Privacy

Privacy policy

This policy explains how personal data is used when you visit szymonpaluch.com, contact me, submit a form, use the practice exam or buy a service, including the Certified AI Consultant Program.

Last updated:

Who is responsible for your data?

Beta Impact Szymon Paluch
NIP: 5492440717 · REGON: 361035480

The data controller is Szymon Paluch, trading as Beta Impact Szymon Paluch in Poland. Use these contact details for any privacy request.

1. Data collected

2. Purposes and legal bases

Providing data is voluntary. Fields marked as required are needed to answer the particular request, process an application or complete a purchase. Without them I may be unable to provide that service. Optional fields and analytics consent are not a condition of admission.

3. Payments through Stripe

When you use a Stripe payment link, payment information is submitted to Stripe through its payment page. The application form on this website does not ask for card details, and I do not receive your full card number or CVC. I can receive payment status, a transaction reference, billing details and limited payment-method information needed to identify the transaction, issue invoices or handle refunds.

Stripe processes data to execute payments and also for its own legal, fraud-prevention and security purposes. Depending on the activity, it acts as a processor or an independent controller. Its practices, entities, retention and international transfers are described in the Stripe Privacy Policy and Data Processing Agreement.

Submitting a program application is free. Payment is a separate step after acceptance. Never send card numbers, CVCs or banking passwords in a form or email.

4. Who receives data

Data is disclosed only where needed for the relevant purpose, through the website request, a submitted form, a service integration, correspondence or legally required records. It may be available to authorised people helping operate the service and to the following categories of providers:

5. International processing

Some providers and their subprocessors operate outside the European Economic Area, including in the United States. The relevant transfer arrangements may use a European Commission adequacy decision or standard contractual clauses and additional safeguards where required.

Provider-specific arrangements are described in the Netlify Data Processing Agreement, Stripe Data Processing Agreement and linked provider privacy information. Contact me for information about safeguards applicable to your data and how to obtain a copy.

6. Browser storage and your analytics choice

Optional browser analytics is off until you choose “Allow analytics”. You can refuse it or withdraw permission through “Privacy settings” in the footer or the button below. Withdrawal stops further browser analytics and removes the stored acquisition record from this browser. It does not retroactively undo processing that was lawful before withdrawal.

The self-hosted Umami tracker does not use analytics cookies. With your permission, this website separately uses localStorage and sessionStorage for attribution. Necessary browser storage keeps features you request working. Expired records are ignored or removed when next accessed; the browser may retain stored bytes until that access or until you clear site data.

7. Retention and security

Contact and application records are retained for handling the request, completing the admission process and related follow-up. If you become a customer, relevant records are kept for providing the service. Further retention depends on accounting or tax obligations, unresolved complaints and applicable limitation periods for claims. Marketing records are retained for the subscription and, where necessary, evidence of consent or an opt-out.

The browser periods above do not set the retention of a submitted application, transaction or historical analytics record. Those records are retained according to their purpose, the need to evaluate the service and campaigns, and any applicable legal obligations. You can ask about the retention or deletion of your particular record using the contact details above.

The site uses HTTPS to protect data in transit. Administrative systems require authenticated access; access and disclosure are limited to what is needed for operating the service. Payment details are handled on Stripe’s payment page. No transmission or storage system can guarantee absolute security.

8. Your rights

Where the GDPR conditions apply, you can request access, correction, deletion, restriction of processing or portability of your data. You can object to processing based on legitimate interests and to direct marketing, and withdraw consent at any time. Some records must still be retained to meet legal obligations or handle claims.

Email contact@szymonpaluch.com, preferably from the address used in the relevant form or purchase. I may need proportionate information to verify that the request concerns your data. GDPR requests are normally answered within one month; if a permitted extension is necessary, you will be informed within that month.

You can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or the competent supervisory authority in your country.

9. Decisions and policy changes

Program admission is reviewed by a person. Practice-exam and assessment scores are calculated automatically for educational feedback; they do not determine admission or produce legal effects. Analytics helps understand visits and applications and is not used to make solely automated admission decisions.

This policy may be updated when services or data practices change. The current version and update date will be published on this page.