PRIVACY POLICY
English PDF- Version date
- 1 September 2026
- Website
- https://europacentrale.com
- Controller
- Wojciech Doniak, a sole trader conducting business under the name “Europa Centrale Wojciech Doniak”
- Address
- ul. Sienkiewicza 28A, 99-200 Poddębice
- NIP
- 8281425237
- Contact
- [email protected] | +48 572 740 292
1. Scope of this Privacy Policy
This Privacy Policy explains how Europa Centrale processes the personal data of people who use the website at europacentrale.com, submit enquiries, book a trial lesson or contact Europa Centrale by email, telephone, SMS, WhatsApp or through social media profiles. It also describes how third-party services used on the website operate.
This Policy is provided for information. Reading it does not constitute consent to the processing of personal data. Where consent is required in a particular situation, it will be requested separately in a freely given and unambiguous manner. Clients who enter into a contract and Participants in lessons also receive a separate Information Pack concerning the processing of personal data in connection with the provision of educational services.
2. Controller and contact details
The controller of personal data is Wojciech Doniak, a sole trader conducting business under the name “Europa Centrale Wojciech Doniak”, entered in the Central Register and Information on Economic Activity (CEIDG), ul. Sienkiewicza 28A, 99-200 Poddębice, NIP 8281425237, hereinafter referred to as the “Controller”.
For matters relating to personal data, please contact the Controller at [email protected] or on +48 572 740 292. The Controller has not appointed a data protection officer.
3. Types and sources of personal data
Depending on how the website is used, the Controller may process:
- data provided in the contact form: first name, email address, selected area of interest or type of service, scheduling preferences and the content of the message;
- data provided when booking a trial lesson: selected date, time and language, first name, surname and email address;
- data provided when contacting Europa Centrale directly: email address, telephone number, the identifier of an account used in a messaging application or social media service, and the content of the correspondence;
- technical data associated with use of the website, such as the IP address, date and time of the request, device or browser type, address of the requested resource, and error and security data — to the extent generated by the website infrastructure and its providers;
- data generated when a booking is handled, including the booking slot identifier, a Google Calendar event, a Google Meet link and booking confirmation messages.
Personal data are collected directly from the person using the website or automatically as part of the normal operation of the website and its infrastructure services. The online forms are intended for adults, including parents and guardians booking lessons for a child.
4. Purposes and legal bases for processing
4.1. Responding to an enquiry and presenting an offer
Personal data are used to review and respond to the message, understand the enquirer’s needs and — at their request — provide information about lessons or translation services.
Legal basis: Article 6(1)(b) GDPR where the contact is made with a view to entering into a contract, and Article 6(1)(f) GDPR in the case of general enquiries; the legitimate interest is the handling of day-to-day communications.
4.2. Booking and providing a trial lesson
Personal data are used to book a time slot, prepare the meeting, create an event and a Google Meet link, send confirmation and communicate about organisational matters.
Legal basis: Article 6(1)(b) GDPR — taking steps at the request of the data subject prior to entering into a contract.
4.3. Operation and security of the website
Technical data may be processed to deliver the website, detect errors, prevent misuse, carry out diagnostics and ensure continuity of service.
Legal basis: Article 6(1)(f) GDPR; the legitimate interest is the secure and proper operation of the website.
4.4. Usage statistics outside the European Union
Cloudflare Web Analytics is configured so that its analytics code is not injected for visitors located in the European Union. For other visitors, Cloudflare may compile aggregated website usage statistics in accordance with the rules governing its service.
Legal basis: Article 6(1)(f) GDPR, to the extent that the information processed constitutes personal data; the legitimate interest is to assess the operation and popularity of the website.
4.5. Establishment, exercise and defence of legal claims
Personal data and correspondence may be retained where necessary to document the course of a contact, booking or other event, and to protect the rights of the Controller or the data subject.
Legal basis: Article 6(1)(f) GDPR; the legitimate interest is the protection and enforcement of legal rights.
5. Contact form and Static Forms
The contact form sends personal data to Static Forms, which acts as the form-handling service provider. Each successfully submitted form entry is stored in the Static Forms account and forwarded to the Controller by email. The account is on the free plan, uses the United States region and is configured for provider-side retention of submissions for one year.
This means that data submitted through the form is transferred to the United States. The processing arrangements and safeguards are described in Static Forms documentation, including its Data Processing Agreement and Standard Contractual Clauses. The provider’s current information is available at https://www.staticforms.dev/privacy-policy and https://www.staticforms.dev/dpa.
Please do not enter data in the form that is not needed for a response, in particular a PESEL number, identity document details, health data or information about third parties, unless this is necessary.
6. Trial lesson bookings and Google Workspace
After a trial lesson time slot is selected, the booking data is handled by a Google Apps Script. The booking is recorded in Google Sheets, while the system creates a Google Calendar event and a Google Meet session and sends the relevant messages through Gmail. To provide lessons, the Controller uses a paid Google Workspace subscription under the europacentrale.com domain.
Google services are provided by Google Ireland Limited. Depending on the configuration and manner in which the services are provided, personal data may also be processed by other Google group companies or their subprocessors. Information about Google’s privacy practices is available at https://policies.google.com/privacy.
If a contract is entered into following the trial lesson, further processing of the Client’s and Participant’s personal data is described in the Information Pack provided to them. Booking through the website does not constitute entry into a paid contract and cannot be used to make payments.
7. Hosting, domain and security
The website is made available through Cloudflare Pages. Cloudflare provides hosting infrastructure, content delivery, connection management and security functionality. As part of these services, it may process technical data required to handle requests and protect the website. Information about Cloudflare’s privacy practices is available at https://www.cloudflare.com/privacypolicy/.
Squarespace is the domain registrar. The fact that the domain is registered with Squarespace does not, in itself, mean that Squarespace receives data entered in the website’s forms. The provider may, however, process data insofar as this is technically connected with the registration and maintenance of the domain.
The Controller applies appropriate technical and organisational measures, including an encrypted HTTPS connection, restricted access to service accounts and safeguards offered by the providers. No method of transmitting or storing data can, however, guarantee complete security.
8. YouTube, WhatsApp and social media
8.1. YouTube video
The website includes a YouTube video player embedded from the youtube-nocookie.com domain. The element uses lazy loading but is present in the page code before the play button is clicked. Consequently, the browser may establish a connection to Google or YouTube servers when the player is loaded, rather than only after the video begins playing. Playing the video may involve further processing of personal data by Google, particularly if the person is signed in to a Google or YouTube account.
Privacy-Enhanced Mode limits the use of playback activity to personalise advertising outside YouTube, but it does not prevent all processing by the provider. Google and YouTube privacy information is available at https://policies.google.com/privacy.
8.2. WhatsApp
The WhatsApp button opens the WhatsApp application or website. Contact through this channel is voluntary. Once a person proceeds to WhatsApp, their data is also processed by that service provider under its own terms. Anyone who does not wish to use WhatsApp may contact Europa Centrale by email or telephone.
8.3. Facebook, Instagram and YouTube
The website contains links to Europa Centrale profiles on Facebook, Instagram and YouTube. Following a link takes the user to an external platform. The operators of these platforms act as separate controllers in relation to personal data processed when their services are used. The Controller may receive messages, comments and other interactions directed to the Europa Centrale profile.
As at the date of this version of the Policy, the Controller does not publish reviews, photographs or recordings of Clients or Participants on the website and does not use their personal data for promotional purposes without a separate legal basis.
9. Cookies and similar technologies
The website may use technologies required for it to display correctly, remain secure and support forms and bookings. The Controller does not currently use Google Analytics 4, Meta Pixel, advertising tracking tools, a newsletter or a user-profiling mechanism.
Cloudflare Web Analytics is enabled with a setting that excludes data relating to visitors from the European Union. Cloudflare describes this service as not using cookies or persistent identifiers to track individual users. The YouTube embed may nevertheless cause the browser to connect to a third-party service before the play button is clicked, as described in section 8.1.
Users may restrict the storage of and access to information through their browser settings. Blocking essential technologies may affect the operation of certain features. Before introducing new analytics or advertising tools, the Controller will update this Policy and — where required — implement a mechanism for obtaining consent.
10. Recipients of personal data
Personal data may be disclosed only to the extent necessary for the relevant purpose:
- hosting, security and infrastructure provider — Cloudflare;
- contact form service provider — Static Forms;
- providers of email, spreadsheets, calendars, video meetings and other Google Workspace services — Google Ireland Limited and entities acting on its behalf;
- operators of WhatsApp, Facebook, Instagram and YouTube — when a person chooses to access or contact Europa Centrale through the relevant service;
- persons authorised by the Controller and providers of legal, accounting or IT support — where access is necessary and appropriately secured;
- public authorities — where disclosure is required by law.
The Controller does not sell personal data. Under the website’s current configuration, data submitted through forms are not disclosed for third-party advertising purposes.
11. Transfers outside the European Economic Area
Data submitted through the contact form are stored by Static Forms in the United States region. Google, Cloudflare, Meta and other global service providers may also process personal data outside the European Economic Area as part of their infrastructure or technical support operations.
Where personal data is transferred to a third country, the transfer should be based on a mechanism permitted under Chapter V of the GDPR, in particular an adequacy decision, Standard Contractual Clauses or another appropriate safeguard. Information about the mechanism used and the possibility of obtaining a copy of the safeguards may be obtained by contacting the Controller.
12. Retention periods
- submissions stored in the Static Forms account — for up to one year from the date of submission, in accordance with the configuration of the plan used;
- copies of enquiries held in email and correspondence with a person who does not enter into a contract — generally for up to 12 months after the correspondence ends;
- trial lesson booking data held in Google Sheets, Google Calendar and email — generally for up to 12 months from the scheduled lesson date, its cancellation or the end of the correspondence;
- contact details held in messaging applications and social media services — for the duration of the conversation and thereafter, as applicable, in accordance with the platform settings, until the conversation is deleted or for as long as needed to preserve evidence relevant to legal claims;
- technical and security-related data — for the period resulting from the relevant provider’s configuration and policies, and no longer than is necessary for security and diagnostic purposes;
- data required for the establishment, exercise or defence of legal claims — until the applicable limitation period expires or the matter is finally concluded.
Where the contact results in a contract, the personal data required to enter into and perform that contract continue to be retained for the periods specified in the Information Pack for Clients and Participants and under applicable tax, accounting and consumer law.
13. Rights of data subjects
Subject to the conditions laid down in the GDPR, a data subject may have the right to:
- access their personal data and receive a copy of it;
- rectify inaccurate personal data and complete incomplete personal data;
- have personal data erased or its processing restricted where the legal conditions are met;
- data portability in respect of personal data processed by automated means on the basis of consent or a contract;
- object, on grounds relating to their particular situation, to processing based on a legitimate interest;
- withdraw consent at any time where a particular processing activity is based on consent; withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Requests may be sent to [email protected]. The Controller may request information needed to verify the requester’s identity and will respond without undue delay, generally within one month. The scope of each right depends on the legal basis and circumstances of the processing.
Anyone who believes that their personal data are being processed unlawfully may lodge a complaint with the President of the Personal Data Protection Office. The authority’s current contact details are available at https://uodo.gov.pl.
14. Voluntary provision of personal data
Providing personal data in the contact form and when booking a trial lesson is voluntary. However, without the data marked as required, it may not be possible to submit an enquiry, book a time slot or receive a response. Use of WhatsApp and social media services is voluntary; contact by email and telephone is also available.
15. Children and minors
The forms on the website are intended for adults. A booking for a child should be made by a parent or legal guardian. The Controller does not encourage children to submit personal data through the website on their own. If it becomes apparent that data was submitted without appropriate adult involvement, the Controller may ask the child’s parent or guardian to make contact, or may delete the submission.
16. Automated decision-making and profiling
Personal data are not used to make decisions concerning a user that are based solely on automated processing, including profiling, and that produce legal effects concerning the user or similarly significantly affect them. The website does not currently carry out advertising profiling.
17. Changes to this Privacy Policy
This Policy may be amended, in particular if the way the website operates, the scope of personal data collected, the list of providers or the applicable law changes. The current version will be published on the website together with its effective date. If an amendment materially affects the way personal data is processed, the Controller will use an appropriate means of informing the data subjects.
Last updated: 1 September 2026