Relentu
Terms of Service Privacy Policy Cookie Policy Data Processing Agreement Sub-processors Acceptable Use Payments

Contents

  1. 01 § 1. The controller
  2. 02 § 2. Who controls what
  3. 03 § 3. What is collected
  4. 04 § 4. Purposes and legal bases
  5. 05 § 5. How the data is used
  6. 06 § 6. Disclosure
  7. 07 § 7. Storage location and international transfers
  8. 08 § 8. Retention
  9. 09 § 9. Security
  10. 10 § 10. Rights of the data subject
  11. 11 § 11. Cookies and similar technologies
  12. 12 § 12. Children
  13. 13 § 13. Regional specifics
  14. 14 § 14. Automated decisions
  15. 15 § 15. Changes to this policy
  16. 16 § 16. Contact and complaints

Legal · Privacy Policy

Privacy Policy

What personal data we collect, why, how long we keep it, and the rights you have under the GDPR and local laws in Poland, Israel, Belarus and Russia.

§ 1. The controller

  1. The controller of personal data collected by Relentu is Mikhail Shabatura, a Polish sole proprietorship (JDG), NIP 9662192552, REGON 528667570, of Jana III Sobieskiego 11/21, 15-013 Białystok, Polska.
  2. Privacy contact: privacy@relentu.com. Security incident contact: security@relentu.com.
  3. Because the Operator is established in Poland, an EU Member State, no separate representative under art. 27 GDPR is required.

§ 2. Who controls what

  1. There are two controller regimes in Relentu, and which one applies matters.
  2. Account and platform data — the data given to the Operator so the service can run: email, name, billing information, sign-in logs, notifications. Here the Operator is the controller.
  3. Provider workspace data — the data a Provider (in the product interface: a teacher) puts into their own workspace about the Recipients they teach (in the interface: students): names, session notes, uploaded files, chat messages, activity cards, recap notes. Here the Provider is the controller and the Operator acts as a processor on the Provider's instructions, on the terms of the Data Processing Agreement.
  4. A Recipient with questions about how their Provider uses their data should ask that Provider first — the Provider decides what to record and how to use it. Ask the Operator where the Provider cannot be reached, or to find out how the Operator looks after that data on the Provider's behalf.

§ 3. What is collected

  1. The following categories of personal data are collected: a) Account and identity — name, email address, chosen role (Provider or Recipient), profile photo where one is uploaded, language and interface preferences, and a salted hash of the password. Passwords are never stored in plain text. b) Contact and booking — time zone, availability windows (for Providers), Sessions scheduled or accepted, and the identity of the other party to a Session. c) Billing — for a Provider on a paid plan: name, billing address, VAT identifier, and a Stripe-hosted payment token. Card numbers are not stored by the Operator. Recipients pay the Operator nothing, so no billing data is held about them — see the Payment Policy. d) Operational content — anything put into the product to make it work: session notes, files, chat messages, activity cards, recap notes, homework, notebooks. e) Technical and security data — IP address, user-agent, device type, timestamps, sign-in history, error reports, feature-usage events, used to keep the platform running, prevent abuse and fix bugs. The Operator does not look up where an IP address is, and holds no tool that would. f) Consent and acceptance records — what was decided when a document was accepted or a cookie choice made, together with the IP address and browser that made the decision. g) Communication — anything sent to the Operator by email.
  2. No advertising identifiers are collected, no cross-site tracking is run, and no data is shared with ad networks. There are no ad networks.

§ 4. Purposes and legal bases

  1. Under art. 6 GDPR the Operator relies on the following bases:
Purpose Category Legal basis
Create the account, sign the user in, run the Sessions booked, deliver notifications tied to those Sessions, invoice a paid plan Account, contact, booking, billing Contract (art. 6(1)(b))
Keep the service running, prevent abuse, mitigate fraud, respond to security incidents Technical and security data Legitimate interest (art. 6(1)(f)) — the interest is a safe, functioning service, balanced against user rights
Comply with Polish tax, accounting, and consumer-protection law; retain invoices for the statutory period Billing Legal obligation (art. 6(1)(c))
Keep a record of what was accepted or consented to, with the IP address and browser that decided it Consent and acceptance records Legal obligation (art. 6(1)(c)) read with art. 7(1) — a consent must be demonstrable, and a record without the circumstances of the decision demonstrates little
Send optional product news, and run non-essential analytics via cookies Communication, technical Consent (art. 6(1)(a)); withdrawable at any time
Process data of a Recipient that a Provider puts into their workspace Operational content in the Provider workspace The Provider is controller; the Operator acts on art. 28 processor terms — see the DPA
  1. Where a special category of data is processed — for example health data a Provider inadvertently writes into a note — the Provider, as controller, is responsible for the corresponding legal basis under art. 9 GDPR.
  2. The Operator does not ask for, and does not knowingly process, special-category data.

§ 5. How the data is used

  1. Personal data the Operator controls is used only to: a) provide the service — render the interface, send notifications, route messages, schedule Sessions, process payments; b) improve the service — fix bugs, add features users ask for, monitor for abuse and fraud; c) communicate — service updates, security alerts, billing, and, only where opted in, product news; d) comply with the law — respond to lawful requests, defend the Operator's position, prove tax compliance.
  2. User content is not used to train artificial-intelligence models, the Operator's own or anyone else's. Where AI-assistant features exist or are added later, they operate under zero-retention terms with the model provider: inputs and outputs are not retained by that provider beyond the live request and are not used to train any model. AI features are off by default.

§ 6. Disclosure

  1. Personal data is shared with the vendors needed to run the platform — the sub-processors: infrastructure, payments, email delivery, error monitoring, product analytics. Each is bound by a written agreement passing the Operator's obligations through, and each is listed with its role, region and data-protection status on the Sub-processors page.
  2. Personal data is shared beyond sub-processors only where: a) the user directs it — for example, on accepting a Provider's invitation the Provider then sees the data needed to serve that Recipient; b) the law requires it — a court order or a lawful regulator demand; where permitted, the affected user is told; c) the business changes hands — in a merger, acquisition, or asset sale the data follows the business under terms at least as protective as this policy, and users are notified before the change takes effect.
  3. Personal data is not sold.

§ 7. Storage location and international transfers

  1. Personal data controlled by the Operator is stored on managed infrastructure in the European Union — Hetzner Online GmbH, in Germany. Backups of that data are kept in the same region.
  2. Some sub-processors are established outside the EU. Where data is transferred outside the European Economic Area, the Operator relies on: a) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporated by reference into the contract with each such sub-processor; b) the UK International Data Transfer Addendum, where the transfer is to the United Kingdom; c) the Swiss FDPIC additions, where the transfer involves Swiss data subjects; d) an adequacy decision, where one is available for the destination country.

§ 8. Retention

  1. Personal data is kept only for as long as there is a reason to keep it.
  2. Account data — for as long as the account is active. On account closure, personal data is soft-deleted immediately and physically deleted or anonymised within 30 days. Encrypted database backups age out on a rolling 30-day cycle; after that no recoverable copy exists.
  3. Operational content — as for account data. A Provider closing their workspace can request an export first.
  4. Billing records — retained for the statutory period required by Polish tax and accounting law, currently 5 full calendar years counted from the end of the financial year in which the invoice was issued. These records are segregated from the operational store.
  5. Support correspondence — support runs by email. Those messages live in the mailbox that receives them; the product stores no ticket, and nothing about them is attached to an account.
  6. Sign-in and consent records — the device, IP address and time of each sign-in, and the IP address and browser recorded with a cookie-consent or document-acceptance receipt, are kept for as long as the account exists and are deleted with it. They exist to show who agreed to what and to investigate account compromise, and are used for nothing else.
  7. Relentu is provided in Beta, and these periods describe how long data is meant to be kept — not a promise that nothing will be lost. While the product is still changing, a fault can destroy data earlier than any period above. Export anything that would be missed, from Settings → Data & export.
  8. Where a Provider workspace holds data as controller, the retention rules in that Provider's own privacy notice apply. The Operator's processor obligations are in the DPA.

§ 9. Security

  1. Personal data is protected by: a) TLS 1.2 or higher in transit, and encryption at rest on the database and on file storage; b) role-based access control. There is no administrative console — data is reachable through the account it belongs to, or by direct database access limited to the operator; c) password hashing with a modern algorithm; refresh tokens stored in HttpOnly, SameSite=Strict cookies; d) regular dependency and container scanning; e) a coordinated disclosure programme — write to security@relentu.com.
  2. No online service is perfectly secure. Where a breach of personal data occurs, the affected users are notified without undue delay and within any regulatory deadline that applies to the Operator or, where a Provider is controller, to that Provider (art. 33 GDPR: 72 hours to the supervisory authority).

§ 10. Rights of the data subject

  1. Under the GDPR every data subject has the right to: a) access — obtain a copy of the data held about them; b) rectification — correct anything inaccurate; c) erasure — have their data deleted, subject to legal-retention obligations; d) restriction — pause certain processing while a dispute is resolved; e) objection — object to processing that relies on legitimate interest; f) portability — receive their data in a structured, commonly used, machine-readable format; g) withdrawal of consent — where processing is based on consent, withdraw it at any time, without affecting past processing; h) complaint — lodge a complaint with a supervisory authority (§ 13).
  2. Most of these can be exercised directly from Settings → Privacy: export account data, close the account, change notification preferences, review cookie preferences.
  3. For anything more involved, write to privacy@relentu.com. The Operator replies within one month of receiving a request it can verify, and may extend by a further two months for a complex request, saying so within that first month (art. 12(3) GDPR).
  4. A Recipient whose data lives in a Provider workspace should ask that Provider first, since the Provider decides what to keep. Where the Provider is uncontactable or unresponsive, the Operator will help.

§ 11. Cookies and similar technologies

  1. The Cookie Policy carries the full list of what is stored on a device and how to control it.
  2. Essential cookies sign the user in and serve protected files. Optional cookies for product analytics and error tracking run only after they have been accepted through the cookie banner or Settings → Privacy.

§ 12. Children

  1. Relentu is designed for Providers to deliver lessons to their own Recipients. Some of those Recipients are children.
  2. The Operator does not knowingly process the personal data of a child below the local age of digital consent (§ 13) without the consent of a parent or legal guardian. That consent is obtained by the Provider from the parent — see Terms of Service § 7.
  3. The Operator does not market to children, does not build behavioural profiles of anyone including children, and does not use children's data to train AI models.
  4. A child, or their parent or guardian, may request access, rectification or erasure of the child's data at any time (§ 10).
  5. Providers are contractually responsible for having parental consent before adding a child to their workspace. Where the Operator becomes aware that a child's data has been added without such consent, it will be removed.

§ 13. Regional specifics

Poland and the wider EU/EEA

  1. The supervisory authority for Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, "UODO"), ul. Stawki 2, 00-193 Warszawa. A consumer in another EU/EEA state may complain to their own national supervisory authority instead.
  2. The age of digital consent under art. 8 GDPR is 16 in Poland, as implemented by the Polish Act on the Protection of Personal Data.
  3. The Consumer Rights Directive gives an EU consumer a 14-day right of withdrawal from a paid plan — see Terms of Service § 10.

Israel

  1. Data on Israeli residents is processed in line with the Privacy Protection Law 5741-1981 and its regulations, including the Privacy Protection Regulations (Data Security) 5777-2017.
  2. The relevant supervisory authority is the Israeli Privacy Protection Authority (Rashut Ha'Gnat Ha'Prati).
  3. For children under 18 in Israel, parental consent for processing personal data is required in the cases specified by the Privacy Protection Law and by the Attorney General's guidelines. The Provider obtains that consent.
  4. Transfers out of Israel comply with the Israeli Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001.

§ 14. Automated decisions

  1. The Operator makes no decision producing legal or similarly significant effects on a data subject that is based solely on automated processing.
  2. Where automation is used — for example anti-abuse checks, spam detection, or scheduling assistants — human review is available on request.

§ 15. Changes to this policy

  1. Where this policy changes materially, a banner appears in the product before the change takes effect. Until the change takes effect the banner may be set aside; from the day it takes effect it is displayed until the new version is accepted.
  2. Continued use after the effective date constitutes acceptance.
  3. A non-material change — a typo, a clarification, an update to contact details — takes effect on posting.
  4. The version in force and the date it took effect are displayed on this page.

§ 16. Contact and complaints

  1. Privacy and data-subject requests: privacy@relentu.com.
  2. Security incidents: security@relentu.com.
  3. Post: Mikhail Shabatura, Jana III Sobieskiego 11/21, 15-013 Białystok, Polska, NIP 9662192552, REGON 528667570.
  4. Supervisory authorities: § 13.
  5. This policy is effective as of 2026-08-01.

Document

A quick orientation to what you're reading.

Type
Privacy policy
Reading time
13 min
Languages
© 2026 Relentu · A calm workspace for teachers who run online lessons.
Terms of Service Privacy Policy Cookie Policy Data Processing Agreement Sub-processors Acceptable Use Payments