Back
Legal document

Privacy Policy

Effective from: June 1, 2026

This Privacy Policy describes how Cerium (IT Maciej Bodnar, ul. Deszczowa 9, 03-673 Warszawa, NIP: 5243050733) processes your personal data. This is a courtesy translation - the Polish version is legally binding.

1. Data controller

The controller of your personal data is IT Maciej Bodnar based in ul. Deszczowa 9, 03-673 Warszawa, NIP: 5243050733, REGON: 542769287.

GDPR contact: [email protected] (fire-gem is the Provider's own brand - the same entity).

If you use Cerium as a school's software - the school is a separate controller of its students/parents/teachers data, and Cerium acts as a processor. We conclude a Data Processing Agreement (DPA) with every school upon contract signing - available on request: [email protected].

2. What data we collect

Account data: first/last name, email, password (bcrypt-hashed), role in organization.

School data: name, VAT ID, address, billing details.

Operational data: lessons, grades, attendance, notes, invoices, messages, materials - entered by Users.

Technical data: IP address, session ID, browser type, login timestamp (stored in login_audit_logs for 90 days - for account security).

Payment data: handled exclusively by Stripe Payments Europe Ltd. - Cerium does not store card numbers.

Cookies: see section 8.

4. Retention

Account data: contract duration + 90 days after termination (archive), then permanent deletion.

Invoices and accounting data: 5 years, counted from the start of the year following the year they concern (Polish Accounting Act, Tax Ordinance).

Login logs (IP, user-agent): 90 days, then auto-deleted.

Complaint data: up to 3 years (statutory limitation).

Database backups: rotation up to 30 days.

5. Recipients (processors)

Stripe Payments Europe Ltd. (Ireland) - card payments; transfer outside EEA to Stripe Inc. (USA) under Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF).

Hetzner Online GmbH (Germany) - hosting of files (S3) and the Jitsi server (video lessons); Cerium's main application server runs on the Provider's own infrastructure in Poland. No transfer outside the EEA.

Zoho Corporation (ZeptoMail, EU) - transactional email. No transfer outside EEA.

Cloudflare, Inc. (USA) - CDN and Cloudflare Tunnel (HTTPS proxy). Transfer outside EEA under SCC and DPF.

Google Ireland Ltd. / Google LLC (USA) - Google Analytics and Google Tag Manager (marketing-site visit statistics); loaded only after consent to analytics cookies. Transfer outside EEA under DPF.

Meta Platforms Ireland Ltd. (Ireland) - Meta Pixel (measuring Facebook and Instagram ad performance on the marketing site); loaded only after consent to marketing cookies. Transfer outside EEA to Meta Platforms, Inc. (USA) under Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF).

6. Your rights

Right of access (art. 15 GDPR).

Right to rectification (art. 16 GDPR).

Right to erasure (art. 17 GDPR) - except data we must retain by law (e.g., invoices).

Right to restriction (art. 18 GDPR).

Right to data portability (art. 20 GDPR).

Right to object (art. 21 GDPR) - for processing based on legitimate interest.

Right to withdraw consent at any time (art. 7(3) GDPR).

Right to lodge a complaint with the Polish DPA (https://uodo.gov.pl).

7. How to exercise rights

Email [email protected] with your request.

We respond within 30 days - extended to 90 days in exceptional cases (with notice).

Free of charge - except for unfounded or excessive requests (we may charge a reasonable administrative fee).

8. Cookies

Cerium uses cookies in three categories:

Essential cookies (always active): logged-in user session (next-auth), tenant switching (activeTenantId), cookie consent (cerium-cookie-consent).

Analytics cookies (optional, require consent): Google Analytics 4 loaded via Google Tag Manager - only after clicking "Accept all" in the cookie banner. Choosing "Essential only" means no analytics script runs.

Marketing cookies (optional, require consent): Meta Pixel (Facebook and Instagram) - measures how our ads perform and lets us show them to people who visited the site. Loaded only after clicking "Accept all". Choosing "Essential only" means the pixel never runs and no data reaches Meta.

You can change your decision at any time by clearing site data (cookies and local storage) in your browser settings - the banner will reappear.

9. Security

Passwords hashed with bcrypt (10 rounds).

HTTPS (TLS 1.3) on all endpoints.

Rate limiting on critical endpoints (login, contact, support, chat).

Tenant isolation at the SQL query level (tenantId filtering).

Daily database backups with 30-day rotation.

Breach monitoring (login_audit_logs, limit_events).

10. Contact

Privacy matters: write to [email protected].

Mailing address: IT Maciej Bodnar, ul. Deszczowa 9, 03-673 Warszawa.

Full Policy effective from June 1, 2026.