Draft notice: This Privacy Policy is a working draft. The Controller’s identification and contact details marked [TO BE COMPLETED] must be completed and the document should be reviewed before it is treated as the final privacy notice.

1. About this Privacy Policy

This Privacy Policy explains how personal data is collected, used, stored and protected in connection with the Business Lounge website and learning portal available at https://businesslounge.pl/ (the “Website”). It also explains the rights available to users under Regulation (EU) 2016/679 (the “GDPR”).

Last updated: 24 August 2026.

2. Data Controller

The controller of personal data processed through the Website is:

  • Full legal name: [TO BE COMPLETED]
  • Registered or business address: [TO BE COMPLETED]
  • Privacy contact email: [TO BE COMPLETED]
  • Tax and registration details: [TO BE COMPLETED]

Questions concerning this Privacy Policy or the exercise of data protection rights should be sent to the privacy contact email specified above once completed.

3. Scope of the Website

The Website presents language-learning services and provides registered adult students with access to an individual course area, learning materials, exercises, homework, presentations and other course resources.

The offer is intended for adults and is not directed to persons under 18 years of age. Services are intended for clients located within the European Union. The Website does not accept online payments and lessons are not recorded.

4. Categories of Personal Data

Depending on how a user interacts with the Website, the following categories of personal data may be processed:

  • identification and contact data, such as name, email address, telephone number and company name;
  • account data, such as username, password stored in protected form, membership level and account status;
  • course-related data, including assigned materials, homework, exercise answers, results, progress information and teacher notes;
  • information voluntarily provided through contact forms or correspondence;
  • technical and security data, including IP address, browser and device information, timestamps, requested URLs, error records and server logs;
  • cookie preferences and, if analytics is introduced in the future, information about Website usage collected after the required consent has been obtained.

Users should not submit special-category personal data or other sensitive information unless it is strictly necessary and specifically requested.

5. Purposes and Legal Bases

Personal data may be processed for the following purposes:

  • Responding to enquiries and taking steps before entering into a contract – Article 6(1)(b) GDPR;
  • Providing course services and administering student accounts – Article 6(1)(b) GDPR;
  • Assigning learning materials, evaluating exercises and supporting the learning process – Article 6(1)(b) GDPR;
  • Maintaining the security, reliability and proper operation of the Website, preventing abuse and keeping technical logs – the Controller’s legitimate interests under Article 6(1)(f) GDPR;
  • Establishing, exercising or defending legal claims – the Controller’s legitimate interests under Article 6(1)(f) GDPR;
  • Complying with legal obligations – Article 6(1)(c) GDPR;
  • Using non-essential analytics cookies in the future – consent under Article 6(1)(a) GDPR and applicable rules governing storage of or access to information on a user’s device.

Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

6. Contact Forms and Correspondence

When a user sends an enquiry through a form or by email, the data entered in the message is used to respond, manage the enquiry and, where requested, take steps towards providing services. Providing data is voluntary, but failure to provide the information required to respond may make it impossible to handle the enquiry.

7. Student Accounts and Learning Data

Registered students receive access to an individual course area. Account and course data is used only to provide and manage the learning service, make resources available to the relevant student, assess submitted exercises and communicate about the course.

Users are responsible for protecting their login credentials and should notify the Controller if they suspect unauthorised access to their account.

8. Payments and Lesson Recordings

The Website does not process online payments. If payment arrangements are made outside the Website, the relevant payment or accounting information may be processed separately in accordance with applicable law and the terms of the service relationship.

Lessons are not recorded. If this changes in the future, students will be informed in advance and an appropriate legal basis and retention period will be established before any recording takes place.

9. Hosting and Service Providers

The Website’s hosting and server infrastructure is provided by cyber_Folks S.A., with its registered office at ul. Wierzbięcice 1B, 61-569 Poznań, Poland, KRS 0000685595, NIP 7792467259 and REGON 367731587. The current legal identity of the provider should be verified against the Controller’s hosting agreement before this draft is finalised.

The hosting provider may process data stored within the Website infrastructure, backups, technical data and server logs on behalf of the Controller.

Personal data may also be disclosed to IT support providers, website administrators, email or communication providers, professional advisers and public authorities where disclosure is required by law. Providers receive only the data necessary to perform their services and are required to protect it appropriately.

10. Cookies

The Website may use cookies and similar technologies that are strictly necessary for security, user authentication, session management, saving privacy choices and the proper operation of the learning portal. These technologies are necessary to provide services requested by the user and cannot always be disabled through the Website.

Users can manage or delete cookies using their browser settings. Blocking necessary cookies may prevent login or interfere with certain Website functions.

11. Planned Google Analytics

Google Analytics is not currently active on the Website. The Controller may introduce Google Analytics in the future to understand how visitors use the Website and improve its content and functionality.

Before Google Analytics is activated, the Website will implement an appropriate consent-management mechanism. Analytics storage and non-essential analytics cookies will be disabled by default and will only be activated after the user has given consent. Refusing analytics cookies will not restrict access to the Website or the learning portal.

If Google Analytics is introduced, this Privacy Policy and the cookie information will be updated to describe the data collected, relevant cookies, retention settings, Google entities involved, safeguards for any transfers outside the European Economic Area and the method for withdrawing consent.

12. International Data Transfers

The Website is intended to provide services to clients within the European Union. The Controller does not intentionally transfer personal data outside the European Economic Area unless this is necessary for a selected service provider and a valid transfer mechanism is in place.

Some future technology providers, including Google in connection with planned analytics, may process data in countries outside the EEA. Before such processing begins, the Controller will assess the transfer and use an applicable safeguard, such as an adequacy decision, the EU–US Data Privacy Framework where applicable, or standard contractual clauses.

13. Data Retention

Personal data related to a course account, learning materials, teacher notes and exercise results is generally retained for up to 12 months after the end of the course. Contact enquiries are generally retained for no longer than 12 months after the matter has been concluded, unless the enquiry leads to a contractual relationship.

Technical and security logs are retained only for the period reasonably necessary to maintain security, diagnose errors and prevent abuse.

Certain data may be retained for a longer period where required by law or necessary for the establishment, exercise or defence of legal claims. Accounting, tax or contractual records processed outside the Website may therefore be retained for the periods required by applicable law.

After the applicable retention period, personal data is deleted or anonymised unless continued retention is legally justified.

14. Data Security

Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls, individual user accounts, software updates, encrypted connections where available, backups and restricting access to persons who need the data for authorised purposes.

No online system can guarantee absolute security. Users should use strong, unique passwords and avoid sending sensitive information through ordinary contact forms.

15. Your Rights

Subject to the conditions set out in the GDPR, a data subject may have the right to:

  • request access to personal data and receive a copy;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive data in a structured, commonly used and machine-readable format where data portability applies;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with a competent supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, https://uodo.gov.pl/.

A request may require identity verification to prevent unauthorised disclosure of personal data.

16. Automated Decision-Making

The Website does not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect users. Interactive exercises may automatically compare submitted answers with predefined correct answers, but this functionality supports learning and does not produce legal or similarly significant effects.

17. Changes to this Privacy Policy

This Privacy Policy may be updated when the Website, services, providers or legal requirements change. Material changes will be communicated in an appropriate manner. The date displayed at the beginning of the document indicates the latest revision.

18. Contact

For privacy-related questions or requests, contact: [PRIVACY CONTACT EMAIL – TO BE COMPLETED].