PRIVACY POLICY
for https://nikitaynatalia.com
Last updated: 27 November 2025
1. Data Controller
The controller of personal data processed through the website https://nikitaynatalia.com (“Website”, “Service”) is:
ONdance sp. z o.o.
ul. Borowa 20, 05-502 Kamionka, Poland
KRS: 0000871948
NIP: 1231481709
REGON: 387656692
Contact e-mail: nikitaynatalia@gmail.com
(“Administrator”, “Company”, “we”, “us”, “our”).
2. Categories of Data and Purposes of Processing
We process personal data only when necessary, for specific and legitimate purposes. The scope of data depends on how you use the Website.
2.1. Purposes and legal bases
| Purpose of processing | Legal basis (GDPR) | Types of data |
|---|---|---|
| Account creation and management | Art. 6(1)(b) – performance of a contract | Name, e-mail, password |
| Purchase processing and access to Digital Courses | Art. 6(1)(b) | Contact details, payment data (processed by Stripe), transaction logs |
| Handling user communication (e-mail, contact form) | Art. 6(1)(f) – legitimate interest | Name, e-mail, content of message |
| Newsletter and marketing communication | Art. 6(1)(a) – consent | |
| Analytics, statistics, log data, service security | Art. 6(1)(f) | IP address, device information, browser data, cookies |
| Compliance with legal obligations (tax, accounting) | Art. 6(1)(c) | Billing and transaction records |
3. Cookies and Tracking Technologies
The Website uses cookies and similar technologies for:
ensuring the proper functioning of the Website,
storing user preferences,
statistical analysis (e.g., Google Analytics),
marketing and remarketing (e.g., Meta Pixel),
improving security and performance.
Upon your first visit, a cookie banner appears, allowing you to manage consent for non-essential cookies.
You may modify cookie settings in your browser at any time.
4. Recipients of Personal Data
Your personal data may be shared with trusted third parties, including:
hosting and IT infrastructure providers,
payment processors (including Stripe),
e-mail and newsletter systems,
analytics and marketing tools,
accounting, legal, and consulting service providers.
All such entities process personal data on the basis of a data processing agreement (DPA) and only according to our documented instructions.
We do not sell your personal data.
5. International Data Transfers
Some of our service providers (e.g., Stripe, analytics tools) may process data outside the European Economic Area (EEA).
Whenever data is transferred outside the EEA, we ensure compliance with Chapter V GDPR, including:
Standard Contractual Clauses (SCCs),
additional contractual and technical safeguards,
transfer impact assessments where required.
Transfers are carried out only if adequate protection of your data is guaranteed.
6. Your Rights under GDPR
You have the following rights regarding your personal data:
Right of access – to obtain a copy of your data.
Right to rectification – to correct inaccurate or incomplete data.
Right to erasure (“right to be forgotten”).
Right to restriction of processing.
Right to data portability – to receive your data in a machine-readable format.
Right to object to processing based on legitimate interest or direct marketing.
Right to withdraw consent at any time (e.g., for the newsletter).
Right to lodge a complaint with a supervisory authority (Polish President of the Personal Data Protection Office – UODO, or your local EU authority).
To exercise any rights, contact us at: nikitaynatalia@gmail.com
We respond within 30 days.
7. Data Retention Periods
We retain data only for as long as necessary:
Account and Course access data – for the duration of the contract and up to 6 years after termination (claims limitation period).
Newsletter data – until you withdraw consent.
Payment and accounting data – for 5 years, according to tax law.
Technical logs – for security purposes, typically up to 12 months.
After the retention period expires, data is securely deleted or anonymized.
8. Voluntary Provision of Data
Providing personal data is voluntary, but necessary for:
creating an Account,
purchasing Digital Content,
receiving newsletter communications,
contacting us through forms or e-mail.
Without certain data, we may be unable to provide specific Services.
9. Security Measures
We implement appropriate technical and organizational safeguards, including:
SSL encryption,
access control and authentication mechanisms,
secure data storage infrastructure,
minimization of processed data,
regular security audits and monitoring.
We take all reasonable measures to ensure the confidentiality, integrity, and availability of your personal data.
10. Automated Decision-Making and Profiling
We do not use automated decision-making that produces legal or similarly significant effects.
Certain marketing tools may involve limited profiling (e.g., remarketing based on Website behaviour), but such processing is based on consent and does not produce significant effects.
11. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy due to:
changes in law,
new functionalities or services,
technological or organizational adjustments.
Updated versions will be published on this Website and become effective upon publication.
12. Contact Details
For any questions related to your personal data or this Privacy Policy, contact us at: