Privacy Policy
Last updated: 20 July 2026
This Privacy Policy describes how Daxowu Cuzana, operating at Al. Jerozolimskie 83, Warszawa, Poland (hereinafter "we," "us," or "the Controller"), collects, uses, stores, and protects personal data obtained through the website daxowu-cuzana.info and through direct contact with our organization. This policy is written in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, or GDPR), as well as the Polish Act of 10 May 2018 on the Protection of Personal Data (Dz.U. 2018 poz. 1000, as amended) and the Polish Telecommunications Law (Prawo telekomunikacyjne) as it applies to electronic communications.
We take data protection seriously. This document is intended to give you a complete and honest picture of what data we handle and why. If anything in this policy is unclear, you are welcome to contact us directly at [email protected].
1. Who is the Data Controller
The Controller of your personal data is Daxowu Cuzana, with its registered address at Al. Jerozolimskie 83, Warszawa, Poland. You can reach us by email at [email protected] or by phone at +48 579 242 299. As the Controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that this processing is lawful, fair, and transparent.
2. What data we collect and how
We collect personal data in two ways: directly, when you provide it to us, and indirectly, through the operation of the website itself. When you use the contact form on our website, we collect the email address you provide and the content of your message. If you choose to include your name, that is also collected, but it is not required. When you contact us by phone or email directly, we collect the information contained in that communication.
Through the operation of the website, our web hosting infrastructure may automatically collect technical data including your IP address, browser type, operating system, referring URL, pages visited, and the time and date of your visit. This data is collected in server logs as a standard part of how websites function and is used solely for security and operational purposes. We do not use this data to identify individual visitors unless required to do so for security or legal reasons.
If you have consented to analytics cookies, additional behavioral data about how you navigate the site may be collected through third-party analytics tools. The specific data collected depends on which tools are active and the consent choices you have made. You can review and change your cookie preferences at any time using the cookie banner on this site.
3. Legal basis for processing
We process your personal data on the following legal bases as defined in Article 6 of the GDPR. When you contact us through the form or by email, we process your data on the basis of our legitimate interest (Article 6(1)(f) GDPR) in responding to inquiries about our educational program, and where relevant, on the basis of your consent (Article 6(1)(a) GDPR) to the processing of your data for that purpose. For analytics and marketing cookies, the legal basis is your freely given, specific, and informed consent (Article 6(1)(a) GDPR), which you provide through the cookie consent mechanism. Necessary cookies are processed on the basis of our legitimate interest in operating a functional website. We do not process any special categories of personal data (as defined in Article 9 GDPR).
4. How we use your data
Data collected through the contact form is used exclusively to respond to your inquiry. We do not add your email address to any mailing list without your explicit consent. We do not use contact form data for marketing purposes. Server log data is used to monitor and maintain the security and availability of the website. Analytics data, where consented to, is used in aggregated form to understand how people use the site so we can improve its content and structure.
5. Data retention
We retain contact form data for as long as is necessary to respond to and resolve your inquiry, and for a reasonable period thereafter in case follow-up is needed, not exceeding 12 months from the date of your last communication with us. Server log data is retained for a maximum of 90 days unless a longer retention period is required for security investigation purposes. Analytics data retention depends on the specific tool in use and is governed by that tool's own data retention settings, which we configure to the shortest reasonable period.
6. Your rights under GDPR
You have the following rights regarding your personal data: the right to access the data we hold about you (Article 15 GDPR); the right to rectification of inaccurate data (Article 16 GDPR); the right to erasure ("the right to be forgotten") where the data is no longer necessary for the purpose for which it was collected (Article 17 GDPR); the right to restriction of processing in certain circumstances (Article 18 GDPR); the right to data portability for data processed on the basis of consent or contract (Article 20 GDPR); and the right to object to processing based on legitimate interests (Article 21 GDPR). Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing that took place before the withdrawal.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by GDPR. If you believe your rights have not been respected, you have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, www.uodo.gov.pl.
7. Data sharing and third parties
We do not sell your personal data to third parties. We may share data with service providers who assist in operating the website and communications infrastructure, including web hosting providers and email service providers. These providers act as data processors under contracts that require them to protect your data and process it only on our instructions, in accordance with Article 28 GDPR. Where analytics or other tools are enabled and consented to, data may be shared with the providers of those tools. We do not transfer personal data outside the European Economic Area except where appropriate safeguards are in place as required by Chapter V of the GDPR.
8. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction, in accordance with Article 32 GDPR. These measures include the use of HTTPS for all data transmission, access controls on systems that store personal data, and regular review of our security practices. No transmission over the internet is completely secure, but we take all reasonable steps to protect the data you share with us.
9. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this document. We encourage you to review this policy periodically. Continued use of the website after changes are posted constitutes your acknowledgment of the updated policy.