Skip to content
PL CSCS

Legal / Prawne

Privacy policy

Privacy version 4.7 (UK) · last updated 15 July 2026.

This privacy policy explains how "PL CSCS" processes your personal data and your rights under the UK GDPR and Data Protection Act 2018.

The data controller is PL CSCS. To contact us about your personal data, open a ticket in the support centre on the Site.

1. What data we process

  • Email address, account identifiers, email-verification status, basic sign-in activity needed to protect the account, and the legal-document versions, language, and timestamp accepted when the account is created. Passwords are handled by our authentication provider; we do not store readable passwords.
  • Payment-provider customer identifier, payment status, and (where applicable) subscription identifiers — to handle one-time purchases, optional auto-renew billing, and cancellations.
  • Session results and attempt history — to show your progress.
  • Support-ticket contact details, category, subject, message history, status, timestamps, and linked account identifier where you are signed in — to investigate and answer your request.
  • Technical and security data needed to operate and protect the Service, such as network signals, browser or device category, timestamps, and automated anti-abuse checks.
  • We use PostHog (EU hosting) for cookieless aggregate page analytics. Events cover page path, referring domain, browser or device category, approximate region, and timestamps. We do not send account IDs, email addresses, support content, payment details, or question and answer content to PostHog.

2. Purposes and legal bases

  • Contract performance — account creation, access sale, and session history.
  • Legal obligations — issuing and storing accounting documents.
  • Legitimate interests — fraud prevention, service security, aggregate visit statistics, product improvement, and support handling.

3. Who receives data

Data is processed by trusted providers:

  • Hosting, authentication, and infrastructure providers that help us run the Service. Processing may involve approved international transfers with appropriate safeguards.
  • Our transactional email provider — delivery of ticket receipts and support notifications.
  • Our payment provider — card payments and receipts. Payment provider privacy policy.
  • Security providers that help prevent automated abuse on registration, sign-in, and support forms.
  • PostHog (EU hosting) — cookieless aggregate web analytics. We send only pathname pageviews and do not use person profiles or session replay for this Service. PostHog privacy policy.

4. How long we store data

  • Account, entitlement, and study history — while the account is active. When signed in, you can delete your account in Account centre after password and two-step verification; paid access and study data on that account end immediately and you can register again later with a new account. Limited security, payment, and support records may be retained where the law or fraud prevention requires it.
  • Payment and accounting records — for the retention period required by applicable tax and accounting law.
  • Support tickets and replies — for as long as reasonably needed to answer the request, maintain service history, handle complaints or legal claims, and meet legal obligations, then deleted or anonymised where appropriate.
  • Sign-in and security logs — only as long as reasonably needed to protect accounts, handle support, or establish legal claims, then deleted or anonymised.
  • PostHog pageview events are kept for the period configured in our EU analytics project and reviewed for deletion or aggregation when no longer reasonably needed to measure traffic.

5. Your rights

You have the right to access, rectify, erase, restrict processing, transfer your data, object, and lodge a complaint with a supervisory authority.

To exercise your rights, including erasure: when signed in, delete your account in Account centre (password and two-step verification required), or open a ticket in the support centre on the Site. You may also complain to the UK Information Commissioner's Office (ICO) or, where applicable, the data-protection authority where you live.

6. Cookies

The service does not use advertising cookies. Necessary browser storage is used for sign-in and study progress. PostHog analytics runs without cookies and without storing analytics data in local or session storage, and sends only pathname pageviews.

7. Security

We use industry-standard protections, including encrypted connections, authentication, email verification, optional two-step verification, and access controls appropriate to the Service. No online service can guarantee absolute security.

8. Policy changes

Changes to this policy are published on this page. The last update date is shown above.