Deen Circle
The Deen Circle
Nurturing young minds
Loading
Global Privacy Framework

Privacy Policy

Effective & Last Updated: September 2, 2026 | Version 2.4

Need to exercise your privacy rights or request account deletion?

Submit a formal data access, correction, or deletion request in accordance with GDPR/CCPA/APP guidelines.

1. Introduction & Scope

Deen Circle Academy ("we", "us", "our", "Academy") is an international online Islamic educational platform providing Quran, Tajweed, Arabic, and Islamic Studies education. We are committed to protecting the privacy, confidentiality, and data subject rights of our students, parents, guardians, and faculty members worldwide.

This Privacy Policy provides full transparency regarding how we collect, store, secure, process, share, and retain personal data across our website (deencircle.com), student portal, live classrooms, and form handlers.

2. Information We Collect & Form Data Map

We collect personal information directly from users when they interact with our website forms:

Form / FeatureCategories of Personal Data CollectedPrimary Purpose & Legal Basis
Account Sign UpFull Name, Email Address, WhatsApp Phone, Date of Birth, Region/Country, Course Interests.Contract Performance & Student Onboarding (GDPR Art. 6(1)(b)).
Free Demo BookingStudent Name, Parent/Guardian Name, Age, Email, Phone, Preferred Date/Time, Notes.Pre-contractual scheduling of live demo session (GDPR Art. 6(1)(b)).
Course EnrolmentStudent ID, Course Title, Amount Paid, Currency, Country, PayPal Order ID.Payment processing & Course Access Fulfillment (GDPR Art. 6(1)(b)).
Contact InquiryName, Email Address, Inquiry Message Body.Customer Support & Legitimate Interest (GDPR Art. 6(1)(f)).
Faculty AdmissionsFull Name, Email, Phone, Country, Specialization, Experience, Ijazah / Bio details.Employment Evaluation & Faculty Contracting (GDPR Art. 6(1)(b)).

3. Children's Privacy Framework (COPPA & Minors)

As an educational platform serving child students, we treat child data privacy as a dedicated compliance area under the US **Children’s Online Privacy Protection Act (COPPA)** and **GDPR Article 8**:

  • Parental Consent Required: Children under 13 in the US or under 16 in the EU/UK must be enrolled by a parent or verified legal guardian.
  • No Commercial Exploitation: We never sell, rent, or monetize children's data or display targeted advertising.
  • Parental Inspection & Deletion: Parents and guardians retain the absolute right to inspect, edit, or request immediate deletion of their child's learning records via Privacy Requests.
  • Safe Live Classrooms: Virtual classroom sessions are monitored for safety, and student chat channels enforce strict automated filter moderation.

4. European Union / EEA Specific Rights (GDPR)

If you reside in the EU/EEA or UK, you possess specific data subject rights under the General Data Protection Regulation (GDPR):

  • Right of Access (Art. 15): Request a copy of all personal data held.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your data.
  • Right to Data Portability (Art. 20): Receive your data in structured, machine-readable JSON format via our Data Export Tool.
  • Right to Object & Withdraw Consent (Art. 21): Withdraw consent for non-essential processing anytime.

5. Australian Privacy Principles (Privacy Act 1988)

For users in Australia, personal information is handled in accordance with the 13 **Australian Privacy Principles (APPs)** under the Privacy Act 1988 (Cth):

  • Collection & Holding (APP 1, 3, 5): We only collect personal information that is reasonably necessary for providing Quran & Islamic education.
  • Access & Correction (APP 12, 13): You may request access to or correction of your information without charge.
  • Overseas Disclosures (APP 8): Information may be processed on secure global infrastructure (Supabase, Vercel, PayPal) operating under ISO 27001 and SOC 2 Type II certifications.
  • Complaints: If you believe we have breached the APPs, contact our Privacy Officer. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

6. United States State Privacy Laws (CCPA / CPRA)

For residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado, and other US states:

  • No Sale or Sharing of Personal Data: We do NOT sell personal information or share personal data for cross-context behavioral advertising.
  • Right to Opt-Out: Users retain the right to opt-out of marketing communications at any time.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA privacy rights.

7. Third-Party Data Processors

We share data only with essential, trusted service providers for core operations:

  • Supabase Inc. — Database, authentication, and secure cloud storage.
  • PayPal Holdings Inc. — Secure payment gateway processing.
  • Vercel Inc. — High-performance global web hosting and CDN infrastructure.
  • FormSubmit & Web Email Services — Transactional email delivery and automated acknowledgements.

8. Data Retention, Archiving & Purging

We retain personal data only for as long as necessary to fulfill the educational purposes for which it was collected or to satisfy legal, tax, or accounting requirements:

  • Active Student Accounts: Retained for the duration of enrolment + 24 months post-graduation.
  • Demo Bookings & Contact Inquiries: Retained for 12 months unless account conversion occurs.
  • Financial & Payment Transaction Logs: Retained for 7 years to satisfy statutory tax obligations.
  • Deleted Account Purges: Account deletion requests permanently purge active databases immediately and clear backup archives within 30 days.

9. Security Measures & Data Breach Notification Protocol

We implement SSL/TLS 256-bit encryption in transit, AES-256 encryption at rest, rate limiting, and honeypot anti-bot security. In the unlikely event of a security incident or data breach involving personal data, we will notify affected users and supervisory authorities (e.g., OAIC, EU Data Protection Authorities) within 72 hours as legally required.

10. Privacy Contact & Escalation Procedure

For questions regarding this policy, to exercise your privacy rights, or to submit a privacy complaint, contact our Data Protection Officer:

Data Protection & Privacy Officer

Email: privacy@deencircle.com

General Support: contact@deencircle.com

Response SLA: All formal privacy requests are acknowledged within 48 hours and fulfilled within 30 days.