H Handrail AI Safe-Use Training
Trust CenterRead this before the demo, not after

Who we are, what we do with your data, and what we do not claim.

A training product asking you to trust it on AI safety should be held to the same standard it teaches. This page is where we hold ourselves to it — in plain English, with named people, and without hiding behind a privacy policy nobody reads.

EU hosted Named authors, no anonymous content Lawyer-reviewed compliance wording
Who writes this

Every lesson is written and reviewed by named humans

Nothing here is anonymous, and nothing is purely AI-generated and shipped unchecked.

Author

Dana Kovář — Founder & Lead Author

Twelve years advising small professional-services firms on operational risk before writing a single Handrail lesson. Writes the first draft of every module and reviews every published change before it goes live.

Reviewer

Tomáš Beneš — Security & Compliance Reviewer

Former IT-security lead at a regional insurer. Checks every scam, deepfake, and data-handling scenario against current real-world cases before it's allowed into the course.

Legal review

Klára Nováková — External Counsel

Independent EU-tech lawyer who reviews and signs off every sentence in this course and site that references the EU AI Act or any other regulation, so no claim outruns what the law actually says.

Our AI-assistance disclosure

We use AI tools to help draft and edit lesson text, the same way many of you will after this course. Every draft is written and then substantively reviewed, fact-checked, and approved by the named humans above before it's published — the same "AI advises, human decides" rule we teach is the rule we follow to build this course.

Your data

Plain-English handling — no clause 14, subsection (b)

In one paragraph

We host in the EU, on Cloudflare's infrastructure. We collect the minimum needed to run the course: a name, a work email or admin-assigned login, module completion timestamps, and quiz results tied to that one person. We do not sell data, we do not show your ads, and — the question we get asked most — we never use your data, your quiz answers, or your firm's content to train AI models, ours or anyone else's. Learner-level quiz answers and scores are retained only as long as needed to support a certificate renewal (currently 13 months, one month past expiry), then deleted. Completion records feeding your admin's compliance report are kept for as long as your organization's account is active, so you can always produce historical proof of training.

Who else touches your data

Sub-processors — the short, complete list

Everyone with any access, and why
  • Cloudflare (EU region) — hosting, storage, and the login/session layer. No other Handrail infrastructure exists outside it.
  • Postmark (EU region) — sends magic-link sign-in emails and certificate notifications only. Never marketing email without opt-in.
  • Stripe — processes your organization's annual invoice payment. Never receives learner names or quiz data — only your billing contact's details.

That's the complete list. No analytics trackers, no ad pixels, no data brokers.

The compliance angle, stated carefully

What this training supports — and the limit of what any training can promise

Reviewed by external counsel

Handrail supports and documents your organization's effort toward the EU AI Act's Article 4 AI-literacy obligation — it gives you a dated, named, verifiable record that your staff received AI-safety training appropriate to their level of use. No training product, including this one, can guarantee your organization's overall legal compliance: compliance depends on your specific systems, uses, and governance, not on any single course. It is also worth stating plainly, because it's often misunderstood: Article 4 itself carries no standalone fine in the AI Act — it is enforced as part of the broader compliance obligations that apply to your organization's specific AI use.

What this training does NOT claim
  • — It does not make your organization "AI Act compliant." No course can.
  • — It does not replace a legal review of any specific AI system or vendor you use.
  • — It does not guarantee staff will never make a mistake — it meaningfully lowers the odds and gives you a documented, dated record of the training that occurred.
  • — It does not certify your organization, only individual learners who complete the course at their assessed level.
  • — It is not legal advice, and nothing on this site or in the course should be treated as such.
What's changed, and when

Dated content changelog

Every update to lesson content is logged here with a date, so you always know exactly what your team was trained on and when.

Recent updates
  • 20 July 2026 — Module 1 (Scams, Deepfakes and Voice Clones) refreshed with a current live-deepfake-video case; no change to quiz questions.
  • 3 June 2026 — Trust Center compliance wording reviewed and re-approved by external counsel following updated EU AI Act guidance.
  • 14 April 2026 — Module 5 mixed-scenario quiz bank expanded from 6 to 8 scenarios per level.

Course content current as of 20 July 2026. This Trust Center is reviewed at minimum quarterly.

Questions before you commit to anything

Dana Kovář, Founder — [email protected] · +420 601 234 567

Ask a question before you commit →