top of page

Privacy Policy

The policy explains how personal data is processed in connection with the use of the website and services of Paulina Turska Dance Academy.

Version effective from August 19, 2026.

1

Data controller and contact details

The controller of personal data processed in connection with the activities of Paulina Turska Dance Academy is the Przestrzeń Tańca Turska & Ramos Foundation, represented by Paulina Turska, with its address: ul. 1 Żołnierzy Armii Wojska Polskiego 8/4U.

Contact in matters concerning personal data: akademiapauliny@gmail.com or turskaramosacademy@gmail.com , tel. +48 500 004 812.

Website: www.turskadanceacademy.com

2

What data can be processed

Depending on the manner of using the services and the Website, the Administrator may process in particular:

  • name and surname of the participant or parent/guardian

  • contact details, including email address and telephone number

  • residential address, if necessary for the provision of the service or settlements

  • data necessary to issue accounting documents and settlements

  • data of children participating in classes – to the extent necessary to organize and conduct classes

  • data regarding registration, selected classes, payments and cooperation history

  • IP address, internet identifiers and technical data related to the use of the Website

  • other data voluntarily provided in correspondence or forms

3

Purposes, legal basis and data storage period

- Registration and implementation of classes, workshops and other services (Article 6, paragraph 1, letter b of the GDPR – activities prior to the conclusion and performance of the contract); identification, contact data, registration and payment data; for the duration of the contract and then until the expiry of the limitation period for claims
- Settlements, accounting and tax documentation (Article 6, paragraph 1, letter c of the GDPR – legal obligation); identification and settlement data; for the period required by tax and accounting regulations

- Contact in organizational matters and handling inquiries (Article 6 paragraph 1 letter b of the GDPR or Article 6 paragraph 1 letter f of the GDPR – legitimate interest consisting in handling correspondence and organizing business activities); contact details and content of correspondence; until the end of the case, and then to the extent necessary to secure any claims

- Pursuing or defending against claims (Article 6, paragraph 1, letter f of the GDPR – legitimate interest of the Controller); data related to a given case or service; until the statute of limitations for claims expires or the proceedings are finally concluded

- Newsletter and electronic marketing (Article 6, paragraph 1, letter a of the GDPR – consent; in the scope of electronic communication, also consent required by the regulations on electronic communication); name, e-mail address, and possibly telephone number; to withdraw consent or terminate marketing activities early

- Ensuring the security and proper operation of the Website (Article 6, paragraph 1, letter f of the GDPR – legitimate interest in security, preventing abuse and maintaining the Website); IP address, technical logs, device identifiers; for the period necessary to ensure security and diagnostics, no longer than is necessary for a given purpose

- Analytics or personalisation using optional cookies (Article 6, paragraph 1, letter a of the GDPR – consent if the data allows for the identification of a person); online identifiers and data on activity on the Website; until consent is withdrawn or for the period indicated for a given cookie in the consent panel.

4

Data recipients

Data may be disclosed to entities supporting the Controller only to the extent necessary to perform specific tasks, in particular:

  • Przelewy24 payment operator – PayPro SA, in the scope of payment processing

  • accounting office and entities providing accounting services

  • providers of hosting, email, registration systems and IT support

  • providers of marketing, newsletter and social media tools – if they are used and there is an appropriate legal basis

  • law firms and other advisors when it is necessary to protect the rights of the Administrator

  • public authorities or other entities entitled to receive data under the law

If a given service provider processes data on behalf of the Controller, this is done on the basis of an appropriate data processing agreement.

5

Transfer of data outside the European Economic Area

As a general rule, the Controller strives to use services that ensure data processing within the European Economic Area (EEA). However, if the use of certain tools – in particular IT, analytical, newsletter, or social media services – results in data being transferred outside the EEA, such transfer will only take place based on a mechanism permitted by the GDPR, in particular an adequacy decision or standard contractual clauses, with the required safeguards in place.

6

Data subject rights

Under the terms set out in the GDPR, the data subject has the right to:

  • access to data and obtaining a copy thereof

  • data rectification

  • deletion of data if the conditions provided for in the GDPR are met

  • processing restrictions

  • data portability – if processing is based on consent or a contract and in an automated manner

  • object to processing based on Article 6(1)(f) of the GDPR, for reasons relating to your particular situation

  • object to direct marketing at any time

  • withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal

  • filing a complaint with the President of the Personal Data Protection Office

Requests regarding the exercise of rights can be sent to: akademiapauliny@gmail.com.

7

Voluntary provision of data

Providing data is generally voluntary. If data is necessary to conclude or perform a contract, failure to provide it may prevent you from registering for classes, participating in an event, making a payment, or providing another service. In the case of data processed based on consent, failure to provide consent does not affect your ability to use the services, unless the activity, by its very nature, requires the use of data covered by consent.

8

Automated decision making

The Controller does not make decisions with respect to users that produce legal effects or similarly significantly affect them solely based on automated processing, including profiling, unless the user is separately and clearly informed about such a mechanism in the future in accordance with the GDPR.

9

Data security

The Controller applies appropriate technical and organisational measures, adapted to the nature, scope, context and purposes of processing and the risk of infringement of the rights or freedoms of natural persons, in order to ensure the confidentiality, integrity, availability and resilience of data and the systems used to process them.

10

Cookies and similar technologies

The Website may use cookies and similar technologies. Cookies necessary for the operation of the Website may be used without consent to the extent permitted by law. Analytical, functional, advertising, and other optional cookies are activated only after obtaining appropriate user consent, if such consent is required. Detailed information can be found in the separate Cookie Policy and in the consent management panel available on the Website.

11

Changes to the Privacy Policy

The Policy may be updated in the event of changes in regulations, data processing methods, or Website functionality. The current version of the document is published on the Website along with its effective date.

bottom of page