How we process personal data
Information for training participants who receive credentials from us and for people who verify those credentials.
Effective from: 14 September 2026
01Data controller
The controller of your personal data is ARPEGGIA STUDIO sp. z o.o., registered office in Białystok, ul. Złota 2/19, 15-016 Białystok, Poland, entered in the National Court Register (KRS) under number 0001215486, NIP (tax ID) 966 221 63 01, REGON 543670898.
For any matter concerning personal data, write to contact@arpeggia.studio.
02What this information covers
This page describes the Arpeggia.studio credential service: issuing and sending training credentials, verification pages, document checks and post-training materials. Other Arpeggia.studio activities, such as the website, consultations and the newsletter, are covered by the privacy policy at arpeggia.studio (in Polish).
03What data we process
- first name and surname;
- e-mail address;
- participant identifier assigned by the organiser, if it was provided to us;
- training data: program name, edition, dates, number of hours, trainers and training partner;
- credential number, its status (valid, expired, revoked, replaced) and change history;
- message delivery history: when a message was sent, delivered or rejected by a mail server;
- answers to the post-training survey, if it is filled in;
- technical data: IP address and request time in server logs and in the traffic counter that protects against abuse, and an access cookie on the materials pages.
04Where we get your data from
We receive the data from you when you sign up for a training, or from the company that ordered the training and registered you as a participant, usually your employer. That company gives us your name, surname, e-mail address and, optionally, a participant identifier.
05Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Issuing the credential and sending it to your e-mail address. | Art. 6(1)(b) GDPR when the training is provided under a contract with you. Art. 6(1)(f) GDPR when the training was ordered by the company that registered you; our legitimate interest is performing the contract with that company and documenting your participation. |
| Maintaining the verification page where you and the people you share the link with can check the authenticity and status of the credential. | Art. 6(1)(f) GDPR: making sure an issued document can be reliably verified and preventing forgery. |
| Providing post-training materials, the survey and the invitation to the alumni community. | Art. 6(1)(f) GDPR: supporting participants after the training and improving training quality. |
| Correcting, replacing and revoking credentials, and logging those events. | Art. 6(1)(f) GDPR: keeping the register of issued credentials accurate. |
| Service security: logs, request rate limiting, abuse detection. | Art. 6(1)(f) GDPR: protecting the service and the data processed in it. |
| Establishing, pursuing or defending legal claims. | Art. 6(1)(f) GDPR. |
06What is publicly visible
The credential verification page shows the first name and surname, program name and scope, training dates and duration, trainers, training partner, and the credential number, issue date and status.
- The page is only reachable through a long, random address from the message and the QR code. There is no search and no list of participants.
- The page is marked as excluded from search engine indexing.
- The e-mail address never appears on the page, in its address or in the PDF file.
- The PDF file and images can only be downloaded from the private link in the message to you.
- You decide who you share the verification page address with.
07How long we keep data
- Credential data, meaning name, surname, training data, number, status and history, is kept without a fixed end date. A credential must remain verifiable years later, for example during recruitment; deleting the data would remove that possibility.
- The e-mail address and delivery history are kept together with the credential so that we can resend the link at your request.
- Technical server logs: 30 days.
- Traffic counter: a few minutes, in server memory only.
- Materials access cookie: 30 days or until you click “Zamknij dostęp” (close access).
- Survey answers: for as long as needed to evaluate and improve the training.
If you no longer want the credential to be available, object by writing to contact@arpeggia.studio. We will then revoke the verification page and delete or anonymise your data. We keep only a minimal event record without identifying data, confirming that a document with a given number was issued and revoked.
08Who receives the data
We entrust the data to providers who process it only on our instructions, under a data processing agreement:
| Provider | Service | Data location |
|---|---|---|
| Microsoft Ireland Operations Ltd. | Microsoft Azure: application servers, database, PDF file storage, keys and logs | European Union, Poland Central region |
| Microsoft Ireland Operations Ltd. | Azure Communication Services: e-mail sending and delivery statuses | European Union |
| Microsoft Ireland Operations Ltd. | Microsoft Forms: post-training survey | European Economic Area |
The data may also be received by:
- the company that ordered the training and the training partner, to the extent needed to confirm participation and settle the training;
- people you share the verification page address with;
- public authorities, where required by law.
Independent controllers. They receive data only when you use their services, and their own privacy policies govern the processing:
- LinkedIn Ireland Unlimited Company: when you use the “Add to LinkedIn” button, we pass the credential name, issuer, issue date, number and verification page address to the LinkedIn form;
- Discord Netherlands B.V.: when you join the Arpeggia Architecture Club from the invitation.
09Transfers outside the EEA
We store the data on servers in the European Economic Area. In exceptional situations, such as technical support, Microsoft may access data from countries outside the EEA. This happens on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses. When you use LinkedIn or Discord, you decide yourself to share data with those services.
10Your rights
You have the right to:
- access your data and receive a copy (Art. 15 GDPR);
- rectification (Art. 16 GDPR); a corrected credential receives a new version and the verification page shows the current one;
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- portability of data processed under a contract (Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR);
- lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl.
Send your request to contact@arpeggia.studio. We will reply within one month. We may ask you to confirm your identity, for example by writing from the address the credential was sent to.
11Voluntary provision and automated decisions
Providing data is voluntary, but without a name, surname and e-mail address we cannot issue or send a credential. We do not make automated decisions about you and do not profile you.
13Changes to this information
When we change how data is processed, for example a service provider, we will update this page and its effective date.