Privacy Policy
Last updated: April 9, 2026
1. Data Controller
Jakub Lasak Consulting
Aleja "Solidarnosci" 68/121, 00-240 Warszawa, Poland
NIP: 5214080890 | REGON: 529336199
Contact: hi@dataengineer.wiki
2. What Data We Collect
- Account data: email address (when you create an account via Supabase authentication)
- Usage data: pages visited, content progress (checkbox states), timestamps
- Purchase data: email address and product access records (when you purchase via Stripe)
- Subscription data: Substack subscription status and lifecycle events
- Error reports: technical error data including IP address (via Sentry)
- Analytics: anonymized usage patterns (via Google Analytics, only with your consent)
3. Legal Basis for Processing (GDPR Art. 6)
- Consent: Google Analytics cookies (you can accept or reject via our cookie banner)
- Contract performance: account creation, content delivery, purchase fulfillment
- Legitimate interest: error tracking (Sentry), service improvement, security
- Legal obligation: retention of purchase and tax records as required by Polish law
4. How We Use Your Data
- To provide and maintain the service
- To process purchases, send confirmation emails, and manage access to paid content
- To track your learning progress (checkboxes, page views)
- To diagnose and fix technical errors
- To analyze usage patterns and improve the service (with consent)
5. Data Processors (Sub-processors)
- Supabase (US/EU) - authentication, database, user data storage
- Stripe (US) - payment processing
- Google Analytics (US) - website analytics (consent-based)
- Sentry (US) - error tracking and monitoring
- Make.com (EU) - purchase fulfillment automation (email delivery, access provisioning)
- Resend (US) - transactional email delivery
- Cloudflare (US) - hosting, CDN, DDoS protection
- Substack (US) - newsletter and subscription management
6. Cookies and Local Storage
Essential (no consent required):
- Supabase session tokens (authentication)
- Cookie consent preference
Non-essential (consent required):
- Google Analytics cookies (_ga, _gid) - usage analytics
7. Data Retention
- Account data: retained until you delete your account
- Progress data: retained until you delete your account
- Purchase records: retained for 5 years (tax/legal obligations)
- Error reports: automatically deleted after 90 days
- Analytics data: aggregated and anonymized after 26 months
8. Your Rights Under GDPR
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise these rights, email hi@dataengineer.wiki.
You also have the right to lodge a complaint with the Polish supervisory authority:
Urzad Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa
https://uodo.gov.pl
9. Children's Privacy
Our service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us at hi@dataengineer.wiki and we will delete it promptly.
10. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
11. International Data Transfers
Some of our processors are based in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, and the processors' compliance with applicable data protection frameworks.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encrypted connections (HTTPS), access controls, and secure authentication.
13. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by posting a notice on our website. Continued use after changes constitutes acceptance.
14. Contact
For any questions about this privacy policy or your personal data:
Jakub Lasak Consulting
Email: hi@dataengineer.wiki