This privacy policy describes how the personal data of visitors to balancebcc.eu, of persons contacting Balance BCC via the contact form, email, or other available communication channels, and of persons booking and paying for sessions via the booking system available on the website, is processed.
1. Data Controller
The controller of your personal data is Bogumiła Czubińska Czapska, operating under the brand Balance BCC.
Contact the Controller:
e-mail: bcc@balancebcc.eu
2. Personal data we process
Depending on how you use the website or contact the Controller, the following data may be processed:
- first and last name,
- email address,
- phone number, if provided voluntarily,
- content of messages sent via the contact form or email,
- data relating to session bookings: the selected date and time and — if provided — a brief description of the session topic,
- information about the payment status of a session (the Controller has no access to full payment card details — see section 7),
- data relating to collaboration, consultations, coaching, or mentoring,
- data necessary for billing, if a contract is concluded,
- technical data associated with use of the website, such as IP address, browser information, date and time of visit,
- statistical data on how the website is used — only after consent to analytics has been given (see section 8).
3. Purposes and legal bases for processing
Personal data is processed for the following purposes:
- handling enquiries submitted via the contact form or email — on the basis of the legitimate interest of the Controller in communicating with persons interested in the services offered;
- booking, paying for, and conducting a session — on the basis of necessity to take steps prior to concluding a contract and to perform the contract;
- preparing a proposal, establishing the terms of collaboration, or taking steps prior to concluding a contract — where the contact concerns coaching, mentoring, or consulting services;
- performance of a concluded contract — where collaboration has commenced;
- fulfilment of legal obligations, in particular tax and accounting obligations;
- analysing how the website is used and improving its content — solely on the basis of voluntary consent given via the cookie banner;
- ensuring the security of the website and protecting against spam and abuse, including through the contact form security mechanisms;
- pursuing or defending against claims, where necessary.
4. Contact form
Use of the contact form is voluntary, but providing the data required in the form is necessary in order to send a message and receive a reply.
The contact form may use security mechanisms to protect against spam and abuse, such as a CSRF token and Google reCAPTCHA. These mechanisms help distinguish genuine submissions from automated spam attempts.
5. Google reCAPTCHA
The website may use the Google reCAPTCHA service to protect the contact form against spam and abuse. This service may analyse how the website is used, technical information about the device, IP address, and other data necessary to assess whether the form is being used by a person or an automated mechanism.
The service is provided by Google Ireland Limited. Use of Google reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
6. Session bookings (Cal.eu)
The website uses the Cal.eu booking system (the European instance of Cal.com), embedded on the contact page, to schedule sessions. During booking, the following data is processed: first and last name, email address, the selected session date and time, and — if provided — a brief description of the topic. This data is necessary to arrange and conduct the session.
The booking system provider processes data on behalf of the Controller, on servers located in the European Union. Details of the provider's data processing: Cal.eu Privacy Policy.
Online sessions take place using video conferencing tools (e.g. Google Meet) — the meeting link is sent in the booking confirmation email.
7. Online payments (Stripe)
Payments for sessions are handled by the payment operator Stripe. Payment data (e.g. card number, data required for BLIK or Przelewy24 payments) is entered directly in the operator's payment form and goes exclusively to Stripe — the Controller has no access to full payment card details. The Controller receives only information about the payment status and the data necessary for billing and for fulfilling tax and accounting obligations.
Details of the payment operator's data processing: Stripe Privacy Policy.
8. Analytics — Google Analytics 4
The website uses Google Tag Manager and Google Analytics 4 to analyse how the website is used and to improve its content. Full analytics measurement — including the setting of cookies — takes place only after consent has been given via the cookie banner displayed on the first visit (legal basis: consent). Until consent is given, Google tools operate in Consent Mode: they do not set cookies or persistent identifiers, and only anonymous technical signals without user identifiers may be transmitted.
Analytics may involve processing of, among other things: device and browser information, approximate location, pseudonymous identifiers, and data about the pages visited. The tools are provided by Google Ireland Limited — details in Google's Privacy Policy.
Consent to analytics may be withdrawn at any time — by changing your decision in the cookie banner or by deleting cookies in your browser. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
9. Recipients of personal data
Personal data may be shared with entities supporting the Controller in operating the website and conducting business, in particular:
- hosting and technical infrastructure provider,
- email service provider,
- the provider of technical maintenance and development of the website (Krzysztof Czapski Consulting),
- the booking system provider (Cal.eu),
- the payment operator (Stripe),
- providers of analytics and security tools (Google),
- providers of accounting, tax, or legal services, where necessary,
- public authorities, where disclosure is required by law.
10. Transfers outside the European Economic Area
In connection with the use of certain technology services, in particular Google services and the Stripe payment operator, data may to a limited extent be processed outside the European Economic Area. Where this occurs, appropriate safeguards as required by data protection legislation apply, in particular standard contractual clauses or other appropriate protections.
11. Data retention
Personal data will be retained for the period necessary to fulfil the purpose for which it was collected.
- correspondence data — for the time needed to handle the enquiry and any subsequent communication;
- booking and payment data — for the duration of the collaboration and the periods required by tax and accounting regulations;
- data relating to a concluded contract — for the duration of the collaboration and the period required by law or necessary for pursuing or defending claims;
- accounting and tax data — for the period required by applicable law;
- analytics data — for the retention periods configured in the analytics tool;
- technical and security data — for the time needed to ensure the proper functioning of the website and protection against abuse.
12. Your rights
In connection with the processing of your personal data, you have the right to:
- access your data,
- rectify your data,
- erase your data,
- restrict processing,
- data portability,
- object to the processing of your data,
- withdraw consent, where processing is based on consent.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) if you consider that your data is being processed unlawfully.
13. Cookies
The website uses cookies in two categories:
- essential (technical) — these ensure the proper functioning of the website: session handling and contact form security (CSRF token), remembering your chosen language version, and remembering your consent decision. They do not require consent and are not used for tracking.
- analytics — Google Analytics 4 (loaded via Google Tag Manager) — enabled only after consent has been given via the cookie banner.
The Cal.eu booking calendar embedded on the contact page may additionally use its own cookies necessary for the proper functioning of bookings and payments.
You can change your cookie decision at any time — via the consent banner settings or by deleting cookies in your browser settings.
14. Data security
The Controller applies appropriate organisational and technical measures to protect personal data, in particular an encrypted HTTPS connection, contact form security mechanisms, and restricting access to data solely to persons and entities who require it for a legitimate purpose.
15. Changes to this policy
This privacy policy may be updated in the event of changes to the website's operation, changes to the tools used, or changes in applicable law. The current version of this document is always available on this page.