Privacy Policy
Last Updated: July 31, 2026
This explains what we do with your personal data, why, how long we keep it, and what you can make us do about it. It's written to be readable rather than impressive. If anything here is unclear, email us and we'll explain it properly.
The short version: we collect very little, we don't track you, and there is nothing here you need to consent to.
Who we are
Effexora Academy is run by Cezary Wieczorek and Anna Góra. We are the joint data controllers for everything described here.
Contact for anything privacy-related: contact@effexora.com
We don't have a Data Protection Officer. We're not required to have one, and at our size it would be theatre. Write to the address above and you reach us directly.
We don't track you
This site runs no analytics, no advertising pixels, and no tracking cookies. There is no Google Analytics, no Meta Pixel, no advertising network, and nothing that follows you to other websites. We don't build profiles, we don't score visitors, and we make no automated decisions about anyone.
That's why there's no cookie consent banner. There is nothing to consent to.
The only cookies this site sets are the ones it cannot function without: keeping your shopping bag between pages, and carrying you through checkout securely. Under EU rules these are strictly necessary cookies and don't require consent. If you block them in your browser, checkout will stop working.
Our payment provider sets its own cookies during checkout, purely for fraud prevention and to process the payment. That's covered below.
What we collect, why, and on what basis
When you buy something
What: your name, email address, billing country, payment confirmation, what you ordered and when, and anything you write in the order comments field.
Why: to take the order, send you what you bought, handle refunds, and keep the records the law requires us to keep.
Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for the financial records.
How long: order and financial records for 5 years from the end of the calendar year in which the relevant tax deadline fell, as Polish law requires. Then deleted.
We never see or store your card number. It goes directly to our payment provider and never touches our systems.
When you book a session
What: the above, plus your scheduling preferences, time zone, and anything you choose to tell us in advance.
Why: to hold the appointment and prepare for it.
Legal basis: performance of our contract with you.
How long: the financial record as above. Anything personal you shared in preparation is deleted within 12 months of the session, unless you ask us to keep it for continuity between sessions.
When you subscribe to our emails
What: your email address and the date you subscribed.
Why: to send you news about new attunements, writings and offers.
Legal basis: your consent (Art. 6(1)(a)). You can withdraw it at any time, with no consequence, using the unsubscribe link in any email or by writing to us.
How long: until you unsubscribe, plus a minimal record that you did, so we don't accidentally add you back.
When you email us
What: whatever is in the email.
Why: to answer you.
Legal basis: performance of a contract, or our legitimate interest in replying to people who write to us (Art. 6(1)(f)).
How long: 3 years, then deleted, unless the thread forms part of an order record.
When you just visit
Our host keeps standard server logs - IP address, browser type, pages requested, timestamps. These exist to keep the site running and to detect abuse or attacks.
Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f)).
How long: per our host's standard log retention. We don't extract, analyse, or store this data ourselves.
What we never do
We don't sell your data. We don't share it with advertisers or list brokers. We don't profile you. We don't use your data to train anything.
Who else handles your data
A short list. Each processes data on our instructions, under contract.
Hostinger - website hosting and the online store platform.
Stripe - card payments and payment security. Stripe is a separate controller for the payment itself and has its own privacy policy.
PayPal - where you choose to pay by PayPal. Also a separate controller for the payment.
[TO FILL IN] Add whoever actually sends your order confirmations and newsletters, if it isn't Hostinger.
That's the whole list. If it grows, this page changes.
We will also disclose data where the law compels us to - a court order, a tax audit, a valid request from an authority. We'd tell you if that happened, unless legally prohibited from doing so.
Data leaving the EU
Stripe and PayPal both operate internationally, so some payment data is processed outside the European Economic Area. Those transfers are covered by the safeguards GDPR permits - an adequacy decision, or Standard Contractual Clauses - which both providers maintain and publish.
You can ask us which safeguard applies to a specific transfer and we'll point you to it.
Nothing else we do moves your data outside the EEA.
Your rights
If you're in the EU or UK, you have all of these. Using them is free, and we'll respond within one month.
Access - ask what we hold about you, and get a copy.
Rectification - make us correct anything wrong.
Erasure - make us delete it. We can't delete records the law requires us to keep, but we'll delete everything else and tell you exactly what remains and why.
Restriction - make us stop processing while something is disputed.
Portability - get your data in a machine-readable format.
Objection - object to anything based on legitimate interest. For marketing, objection is absolute: say stop and we stop.
Withdraw consent - at any time, for anything based on consent. Withdrawing doesn't undo what was lawful before.
To use any of these: contact@effexora.com. We won't ask you to justify the request.
If we get it wrong
You can complain to a supervisory authority. In Poland that is:
Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa uodo.gov.pl
If you live elsewhere in the EU, you can complain to your own national authority instead.
We'd rather you came to us first, but you're not obliged to, and it makes no difference to your right to go to them.
Security
Your data sits on our providers' servers, encrypted in transit. Access is limited to the two of us, with strong authentication on the accounts that hold it.
We're a two-person operation, not a bank, and we won't claim security we don't have. No internet transmission is completely secure. What we can honestly say is that we collect very little, keep it briefly, and don't move it around.
If a breach happened that put your rights at risk, we'd notify UODO within 72 hours and tell you directly.
Age
This site is for adults. We don't knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us and we'll delete it.
Links elsewhere
We link to other sites. Once you're there, their privacy policy applies, not ours.
Changes to this policy
If we change this, the date at the top changes. For anything material - a new processor, a new purpose, a new category of data, or if we ever add analytics - we'll say so plainly rather than quietly editing.
Questions, requests, or complaints: contact@effexora.com

