KAMPSTER PRIVACY POLICY

Last Updated: May 29, 2026

1. INTRODUCTION

The Kampster Service is operated by Kampster DOO (Serbia), which is the data controller responsible for your personal data, together with its affiliated company Kampster Pte. Ltd. (Singapore), which sells and distributes subscriptions to you and acts as an independent (or joint) data controller for sales and billing data. In this Privacy Policy, "Kampster," "we," "us," or "our" refers to Kampster DOO as data controller.

Kampster respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered Learning Management System, including our website at https://kampster.com, our mobile applications distributed through the Apple App Store and Google Play Store, and related applications (collectively, the "Service").

Please read this Privacy Policy carefully. By accessing or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this document. If you do not agree with our policies and practices, please do not use our Service.

2. CONTROLLER, REPRESENTATIVE & CONTACTS

Data Controller:

  • Kampster DOO
  • Vladimira Popovića 38–40, 11070 Beograd (Novi Beograd), Serbia
  • Company registration number (MB): 21312401
  • Tax ID (PIB): 110181684
  • Email: legal@kampster.com

Affiliated seller / controller (sales & distribution):

  • Kampster Pte. Ltd.
  • 68 Circular Road, #02-01, 049422, Singapore
  • UEN: 202523773R

Kampster Pte. Ltd. is the seller/distributor of subscriptions and acts as an independent (or joint) data controller for the sales and billing data it processes, under an intercompany agreement with Kampster DOO. As Singapore is outside the EEA, transfers are covered by appropriate safeguards (see Section 7.5).

EU Representative (GDPR Article 27):

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • European Union (EU)

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/19848992175

Data Protection contact / DPO:

3. DATA WE COLLECT

We collect several types of information from and about users of our Service:

3.1 Personal Data

Personal data refers to any information that identifies or can be used to identify you directly or indirectly. We may collect the following personal data:

  • Account Information: Name, email address, username, profile picture
  • Contact Information: Address, phone number, country of residence
  • Payment Information: Credit card details, billing address, payment history (processed by our payment processor)
  • Educational Information: Learning history, course progress, completion records, assessment scores
  • Professional Information: Occupation, employer, professional goals (if provided by you)

3.2 Proctoring and Test Data (Organisational/B2B feature only)

Proctoring is an optional feature available only to organisational (business) customers and only where that organisation has explicitly enabled it. It is not used in standard or individual (consumer) learning, courses, or assessments. Where an organisation enables proctoring for an assessment, the organisation acts as the data controller and Kampster acts as a data processor on its behalf. The legal basis for the processing, the collection of any consent, and the retention period (including the 30-day period referenced below, which is a default the organisation may vary) are determined by the organisation under its agreement with Kampster, not by this Privacy Policy.

Where proctoring is enabled, and only during an active, clearly-notified test session for which you have given explicit prior consent, the following may be collected to ensure test integrity: photographs/video of you, audio of your environment, behavioural data (mouse, keyboard, keystroke timing), biometric data (e.g. facial recognition, eye-movement patterns — special-category data processed only on the basis of your explicit consent), screen activity, and related device data. Proctoring data is retained for 30 days for audit purposes and then deleted (see Section 8).

If you use Kampster as an individual consumer, proctoring does not apply to you.

3.3 Usage Data

We automatically collect certain information when you access or use our Service:

  • Interaction Data: Learning activities, content viewed, features used, time spent on platform
  • AI Interaction Data: Queries submitted to AI tutors, responses received, feedback provided
  • Device and Connection Information: IP address, browser type, operating system, device information
  • Log Data: Access times, pages viewed, features used, crashes, system activity
  • Location Data: General location information derived from IP address

3.4 Authentication Data

We collect data related to account access and security:

  • Login Data: Email addresses used for OTP (One-Time Password) authentication
  • Session Data: Login timestamps, device information, session duration
  • Security Data: Failed login attempts, suspicious activity patterns

3.5 Cookies and Similar Technologies

We use cookies and similar tracking technologies to collect and store information about your interactions with our Service. For more detailed information about our use of cookies, please see our Cookie Policy.

4. HOW WE COLLECT YOUR DATA

We collect data through various methods:

4.1 Direct Collection

  • Information you provide when creating an account
  • Information you provide when subscribing to our Service
  • Profile information you enter in your account settings
  • Content you submit when using our AI tutoring features
  • Consent provided before proctored tests
  • Responses to surveys or feedback forms
  • Communications with our customer support team

4.2 Automated Collection

  • Through cookies and similar tracking technologies
  • Through server logs and analytics tools
  • Through AI system interactions and feedback mechanisms
  • Through proctoring software during tests
  • When you access our Service through different devices

4.3 Third-Party Sources

  • Payment processors
  • Authentication services (if you use third-party sign-in options)
  • Analytics providers

5. HOW WE USE YOUR DATA

We use your personal data for the following purposes:

5.1 Service Provision and Enhancement

  • To create and manage your Kampster account
  • To provide and personalize our educational services
  • To process payments and manage subscriptions
  • To deliver appropriate educational content based on your learning patterns
  • To improve and optimize our Service and educational content
  • To develop new features, products, and services
  • To send login OTP codes via email

5.2 AI-Specific Processing

  • To personalize AI responses to your learning needs
  • To analyze patterns in AI interactions to enhance educational effectiveness
  • To identify and fix potential issues with AI-generated content

We do not use your personal data, queries, or AI interactions to train AI models, whether our own or those of third parties. Our AI features run on third-party models under zero-data-retention terms: your prompts and the generated responses are not retained by the model providers after a request is processed and are not used for model training.

5.3 Proctoring and Test Integrity (Organisational/B2B feature only)

Where an organisational customer has enabled proctoring (see Section 3.2), and only during active proctored sessions, data may be used to verify identity, detect cheating or unauthorized assistance, analyse behavioural patterns, and maintain the integrity and validity of test results. For proctoring, Kampster acts as a data processor on behalf of the organisational customer (the controller), and the purposes, legal basis, and retention are governed by that organisation's agreement. This does not apply to individual consumer use of the Service.

5.4 Communications

  • To send administrative messages about your account or the Service
  • To provide customer support and respond to inquiries
  • To send updates about our Service, including feature updates
  • To send promotional and marketing communications (only where you have given opt-in consent)
  • To send educational recommendations based on your learning patterns
  • To send email newsletters and reminders (only where you have given opt-in consent; you may withdraw consent at any time)
  • To verify your identity and prevent fraud
  • To enforce our Terms of Service
  • To protect the security and integrity of our Service
  • To comply with applicable laws and regulations
  • To respond to legal requests from public authorities
  • To establish, exercise, or defend legal claims

We process your personal data on the following legal bases:

6.1 Performance of Contract

Processing necessary for the performance of our contract with you to provide the Service.

6.2 Legitimate Interests

Processing necessary for our legitimate interests, provided these interests are not overridden by your rights and freedoms. Our legitimate interests include:

  • Improving and personalizing our Service
  • Ensuring the security of our platform
  • Analyzing aggregated, de-identified usage to improve platform reliability and educational content
  • Marketing our services to existing customers
  • Maintaining test integrity and preventing fraud

Processing based on your specific consent, such as:

  • Sending marketing communications
  • Using analytics and marketing cookies (see our Cookie Policy)
  • Collecting proctoring data during tests (organisational/B2B feature only)

Where proctoring is enabled by an organisational customer, any biometric data (such as facial-recognition data) is special-category data processed solely on the basis of your explicit consent (GDPR Article 9(2)(a)). You may refuse, in which case you will not take the proctored assessment.

Processing necessary to comply with our legal obligations under the Serbian Law on Personal Data Protection (ZZPL), the EU General Data Protection Regulation (GDPR), and other applicable laws.

7. DATA SHARING AND RECIPIENTS

We may share your personal data with the following categories of recipients:

7.1 Service Providers

We share information with third parties that help us operate, provide, improve, and market our Service:

  • Kampster Pte. Ltd. (Singapore) — our affiliated company, which sells and distributes subscriptions and acts as an independent (or joint) controller for sales and billing data (transfer covered by safeguards in Section 7.5)
  • Stripe — payment processing for web-based subscriptions. Stripe collects payment card details, billing address, and transaction data, and acts as a processor and as an independent controller for payment fraud prevention. See https://stripe.com/privacy
  • RevenueCat — subscription management and in-app purchase processing for our mobile applications. Collects device identifiers, purchase history, subscription status, and approximate location (via IP). Acts as a processor on our behalf. See https://www.revenuecat.com/privacy
  • Hosting & infrastructure — Vercel (hosting, file/blob storage, and cookieless analytics), Cloudflare (CDN and private object storage), PlanetScale (database, EU region), and Upstash (Redis cache/queue, EU region). These act as processors and store data primarily in the EU.
  • Analytics providers — Vercel Web Analytics (cookieless)
  • Customer support and communication tools
  • Advertising & Marketing Partners — where you give consent, we use advertising/marketing tools (currently the Meta/Facebook Pixel, on our website only; the current list is available in our Cookie Settings). For some of these, we and the partner act as joint controllers for the collection and onward transmission of the relevant data; the essence of these arrangements is available on request. These tools load only with your consent (see our Cookie Policy).

We may disclose your information where required by law, regulation, or legal process.

7.3 Business Transfers

If Kampster is involved in a merger, acquisition, or sale of all or a portion of its assets, your personal data may be transferred as part of that transaction.

We may share your information with third parties when you have given us your consent to do so.

7.5 International Transfers

Your personal data may be transferred to, and processed in, countries other than your country of residence, including Serbia (where our controller and operations team are located), Singapore (our affiliated seller and independent/joint controller), and the United States (certain sub-processors).

Safeguards. Serbia and Singapore are not the subject of an EU adequacy decision. Where we transfer personal data outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR — principally the European Commission's Standard Contractual Clauses (SCCs) — and, for US-based providers participating in it, the EU-US Data Privacy Framework (DPF). Each processor handles your personal data under a data processing agreement that incorporates these safeguards. You may request a copy of the relevant safeguards by contacting legal@kampster.com.

EU Data Storage. We store personal data primarily in the EU region through our hosting and database providers (e.g. PlanetScale and Upstash in the EU). Data may be accessed from Serbia and Singapore for operational purposes under the safeguards above.

8. DATA RETENTION

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account Data: 2 years after account deletion
  • Learning Progress: 1 year after account deletion
  • Proctoring Data (organisational/B2B feature only): 30 days from test completion, then deleted
  • Billing Records: 7 years for tax and audit compliance
  • Marketing Data: Until you opt-out or 2 years after account deletion
  • Aggregated/De-identified Analytics: Retained in aggregated, non-identifying form for service improvement (we do not retain AI training data, as we do not train models on user data)

When determining retention periods, we consider:

  • The amount, nature, and sensitivity of the personal data
  • The potential risk of harm from unauthorized use or disclosure
  • The purposes for which we process the data
  • Whether we can achieve those purposes through other means
  • Applicable legal, accounting, or reporting requirements

9. COOKIES AND TRACKING TECHNOLOGIES

9.1 What Are Cookies

Cookies are small text files that are placed on your device when you visit our website. We use cookies and similar technologies to:

  • Enable core functionality of our Service
  • Remember your preferences and settings
  • Authenticate users and prevent fraud
  • Analyze how our Service is used
  • Personalize your experience
  • Measure the effectiveness of our marketing

9.2 Types of Cookies We Use

  • Strictly Necessary: required for the operation of our Service (no consent needed)
  • Analytics: help us understand how the Service is used (cookieless; loaded only with your consent)
  • Marketing / Advertising: used, only with your consent, by our advertising partners (currently the Meta/Facebook Pixel, web only)

Analytics and Marketing cookies are off by default and load only after you opt in.

You can accept or reject non-essential cookies via our cookie banner and change your choice at any time through "Cookie Settings" in our website footer, which also lists the current third-party tools in use. You can additionally manage cookies through your browser settings. See our Cookie Policy for full details.

10. DATA SECURITY

We have implemented appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of personal data where appropriate
  • Regular testing of security systems and processes
  • Access controls and authentication procedures
  • Staff training on data protection and security
  • Regular backups of our systems
  • Secure data centers with physical security measures
  • Multi-factor authentication for administrative access

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

11. AI-SPECIFIC DATA PRACTICES

As an AI-powered Learning Management System, we have specific data practices related to our AI technology:

11.1 AI Models and Your Data

  • We use third-party AI models to provide tutoring and generate educational content
  • These models operate under zero-data-retention terms: your prompts and the responses are not stored by the providers after the request is processed
  • We do not use your personal data, conversations, or AI interactions to train AI models, whether our own or those of third parties
  • We may review limited aggregated or de-identified usage metrics to monitor quality and fix issues

11.2 AI Content Generation and Limitations

  • Our AI systems generate personalized educational content and responses
  • AI-generated content is based on your interactions and learning patterns
  • IMPORTANT DISCLAIMER: You acknowledge that AI-generated content may contain inaccuracies, errors, or misleading information
  • NO WARRANTY: We provide no warranty regarding the accuracy, completeness, or reliability of AI-generated content
  • USER RESPONSIBILITY: You must independently verify any important information provided by our AI systems

11.3 AI Data Processing

  • AI processing occurs in real time to generate immediate responses; we do not retain your queries or responses for model training
  • Our AI systems do not make automated decisions that have legal or similarly significant effects on you
  • Where enabled by an organisational customer, proctoring AI analyses behaviour and biometric data only during active test sessions (organisational/B2B feature only — see Section 3.2)

11.4 Third-Party AI Services

Our AI-powered features may utilize third-party AI services for content generation and tutoring. When you interact with AI tutors, your queries and relevant learning context may be processed by third-party AI service providers. This data is transmitted securely and used solely for generating educational responses. We do not share your personal identity information (such as your name, email, or account details) with these AI providers. All third-party AI service providers are contractually bound to process data only as instructed by Kampster and in accordance with applicable data protection laws. These providers operate under zero-data-retention agreements: they do not retain your prompts or the generated outputs after processing and do not use them to train their models.

12. YOUR DATA PROTECTION RIGHTS

Depending on your location, you may have the following rights regarding your personal data:

12.1 Access

You have the right to request copies of your personal data.

12.2 Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

12.3 Erasure

You have the right to request that we erase your personal data, under certain conditions.

12.4 Restriction of Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

12.5 Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

12.6 Objection

You have the right to object to our processing of your personal data, under certain conditions.

12.7 Automated Decision Making and Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

If we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.

12.9 How to Exercise Your Rights

To exercise any of these rights, please contact us at legal@kampster.com. We will respond to your request within 30 days. We may need to verify your identity before responding to your request.

12.10 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: You have the right to request information about the categories and specific pieces of personal data we have collected about you, the categories of sources from which we collect personal data, the business purposes for collecting personal data, and the categories of third parties with whom we share personal data.
  • Right to Delete: You have the right to request deletion of your personal data, subject to certain exceptions.
  • Right to Opt-Out of Sale or Sharing: Kampster does not sell your personal data. We do not share your personal data for cross-context behavioral advertising purposes.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To exercise your California privacy rights, contact us at legal@kampster.com. We will verify your identity before processing your request and respond within 45 days.

13. CHILDREN'S PRIVACY

Our Service is intended for users aged 16 and above, and we do not knowingly collect personal data from anyone under 16. Setting our minimum age at 16 also meets the highest age of digital consent applied across the EU/EEA, so consent-based processing does not rely on the personal data of children below that age.

If you are a parent or guardian and believe that a child under 16 has provided us with personal data, please contact us at legal@kampster.com and we will take steps to delete such information.

14. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. The updated policy will be posted on this page with a revised "Last Updated" date.

For material changes to this Privacy Policy, we will notify you through:

  • A notice on our website
  • An email to the address associated with your account
  • A notification when you access our Service

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

15. DATA PROTECTION OFFICER

For any questions or concerns about this Privacy Policy or our data practices, you can contact our data protection function:

16. COMPLAINTS

If you have a complaint about our use of your personal data or our response to your requests, you have the right to lodge a complaint with a supervisory authority.

Our lead supervisory authority is the Serbian data protection authority:

Commissioner for Information of Public Importance and Personal Data Protection (Poverenik) Bulevar kralja Aleksandra 15, 11000 Beograd, Serbia Website: https://www.poverenik.rs/

EU/EEA residents may also lodge a complaint with their local data protection authority, and may contact our EU representative (Prighter — https://app.prighter.com/portal/19848992175).

To the extent our affiliated company in Singapore (an independent/joint controller for sales and billing) is involved, the Singapore supervisory authority is the Personal Data Protection Commission (https://www.pdpc.gov.sg/).

17. CONTACT US

For any questions about this Privacy Policy or our data practices, please contact us at:


By using Kampster, you acknowledge that you have read and understood this Privacy Policy.