Privacy
Privacy policy
This policy explains how personal data is used when you visit szymonpaluch.com, contact me, submit a form, use the practice exam or buy a service, including the Certified AI Consultant Program.
Last updated:
Who is responsible for your data?
Beta Impact Szymon Paluch
NIP: 5492440717 · REGON: 361035480
The data controller is Szymon Paluch, trading as Beta Impact Szymon Paluch in Poland. Use these contact details for any privacy request.
1. Data collected
- Contact and applications: the details you provide, such as name, email, phone, company, location, professional profile link, selected service and message. A program application also includes its ID, language, offer and optional answer about how you heard about the program.
- Practice exam and assessments: answers and progress are processed in your browser. If you request a study plan or assessment result by email, the form also submits the result and the information shown next to that form, such as scores by topic, weakest topics and your question.
- Customers and payments: contact and billing details, service purchased, invoice information, amount, currency, payment reference and payment or refund status. Stripe collects the payment details needed for your chosen payment method.
- Website operation: hosting and security providers receive technical request information, including IP address, requested URL, browser information and time, to deliver and protect the site.
- Optional analytics: with your permission, visits, page performance, interaction and form events, campaign tags, referring domain, entry page and clicked program links. An attribution ID connects visits; an application ID can connect an analytics confirmation to the received application. These identifiers are pseudonymous, not a claim that the data is anonymous. Names, email addresses and message contents are not deliberately sent as analytics event properties.
2. Purposes and legal bases
Providing data is voluntary. Fields marked as required are needed to answer the particular request, process an application or complete a purchase. Without them I may be unable to provide that service. Optional fields and analytics consent are not a condition of admission.
- Answering an enquiry, reviewing an application and delivering a service: taking steps at your request before a contract and performing a contract, under Article 6(1)(b) GDPR. General business correspondence and handling enquiries made for an organisation rely on the legitimate interest in communicating with that organisation, under Article 6(1)(f).
- Billing, accounting and legal obligations: Article 6(1)(c) GDPR. Handling disputes and establishing or defending claims rely on the legitimate interest in protecting the business and its customers, under Article 6(1)(f).
- Security and reliable operation: the legitimate interest in preventing abuse, troubleshooting and providing a working website, under Article 6(1)(f) GDPR.
- Optional analytics and remembering acquisition sources: your consent, under Article 6(1)(a) GDPR. Declining does not prevent you from using the site or submitting a form.
- Marketing emails: consent where you have subscribed to them. You can unsubscribe using the option in the message or by emailing me. Messages needed to fulfil your request, review an application or provide a purchased service are separate from marketing.
3. Payments through Stripe
When you use a Stripe payment link, payment information is submitted to Stripe through its payment page. The application form on this website does not ask for card details, and I do not receive your full card number or CVC. I can receive payment status, a transaction reference, billing details and limited payment-method information needed to identify the transaction, issue invoices or handle refunds.
Stripe processes data to execute payments and also for its own legal, fraud-prevention and security purposes. Depending on the activity, it acts as a processor or an independent controller. Its practices, entities, retention and international transfers are described in the Stripe Privacy Policy and Data Processing Agreement.
Submitting a program application is free. Payment is a separate step after acceptance. Never send card numbers, CVCs or banking passwords in a form or email.
4. Who receives data
Data is disclosed only where needed for the relevant purpose, through the website request, a submitted form, a service integration, correspondence or legally required records. It may be available to authorised people helping operate the service and to the following categories of providers:
- Netlify: website hosting and receiving form submissions. See Netlify’s privacy information.
- Cloudflare: network delivery and protection of the website. The site also loads animation-library files from the cdnjs service, which receives the technical request. See Cloudflare’s privacy policy.
- Hetzner: infrastructure used for the self-hosted Umami analytics service at stats.szymonpaluch.com. Umami is operated for this website; it is not an advertising network.
- Stripe and its payment partners: processing and securing payments, as described above.
- Email, scheduling and business-service providers: delivering correspondence, arranging meetings and, where applicable, supporting accounting and legal obligations. Opening a Google booking link involves Google; the speaking form also uses Google reCAPTCHA for spam protection. See Google’s privacy policy.
- Public authorities or professional advisers where disclosure is legally required or necessary to establish, exercise or defend claims. Personal data is not sold.
5. International processing
Some providers and their subprocessors operate outside the European Economic Area, including in the United States. The relevant transfer arrangements may use a European Commission adequacy decision or standard contractual clauses and additional safeguards where required.
Provider-specific arrangements are described in the Netlify Data Processing Agreement, Stripe Data Processing Agreement and linked provider privacy information. Contact me for information about safeguards applicable to your data and how to obtain a copy.
6. Browser storage and your analytics choice
Optional browser analytics is off until you choose “Allow analytics”. You can refuse it or withdraw permission through “Privacy settings” in the footer or the button below. Withdrawal stops further browser analytics and removes the stored acquisition record from this browser. It does not retroactively undo processing that was lawful before withdrawal.
The self-hosted Umami tracker does not use analytics cookies. With your permission, this website separately uses localStorage and sessionStorage for attribution. Necessary browser storage keeps features you request working. Expired records are ignored or removed when next accessed; the browser may retain stored bytes until that access or until you clear site data.
- Privacy choice: remembered for up to 180 days in this browser.
- Acquisition source: first discovery and most recent non-direct source for up to 30 days, only with analytics consent. The most recent program-link placement is valid for 30 minutes within the tab session.
- Form confirmation: a short-lived handoff retains the form, submission language and application ID so the correct confirmation can be shown. Its validity is 15 minutes; session markers prevent duplicate success events. Attribution is attached only when analytics is allowed.
- Requested features: a language choice and practice-exam progress remain until you change or clear them; a program offer code is remembered for up to 30 days to retain the price you opened. Clearing site data can reset those features.
- External payment, booking and embedded-content services have their own browser-storage practices. Loading an embedded video or social post connects to its provider. Read the provider’s notice before using that service.
7. Retention and security
Contact and application records are retained for handling the request, completing the admission process and related follow-up. If you become a customer, relevant records are kept for providing the service. Further retention depends on accounting or tax obligations, unresolved complaints and applicable limitation periods for claims. Marketing records are retained for the subscription and, where necessary, evidence of consent or an opt-out.
The browser periods above do not set the retention of a submitted application, transaction or historical analytics record. Those records are retained according to their purpose, the need to evaluate the service and campaigns, and any applicable legal obligations. You can ask about the retention or deletion of your particular record using the contact details above.
The site uses HTTPS to protect data in transit. Administrative systems require authenticated access; access and disclosure are limited to what is needed for operating the service. Payment details are handled on Stripe’s payment page. No transmission or storage system can guarantee absolute security.
8. Your rights
Where the GDPR conditions apply, you can request access, correction, deletion, restriction of processing or portability of your data. You can object to processing based on legitimate interests and to direct marketing, and withdraw consent at any time. Some records must still be retained to meet legal obligations or handle claims.
Email contact@szymonpaluch.com, preferably from the address used in the relevant form or purchase. I may need proportionate information to verify that the request concerns your data. GDPR requests are normally answered within one month; if a permitted extension is necessary, you will be informed within that month.
You can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or the competent supervisory authority in your country.
9. Decisions and policy changes
Program admission is reviewed by a person. Practice-exam and assessment scores are calculated automatically for educational feedback; they do not determine admission or produce legal effects. Analytics helps understand visits and applications and is not used to make solely automated admission decisions.
This policy may be updated when services or data practices change. The current version and update date will be published on this page.