Important: This Data Processing Agreement ("DPA") forms part of our Terms of Service and applies to all users of AI Prompting Bootcamp by Brainsful. By using our Service, you agree to these data processing terms.
1. Definitions
For the purposes of this DPA:
- "Controller": Brainsful, the entity that determines the purposes and means of processing personal data
- "Data Subject": You, the individual user of our Service
- "Personal Data": Any information relating to an identified or identifiable natural person
- "Processing": Any operation performed on personal data, including collection, storage, use, disclosure, or deletion
- "Processor": Third-party service providers who process data on our behalf
- "GDPR": General Data Protection Regulation (EU) 2016/679
- "UK GDPR": GDPR as retained in UK law
2. Scope of Processing
2.1 Subject Matter
We process your personal data to provide the AI Prompting Bootcamp service, including course delivery, payment processing, account management, and customer support.
2.2 Duration of Processing
We process your personal data for the duration of your subscription and for the retention periods specified in our Privacy Policy (generally up to 3 years after account closure for legal and accounting purposes).
2.3 Nature and Purpose of Processing
Processing activities include:
- Account creation and authentication
- Course content delivery and progress tracking
- Payment processing and billing
- Email communications (transactional and marketing with consent)
- Customer support and service improvements
- Analytics and usage statistics (with consent)
- Legal compliance and fraud prevention
2.4 Categories of Personal Data
We process the following categories of personal data:
- Identification Data: Name, email address
- Account Data: Username, password (hashed), account preferences
- Usage Data: Course progress, lesson completions, practice exercise submissions
- Payment Data: Payment method details (processed by Stripe), transaction history
- Technical Data: IP address (anonymized for analytics), browser type, device information
- Communication Data: Support tickets, email correspondence, marketing preferences
2.5 Categories of Data Subjects
- Registered users of AI Prompting Bootcamp
- Course participants and students
- Prospective customers (email inquiries only)
3. Your Rights as Data Subject
3.1 Right of Access
You have the right to request access to your personal data and receive a copy of the data we hold about you.
3.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
3.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where processing is based on consent)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Note: We may retain certain data where required by law or for legitimate business purposes (e.g., accounting, legal compliance).
3.4 Right to Restriction of Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing.
3.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
3.6 Right to Object
You have the right to object to processing of your personal data for:
- Direct marketing purposes (including profiling)
- Processing based on legitimate interests
- Processing for scientific or historical research purposes
3.7 Right to Withdraw Consent
Where processing is based on consent (e.g., marketing communications, analytics cookies), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
3.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.
3.9 How to Exercise Your Rights
To exercise any of these rights, contact us at: [email protected]
We will respond to your request within 30 days (or as required by applicable law).
4. Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption: TLS/HTTPS for data in transit, encryption at rest for databases
- Access Controls: Role-based access, authentication requirements, limited employee access
- Password Security: Bcrypt hashing for password storage
- Infrastructure Security: Secure hosting on Heroku and MongoDB Atlas with enterprise-grade security
- Regular Security Audits: Monitoring for vulnerabilities and security threats
- Data Minimization: We only collect data necessary for our services
- Pseudonymization: IP anonymization for analytics purposes
5. Sub-Processors
We engage the following sub-processors to assist in providing our Service:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Heroku Postgres | Database hosting and data storage | USA (GDPR-compliant) |
| Heroku | Application hosting | USA (GDPR-compliant) |
| Stripe | Payment processing | USA (PCI-DSS Level 1) |
| SendGrid | Email delivery (transactional & marketing) | USA (GDPR-compliant) |
| Google Analytics | Website analytics (with consent) | USA (GDPR-compliant, IP anonymization) |
All sub-processors have been assessed for GDPR compliance and have appropriate safeguards in place, including Standard Contractual Clauses where applicable.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) and United Kingdom, including the United States.
We ensure that international transfers are protected through:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms with service providers
- Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
- Appropriate Safeguards: Additional security measures to protect transferred data
- Data Processing Agreements: Binding agreements with all sub-processors
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR)
- Notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms
- Provide information about the nature of the breach, likely consequences, and measures taken or proposed
- Document all data breaches and our response
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Active Accounts: Duration of subscription
- Expired Accounts: 30 days after subscription expiration, then permanently deleted
- Marketing Data: Until consent is withdrawn or account deletion
- Payment Data: 7 years for tax and accounting compliance
- Support Communications: 2 years from last interaction
After retention periods expire, data is securely deleted or anonymized.
9. Audit Rights
Upon reasonable notice, and subject to confidentiality obligations, we will make available to you information necessary to demonstrate compliance with this DPA and applicable data protection laws.
10. Liability and Indemnification
Each party shall be liable for any damage caused by processing personal data in violation of this DPA or applicable data protection laws, except where the party proves it is not responsible for the event giving rise to the damage.
11. Termination
This DPA remains in effect for as long as we process your personal data. Upon termination of our relationship:
- We will delete or return all personal data (except where retention is required by law)
- We will delete existing copies of personal data (unless legal retention is required)
- We will certify deletion upon request
12. Changes to This DPA
We may update this DPA to reflect changes in data protection laws, our processing activities, or business practices. Material changes will be communicated with at least 30 days' notice.
13. Governing Law
This DPA is governed by:
- EU/EEA Users: GDPR and the laws of the Republic of Ireland
- UK Users: UK GDPR and the laws of England and Wales
- US Users: Applicable federal and state data protection laws
Contact for Data Processing Matters
For questions, concerns, or to exercise your data subject rights, please contact:
- Email: [email protected]
- Subject Line: "Data Processing Request" or "GDPR Request"
- Response Time: Within 30 days of receipt
Company Information:
- Data Controller: Brainsful
- Service: AI Prompting Bootcamp
Legal Notice: This Data Processing Agreement is provided in English. If translated into other languages, the English version shall prevail in case of any conflicts or discrepancies.