PRIVACY POLICY
PRIVACY POLICY
Last Updated: February 2026
1. GENERAL INFORMATION
1.1. This Privacy Policy describes how personal data is processed when using the website and services provided under the brand Soul Path.
1.2. The Data Controller (“Administrator”, “ADO”) is:
Recruitment Design
Małgorzata Miela
NIP (Tax ID): 8172100909
Address: ul. Wyszyńskiego 2/69, 30‑688 Kraków, Poland
Email: info@soulpath.pl
Although the services are provided under the brand “Soul Path”, the formal Data Controller is Recruitment Design Małgorzata Miela.
1.3. The Administrator processes data in accordance with GDPR, the Polish Data Protection Act, the Act on the Provision of Electronic Services, and the Polish Telecommunications Law.
1.4. The website and services are intended for adults only (18+).
2. DEFINITIONS
2.1. User – any individual using the website or Soul Path services.
2.2. Personal Data – any information that identifies or can identify a natural person.
2.3. Services – online sessions, consultations, newsletters, booking tools, contact forms, educational content and all functionalities of the website.
2.4. Cookies – small text files stored on the User’s device to enable website operation, analytics, or marketing.
3. TYPES OF DATA WE PROCESS
3.1. Data provided directly by the User
- Name and surname
- Email address
- Phone number (if needed)
- Content of messages
- Booking details (Calendly, Microsoft Bookings)
- Payment‑related data (processed via Stripe)
3.2. Technical and analytical data
- IP address
- Browser and device information
- Usage time and actions on the website
- Cookies
- Analytical tool data (e.g., Google Analytics, if implemented)
3.3. Newsletter data
- Email address
- Subscription confirmation (double opt‑in)
- Email engagement statistics (opens, clicks)
3.4. Transaction data
Processed through Stripe: payment tokens, transaction identifiers.
4. PURPOSES AND LEGAL BASES FOR PROCESSING
4.1. Contact and responses to inquiries
- Art. 6(1)(f) GDPR – legitimate interest (communication).
4.2. Booking appointments and service provision
- Art. 6(1)(b) GDPR – necessary to perform a contract.
4.3. Accounting and compliance
- Art. 6(1)(c) GDPR – legal obligation.
4.4. Newsletter subscription
- Art. 6(1)(a) GDPR – consent.
- Art. 10 Electronic Services Act & Art. 172 Telecommunications Law – consent for marketing messages.
4.5. Marketing, analytics, remarketing
- Art. 6(1)(a) GDPR – consent (analytics & marketing cookies).
- Art. 6(1)(f) GDPR – legitimate interest (own direct marketing that does not require cookies).
4.6. Establishment or defense of legal claims
- Art. 6(1)(f) GDPR – legitimate interest.
5. NEWSLETTER
5.1. Subscribing to the newsletter requires providing an email address and confirming the subscription (double opt‑in).
5.2. Data is processed until consent is withdrawn.
5.3. Each message contains an “Unsubscribe” link.
5.4. Consent may also be withdrawn by contacting: info@soulpath.pl
5.5. Data may be transferred to the chosen email marketing provider.
5.6. Newsletter performance (opens, clicks) is analyzed for statistics and improvement.
6. DATA RECIPIENTS
The Administrator may share data with:
- LH.pl – hosting and email services
- Stripe – payment processor
- Calendly – appointment scheduling
- Microsoft Bookings – appointment scheduling
- Accounting and advisory providers
- IT and technical support services
- Email marketing tool provider (to be selected)
Each recipient processes data under a GDPR‑compliant Data Processing Agreement.
7. INTERNATIONAL DATA TRANSFERS
Some providers (e.g., Stripe, Calendly, Microsoft) may process data outside the EEA (e.g., in the USA).
Such transfers take place based on:
- Standard Contractual Clauses (SCC),
- additional security measures,
- data processing agreements.
8. DATA RETENTION PERIODS
- Contact form/message data: 12 months
- Service‑related data: duration of cooperation + 6 years (limitation period)
- Newsletter data: until consent is withdrawn
- Accounting records: 5 years (as required by law)
- Cookies: according to type (typically 14–26 months)
9. USER RIGHTS
Users have the right to:
- access their personal data,
- correct or update data,
- delete data (“right to be forgotten”),
- restrict processing,
- object to processing,
- transfer data,
- withdraw consent at any time.
Requests can be sent to: info@soulpath.pl
Users may lodge a complaint with:
President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00‑193 Warsaw, Poland.
10. PROFILING
Soul Path does not make decisions based solely on automated processing.
Marketing profiling (e.g., personalized ads) may occur only after the User gives consent for marketing cookies.
11. COOKIES
11.1. The website uses the following types of cookies:
- Essential cookies – required for website operation (no consent needed)
- Analytical cookies – require consent
- Marketing cookies – require consent
11.2. Consent may be withdrawn at any time via the cookie banner.
11.3. Cookie preferences may also be managed through the User’s browser.
12. DATA SECURITY
The Administrator applies appropriate technical and organizational safeguards, including:
- SSL encryption
- Secure server infrastructure
- Access control
- Regular updates and monitoring
In the event of a data breach, Users will be notified in accordance with GDPR.
13. AGE RESTRICTION
All services under the brand Soul Path are intended only for individuals aged 18 or older.
No data from minors is knowingly collected.
14. CHANGES TO THIS POLICY
The Administrator may update this Policy from time to time.
The updated version will include a new “Last Updated” date.
15. CONTACT
For any questions regarding personal data, please contact:
📩 info@soulpath.pl
