1. General Information
This Privacy Policy describes the rules of processing personal data and the use of cookies and similar technologies in connection with using the StartCyber.pl website.
The policy applies in particular to:
- using the website and its subpages,
- using contact forms and registration forms,
- creating and managing user accounts,
- purchasing training courses, bootcamp programs, webinars, and educational products,
- using the training platform,
- participating in online training sessions and live events,
- using recordings, video materials, documents, quizzes, and certificates,
- participating in training ordered by companies and institutions,
- subscribing to the newsletter,
- making online payments.
The term "Website" refers to StartCyber.pl, its subpages, forms, user dashboard, and the associated learning management system used by StartCyber.
The term "User" refers to any person visiting the Website, contacting the Controller, placing an order, holding an account, or attending training.
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR") and applicable data protection legislation.
2. Data Controller
The controller of your personal data is:
For any matters regarding privacy, personal data protection, or exercising your rights under GDPR, contact us at:kontakt@startcyber.pl
3. What Data May Be Processed
The scope of processed data depends on your interaction with the Website. The Controller may process in particular:
- identification and contact data: name, surname, email address, phone number, company/institution name, job position or role,
- user account data: username, account ID, login history, permissions, and account activation details,
- order and billing data: buyer details, address, company name, Tax ID (NIP), product selected, price, order date and number,
- payment data: amount, payment method, transaction status, and transaction ID,
- training performance data: assigned course, progress, completed lessons, attendance, test scores, assignments, and certificate details,
- online live session data: display name during webinars, email address, voice, image, statements, questions, and chat messages,
- communication data: messages, inquiries, and correspondence with the Controller,
- consent records: consent choices and privacy preferences,
- technical data: IP address, timestamp, pages visited, device type, OS, browser type, network identifiers, and technical logs.
The Controller does not receive or store full payment card numbers, bank credentials, or BLIK authorization codes. Payments are handled securely by regulated payment operators.
4. Purposes and Legal Bases for Processing
4.1. Website Operation and Security
Technical data, IP addresses, and logs are processed to ensure the correct operation, security, threat detection, spam prevention, backups, and service continuity.
Legal basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR).
4.2. Inquiries and Contact
Data provided via forms or email is processed to respond to questions, present offers, and conduct correspondence.
Legal basis: Art. 6(1)(b) GDPR (for pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest in communication).
4.3. User Account
Account data is processed to create and manage the account, enable login, assign purchased courses, and provide materials.
Legal basis: Art. 6(1)(b) GDPR (fulfillment of user account service agreement).
4.4. Orders, Payments, and Invoicing
Order data is processed to complete transactions, issue invoices, maintain tax records, and defend against potential claims.
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal tax obligations), and Art. 6(1)(f) GDPR (claims defense).
4.5. Training & Bootcamp Delivery
Participation data is processed to deliver training materials, track progress, conduct tests, issue certificates, and verify certificate authenticity.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
4.6. Corporate & B2B Group Training
For organization-sponsored training, participant data provided by the employer is processed to deliver the training, report completion status, and issue certificates.
Legal basis: Contract performance or legitimate interest of Controller and employer.
4.7. Newsletter & Marketing
If subscribed, data is processed to send educational articles, course updates, and invitations.
Legal basis: Voluntary consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time.
4.8. Live Sessions & Recordings
Online sessions may be recorded to provide replay access for students. Participants not wishing to have their image/voice recorded can participate with camera and microphone disabled.
5. External Tools & Services
Google reCAPTCHA: Protects forms from automated spam/abuse. Data processed on Controller's behalf.
Google Search Console: Monitors website indexing and technical search performance.
Cloudflare: Enhances website security, DDoS mitigation, speed, and content distribution.
6. Data Recipients
Data may be shared with trusted technical providers under data processing agreements:
- hosting, server, and cloud infrastructure providers,
- learning platform providers (including Web To Learn sp. z o.o.),
- email and communication software providers,
- payment operators and banking partners,
- invoicing software and accounting services,
- instructors and sub-contractors,
- legal and tax advisors.
The Controller never sells user personal data.
7. Data Transfers Outside the EEA
If data is processed by tech vendors located outside the European Economic Area, transfers occur under valid GDPR mechanisms, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions.
8. Data Retention Periods
Data is stored only for as long as necessary:
- Account & Course Data: for the duration of account active state and access period,
- Invoices & Tax Records: 5 years from the end of the tax year (as required by tax law),
- Correspondence & Claims: until the expiration of statutory limitation periods,
- Newsletter Data: until consent is withdrawn.
9. Provision of Data
Providing data is voluntary but necessary to process orders, issue invoices, access courses, or receive certificates.
10. Your Rights Under GDPR
You have the right to access, rectify, erase, restrict processing, transfer data, object to processing, withdraw consent, or lodge a complaint with the Data Protection Authority (PUODO).
To exercise your rights, email us at: kontakt@startcyber.pl.
11. Cookies & Similar Technologies
We use Necessary, Functional, Analytical, and Marketing cookies. You can manage or disable cookies at any time via your browser settings (Chrome, Firefox, Safari, Edge).
12. External Content & Third-Party Media
Embedded video players or social media links operate under the respective privacy policies of those third-party providers.
13. Automated Decision-Making
The Controller does not engage in automated decision-making or profiling that produces legal effects under Art. 22 GDPR.
14. Technical & Organizational Data Security
We implement SSL/TLS encryption, access controls, system updates, and backups to protect your data.
15. Updates to this Privacy Policy
This Privacy Policy may be updated periodically. The current version is always available on the Website with the date of last revision.