1. Scope of this policy
This policy applies to helmark.org, the contact form, training enquiries, course delivery and the issue and verification of Helmark certificates. It does not apply to external websites linked from this site.
2. What data we process and why
Contact enquiries
When you use the contact form, we may receive your name, work e-mail, company, team size, preferred delivery format and the content of your message. We use this information only to answer the enquiry, prepare a quote or take steps requested before entering into a contract.
Legal basis: legitimate interest in responding to messages addressed to us and steps taken at your request before a contract, under Art. 6(1)(f) and Art. 6(1)(b) GDPR.
Training and certificate administration
For booked training, we may process participant names, e-mail addresses, organisation names, attendance information and certificate identifiers. This is necessary to organise the course, communicate with participants, issue HDP or HDL certificates and verify an issued certificate on request.
Legal basis: performance of a contract or steps connected with a contract, Art. 6(1)(b) GDPR. Where accounting records are required, data may also be processed to meet a legal obligation, Art. 6(1)(c) GDPR.
What we do not do
We do not sell personal data, build advertising profiles or use contact-form data for unrelated marketing.
3. How long data is kept
- Unsuccessful or general enquiries: for the time needed to respond and normally no longer than 24 months, unless a dispute or legal obligation requires longer storage.
- Contract and accounting data: for the period required by tax, accounting and limitation rules.
- Certificate register data: for as long as the certificate is intended to remain verifiable. The register is limited to information necessary for verification.
4. Data controller
The controller of personal data processed through this website is Piotr Sobiegał, ul. Olimpijska 15a/4, Bytom, Poland. Privacy requests can be submitted through the contact form.
5. Service providers and recipients
Web3Forms provides the technical delivery of contact-form messages. Hosting, e-mail, accounting, payment and certificate services may process data only where needed to provide their service and under appropriate contractual or legal safeguards. The current public site does not embed advertising networks or analytics platforms.
If a provider transfers data outside the European Economic Area, the transfer must rely on a lawful safeguard, such as an adequacy decision or standard contractual clauses.
7. Your rights
Subject to the conditions of the GDPR, you may request access to your data, correction, erasure, restriction of processing, data portability or object to processing based on legitimate interest. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO).
8. Security and mandatory data
We use reasonable organisational and technical measures appropriate to the scope of the service. Data marked as required in a form is needed to handle the request. Providing optional information is voluntary. No solely automated decision-making or profiling is used.
9. External links and policy changes
External websites operate under their own privacy policies. This policy may be updated when the site, service providers or legal requirements change. The current version and update date will always be published on this page.