Privacy Policy

01Who we are

Data101 is operated by Mohammad Sayfe, a sole trader based in Amman, Jordan (Aktham Bin Saifi Street, Bin Auf Neighborhood, Al-Jubaiha, Amman 11941, Jordan). For data-protection law, the operator is the controller of the personal data described here. Contact: [email protected].

Because Data101 is established in Jordan and the site serves visitors in the United Kingdom and the European Union, we aim to comply with:

02What we collect, and why

Booking details

When you book at cal.data101.uk (our self-hosted booking system) we collect your name, email address, the time you pick, your time zone, and anything you type into the booking notes. Purpose: scheduling and running your sessions, and sending confirmation, reminder and rescheduling emails. Lawful basis: taking steps at your request before, and performance of, our agreement to provide the session (UK/EU GDPR Art. 6(1)(b)); contractual necessity under the PDPL. Kept for: 24 months after your last session, then deleted.

Email

If you write to [email protected] we hold your address and whatever you send us. Purpose: replying, and keeping the context of our conversation. Lawful basis: our legitimate interest in responding to people who contact us. Kept for: 24 months after our last exchange.

Session notes and recordings

We keep brief notes of sessions — goals, progress, agreed next steps — to prepare and follow up. The lawful basis is performance of our agreement, and notes are kept with your booking record, on the same 24-month schedule.

We do not record sessions. If we ever propose recording one, we will ask for your explicit consent first, each time, and you can decline without affecting the session.

Technical data

Our web server and Cloudflare (our network provider) log IP addresses and browser information for security and to keep the site running. Lawful basis: our legitimate interest in operating and securing the site. Kept for: 30 days.

What we don’t collect

No payment or card data (the service is currently free and nothing on the site takes payment). No analytics or behavioural tracking. No advertising identifiers. We never sell personal data, and we make no automated decisions about you and build no profiles.

03Cookies

The marketing site at data101.uk sets no cookies of its own and runs no analytics.

Because everything set is strictly necessary, no consent banner is currently shown. If we ever add analytics or any other non-essential cookie, we will ask for your consent before setting it, as UK PECR and the ePrivacy rules require.

Everything else the site needs — scripts, styles, fonts — is served from data101.uk itself, delivered through Cloudflare as our network provider. Your browser contacts no other third party.

04Who we share data with

We use a small number of service providers (processors):

We share your data with no one else, and we never sell it.

05International transfers

Data101 is operated from Jordan, and Jordan does not have a UK or EU adequacy decision. In practice:

For access from Jordan we rely on [safeguard under legal review — UK IDTA / EU Standard Contractual Clauses / direct-collection analysis], alongside technical measures: TLS on every connection, a firewalled server, and access limited to the operator alone.

06Your rights

Under the UK and EU GDPR you can ask us to: give you a copy of your data (access); correct it; delete it; restrict or object to how we use it; hand it over in a portable format; and, where we rely on consent, withdraw that consent at any time. Jordan’s PDPL gives you equivalent rights of access, correction, erasure and objection, and the right to withdraw consent.

To use any of them, email [email protected] — no form, no fee. We respond within one month (UK/EU) or within the period the PDPL requires.

Complaints: we’d appreciate the chance to fix things first, but you can go directly to:

07Children

Data101 is for people aged 16 or over, and booking a session confirms you meet that age. The service is not directed at children and we do not knowingly collect children’s data. If you believe a child has booked or written to us, contact [email protected] and we will delete the data.

08Security

TLS on every connection, a firewalled server, and access limited to the operator. The strongest protection, though, is a deliberately small footprint: we collect little, keep it briefly, and add nothing we don’t need.

09Changes and contact

When our practices change we will update this page and revise the “Last updated” date above. If a change materially affects existing mentees, we will email you before it takes effect.

Questions about this policy, or about your data: [email protected]. See also our Terms of Service.