Privacy Policy
Version 2.0 · Last updated: July 30, 2026
This Privacy Policy explains how personal data are processed when you visit tromplo.com, create an account, buy or use a course, webinar, ebook or other digital product, join a community or feedback activity, subscribe to marketing, contact Tromplo, or otherwise interact with the Website.
1. Controller and contact details
The data controller is Agnieszka Janarek, conducting business as TROMPLO Agnieszka Janarek, Jana Kowalika 7, 32-064 Niegoszowice, Poland. NIP: 5130241087. REGON: 361915607.
Email: [email protected]. Phone: +48 509 217 119. Privacy requests may be sent to the email or postal address above.
2. Personal data we collect
- Account and identity data: name, email address, login credentials in protected form, profile information, account settings and account activity.
- Order and billing data: billing address, country, company and tax details, purchased products, price, currency, tax status, discounts, loyalty points, affiliate or referral identifier, payment status, transaction identifiers, invoices, refunds and order history. Tromplo does not receive or store complete card or PayPal credentials.
- Course and community data: enrolment, access dates, lesson progress, questions, comments, assignments, certificates, feedback records, uploaded files and training videos, and information visible in a cohort or community where the product includes those features.
- Contact and support data: messages, complaint or withdrawal details, survey responses and correspondence.
- Marketing data: newsletter consent and source, subscription status, campaign delivery, opens and clicks, interests or segments, and responses to promotional content.
- Technical and usage data: IP address, device and browser information, language, approximate location derived from IP, timestamps, referring pages, pages and buttons used, cookie or similar identifiers, security events, diagnostic logs and consent choices.
- Social and third-party data: information returned by a sign-in provider when that option is used, public interactions with Tromplo social-media profiles, and source or referral information supplied by partners.
Data usually come directly from you, your device, the Website, a payment or sign-in provider, or a partner link you choose to use. Required fields are identified at the point of collection. Without the information required for an account, order or course, Tromplo may be unable to provide the requested service.
3. Purposes and legal bases
- Contract and pre-contract steps — Article 6(1)(b) GDPR: create and operate accounts; process orders and payments; provide access, materials, feedback, community features and certificates; deliver transactional messages; handle support, complaints, withdrawals and refunds.
- Legal obligations — Article 6(1)(c) GDPR: tax, accounting, invoicing, consumer-protection, fraud-prevention and regulatory duties.
- Consent — Article 6(1)(a) GDPR: newsletters and other electronic marketing where consent is required; non-essential cookies or similar technologies where consent is required; and separate permission for promotional use of a testimonial, image or video. Consent may be withdrawn at any time without affecting earlier lawful processing.
- Legitimate interests — Article 6(1)(f) GDPR: secure and maintain the Website; prevent abuse and fraud; diagnose errors; preserve evidence; establish or defend claims; measure and improve services; understand aggregate use; manage existing-customer relationships; and conduct proportionate business-to-business contact or direct marketing where permitted. You may object to processing based on legitimate interests.
Information entered during an incomplete checkout may be processed to preserve the cart, diagnose checkout problems, prevent fraud and, only where applicable law permits it, send a cart reminder. Marketing consent is separate from acceptance of the Terms and from data needed to perform a purchase.
4. Service providers and other recipients
Personal data are shared only to the extent necessary with providers and recipients supporting Tromplo, including:
- Stripe and PayPal for payment, authentication, fraud prevention and related transaction services;
- MailerLite for newsletter delivery, consent records, segmentation and campaign analytics;
- hosting, storage, backup, content-delivery, security, transactional-email and website-administration providers;
- Google services used on the Website, such as Tag Manager, reCAPTCHA and, where offered, sign-in or embedded media;
- Meta services, including the Meta Pixel and Tromplo’s Facebook and Instagram profiles;
- Cloudflare for security, delivery and performance analytics, and Sentry where error monitoring is enabled;
- wFirma and professional accountants, advisers and banks for invoicing, accounting, tax and legal compliance;
- instructors, moderators and contractors who need access to deliver the product or support the learner;
- public authorities or other parties where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Some providers act as Tromplo’s processors and some, such as payment, social-media or sign-in providers, may act as independent controllers for parts of their service. Their own privacy information applies to processing they control.
5. International transfers
Some providers may process data outside Poland or the European Economic Area. Where a restricted transfer occurs, Tromplo relies on an applicable adequacy decision, the European Commission’s standard contractual clauses with supplementary safeguards where required, or another lawful transfer mechanism. A provider’s participation in the EU–US Data Privacy Framework is relied on only where the relevant entity and transfer are covered by that framework.
6. Cookies, pixels and similar technologies
The Website uses strictly necessary technologies for functions such as login, security, cart, checkout, language and account sessions. These do not require consent where they are necessary to provide a service requested by the user.
The Website also uses or may use measurement, marketing and embedded-service technologies, including Google Tag Manager, Meta Pixel, Google reCAPTCHA and Cloudflare analytics. These technologies may read or store identifiers and process technical and usage data. Where applicable law requires consent for a non-essential technology, consent is the legal basis. You can block or delete cookies through your browser and may contact Tromplo to withdraw a consent or object to related processing. Blocking necessary storage can prevent login, checkout or course access.
Cookie names, providers, purposes and duration can change when providers update their services. Tromplo reviews the Website’s cookie and vendor inventory and will make an on-site cookie-settings control available for non-essential technologies. Until that control is active, browser controls remain available, but they may not affect information already processed lawfully.
7. Marketing and profiling
Newsletter subscribers can unsubscribe through the link in any marketing email or by contacting Tromplo. Tromplo may use campaign interactions, purchases and stated interests to create audience segments, avoid sending irrelevant offers, exclude existing buyers and measure campaign results. Website and campaign data may also be used to understand which source or partner led to a visit or purchase.
Tromplo does not make decisions based solely on automated processing that produce legal or similarly significant effects. Payment and security providers may independently apply automated fraud, authentication or transaction controls under their own terms.
8. Course videos, assignments and community content
If a course includes feedback, peer viewing or community participation, the product page or course interface will explain who can view submitted material. Tromplo processes the material to provide the requested teaching, feedback, moderation and course record. Promotional reuse is not included in that purpose and requires separate permission.
Before uploading material, make sure that you are entitled to share it and that any identifiable person has been informed and, where required, has consented. Do not upload children’s personal data or images unless Tromplo has expressly agreed to the process and the necessary guardian permissions are in place.
9. Retention
- Account data are kept while the account is active and for a reasonable period afterwards where needed for access history, security, claims or legal duties.
- Order, payment-confirmation, invoice and accounting records are kept for periods required by tax, accounting, consumer-protection and limitation-of-claims rules, generally up to six years after the contract is performed.
- Support and complaint correspondence may be kept for up to three years after contact ends, or longer where an active claim or legal duty requires it.
- Marketing data are kept until consent is withdrawn, an objection is accepted or the data are no longer needed. A minimal suppression record may be retained to respect an opt-out.
- Course submissions and community content are kept for the relevant access, feedback or community period and a reasonable technical backup period, unless longer retention is required for a dispute or the user has separately permitted reuse.
- Security, analytics, cookie and provider logs follow the purpose-specific period or the provider’s documented schedule and are not intentionally kept longer than necessary.
10. Your rights
Subject to the conditions in applicable law, you may request access, rectification, erasure, restriction, portability or a copy of your personal data; object to processing based on legitimate interests or to direct marketing; and withdraw consent. You may also ask for information about applicable transfer safeguards. Some records cannot be deleted while Tromplo must retain them by law or for legal claims.
Requests may be sent to [email protected]. Tromplo may need proportionate information to verify identity. You have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland at uodo.gov.pl. If another data-protection law applies to you, you may also contact the competent authority in your place of residence.
11. Social media and external services
When you interact with Tromplo through Facebook, Instagram, Google, YouTube or another external service, that provider processes data under its own terms. Tromplo receives only the data made available through the interaction or service. External links do not make Tromplo responsible for the independent privacy practices of another website.
12. Age requirement
Tromplo accounts and purchases are intended for adults with legal capacity to enter a contract. Tromplo does not knowingly invite children to create accounts or submit personal data. A guardian who believes that a child has submitted data should contact Tromplo.
13. Security
Tromplo uses proportionate technical and organisational safeguards designed to protect personal data, including access controls, protected connections, backups, monitoring and provider contracts where appropriate. No internet service can promise absolute security. Please use a unique password and notify Tromplo if you suspect unauthorised access.
14. Changes to this Policy
This Policy may be updated when the Website, providers or legal requirements change. The current version and date will remain available on this page. Material changes affecting an existing service or consent will be communicated through an appropriate channel where required.