Legal
Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how Saturday Code Club (“we”, “us”, “our”) collects, uses, shares and protects personal data when you use this website and our services. We are committed to handling your personal data in accordance with the UK GDPR, the EU General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
1. Who we are (Data Controller)
Saturday Code Club is the data controller responsible for your personal data.
Contact: privacy@saturdaycodeclub.co.uk
(replace with your real contact / postal address).
2. The personal data we collect
- Account data: full name, email address, password (stored only as a salted hash).
- Authentication & security data: two-factor authentication settings, login timestamps, IP addresses, and security audit logs (used to protect your account).
- Billing data: subscription status and payment history. Card details are entered directly with our payment provider and are not stored on our servers.
- Content you submit: information you enter into the platform, including any prompts, text or code you choose to process using AI features.
- Technical data: cookies and similar technologies (see our Cookie Policy).
3. How and why we use your data (lawful bases)
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Securing accounts (2FA, lockout, audit logs) | Legitimate interests / legal obligation |
| Taking payments and managing subscriptions | Performance of a contract |
| Sending service emails (confirmation, password reset) | Performance of a contract |
| Providing AI-assisted features you request | Performance of a contract / consent |
| Improving and securing our services | Legitimate interests |
| Non-essential cookies / analytics (if any) | Consent |
4. Sharing your data with third parties
We do not sell your personal data. We share it only with trusted service providers (“processors”) who help us operate the service. Information you provide may be sent to and processed by the following categories of third parties:
- Payment providers. We use Stripe to process payments and manage subscriptions. When you pay, your payment and related personal data are processed by Stripe under their own privacy policy.
- Email providers. We use Brevo (Sendinblue) to send transactional emails such as account confirmation and password-reset messages. Your name and email address are processed by Brevo for this purpose.
- AI providers. When you use AI-assisted features, the content you submit (for example prompts, text or code) may be sent to and processed by third-party AI providers to generate a response. Please avoid submitting sensitive personal or confidential information to AI features.
- Hosting and infrastructure providers that store and run the application and its database.
Each provider only processes your data on our instructions and under a data-processing agreement, and is responsible for keeping it secure.
5. International transfers
Some of our providers (including payment, email and AI providers) may process data outside the UK / European Economic Area. Where this happens, we rely on appropriate safeguards such as UK/EU adequacy decisions or Standard Contractual Clauses to protect your data.
6. How long we keep your data
We keep personal data for as long as your account is active and as needed to provide the service, then for any period required to meet legal, accounting or security obligations. Security audit logs are retained for a limited period to detect and investigate misuse.
7. Your rights
Under the UK GDPR / GDPR you have the right to:
- access a copy of your personal data;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”), where applicable;
- restrict or object to processing;
- data portability;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us using the details above. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority.
8. How we protect your data
We apply industry-standard security measures, including encrypted (HTTPS) connections, hashed passwords, two-factor authentication, account lockout, rate limiting, anti-forgery protection, strict security headers and access controls.
9. Children
Where our services are used by children, we only process the minimum data necessary and expect appropriate parental or school consent in line with applicable law.
10. Changes to this policy
We may update this policy from time to time. We will post any changes on this page and update the “last updated” date above.
See also our Cookie Policy and Terms & Conditions.