Privacy Policy

Ainshtein Coaching (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, why, how we use it, who we share it with, and what rights you have. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR & Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA).

1. Data Controller

The controller of your personal data is:

We have not appointed a formal Data Protection Officer (DPO) as this is not a mandatory requirement for our processing activities under GDPR Art. 37. For any privacy-related question please contact us at the email above.

2. What personal data we collect

2.1 Data you provide directly

When you fill in the contact form on our website we collect:

2.2 Data collected automatically

When you visit the website your browser sends technical data to our server (Cloudflare Pages):

2.3 Cookies and similar technologies

See the separate Cookie Policy for a full list of cookies we may set (only after your explicit consent for non-essential ones).

3. Purposes and legal basis for processing (GDPR Art. 6)

PurposeDataLegal basisRetention
Reply to your contact-form enquiry Name, email, phone, message Consent — GDPR Art. 6(1)(a) Until the conversation is closed + 24 months, unless you request earlier deletion
Perform coaching / training services (if we enter a contract) Contact + billing data Contract — GDPR Art. 6(1)(b) Duration of contract + 6 years (tax record retention)
Website security & abuse prevention IP address, request headers Legitimate interests — GDPR Art. 6(1)(f) 30 days (Cloudflare default)
Analytics (page views) IP-derived country, browser, page URL Consent — GDPR Art. 6(1)(a) 13 months maximum

4. Who we share data with (processors)

We only share data with the following categories of sub-processors, each bound by a Data Processing Agreement (DPA):

We do not sell your personal data to any third party. We do not share it with advertising networks.

5. International data transfers

Some of our processors (notably Cloudflare and MailChannels) operate outside the European Economic Area. Transfers are covered by:

6. Your rights

Under GDPR / UK GDPR you have the following rights. To exercise any of them, contact us at the email above — we respond within 30 days.

6.1 California residents (CCPA/CPRA)

If you are a California resident you additionally have:

7. Security

Personal data are transmitted over HTTPS (TLS 1.2+). Website assets are hosted on Cloudflare, which provides DDoS protection, bot mitigation, and edge-level security. Email delivery is authenticated via SPF and DKIM. Access to raw form submissions is limited to the site owner.

8. Children

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.

9. Changes to this policy

We may update this policy from time to time. Substantive changes will be indicated by the “Last updated” date above. Continued use of the website after an update constitutes acceptance of the revised policy.

10. Contact and complaints

For any question about this policy or to exercise your rights: [email hidden — enable JavaScript].

You can also lodge a complaint with your data-protection supervisory authority. A directory of EU authorities is available on the European Data Protection Board website.