How we protect your data.
Pyyrah+ is run on third-party infrastructure that handles payments, hosting, and email. Here’s exactly what each one does, what data they see, and how we protect everything else.
How payments are handled.
Pyyrah+ uses Stripe as its payment processor for course purchases. Card data never touches Pyyrah+ infrastructure.
When you check out, you’re redirected to Stripe’s hosted checkout page. Your card details are entered directly into Stripe’s systems · we never see, store, or transmit them. The only information we receive back is a transaction ID, the amount, your email, and (where required) your billing country for tax purposes.
What Stripe handles for us
- Card and payment-method capture · all sensitive payment data lives inside Stripe
- PCI DSS Level 1 compliance · the highest level in the Payment Card Industry Data Security Standard
- 3D Secure (SCA) authentication where required by your card issuer or the EU PSD2 regulations
- Fraud detection and risk scoring on every transaction (Stripe Radar)
- Sales-tax calculation and remittance where required by jurisdiction (EU OSS, US states, etc)
What Pyyrah+ stores after a payment
- Your email address · so we can send you the receipt, the welcome email, and product updates
- A Stripe customer ID · so we can match payments to your account without storing card data
- Order metadata · product, price, currency, transaction ID, timestamp
- We do not store full card numbers, CVV codes, or expiry dates · those live only in Stripe
How we protect data we do hold.
Most of what we hold is straightforward · email addresses, account details, course progress. Here’s how it’s stored and who can reach it.
Encryption
- In transit · all browser-to-server traffic served over TLS 1.2 or higher, with HSTS enforced and modern cipher suites only
- At rest · personal data stored by our hosting and email providers is encrypted at rest using AES-256 (the standard each provider applies to all customer data)
- Passwords are never stored in plaintext · they’re hashed with a salted one-way function by the platform that holds them
Access control
- Least-privilege · staff only get access to the systems and data they need to do their job
- Two-factor authentication required on every admin account · email, hosting, payment processor, analytics
- Credentials are rotated when staff leave or when there’s any reason to suspect compromise
- Vendor access logs reviewed periodically for unusual activity
Data retention
We keep your account data while you’re an active Pyyrah+ member and for a defined period after, then delete or anonymise it. Specific retention windows are documented in the Privacy Policy. You can request earlier deletion at any time by emailing Privacy@pyyrahplus.com.
Backups
Production data is backed up regularly by our hosting providers (WordPress.com, Stripe, Klaviyo, Google). We rely on the providers’ backup schedules and restoration procedures rather than running our own backup infrastructure on top.
Our privacy & compliance posture.
Pyyrah Limited is registered in England & Wales. We apply UK GDPR & EU GDPR standards to every user worldwide, not just those in the UK or EU.
- Data controller
- Pyyrah Limited (trading as Pyyrah+), Company No. 12176473
- Registered office
- 27 Old Gloucester Street, London WC1N 3AX, United Kingdom
- Supervisory authority
- UK Information Commissioner’s Office (ICO)
- Privacy contact
- Privacy@pyyrahplus.com
- Lawful basis
- Contract (your Pyyrah+ purchase) · consent (marketing emails) · legitimate interest (analytics, security)
- International transfers
- Standard Contractual Clauses (SCCs) where data leaves the UK / EEA
Your rights under UK & EU GDPR
- Access · request a copy of the personal data we hold about you
- Rectification · correct any inaccurate or incomplete data
- Erasure · ask us to delete your data (subject to legal retention obligations)
- Restriction · pause our processing in specific circumstances
- Portability · receive your data in a machine-readable format
- Objection · object to processing for direct marketing or based on legitimate interest
- Withdrawal of consent · revoke consent at any time, for any future processing
- Complaint · lodge a complaint with the ICO (UK) or your local supervisory authority (EU)
To exercise any of these rights, email Privacy@pyyrahplus.com. We respond within 30 days, free of charge in standard cases.
Who else touches your data.
We rely on third-party providers for hosting, payment, email, and analytics. The list is fully published and kept current.
What happens if there’s a breach.
No system is incident-proof. What matters is how quickly we detect, contain, and tell you.
Our commitments under UK GDPR
- Notification to the UK Information Commissioner’s Office (ICO) within 72 hours of confirming a personal-data breach that meets the reporting threshold (UK GDPR Article 33)
- Notification to affected users directly · by email, without undue delay · when the breach is likely to result in a high risk to your rights and freedoms (UK GDPR Article 34)
- A clear description of what happened, what data was affected, what we’re doing about it, and what (if anything) we recommend you do
What we won’t do
- Bury a security incident in a quiet legal update or a footer link
- Wait for press attention before acknowledging an issue
- Send a vague "we may have been affected" email without specifics
Securing your Pyyrah+ account.
Most account compromises happen at the user end · weak passwords, reuse across sites, phishing. These habits prevent most of it.
- Use a strong, unique password · ideally generated by a password manager (1Password, Bitwarden, iCloud Keychain). Don’t reuse a password you use anywhere else
- Don’t share your login · Pyyrah+ is one account per person. Sharing credentials breaches the Acceptable Use Policy
- Check the sender on any email asking you to log in. Legitimate Pyyrah+ email comes from
@pyyrahplus.com· never@pyyrah-plus.com,@pyyrah.support, or similar - If something feels off · pause and email Support@pyyrahplus.com directly from the browser address bar, not from a link in the suspicious email
- Don’t enter your Pyyrah+ password on any page that isn’t hosted at
pyyrahplus.com. We’ll never ask you to log in via a third-party form
Found a security issue? Tell us.
If you’ve found a vulnerability in Pyyrah+, email security@pyyrahplus.com with as much detail as you can. We’ll acknowledge within 2 business days, work through it with you, and credit you (with permission) once it’s fixed. Please don’t publish details publicly until we’ve had a reasonable window to remediate.
Email security@pyyrahplus.com