30 days (GDPR/UK GDPR, Art. 12(3)), whichever is applicable to your jurisdiction.
India (DPDPA): If you are located in India, you may exercise your rights under the Digital Personal Data Protection Act 2023 (Section 6) by contacting us at the email above. We serve as the grievance contact for the purposes of DPDPA.
9. Cookies
We use Plausible Analytics, which is entirely cookie-free and does not require consent under the ePrivacy Directive or any other cookie legislation.
Cloudflare may set a strictly necessary security cookie (__cf_bm) to identify and mitigate bot traffic.
Strictly necessary cookies are exempt from consent requirements under the ePrivacy Directive Art. 5(3) and PECR Regulation 6.
We do not use Google Analytics, Facebook Pixel, advertising cookies, or any tracking cookies. No cookie consent banner is required because we do not set any non-essential cookies.
10. Supervisory Authorities
If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority:
- Brazil — ANPD (Autoridade Nacional de Protecao de Dados): gov.br/anpd
- United Kingdom — ICO (Information Commissioner's Office): ico.org.uk
- European Union — the data protection authority of your EU/EEA member state. A list is available at edpb.europa.eu.
- India — Data Protection Board of India (when constituted under the DPDPA 2023).
- Canada — Office of the Privacy Commissioner of Canada: priv.gc.ca
11. Children
Our products are designed for adults preparing for professional certification exams. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have collected data from a minor, please contact us at privacy@studymaps.work and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, the "Last updated" date at the top of this page will be revised. We encourage you to review this page periodically.
13. Contact
For any privacy-related questions, data subject requests, or complaints:
- Email: privacy@studymaps.work
- Website: studymaps.work