Privacy policy
This page explains how data and messages are handled.
Privacy is built into the platform: we collect only what is needed, and contact details and email addresses are never displayed publicly.
Last updated: 26 July 2026
This policy explains what data the Prof. Dr. Hassan Yachou platform processes, why it is processed, how long it is retained, and the safeguards used when you browse the site, contact the platform, or request a knowledge certificate.
Scope and responsibility
This policy covers the public pages, contact form, book quizzes and certificates, and the platform’s anonymous audience measurement.
The platform manages data for the scholarly and operational purposes described below. Privacy enquiries may be submitted through the official contact page.
Data we process
Contact messages: name, email address, subject, message, and interface language. The server derives an anonymous HMAC from connection data for abuse prevention; the raw IP address is not stored.
Certificates: the submitted name, book, language, result, issue date, and serial number. After verification, the email is retained only as an HMAC and is not shown on the public certificate page.
Audience measurement: a random first-party cookie identifier, its server-side HMAC, and an approximate country code. IP addresses and browser user-agent strings are not stored for this measurement.
Why data is processed
We use data to receive and answer messages, prevent automated abuse, run book quizzes, issue and verify certificates, protect the platform, and publish aggregate indicators of content reach.
We do not sell personal data, use contact messages or email addresses for advertising, or build commercial visitor profiles.
Protection and access
Messages pass through a protected server endpoint with verification and rate limiting. Only authorized administrative roles may read them.
Database-level access policies are enforced, service credentials remain server-side, and sensitive administrative actions are recorded in an audit log.
Essential infrastructure providers, such as hosting, database, email delivery, and automated verification services, may process limited data solely to provide their service under their security settings.
Retention
A contact message is retained while needed for administrative follow-up and may be archived or deleted by an authorized administrator. Abuse-prevention hashes and attached technical metadata are cleared automatically after one day.
Certificate verification records are retained, while expired email codes and temporary quiz attempts are removed periodically.
The anonymous visitor cookie may remain for up to twelve months to count a unique visit. Non-personal aggregate statistics may be retained for reporting.
Cookies and external services
The platform uses cookies required for security, administrative sessions, and anonymous visitor counting. Turnstile may process technical signals to confirm that a request is made by a real user.
If an external measurement service requiring consent is enabled, available consent controls are applied; it is not intended to access message content or certificate data.
Your choices
You may ask about a message you submitted, request a correction, or request deletion where your connection to the message can be verified and no legitimate security or operational requirement prevents it.
You may block non-essential cookies in your browser. Blocking cookies that are strictly necessary may affect some site functions.
Updates and contact
This policy may change when platform functions or providers change. The latest revision date is shown above.
For privacy questions or responsible security reports, use the contact page. Never include passwords, secret codes, or financial information in a message.




















