Joanna HryniewiczCoaching
About
Coaching↓
All about coaching →1:1 CoachingICF & how I workEnneagram CoachingLeadership CoachingTeam CoachingCoaching Through Change
Beyond coachingBlogBook a session
🇵🇱PL🇬🇧EN
About
Coaching↓
All about coaching →1:1 CoachingICF & how I workEnneagram CoachingLeadership CoachingTeam CoachingCoaching Through Change
Beyond coachingBlogBook a session
🇵🇱PL🇬🇧EN

PRIVACY

Privacy Policy

Last updated: 10 August 2026

This policy explains what personal data may be processed when you use the Beyond Data Coach website, contact form, booking system and paid services.

1. Data Controller

The controller of personal data is:

ABC Joanna Hryniewicz - AI, BI, Consultingbusiness address: Biskupa M. Jaworskiego 26/8, 25-430 Kielce, woj. świętokrzyskie, PolskaPolish tax ID (NIP): 8512923433REGON: 386172035email: analizybusinessintelligence@gmail.comphone: +48 511 434 283

referred to below as the “Controller”.

For privacy matters, contact the Controller at analizybusinessintelligence@gmail.com.

2. Scope of this Policy

This Policy covers personal data processed in connection with:

  • use of the Website,
  • contact-form enquiries,
  • booking through Cal.com,
  • purchase and delivery of paid sessions or packages,
  • payments, accounting documents and correspondence,
  • individually quoted services.

3. Personal data that may be processed

Depending on how you use the Website, this may include:

  • your name,
  • email address and optional phone number,
  • enquiry topic, preferred contact time and message content,
  • booking data, including the selected Service, meeting date and time,
  • payment information such as payment status, amount, currency and transaction identifier; the Controller generally does not need full payment-card data,
  • invoicing and accounting information where relevant,
  • technical data generated when using the Website or external services, such as IP address, device and browser information, security logs and error data.

Providing data through the contact form is voluntary, but required fields are necessary to submit the enquiry. Providing a phone number is optional.

4. Purposes and legal bases

PurposeLegal basis
Handling an enquiry about a specific service or possible collaboration and taking steps before entering into a contractArticle 6(1)(b) GDPR
Handling other correspondence not directly aimed at forming a contractArticle 6(1)(f) GDPR — legitimate interest in managing correspondence and responding
Booking, entering into and performing a Service contractArticle 6(1)(b) GDPR
Payments, invoices and compliance with legal obligationsArticle 6(1)(c) GDPR
Establishing, exercising or defending legal claimsArticle 6(1)(f) GDPR
Website security, abuse and spam prevention, diagnosticsArticle 6(1)(f) GDPR
Non-essential cookies or similar technologies, where usedconsent — Article 6(1)(a) GDPR together with applicable Polish Electronic Communications Law requirements

5. Contact form and Netlify Forms

The contact form is handled using Netlify Forms. Data submitted through it is processed to deliver the message to the Controller and handle the enquiry.

Netlify Forms submissions may be automatically analysed for spam using anti-abuse mechanisms, including Akismet. This mechanism protects the form and is not used by the Controller to assess a person, their coaching situation, creditworthiness or suitability for a Service.

The Controller should periodically remove Netlify submissions for which the retention period described in this Policy has expired.

6. Bookings and paid services — Cal.com

The Website uses Cal.com to display availability and handle bookings. Booking data is therefore also processed using Cal.com infrastructure and providers supporting that service.

Where a booking requires payment, the payment may be handled by the payment provider shown in the booking flow. That provider may act as an independent controller for data needed to process the payment and meet its own legal obligations.

The Controller generally receives information required to confirm the payment and deliver the Service rather than full payment-instrument details.

7. Special-category personal data

The public contact form is not intended for special-category data, including health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, or information concerning sex life or sexual orientation.

Please do not include such information in an initial enquiry. If a specific engagement genuinely requires processing special-category data, the scope, purpose and appropriate legal basis should be established separately before that processing takes place.

8. Recipients of personal data

Personal data may be disclosed only to the extent necessary for the relevant purpose, including to:

  • hosting and website infrastructure providers, including Netlify,
  • form-processing and anti-spam providers,
  • Cal.com and providers supporting the booking service,
  • payment providers used for paid bookings,
  • email, calendar and video-conferencing providers,
  • accounting, legal or technical providers where necessary,
  • public authorities where disclosure is required by law.

Depending on the service and context, a provider may act as a processor on the Controller’s instructions or as an independent controller for processing determined by that provider and applicable law.

The Controller does not sell Website users’ personal data.

9. Transfers outside the EEA

Some technology providers used by the Website are established, or use infrastructure, outside the European Economic Area, including in the United States. Personal data may therefore be transferred outside the EEA.

Where such a transfer occurs, it should rely on a GDPR-compliant transfer mechanism appropriate to the provider and circumstances, for example a European Commission adequacy decision, including the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses with additional safeguards where required.

10. Retention

Enquiry data that does not lead to an engagement is generally retained for no longer than 12 months after the correspondence ends, unless earlier deletion is appropriate or continued retention is justified by legal claims or another lawful purpose.

Data connected with a contract and delivery of a Service is retained for the duration of the engagement and afterwards for periods resulting from tax, accounting and applicable limitation requirements.

Accounting and tax records are kept for the period required by applicable law. Data required for establishing, exercising or defending legal claims may be retained until the relevant limitation period expires.

Technical and security logs are retained for a period justified by security and diagnostic needs and by the relevant provider’s retention settings where the Controller cannot set a shorter period.

11. Your rights

Depending on the legal basis and circumstances, you may have the right to:

  • access your data and obtain a copy,
  • rectify inaccurate data,
  • request erasure,
  • restrict processing,
  • data portability where the relevant conditions are met,
  • object to processing based on Article 6(1)(f) GDPR,
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

Requests can be sent to analizybusinessintelligence@gmail.com. The Controller may request information reasonably necessary to verify the identity of the requester.

You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

12. Automated decisions, profiling and AI

The Controller does not use contact-form or booking data for solely automated decisions producing legal effects or similarly significantly affecting a user, and does not profile users for that purpose.

An automated spam filter may classify a submission as spam or legitimate. This classification is a Website-security measure and is not an assessment of the Client or a decision on eligibility for a paid Service.

As of the last update, the Website does not provide users with a chatbot or another AI system that directly converses with them on the Controller’s behalf. If such a system is introduced, users will receive the legally required information that they are interacting with AI, and this Policy will be updated where necessary.

If a particular service involves using an external AI system to process personal data for a new purpose or in a new scope, the Controller should first determine the appropriate legal basis, data minimisation, confidentiality, provider role and transfer safeguards and provide any information required by law.

13. Cookies and similar technologies

The Website may use technologies necessary for operation, security and functions explicitly requested by the user.

Where a technology stores information on, or accesses information already stored on, a user’s device and is not necessary for transmitting a communication or delivering a service requested by the user, prior information and consent are required in accordance with applicable Polish Electronic Communications Law.

External components, in particular the Cal.com booking system, may use cookies or similar technologies according to their configuration and policies. The Website implementation should block technologies requiring consent until that consent has been obtained.

14. LinkedIn and external links

The Website may contain ordinary links to external websites, for example a LinkedIn profile. A plain text link or locally stored icon is not an embedded social-media widget. Once the link is clicked, the external service processes data under its own rules.

15. Security

The Controller applies technical and organisational measures appropriate to the nature of the data and relevant risks, including limiting access to persons and providers who need it for their tasks and using secured connections and technology services.

No internet transmission can be guaranteed to be absolutely secure. Users should avoid submitting information through the public form that is not necessary for initial contact.

16. Changes to this Policy

This Policy may be updated in particular when Website functionality, processing practices, technology providers or applicable law change. The current version is published on this page together with the date of the latest update.

Joanna Hryniewicz

ABC — Awareness • Balance • Change

AboutCoachingBlogBook a session

© 2026 Joanna Hryniewicz. All rights reserved.

AI & transparency+

AI supported the process. Responsibility remains human.

AI tools were used as editorial and technical support in developing parts of this website and its code. They supported activities such as drafting, language refinement, content structuring and code development.

Final selection, editing, review and responsibility for the published content remain with Joanna Hryniewicz.

AI supports the process. It does not replace human judgement, responsibility or decision-making.

Beyond Data CoachABC Joanna Hryniewicz - AI, BI, Consulting
Privacy PolicyTermsLinkedIn

© 2026 Beyond Data Coach