Legal

Privacy Policy

1. Introduction

This Privacy Policy explains how MHKI ACADEMY OY (“we”, “our”) collects and processes personal data on www.amplifychallenge.com (“Site”) and the “Amplify” mobile application (“App”).

We comply with the EU General Data Protection Regulation (GDPR) and applicable laws. By using the Site or App, you consent to this Policy.

2. Data We Collect

  • Full name and contact details (email, phone, address)
  • Date of birth and gender (where applicable)
  • IP address, device identifiers, browser/OS details
  • Usage data (pages viewed, features used, session duration)
  • Billing/payment info
  • Approximate location data (when participating in challenges)
  • Linked social handles (e.g., TikTok, Instagram, YouTube)

You are responsible for keeping your information accurate and up-to-date.

2.1 Analytics & Diagnostics (Sentry)

We use Sentry (sentry.io) to monitor app stability, crashes, and performance. Depending on your session and settings, Sentry may receive:

  • Crash reports (stack traces, device/OS info, app version, timestamps)
  • Performance metrics (screen loads, network timing, UI responsiveness)
  • Usage events (navigation events and interaction breadcrumbs)
  • User identifier and contact (only if you sign in and we attach it)

We may associate crash/diagnostic events with your account by sending a user ID, username, or email. If you do not want diagnostic data linked to your identity, you can request unlinking or disable diagnostics as described below.

2.2 Session Replay (Sentry Replay)

We may use Sentry Session Replay to reproduce errors. Replay captures a sequence of UI events (e.g., screen transitions, touches, layout states) to help us diagnose issues. Password fields and other sensitive inputs are intended to be masked. We do not record microphone, camera, or your photo/video content via Replay.

3. Purpose of Processing

  • Provide, operate, and improve the Service
  • Personalize experience and content
  • Manage accounts and registrations
  • Process payments and transactions
  • Send updates, offers, and service notifications
  • Analytics, research, and performance tracking
  • Comply with legal obligations
  • Diagnose crashes, errors, and performance issues (Sentry)
  • Ensure reliable email delivery for account security (Mailgun)

4. Storage & Retention

Data is stored securely and retained only as long as necessary for the purposes above or as required by law. Marketing data is retained until you opt out or withdraw consent.

5. Sharing with Third Parties

We may share data with trusted processors for:

  • Payment processing
  • Cloud hosting and analytics
  • Marketing/communication tools
  • Fraud prevention and security

Processors act under contracts with confidentiality and security obligations. We do not sell personal data.

5.1 Our Processors

  • Sentry (EU data hosting available): crash reporting, performance monitoring, replay diagnostics
  • Mailgun (EU region – Frankfurt): transactional email (e.g., password resets)
  • AWS: application hosting, databases, storage and CDN

These providers act on our instructions under data processing agreements. We do not sell personal data.

6. International Transfers

Where data is transferred outside the EEA, we use appropriate safeguards (e.g., EU Standard Contractual Clauses).

We prefer EU data residency where available. When data is processed outside the EEA, we use EU Standard Contractual Clauses or other lawful transfer safeguards. For Mailgun we use the EU region (Frankfurt). Sentry and AWS offer EU hosting options; where EU hosting is not technically feasible, we apply SCCs and minimize data.

7. Cookies & Tracking

We use cookies to remember preferences, keep you signed in, and collect anonymous analytics. You can disable cookies in your browser; some features may be limited.

8. Your Rights (GDPR)

  • Access your data
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time

To exercise rights: niko@amplifychallenge.com

9. Security

We implement technical and organizational measures to protect data. No system is fully secure; you share at your own discretion.

10. Updates

We may update this Policy. Material changes will be announced via the Site, App, or email. Continued use means you accept the updated Policy.

11. Legal Bases (GDPR)

  • Contract (Art. 6(1)(b)): account creation, authentication, providing core features
  • Legitimate interests (Art. 6(1)(f)): crash diagnostics, preventing abuse, service security and performance
  • Consent (Art. 6(1)(a)) where required: certain analytics/diagnostic features or marketing

12. Your Choices for Analytics/Diagnostics

You may request that we disable linking of diagnostic events to your identity or delete previously linked diagnostic data by contacting us at niko@amplifychallenge.com. You may also opt out of marketing communications at any time via unsubscribe links or by contacting us.

13. Contact

MHKI Academy Oy

📍 Pulttitie 20, 00880 Helsinki, Finland

📧 niko@amplifychallenge.com

© 2025 MHKI Academy Oy. “Amplify” is a registered trademark of MHKI Academy Oy.