Privacy Policy
What personal data we collect, why we have it, who touches it, and how you get rid of it.
Last updated: 21 September 20261. The short version
We collect your name and email address so we can deliver the course you paid for, and payment details are handled by Stripe without passing through our systems. We do not sell your data, we do not share it for advertising, and nothing beyond what is strictly necessary runs without your consent. You can ask us to delete your data at any time by writing to support@fynticai.com.
2. Who is responsible for your data
The data controller is Leonardo Nogueira Vieira, sole trader, trading as Fyntic AI, Rua do Maçarico, n.º 117, 1.º Dto., Cascais, Portugal. You can reach us at support@fynticai.com or +351 927 079 091.
We are not required to appoint a data protection officer. Data protection questions are handled by the owner personally, at the address above.
3. What we collect and why
| Data | Why we have it | Legal basis |
|---|---|---|
| Email address, and name if you give it | To deliver the 21 lessons and give you access to the archive | Performance of our contract with you |
| Purchase record: plan, amount, date, country, payment status, Stripe identifiers | To confirm your order, give support, and handle refunds | Performance of our contract with you |
| Invoice and accounting records | To meet Portuguese tax and accounting obligations | Compliance with a legal obligation |
| Messages you send us, and our replies | To answer you and keep a record of what was agreed | Performance of our contract, and our legitimate interest in keeping a support history |
| Whether a lesson email was delivered, opened or failed | To make sure the course actually reaches you and to fix delivery problems | Performance of our contract with you |
| Technical data: IP address, browser type, pages requested, timestamps | To keep the site running, to detect abuse and fraudulent payment attempts | Our legitimate interest in the security of the service |
| Analytics about how pages are used | To improve the course pages | Your consent, given through the cookie banner |
| Marketing and attribution data | To understand which link or advert led to a purchase | Your consent, given through the cookie banner |
| Email address for news about our own products | To tell existing customers about related material | Your consent, or our legitimate interest in marketing similar products to existing customers, with an unsubscribe link in every message |
We never ask for and never store your full card number, card expiry or security code. Those go directly to Stripe.
We do not knowingly collect data from children. The course is sold to adults and you must be at least 18 to buy it.
4. Who we share it with
We use a small number of service providers who process data on our instructions. Each of them is bound by a contract that restricts what they may do with it.
| Provider | What they do | Where |
|---|---|---|
| Stripe Payments Europe, Ltd. and affiliates | Take and process your payment, fraud prevention, receipts | Ireland, with group processing in the United States |
| Vercel Inc. | Host this website and serve its pages | United States, with edge delivery in the EU |
| Our email delivery provider | Send the course lessons, confirmations and support replies | European Union or United States, depending on the provider in use |
| Our accountant | Prepare and file statutory accounts and tax returns | Portugal |
We may also disclose data where we are legally required to, for example to a tax authority or a court, or where it is necessary to establish or defend a legal claim.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
5. Transfers outside the European Economic Area
Some of the providers above are established in the United States. Where data is transferred outside the EEA, the transfer is covered by one or more of the following safeguards: the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified under it, or the Commission's Standard Contractual Clauses together with additional technical measures. You may ask us for a copy of the safeguards that apply.
6. How long we keep it
| Record | Kept for |
|---|---|
| Your course access and email address | For as long as the archive is available to you, or until you ask us to delete it |
| Invoices and accounting records | 10 years, as required by Portuguese tax law |
| Support correspondence | 3 years from the last message |
| Email delivery logs | 12 months |
| Server and security logs | Up to 12 months |
| Record of your cookie choice | 6 months, after which we ask again |
When a retention period ends we delete the data or irreversibly anonymise it.
7. Your rights
Under the General Data Protection Regulation you have the right to:
- ask what data we hold about you and receive a copy of it;
- have inaccurate data corrected;
- have your data deleted, where we have no overriding obligation to keep it;
- ask us to restrict how we use it while a dispute is resolved;
- receive the data you gave us in a portable, machine-readable format;
- object to processing that relies on our legitimate interests;
- withdraw a consent you gave, at any time, without affecting what was lawful before you withdrew it;
- unsubscribe from any marketing message using the link at its foot.
To exercise any of these, write to support@fynticai.com. We reply within one month. We may ask you to confirm your identity first, to avoid disclosing your data to somebody else. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or repetitive requests.
8. Complaining to a supervisory authority
If you believe we have handled your data badly, please tell us first so that we can put it right. You also have the right to complain to a data protection authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt. If you live in another EU country you may complain to the authority there.
9. Automated decisions
We do not make decisions about you by purely automated means that produce legal effects or similarly significant effects. Our payment processor runs automated fraud checks on transactions, which may result in a payment being declined; if that happens to you and you believe it is wrong, contact us and we will look into it.
10. Security
The Site is served over HTTPS. Access to customer records is limited to the owner and protected by strong authentication. Payment data never reaches our systems. No system is perfectly secure, but if a breach ever affects your rights and freedoms we will notify the CNPD within 72 hours and tell you directly where the law requires it.
11. Changes to this policy
We update this policy when what we do changes. The date at the top shows the current version. If a change matters to you, we will say so by email before it takes effect.
12. Contact
Leonardo Nogueira Vieira, Rua do Maçarico, n.º 117, 1.º Dto., Cascais, Portugal. Email support@fynticai.com, telephone +351 927 079 091.