Back to home
GDPR / RODO

Privacy Policy

Last updated: 2026-01-15

This Privacy Policy explains how EducaGrade sp. z o.o. collects, uses and protects personal data when you visit educagrade.com or use the EducaGrade platform. It is issued in accordance with Regulation (EU) 2016/679 (GDPR / RODO) and Polish data protection law.

1. Data controller

The controller of your personal data is EducaGrade sp. z o.o., ul. Prosta 51, 00-838 Warszawa, Polska, registered under KRS 0000876543, NIP 5252891234. The company is represented by Katarzyna Sonnwald, CEO & Managing Director.

For educational institutions using EducaGrade, the institution acts as controller of student data and EducaGrade acts as processor under a Data Processing Agreement. You can reach us at privacy@educagrade.com.

2. Data Protection Officer

We have appointed a Data Protection Officer who supervises all processing activities and is your first point of contact for privacy questions: dpo@educagrade.com or by post at the registered address above, marked "DPO".

3. Categories of data we process

We limit collection to what each purpose requires:

  • Account data: name, work email, institution, role, password hash.
  • Academic data processed on behalf of institutions: assignments, rubric scores, grades, feedback, moderation history.
  • Billing data: company name, tax identifiers, invoice address, payment references (card data is handled by our payment provider).
  • Technical data: IP address, device and browser type, pages visited, security and audit logs.
  • Support data: messages and attachments you send to our team.

4. Purposes and legal bases

Each processing activity has a defined legal basis under Article 6 GDPR:

  • Providing the platform and fulfilling our contract — Art. 6(1)(b).
  • Legal and accounting obligations, including invoice retention — Art. 6(1)(c).
  • Security, abuse prevention, service improvement and legitimate business interests — Art. 6(1)(f).
  • Analytics and marketing cookies, newsletters and demo requests — your consent, Art. 6(1)(a), withdrawable at any time.

5. Retention

Account data is retained for the life of the contract and deleted or anonymised within 90 days of termination, unless a longer statutory period applies. Invoicing records are kept for five years as required by Polish tax law. Security logs are kept for 12 months. Academic records processed for an institution are retained according to that institution's instructions.

6. Recipients and transfers

We share data only with vetted processors: EU-based cloud hosting, email delivery, payment processing, error monitoring and customer support tooling. Each processor is bound by a data processing agreement.

Production data is stored within the European Union. Where an exceptional transfer outside the EEA is necessary, it relies on an adequacy decision or the European Commission's Standard Contractual Clauses together with supplementary technical measures.

7. Your rights

Under the GDPR you may exercise the following rights free of charge:

  • Access a copy of your personal data (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erasure — the right to be forgotten (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability in a structured, machine-readable format (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3)).

8. Complaints

We answer requests within 30 days. If you believe your data is handled unlawfully you may lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, or with the authority of your EU country of residence.

9. Security and data handling standards

We apply encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, least-privilege administration, mandatory two-factor authentication for staff, segregated production environments, continuous backups with tested restores, and full audit logging of every grade change. Personal data breaches are assessed immediately and reported to the supervisory authority within 72 hours where required, and to affected institutions without undue delay.

10. Minors

EducaGrade is licensed to institutions, not to children directly. Where a school processes data of pupils under 16, the school is responsible for the legal basis and for parental information, and EducaGrade processes such data solely on documented instructions.

11. Changes to this policy

We publish any material change on this page and notify account administrators by email at least 14 days before it takes effect.