Your data is never sold, rented or handed over. Only three providers have access to it, each for a specific task: OVH, for delivering outgoing email; Indy, for bookkeeping and for invoicing sales made on a quote; Stripe, for card payment of the subscription and the matching invoice. None of the three has access to student data.
Stripe is only involved if you pay by card; a sale made on a quote does not go through it. It then receives the name and email address of your teacher account, followed by the billing address and, if you provide one, the VAT number you enter on its payment page. Your card details are entered directly with Stripe: they never pass through our servers and we have no access to them. For its own legal obligations, notably fraud and money-laundering prevention, Stripe acts as an independent controller, and its own privacy policy then applies.
OVH and Indy are established in the European Union, and the data they process does not leave it. Stripe contracts from Ireland (Stripe Payments Europe, Limited), but part of the payment data is processed in the United States by Stripe, Inc.: this transfer relies on the European Commission's adequacy decision on the EU–US Data Privacy Framework, to which Stripe, Inc. has self-certified, and on standard contractual clauses.
No request leaves your browser towards a third party: no analytics, no social network button, no typeface loaded from elsewhere. Everything a page of this site displays is served from our own servers, and an automated check replayed on every change forbids an external resource from coming back without this sentence being corrected. One clarification about card payment: it takes you off this site to a page served by Stripe, and brings you back once the payment is completed or abandoned.