Privacy Policy
Last updated: April 2026
1. Data Controller
Enigmatica is operated by Modular Trading Solutions Ltd (Company No. 01869330), registered at 9 Mandeville Close, London, SW20 8SB. For any questions about how we handle your data, contact us at hello@enigmatica.ai.
2. What We Collect
We collect and process the following personal data:
- Registration data: your name and email address, provided when you create an account.
- Profile data: job title, company name, company size, and primary AI goal, provided optionally via progressive profiling prompts.
- Enterprise enquiry data: name, email, company name, team size, and message, provided when you submit an enterprise contact form.
- Progress data: lesson completion status and quiz results, stored to track your learning progress.
- Feedback data: any feedback or survey responses you voluntarily provide.
- Analytics data: anonymous, aggregate page view and referral data collected by Plausible Analytics (no cookies, no personal identifiers).
3. Lawful Basis for Processing
Under the UK GDPR, we rely on the following lawful bases:
- Consent (Article 6(1)(a)):
- Processing your registration data to create your account
- Sending you educational emails (welcome sequence, learning reminders, the AI Briefing newsletter)
You provide consent via the checkbox at registration. You may withdraw consent at any time (see Section 6).
- Legitimate interest (Article 6(1)(f)):
- Tracking your learning progress to deliver the service effectively
- Processing enterprise enquiries to respond to business requests
- Analysing feedback to improve the platform
- Domain clustering: we may identify when multiple registrations share a company email domain to determine whether an organisation may benefit from enterprise training. This processing is based on our legitimate interest in identifying potential enterprise clients.
- Aggregate, cookieless analytics via Plausible to understand platform usage
4. How We Use Your Data
- To provide access to the course, tools, and learning resources
- To track and display your learning progress
- To send you a welcome email and educational email sequence
- To respond to enterprise enquiries
- To identify potential enterprise training opportunities via domain clustering
- To improve the platform based on aggregate usage data and feedback
5. Third-Party Services
We share your data with the following service providers, solely for the purposes described above:
- Supabase (EU-hosted) — database and authentication
- Resend (US-based, Standard Contractual Clauses in place) — transactional and marketing email delivery
- Plausible Analytics (EU-hosted) — cookieless, privacy-focused web analytics
- Vercel (US-based, Standard Contractual Clauses in place) — website hosting and delivery
We do not sell your data to anyone. We do not share your data with third-party advertisers.
6. Your Rights
Under UK GDPR, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to restrict processing: request that we limit how we use your data.
- Right to object: object to processing based on legitimate interest, including domain clustering.
- Right to withdraw consent: withdraw your consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email hello@enigmatica.ai. We will respond within 30 days. To delete your account and all personal data, visit enigmatica.ai/account/delete.
To unsubscribe from emails, use the unsubscribe link included in every email we send, or visit enigmatica.ai/unsubscribe.
7. International Data Transfers
Your data is primarily stored and processed within the EU/UK. Where data is transferred to the United States (Resend, Vercel), appropriate safeguards are in place via Standard Contractual Clauses (SCCs) as approved by the UK ICO.
8. Data Retention
- Registration and profile data: retained until you request deletion of your account.
- Email preferences: retained until you unsubscribe.
- Progress data: retained for as long as your account is active.
- Feedback data: retained for up to 2 years.
- Enterprise enquiry data: retained for up to 3 years.
9. Cookies
We use a single session/authentication cookie that is strictly necessary for the platform to function. This cookie does not track you across other websites.
We do not use any third-party tracking cookies. Our analytics provider (Plausible) is entirely cookieless. Because we only use strictly necessary cookies, no cookie consent banner is required under UK GDPR / PECR.
For more details, see our Cookie Policy.
10. Children
Enigmatica is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at hello@enigmatica.ai and we will delete it promptly.
11. Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we will notify you via email. The “last updated” date at the top of this page indicates when the policy was last revised.
12. Contact
If you have any questions about this privacy policy or how we handle your data, contact us at hello@enigmatica.ai.
Supervisory authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113