Arpeggia.studioPolski

How we process personal data

Information for training participants who receive credentials from us and for people who verify those credentials.

Effective from: 14 September 2026

01Data controller

The controller of your personal data is ARPEGGIA STUDIO sp. z o.o., registered office in Białystok, ul. Złota 2/19, 15-016 Białystok, Poland, entered in the National Court Register (KRS) under number 0001215486, NIP (tax ID) 966 221 63 01, REGON 543670898.

For any matter concerning personal data, write to contact@arpeggia.studio.

02What this information covers

This page describes the Arpeggia.studio credential service: issuing and sending training credentials, verification pages, document checks and post-training materials. Other Arpeggia.studio activities, such as the website, consultations and the newsletter, are covered by the privacy policy at arpeggia.studio (in Polish).

03What data we process

  • first name and surname;
  • e-mail address;
  • participant identifier assigned by the organiser, if it was provided to us;
  • training data: program name, edition, dates, number of hours, trainers and training partner;
  • credential number, its status (valid, expired, revoked, replaced) and change history;
  • message delivery history: when a message was sent, delivered or rejected by a mail server;
  • answers to the post-training survey, if it is filled in;
  • technical data: IP address and request time in server logs and in the traffic counter that protects against abuse, and an access cookie on the materials pages.

04Where we get your data from

We receive the data from you when you sign up for a training, or from the company that ordered the training and registered you as a participant, usually your employer. That company gives us your name, surname, e-mail address and, optionally, a participant identifier.

05Purposes and legal bases

PurposeLegal basis
Issuing the credential and sending it to your e-mail address.Art. 6(1)(b) GDPR when the training is provided under a contract with you. Art. 6(1)(f) GDPR when the training was ordered by the company that registered you; our legitimate interest is performing the contract with that company and documenting your participation.
Maintaining the verification page where you and the people you share the link with can check the authenticity and status of the credential.Art. 6(1)(f) GDPR: making sure an issued document can be reliably verified and preventing forgery.
Providing post-training materials, the survey and the invitation to the alumni community.Art. 6(1)(f) GDPR: supporting participants after the training and improving training quality.
Correcting, replacing and revoking credentials, and logging those events.Art. 6(1)(f) GDPR: keeping the register of issued credentials accurate.
Service security: logs, request rate limiting, abuse detection.Art. 6(1)(f) GDPR: protecting the service and the data processed in it.
Establishing, pursuing or defending legal claims.Art. 6(1)(f) GDPR.

06What is publicly visible

The credential verification page shows the first name and surname, program name and scope, training dates and duration, trainers, training partner, and the credential number, issue date and status.

  • The page is only reachable through a long, random address from the message and the QR code. There is no search and no list of participants.
  • The page is marked as excluded from search engine indexing.
  • The e-mail address never appears on the page, in its address or in the PDF file.
  • The PDF file and images can only be downloaded from the private link in the message to you.
  • You decide who you share the verification page address with.

07How long we keep data

  • Credential data, meaning name, surname, training data, number, status and history, is kept without a fixed end date. A credential must remain verifiable years later, for example during recruitment; deleting the data would remove that possibility.
  • The e-mail address and delivery history are kept together with the credential so that we can resend the link at your request.
  • Technical server logs: 30 days.
  • Traffic counter: a few minutes, in server memory only.
  • Materials access cookie: 30 days or until you click “Zamknij dostęp” (close access).
  • Survey answers: for as long as needed to evaluate and improve the training.

If you no longer want the credential to be available, object by writing to contact@arpeggia.studio. We will then revoke the verification page and delete or anonymise your data. We keep only a minimal event record without identifying data, confirming that a document with a given number was issued and revoked.

08Who receives the data

We entrust the data to providers who process it only on our instructions, under a data processing agreement:

ProviderServiceData location
Microsoft Ireland Operations Ltd.Microsoft Azure: application servers, database, PDF file storage, keys and logsEuropean Union, Poland Central region
Microsoft Ireland Operations Ltd.Azure Communication Services: e-mail sending and delivery statusesEuropean Union
Microsoft Ireland Operations Ltd.Microsoft Forms: post-training surveyEuropean Economic Area

The data may also be received by:

  • the company that ordered the training and the training partner, to the extent needed to confirm participation and settle the training;
  • people you share the verification page address with;
  • public authorities, where required by law.

Independent controllers. They receive data only when you use their services, and their own privacy policies govern the processing:

  • LinkedIn Ireland Unlimited Company: when you use the “Add to LinkedIn” button, we pass the credential name, issuer, issue date, number and verification page address to the LinkedIn form;
  • Discord Netherlands B.V.: when you join the Arpeggia Architecture Club from the invitation.

09Transfers outside the EEA

We store the data on servers in the European Economic Area. In exceptional situations, such as technical support, Microsoft may access data from countries outside the EEA. This happens on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses. When you use LinkedIn or Discord, you decide yourself to share data with those services.

10Your rights

You have the right to:

  • access your data and receive a copy (Art. 15 GDPR);
  • rectification (Art. 16 GDPR); a corrected credential receives a new version and the verification page shows the current one;
  • erasure (Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR);
  • portability of data processed under a contract (Art. 20 GDPR);
  • object to processing based on legitimate interest (Art. 21 GDPR);
  • lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl.

Send your request to contact@arpeggia.studio. We will reply within one month. We may ask you to confirm your identity, for example by writing from the address the credential was sent to.

11Voluntary provision and automated decisions

Providing data is voluntary, but without a name, surname and e-mail address we cannot issue or send a credential. We do not make automated decisions about you and do not profile you.

12Cookies

Credential and materials pages use no analytics or advertising cookies and contain no tracking tools. On the materials pages we store one strictly necessary cookie, arp_kb, which remembers the credential number you entered. It expires after 30 days or when you close access. It does not require consent because the materials do not work without it.

13Changes to this information

When we change how data is processed, for example a service provider, we will update this page and its effective date.