Privacy policy
Last updated: 16 August 2026
This translation is provided for ease of reading. In case of any discrepancy, the Spanish version prevails.
1. Data controller
To be completed by the owner before launch: legal company name, registered address, tax and VAT number, and legal and privacy contact email. Bit AI School is the name of the online training project.
2. What data we collect
If you create an account: your email address, a password (stored only as a PBKDF2 cryptographic hash, never in plain text), optionally your name, your chosen language, the date you signed up and your last login date.
Your course progress: which pages you’ve completed, where you left off, and the status of your exercises, so you can pick up from the same place on any device.
If you give us your email without creating an account (at the end of the free course): your address, the consent you ticked, the exact text you accepted, and the date.
Minimal usage and attribution metrics: events such as “home page viewed”, “lesson started” or “exercise completed”, with a random session ID, language, page and date. If you arrive from a campaign, we store its campaign parameters or click identifiers and only the referring domain, never the full address. We do not store your IP in plain text or anything you type in exercises.
If you buy Bit AI School Complete: the transaction ID, amount, currency, email linked to the purchase, purchase code and date. We do not receive or store your card details: you enter them directly in the payment gateway, which handles them.
If you register interest for your company: the company name, your name, work email, approximate team size, the need you describe and the consent text you accepted.
3. What we use your data for and on what legal basis
Service delivery (art. 6.1.b GDPR): giving you access to your account, keeping you signed in, saving your progress and sending you essential account emails (email confirmation and password reset).
Consent (art. 6.1.a GDPR): sending you notifications about new lessons or updates, if you have specifically chosen to receive them. You can withdraw your consent at any time without losing access to the course.
Legitimate interest (art. 6.1.f GDPR): aggregated metrics to understand which lessons are effective, and protection against abuse through request limits.
Consent (art. 6.1.a GDPR): storing and responding to a company interest request. The form starts no automatic follow-up or email.
4. Cookies
We use two technical cookies: aula_sid, which keeps you signed in, and aula_lang, which remembers your chosen language. The session cookie is httpOnly, Secure and SameSite=Lax, lasts for 30 days and is deleted when you sign out. We do not use advertising or third-party cookies, and there are no external trackers.
If you browse without an account, your progress is saved in your browser’s local storage (this is not a cookie and is not sent to our servers until you create an account and choose to keep it).
5. Who we share data with
We do not sell or pass on personal data. We use only the essential data processors: the infrastructure provider that hosts the application and its database (servers in the European Union), and the provider for sending transactional emails. Both act under contract and only follow our instructions.
If you make a purchase, the payment gateway processes your payment details as an independent data controller, according to its own policy, to carry out the transaction and comply with anti-fraud and accounting regulations. We only receive confirmation of payment and the minimum details of the transaction.
6. How long we keep your data
Your account data and progress are kept as long as your account exists. If you delete your account, your data is erased immediately and irreversibly.
Confirmation and reset tokens expire after 24 hours and 60 minutes respectively, and become invalid after first use.
Usage events are kept for a maximum of 24 months. Consent records are kept as long as needed to prove consent was given.
Purchase data is kept for the periods required by commercial and tax regulations, even if you delete your account. In that case, the purchase is no longer linked to you: it is kept as an accounting record with no connection to any account.
7. Your rights
You can access, correct, delete, restrict or object to the processing of your data, and request your data in a portable format. From your account panel you can download all your data as a JSON file and delete your account completely, without filling in any forms.
You can also write to us at hola@bitaischool.com, and you can make a complaint to the Spanish Data Protection Agency (aepd.es) if you believe we have not dealt with your request.
8. Security
The application is always served over HTTPS. Passwords are stored with PBKDF2-SHA256 and 210,000 iterations using a random salt for each user. Sessions and one-time tokens are stored as SHA-256 hashes, never in plain text. When you reset your password, all open sessions are automatically closed.
9. Minors
This service is intended for people aged 14 and over. If we detect an account belonging to someone under this age without their guardians’ permission, we will delete it.
10. Changes
If we update this policy, we will change the date above. If the change affects the legal basis or the purposes, we will let you know by email before it takes effect.