Privacy Policy
Last updated: August 5, 2026
1. Who We Are
Privacy Tech Courses (privacytechcourses.com) is operated by Curtis Mitchell and Mitchell Technology Consulting, LLC. We provide online courses on privacy-enhancing technologies. In this policy, "we", "us", and "our" refer to Privacy Tech Courses.
For privacy-related questions or to exercise your rights, contact us at: [email protected]
2. What Data We Collect and Why
Account and Course Access
When you purchase a course, we collect your email address to create your account and send you access to your course. We do not collect passwords -- we use magic links (one-time login links sent by email). We also store your course progress (which lessons you have completed and quiz scores) so you can resume where you left off.
Legal basis (GDPR): Performance of a contract -- this data is necessary to provide the service you paid for.
Newsletter
If you sign up for our newsletter, we collect your email address. We require double opt-in: you must confirm your subscription by clicking a link in a confirmation email before we add you to our list. You can unsubscribe at any time via the one-click link in any newsletter email.
Legal basis (GDPR): Consent. You may withdraw consent at any time.
Payment
Payments are processed by Creem (our payment provider), operated by Armitage Labs OÜ, a company registered in Tallinn, Estonia. We do not receive or store your credit card number or other payment details. We only receive a confirmation that your payment was successful and a reference ID. Creem's privacy practices are governed by Creem's Privacy Policy.
Legal basis (GDPR): Performance of a contract.
Security and Rate Limiting
We temporarily store your IP address in memory to enforce rate limits (for example, to prevent abuse of our login and sign-up endpoints). IP addresses used for rate limiting are held for no more than one hour and are never written to long-term storage.
Legal basis (GDPR): Legitimate interests (preventing abuse and protecting our systems).
Session Cookies
We use a single HTTP-only, same-site session cookie to keep you logged in. This cookie contains only a random session identifier; no personal data is stored in the cookie itself. Session data expires after 7 days.
We do not use advertising cookies, tracking pixels, or cross-site tracking. Our analytics are cookieless and are described below.
Legal basis (GDPR): Legitimate interests (maintaining your login session).
Analytics
On our public marketing pages (such as the home page, course descriptions, and this policy) we use Plausible Analytics to understand aggregate traffic: for example, how many people visit a page and which pages are most popular. Plausible is a privacy-focused analytics service that is cookieless. It sets no cookies, uses no persistent identifiers, and does not track you across sites or over time. Analytics run only on our public pages, not on logged-in course or account pages.
Plausible records the page URL (path only; query strings are discarded apart from campaign parameters), the referring site, your browser, operating system, device type, and an approximate location (country, region, city) derived from your IP address. To count returning visits within a single day without an identifier, it computes a hash of a daily-rotating salt, our domain, your IP address, and your user agent. The salt is deleted every 24 hours, and your raw IP address and user agent are never stored. The result is that the counts cannot be linked back to you or joined across days.
Plausible is operated by Plausible Insights OÜ, established in Tartu, Estonia. It stores and processes this data on servers in Falkenstein, Germany, using European infrastructure providers (Hetzner, Bunny, and UpCloud). Visitor data does not leave the EU.
Legal basis (GDPR): Legitimate interests (measuring aggregate site usage to improve our content). Because this analytics stores nothing on your device and reads nothing from it, it does not require consent under the ePrivacy Directive. The brief, in-memory use of your IP address to derive an approximate location and a same-day hash relies on those same legitimate interests, and nothing identifying is retained.
3. How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Account email and course progress | Until you request account deletion |
| Newsletter subscription | Until you unsubscribe or request deletion |
| Session cookie | 7 days (or until you log out) |
| IP address (rate limiting) | Up to 1 hour |
| Payment reference (confirmation ID only) | Until account deletion |
| Encrypted database backups | Up to 90 days |
When you delete your account, we remove your data from the live database immediately. Encrypted backups taken before your deletion request still contain that data until they age out, which takes up to 90 days. We do not restore deleted accounts from backups: we keep a record of every deletion request so that if we ever have to restore from a backup, accounts deleted after that backup was taken are deleted again as part of the restore.
4. Who We Share Data With
We share your data only with the third-party services required to operate the platform:
- DigitalOcean (United States) -- Cloud hosting provider, operated by DigitalOcean, LLC (Broomfield, Colorado). The application and its database run in DigitalOcean's San Francisco region, and encrypted database backups are stored in its New York region. DigitalOcean executes the EU Standard Contractual Clauses through its data processing agreement and is certified under the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework.
- Postmark (United States) -- Email delivery service used to send magic link login emails, enrollment confirmations, and newsletters, operated by ActiveCampaign, LLC (Chicago, Illinois). Postmark processes email addresses only to deliver messages we instruct it to send. Its servers are in the United States (a data center outside Chicago, and Amazon Web Services); Postmark does not offer EU-based servers, so email delivery for EU visitors is handled in the United States. ActiveCampaign executes the EU Standard Contractual Clauses through its data processing agreement and is certified under the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework.
- Creem -- Payment processor, operated by Armitage Labs OÜ, a company established in Tallinn, Estonia (European Union) and directly subject to the GDPR. Handles all payment card data. We share only the minimum data required to process your purchase (email address for the payment record).
- Plausible Analytics (Germany, European Union) -- Privacy-focused, cookieless website analytics for our public pages, operated by Plausible Insights OÜ (established in Tartu, Estonia) on servers in Falkenstein, Germany. Plausible acts as our processor for visitor data and stores no raw IP addresses or persistent identifiers, so we receive only aggregate page-view data that does not identify you.
We do not sell your data, share it for advertising purposes, or provide it to any other third parties.
5. International Transfers
Our processors are split across two jurisdictions:
- United States -- application hosting and your account, course, and progress data (DigitalOcean, in its San Francisco region, with encrypted backups in its New York region), and email delivery (Postmark, near Chicago).
- European Union -- payment processing (Creem, operated by Armitage Labs OÜ, established in Estonia) and website analytics (Plausible Insights OÜ, on servers in Germany).
If you are accessing the platform from the European Economic Area (EEA), United Kingdom, or Switzerland, the data we hold in the United States is transferred to a country that may not have the same data protection laws as your jurisdiction. Both of our US processors, DigitalOcean and Postmark (ActiveCampaign), are certified under the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework, and both also execute the EU Standard Contractual Clauses (SCCs) through their data processing agreements. You can verify either certification on the Data Privacy Framework List.
Creem is established in the EU and is therefore directly subject to the GDPR, but it may use its own service providers outside the EEA under Standard Contractual Clauses. We do not control where Creem processes payment data; see Creem's Privacy Policy for its own transfer disclosures.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access -- Request a copy of the personal data we hold about you.
- Rectification -- Correct inaccurate data (you can update your email address in account settings).
- Erasure -- Request deletion of your account and personal data.
- Data portability -- Request your data in a machine-readable format.
- Restriction -- Ask us to restrict processing of your data in certain circumstances.
- Objection -- Object to processing based on legitimate interests.
- Withdraw consent -- If processing is based on consent (newsletter), you may withdraw at any time by unsubscribing.
How to exercise your rights
- Data export or account deletion: Log in and go to your Account Settings. You can export your data or delete your account from there.
- Newsletter unsubscribe: Click the unsubscribe link in any newsletter email, or contact us directly.
- Any other request: Email us at [email protected]. We will respond within 30 days (or sooner as required by applicable law).
If you are in the EEA, you also have the right to lodge a complaint with your local data protection authority (DPA). A list of EEA DPAs is available from the European Data Protection Board.
7. Security
We use industry-standard security measures to protect your data, including:
- HTTPS (TLS) for all data in transit
- HTTP-only, same-site session cookies to prevent XSS and CSRF
- Strict Content Security Policy headers
- Encrypted database backups with AES-256-GCM
- Passwordless authentication (no password database to breach)
- Rate limiting on all authentication and subscription endpoints
No method of transmission over the internet is 100% secure. If you discover a security issue, please contact us at [email protected].
8. Children's Privacy
Our courses are intended for adults. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify enrolled users by email and update the "Last updated" date at the top of this page. Continued use of the platform after changes take effect constitutes acceptance of the revised policy.
10. Contact
For any questions about this privacy policy or how we handle your data:
- Email: [email protected]
- Website: privacytechcourses.com