Privacy Policy
Effective date: 3 September 2026
This privacy policy explains how Bharat Sharma collects and uses personal data through aieasypart.com, the website for AI Is the Easy Part.
Who is responsible for your data?
Bharat Sharma, trading as a sole trader, is the controller of the personal data described in this policy.
Email: bharat@aieasypart.com
You may contact us about this policy or to exercise your data-protection rights.
Information we collect and why we use it
Sample chapter
If you request a sample chapter, we collect your email address so that we can send it to you. We use this information on the basis of our legitimate interests in responding to your request.
If you separately tick the box to receive the four-email follow-up series about the book, we use your email address for that purpose on the basis of your consent. Requesting the sample chapter does not require you to agree to those emails, and you will receive the chapter either way.
“For Teams” enquiries
If you submit a bulk-purchase enquiry, we collect your name, job title, work email address, company, organisation-size band, the package you are interested in, and anything you write in your message.
We use this to respond to and manage the enquiry. Where you are considering contracting personally, the basis is taking steps at your request before entering into a contract. Where you are acting for an organisation, the basis is our legitimate interests in responding to its enquiry.
Please do not include sensitive personal information, or information that is not necessary for the enquiry.
Bulk-purchase receipt verification
If you submit evidence of a bulk purchase, we collect your name, work email address, company, any order reference, and the receipt file you upload.
We use this to verify the purchase and administer the bulk-purchase arrangement. The basis is performance of a contract or taking requested pre-contractual steps where you are the contracting party, and our legitimate interests in verifying an organisation's purchase where you submit on its behalf.
Uploaded files are stored privately and are not publicly accessible. Before uploading, please redact payment-card numbers, bank details, home addresses, and information about other people unless it is genuinely needed for verification.
Diagnostic quiz and shareable results
When you use the diagnostic quiz, we collect your answers to fifteen questions expressing views about your employer, your seniority band and organisation-size band if you choose to provide them, your country, campaign-attribution information such as UTM parameters, and the technical information needed to store and retrieve the result.
We use this to calculate your result and make it available at a unique, shareable URL. Our basis is our legitimate interests in providing the diagnostic, maintaining the shareable result, and understanding how the tool is used.
The result does not contain your name or email address. It does have a unique URL and may still be capable of being linked to you using other information, such as timing. We therefore treat diagnostic records as personal data rather than anonymous data.
Anyone who has your result URL can view the result. Please share and store that link accordingly.
The diagnostic provides general informational material. It does not make decisions producing legal or similarly significant effects about you.
Diagnostic report
If you request a personalised report, we collect your email address so that we can send it. We do this on the basis of our legitimate interests in responding to your request. Your email address is not stored alongside your diagnostic result.
Calls about a diagnostic result
If you book a call to discuss your diagnostic result, the booking is made through Cal.com, which collects your name, email address, the time you choose, and the link to your result, together with anything you write in the booking form.
We use this to hold the call and to have your result in front of us during it. Our basis is our legitimate interests in responding to your request for a conversation. Because the booking includes your result link, it connects you to a diagnostic record that is otherwise held without your name or email address; if you would rather not make that connection, do not book a call.
Marketing emails
Where you consent, we send a four-email series about AI Is the Easy Part and related material. You may withdraw consent at any time using the unsubscribe link in any of those emails, or by contacting us.
Withdrawing consent does not affect processing carried out before withdrawal. We may keep a minimal suppression record so that we can honour your request and avoid sending you further marketing. Service messages needed to deliver something you asked for are not marketing and may still be sent.
Buy-link attribution
When a visitor follows a link to buy the book, we record the country, the page the link was followed from, and any UTM campaign parameters. We do not attach a name or email address to these records.
We use this to measure which pages and campaigns generate interest in the book. To the extent these records constitute personal data, our basis is our legitimate interests in measuring the effectiveness of the site and its campaigns.
Website analytics
We use Vercel Analytics to measure pageviews and overall traffic. It is configured as cookieless analytics, and we do not use it to build advertising profiles or track visitors across unrelated websites.
To the extent analytics information constitutes personal data, we process it on the basis of our legitimate interests in measuring and improving the website. We do not currently set marketing cookies. If we introduce a technology requiring consent, we will ask before using it.
Where we obtain information
Most personal data is provided directly by you through the website. Country, page, UTM, analytics and related technical information may be generated automatically when you visit the site, complete the diagnostic, or follow a buy link.
Who receives personal data?
We use the following service providers as processors:
- Supabase, which provides the database holding diagnostic and attribution records, and the private storage holding uploaded receipts. This data is hosted in Tokyo, Japan, in the AWS ap-northeast-1 region.
- Resend, which delivers email and manages email contacts. Email addresses are held by Resend in the United States and are not stored in our database.
- Vercel, which hosts the website and provides website analytics.
- Cal.com, which takes bookings for calls about a diagnostic result. Booking details are held by Cal.com in the United States.
These providers may use approved subprocessors for infrastructure, security and support, and may process information only as permitted by their agreements with us and applicable law.
“For Teams” enquiries are also delivered to and kept in our business email inbox, subject to the retention periods below.
We may disclose information where reasonably necessary to professional advisers, regulators, courts, law-enforcement bodies, or another party in connection with legal obligations, legal claims, fraud prevention, or a transfer of the business. We do not sell personal data.
International transfers
Personal data may be processed outside the country where you live.
Database and stored-file information is processed in Japan. We rely on the applicable European Union and United Kingdom adequacy arrangements where the recipient and the processing fall within their scope.
Email and call-booking information is processed in the United States. Transfers may be protected by the EU-US Data Privacy Framework or its UK Extension where the receiving entity holds an active certification covering the data, or by the European Commission's standard contractual clauses together with the UK Addendum or another safeguard recognised by UK law.
Vercel and its subprocessors may process information in other countries under an applicable adequacy arrangement, approved contractual safeguards, or another lawful transfer mechanism.
You may contact us for further information about the transfer mechanism applying to your data. Commercial or security-sensitive terms may be redacted.
How long we retain information
Unless a longer period is required for a legal obligation or legal claim, we apply the following periods. The first four are enforced automatically by a scheduled job; the remainder are applied by periodic review.
- Completed diagnostic results are deleted 730 days after they are created.
- Diagnostic sessions that are started but never completed are deleted after 30 days.
- Uploaded receipt files and their submission records are deleted 90 days after submission. We do not keep a separate long-term record of a verification, because no payment passes through us.
- Individual buy-link records are deleted after 90 days. Before deletion they are combined into daily totals that record no time more precise than a date and cannot be traced to a visit.
- Short-lived counters used to rate-limit abusive requests expire within hours and record no address, only an irreversible fingerprint of one.
- “For Teams” enquiries are held as email correspondence and are reviewed and deleted within 24 months of the last meaningful contact, unless they form part of a purchase record.
- Call bookings, including the result link supplied with them, are held by Cal.com and in our calendar, and are reviewed and deleted within 12 months of the call.
- Email contacts held by Resend are kept until you unsubscribe or ask us to remove you, and are reviewed periodically so that addresses no longer needed are removed.
- A minimal consent or suppression record may be kept for as long as reasonably necessary to demonstrate consent, or to ensure an opt-out continues to be respected.
- Aggregate statistics that no longer identify anyone may be retained indefinitely.
Where information falls into more than one category, the longest genuinely applicable period may apply. Deletion from backups and provider systems happens during those providers' normal deletion cycles.
How we protect information
We use reasonable technical and organisational measures intended to prevent personal data being lost, altered, disclosed, or accessed without authorisation. These include restricting database and file access to our own server, keeping email addresses separate from diagnostic results, storing uploaded receipts privately rather than as email attachments, and applying automatic deletion to the records listed above.
No internet or storage system is completely secure. Please avoid submitting unnecessary sensitive information, and keep your diagnostic result URL to yourself unless you intend to share the result.
Your rights
Depending on where you live and the circumstances, you may have the right to:
- obtain information about how your personal data is used
- request access to your personal data
- have inaccurate or incomplete data corrected
- request deletion of your personal data
- request restriction of processing
- object to processing based on legitimate interests
- receive certain data in a portable format
- withdraw consent at any time
- complain to a data-protection authority
These rights may be subject to legal conditions and exceptions. You have an absolute right to object to the use of your personal data for direct marketing, which you can do through the unsubscribe link in any marketing email or by contacting us.
You can also complain to a data-protection authority — in the United Kingdom, the Information Commissioner's Office, and elsewhere the authority where you live or work, listed by the European Data Protection Board. Please contact us first if you can, so that we have a chance to resolve it.
Requests concerning diagnostic results
We deliberately do not store email addresses or names alongside diagnostic results, so we ordinarily cannot locate a diagnostic record from your name or email address.
To request access to or deletion of a diagnostic result, please send us its unique result URL. That URL lets us find the record without collecting further identifying information about you.
If you cannot provide the URL and we have no other reasonable means of identifying the record, we may be unable to fulfil the request, because we cannot tell which result relates to you. We will not require unnecessary additional identification purely to create a link between your identity and a diagnostic record.
We may ask for limited additional information where reasonably necessary to confirm identity or authority and prevent improper disclosure or deletion. We normally respond to valid requests within one month.
Children
The website and the diagnostic are intended for adults and business audiences. We do not knowingly solicit personal data from children. If you believe a child has provided personal data, please contact us.
Changes to this policy
We may update this policy when our practices, providers, or legal obligations change. We will publish the revised policy on this page and change the effective date. If a change materially affects an existing consent, we will ask for a new one where required.