Ometek Academy Ometek Academy
Training starten → Bewerben
⬢ Ometek Academy

Privacy policy

Most of my students are minors, so privacy here is not a box to tick. This site has no analytics, no advertising, no social pixels, and does not load fonts from Google — every typeface is served from my own server precisely so that a student's browser does not hand its IP address to a third party on every page view.

Below is the complete list of what I actually collect. If something is not on it, I do not collect it.

Who the data controller is

The data controller is Kuba Ornatek, operating Ometek Academy as a sole coaching practice. There is no team, no support desk and no teaching subcontractors: the data is seen by one person, the same one who runs the lessons.

Contact on any data matter — including exercising the rights described below — goes through the contact form. I deliberately do not publish an email address or a phone number; the form reaches me directly and I reply from an address you can answer.

Data from the contact form

The contact form and the invite form store exactly the fields you can see in them:

  • your name and email address — so I can reply,
  • a phone number — optional, blank is fine,
  • your role (parent / student / teacher) and the message itself,
  • optionally: the student's first name, school year, goal (OI, OIJ, Logia, matura…) and level — only so my first reply can be specific instead of generic.

Account data and learning data

I create platform accounts myself — there is no open sign-up. A student account holds a username, a display name, an optional email address, a role, and a hashed password. I do not store the password and cannot read it.

On top of that sits the learning data: which problems were submitted and when, my review status, my written feedback on solutions, XP, rank, coins, the activity calendar and lesson attendance. This is the substance of the service — without it the platform has nothing to show a student or a parent.

A parent account is view-only and linked to the child's. A parent sees their own child's profile and activity calendar and nothing else — not the problem content, not other students, and they cannot submit anything on the child's behalf.

Data about minors

Most of my students are minors. I create a student account at the request of a parent or guardian, once we have agreed to work together — a child cannot open an account or book lessons on their own.

I collect the minimum: a first name (or initials, if the parent prefers), a school year, and what the student did with the problems. I do not collect a home address, a national ID number, school details, photographs, or anything else that learning algorithms does not require.

A parent can at any time ask to see their child's data, have it corrected, or have the account deleted.

Technical data

The server keeps standard logs: IP address, request time, requested path and browser type. They exist for diagnostics and for defending against attacks, and for nothing else.

Login protection runs separately: after several failed attempts the (IP address, username) pair is locked for a while, and the number of requests per minute is capped. That requires remembering an IP address for the duration of the lockout, and that is the only thing it is used for.

Public forms may be protected by Cloudflare Turnstile. I chose it over reCAPTCHA precisely because it does not ship a visitor's IP address to Google; my server deliberately does not even pass it the optional IP parameter.

Legal bases and retention

  • A message from the form — GDPR art. 6(1)(b) (steps prior to a contract) or (f) (answering an enquiry). Kept until the matter is closed and for a reasonable period after, so I know what we have already discussed.
  • Account and learning data — GDPR art. 6(1)(b) (performance of a contract). Kept while we work together; afterwards I delete the account on request, and if there is no request I ask at the end of the school year whether to keep it.
  • Logs and login protection — GDPR art. 6(1)(f) (service security). Short-lived: logs rotate, lockouts expire on their own.
  • Accounting records, where they arise — a statutory obligation, kept for the period tax law requires.

Who processes data for me

I do not sell data, trade it, or share it for marketing. To anyone. I do rely on infrastructure providers, without which the site would not run:

  • Render — application hosting,
  • Supabase — the database (PostgreSQL),
  • Cloudflare — content delivery, attack protection and the Turnstile check.

Transfers outside the EEA

Some of the providers above are companies outside the European Economic Area. Where that is the case, the transfer relies on the European Commission's standard contractual clauses, included in the data-processing agreements with those providers.

Your rights

You have the right to:

  • access your data and receive a copy of it,
  • have inaccurate data corrected,
  • have data erased (the “right to be forgotten”),
  • restrict processing,
  • data portability,
  • object to processing based on legitimate interest,
  • lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).

Changes

If I change how data is processed, I change this page and update the date at the bottom. If the change is material, I write to the parents of the students it affects.

Zuletzt überprüft am 2026-09-08. Fragen dazu bitte über das Kontaktformular.