Privacy Policy
Introduction
Effective protection of your privacy, including personal data, is of particular importance to us. Therefore, we present our Privacy Policy to provide the most important information regarding the principles we follow to protect your data.
Glossary
For the purposes of this document, the following definitions apply:
- Administrator, i.e. the entity determining the purposes and means of personal data processing — Łukasz Zdanowicz, conducting business under the name PHU Łukasz Zdanowicz, Stanisława Knapowskiego 20/5, 60-126 Poznań, email address: office@phiboard.com;
- Application — PhiBoard application;
- data — see "personal data";
- personal data — information about an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be directly or indirectly identified, in particular based on an identifier such as name, identification number, location data, online identifier, or one or more specific factors that define the physical, physiological, genetic, mental, economic, cultural, or social identity of that person;
- supervisory authority — the President of the Personal Data Protection Office;
- processing — an operation or set of operations performed on personal data or sets of personal data, whether automated or non-automated, such as collection, recording, organizing, structuring, storing, adapting or altering, retrieving, viewing, using, disclosing by transmission, dissemination, or otherwise making available, aligning or combining, restricting, erasing, or destroying;
- GDPR — the Regulation of the European Parliament and Council (EU) 2016/679 of April 27, 2016, on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119/1, 2016);
- Service — the website of the Service Provider, available at https://phiboard.com/;
- User — a natural person, legal entity, or organizational unit without legal personality using the Application and the Service;
- data subject's consent — a voluntary, specific, informed, and unequivocal indication of the data subject's wishes, whereby the data subject, by a statement or a clear affirmative action, consents to the processing of their personal data.
Basic Principles of Data Processing by the Administrator
When processing your personal data, we commit to adhering to the following principles:
- lawfulness, fairness, and transparency. Data processing will be conducted in accordance with the law, fairly, and in a transparent manner for the data subject;
- purpose limitation. Data will be collected for specific, legitimate, and legally justified purposes and not processed further in a manner incompatible with those purposes;
- data minimization. Data will be adequate, relevant, and limited to what is necessary for the purposes for which they are processed;
- accuracy. Data will be accurate and, where necessary, kept up to date. Reasonable steps will be taken to ensure that personal data that are inaccurate in relation to the purposes of processing are erased or rectified without delay;
- storage limitation. Data will be kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which the data are processed;
- integrity and confidentiality. Data will be processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
What Data Do We Process?
By registering on the Service and using the PhiBoard.com Application, you provide your email address, as well as choose a username and password. If you register via media available on the Service, such as a Google, Facebook, or Discord account, the Application and Service will also have access to the data identifying you, provided by you in the mentioned sources. You also provide personal data — first name, last name, and email address — through the contact form on https://phiboard.com/.
Data on the Use of the Service and the Application
In addition to the data you provide yourself, we record the moment of your last activity, i.e. the date and time you last used the Service or the Application, in particular when you open a board. We do not record a history of individual actions or their content.
This information serves technical and statistical purposes only: it lets us tell whether an account is active, schedule maintenance so that it does not interrupt ongoing classes, and respond to reports about how the service behaves.
The legal basis for processing is the legitimate interest of the Administrator in ensuring the correct operation and development of the service (Article 6(1)(f) GDPR).
Is Providing Data Mandatory?
Providing data is voluntary, but if you do not provide the required data, you will not be able to use the Service and the Application.
Purposes and Legal Basis for Data Processing
Your data is primarily processed by us to enable you to use the Service and the Application, including conducting classes/trainings and taking part in them after being invited by the person running them. Use of the Service and the Application is free of charge.
Providing certain data is necessary for the performance of the contract and to take actions at your request before the contract is concluded (Art. 6(1)(b) GDPR). Since some data may also be processed to fulfill statutory obligations imposed on the Administrator under applicable law (e.g., tax regulations, accounting provisions), the legal basis for processing also includes Art. 6(1)(c) GDPR. In the case of data processed for the purpose of asserting or defending claims, the legal basis for processing is Art. 6(1)(f) GDPR (legitimate interest of the administrator or a third party in enabling the Administrator and clients to pursue or defend claims). If, while using the Application and Service, you decide to provide more data than required by the Administrator, their processing will be based on your consent (Art. 6(1)(a) GDPR).
Data Processing Period
We ensure that your data will be processed for no longer than necessary for the purposes for which it is processed, at least for the period necessary to perform the contract, but no longer than the applicable statute of limitations for claims as set by law. In some cases, periods specified in legal provisions also apply. This particularly applies to tax documents (e.g., invoices) and documents specified in accounting regulations, which must be stored for 5 years from the end of the calendar year in which the tax obligation arose.
Who Can Access Your Data?
As part of our activities, the Administrator may disclose your data to:
- postal and courier companies for correspondence purposes,
- the law firm providing legal services to the Administrator in case of potential claims by or against the Administrator, and thus also to courts,
- the accounting firm servicing the Administrator,
- public authorities, law enforcement, and justice bodies upon their request if required by applicable law.
The Administrator assures that it does not intend to transfer your data to third countries.
Voice Chat on the Board
The Application offers voice chat between participants of the same board. The call is started by the board owner, and the remaining participants join it themselves. Turning on the microphone always requires your consent, given in the browser or in your device settings; you may withdraw this consent at any time in those settings.
The audio of the call is transmitted directly between participants' devices using WebRTC technology. It does not pass through our servers, and we do not listen to it, record it, store it or share it with third parties. We do not create transcripts of calls either.
To establish such a connection, our server only relays the technical information required to set it up (so-called signalling): the session description and the network addresses of the participants' devices, including the IP address. This information is processed solely for the time needed to establish the connection and is not stored by us afterwards.
Determining a device's public address is assisted by public STUN servers provided by Cloudflare, Inc. and Google LLC. Only the information necessary to establish the connection reaches those servers; we do not send them the content of the call or your account data.
The legal basis for processing in this respect is Article 6(1)(b) GDPR, i.e. the necessity to perform a service requested by you, and with regard to microphone access itself — your consent (Article 6(1)(a) GDPR).
Using voice chat is entirely voluntary. Declining it does not limit your ability to use the other features of the board.
Cookies Policy
Cookies are small text files stored on your device (computer, smartphone, tablet) when using the Service and Application. They contain information that allows us to recognize your browser during subsequent visits.
We use the following types of cookies:
- essential cookies: these cookies are necessary for the functioning of the Service, e.g., to log into your user account, browse courses;
- analytical cookies: they collect anonymous statistical data regarding the use of the Website, allowing us to improve its functionality and content, such as Google Analytics;
- marketing cookies: they may be used to display personalized ads on other websites.
You can manage cookies using your browser settings, allowing you to block them, delete existing cookies, or allow their storage. Detailed information about managing cookies can be found in the help options of your browser or on the producer's page (Google Chrome, Internet Explorer, Mozilla Firefox, Opera, Safari).
Your Rights
Under the GDPR, you have the right to:
- access your data and obtain a copy of it;
- correct your data (if the data is incomplete, outdated, or inaccurate);
- request the deletion of data when: the data is no longer necessary for the purposes for which it was collected; consent to data processing is withdrawn; objection to processing is raised; data has been processed unlawfully; data needs to be deleted in order to comply with legal obligations under Union or Polish law;
- request restriction of data processing when: data is inaccurate — for a period allowing the Administrator to verify its accuracy; data has been processed unlawfully but you do not wish to have it deleted; the Administrator no longer needs the data for processing purposes but you need it for the establishment, exercise, or defense of legal claims; you have objected to the processing — until it is determined whether the legitimate grounds for the Administrator's processing outweigh the objections;
- data portability, i.e., the right to receive your personal data in a structured, commonly used, machine-readable format and the right to transmit this data to another administrator, or request the Administrator to directly transmit this data to another administrator, where technically feasible;
- not to be subject to decisions based solely on automated processing, including profiling;
- object to the processing of your data;
- with regard to data processed based on your consent — withdraw your consent at any time without affecting the lawfulness of processing carried out prior to its withdrawal;
- file a complaint with the supervisory authority, i.e., the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
Information on Automated Decision-Making, Including Profiling
The data you provide will not be used for automated decision-making, including profiling.