FuryHack
Courses on IT security and ethical hacking
Privacy policy
Last updated: 5 September 2026
FuryHack delivers IT security course content. The app requests no system permissions: no location, no camera, no microphone, no notifications. An account is optional — you can also purchase and learn without one; in that case the app creates a random device identifier that is not linked to any person.
1. Data controller
- Company
- Babala Özdemir (Einzelunternehmen)
- Address
- Unterer Rainweg 22
4414 Füllinsdorf
Schweiz - info@babala.ch
- Phone
- 076 222 45 99
- Company ID
- CHE-322.105.560
- App identifier
- iOS: ch.babala.furyhack
We have not appointed a data protection officer or an EU representative because we do not reach the relevant thresholds. Please address all requests to the contact above.
2. What data we process
| Data | Purpose | Stored where | Retention |
|---|---|---|---|
| E-mail address and password (hashed) — only with an account | Login and progress across devices | Our server (EU data centre) | Until you delete your account |
| Random device identifier — when used without an account | Unlocking the subscription on this device | Device and server | Until the subscription ends |
| Learning progress, exam results, issued certificates | Resuming the course and proving completion | Our server | Until you delete your account |
| Subscription receipt | Verifying the term; statutory retention | Our server; verified with Apple | 10 years (accounting obligation) |
What we explicitly do not collect
- No system permissions: no location, no camera, no microphone, no contacts
- No push notifications — the app registers no device token
- No advertising, no advertising ID, no analytics SDK, no cross-app tracking
- No payment instrument data — the purchase runs entirely through Apple
3. Permissions on your device
The app does not request any special system permissions.
4. Legal bases
We process personal data under the Swiss Federal Act on Data Protection (revFADP). Where the GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b) GDPR) — everything needed for the app to deliver the function you requested.
- Legitimate interests (Art. 6(1)(f) GDPR) — secure and stable operation, abuse prevention, troubleshooting.
- Consent (Art. 6(1)(a) GDPR) — this app requests no special system permissions, so no separate consent is required.
- Legal obligation (Art. 6(1)(c) GDPR) — in particular commercial and tax retention duties for payments.
5. Recipients and third parties
We do not sell data and do not disclose it for advertising purposes. Data is disclosed only to the following parties, and only where required for operation:
| Recipient | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Gunzenhausen (Germany), data centre inside the EU | Operation of our servers. Hetzner processes data solely on our behalf and is contractually bound to confidentiality. |
| Apple Inc. / Apple Distribution International Ltd. | Cupertino (USA) / Cork (Ireland) | App Store distribution, processing of in-app purchases and subscriptions, and crash reports if you have enabled them with Apple. |
Authorities and courts receive data only where we are legally obliged to provide it.
Transfers abroad
Some of the recipients listed above process data outside Switzerland and the EEA, in particular in the United States. We base such transfers on the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the FDPIC and, where applicable, on the EU-US Data Privacy Framework. We will provide information on the safeguards in place on request.
6. Retention and deletion
Account, progress and certificates remain until you delete your account. When used without an account only the random device identifier and subscription status are stored; they expire with the subscription. Purchase records are kept for 10 years (accounting duty). Server logs expire after 14 days.
Step-by-step instructions are available at Delete data.
7. Children and young people
This app is not directed at children. We do not knowingly collect personal data from children under 16. If we learn that such data has been submitted without parental consent, we delete it without delay.
8. Data security
Wherever the app transmits data at all, connections are encrypted via HTTPS/TLS. On the server side we use access restrictions, tenant separation and regular backups. Nobody can, however, guarantee absolute security for data transmission over the internet.
9. Your rights
- Access to the personal data we process
- Rectification of inaccurate data
- Erasure or destruction of your data
- Restriction of and objection to processing
- Receiving or porting your data in a common format
- Withdrawal of consent with effect for the future
An informal message to info@babala.ch or a call to 076 222 45 99. We normally respond within 30 days. To verify your identity we may request suitable proof. You may also lodge a complaint with a supervisory authority (Switzerland: FDPIC; EU: your competent authority).
10. Changes to this policy
We may adapt this policy when the app or the legal framework changes. The version published on this page, with the date shown above, is the applicable one. We announce material changes inside the app.
← Back to the app overview