Legal · Effective 2026-09-03
Privacy Notice
Ascent Elite · Your data, your control
Last updated · 2026-09-03
This Privacy Notice ("Notice") explains what personal data Ascent Elite ("we", "us", "our") collects when you visit our website, sign up for free content, or purchase The AI Systems Architect Playbook, how we use it, how long we keep it, who we share it with, and the rights you have as a data subject. This Notice applies alongside the Terms of Service and Refund Policy.
Contents
- 1. Overview of This Notice
- 2. Controller & Contact
- 3. Data We Collect
- 4. How We Use Your Data
- 5. Legal Bases (GDPR / UK GDPR)
- 6. Who We Share Data With
- 7. Sub-processors (Supabase, Paddle, Lovable)
- 8. International Data Transfers
- 9. Retention Periods
- 10. Your Rights as a Data Subject
- 11. Cookies & Similar Technologies
- 12. Security Measures
- 13. Children's Data
- 14. Changes to This Notice
01 Overview of This Notice
We take a collect-minimum approach to personal data. We only collect information that is necessary to deliver the Course, process payments, prevent fraud, respond to your support queries, and comply with applicable law. We do not sell your personal data, ever. We do not build advertising profiles on visitors to this site.
02 Controller & Contact
For the purposes of the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA), and other applicable data protection laws, the data controller is Ascent Elite, operating the website at www.ascent-elite.org.
You may contact the controller and our data protection point of contact at privacy@ascent-elite.org.
03 Data We Collect
We collect the following categories of personal data:
- Account & Auth data: email address, display name (optional), and a user ID created by Supabase Auth when you sign in. We do not see or store your password — authentication credentials are handled by Supabase using industry-standard hashing.
- Checkout & Billing data: name, email address, billing address, company name (optional), order ID, and the last 4 digits of the card used. Full card numbers, CVV, and complete payment details are processed and stored by Paddle — we never see or store full card numbers on our systems.
- Free-content opt-in data: the name, email, and optional role/tier fields you submit when downloading the free 9-Layer System Map or joining the waitlist.
- Support correspondence: any information you voluntarily provide in customer-support emails, tickets, or direct messages (including attachments, URLs, screenshots, and transcripts).
- Server-side analytics & traffic: anonymous-ish request logs (date/time, URL path, country-level geo-IP, user-agent, referer) processed by our hosting, deployment, and CDN providers. This is normally pseudonymous and is not used to build profiles.
We do not collect "special categories" of personal data (race, religion, health, biometrics, union membership, sex life, or criminal records) and we ask that you do not send such information to us.
04 How We Use Your Data
We use personal data for these specific purposes only:
- To create, authenticate, and maintain your user account and library.
- To deliver the Course and any purchased downloads (tiered by your purchase tier per the Terms).
- To process payments, invoices, and VAT/GST/sales tax via Paddle.
- To prevent, detect, and investigate fraud, chargebacks, and account abuse.
- To send transactional emails (purchase confirmations, download receipts, account recovery, refunds, replies to support queries).
- To send occasional, low-volume product updates only where you have actively opted in. You can unsubscribe from every marketing email with one click.
- To comply with legal, tax, or accounting obligations.
- To defend our legal rights and enforce the Terms of Service.
05 Legal Bases (GDPR / UK GDPR)
When processing personal data covered by the GDPR or UK GDPR, we rely on the following legal bases, depending on the processing activity:
- Contractual necessity (Art. 6(1)(b)) — to create your account, deliver the purchased Course, and perform our obligations under the Terms of Service and any purchase contract.
- Legitimate interests (Art. 6(1)(f)) — for short-lived traffic and error logging, basic anti-fraud checks, and low-volume product updates to existing purchasers who have a clear reasonable expectation to hear about material Course updates.
- Consent (Art. 6(1)(a)) — for free-content opt-ins and any explicitly opt-in marketing communications. Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, and lawful-request disclosure.
07 Sub-processors (Supabase, Paddle, Lovable)
The following sub-processors process personal data on our behalf. Each has its own published privacy notice and (where applicable) EU Standard Contractual Clauses or equivalent transfer mechanisms in place:
- Supabase, Inc. (authentication server, user records, database storage, session metadata, optional storage bucket access). See supabase.com/privacy.
- Paddle Ltd / Paddle.com Market Ltd (Merchant of Record, payment processing, billing, invoices, tax calculation, compliance, fraud). See paddle.com/legal/privacy.
- Lovable / Cloudflare Pages / hosting & CDN providers (static site hosting, edge caching, request logging). See lovable.dev/privacy and equivalent provider privacy notices.
- Email delivery services — transactional and (optional) opt-in marketing email. Processor details available on request.
08 International Data Transfers
Supabase and Paddle operate infrastructure that may process personal data outside your country of residence, including in the United States. Where we transfer personal data from the European Economic Area, the UK, or Switzerland to countries whose laws have not been deemed to provide an adequate level of protection, we use appropriate safeguards including: (a) EU Standard Contractual Clauses (SCCs) as approved by the European Commission, (b) UK International Data Transfer Addendum where applicable, and/or (c) processor-side Binding Corporate Rules or equivalent adequacy findings. You may request a copy of the relevant transfer mechanism by writing to privacy@ascent-elite.org.
09 Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and to satisfy our legal and accounting obligations. As a general baseline:
- Accounts & purchases: at least the duration of your active account, plus 7 years after the last purchase for tax and accounting purposes.
- Free-content opt-ins: until you unsubscribe, plus a short period for unsubscribe-confirmation records.
- Support correspondence: 24 months from resolution of the ticket, or longer if we are advised to keep it for legal or dispute reasons.
- Traffic/access logs: normally 30–90 days, rotated automatically.
After retention expires we securely delete, anonymise, or irreversibly pseudonymise the affected records consistent with commercially reasonable deletion practices.
10 Your Rights as a Data Subject
Depending on your location and applicable law, you may have some or all of the following rights in relation to your personal data:
- Right of access (Art. 15 GDPR) — a copy of the data we hold about you.
- Right to rectification — to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — where processing is based on consent, is no longer necessary, or you have a valid overriding objection.
- Right to restrict processing — under the conditions set out in Art. 18 GDPR.
- Right to data portability — where processing is by automated means and based on consent or contract, to receive your data in a structured, commonly used, machine-readable format.
- Right to object — to processing based on legitimate interests or for direct marketing purposes at any time.
- Right to withdraw consent at any time, where consent was the legal basis.
- Right to lodge a complaint with your local supervisory authority (for example, the ICO in the UK or your national DPA in the EU).
To exercise any of these rights, contact privacy@ascent-elite.org from the email associated with your account. We respond to valid, verified requests within 30 calendar days (extended by up to 60 calendar days where permitted and notified to you).
12 Security Measures
We protect personal data using industry-standard, commercially reasonable controls including: TLS 1.2+ for all in-transit traffic, AES-256 at rest for managed storage (Supabase Postgres + storage), role-based access control for internal systems, principle of least privilege, OWASP-compliant input validation, regular dependency patching, and managed SOC/monitoring through our infrastructure providers. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
If we become aware of a data breach affecting personal data that creates a risk to the rights and freedoms of individuals, we will assess and, where required, notify the applicable supervisory authority and affected data subjects in accordance with mandatory timelines.
13 Children's Data
The Service is intended for professional audiences and is not directed to children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect or solicit personal information from children. If we become aware that we have inadvertently collected personal data from a child, we will promptly delete it.
14 Changes to This Notice
We may update this Privacy Notice from time to time, for example to reflect changes in applicable law, changes in our tools or practices, or a material new product feature. Material changes will be flagged with an updated "Effective" date at the top of this page and, where appropriate, communicated via email to existing account holders or an in-product notice. Continuing to use the Service after changes take effect means you accept the revised Notice.
© 2026 Ascent Elite · All rights reserved