Privacy Policy
Effective Date: January 15, 2025
At CBC Inestings, we take your privacy seriously. This policy explains what information we collect, why we need it, and how we keep it safe. We believe in being transparent about our practices.
We're committed to complying with the General Data Protection Regulation (GDPR) and Polish data protection laws. Your trust matters to us, and we've built our approach around protecting that trust.
Information We Collect
We collect different types of information depending on how you interact with our platform. Here's what that includes:
Information You Provide Directly
When you create an account or use our services, you share certain details with us:
- Your name, email address, and phone number when you register
- Payment details when you enroll in courses (processed securely through our payment providers)
- Course progress, quiz responses, and assignment submissions
- Messages you send through our contact forms or support channels
- Profile information you choose to add, like a photo or bio
Information We Collect Automatically
Some information gets collected as you use our website. This helps us understand how people navigate our platform and where we can improve:
- Browser type, operating system, and device information
- IP address and approximate location (city level, not your exact address)
- Pages you visit, time spent on each page, and links you click
- Referral source (how you found our website)
About Cookies: We use cookies to keep you logged in, remember your preferences, and analyze site usage. You can control cookie settings through your browser, but some features might not work properly if you disable them.
How We Use Your Information
We use the information we collect for specific purposes that support your learning experience and our operations:
| Purpose | Details |
|---|---|
| Course Delivery | Managing your enrollment, tracking progress, issuing certificates, and providing personalized learning recommendations |
| Communication | Sending course updates, responding to inquiries, sharing important announcements, and providing technical support |
| Payment Processing | Handling transactions, sending receipts, and managing billing for course enrollments |
| Platform Improvement | Analyzing usage patterns to enhance features, fix technical issues, and develop new educational content |
| Legal Compliance | Meeting regulatory requirements, preventing fraud, and protecting our legitimate business interests |
We don't sell your personal information to third parties. Period. And we won't use your data for purposes beyond what's described here without getting your explicit consent first.
Legal Basis for Processing (GDPR)
Under GDPR, we need a legal reason to process your personal data. Here's what applies to us:
- Contract Performance: We need your information to deliver the courses you've enrolled in and fulfill our agreement with you
- Legitimate Interests: We process certain data to improve our platform, prevent fraud, and run our business effectively
- Legal Obligation: Some processing is required to comply with Polish and EU tax, accounting, and regulatory requirements
- Consent: For marketing communications and non-essential cookies, we ask for your explicit permission
Sharing Your Information
We work with trusted partners to deliver our services, but we're selective about who gets access to your data:
Service Providers We Work With
- Payment Processors: Secure payment gateways that handle transaction processing (they never store your complete payment details on our servers)
- Email Services: Platforms we use to send course updates and communications
- Hosting Providers: Companies that maintain our servers and ensure our platform stays online
- Analytics Tools: Services that help us understand how people use our website
All these partners are bound by strict confidentiality agreements and can only use your data for the specific purposes we've authorized.
When We Might Disclose Information
We'll share your information only in these limited circumstances:
- If required by Polish law or valid legal process
- To protect our rights, property, or safety (or those of our users)
- In connection with a business transfer, like a merger or acquisition
- With your explicit consent for a specific purpose
Your Privacy Rights
Under GDPR and Polish law, you have significant control over your personal information. Here's what you can do:
Access Your Data
Request a copy of all personal information we hold about you. We'll provide it in a structured, commonly used format.
Correct Information
Update or fix any inaccurate personal data. You can do this directly in your account settings or by contacting us.
Delete Your Data
Request deletion of your personal information, subject to legal retention requirements for financial and educational records.
Restrict Processing
Limit how we use your information in certain circumstances, like when you're disputing data accuracy.
Object to Processing
Opt out of marketing communications or object to processing based on legitimate interests.
Data Portability
Receive your data in a portable format and request that we transfer it to another service provider where technically feasible.
How to Exercise These Rights: Send your request to the contact details below. We'll respond within 30 days and verify your identity before processing requests. There's no fee unless your request is clearly unfounded or excessive.
Data Security
We've implemented multiple layers of security to protect your information:
- SSL/TLS encryption for all data transmitted between your browser and our servers
- Encrypted storage for sensitive personal and payment information
- Regular security audits and vulnerability assessments
- Access controls that limit who can view personal data (only authorized staff with legitimate need)
- Secure backup systems with encrypted off-site storage
- Staff training on data protection practices and GDPR requirements
While we take security seriously and use industry-standard protections, no system is completely immune to threats. We continuously monitor and improve our security measures, but we also encourage you to use strong passwords and keep your login credentials private.
Data Retention
We don't keep your information longer than necessary. Here's our general approach:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of your account plus 3 years after closure (for legal compliance) |
| Course Progress & Certificates | 7 years from course completion (Polish educational record requirements) |
| Financial Records | 10 years from transaction date (Polish tax law requirements) |
| Marketing Communications | Until you unsubscribe, then deleted within 30 days |
| Analytics Data | Aggregated data kept indefinitely; individual identifiers deleted after 26 months |
After retention periods expire, we securely delete or anonymize your information so it can no longer identify you.
International Data Transfers
Our primary servers are located within the European Union. However, some service providers we work with may process data outside the EU/EEA. When this happens:
- We only use providers that offer adequate data protection (through adequacy decisions, Standard Contractual Clauses, or other approved mechanisms)
- We ensure appropriate safeguards are in place before any transfer occurs
- You can request details about specific transfers by contacting us
Children's Privacy
Our courses are designed for adults and individuals aged 16 and over. We don't knowingly collect information from anyone under 16. If you're a parent who believes your child has provided us with personal information, please contact us immediately and we'll delete it.
Changes to This Policy
We review and update this privacy policy periodically to reflect changes in our practices or legal requirements. When we make significant changes, we'll notify you by email or through a prominent notice on our website.
The "Effective Date" at the top shows when the current version took effect. We encourage you to check back occasionally to stay informed about how we're protecting your information.
Supervisory Authority
You have the right to lodge a complaint with the Polish data protection authority if you're concerned about how we handle your personal information:
President of the Personal Data
Protection Office (UODO)
ul. Stawki 2
00-193 Warsaw, Poland
Website: uodo.gov.pl
We'd appreciate the opportunity to address your concerns directly first, but you're entitled to contact UODO at any time.
Questions About Privacy?
If you have questions about this policy, want to exercise your rights, or need clarification about how we use your information, we're here to help.
CBC Inestings
Jana Pawła II 30
25-025 Kielce, Poland
Phone: +48 506 610 131
We typically respond to privacy inquiries within 48 hours on business days.