Privacy Policy
Effective from: June 1, 2026
This Privacy Policy describes how Cerium (IT Maciej Bodnar, ul. Deszczowa 9, 03-673 Warszawa, NIP: 5243050733) processes your personal data. This is a courtesy translation - the Polish version is legally binding.
1. Data controller
The controller of your personal data is IT Maciej Bodnar based in ul. Deszczowa 9, 03-673 Warszawa, NIP: 5243050733, REGON: 542769287.
GDPR contact: [email protected] (fire-gem is the Provider's own brand - the same entity).
If you use Cerium as a school's software - the school is a separate controller of its students/parents/teachers data, and Cerium acts as a processor. We conclude a Data Processing Agreement (DPA) with every school upon contract signing - available on request: [email protected].
2. What data we collect
Account data: first/last name, email, password (bcrypt-hashed), role in organization.
School data: name, VAT ID, address, billing details.
Operational data: lessons, grades, attendance, notes, invoices, messages, materials - entered by Users.
Technical data: IP address, session ID, browser type, login timestamp (stored in login_audit_logs for 90 days - for account security).
Payment data: handled exclusively by Stripe Payments Europe Ltd. - Cerium does not store card numbers.
Cookies: see section 8.
3. Purposes and legal bases
Service provision (art. 6(1)(b) GDPR - contract performance): account, lessons, invoices, communication.
Security (art. 6(1)(f) GDPR - legitimate interest): login logs, abuse monitoring.
Own marketing (art. 6(1)(f) GDPR): existing Users only, regarding service improvements. You may object at any time.
Newsletter (art. 6(1)(a) GDPR): only after explicit consent. Consent revocable at any time.
Legal obligations (art. 6(1)(c) GDPR): accounting, taxes, KSeF.
Providing data is voluntary but necessary to conclude and perform the contract (without it we cannot create an account or issue an invoice).
We make no automated decisions producing legal effects and do not profile users.
4. Retention
Account data: contract duration + 90 days after termination (archive), then permanent deletion.
Invoices and accounting data: 5 years, counted from the start of the year following the year they concern (Polish Accounting Act, Tax Ordinance).
Login logs (IP, user-agent): 90 days, then auto-deleted.
Complaint data: up to 3 years (statutory limitation).
Database backups: rotation up to 30 days.
5. Recipients (processors)
Stripe Payments Europe Ltd. (Ireland) - card payments; transfer outside EEA to Stripe Inc. (USA) under Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF).
Hetzner Online GmbH (Germany) - hosting of files (S3) and the Jitsi server (video lessons); Cerium's main application server runs on the Provider's own infrastructure in Poland. No transfer outside the EEA.
Zoho Corporation (ZeptoMail, EU) - transactional email. No transfer outside EEA.
Cloudflare, Inc. (USA) - CDN and Cloudflare Tunnel (HTTPS proxy). Transfer outside EEA under SCC and DPF.
Google Ireland Ltd. / Google LLC (USA) - Google Analytics and Google Tag Manager (marketing-site visit statistics); loaded only after consent to analytics cookies. Transfer outside EEA under DPF.
Meta Platforms Ireland Ltd. (Ireland) - Meta Pixel (measuring Facebook and Instagram ad performance on the marketing site); loaded only after consent to marketing cookies. Transfer outside EEA to Meta Platforms, Inc. (USA) under Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF).
6. Your rights
Right of access (art. 15 GDPR).
Right to rectification (art. 16 GDPR).
Right to erasure (art. 17 GDPR) - except data we must retain by law (e.g., invoices).
Right to restriction (art. 18 GDPR).
Right to data portability (art. 20 GDPR).
Right to object (art. 21 GDPR) - for processing based on legitimate interest.
Right to withdraw consent at any time (art. 7(3) GDPR).
Right to lodge a complaint with the Polish DPA (https://uodo.gov.pl).
7. How to exercise rights
Email [email protected] with your request.
We respond within 30 days - extended to 90 days in exceptional cases (with notice).
Free of charge - except for unfounded or excessive requests (we may charge a reasonable administrative fee).
9. Security
Passwords hashed with bcrypt (10 rounds).
HTTPS (TLS 1.3) on all endpoints.
Rate limiting on critical endpoints (login, contact, support, chat).
Tenant isolation at the SQL query level (tenantId filtering).
Daily database backups with 30-day rotation.
Breach monitoring (login_audit_logs, limit_events).
10. Contact
Privacy matters: write to [email protected].
Mailing address: IT Maciej Bodnar, ul. Deszczowa 9, 03-673 Warszawa.
Full Policy effective from June 1, 2026.