Legal

Privacy notice

How personal data is used across the website, checkout, courses and product connector.

Preview draft, not legal advice: controller identity, lawful-basis analysis, processor list, transfer mechanisms and retention schedule require specialist review before publication.

Controller and contact

[Legal entity and registered address]
Privacy contact: privacy@csauerborn.com

Storage on your device

This site sets no cookies. It does use two browser storage entries, and they are treated differently:

  • Session storage, no consent required. If you arrive through a campaign link, its parameters (utm_*, gclid, fbclid) are kept under campaign_context for the duration of the browser session, so that the checkout you started can be attributed to the link you actually clicked. It is deleted when you close the tab.
  • Local storage, consent required. A random identifier bx_uid is used to recognise a returning visit for measurement. It is only created after you allow analytics, it is never created on page load, and without that permission no identifier is stored and no measurement event is sent. It contains no name, email or address.

Where a consent banner is active, these choices are managed there and can be changed at any time. Until it is, anything that is not strictly necessary stays switched off.

Website and analytics

Measurement is limited to events you trigger, such as starting a checkout. Marketing signals are sent only where the required consent exists. Browser and server events share an event identifier to prevent double counting. Client files, prompts and API keys are excluded from analytics events.

Newsletter

When you subscribe, your email address, consent record and relevant campaign attribution are processed to deliver and measure the newsletter. You can withdraw consent using the unsubscribe link in any email.

Checkout and course delivery

Checkout, taxes, receipts and payment notifications are planned through ThriveCart; course access through ThriveAcademy; lifecycle messages through Brevo; workflow orchestration through n8n; and customer records through Attio. A private Agency AI OS application is a qualified handover to Brixon AI, which owns review, contract and delivery under its separate notice and agreement. The final controller/processor inventory and international-transfer safeguards will be published after legal review.

BrandOS Image Connector

The connector uses the agency's own OpenAI API key. Only an agency administrator can store or replace it. The key is encrypted at rest and is never returned to staff users. Reference images expire after 24 hours and generated images after 30 days. Access identity and entitlement status are checked for each request. Prompts, keys and customer files are not written to telemetry logs.

Your rights

Depending on applicable law, you may have rights of access, correction, erasure, restriction, portability and objection, plus a right to complain to a supervisory authority. Contact privacy@csauerborn.com to make a request.