Legal & Transparency
Privacy Policy
Last updated: August 28, 2026
Our Core Privacy Commitments
We never sell, rent, monetize, or trade your personal data, email address, or browsing habits to advertisers or data brokers.
We use zero invasive third-party ad tracking pixels or cross-site fingerprinting scripts.
All payments are processed off-site by Stripe. AutomateSQL never sees or stores your credit card numbers.
1. Who We Are & Data Controller
This Privacy Policy applies to AutomateSQL LLC ("AutomateSQL", "we", "us", or "our"), operating the website automatesql.com. AutomateSQL LLC acts as the Data Controller under the EU General Data Protection Regulation (GDPR) and UK Data Protection Act 2018.
If you have any questions or wish to exercise your legal data rights, contact us directly at our contact page or by submitting a request through our contact form.
2. Information We Collect & How We Collect It
A. Account & Identity Data
When you create an account, request a magic link, or enroll in a course, we collect your email address, name (if provided), and password hash (encrypted via strong one-way hashing).
B. Course Progress & Community Contributions
To provide a seamless learning experience, we record your chapter completion checkpoints, discussion comments posted in student forums, and technical questions submitted to Dave AI Lab Assistant (with telemetry IPs anonymized via salted SHA-256 hashes).
C. Payment & Transaction Details
Purchases are tokenized and processed directly by Stripe Inc. We store transaction IDs, purchased course entitlements, duration labels, and invoice records for legal tax compliance.
3. Lawful Bases for Processing (GDPR Article 6)
We process your personal data strictly under valid legal grounds:
- Contractual Necessity (Art. 6(1)(b)): To process purchases, grant course access, authenticate student logins, and provide downloadable IaC codebase assets.
- Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent unauthorized account sharing, enforce API rate-limits, and improve Dave AI grounding accuracy.
- Consent (Art. 6(1)(a)): When you voluntarily subscribe to our educational newsletter or opt-in to technical updates. You may withdraw consent at any time.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction tax and VAT receipts to comply with statutory accounting and financial regulations.
4. Authorized Sub-Processors (GDPR Article 28)
We only share data with essential infrastructure partners bound by strict Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs):
| Partner | Role / Purpose | Location | Compliance Mechanism |
|---|---|---|---|
| Supabase Inc. | Database, User Auth & Vector Embeddings | USA / EU | DPA / SOC 2 Type II / SCCs |
| Stripe Inc. | Checkout & Payment Processing | USA / EU | PCI-DSS Level 1 / DPA |
| Resend Inc. | Transactional & Magic Link Emails | USA | DPA / GDPR Addendum |
| Cloudflare Inc. | Video Streaming & Edge CDN | USA / Global | DPA / ISO 27001 |
| Vercel Inc. / GCP | Web Hosting & Serverless Compute | USA / Global | DPA / SOC 2 / SCCs |
5. Cookies & Local Storage (ePrivacy Directive)
We only use Strictly Necessary Functional Cookies required for site security and session management:
auth_session: Encrypted token identifying your active login session.student_email: Resolves enrollment permissions across chapters.admin_mfa_verified: Cryptographically verified administrator MFA session.
Because these cookies are strictly essential for platform operation, they do not require opt-in tracking consent banners under the ePrivacy Directive.
6. Your Statutory Rights (GDPR & CCPA)
Under GDPR (Articles 15–22) and California CCPA/CPRA, you possess the following rights:
Request a complete, machine-readable copy of your personal data and learning history.
Request the permanent deletion of your user account, comments, and learning records.
Update inaccurate or incomplete profile and contact details.
Unsubscribe from any newsletter communication via the 1-click link in any email footer.
To exercise any of these rights, please submit a request through our contact page. We respond to and fulfill all verified requests within 30 days at zero cost.
7. Data Retention & Security Safeguards
We retain personal account information only for as long as your account remains active. If you request account deletion, your records across learning checkpoints, comments, and sessions are immediately erased. Transaction receipts are retained for 7 years strictly to satisfy statutory tax obligations.
All web and API traffic is encrypted in transit using HTTPS (TLS 1.2/1.3), and all database records, storage buckets, and automated backups are encrypted at rest using AES-256 on Supabase cloud infrastructure.
