Controller and scope
AGENTIC SYSTEMS S.R.L. is the data controller for personal data processed through Agentic AI Automation Academy. This policy covers the public website, student accounts, course access, purchases, support, security, analytics, and academy communications. We do not sell personal data.
Data we process
We may process your name, email address, authentication and account records, enrollment, lesson progress, saved lesson work, download access, final-project records, support messages, consent records, and limited security or analytics events. We also process purchase status, amount, currency, billing country or region, Stripe customer and checkout references, tax information supplied at checkout, refund or dispute state, and related support records. Stripe handles card details; the academy does not store raw card numbers.
Cloudflare Turnstile and our hosting or security providers may receive technical request data, such as IP address, browser, device, request time, hostname, and challenge result, to detect abuse and protect forms and accounts.
Why we use it
- Contract: to create accounts, provide lessons, save progress, deliver downloads, process purchases, and provide support.
- Legal obligation: to keep tax, accounting, consumer, refund, dispute, fraud, and compliance records.
- Legitimate interests: to secure the academy, prevent abuse, diagnose failures, respond to support, and improve course reliability using proportionate data.
- Consent: for optional marketing email and optional first-party audience measurement, including campaign attribution. You can withdraw consent without affecting earlier lawful processing.
Required and optional data
An email address and authentication data are required to create an account. Purchase and billing data requested by Stripe are required to complete a paid order. Without them, we cannot create the account, complete the payment, or grant paid access. Lesson progress, optional project submissions, marketing signup, and audience measurement are optional. Declining optional processing does not block the two public lessons or an existing purchase.
Cookies and measurement
- Essential account cookies: Supabase session cookies keep login and account access working and expire with the configured session or when you sign out.
- Campaign attribution:
aaa_marketing_attributionstores a signed, sanitized campaign record for up to 30 days only after you allow it. - Audience choice:
aaa_marketing_consentremembers allow or decline for up to 12 months. You can clear it below. - Consented visitor:
aaa_analytics_visitoris a signed random first-party identifier kept for up to 90 days. Its raw value is never stored in analytics; it is converted to a keyed pseudonymous value before an event is written. - Consented session:
aaa_analytics_sessionseparates visits into 30-minute sessions so we can distinguish first-time and returning use without using an email address. - Vercel Web Analytics: provides aggregated page statistics without third-party cookies. We do not send email addresses or payment identifiers in analytics events.
- Security: Cloudflare may use short-lived challenge data or security cookies when needed to distinguish people from abusive traffic.
No advertising pixel is currently loaded. If advertising tracking is introduced later, this policy and the consent interface must be updated before it is enabled. Read the separate Cookie and Measurement Notice for the current inventory.
Optional starter series and marketing email
If you request the free starter series, we record your email address, the form and consent version you accepted, source page, consent time, confirmation status, sequence position, and limited delivery status. We send the series only after you use a confirmation link that expires after 48 hours. The confirmation secret is stored as a one-way hash and is cleared after use or expiry.
Marketing unsubscribe links use an opaque signed token and do not place your email address in the URL. Unsubscribing immediately suppresses future marketing messages without removing your account, course access, purchase records, or necessary transactional email.
Recipients and service providers
We use Supabase for authentication, database, and storage; Vercel for hosting and aggregated web analytics; Stripe for payment, tax, fraud, and billing services; Cloudflare for domain, email routing, and security services; Mailjet for transactional and consented marketing email; and Google for the receiving mailbox used by the support desk. Mux is used only where protected video delivery is enabled. These providers receive only the data needed for their role and may also process limited data as independent controllers under their own notices, particularly for regulated payment, fraud, or account-security purposes.
International transfers
Some providers or subprocessors may process data outside the European Economic Area. Where a transfer requires safeguards, we rely on an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism included in the provider agreement. Contact support to request information about the safeguard relevant to a particular provider.
Retention
- Account, enrollment, and course-progress records are retained while the account and purchased access remain active, unless a valid deletion request or legal requirement changes that period.
- Purchase, legal-acceptance, tax, invoice, refund, and dispute records are retained for the period required by Romanian accounting, tax, consumer, and limitation rules.
- Closed support records are reviewed for deletion after 24 months unless they are needed for an active access, payment, legal, or security issue.
- Security events and pseudonymous first-party analytics events are reviewed for deletion or aggregation after 13 months unless an incident or legal claim requires longer retention. The consented visitor cookie itself expires after no more than 90 days.
- Unconfirmed marketing requests are reviewed after the confirmation link expires. Confirmed marketing data is kept until unsubscribe; minimal consent and suppression evidence may then be retained for up to three years to prove and honor the choice.
A legal hold, active dispute, fraud investigation, or statutory recordkeeping duty may extend a period. When the reason ends, the record returns to the normal deletion review.
Security and data minimization
We use access controls, row-level database policies, private media delivery, expiring signed links, server-side authorization, abuse protection, and reasonable technical and organizational safeguards. No online service can promise zero risk. Students should not send API keys, passwords, tokens, private client data, sensitive customer data, or unredacted logs through support, lesson work, project submissions, or screenshots.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. We do not use solely automated decisions that produce legal or similarly significant effects. Submit a request through support or email the address below. We may verify identity before disclosing or changing account data and will respond without undue delay, normally within one month as required by GDPR.
You may lodge a complaint with the Romanian supervisory authority, ANSPDCP, or your local supervisory authority. ANSPDCP information and its complaint route are available at dataprotection.ro.
Policy updates
We may update this policy when the academy, providers, retention rules, or legal requirements change. Material changes will be dated here and communicated where required.
Academy operator
AGENTIC SYSTEMS S.R.L.
Bulevardul Pipera nr. 84D, Voluntari, Ilfov, Romania
Trade register: J2026041331006
Tax identification number (CUI): 55009198
EUID: ROONRC.J2026041331006
Contact: support@agenticautomationacademy.com