Privacy

Privacy Policy

Last updated August 13, 2026. For account, access, or policy questions, contact support.

Controller and scope

AGENTIC SYSTEMS S.R.L. is the data controller for personal data processed through Agentic AI Automation Academy. This policy covers the public website, student accounts, course access, purchases, support, security, analytics, and academy communications. We do not sell personal data.

Data we process

We may process your name, email address, authentication and account records, enrollment, lesson progress, saved lesson work, download access, final-project records, support messages, consent records, and limited security or analytics events. We also process purchase status, amount, currency, billing country or region, Stripe customer and checkout references, tax information supplied at checkout, refund or dispute state, and related support records. Stripe handles card details; the academy does not store raw card numbers.

Cloudflare Turnstile and our hosting or security providers may receive technical request data, such as IP address, browser, device, request time, hostname, and challenge result, to detect abuse and protect forms and accounts.

Why we use it

  • Contract: to create accounts, provide lessons, save progress, deliver downloads, process purchases, and provide support.
  • Legal obligation: to keep tax, accounting, consumer, refund, dispute, fraud, and compliance records.
  • Legitimate interests: to secure the academy, prevent abuse, diagnose failures, respond to support, and improve course reliability using proportionate data.
  • Consent: for optional marketing email and optional first-party audience measurement, including campaign attribution. You can withdraw consent without affecting earlier lawful processing.

Required and optional data

An email address and authentication data are required to create an account. Purchase and billing data requested by Stripe are required to complete a paid order. Without them, we cannot create the account, complete the payment, or grant paid access. Lesson progress, optional project submissions, marketing signup, and audience measurement are optional. Declining optional processing does not block the two public lessons or an existing purchase.

Cookies and measurement

  • Essential account cookies: Supabase session cookies keep login and account access working and expire with the configured session or when you sign out.
  • Campaign attribution: aaa_marketing_attribution stores a signed, sanitized campaign record for up to 30 days only after you allow it.
  • Audience choice: aaa_marketing_consent remembers allow or decline for up to 12 months. You can clear it below.
  • Consented visitor: aaa_analytics_visitor is a signed random first-party identifier kept for up to 90 days. Its raw value is never stored in analytics; it is converted to a keyed pseudonymous value before an event is written.
  • Consented session: aaa_analytics_session separates visits into 30-minute sessions so we can distinguish first-time and returning use without using an email address.
  • Vercel Web Analytics: provides aggregated page statistics without third-party cookies. We do not send email addresses or payment identifiers in analytics events.
  • Security: Cloudflare may use short-lived challenge data or security cookies when needed to distinguish people from abusive traffic.

No advertising pixel is currently loaded. If advertising tracking is introduced later, this policy and the consent interface must be updated before it is enabled. Read the separate Cookie and Measurement Notice for the current inventory.

Optional starter series and marketing email

If you request the free starter series, we record your email address, the form and consent version you accepted, source page, consent time, confirmation status, sequence position, and limited delivery status. We send the series only after you use a confirmation link that expires after 48 hours. The confirmation secret is stored as a one-way hash and is cleared after use or expiry.

Marketing unsubscribe links use an opaque signed token and do not place your email address in the URL. Unsubscribing immediately suppresses future marketing messages without removing your account, course access, purchase records, or necessary transactional email.

Recipients and service providers

We use Supabase for authentication, database, and storage; Vercel for hosting and aggregated web analytics; Stripe for payment, tax, fraud, and billing services; Cloudflare for domain, email routing, and security services; Mailjet for transactional and consented marketing email; and Google for the receiving mailbox used by the support desk. Mux is used only where protected video delivery is enabled. These providers receive only the data needed for their role and may also process limited data as independent controllers under their own notices, particularly for regulated payment, fraud, or account-security purposes.

International transfers

Some providers or subprocessors may process data outside the European Economic Area. Where a transfer requires safeguards, we rely on an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism included in the provider agreement. Contact support to request information about the safeguard relevant to a particular provider.

Retention

  • Account, enrollment, and course-progress records are retained while the account and purchased access remain active, unless a valid deletion request or legal requirement changes that period.
  • Purchase, legal-acceptance, tax, invoice, refund, and dispute records are retained for the period required by Romanian accounting, tax, consumer, and limitation rules.
  • Closed support records are reviewed for deletion after 24 months unless they are needed for an active access, payment, legal, or security issue.
  • Security events and pseudonymous first-party analytics events are reviewed for deletion or aggregation after 13 months unless an incident or legal claim requires longer retention. The consented visitor cookie itself expires after no more than 90 days.
  • Unconfirmed marketing requests are reviewed after the confirmation link expires. Confirmed marketing data is kept until unsubscribe; minimal consent and suppression evidence may then be retained for up to three years to prove and honor the choice.

A legal hold, active dispute, fraud investigation, or statutory recordkeeping duty may extend a period. When the reason ends, the record returns to the normal deletion review.

Security and data minimization

We use access controls, row-level database policies, private media delivery, expiring signed links, server-side authorization, abuse protection, and reasonable technical and organizational safeguards. No online service can promise zero risk. Students should not send API keys, passwords, tokens, private client data, sensitive customer data, or unredacted logs through support, lesson work, project submissions, or screenshots.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. We do not use solely automated decisions that produce legal or similarly significant effects. Submit a request through support or email the address below. We may verify identity before disclosing or changing account data and will respond without undue delay, normally within one month as required by GDPR.

You may lodge a complaint with the Romanian supervisory authority, ANSPDCP, or your local supervisory authority. ANSPDCP information and its complaint route are available at dataprotection.ro.

Policy updates

We may update this policy when the academy, providers, retention rules, or legal requirements change. Material changes will be dated here and communicated where required.


Academy operator

AGENTIC SYSTEMS S.R.L.
Bulevardul Pipera nr. 84D, Voluntari, Ilfov, Romania
Trade register: J2026041331006
Tax identification number (CUI): 55009198
EUID: ROONRC.J2026041331006
Contact: support@agenticautomationacademy.com