๐Ÿ‡ต๐Ÿ‡ฑ ilearnpolski

PRIVACY POLICY โ€” ILEARNPOLSKI.COM

This is a courtesy translation provided for convenience. The legally binding version of this Policy is the Polish version available at privacy-pl. In case of any discrepancy, the Polish version prevails.

1. Data controller

The controller of the personal data of persons using the website https://www.ilearnpolski.com (the "Service"), holding an Account, making payments, or contacting the controller is ILearnPolski, e-mail: support@ilearnpolski.com, tel. +48 531 503 579 (the "Controller").

2. What data we process

  1. Account data: e-mail address, password โ€” stored by the authentication provider solely as a cryptographic hash; the Controller has no access to the User's password in plain form โ€” and, optionally, first name.
  2. Learning data: progress in exercises, vocabulary tests, and other modules of the Service.
  3. Payment data: Subscription status, customer, payment, and subscription identifiers assigned by Stripe, payment history, and limited information identifying the payment method, such as card brand, expiry date, and the last four digits of the number. The Controller does not receive or store the full card number or CVC code โ€” full payment data is processed by Stripe.
  4. Technical data: IP address, browser type, server logs โ€” generated automatically when using the Service.
  5. Correspondence: the content of messages sent to the Service's contact addresses.

Sources of data: data is obtained directly from the data subject, automatically while the Service is used, and from Stripe in connection with handling payments and Subscriptions.

The Service is intended for persons aged 16 or over; persons under 16 may use the Service only with the consent and under the supervision of a legal guardian.

3. Purposes and legal bases of processing

  1. Performance of contracts for the Account and the Subscription โ€” creating and operating the Account, access to content, saving progress, handling payments and the Trial Period (Article 6(1)(b) GDPR);
  2. Compliance with legal obligations โ€” tax and accounting settlements, handling the right of withdrawal and complaints, storing evidence of required consents (Article 6(1)(c) GDPR);
  3. Legitimate interests of the Controller (Article 6(1)(f) GDPR) โ€” ensuring the security of the Service, preventing abuse (including verifying that the Trial Period is used once per person, Account, and payment method), establishing, pursuing, and defending claims, and handling correspondence.

Providing an e-mail address and password is voluntary but necessary to create an Account. Providing the data required by Stripe is necessary to start a paid Subscription. Providing a first name is voluntary. Failure to provide required data will prevent, respectively, creating an Account or purchasing a Subscription.

4. Data recipients and service providers

Data may be transferred to entities supporting the Service which โ€” depending on the type of operation performed โ€” act as processors on the Controller's instructions or as independent controllers:

EntityRole
Supabase, Inc.database and authentication system (primary project instance in the EU region โ€” Ireland)
Stripe Payments Europe Limited and other relevant Stripe group entitiespayment processing, fraud prevention, and performance of Stripe's legal obligations; depending on the operation, Stripe acts as a processor or an independent controller
Vercel, Inc.hosting of the Service
Google Ireland Limitedoperation of the e-mail inbox to which contact correspondence is directed
Resend, Inc.sending transactional e-mails (contract confirmations and Account-related messages)

Data may also be disclosed to public authorities where required by law.

5. Transfers of data outside the EEA

The primary instance of the Supabase project, including the Service's database, was created in the West EU (Ireland) region. In connection with the use of IT service providers, data may also be processed outside the European Economic Area, in particular in the United States. For entities participating in the EUโ€“US Data Privacy Framework, transfers take place on the basis of the European Commission's adequacy decision. In other cases, transfers take place on the basis of appropriate safeguards, in particular standard contractual clauses approved by the European Commission. Information about the safeguards used, or a copy of them, can be obtained by contacting the Controller.

6. Retention periods

  1. Account data and learning data โ€” for as long as the Account exists. After the Account is deleted, learning data is deleted or anonymised, while a limited scope of data concerning the conclusion and performance of the contract may be retained until the limitation period for claims expires;
  2. settlement data and documents โ€” for the period required by tax and accounting regulations, as a rule for 5 years from the end of the calendar year in which the deadline for payment of the relevant tax expired;
  3. technical logs under the Controller's control or processed on its instructions โ€” for the period necessary to ensure the security and proper operation of the Service, no longer than 12 months; providers acting as independent controllers may retain data for periods resulting from their own legal obligations and privacy policies;
  4. correspondence โ€” up to 3 years from the closure of the matter it concerns.

7. Rights of data subjects

Data subjects have โ€” in the cases and under the conditions set out in the GDPR โ€” the rights of access to their data, rectification, erasure, restriction of processing, and data portability. Where processing is based on the Controller's legitimate interest, the data subject also has the right to object. Requests concerning the exercise of these rights may be sent to support@ilearnpolski.com.

Every data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl).

8. Cookies and similar technologies

The Service uses technically necessary cookies and similar technologies, including localStorage, to maintain the login session, ensure Account security, preserve the state of started tasks, and carry out the payment process. These technologies are necessary to provide services expressly requested by the User and are not used for analytics or marketing purposes. For this reason, the Service does not currently require consent for their use.

MechanismProviderPurposeDuration
Authentication session (localStorage)Supabasemaintaining loginaccording to session duration
Test state (localStorage)ilearnpolski.comsaving a started vocabulary testuntil the test is finished or deleted
Payment mechanismsStripe (checkout.stripe.com)carrying out the payment, security, and fraud preventionaccording to Stripe's settings

If analytics or marketing tools are implemented in the future, this Policy will be updated and Users will be presented with a consent mechanism before those tools are activated.

9. Automated decisions

The Controller does not make decisions concerning persons using the Service that are based solely on automated processing and that would produce legal effects concerning them or similarly significantly affect them. Stripe may use its own automated risk-assessment, fraud-prevention, and payment-authorisation mechanisms under the rules described in Stripe's privacy policy.

10. Changes to this Policy

Users will be informed of material changes to this Policy by e-mail or by a notice in the Service. This Policy is drawn up in Polish; translations are provided for information purposes only and the Polish version prevails in case of discrepancy.