STARTCYBER
StartBootcampBusinesses & InstitutionsAbout UsBlogContact
PL
PL
StartBootcampBusinesses & InstitutionsAbout UsBlogContact

Privacy and Cookie Policy

We respect your privacy and take data protection seriously. Below you will find detailed information about the purposes, legal bases, and methods of processing personal data on StartCyber.pl.

Last updatedAugust 4, 2026

Table of Contents

1. General Information2. Data Controller3. Processed Data4. Purposes & Legal Bases5. External Tools & Services6. Data Recipients7. Transfers Outside EEA8. Data Retention Period9. Provision of Data10. User Rights11. Cookies & Technologies12. External Content & Media13. Automated Decisions14. Data Security15. Policy Changes

1. General Information

This Privacy Policy describes the rules of processing personal data and the use of cookies and similar technologies in connection with using the StartCyber.pl website.

The policy applies in particular to:

  • using the website and its subpages,
  • using contact forms and registration forms,
  • creating and managing user accounts,
  • purchasing training courses, bootcamp programs, webinars, and educational products,
  • using the training platform,
  • participating in online training sessions and live events,
  • using recordings, video materials, documents, quizzes, and certificates,
  • participating in training ordered by companies and institutions,
  • subscribing to the newsletter,
  • making online payments.

The term "Website" refers to StartCyber.pl, its subpages, forms, user dashboard, and the associated learning management system used by StartCyber.

The term "User" refers to any person visiting the Website, contacting the Controller, placing an order, holding an account, or attending training.

Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR") and applicable data protection legislation.

2. Data Controller

The controller of your personal data is:

Damian Banat
operating a registered business under the company name:
Damian Banat Business Consulting
ul. Stefana Jaracza 32 lok. 19, 90-262 Łódź, Poland
NIP (Tax ID): 7322131065 | REGON: 541620554
operating the Website under the brand StartCyber (hereinafter referred to as the "Controller").

For any matters regarding privacy, personal data protection, or exercising your rights under GDPR, contact us at:kontakt@startcyber.pl

3. What Data May Be Processed

The scope of processed data depends on your interaction with the Website. The Controller may process in particular:

  • identification and contact data: name, surname, email address, phone number, company/institution name, job position or role,
  • user account data: username, account ID, login history, permissions, and account activation details,
  • order and billing data: buyer details, address, company name, Tax ID (NIP), product selected, price, order date and number,
  • payment data: amount, payment method, transaction status, and transaction ID,
  • training performance data: assigned course, progress, completed lessons, attendance, test scores, assignments, and certificate details,
  • online live session data: display name during webinars, email address, voice, image, statements, questions, and chat messages,
  • communication data: messages, inquiries, and correspondence with the Controller,
  • consent records: consent choices and privacy preferences,
  • technical data: IP address, timestamp, pages visited, device type, OS, browser type, network identifiers, and technical logs.

The Controller does not receive or store full payment card numbers, bank credentials, or BLIK authorization codes. Payments are handled securely by regulated payment operators.

4. Purposes and Legal Bases for Processing

4.1. Website Operation and Security

Technical data, IP addresses, and logs are processed to ensure the correct operation, security, threat detection, spam prevention, backups, and service continuity.

Legal basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR).

4.2. Inquiries and Contact

Data provided via forms or email is processed to respond to questions, present offers, and conduct correspondence.

Legal basis: Art. 6(1)(b) GDPR (for pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest in communication).

4.3. User Account

Account data is processed to create and manage the account, enable login, assign purchased courses, and provide materials.

Legal basis: Art. 6(1)(b) GDPR (fulfillment of user account service agreement).

4.4. Orders, Payments, and Invoicing

Order data is processed to complete transactions, issue invoices, maintain tax records, and defend against potential claims.

Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal tax obligations), and Art. 6(1)(f) GDPR (claims defense).

4.5. Training & Bootcamp Delivery

Participation data is processed to deliver training materials, track progress, conduct tests, issue certificates, and verify certificate authenticity.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

4.6. Corporate & B2B Group Training

For organization-sponsored training, participant data provided by the employer is processed to deliver the training, report completion status, and issue certificates.

Legal basis: Contract performance or legitimate interest of Controller and employer.

4.7. Newsletter & Marketing

If subscribed, data is processed to send educational articles, course updates, and invitations.

Legal basis: Voluntary consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time.

4.8. Live Sessions & Recordings

Online sessions may be recorded to provide replay access for students. Participants not wishing to have their image/voice recorded can participate with camera and microphone disabled.

5. External Tools & Services

Google reCAPTCHA: Protects forms from automated spam/abuse. Data processed on Controller's behalf.

Google Search Console: Monitors website indexing and technical search performance.

Cloudflare: Enhances website security, DDoS mitigation, speed, and content distribution.

6. Data Recipients

Data may be shared with trusted technical providers under data processing agreements:

  • hosting, server, and cloud infrastructure providers,
  • learning platform providers (including Web To Learn sp. z o.o.),
  • email and communication software providers,
  • payment operators and banking partners,
  • invoicing software and accounting services,
  • instructors and sub-contractors,
  • legal and tax advisors.

The Controller never sells user personal data.

7. Data Transfers Outside the EEA

If data is processed by tech vendors located outside the European Economic Area, transfers occur under valid GDPR mechanisms, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions.

8. Data Retention Periods

Data is stored only for as long as necessary:

  • Account & Course Data: for the duration of account active state and access period,
  • Invoices & Tax Records: 5 years from the end of the tax year (as required by tax law),
  • Correspondence & Claims: until the expiration of statutory limitation periods,
  • Newsletter Data: until consent is withdrawn.

9. Provision of Data

Providing data is voluntary but necessary to process orders, issue invoices, access courses, or receive certificates.

10. Your Rights Under GDPR

You have the right to access, rectify, erase, restrict processing, transfer data, object to processing, withdraw consent, or lodge a complaint with the Data Protection Authority (PUODO).

To exercise your rights, email us at: kontakt@startcyber.pl.

11. Cookies & Similar Technologies

We use Necessary, Functional, Analytical, and Marketing cookies. You can manage or disable cookies at any time via your browser settings (Chrome, Firefox, Safari, Edge).

12. External Content & Third-Party Media

Embedded video players or social media links operate under the respective privacy policies of those third-party providers.

13. Automated Decision-Making

The Controller does not engage in automated decision-making or profiling that produces legal effects under Art. 22 GDPR.

14. Technical & Organizational Data Security

We implement SSL/TLS encryption, access controls, system updates, and backups to protect your data.

15. Updates to this Privacy Policy

This Privacy Policy may be updated periodically. The current version is always available on the Website with the date of last revision.

STARTCYBER

Practical cybersecurity courses and training. Learn from experts with years of experience in commercial projects.

Pages

  • Start
  • Bootcamp
  • How to enter cybersecurity
  • Corporate & Institutional Training
  • How to secure a company or institution
  • About us
  • Blog
  • Contact

Contact

kontakt@startcyber.pl

StartCyber
NIP: 7322131065
REGON: 541620554

© 2026 StartCyber. All rights reserved. No part of this website or its content, including course materials, videos, recordings, documents, graphics and branding, may be copied, reproduced, distributed, modified, published, sold or shared without the prior written consent of StartCyber.

Terms of Service|Privacy Policy