Legal · Privacy

PRIVACY

This notice explains what personal data is processed on andrepitie.com, why it is processed, which service providers are involved, and what rights you have.

Last updated: 4 October 2026

1. Controller and contact

The controller for this website is André Pitié, Almstadtstraße 46, 10119 Berlin, Germany. For privacy questions or data-subject requests, email hello@andrepitie.com.

2. What this website does

andrepitie.com is a public portfolio and learning website. Some course, mentoring and workspaces are protected and require an approved account. The site does not intentionally use advertising pixels or public-site analytics trackers at the date of this notice.

3. Data processed

  • Basic technical data: requests to the website can include IP address, browser/device information, date/time, requested URL and security/diagnostic metadata generated by the hosting platform.
  • Account and access data: email address, name, access scope and, where relevant to a course or workspace, profile information such as programme, education, languages, LinkedIn URL, nationality, roles, profile summary or profile photo.
  • Authentication security logs: email address, sign-in date/time, sign-in method, browser/device information, approximate country when available, language/host information and a masked network prefix. The application deliberately masks IP addresses before storing this authentication log.
  • AI course assistant: when an authorised user chooses to use the course assistant, the submitted conversation and selected course context are sent to the OpenAI API to generate an answer.

4. Purposes and legal bases

  • Providing requested protected learning/workspace functionality and authentication: Article 6(1)(b) GDPR where processing is necessary for a contractual service, or Article 6(1)(f) GDPR where the legitimate interest is to provide and administer the requested educational or professional service.
  • Fraud prevention, access control, debugging and service security: Article 6(1)(f) GDPR, based on the legitimate interest in operating a secure service.
  • Compliance with legal obligations where applicable: Article 6(1)(c) GDPR.
  • Where a future feature genuinely requires consent, Article 6(1)(a) GDPR will be used and consent can be withdrawn for the future.

5. Cookies and local device storage

The site currently uses authentication/security cookies rather than advertising or analytics cookies. These include:

  • ap_csrf — short-lived security token, normally up to 10 minutes.
  • __session — authenticated session, normally up to 5 days.
  • ap_google_credential — temporary Google sign-in credential hand-off, normally up to 2 minutes.
  • Google Identity Services may also use an anti-CSRF cookie during the Google sign-in flow.

These mechanisms are used for sign-in, session security and delivery of protected services. A general advertising/analytics consent banner is therefore not currently used. If optional tracking is introduced later, this notice and the consent mechanism must be updated before that tracking is activated.

6. Service providers and recipients

  • Google Cloud / Firebase — website hosting, database services and authentication infrastructure.
  • Google Identity Services — optional Google account sign-in.
  • Microsoft — optional Microsoft account sign-in through Firebase Authentication.
  • Brevo — delivery of one-time login-code emails when email sign-in is used.
  • OpenAI API — generation of answers in the protected course assistant. The application sets store: falseon these API requests. OpenAI states that API business data is not used to train models by default. Limited API data can still be retained for abuse and security monitoring under OpenAI's API data controls unless a qualifying zero-data-retention configuration applies.
  • Google Slides — some protected learning pages offer an optional embedded presentation. The Google connection is initiated only when the user chooses to load the embedded viewer.

7. International transfers

Some service providers operate globally and processing may take place outside the EEA. Where GDPR transfer restrictions apply, transfers are handled using an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses and the provider's data-processing terms.

8. Retention

  • One-time email login-code records expire after about 10 minutes.
  • Detailed authentication attempts and sign-in event logs are retained for up to 90 days.
  • The minimal authentication summary is retained for up to 12 months after the last sign-in.
  • Active course/workspace access profiles are retained while access is required. When access is revoked, the access record is scheduled for deletion after up to 12 months unless a shorter period is appropriate or continued retention is legally required.
  • The course assistant sets store: false and the application does not intentionally persist the text of course-assistant conversations after the request, apart from operational metadata such as usage/quota information. OpenAI may separately retain limited API data for abuse/security monitoring under its API data controls unless zero data retention applies.
  • Hosting providers can generate operational/security logs under their service configuration; their retention follows the configured cloud service and applicable provider terms.

9. Your rights

Subject to the conditions of the GDPR, you may request access, rectification, erasure, restriction, data portability where applicable, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent for the future.

Send requests to hello@andrepitie.com. You also have the right to complain to a competent data-protection supervisory authority. In Berlin, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

10. Automated decision-making

The website does not use solely automated decision-making that produces legal effects or similarly significant effects on visitors. The course AI assistant is an informational learning feature and does not decide access, grades, employment or other legal rights.

11. External links

Links to services such as LinkedIn, Google Calendar, Google Drive or other third-party sites open those services separately. Their own privacy notices apply once you choose to visit them.

Kurzfassung auf Deutsch

DATENSCHUTZ AUF EINEN BLICK

Verantwortlicher ist André Pitié, Almstadtstraße 46, 10119 Berlin, Deutschland. Datenschutzanfragen können an hello@andrepitie.com gesendet werden.

Die öffentliche Website verwendet derzeit bewusst keine Werbepixel oder allgemeinen Web-Analytics-Tracker. Technisch notwendige Cookies werden für Anmeldung, Sitzungsschutz und geschützte Bereiche eingesetzt.

Für Hosting und Authentifizierung werden Google Cloud/Firebase sowie optional Google- und Microsoft-Anmeldung genutzt. Brevo versendet Einmalcodes per E-Mail. Der geschützte Kursassistent nutzt die OpenAI API mit store: false; OpenAI kann nach seinen API-Datenkontrollen dennoch begrenzte Daten zur Missbrauchs- und Sicherheitsüberwachung aufbewahren, sofern keine Zero-Data-Retention-Konfiguration gilt. Detaillierte Authentifizierungsprotokolle werden bis zu 90 Tage aufbewahrt.

Betroffene Personen haben insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung und Widerspruch nach Maßgabe der DSGVO sowie ein Beschwerderecht bei einer Datenschutzaufsichtsbehörde.

Back to andrepitie.com