Your data,
clearly explained.

Boffin Hub is built on trust. This page explains what personal data we collect when you use the site or book a session, why we collect it, who else sees it, how long we keep it, and how to ask us to stop. The data controller is AI Boffin Hub Ltd, registered at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, contactable via our contact form at aiboffinhub.com/book.

Last updated
May 2026
We'll email you before any meaningful changes.
01

What we collect

We collect the minimum personal data needed to match you with the right specialist and run your coaching sessions. Specifically:

  • Matching form: your name, email, role, company size, the track you’re interested in (Claude Code, Claude Design, or Claude Cowork), what you want to do with Claude, your scheduling preferences, and any free-text notes you add.
  • Booking metadata: which specialist you’re matched with, your preferred session cadence, and timezone.
  • Session content: during a live coaching session your specialist can see whatever you choose to share, your screen, your files, your prompts, and Claude’s output. We do not record sessions by default. If a session is recorded for any reason (for example, if you ask for one), you’ll be told before the recording starts.
  • Session follow-ups: written summaries your specialist sends after each session, what you covered, what to practise, links to anything they referenced.
  • Attribution metadata: when you arrive on the site through a marketing link, we capture the campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), Google/Meta click IDs (gclid, fbclid), the referring site, and the landing page. Stored in your browser only and submitted with your matching form so we know which campaigns work.
  • Hosting access logs: our host (Netlify) records standard server data, IP address, user agent, requested URL, timestamp. Used for security monitoring and abuse prevention.
  • Browser local storage: your in-progress matching form (so a refresh doesn’t lose it), your dark mode preference, and whether you’ve dismissed our sticky CTA. None of this is transmitted to us, it stays in your browser until you clear it.

We do not collect special category data (health, religion, biometrics, etc.) and we don’t need it. If a session inadvertently surfaces this kind of data because of the work you brought, your specialist will treat it with the same confidentiality as everything else and will not retain it.

02

How we use it

Each thing we collect maps to a specific purpose. Under UK GDPR / EU GDPR Article 6, our lawful basis is shown beside each one.

  • Matching your submission to the right specialist (lawful basis: performance of contract, taking steps at your request before entering a contract).
  • Scheduling, running, and following up on your coaching sessions (lawful basis: performance of contract).
  • Processing payment and issuing invoices (lawful basis: contract + legal obligation for tax records).
  • Replying to enquiries you send via our contact form (lawful basis: legitimate interests, answering people who contact us).
  • Aggregated, anonymised analytics to improve which specialist we match to which kind of request (lawful basis: legitimate interests, improving service quality).
  • Security, fraud prevention, and abuse monitoring on hosting logs (lawful basis: legitimate interests).

We do not use your data to train AI models, including Anthropic’s Claude. Your work, your prompts, and your session content are not shared with Anthropic by us, and we have no commercial relationship that would let them be. We do not sell advertising or build marketing profiles.

03

What we don't do

Some things we simply won't do, no caveats, no fine print.

Sell your data
Share with advertisers
Train AI on your content
Cold-call you
Spam your inbox
Track you across sites
04

Specialists & subprocessors

Your specialist sees what they need to run your sessions well, and no more.

  • Specialists see your name, your matching-form responses, and the session notes for your track. They do not see other learners’ data, your billing information, or your hosting logs.
  • Confidentiality is enforced by non-retention rather than paperwork: we do not retain any details of your data or your work outside of the live session itself.
  • Re-matches are free within your first two sessions if a specialist isn’t the right fit.

How sessions actually run. Our default and recommended model is bring your own account: you log in to Claude in your own browser, share your screen, and your specialist guides you, including typing into your environment to demonstrate prompts or resolve issues. In that model, your work, files, and prompts never leave your Claude account or your machine. Boffin Hub holds nothing.

If for any reason a session is run inside a Boffin Hub-controlled Claude account instead of your own (rare, and only with your explicit agreement), Anthropic’s standard terms and privacy policy apply to that session content in the same way they apply to any other Claude user. We still don’t retain it on our side once the session ends.

Beyond our specialists, we use a small set of subprocessors to run the service. The current list:

NetlifySite hosting + form submissionsUnited States (with EU/UK data transfer safeguards)
Google WorkspaceDocument storage and form submissionsUnited States (Standard Contractual Clauses)
Plausible AnalyticsCookieless, aggregate site analyticsEuropean Union
Cal.comBooking, scheduling and the live video session itselfUnited States (GDPR, SOC 2 Type II and ISO 27001 certified, formal Data Processing Agreement in place)
StripeCard payment processing for paid sessionsUnited States / European Union (Standard Contractual Clauses)

If we add or change a subprocessor, this list is updated and the change is reflected in the “Last updated” date at the top of the page.

05

Data retention

We don’t keep data longer than we need to. Here is how long each thing lasts.

Matching submissionsHeld for 12 months from the date of submission, then deleted unless you’ve become an active learner
Active learner recordHeld while you are an active learner, plus 12 months after your last session
Session notesHeld for 24 months after your last session, then deleted
Payment / invoice recordsHeld for 7 years in line with HMRC guidance on business record-keeping for tax purposes
Email correspondenceHeld for 24 months from the most recent message in the thread
Hosting access logsHeld by Netlify for ~30 days, then automatically purged
Aggregated analyticsAggregated and anonymised at collection; not tied to identity
06

Your rights

Under the UK GDPR and EU GDPR, you have the following rights over the personal data we hold about you:

  • Right of access, ask us for a copy of everything we hold on you.
  • Right to rectification, ask us to correct anything inaccurate.
  • Right to erasure, ask us to delete your data (subject to retention obligations like tax records).
  • Right to restrict processing, ask us to pause certain uses of your data.
  • Right to data portability, ask us to send you your matching-form answers and session notes in a structured, machine-readable format.
  • Right to object, to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent, at any time, where consent was the basis for processing. Withdrawal does not affect anything we did before you withdrew.

To exercise any of these, use our contact form and choose "Data request (privacy)" as the enquiry type. We respond within 5 working days and complete the request within the statutory 30 days. If you’re not happy with how we’ve handled it, you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to the data protection authority in your EU country of residence.

California residents (CCPA / CPRA): you have the right to know what we collect, the right to delete it, the right to correct it, and the right to opt out of sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA. To exercise CCPA rights, use the same contact form and enquiry type.

07

Cookies & local storage

The Boffin Hub site itself currently sets no cookies. We use browser local storage instead, which never leaves your device and is not transmitted to our servers.

boffin_booking_dataFunctionalSaves your in-progress matching form so a refresh doesn’t lose it. Cleared automatically when you submit.Until submit
boffin_attributionFunctionalFirst-touch marketing attribution: UTM params, click IDs, referrer, landing page. Submitted with your matching form so we know which campaigns work.Until submit
bh-darkFunctionalRemembers if you’ve toggled dark mode on the homepage.Until cleared
bh-sticky-cta-dismissedFunctionalStops the “Book now →” pill re-appearing in the same browser tab once you’ve dismissed it.Tab session

We use Plausible Analytics to see which pages people find useful. It is privacy-first by design: it sets no cookies, stores nothing on your device, and does not collect IP addresses or any data that identifies you. We only ever see aggregate figures, such as how many people visited a page and roughly where in the world they were. Data is processed in the EU. Lawful basis: legitimate interests. We do not use advertising cookies, third-party tracking pixels, or social media widgets that profile you across sites.

08

Security

We take reasonable and appropriate technical and organisational measures to protect your personal data, in line with UK GDPR Article 32.

  • All traffic to and from aiboffinhub.com is encrypted in transit using TLS, served via Netlify’s CDN with HSTS enforced.
  • Form submissions are stored encrypted at rest by Netlify Forms.
  • Two-factor authentication is required on every administrator account that can access learner data.
  • A Content Security Policy restricts scripts to our own domain and a small allowlist, and blocks the site from being framed by others.
  • No production systems are accessible from the public internet without authentication.
  • Specialists access learner data through accounts that follow the same 2FA + minimum-necessary-access principles.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours and inform you directly without undue delay.

09

Changes to this policy

If we make meaningful changes to this policy, we'll email you at least 14 days before they take effect. Minor clarifications (typos, formatting) won't warrant a notice.

The version date at the top of this page always reflects the last substantive update.

10

Children & international transfers

Boffin Hub is for working professionals and is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, please use our contact form and we will delete it.

Some of our subprocessors (listed in section 04) are located outside the UK and EEA. Where they are, we rely on the UK International Data Transfer Agreement and EU Standard Contractual Clauses to keep your data protected to the same standard you’d expect at home.

11

Contact us

Privacy questions, data requests, complaints, or anything else, we’re reachable.

Enquiry type for data requestsData request (privacy)
Response timeWithin 5 working days; complete within 30 days (UK GDPR statutory limit)