Draft — pending legal review. This document is a working draft and has not been reviewed or approved by a lawyer. It is not legal advice and should not be relied on until finalised. The governing version is English.

Privacy & GDPR Policy

Last updated: 2026-07-21

This Policy explains how CBAM.School processes personal data. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the controller is RHND Innovations GmbH, Dornbacher Straße 5 Top 2-3, 1170 Vienna, Austria, contactable at privacy@cbam.school.

We serve users in the EU and UK. Where the EU GDPR and UK GDPR both apply, references to “GDPR” should be read to include both.

1. The data we process

Account and legal-evidence data: your name, email address, authentication records, and the version, time, IP address and user agent associated with accepting legal documents or requesting early digital supply.

Membership and billing data: your membership status and payment records. Card details are entered directly into our payment processor (Stripe) and are not stored by us.

Learning and user-content data: course progress, viewing time, quiz and exam results, capstone files and review information, certificate records, and support correspondence.

Technical, security and content-protection data: IP address, user agent, device identifier, session and concurrent-stream activity, security/anomaly decisions, playback grants, and a pseudonymous watermark label tied to your account. The visible watermark does not display your email address.

Communications and waitlist data: sender and recipient addresses, message bodies, headers and attachments for email sent to our published addresses; and your waitlist/newsletter choices, consent time, source and unsubscribe status.

Usage and diagnostics data: allowlisted product events linked to your member identifier; and error, performance, device and request data sent to Sentry. Before transmission, our request scrubber removes query strings, headers, cookies and request bodies and limits any user object to its internal ID. Error messages and diagnostic context are not guaranteed to be free of personal data, so developers must not deliberately place names, email addresses, secrets or submitted content in errors. Sentry session replay is disabled.

Public certificate data: a holder name, credential, certificate number, issue/validity dates and status are available only through the certificate's unguessable verification link. If no holder name is stored, we display 'Name withheld', never the account email.

2. Why we process it, and our legal bases

To provide the Service and perform our contract with you (Art. 6(1)(b)): accounts, membership, delivering the course, exams, capstone review and certificates.

To comply with legal obligations (Art. 6(1)(c)): for example, tax and accounting records.

For our legitimate interests (Art. 6(1)(f)): securing and diagnosing the Service (including Sentry), preventing account sharing, abuse and content redistribution, preserving assessment and certificate integrity, and defending legal claims — balanced against your rights.

With your consent (Art. 6(1)(a)): non-essential cookies and analytics, including session replay, and any optional marketing. You can withdraw consent at any time.

3. Processors and sub-processors

Processors used when the corresponding feature is configured are: WorkOS (authentication); Neon (database hosting); Vercel and Vercel Blob (application hosting, CDN and capstone file storage); Resend (transactional and inbound email); PostHog (product analytics and optional masked session replay); Sentry (scrubbed error and performance monitoring); Arcjet (security and abuse prevention); and Cloudflare Stream (protected video delivery). These providers act under their data-processing terms for those functions.

Stripe processes payments. It acts as our processor for some payment operations and as an independent controller where it determines processing required for fraud prevention, regulatory compliance and its own legal obligations; Stripe's privacy notice also applies at checkout. A provider is not necessarily active merely because it appears in this list: dormant integrations send no data until configured.

We do not sell personal data. We review provider roles, data-processing terms, sub-processors and locations before activation and keep this notice current.

4. International transfers

The configured database and analytics deployments are intended to use EU regions, but support, security, payment, email, hosting and video providers may process data in other countries. Before activation we verify the actual account region and transfer route. For restricted transfers we use an adequacy decision where available or the European Commission's 2021 Standard Contractual Clauses and, for UK data, the UK Addendum or International Data Transfer Agreement, together with supplementary safeguards identified by a transfer assessment. Contact privacy@cbam.school for a copy or summary of the applicable safeguards.

5. Retention

Account, learning and capstone data is retained while the account is active and then deleted or anonymised following an erasure request unless contract performance, legal claims or a statutory duty requires longer retention. Billing and tax evidence is retained for the applicable Austrian statutory period. Certificate records remain available while verification is necessary, subject to objection and erasure rights and any overriding integrity or legal-claims basis.

Inbound email is scheduled for deletion after 180 days; inactive stream leases after 30 days; playback grants and content-security anomalies after 730 days; completed privacy-request records after three years; and unsubscribed waitlist records after 30 days. The application contains an authenticated scheduled cleanup that enforces these operational periods. Provider backups may persist for their documented rolling backup period before deletion completes.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and object to processing, and to data portability, and — where processing is based on consent — to withdraw consent at any time without affecting prior processing.

Use the Privacy requests page in your member menu to download a portable JSON copy immediately or lodge an access, rectification, erasure/account-deletion, restriction, portability or objection request. The system records a one-month response deadline. You may also contact privacy@cbam.school. We may verify identity and may retain data where a legal obligation, legal claim or another GDPR exception applies; we will explain any refusal.

You also have the right to lodge a complaint with your supervisory authority. Our EU lead authority is the Austrian Data Protection Authority (Datenschutzbehörde); UK users may contact the Information Commissioner's Office.

7. Cookies

We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, with your consent, analytics cookies. See our Cookie Policy for details and how to change your choices.

8. Security

We use technical and organisational measures appropriate to the risk, including encryption of secrets, access controls, and abuse prevention. No system is perfectly secure; report concerns to security@cbam.school.

9. Changes and contact

We may update this Policy; material changes will be notified by a reasonable means. Questions or requests: privacy@cbam.school. Controller: RHND Innovations GmbH, Dornbacher Straße 5 Top 2-3, 1170 Vienna, Austria.