This Privacy Policy explains what personal data we process when you use the ATJ Research members area at https://member.atjresearch.com (the "Service"), why, for how long, who receives it, and what rights you have. It applies together with our Terms and Conditions.
1. Who is responsible for your data
The controller is ATJ Traders s.r.o., company ID (IČO) 21360588, with its registered office at Šafránkova 1238/1, Stodůlky, 155 00 Praha, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 400740. For anything concerning your personal data, write to [email protected]. We have not appointed a data protection officer, as we are not required to.
2. What we process, why, and on what legal basis
| Data | Why we use it | Legal basis (GDPR) |
|---|---|---|
| Account: email address, name (if you give one), password (stored only as an Argon2 hash, never readable), whether and when you confirmed your email, time of your last sign-in. | To create and secure your account, sign you in, and send you service emails (confirmation, password reset, welcome, payment problems, security notices, changes to the Terms). | Performance of our contract with you, Art. 6(1)(b). |
| Sign in with Google: Google's identifier for your account and, when you first sign in, the email address and name Google shares. We do not receive your Google password or any other Google data. | To let you sign in with Google and to link it to your account. | Contract, Art. 6(1)(b). |
| Members from our previous website: your Wix member identifier, the status and end date of your Wix plan, and a Wix token that lets us re-check that plan without asking you to sign in again. | To honour the membership you already paid for through Wix. | Contract, Art. 6(1)(b). |
| Accounts you choose to connect: your GitHub username; your Discord user identifier, username and a Discord token limited to identifying you and adding you to our server. | To give you read access to our private repositories and the members' role on our Discord server, and to remove both when the membership ends. | Contract, Art. 6(1)(b). Connecting is optional. |
| Membership and payments: your Stripe customer identifier, the status and billing period of your subscription, and for each payment its date, amount, currency, Stripe reference and whether it was refunded or disputed. We never receive or store your card details. | To know whether your membership is active, show you your payment history, handle refunds and disputes, and keep our accounts. | Contract, Art. 6(1)(b); legal obligation (accounting and tax law), Art. 6(1)(c). |
| Your acceptance of the Terms: the version you accepted, when, and the checkout it belonged to, including your request for immediate access and the withdrawal waiver. | To be able to prove what was agreed. | Legitimate interest in establishing and defending legal claims, Art. 6(1)(f). |
| Usage log: that, and when, you opened a lesson, downloaded a file, opened a web application, activated a desktop licence, were granted repository access or connected Discord. | To decide refund requests under the Refund Policy, to answer payment disputes, and to operate the Service. We do not use it for advertising or profiling. | Legitimate interest, Art. 6(1)(f). |
| Desktop licences: the name and email written into your licence, a technical identifier of each machine you activate, the application name and version, and when the licence was last renewed or refused. Connection tokens are stored only as hashes. | To issue and renew licence keys, enforce the limit of 2 machines, and help you when an application stops working. | Contract, Art. 6(1)(b); legitimate interest in preventing misuse, Art. 6(1)(f). |
| API tokens you create (stored only as hashes) and when each was last used. | To authenticate your requests to our data API. | Contract, Art. 6(1)(b). |
| Technical data: IP address, time, requested address and browser type in server logs; short-lived counters of sign-in and licence requests per IP address or account. | To keep the Service secure and working: detecting abuse, limiting password guessing, diagnosing faults. | Legitimate interest, Art. 6(1)(f). |
| Messages you send us by email. | To answer you. | Contract or steps before a contract, Art. 6(1)(b); otherwise legitimate interest, Art. 6(1)(f). |
We do not buy data about you, we do not sell your data, we do not send marketing email, and we do not use analytics or advertising trackers. We do not ask for or need any special categories of data.
Providing an email address and a password (or a Google sign-in) is necessary to have an account; without them we cannot provide the Service. Everything marked optional above is up to you.
3. Automated decisions
Two things are decided automatically by rules, not by profiling: whether your membership is active (from your subscription status), and whether a refund request is eligible (from the time of your first purchase and the usage log, exactly as the Refund Policy describes). If you think either result is wrong, write to us and a person will review it.
4. Who receives your data
We share personal data only with the providers we need to run the Service:
- Stripe (payments). The Stripe group company named at checkout, operating as "Link", is the merchant of record: it sells you the membership as our reseller and is an independent controller of the payment data you give it, under its own privacy policy. We send Stripe your email address, name and our internal member number so that your payment can be matched to your account.
- DigitalOcean (hosting, database and file storage), in data centres in the United Kingdom and the European Union.
- Google, only if you use Sign in with Google.
- GitHub (Microsoft) and Discord, only if you connect those accounts: we send them your username or identifier to add you to, or remove you from, our team or server.
- Wix, only for members who joined through our previous website and sign in with Wix.
- Our email delivery provider, which transmits the service emails we send you.
- Our accountants, legal advisers and public authorities, where the law requires or a legal claim makes it necessary.
Market data shown in the web applications is fetched by our servers. Exchanges, brokers and data vendors do not receive any information about you from us.
5. Transfers outside the European Economic Area
Our hosting is in the United Kingdom, which is covered by a European Commission adequacy decision. Some of our other providers are based in, or may process data in, the United States (Stripe, Google, GitHub, Discord) or Israel (Wix). Transfers to the United States rely on the provider's certification under the EU-U.S. Data Privacy Framework or on the European Commission's standard contractual clauses; Israel is covered by a Commission adequacy decision. You can ask us for details of the safeguard used for a particular provider.
6. How long we keep it
- Account, connected accounts, licences, API tokens: for as long as you have an account. You can disconnect Google, GitHub or Discord at any time on the Account page.
- When you delete your account (Account page, "Delete account"): any subscription is cancelled, your access is removed, and your email address, name, password, sign-in identifiers, connected accounts and tokens are erased at once. The account number remains as an anonymous key for the records below.
- Payment records and your acceptance of the Terms: 10 years from the end of the year of the payment, as accounting and tax law requires, and as long as needed for legal claims.
- Usage log: for as long as the payment records it relates to are kept, because it is the evidence for refund and dispute decisions. After account deletion it is no longer linked to your name or email.
- Server logs: a short period, normally no longer than 30 days.
- Emails you send us: up to 3 years after the matter is closed.
7. Cookies and browser storage
We use one essential cookie: it keeps you signed in and protects forms against cross-site request forgery. It contains no tracking identifier and is deleted when you sign out or it expires. One web application can remember your list of favourites in your browser's local storage; that list never leaves your browser. Because we use only what is strictly necessary, we do not show a cookie banner. Stripe, Google, GitHub and Discord set their own cookies on their own pages when you visit them.
8. Security
Connections to the Service are encrypted. Passwords are stored as Argon2 hashes; API tokens and desktop connection tokens are stored only as hashes; the database connection is encrypted; access to production systems is limited to the people who operate the Service. No system is perfectly secure: if a breach affecting your rights occurs, we will inform you and the supervisory authority as the law requires.
9. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy;
- have inaccurate data corrected (you can change your name and connected accounts yourself);
- have your data erased (the "Delete account" function does this, subject to the records the law requires us to keep);
- restrict processing in certain cases;
- receive the data you gave us in a portable format;
- object to processing that is based on our legitimate interests, including the usage log; we will then stop unless we have compelling grounds or need the data for legal claims.
Write to [email protected]. We answer within one month and may ask you to confirm your identity first. You also have the right to complain to the supervisory authority: in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz), or the authority where you live.
10. Age
The Service is for adults. We do not knowingly process data of anyone under 18.
11. Changes
If we change how we process personal data, we will update this page and its version, and tell you by email when the change is significant.