Keystone Privacy Notice
Keystone course applications, enrollment, and invoicing
Last updated: August 25, 2026
Scope
This notice explains how AI BEAVERS processes personal data when you apply for the Keystone course at ai-beavers.com/keystone, confirm your application by email, receive a seat offer, get invoiced, take part in a cohort, or contact us about the course (for example about subsidized seats).
It supplements the main Privacy Policy. If the two documents conflict for a Keystone flow, this notice applies to that flow.
Controller
Alexander Zakharov
Turmweg 31
20148 Hamburg, Germany
Email: [email protected]
Data We Collect
- Application answers: full name, email address, function or role (including a written detail if you pick “Other”), optional AI-usage frequency, the AI assistants you use at work (including a written detail if you pick “Other”), and how you heard about us. If you provide a partner referral code, we also store the code, referring partner, attribution date, and applicable commission rate.
- Billing details: bill-to name, street and number, postal code, city, country, and an optional VAT or tax ID. These are collected so we can issue an invoice if you enroll.
- Consent and confirmation records: consent timestamp and version, double-opt-in confirmation tokens and their expiry, and confirmation status.
- Technical metadata: IP address used for rate limiting and abuse prevention, and submission timestamps.
- Correspondence: emails you send us about the course, including subsidized-seat requests and any context you share in them.
Purposes and Legal Bases
- Application review and seat offers: assessing fit and contacting you about the outcome. Legal basis: pre-contract steps under Art. 6(1)(b) GDPR.
- Confirmation and application emails: sending the double-opt-in confirmation email and updates about your application and cohort dates. Legal basis: consent under Art. 6(1)(a) GDPR, which you can withdraw at any time for future emails.
- Enrollment and invoicing: issuing the course invoice to you or your company, processing payment, and providing the course. Legal basis: contract under Art. 6(1)(b) GDPR and legal obligation under Art. 6(1)(c) GDPR for tax and accounting records.
- Referral administration: matching introductions to bookings, calculating commissions, and reconciling refunds and payouts. Our legitimate interest is operating an accurate referral program and preventing duplicate or incorrect payments under Art. 6(1)(f) GDPR. Required financial records are retained under applicable accounting obligations. Partner statements identify the referred customer or booking and relevant amounts, but do not include application answers or billing addresses. We do not use persistent referral cookies.
- Abuse prevention: honeypot checks, IP rate limiting, and duplicate detection to keep the application flow working. Legal basis: legitimate interests under Art. 6(1)(f) GDPR.
- Course correspondence: answering questions and reviewing subsidized-seat requests. Legal basis: pre-contract steps under Art. 6(1)(b) GDPR and legitimate interests under Art. 6(1)(f) GDPR.
Required or Optional
Fields marked required on the application form (name, email, function, workplace AI-assistant selection, referral source, and billing address) are needed to review your application, adapt the cohort to its participants, and prepare an invoice-ready record. The AI-usage frequency, partner referral code, and VAT or tax ID are optional. Applying does not commit you to enrolling or paying.
Recipients and Processors
- Firebase / Google Cloud: hosting and storage of application records.
- Resend: confirmation and application emails.
- Telegram: limited operational notifications to the course team when a new application arrives.
- PostHog: consent-gated product analytics, session replay, and error tracking on the Keystone pages, processed in the European Union. Once you submit the waitlist form, the analytics identifier collected on the Keystone pages is linked to the email address you provided.
- Payment providers: where used to complete enrollment payments, under the payment section of the main Privacy Policy.
Transfers outside the EEA rely on the safeguards described in the main Privacy Policy, such as adequacy decisions or standard contractual clauses.
Retention
- Unconfirmed applications and expired confirmation tokens may be deleted after a reasonable period.
- Application records are kept while your application or cohort participation is active and then as needed for audit, dispute resolution, and legal claims.
- Invoice, payment, and accounting records are retained for statutory periods, including up to 10 years where German accounting and tax rules require it.
Your Rights
You have the rights described in the main Privacy Policy, including access, rectification, erasure, restriction, objection, and withdrawal of consent for future processing. To exercise them, email [email protected]. You may also lodge a complaint with a supervisory authority; the Hamburg authority is listed in the main policy.
Changes
We may update this notice when the course, our processors, or legal requirements change. The date at the top shows when this version was last updated.