Privacy Policy
1. Who we are
This Privacy Policy describes how PRECANACOURSE Spółka z ograniczoną odpowiedzialnością (operating as PRECANACOURSE sp. z o.o.; "we", "our", "us") collects, uses, and protects your personal data when you use the Pre-Cana Course platform.
Our website: www.precanacourse.com
Registered address: ul. Oleśnicka 16/1, 50-320 Wrocław, Poland
Company identifiers: NIP 8982334303 · KRS 0001243785 · REGON 544857191
Contact: [email protected]
Data Controller: PRECANACOURSE sp. z o.o., ul. Oleśnicka 16/1, 50-320 Wrocław, Poland.
2. Data we collect
2.1 Account data
- Email address (required for account creation)
- First and last name (required)
- Partner's first and last name (optional)
- Wedding date (optional)
- Parish name and officiant (optional)
2.2 Special category data (GDPR Art. 9)
By signing up for our pre-marriage course, you implicitly disclose information about your religious beliefs (Catholic faith).
Additionally, during course exercises you may voluntarily share:
- Reflections on your relationship
- Information about your sexual life and intimacy
- Mental health and emotional state observations
- Family and parenting plans
- Financial planning details
- Religious practices and beliefs
By accepting our Terms of Service at registration, you give your explicit and informed consent (GDPR Art. 9(2)(a)) to the processing of this special category data for the sole purpose of providing the course, generating AI feedback on your reflection answers, and tracking your progress. Acceptance is bundled into Terms acceptance to avoid form friction; the substance of the consent (what is processed, by whom, for what purpose) is fully described in this Privacy Policy and in Terms §8a.
You can withdraw this consent at any time by deleting your account via My Account → Data Privacy. Withdrawal stops further processing but does not invalidate processing performed before withdrawal.
2.3 Usage data
- Course progress (which modules/sections completed)
- Exercise answers and AI-generated feedback
- Time spent on lessons (videos watched, audio played)
- Browser type, IP address (hashed for audit purposes only)
2.4 Payment data
Payment processing is handled by Stripe. We do not store your full card number. We store only:
- Order number
- Order amount and currency
- Billing address (for invoicing)
- Stripe transaction ID (for refunds)
2.5 Referral data (if you arrived through a partner)
Some visitors reach us through a link shared by one of our program partners — a priest, a marriage-preparation coordinator, or a past student who recommends the course. If you arrived that way and accepted marketing cookies, we record which partner referred you:
- the partner's referral code, stored in a cookie named
precana_reffor 90 days; - if you then create an account or sign in, a permanent note on your account of which partner referred you;
- on your order, the partner credited with it.
The partner never learns who you are. Their panel shows counts and totals only — never your name, e-mail address, order details, or anything you write inside the course. This is a deliberate design decision, not a setting, and we cannot switch it on for a partner who asks.
We use this record for one purpose only: to calculate and pay the commission owed to that partner, and to keep the accounting records that supports. It is not used to profile you and it is not shared with anyone else. See also §9 and our Cookie Policy.
2.6 Partner data (only if you take part in our affiliate program)
This subsection applies only if we have enabled our invitation-only affiliate program on your account. It does not apply to ordinary course participants.
For partners we additionally process:
- Payout details — depending on the method chosen: bank account holder name, IBAN, SWIFT/BIC, bank name and country, and the holder's address; or a Revolut tag, phone number, or e-mail; or a PayPal e-mail address.
- Country of tax residence, whether you act as a private individual or through a business, any business or tax identification number, and any tax-residence documents you provide (see Affiliate Program Terms §11).
- Commission and payout records — amounts, currencies, dates, and payment references.
- Aggregate performance figures — daily click and enrolment counts for your referral link. We store these as daily totals only, without IP addresses or browser fingerprints of the people who clicked.
Payout details are treated as financial data: they are encrypted at rest (§8), are never returned to your browser in full — the panel shows a masked form such as IBAN ****1234 — and are readable in unmasked form only by administrators who need them to execute a payment.
3. Legal basis for processing
We process your data under the following legal bases (GDPR Art. 6 and 9):
- Performance of a contract (Art. 6(1)(b)) — to provide you with access to the course you purchased.
- Explicit consent for special category data (Art. 9(2)(a)) — for processing of reflection answers that may reveal religious beliefs, relationship details, sexual life, or other special category data. This consent is given by accepting our Terms of Service at registration; Terms §8a describes the substance of the consent in plain language. You can withdraw consent at any time by deleting your account in My Account.
- Consent (Art. 6(1)(a)) — for marketing emails. Opt-in, non-required.
- Legal obligation (Art. 6(1)(c)) — for invoicing data, retained for tax purposes for 5 years following the end of the calendar year in which the tax obligation arose (Polish Tax Ordinance Art. 86 §1).
- Legitimate interests (Art. 6(1)(f)) — for security and fraud prevention (IP hash, login attempt tracking).
- Consent (Art. 6(1)(a)) — for the referral cookie described in §2.5. It is classified as a marketing cookie, so it is set only if you accept marketing cookies. Refusing costs you nothing: any partner discount still applies to your order.
- Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) — for the partner data in §2.6. We need payout and tax-residence details to perform the affiliate agreement, and we are required to keep records of payments made under Polish accounting and tax law.
Clergy review-access requests are processed under Art. 9(2)(e) ("data manifestly made public by the data subject") — clergy disclose their role voluntarily to obtain verification, and their role is typically public via diocesan registers. Data is used solely for verification and deleted after the review decision plus a short audit window.
4. How we use your data
- To provide the pre-marriage course content (videos, audio, scriptures, exercises)
- To generate AI-powered feedback on your reflection answers (via OpenAI)
- To track your progress and issue completion certificates
- To send transactional emails (welcome, password reset, completion)
- To send marketing emails (only with your explicit consent)
- To improve our course content (anonymized analytics)
- To comply with legal obligations (invoicing, tax)
5a. International data transfers
Some of our processors are established in, or transfer personal data to, the United States. We rely on two complementary legal bases for these transfers:
- The EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF — adequacy decisions of the European Commission under Article 45 GDPR, applicable where the receiving processor is actively certified to the relevant DPF.
- The European Commission's Standard Contractual Clauses 2021/914 ("SCCs") under Article 46(2)(c) GDPR, with supplementary measures, applicable where DPF certification does not cover the transfer or as an automatic fallback in our processors' Data Processing Agreements.
| Processor | Role | Location / EU contracting entity | Transfer mechanism |
|---|---|---|---|
| OpenAI, Inc. | AI feedback on exercises | EEA users contract with OpenAI Ireland Ltd; intra-group onward transfer to OpenAI, Inc. (US) | EU SCCs 2021/914 Module 3 + supplementary measures (no personal identifiers sent to API, no training on API data per DPA, AES-256-GCM encryption at rest) |
| Stripe, Inc. | Card, Apple Pay & Google Pay processing | EEA users contract with Stripe Payments Europe, Ltd. (Ireland); intra-group onward transfer to Stripe, Inc. (US) | EU-U.S. DPF (Art. 45 GDPR); EU SCCs as automatic fallback under Stripe's Data Transfers Addendum |
| PayPal | PayPal payment processing | EEA/UK users contract with PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg); onward transfer to PayPal, Inc. (US) for group functions | EU SCCs 2021/914 under PayPal's Data Protection Addendum; PayPal (Europe) is the primary controller for EEA/UK payments |
| Cloudflare, Inc. | CDN, WAF, DDoS protection, Turnstile CAPTCHA, analytics traffic routing | Direct EEA → US | EU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Cloudflare's DPA |
| Google LLC | Analytics & advertising (loaded only after cookie consent) | Direct EEA → US | EU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Google Ads Data Processing Terms |
| Google LLC | reCAPTCHA v3 — checkout bot/fraud protection (loads independently of cookie consent) | Direct EEA → US | EU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Google's Data Processing Terms |
| PostHog, Inc. | Product analytics, heatmaps and session replay (loaded only after cookie consent; not loaded in the course area) | PostHog Cloud EU — data stored in Frankfurt, Germany (AWS eu-central-1). The processor entity is PostHog, Inc. (US), which may access the data from outside the EEA for support and operations | EU-U.S. DPF, UK Extension and Swiss-U.S. DPF (Art. 45 GDPR), which PostHog confirms it participates in; EU SCCs 2021/914 with the UK Addendum incorporated in the same DPA as fallback |
| Brevo SAS | Transactional & marketing email | France (EU) | No EU → US transfer for primary processing; any onward sub-processor transfers covered by SCCs in Brevo's DPA |
| Hostinger International, Ltd. | Hosting (database, files) | Lithuania (EU data center) | No EU → US transfer |
US government access notice. US law (notably Section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12333) may, in defined circumstances, permit US public authorities to request access to data processed by US-based providers. The EU-U.S. DPF was adopted by the European Commission on 10 July 2023 after the US established, via Executive Order 14086, additional safeguards including binding limits on signals intelligence and a two-layer independent redress mechanism — including the Data Protection Review Court (DPRC) — which EU/UK/Swiss residents can use without cost via their national data protection authority. Where transfers rely on EU SCCs, we apply supplementary measures (encryption in transit and at rest, access controls, data minimization).
You can request a copy of the SCCs or further information about our transfer safeguards by emailing [email protected].
6. Your rights (GDPR Chapter 3)
You have the following rights regarding your personal data:
- Right of access (Art. 15) — download all your data as JSON. Available at My Account → Data Privacy → Download My Data.
- Right to rectification (Art. 16) — correct inaccurate data via My Account → Profile.
- Right to erasure (Art. 17) — delete your account and data. Available at My Account → Data Privacy → Delete My Account. 30-day grace period (you can cancel deletion within 30 days). Invoicing data is retained for the legal obligation period (5-7 years per local tax law) but anonymized.
- Right to data portability (Art. 20) — machine-readable JSON export (same as Right of access).
- Right to restrict processing (Art. 18) — contact [email protected].
- Right to object (Art. 21) — withdraw consent for marketing emails at My Account → Profile → Unsubscribe.
- Right to lodge a complaint — with your local supervisory authority (ICO in UK, UODO in Poland, CNIL in France, etc.).
United Kingdom users. If you reside in the United Kingdom, your personal data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Your rights under UK GDPR are equivalent to those described above for EU users. You have the right to lodge a complaint with the United Kingdom Information Commissioner's Office (ICO) at ico.org.uk/concerns.
7. Data retention
- Course data (exercises, progress, AI feedback): retained while your account is active + 2 years after course completion. After 2 years, you receive an email asking whether to keep or delete the data.
- Account data (profile, email): retained while account is active. Deleted within 30 days of account deletion request.
- Invoicing data: retained for 5 years from the end of the calendar year in which the tax obligation arose, as required by Polish Tax Ordinance Art. 86 §1. Anonymized after account deletion.
- Marketing data: retained until you unsubscribe.
- Audit logs (IP hash, login attempts): retained 6 months for security purposes, then automatically deleted.
- Referral record (§2.5): the
precana_refcookie expires after 90 days. The note of which partner referred you is deleted together with your account; the attribution stored on an order follows the retention of the order itself. - Partner payout details (§2.6): deleted when you delete your account or leave the affiliate program. Records of payments already made to you are retained for 5 years from the end of the calendar year in which they were made, as required by Polish accounting and tax law — we cannot delete these on request, but they are limited to what the law requires (amount, date, currency, recipient, reference).
8. Security
We use industry-standard security measures (GDPR Art. 32):
- HTTPS (TLS 1.3) for all data in transit
- AES-256-GCM encryption-at-rest for sensitive user data (reflection answers, partner names, religious data)
- Bcrypt password hashing
- Two-factor authentication (2FA) available for accounts
- Rate limiting and brute-force protection
- WAF (Web Application Firewall) via Cloudflare
- Bot protection via Cloudflare Turnstile (public forms & sign-in) and Google reCAPTCHA v3 (checkout payment fraud-prevention)
- Daily malware scans
- Regular security audits
In the event of a data breach affecting your personal data, we will notify you within 72 hours per GDPR Art. 33-34, unless the data was encrypted (in which case notification may not be required).
10. Children
Our Service is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. For residents of California (CCPA/CPRA) and Delaware (DPDPA), we do not knowingly sell or share personal information of any user under 16. If we learn that we have inadvertently collected personal information from a minor, we will delete it without undue delay. If you believe a minor has provided us with personal data, please contact us at [email protected].
11. US Residents — Additional Disclosures
This section provides additional information for US residents. It applies in addition to the rest of this Privacy Policy. We provide it as a single integrated section (rather than a separate "US Privacy Notice") for clarity. We are not currently subject to the threshold requirements of the California Consumer Privacy Act (CCPA/CPRA) or other US state privacy statutes, but we offer the disclosures and rights below voluntarily.
11.1 We do not sell or share your personal information
We do not "sell" or "share" your personal information as those terms are defined by the CCPA/CPRA, including for cross-context behavioral advertising. We have not done so in the preceding 12 months and have no plans to do so. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required, and none is provided.
11.2 Categories of personal information collected
In the preceding 12 months we have collected the following categories of personal information from US residents. None of the categories below have been sold or shared.
| CCPA category | Examples relevant to our Service | Collected? | Source |
|---|---|---|---|
| A. Identifiers | Name, email, account ID, hashed IP | Yes | You; security logs |
| B. Customer records (Cal. Civ. Code §1798.80(e)) | Billing address, order history, partner name (optional); for affiliate program participants only: payout account details, stored encrypted (§2.6) | Yes | You; Stripe |
| C. Protected classifications | Religious beliefs (implied by Catholic course enrollment) | Yes | You |
| D. Commercial information | Purchase records, refund history | Yes | You; Stripe |
| E. Biometric information | — | No | — |
| F. Internet / network activity | Login timestamps, course progress, exercise interactions, referring partner code if you arrived through a partner link (§2.5) | Yes | You; our servers |
| G. Geolocation | Country only (derived from IP for compliance / fraud detection) | Yes (country-level) | Our servers; Cloudflare |
| H. Sensory / audio-visual | — | No | — |
| I. Professional / employment | Role-related information for clergy verification requests only | Yes (clergy only) | You (clergy form) |
| J. Education information | — | No | — |
| K. Inferences | AI-generated feedback drawn from your reflection answers | Yes | OpenAI (processor) |
Purposes: providing the course, generating AI feedback, processing payments, issuing certificates, transactional and (with consent) marketing email, security, legal compliance. Retention: as described in §7. Disclosure recipients: only the processors listed in §5; never sold; never shared for cross-context behavioral advertising.
11.3 Your rights as a US resident
Although we are not currently subject to the threshold requirements of US state privacy laws, we voluntarily extend the following rights to all US residents:
- Right to know what personal information we have collected, used, disclosed, and (if applicable) sold or shared.
- Right to delete personal information we have collected from you, subject to lawful exceptions (e.g., tax retention).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — not applicable, as we do not sell or share.
- Right to limit the use of sensitive personal information to purposes necessary to provide the Service.
- Right to non-discrimination for exercising any of these rights.
- Right to use an authorized agent (residents of CA, CT, CO, DE) — we will require verification.
- Right to appeal a denial of a privacy request (residents of VA, CO, CT).
How to exercise these rights. All rights above are implemented through the same mechanisms used to satisfy our GDPR obligations — a machine-readable JSON export of your data, a self-service account deletion flow with a 30-day grace period, and email-based correction and appeal handling. See §6 for in-product links, or use the contact addresses in §11.5.
11.4 State-specific notes
California (CCPA/CPRA). We will respond to verifiable consumer requests within 45 days (extendable by an additional 45 days where reasonably necessary, with notice). Requests may be submitted by an authorized agent with appropriate written authorization. The California "Shine the Light" law (Cal. Civ. Code §1798.83) does not apply because we do not disclose personal information to third parties for their direct marketing.
Nevada (NRS 603A). Although we do not sell personal information, Nevada residents may direct us not to sell their covered information by emailing [email protected] with the subject line "Nevada Opt-Out".
Virginia-model states (VCDPA, CPA, CTDPA, UCPA, OCPA, MCDPA, ICDPA, TIPA, FDBR, DPDPA, NHDPA, NJDPA, MODPA, MNCDPA, RIDTPPA, KCDPA, MN). We honor the rights of access, deletion, correction, and (where applicable) opt-out and appeal as outlined in §11.3. Residents of these states may submit requests as described in §11.5.
Illinois Biometric Information Privacy Act (BIPA). We do not collect, capture, purchase, receive through trade, or otherwise obtain any biometric identifiers or biometric information as defined by 740 ILCS 14/.
New York SHIELD Act. We maintain a written information security program with reasonable administrative, technical, and physical safeguards (see §8) that meet or exceed the requirements of N.Y. Gen. Bus. Law §899-bb for personal information of New York residents.
11.5 Contact for US privacy requests
Email [email protected] using one of the following subject lines so we can route your request correctly:
- "California Privacy Request" — for CCPA/CPRA rights.
- "Nevada Opt-Out" — for NRS 603A opt-out direction.
- "Privacy Appeal" — to appeal a denied privacy request.
- For all other US state privacy rights, use a subject line that identifies your state.
We respond to verifiable US privacy requests within 45 days where state law requires it.
12. Policy updates
We may update this Privacy Policy from time to time. We will notify you via email of any material changes. If the changes require new consent, we will ask you to re-consent at next login. Continued use after notification constitutes acceptance.
13. Contact us
For any privacy-related questions, requests, or complaints:
Email: [email protected]
Postal: PRECANACOURSE sp. z o.o., ul. Oleśnicka 16/1, 50-320 Wrocław, Poland
Data Controller: PRECANACOURSE Spółka z ograniczoną odpowiedzialnością (NIP 8982334303, KRS 0001243785).
If we don't respond within 30 days, you can lodge a complaint with the Polish data protection authority (UODO, uodo.gov.pl) or with the supervisory authority of your country of residence.