Effective: 25.08.2026

This Privacy Policy explains what personal data we collect when you visit our website or buy one of our courses, why we collect it, who we share it with, and what rights you have.

Who we are

The website aisessions.com and the course platform at learn.aisessions.com are operated by PRINTED LTD., a company registered in Bulgaria (“AI Sessions,” “we,” “us,” or “our”).

We are the data controller for the personal data described in this policy, which means we decide what data is collected and why.

You can contact us about anything in this policy at support@aisessions.com. Requests are handled directly by us.


1. What we collect

Information you give us

When you buy a course: your name, email address, billing country, and the details of your purchase. Your card details are entered directly with our payment processor — we never see or store your full card number.

When you create an account: your name, email address, and password. Your password is stored in encrypted form by our course platform and is not visible to us.

When you subscribe to our newsletter: your email address.

When you contact us: your email address and whatever you choose to include in your message.

Information collected automatically

Course activity: which lessons you have opened and completed, and your progress through a course. This is generated by our course platform and lets us see whether a course is working.

Technical and usage data: your IP address, browser type, device type, operating system, referring website, the pages you visit, and the dates and times of your visits.

Cookies and similar technologies: described in Section 5.

What we do not collect

We do not collect special category data (such as health, political opinions, or biometric data), and we do not ask for it. Please do not send it to us.

We do not knowingly collect data from anyone under 18. Our courses are sold to adults only. If you believe someone under 18 has given us personal data, contact us and we will delete it.


2. Why we use it, and our legal basis

Under the GDPR we must have a legal basis for each use of your data. Here is what we do and why.

What we use it forLegal basis
Giving you access to a course you bought, and running your accountPerformance of a contract
Processing your payment and issuing an invoicePerformance of a contract; legal obligation
Handling refund requestsPerformance of a contract; legal obligation
Answering your emails and providing supportPerformance of a contract; legitimate interests
Keeping accounting and tax recordsLegal obligation
Sending our newsletterConsent
Emailing existing customers about our own coursesLegitimate interests (you may opt out at any time)
Analytics, to understand how our website is usedConsent (EEA/UK); legitimate interests, with opt-out, elsewhere
Advertising and measuring ad performanceConsent (EEA/UK); legitimate interests, with opt-out, elsewhere
Keeping our website and accounts secure, and preventing fraudLegitimate interests
Defending or bringing legal claimsLegitimate interests; legal obligation

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and we have concluded it is not. You can object to any of this — see Section 7.

We do not sell your personal data. We do not share it with third parties for their own marketing. We do not use it to train AI models.


3. Who we share it with

We use a small number of service providers who process data on our behalf, under contract and only on our instructions.

ProviderWhat they doWhere
ThinkificHosts our course platform and your accountCanada
StripeProcesses paymentsUnited States, Ireland
GoogleWebsite analytics and advertising tagsUnited States
MetaAdvertising and ad measurementUnited States, Ireland
Our website host and email pluginRuns aisessions.com and sends our newsletterEuropean Union

We may also disclose personal data where we are legally required to — for example to tax authorities, or in response to a valid order from a court or public authority — and to our accountants and legal advisers where necessary.

If our business is sold or merged, customer data may transfer to the acquiring company. We would tell you before that happens.


4. International transfers

Some of the providers above are outside the European Economic Area. Where data is transferred outside the EEA, we rely on:

  • the European Commission’s adequacy decision for Canada, where applicable; and
  • Standard Contractual Clauses and/or certification under the EU–US Data Privacy Framework for providers in the United States.

You can ask us for more detail about the safeguards applying to any particular transfer.


5. Cookies

Cookies are small files stored on your device. We use them in three ways.

Functional (strictly necessary). Required to run the site, keep you logged in, and remember your cookie preferences. These cannot be switched off and do not need your consent.

Analytical. Google Analytics, to understand which pages people visit and how they got there.

Advertising. The Meta Pixel and Google advertising tags, used to measure how our ads perform and to show relevant ads to you on other platforms. These cookies may track your personal data.

Your control. If you are in the EEA or UK, analytics and advertising cookies are not set unless you accept them through our consent banner. If you are elsewhere, these cookies may be set by default and you can opt out at any time through the cookie settings link on our site. You can change your choice at any time, and you can block or delete cookies through your browser settings — though some parts of the site may then not work properly.


6. How long we keep it

DataRetention
Account and course access dataWhile your account is active
Purchase, invoice, and accounting recordsAs required by Bulgarian accounting and tax law (generally 5–10 years)
Newsletter subscriptionUntil you unsubscribe
Support emailsUp to 2 years after the matter is resolved
Analytics dataPer the retention settings of our analytics provider

After a refund, or if you ask us to delete your account, we delete your personal data except the purchase records we are legally required to keep.


7. Your rights

If you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your data, where we have no overriding legal obligation to keep it
  • Restrict how we use it, in certain circumstances
  • Port your data to another provider in a machine-readable format
  • Object to processing based on legitimate interests, including direct marketing
  • Withdraw consent at any time, where consent is our legal basis — this does not affect anything we did before you withdrew it

To exercise any of these, email support@aisessions.com. We will respond within one month. We may ask you to confirm your identity first.

Marketing opt-out. Every marketing email has an unsubscribe link. You can also just email us and ask.

Complaints. If you think we have handled your data improperly, please contact us first so we can put it right. You also have the right to complain to a supervisory authority — in Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), cpdp.bg. If you live elsewhere in the EEA, you may complain to your local authority instead.

If you are in the United States

Depending on your state, you may have rights to know what personal data we hold, to have it deleted or corrected, and to opt out of its sale or of targeted advertising. We do not sell personal data. To exercise any state privacy right, email us at the address above — we handle these requests the same way regardless of where you live.


8. Using ChatGPT with our courses

Some of our courses include a Course Companion — a custom assistant you set up inside ChatGPT using your own OpenAI account.

When you use it, your data goes to OpenAI, not to us. We do not receive, see, or store anything you type into ChatGPT. Your use of ChatGPT is governed by OpenAI’s own privacy policy and terms, and you should read them.

Be careful what you enter. If you paste details about a client, a property, or a transaction into ChatGPT, you are sharing that information with a third party. Depending on your profession and jurisdiction, you may have confidentiality or data protection obligations to the people involved. Our course materials are designed so you can use initials, partial addresses, and rounded figures instead of identifying details, and we recommend you do so.

You are responsible for what you enter into ChatGPT and for complying with any obligations you have to your own clients.


9. Security

We take reasonable technical and organisational measures to protect your data. Our website and course platform use encrypted connections (HTTPS), payment data is handled entirely by our payment processor under PCI-DSS standards, and access to customer data is limited to those who need it.

No system is completely secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you.


10. Changes to this policy

We may update this policy. If we make a material change, we will post the updated version here with a new effective date and, where appropriate, notify you by email.


11. Contact

Questions, requests, or complaints about your data:

support@aisessions.com

PRINTED LTD.
Bulgaria


Last updated: 25.08.2026