Privacy Policy
Data101 is a small, one-person data mentoring practice. This policy explains what personal data we handle when you visit data101.uk, book a session at cal.data101.uk, or email us — and what your rights are. It is short because the data we handle is genuinely limited: no analytics, no advertising, no payment processing.
01Who we are
Data101 is operated by Mohammad Sayfe, a sole trader based in Amman, Jordan (Aktham Bin Saifi Street, Bin Auf Neighborhood, Al-Jubaiha, Amman 11941, Jordan). For data-protection law, the operator is the controller of the personal data described here. Contact: [email protected].
Because Data101 is established in Jordan and the site serves visitors in the United Kingdom and the European Union, we aim to comply with:
- Jordan’s Personal Data Protection Law No. 24 of 2023 (PDPL);
- the UK GDPR and the Data Protection Act 2018, for visitors in the UK;
- the EU GDPR, for visitors in the European Economic Area.
02What we collect, and why
Booking details
When you book at cal.data101.uk (our self-hosted booking system) we collect your name, email address, the time you pick, your time zone, and anything you type into the booking notes. Purpose: scheduling and running your sessions, and sending confirmation, reminder and rescheduling emails. Lawful basis: taking steps at your request before, and performance of, our agreement to provide the session (UK/EU GDPR Art. 6(1)(b)); contractual necessity under the PDPL. Kept for: 24 months after your last session, then deleted.
If you write to [email protected] we hold your address and whatever you send us. Purpose: replying, and keeping the context of our conversation. Lawful basis: our legitimate interest in responding to people who contact us. Kept for: 24 months after our last exchange.
Session notes and recordings
We keep brief notes of sessions — goals, progress, agreed next steps — to prepare and follow up. The lawful basis is performance of our agreement, and notes are kept with your booking record, on the same 24-month schedule.
We do not record sessions. If we ever propose recording one, we will ask for your explicit consent first, each time, and you can decline without affecting the session.
Technical data
Our web server and Cloudflare (our network provider) log IP addresses and browser information for security and to keep the site running. Lawful basis: our legitimate interest in operating and securing the site. Kept for: 30 days.
What we don’t collect
No payment or card data (the service is currently free and nothing on the site takes payment). No analytics or behavioural tracking. No advertising identifiers. We never sell personal data, and we make no automated decisions about you and build no profiles.
03Cookies
The marketing site at data101.uk sets no cookies of its own and runs no analytics.
- The booking pages and embedded widget (cal.data101.uk) set cookies that are strictly necessary for the booking flow to work.
- Cloudflare may set strictly necessary security cookies while protecting the site.
Because everything set is strictly necessary, no consent banner is currently shown. If we ever add analytics or any other non-essential cookie, we will ask for your consent before setting it, as UK PECR and the ePrivacy rules require.
Everything else the site needs — scripts, styles, fonts — is served from data101.uk itself, delivered through Cloudflare as our network provider. Your browser contacts no other third party.
04Who we share data with
We use a small number of service providers (processors):
- Hetzner Online GmbH (Germany) — hosts our web server and the booking system, including its database, in its Nuremberg, Germany data centre (EU).
- Cloudflare, Inc. (US) — DNS, TLS and network security in front of data101.uk and cal.data101.uk; it processes visitor IP addresses.
- Google (Google Ireland Ltd / Google LLC) — bookings are synced to our Google Calendar, so your name, email and session time appear in a calendar entry.
- SMTP2GO — delivers booking confirmation and reminder emails from [email protected], via its EU servers.
- Apple Inc. — hosts our mailboxes (hello@ and bookings@) through iCloud custom email domains, so email you send us is stored with Apple.
We share your data with no one else, and we never sell it.
05International transfers
Data101 is operated from Jordan, and Jordan does not have a UK or EU adequacy decision. In practice:
- When you book or email us, you provide your data directly to a controller based in Jordan.
- Booking data is stored on Hetzner servers in Germany (EU) and accessed from Jordan by the operator; our email is likewise read from Jordan.
- Of our processors: Cloudflare, Google and Apple participate in the EU–US Data Privacy Framework and its UK extension; SMTP2GO processes our email on servers in the EU.
For access from Jordan we rely on [safeguard under legal review — UK IDTA / EU Standard Contractual Clauses / direct-collection analysis], alongside technical measures: TLS on every connection, a firewalled server, and access limited to the operator alone.
06Your rights
Under the UK and EU GDPR you can ask us to: give you a copy of your data (access); correct it; delete it; restrict or object to how we use it; hand it over in a portable format; and, where we rely on consent, withdraw that consent at any time. Jordan’s PDPL gives you equivalent rights of access, correction, erasure and objection, and the right to withdraw consent.
To use any of them, email [email protected] — no form, no fee. We respond within one month (UK/EU) or within the period the PDPL requires.
Complaints: we’d appreciate the chance to fix things first, but you can go directly to:
- the UK Information Commissioner’s Office — ico.org.uk;
- your local data-protection supervisory authority, if you are in the EEA;
- the Personal Data Protection Council under Jordan’s Personal Data Protection Law, via the Ministry of Digital Economy and Entrepreneurship (modee.gov.jo).
07Children
Data101 is for people aged 16 or over, and booking a session confirms you meet that age. The service is not directed at children and we do not knowingly collect children’s data. If you believe a child has booked or written to us, contact [email protected] and we will delete the data.
08Security
TLS on every connection, a firewalled server, and access limited to the operator. The strongest protection, though, is a deliberately small footprint: we collect little, keep it briefly, and add nothing we don’t need.
09Changes and contact
When our practices change we will update this page and revise the “Last updated” date above. If a change materially affects existing mentees, we will email you before it takes effect.
Questions about this policy, or about your data: [email protected]. See also our Terms of Service.