AUTOMATESQL

Legal & Transparency

Privacy Policy

Last updated: August 28, 2026

Our Core Privacy Commitments

Zero Data Selling

We never sell, rent, monetize, or trade your personal data, email address, or browsing habits to advertisers or data brokers.

No Ad Trackers

We use zero invasive third-party ad tracking pixels or cross-site fingerprinting scripts.

PCI Level 1 Billing

All payments are processed off-site by Stripe. AutomateSQL never sees or stores your credit card numbers.

1. Who We Are & Data Controller

This Privacy Policy applies to AutomateSQL LLC ("AutomateSQL", "we", "us", or "our"), operating the website automatesql.com. AutomateSQL LLC acts as the Data Controller under the EU General Data Protection Regulation (GDPR) and UK Data Protection Act 2018.

If you have any questions or wish to exercise your legal data rights, contact us directly at our contact page or by submitting a request through our contact form.

2. Information We Collect & How We Collect It

A. Account & Identity Data

When you create an account, request a magic link, or enroll in a course, we collect your email address, name (if provided), and password hash (encrypted via strong one-way hashing).

B. Course Progress & Community Contributions

To provide a seamless learning experience, we record your chapter completion checkpoints, discussion comments posted in student forums, and technical questions submitted to Dave AI Lab Assistant (with telemetry IPs anonymized via salted SHA-256 hashes).

C. Payment & Transaction Details

Purchases are tokenized and processed directly by Stripe Inc. We store transaction IDs, purchased course entitlements, duration labels, and invoice records for legal tax compliance.

3. Lawful Bases for Processing (GDPR Article 6)

We process your personal data strictly under valid legal grounds:

  • Contractual Necessity (Art. 6(1)(b)): To process purchases, grant course access, authenticate student logins, and provide downloadable IaC codebase assets.
  • Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent unauthorized account sharing, enforce API rate-limits, and improve Dave AI grounding accuracy.
  • Consent (Art. 6(1)(a)): When you voluntarily subscribe to our educational newsletter or opt-in to technical updates. You may withdraw consent at any time.
  • Legal Obligation (Art. 6(1)(c)): Retaining transaction tax and VAT receipts to comply with statutory accounting and financial regulations.

4. Authorized Sub-Processors (GDPR Article 28)

We only share data with essential infrastructure partners bound by strict Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs):

PartnerRole / PurposeLocationCompliance Mechanism
Supabase Inc.Database, User Auth & Vector EmbeddingsUSA / EUDPA / SOC 2 Type II / SCCs
Stripe Inc.Checkout & Payment ProcessingUSA / EUPCI-DSS Level 1 / DPA
Resend Inc.Transactional & Magic Link EmailsUSADPA / GDPR Addendum
Cloudflare Inc.Video Streaming & Edge CDNUSA / GlobalDPA / ISO 27001
Vercel Inc. / GCPWeb Hosting & Serverless ComputeUSA / GlobalDPA / SOC 2 / SCCs

5. Cookies & Local Storage (ePrivacy Directive)

We only use Strictly Necessary Functional Cookies required for site security and session management:

  • auth_session: Encrypted token identifying your active login session.
  • student_email: Resolves enrollment permissions across chapters.
  • admin_mfa_verified: Cryptographically verified administrator MFA session.

Because these cookies are strictly essential for platform operation, they do not require opt-in tracking consent banners under the ePrivacy Directive.

6. Your Statutory Rights (GDPR & CCPA)

Under GDPR (Articles 15–22) and California CCPA/CPRA, you possess the following rights:

Right to Access & Portability:

Request a complete, machine-readable copy of your personal data and learning history.

Right to Erasure ("Be Forgotten"):

Request the permanent deletion of your user account, comments, and learning records.

Right to Rectification:

Update inaccurate or incomplete profile and contact details.

Right to Withdraw Consent:

Unsubscribe from any newsletter communication via the 1-click link in any email footer.

To exercise any of these rights, please submit a request through our contact page. We respond to and fulfill all verified requests within 30 days at zero cost.

7. Data Retention & Security Safeguards

We retain personal account information only for as long as your account remains active. If you request account deletion, your records across learning checkpoints, comments, and sessions are immediately erased. Transaction receipts are retained for 7 years strictly to satisfy statutory tax obligations.

All web and API traffic is encrypted in transit using HTTPS (TLS 1.2/1.3), and all database records, storage buckets, and automated backups are encrypted at rest using AES-256 on Supabase cloud infrastructure.