Privacy policy
Last updated: 27 Aug 2026
§ 1. General provisions and Personal Data Controller
This Privacy Policy sets out the rules for processing and protecting the personal data of Clients and Students using the educational services of the ePiFii School of Exact Sciences, as well as users of the related application and websites.
The Personal Data Controller is Martyna Kowalczyk, conducting business activity under the name ePiFii Martyna Kowalczyk, tax ID (NIP): [NIP number], with its registered office in Warsaw at ul. Dembowskiego 7/57, 02-784 Warsaw (the “Controller” or the “School”).
In all matters concerning personal data protection the Controller can be contacted at: martyna.kowalczyk@epifii.pl.
§ 2. Legal bases and purposes of processing
Personal data is processed in strict compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”). Data is processed for the following purposes:
1. Conclusion and performance of the educational services agreement (Art. 6(1)(b) GDPR) – to handle bookings, conduct lessons, provide teaching materials and operate the profile in the application.
2. Fulfilment of legal obligations incumbent on the Controller (Art. 6(1)(c) GDPR) – including accounting and tax obligations, such as issuing e-receipts and invoices.
3. Pursuit of the Controller's legitimate interests (Art. 6(1)(f) GDPR) – for ongoing communication with the Client, handling enquiries, ensuring the security of IT systems and, where applicable, establishing, pursuing or defending against claims.
§ 3. Scope of personal data processed
Depending on the nature of the service provided, the Controller processes the following categories of personal data:
1. Identification data: the full name of the Client (Parent/Legal guardian) and the full name of the Student.
2. Contact data: e-mail address and phone number.
3. Billing data: residence/registered address, tax ID (for business entities) and payment transaction history.
4. System data: history of purchased lesson packages, system logs related to the acceptance of the terms and current activity in the ePiFii application.
§ 4. Security standards and server infrastructure location
The Controller implements rigorous technical and organisational measures to ensure a level of security appropriate to the risk to the rights and freedoms of natural persons, including modern data transmission encryption protocols and strict access control.
Entrusted personal data is stored in an advanced, certified data centre located in the United Kingdom.
Transfers of data outside the European Economic Area (EEA) to the United Kingdom are fully lawful and secure, based on the European Commission's implementing decision confirming an adequate level of personal data protection in the United Kingdom (the “adequacy decision”). The server infrastructure therefore meets all requirements imposed by EU legislation and the GDPR.
§ 5. Disclosure of data to third parties (data recipients)
Personal data may only be transferred to trusted processors with whom the Controller has concluded appropriate data processing agreements guaranteeing the highest security standards. These include in particular:
1. Electronic payment system operators, for the authorisation and processing of financial transactions.
2. An external accounting office handling the School's accounting and HR processes.
3. Providers of IT infrastructure, hosting and authorised software (including the virtual fiscal cash register).
Under no circumstances does the Controller sell or share personal data with external parties for marketing purposes.
§ 6. Data retention period
Data processed for the provision of educational services is stored for the entire duration of the cooperation and, after it ends, only until the limitation of any claims under civil law.
Data contained in accounting and tax documentation (including fiscal receipts and invoices) is stored for 5 years from the end of the calendar year in which the relevant tax payment deadline expired, in accordance with mandatory provisions of Polish tax law.
§ 7. Rights of data subjects
Under the GDPR, every person whose data is processed by the School has:
1. The right of access: to request information about the processed data and to receive a copy of it.
2. The right to rectification: to request the prompt correction of inaccurate data or the completion of incomplete data.
3. The right to erasure (“right to be forgotten”): unless there are overriding legal grounds obliging the Controller to continue processing (e.g. tax requirements).
4. The right to restriction of processing.
5. The right to data portability to another controller in a structured format.
6. The right to object to processing based on the Controller's legitimate interest.
7. The right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office (PUODO).
To exercise the above rights, please contact the Controller by e-mail.
§ 8. Final provisions
The Controller reserves the right to update this Privacy Policy in connection with the ongoing development of the ePiFii application's functionality or changes in applicable law.
Clients will be informed of any material changes to the Privacy Policy by e-mail with the appropriate statutory advance notice.