Legal
Privacy Policy
Last updated: August 25, 2026
1. Who we are
Python Land is an interactive learning platform available at learn.python.land. For the personal data processed to operate the platform, the data controller is:
Erik van Baaren · The Dutch Dev, trading as Python LandRegistered near Amsterdam, Netherlands
Dutch Chamber of Commerce: 89776232
EU VAT ID: NL002976373B42
Privacy contact: Python Land contact form
The registered office is also the operator's home address. Consistent with the public company information on Python Land, the full address is supplied on invoices rather than published on the public website.
Paddle is the authorised reseller and merchant of record for new subscription purchases. Paddle separately controls the personal data it needs to process checkout, payment, tax, fraud prevention, and buyer support.
2. Scope
This policy covers visitors, registered learners, legacy customers, subscribers, and people who contact us. It explains the personal data Python Land processes through the website, learning platform, code runner, account communications, and migrated legacy records. Third parties such as Paddle and Google also publish their own privacy notices.
3. Personal data we process
| Category | Examples |
|---|---|
| Account and identity | Email address, display name, password hash, Google account identifier when used, locale, operating-system preference, role, account status, and session-security version. |
| Legacy migration data | Legacy WordPress user identifier, email, display name, completed WooCommerce purchase references, and course entitlements. |
| Learning and user content | Course and lesson progress, quiz responses, submitted code, test output, saved chapter workspaces, grading results, Monty conversations kept in your browser session, optional inferred or user-authored learning notes, private notes you write on a lesson, timestamps, and reset choices. |
| Subscription and access | Paddle customer, subscription, and price identifiers; plan; subscription status; billing-period end; cancellation state; and entitlement history. |
| Technical and usage | IP address, browser and device information, request and security logs, runner and AI usage, CPU time, quota events, errors, and timestamps. |
| Communications | Support correspondence, transactional-email destination and delivery information, password-reset requests, and marketing preferences if used. |
| Advertising and consent | Consent choices and, where advertising is enabled, identifiers and interaction data described by Google and its selected ad technology providers. |
| Administration and audit | Administrative changes, entitlement grants and revocations, suspension reasons, actors, notes, and event timestamps. |
Please do not place confidential information, production credentials, special-category personal data, or third-party personal data in code submissions or saved workspaces.
4. How we obtain data
- Directly from you when you register, learn, submit code, or contact us.
- Automatically from your browser and use of the platform.
- From Paddle when a subscription transaction or lifecycle event is associated with your account.
- From Google when you choose Google sign-in.
- From the legacy Python Land WordPress and WooCommerce site, including active user accounts and completed course purchases migrated to preserve access.
5. Purposes and legal bases
| Purpose | Typical data | GDPR legal basis |
|---|---|---|
| Create and secure accounts | Account, identity, sessions, login events, and password-reset data. | Contract; legitimate interests in security and fraud prevention. |
| Deliver learning features | Progress, quizzes, code, workspaces, submissions, grading, runner usage, optional AI-help inputs and outputs, inspectable learner-memory notes, and your own lesson notes. | Contract; steps taken at your request; legitimate interests for free users. |
| Provide paid and legacy access | Subscription status, Paddle identifiers, legacy purchases, and entitlements. | Contract; legal obligations; legitimate interests in preserving purchases. |
| Operate, protect, and improve the Service | Technical logs, errors, audit events, usage, quotas, and aggregate statistics. | Legitimate interests; legal obligations where applicable. |
| Send service communications and support | Email, display name, account context, and correspondence. | Contract; legitimate interests; legal obligations. |
| Show and measure advertising | Consent signals, device and advertising data for eligible visitors. | Consent where required; legitimate interests only where law permits. |
| Comply with law and resolve disputes | Relevant account, transaction, communication, security, and audit records. | Legal obligations; legitimate interests; establishment or defence of claims. |
Where we rely on legitimate interests, those interests include operating and securing the platform, preventing abuse, improving lessons, preserving purchased access, and running a sustainable learning service. We balance those interests against your rights.
7. Subscription payments and Paddle
New subscriptions are purchased from Paddle, the authorised reseller and merchant of record. Checkout is hosted or embedded by Paddle. Python Land does not receive or store full card or PayPal credentials. We receive the identifiers and status information needed to connect a Paddle customer and subscription to a Python Land account, provide access, show plan and renewal information, handle cancellation state, and reconcile support issues.
Paddle's processing is governed by its Privacy Notice and Buyer Terms.
9. International data transfers
Some providers may process data outside your country, including outside the EEA, UK, or Switzerland. Where required, we will rely on an adequacy decision, approved standard contractual clauses, the EU–US Data Privacy Framework where applicable, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. [COUNSEL: CONFIRM EACH PROVIDER, LOCATION, ROLE, AND TRANSFER MECHANISM.]
10. Retention
We keep personal data only for as long as needed for the purposes described above, including providing purchased access, meeting tax and accounting duties, resolving disputes, and preventing abuse. The intended schedule is:
- Account, access, progress, saved workspace, and submission data: while the account is active. A self-service deletion request locks the account immediately and makes it eligible for permanent erasure after a seven-day recovery period, unless longer retention is required for a specific legal reason.
- Legacy purchase entitlements and related import records: while needed to honour the purchase and for [LEGACY ENTITLEMENT RECORD PERIOD].
- Subscription and transaction records: seven years after the transaction or end of the commercial relationship, where required for Dutch tax and accounting duties.
- Minimal erasure-request records and one-way Paddle reference hashes: up to seven years to demonstrate that a request was completed, handle legal claims, and prevent an erased billing identity from being reattached by delayed provider events.
- Security, application, and audit logs: ordinarily [LOG RETENTION PERIOD].
- Password-reset tokens: until used or expired; reset links expire after 48 hours.
- Backups: [BACKUP RETENTION PERIOD], after which they are overwritten or securely deleted in the normal backup cycle. Erased data in a protected backup is not returned to ordinary use and must be erased again if a backup is restored.
Data may be retained longer when necessary for a legal claim, fraud prevention, regulatory request, or another legal obligation. It may also be irreversibly anonymised for aggregate reporting.
11. Security
We use technical and organisational measures designed to protect personal data, including encrypted transport, password hashing, access controls, authenticated internal services, backups, rate limits, audit logging, and isolation and resource limits for server-side code execution. No online system can be guaranteed completely secure.
12. Your privacy rights
Depending on your location and applicable law, you may have rights to be informed; access, correct, or delete personal data; restrict or object to processing; receive portable data; withdraw consent; opt out of targeted advertising or certain disclosures; and not be discriminated against for using a privacy right. Withdrawing consent does not affect earlier lawful processing.
Python Land does not currently make decisions based solely on automated processing that produce legal or similarly significant effects. Automated grading and quota checks affect learning feedback and resource availability, not legal rights.
Learners can request account deletion under Account → Account. The account is locked and its paid subscription is cancelled immediately; an administrator completes permanent erasure after the seven-day recovery period. You may also submit any privacy request through the Python Land contact form, including when you cannot sign in. We may need to verify your identity and may retain limited information about the request. We normally respond within one month where the GDPR applies. You may also complain to your local data protection authority. Our lead authority is the Dutch Autoriteit Persoonsgegevens.
13. Children's privacy
Python Land is not directed to children under 18 and we do not knowingly collect their personal data. A parent or guardian who believes a child provided data should contact us so we can investigate and delete it where appropriate.
14. External links and services
Lessons may link to or embed third-party websites and media. Their operators control their own data practices. Review their privacy notices before providing information.
15. Changes to this policy
We may update this policy as the Service, providers, or legal requirements change. We will post the updated version and change the date above. Where a change is material, we will provide additional notice when required, such as an in-product or email notice.
16. Contact
Privacy questions, data-subject requests, and general support requests can be submitted through the Python Land contact form. The full registered address is included on Python Land invoices.