Legal
Privacy Policy
Last updated: 2026-07-28 — Version 1.0
This Privacy Policy describes how Handgemacht AI FlexCo ("we", "us") collects, uses, and protects personal data in connection with the Claude Code Course website and learning platform at agentic-coding.handgemacht.ai/claude. It applies to visitors of the landing page, waitlist and workshop signups, guest check-in participants, and registered learners.
Our core application and database are hosted in the European Union (Frankfurt). Transactional and double-opt-in email is handled by Brevo, an EU provider; payment processing for paid plans runs through Stripe. We do not sell personal data, use advertising trackers, or run third-party analytics.
1. Controller Identity and Contact Details
The data controller responsible for processing your personal data is:
- Legal name
- Handgemacht AI FlexCo
- Registered address
- Prof.-Franz-Spath-Ring 7/8, 8042 Graz, Austria
- Commercial register
- FN 671551 a, Landesgericht für Zivilrechtssachen Graz
- VAT ID
- ATU83128269
- Managing director
- Marco Livio Rotili
To exercise data-subject rights or raise a privacy concern, contact us at [email protected]. We will respond within one month of receipt (GDPR Art. 12(3)).
No Data Protection Officer (DPO) has been appointed; we do not engage in large-scale systematic monitoring or process special-category data as a core activity (GDPR Art. 37(1)).
2. Categories of Personal Data Processed
2a. Waitlist signup data
When you join the early-access waitlist on the landing page, we store your email address, the signup source (for example "landing"), your seat position in the price ladder, and the discount tier your seat locked in. If you took the anonymous check-in before signing up, the signup is linked to your pseudonymous guest identifier so your progress carries over.
2b. Guest check-in data (no account required)
You can take the diagnostic check-in without an account. We then mint a
pseudonymous guest identifier (guest:<uuid>)
and store your answers, scores, and confidence ratings under that
identifier. The guest id contains no name or email address.
2c. Account data
- Email address (used for passwordless magic-link sign-in)
- Optional display name
- Role (learner or admin) and account timestamps
Sign-in uses single-use magic links sent by email; no passwords are stored. Magic-link tokens expire after 10 minutes.
2d. Learning evidence
As you work through check-ins and lessons, we store learning evidence linked to your account or guest identifier: probe attempts and answers, rubric scores, and grading metadata (which judge produced a score — for example your own AI agent via the learner MCP connection — plus a model version and prompt hash). Grading by an AI agent happens inside your Claude Code session under your own provider account; our servers receive and store the resulting evidence, they do not send your answers to a third-party LLM for grading.
2e. Connected-client / OAuth data
The platform is an OAuth 2.0 authorization server for the learner MCP connection. When you authorize a client (such as your Claude Code session), we store the client registration, your consent record, and the issued authorization codes and refresh tokens (stored hashed), together with the scopes granted.
2f. Workshop signup data
If you sign up for a workshop, we store your email address, the workshop code, and the signup source.
2g. Team invitations
When a team or organization member invites you, we receive your email address from the inviting user and store it with the invitation (role, single-use token, expiry). The invitation email links you to this policy.
2h. Payment and billing data (via Stripe)
If you purchase a paid plan, billing is processed by Stripe. We store only the Stripe customer and subscription identifiers, subscription status, and plan tier on the organization record. Full payment card data never touches our servers — it passes directly to Stripe and is subject to Stripe's own privacy policy.
2i. Technical and operational data
- Session authentication token (stored in a browser cookie)
- IP address and HTTP request metadata (server access logs at our hoster)
- IP addresses are used transiently (in-memory only) to rate-limit the public waitlist endpoint against abuse; these counters are not persisted.
3. Purposes of Processing and Legal Bases
| Processing activity | Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Waitlist signup and double opt-in | Reserve your early-access seat; confirm your address; send your tier confirmation | Art. 6(1)(a) — consent (via double opt-in) |
| Guest check-in | Provide the anonymous diagnostic you requested | Art. 6(1)(b) — pre-contractual steps at your request |
| Account creation and magic-link sign-in | Provide access to the learning platform | Art. 6(1)(b) — performance of contract |
| Storing learning evidence and mastery progress | Core product functionality: adaptive lessons and progress tracking | Art. 6(1)(b) — performance of contract |
| OAuth client authorizations and tokens (MCP) | Core product functionality: connecting your agent session | Art. 6(1)(b) — performance of contract |
| Workshop signups | Organize your workshop participation | Art. 6(1)(a) — consent (via double opt-in) |
| Subscription billing via Stripe | Processing payment for paid plans | Art. 6(1)(b) — performance of contract |
| Server access logs and rate limiting | Security, abuse prevention, infrastructure operation | Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8. |
| Retention of billing records | Tax and accounting obligations under Austrian UGB §212 and §132 BAO | Art. 6(1)(c) — legal obligation |
4. Data Retention
- Waitlist records
- Retained while the early-access campaign runs and deleted no later than 12 months after signup, unless you convert to an account sooner.
- Guest check-in data
- Retained so your progress can be linked to a later account; removed on request.
- Account and learning evidence
- Retained for the duration of your account. On request, we delete your account data within 30 days of your account-closure request, except where a legal retention obligation requires longer retention.
- Magic-link tokens
- Single-use; expire 10 minutes after issue.
- Session token
- Valid for up to 14 days from sign-in or until you sign out.
- OAuth tokens
- Authorization codes are single-use and short-lived; refresh tokens are retained until revoked, rotated, or expired.
- Email suppression
- Unsubscribe and suppression records are maintained by Brevo on our behalf so that opt-out requests keep being honoured.
- Billing records
- Retained for 7 years from the end of the relevant financial year (Austrian UGB §212, §132 BAO).
- Server / access logs
- Retained for a maximum of 90 days for security and operational purposes.
5. Processors, Sub-Processors, and Third-Party Recipients
We share data only with the processors listed below. We do not sell personal data or share it with advertising networks or analytics platforms.
5a. Fly.io, Inc. — Infrastructure and hosting
Cloud infrastructure and PostgreSQL database hosting in the Frankfurt (fra) EU region; data at rest is stored in the European Union. Fly.io, Inc. is a US entity (Delaware); EU-US Data Privacy Framework certification applies, with Standard Contractual Clauses (Decision (EU) 2021/914) as fallback under the executed Fly.io DPA (fly.io/documents).
5b. Brevo (Sendinblue SAS) — Email and contact-list management
Brevo handles all email for the platform: the double opt-in confirmation for waitlist and workshop signups, transactional tier-confirmation and magic-link sign-in emails, and the contact lists built from confirmed signups. When you confirm your address via double opt-in, Brevo stores your email address and signup attributes (for example your discount tier and the signup source) as a contact on our behalf. List membership, confirmation status, and unsubscribe handling are managed by Brevo; every email carries an unsubscribe link honored there.
Brevo (Sendinblue SAS) is established in Paris, France (European Union), and processes this data under a Data Processing Agreement (brevo.com/legal); any sub-processor transfers outside the EU are covered by Standard Contractual Clauses.
5c. Stripe, Inc. — Payment processing
Subscription billing, Stripe Checkout, and webhook events for paid plans. Stripe acts as processor for payment facilitation and as an independent controller for fraud prevention and financial-compliance obligations. DPA: stripe.com/legal/dpa; transfers are covered by Stripe's EU-US DPF certification, with SCCs per the Stripe Data Transfers Addendum as fallback.
5d. Jina AI — Search embeddings
Course content and search queries against the course knowledge graph are vectorized via the Jina AI embedding API to power semantic search. No account data or learning evidence is sent to Jina AI; queries are processed transiently to compute the embedding.
5e. Third-party requests from your browser
All fonts are self-hosted from our own servers — no font requests leave our infrastructure. The experimental check-in view loads JavaScript libraries (React, Babel) from the unpkg CDN (Cloudflare, Inc., USA), which means your browser discloses your IP address to Cloudflare when loading that view. The CDN receives no form data or account information from us.
6. International Data Transfers
Several recipients listed above are incorporated in the United States (Fly.io, Stripe, Cloudflare/unpkg). For each, the primary transfer mechanism is the EU-US Data Privacy Framework (European Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), with Standard Contractual Clauses (Decision (EU) 2021/914) as fallback where applicable. Email and contact-list data processed by Brevo stays within the European Union. Copies of the applicable safeguards are available on request (GDPR Art. 46(1)).
7. Cookies and Browser Storage
We use only technically necessary cookies and browser storage. No advertising cookies, cross-site tracking cookies, or third-party analytics trackers are used. Under §165(3) TKG 2021 (implementing the ePrivacy Directive), strictly necessary cookies do not require prior consent, so no cookie banner is shown.
| Cookie / storage item | Purpose | Duration |
|---|---|---|
_claude_code_course_key (SameSite=Lax, signed) |
Carries your sign-in session and CSRF token | Session cookie; the referenced token is valid up to 14 days or until sign-out |
| localStorage: admin sidebar state | Remembers admin UI layout preference (no personal data) | Until cleared via browser settings |
8. Your Rights
Under GDPR Arts. 15–22 and the Austrian Datenschutzgesetz (DSG), you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to withdraw consent at any time (Art. 7(3)) — for example by unsubscribing from the waitlist emails, which stops all further list email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. We do not conduct automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22).
To exercise any of these rights, contact us at the address in Section 1. We will respond within one month; for complex or numerous requests we may extend by up to two further months and will inform you within the first month (Art. 12(3)). Exercising your rights is free of charge.
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority at any time (GDPR Art. 77). The lead authority for Austria is:
Österreichische Datenschutzbehörde (DSB)
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at
10. Security Measures
- Encryption in transit: all connections use HTTPS/TLS (HSTS enforced).
- Encryption at rest: managed disk encryption in the Frankfurt (fra) EU region.
- Access controls: learner data endpoints require bearer-token authentication scoped to the authenticated user; OAuth tokens are stored hashed.
- Passwordless authentication only — no password database to breach.
- Rate limiting on public signup endpoints against abuse.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available at this address. Minor changes (for example a new sub-processor) take effect with an updated date above; for material changes (a new purpose or legal basis) we notify affected users by email before the change takes effect.
Version 1.0 — effective 2026-07-28.