This policy describes what personal data the postnikov.ai website collects and what happens to it. Short and free of legal fog — but in line with Regulation (EU) 2016/679 (GDPR).
1. Who is responsible for your data
Data controller: Maxim Postnikov, sole trader (NIE Y6205622Y), Barcelona, Spain.
For any question about your data: [email protected] — I answer personally.
2. What data is collected
- Sign-up form: name, email, Telegram handle — what you enter yourself in the form on a program page (the mastermind, for example). Applications are stored in the same database as sign-ups for the “AI Anti-Magic” course: the controller is one and the same.
- Correspondence: if you write to me by email or on Telegram — whatever you send yourself.
- Technical data: server logs (IP address, request time, requested page, user agent).
The site sets no cookies. The colour theme you pick is kept in your browser's localStorage and never goes to the server. There is no analytics and there are no advertising trackers on the site.
3. Why and on what legal basis
| What we do | Legal basis |
|---|---|
| Process your application and contact you to arrange the interview and explain the terms | Steps taken at your request prior to entering into a contract — Art. 6(1)(b) GDPR |
| Write about a new intake to those who left an application or joined the waiting list themselves | Legitimate interest — Art. 6(1)(f); every email includes a way to opt out |
| Marketing emails beyond that | Only with separate consent — Art. 6(1)(a) |
| Keep the site running and protect it from abuse (server logs) | Legitimate interest — Art. 6(1)(f) |
| Keep invoices and payment records if it came to paying for participation | Legal obligations (tax, accounting) — Art. 6(1)(c) |
4. Who the data is shared with
Only with the services the site and the handling of applications cannot work without (processors under Art. 28 GDPR):
- Hetzner — website hosting (servers in the EU)
- Supabase — the database where applications are stored
- Resend — sending emails about your application
- Sentry — monitoring technical errors while an application is processed
- Google Workspace — email
- Telegram — correspondence about your application
There is no sale of data and no sharing with “partners”. Where a service processes data outside the EEA, the transfer relies on the EU Standard Contractual Clauses (SCC) or on an adequacy decision.
5. How long we keep it
- Applications and the correspondence about them — up to 3 years after the last contact (future intakes, invitations), or until you ask for deletion.
- Payment and accounting records — up to 6 years (required by Spanish law).
- Server logs — rotated automatically; kept no longer than needed to diagnose and protect the site.
6. Your rights
At any time you can: request a copy of your data, have it corrected, have it erased (except what we are legally obliged to keep), restrict the processing, receive your data in a machine-readable format, object to processing based on legitimate interest, withdraw your consent.
An email to [email protected] is enough for that. If you believe your rights have been breached, you have the right to lodge a complaint with the Spanish data protection authority — AEPD (www.aepd.es) — or with the supervisory authority in your country.
7. Changes to this policy
When the policy changes, its version is updated (the date at the top of the page). The consent you give when submitting an application is tied to the version in force at that moment.