Privacy Policy – Practicly
Last updated: 15.09.2026 Version: 1.0
Section 1. General Information
- This Privacy Policy describes how personal data of Users of the Practicly service, available at https://practicly.app (the "Service"), is collected, processed, and protected.
- A User is a natural person who uses the Service or the Services, in particular a person with an Account, regardless of whether they use them under an agreement entered into directly with the Controller or as part of access provided by another entity.
- The data controller is Michał Cieśla, conducting sole proprietorship business under the name Enovic Inteligentne Instalacje Michał Cieśla, with its registered place of business at ul. Marynarska 12, 05-825 Kady, Grodzisk Mazowiecki municipality, Mazowieckie voivodeship, Poland, Tax ID (NIP): 5060063248, Statistical Number (REGON): 365266100 (the "Controller").
- For questions related to data protection, please contact us at: [email protected]. Electronic delivery address: AE:PL-79539-74761-IAGTC-22.
- The Controller has not appointed a Data Protection Officer. For all matters related to the processing of personal data, please contact the Controller using the address provided above.
- The Controller processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Polish data protection legislation.
Section 2. Categories of Data Processed by the Controller
The scope of personal data processed by the Controller depends on the type of service used by the User and the manner in which the Service is used. The Controller may process, in particular, the following categories of data:
2.1. Identification and contact data, such as first and last name, email address, and company name.
2.2. Account access data, such as passwords (stored only in hashed form) and other security information used for authentication and access authorization.
2.3. Billing data, such as:
- payment details (credit or debit card number, banking information) used to process electronic payments – provided by the User directly to the payment operator Stripe (Stripe, Inc.). The Controller does not store credit card numbers or banking details on its own servers,
- data necessary to issue an invoice or other accounting document, in particular first and last name or company name, address, and Tax ID (NIP) – for Users conducting business activity.
2.4. Data and content entered by the User into the Service, such as:
- transcripts of Sessions with Virtual Patients,
- the User's notes regarding Sessions,
- proposed diagnoses of Virtual Patients.
2.5. Data concerning use of the Service, including information on Session duration, login dates, and use of the hours limit.
2.6. Voice data – recordings of the User's voice (raw audio) captured during a Session via the microphone.
Raw audio is transmitted in real time to our speech-to-text (STT) provider solely for transcription purposes, i.e., converting the User's speech into text. The Controller does not retain raw audio on its own infrastructure after the transcription process is completed.
In accordance with the terms of the STT service, which prohibit the use of data for model training, and the zero-retention control mechanism described in Section 10.3, audio recordings are not used to train models or to create a voiceprint, speaker identification profile, or biometric template, either by the Controller or by the STT provider.
2.7. Technical data relating to the device and connection, such as IP address, browser type and version, operating system, and device information.
Section 3. Purposes and Legal Bases for Processing
- The Controller processes personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account registration and management | Art. 6(1)(b) – performance of a contract |
| Providing the Service (conducting sessions, generating transcripts) | Art. 6(1)(b) – performance of a contract |
| Processing subscription payments | Art. 6(1)(b) – performance of a contract |
| Storing transcripts and notes for AI feedback generation | Art. 6(1)(b) – performance of a contract / Art. 6(1)(f) – legitimate interest (service improvement) |
| Handling complaints and communicating with Users | Art. 6(1)(b) – performance of a contract / Art. 6(1)(f) – legitimate interest |
| Ensuring the security of the Service | Art. 6(1)(f) – legitimate interest |
| Reviewing user-reported AI responses (consented session snapshot) | Art. 6(1)(a) – consent (see Section 10.4) / Art. 6(1)(f) – legitimate interest (AI safety) |
| Cookieless website traffic and conversion analytics | Art. 6(1)(f) – legitimate interest (measuring outreach effectiveness and improving the Service) |
| Measuring the effectiveness of marketing campaigns via Meta Pixel, based on consent | Art. 6(1)(a) – consent |
| Fulfilling legal obligations (e.g., accounting, taxes) | Art. 6(1)(c) – legal obligation |
-
Special category data. The Service is not intended for entering, collecting, or analyzing real special category data concerning Users or third parties. Virtual Patients are fictional characters generated by artificial intelligence and do not represent real persons.
Under the Terms of Service, the User may not enter into the Service information concerning real persons where such information allows or may allow their identification, in particular personal data and health-related data. This prohibition also covers information that has previously been anonymized, where its scope or combination with other information may allow the identification of a person.
If, despite the above prohibition, the User enters special category data into the Service, including health data concerning a real person, such data may be processed as part of the content entered by the User, solely to the extent necessary to support the Session, ensure the security of the Service, prevent abuse, handle reports, and establish, exercise, or defend legal claims. Such processing is incidental to the core functions of the Service and does not constitute a purpose of its operation.
Section 4. Data Recipients and Processors
To ensure the proper functioning of the Service and the provision of the Services, we use external providers who support us, among other things, in hosting and data storage, payment processing, communication, security, analytics, and AI-based functions. Accordingly, to the extent necessary to achieve these purposes, we may share personal data with these entities. Personal data may also be shared with entities authorized to receive it where this is necessary to fulfil a legal obligation to which the Controller is subject.
4.1. Specific Data Recipients
| Recipient Category | Data Scope | Purpose | Location |
|---|---|---|---|
| Stripe, Inc. | Payment data | Payment processing | USA (with GDPR-compliant safeguards) |
| Amazon Web Services EMEA SARL | All data stored within the Service | Hosting and data storage (S3, DynamoDB, Lambda, RDS) | EU (Frankfurt region) |
| Amazon CloudFront (AWS service) | IP address, HTTP request headers | Content delivery (CDN); personal data stored exclusively in the EU, edge nodes used solely for technical purposes | Global edge nodes; personal data in the EU |
| Amazon Simple Email Service (AWS service) | Email address, message content | Sending transactional and marketing emails | EU (Frankfurt region) |
| PostHog Inc. | Page interaction events, rotating anonymised identifier (no cookies) | Cookieless website traffic and conversion analytics (see Section 8) | EU (Frankfurt, PostHog Cloud EU) |
| Cloudflare, Inc. (Turnstile) | IP address, browser/device signals used for the bot-detection challenge | Protecting the Service's forms from automated abuse | USA (EU-US Data Privacy Framework + SCCs) |
| Meta Platforms, Inc. | Browser event data, event identifier, hashed email address (with consent) | Marketing conversion measurement (Meta Pixel and a corresponding server-side Conversions API event), see Section 8 | USA (EU-US Data Privacy Framework + SCCs) |
| CPC Servicios Informáticos Aplicados a Nuevas Tecnologías, S.L. (MailRelay) | Name, email address, language | Sending marketing communications to subscribers, based on consent | EU (Spain; data centres in Germany) |
Data may also be shared with the following categories of recipients:
- providers of advisory, legal, accounting, audit, security, and compliance services – to the extent necessary to provide those services;
- public administration bodies, regulators, courts, and other entities authorized to receive data under applicable law – to the extent required or permitted by law.
4.2. International Data Transfers
In connection with the use of artificial intelligence service providers, the payment operator (Stripe), Meta Platforms, Inc. (based on marketing consent, see Section 8), and Cloudflare, Inc. (bot protection), all based in the United States, personal data of Users may be transferred outside the European Economic Area (EEA). Such transfers are carried out on the basis of:
- an adequacy decision by the European Commission (EU-US Data Privacy Framework), or
- Standard Contractual Clauses (SCCs) adopted by the European Commission.
The Amazon CloudFront CDN may use local edge servers in various regions worldwide solely for technical purposes (accelerating page load) – this does not constitute a transfer of personal data outside the EEA.
Section 5. Data Retention Periods
| Data Category | Retention Period |
|---|---|
| Registration data (Account) | Until the Account is deleted, plus up to 30 days for backup processing |
| Billing data | For the period required by tax law (5 years from the end of the tax year) |
| Session transcripts and notes | Maximum 24 months from the date of subscription termination or Account deletion; the User may delete them earlier via the Account panel |
| Technical data (logs) | Up to 12 months |
| Aggregated cookieless analytics data (non-identifying) | Up to 12 months |
We retain personal data for no longer than is necessary to achieve the purposes for which it was collected, taking into account the retention periods indicated above and obligations arising from applicable law. After the relevant period has elapsed, data is deleted or anonymized, unless its further retention is required by law, necessary to establish, exercise, or defend legal claims, or justified on another legal basis.
Section 6. Your Rights
Under the GDPR, you have the following rights:
- Right of access – the right to obtain information about, and access to, your personal data being processed (Art. 15 GDPR).
- Right to rectification – the right to correct inaccurate or incomplete personal data (Art. 16 GDPR).
- Right to erasure ("right to be forgotten") – the right to request the deletion of your personal data (Art. 17 GDPR).
- Right to restriction of processing – the right to request a limitation on the processing of your data in certain circumstances (Art. 18 GDPR).
- Right to data portability – the right to receive your personal data in a structured, commonly used, machine-readable format and to request that it be transmitted to another controller, in the cases specified in Art. 20 GDPR.
- Right to object – the right to object to the processing of your personal data in the cases specified in Art. 21 GDPR, in particular processing based on the Controller's legitimate interest. You may also object at any time to the processing of your data for direct marketing purposes.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint – you have the right to file a complaint with the President of the Polish Data Protection Authority (Prezes Urzędu Ochrony Danych Osobowych), if you believe that the processing of your data violates your rights.
To exercise any of these rights, please contact us at: [email protected].
Section 7. Automated Decision-Making and Profiling
- The Controller does not make decisions concerning the User based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect the User within the meaning of Article 22 GDPR.
- AI-generated feedback regarding Sessions is solely educational in nature and does not constitute an assessment of the User's professional qualifications.
Section 8. Cookies
- The Service uses cookies to the extent necessary for its proper functioning and, with the User's consent, to measure the effectiveness of marketing activities.
- Types of cookies currently used:
| Type | Purpose | Duration |
|---|---|---|
| Session cookies (essential) | Maintaining the User's authentication session | Until the browser session ends |
Meta Pixel cookies (_fbp, _fbc) — marketing, opt-in | Measuring the effectiveness of marketing campaigns (Meta Pixel) | Up to 90 days |
- The analytics service used (PostHog) operates in cookieless mode – it does not store cookies or personal identifiers on the User's device. The Service may use only essential technical cookies necessary for proper operation (e.g., anti-spam safeguards and the Cloudflare Turnstile challenge that protects forms from automated abuse), on the basis of Article 173(3)(2) of the Polish Telecommunications Act of 16 July 2004.
- Marketing cookies (Meta Pixel and the corresponding server-side event). The Controller uses Meta Pixel (Meta Platforms, Inc.) to measure the effectiveness of marketing campaigns. The Meta Pixel is loaded, and its cookies (
_fbp,_fbc) are set, only after the User gives explicit consent via the cookie banner – the legal basis is Art. 6(1)(a) GDPR. Once consent is given, the same conversion event recorded by the browser Pixel is additionally sent server-side via Meta's Conversions API – carrying only a SHA-256 hash of the confirmed email address (never the raw address) plus a shared event identifier that lets Meta deduplicate the two events into a single conversion. Consent can be withdrawn at any time via the "Cookie settings" link in the Service's footer, which stops the Pixel and the corresponding server-side event and revokes further tracking. - If further analytics or marketing cookies that store identifiers on the User's device are introduced in the future, Users will be informed and appropriate consent will be obtained before their activation.
- You can manage cookies through your browser settings, and marketing cookies specifically through the "Cookie settings" link described in paragraph 4. Blocking essential session cookies may prevent you from properly using the Service or some of its functions.
Section 9. Data Security
- The Controller implements appropriate technical and organizational measures to protect personal data from unauthorized access, loss, destruction, or disclosure, including:
- encryption of connections using TLS/SSL protocols,
- storing passwords exclusively in hashed form,
- regular software and infrastructure updates,
- restricting access to personal data to authorized personnel, to the extent necessary for their duties.
- Payment data is processed exclusively by Stripe, which holds PCI DSS Level 1 certification.
Section 10. AI Data Processing
- As part of providing the Service, data entered by the User during Sessions (text and audio) and Session Notes are processed by external artificial intelligence models for the following purposes:
- generating Virtual Patient responses,
- speech-to-text (STT) and text-to-speech (TTS) conversion,
- analysis of the User's transcripts and notes to generate educational feedback.
- The Controller uses the APIs of these services, which means data is transmitted to the providers' servers for the duration of processing. These providers are based in the United States, and data transfers are carried out on the bases indicated in Section 4.2.
- No-training commitment. User Session content (audio recordings, transcripts, Session Notes) is shared with AI providers only to the extent necessary to provide the relevant functions of the Service. The Controller uses providers whose terms of service and agreements provide that the data shared is not used to train, fine-tune, evaluate, or improve AI models. The Controller uses the data-retention control mechanisms available from its speech and language providers.
- Reporting an AI response. Using the "Report AI response" feature requires consenting to share with our internal review team a snapshot of the Session. The snapshot is a one-time copy of the data related to the given Session, comprising the full transcript and the AI-generated feedback for that Session, created at the moment the report is submitted in order to investigate the reported issue. The snapshot is used to analyze the report, assess safety, and improve the quality of the Service. Reviewers have access only to the created snapshot and do not have direct or ongoing access to the rest of the Session data, which also serves as a form of human review of AI feedback at the User's request. The legal basis is Art. 6(1)(a) GDPR (your consent), which you may withdraw at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal and results in deletion of the report together with the created snapshot, unless their further retention is required by law or necessary to establish, exercise, or defend legal claims. The Service may also periodically invite the User to share a Session for quality review; accepting requires the same consent and creates the same kind of snapshot, used and retained as described above. Declining shares nothing.
Section 11. Changes to This Privacy Policy
- The Controller reserves the right to amend this Privacy Policy.
- Users will be notified of any material changes via email or a notice within the Service at least 14 days before the changes take effect.
- Continued use of the Service after the changes take effect constitutes acceptance of the updated Privacy Policy.
Section 12. Final Provisions
- This Privacy Policy is an integral part of the Practicly Terms of Service.
- Matters not covered by this Privacy Policy shall be governed by the GDPR and applicable Polish data protection legislation.
- In case of any discrepancies between the Polish and English versions of this Privacy Policy, the Polish version shall prevail.
This Privacy Policy is in effect as of 15.09.2026.

