Privacy Policy
Ainshtein Coaching (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, why, how we use it, who we share it with, and what rights you have. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR & Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller
The controller of your personal data is:
- Ainshtein Coaching (sole trader), operated by Nadezhda Ainshtein
- Contact: [email hidden — enable JavaScript]
- Website: https://ainshtein.com
We have not appointed a formal Data Protection Officer (DPO) as this is not a mandatory requirement for our processing activities under GDPR Art. 37. For any privacy-related question please contact us at the email above.
2. What personal data we collect
2.1 Data you provide directly
When you fill in the contact form on our website we collect:
- Your name
- Your email address
- Your phone number (optional)
- The content of your message
- Your explicit consent to processing (via a mandatory checkbox)
2.2 Data collected automatically
When you visit the website your browser sends technical data to our server (Cloudflare Pages):
- IP address (used for security & abuse protection; anonymized for analytics if you consent)
- Browser type, operating system, screen resolution
- Pages visited and time spent (only if you consent to analytics cookies)
- Referrer URL
2.3 Cookies and similar technologies
See the separate Cookie Policy for a full list of cookies we may set (only after your explicit consent for non-essential ones).
3. Purposes and legal basis for processing (GDPR Art. 6)
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Reply to your contact-form enquiry | Name, email, phone, message | Consent — GDPR Art. 6(1)(a) | Until the conversation is closed + 24 months, unless you request earlier deletion |
| Perform coaching / training services (if we enter a contract) | Contact + billing data | Contract — GDPR Art. 6(1)(b) | Duration of contract + 6 years (tax record retention) |
| Website security & abuse prevention | IP address, request headers | Legitimate interests — GDPR Art. 6(1)(f) | 30 days (Cloudflare default) |
| Analytics (page views) | IP-derived country, browser, page URL | Consent — GDPR Art. 6(1)(a) | 13 months maximum |
4. Who we share data with (processors)
We only share data with the following categories of sub-processors, each bound by a Data Processing Agreement (DPA):
- Cloudflare, Inc. — website hosting and content delivery. Data processed in worldwide edge locations; Cloudflare offers Standard Contractual Clauses (SCCs) for EU-to-US transfers. Cloudflare GDPR
- MailChannels, Inc. — transactional email delivery for contact-form submissions. MailChannels Privacy
- Yandex 360 for Business or another email provider — storage of email correspondence originating from the contact form.
We do not sell your personal data to any third party. We do not share it with advertising networks.
5. International data transfers
Some of our processors (notably Cloudflare and MailChannels) operate outside the European Economic Area. Transfers are covered by:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914);
- Additional safeguards such as encryption in transit and at rest;
- Where applicable, the EU–US Data Privacy Framework (DPF).
6. Your rights
Under GDPR / UK GDPR you have the following rights. To exercise any of them, contact us at the email above — we respond within 30 days.
- Right of access (Art. 15) — get a copy of your data.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure / “right to be forgotten” (Art. 17) — ask us to delete your data.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)) — at any time, without affecting past lawful processing.
- Right to lodge a complaint with your supervisory authority (e.g. your national Data Protection Authority in the EU, or the ICO in the UK).
6.1 California residents (CCPA/CPRA)
If you are a California resident you additionally have:
- The right to know what personal information we collect and disclose.
- The right to delete personal information collected from you.
- The right to correct inaccurate personal information.
- The right to opt-out of the sale or sharing of personal information — note that we do not sell or share your personal information as defined by CCPA.
- The right to limit the use of sensitive personal information.
- The right not to be discriminated against for exercising your rights.
7. Security
Personal data are transmitted over HTTPS (TLS 1.2+). Website assets are hosted on Cloudflare, which provides DDoS protection, bot mitigation, and edge-level security. Email delivery is authenticated via SPF and DKIM. Access to raw form submissions is limited to the site owner.
8. Children
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.
9. Changes to this policy
We may update this policy from time to time. Substantive changes will be indicated by the “Last updated” date above. Continued use of the website after an update constitutes acceptance of the revised policy.
10. Contact and complaints
For any question about this policy or to exercise your rights: [email hidden — enable JavaScript].
You can also lodge a complaint with your data-protection supervisory authority. A directory of EU authorities is available on the European Data Protection Board website.