Last updated: 21 July 2026
This policy explains, in plain terms, what happens to information about you when you visit this website or send us a message. It is written to comply with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Polish Act of 10 May 2018 on the Protection of Personal Data.
When we refer to the Data Controller, we mean the entity responsible for deciding how and why your personal data is processed. In this case, that is Zidotu, operating this website and the training program it describes.
Most visitors browse this site without giving us any information beyond what a browser sends automatically, such as an approximate location derived from an IP address and the type of device used. This falls under what is sometimes called Personal Data. We do not attempt to identify individual visitors from this technical data on its own.
If you use the contact form, you provide your name, email address, phone number and message content directly. Because the form is built to open your own email client rather than submit data to our server, that information travels through your email provider rather than through our website's backend, and we receive it only once you actually send the resulting email.
We rely on what the GDPR calls a Legal Basis for each processing activity. Responding to an inquiry you send us relies on legitimate interest in operating this business and, where a program is subsequently arranged, on the necessity of processing to perform that arrangement. Any optional cookies described in our Cookie Policy rely on your consent, which you can withdraw at any time.
Email correspondence is generally retained for as long as needed to respond to your inquiry and for a reasonable period afterward in case of follow-up, typically no longer than 24 months unless a training arrangement is ongoing, in which case records tied to that arrangement are kept according to standard bookkeeping retention rules under Polish tax law.
We do not sell personal data. Limited categories of recipients may process data on our behalf, referred to as a Processor. This can include our website hosting provider and standard email infrastructure. We do not transfer personal data outside the European Economic Area without an appropriate safeguard in place, such as Standard Contractual Clauses.
Under the GDPR you have the right to request access to, correction of, or deletion of personal data we hold about you, to object to certain processing, to request restriction of processing, and to lodge a complaint with the Polish supervisory authority, the Urząd Ochrony Danych Osobowych (UODO), if you believe your rights have been violated. To exercise any of these rights, contact us at [email protected].
We apply reasonable technical and organizational measures to protect information in our care, including access restrictions and secure connections for this website. No system is completely without risk, and we encourage you to avoid sending highly sensitive information through the contact form.
We may update this policy from time to time to reflect changes in our practices or in applicable law. The date at the top of this page indicates when it was last revised.