This Privacy Policy sets out information on the processing of personal data, the use of cookies and other technologies while using the Service. This Privacy Policy applies to all websites or services that reference it.
Date of publication: 1 July 2026
Last updated: 1 July 2026
Mext.pl sp. z o.o. with its registered office in Baranów (96-314), ul. Polna 9c, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under KRS number: 0000611184, share capital PLN 5,000.00, NIP (Tax ID): 5291811199, REGON: 364127431, e-mail: contact@leksykon.app, tel. 606286050 (the "Controller"), operator of the Leksykon service.
1. Personal data – information about an identified or identifiable natural person, identifiable directly or indirectly, in particular by reference to an identifier such as a name, an online identifier (including device IP), location data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity, as well as information collected via cookies and similar technologies; personal data within the meaning of Art. 4(1) GDPR.
2. EEA – European Economic Area – the free-trade area and single market comprising the Member States of the European Union and the European Free Trade Association, excluding Switzerland.
3. Account – the User's account created in the Service, which enables access to purchased services and content.
4. Cookies – text-and-numeric information files stored on the User's end devices (e.g. phone, laptop, tablet). Basic types of cookies:
strictly necessary cookies – used to provide the User with the services and functionalities available in the Service (e.g. maintaining the logged-in User's session, security);
functional cookies – used to remember and adapt the Service to the User's choices;
analytics / marketing cookies – used to analyse traffic or tailor advertising content. As at the date of publication of this Policy, the Service does not use analytics or marketing cookies (see section 13).
5. Privacy Policy – this document.
6. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
7. Service – the website at https://leksykon.app/ and all its subpages.
8. Information society service – any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services; in Poland referred to as a service provided by electronic means.
9. Act on Providing Services by Electronic Means – the Polish Act of 18 July 2002 on providing services by electronic means.
10. Telecommunications Law – the Polish Act of 16 July 2004 – Telecommunications Law.
1. A User is any natural person visiting the Service or using one or more of the services or functionalities described in this Privacy Policy.
2. The Service is not intended for children. A User:
should be at least 16 years old to give consent to the processing of personal data on their own;
under the age of 16 must obtain the consent of a legal guardian – for the purpose of receiving information society services.
3. The Controller is entitled to take measures to verify the User's age.
The Controller has appointed a Data Protection Officer (DPO) in the person of Wiktor Kowalczyk, who can be contacted via:
e-mail: wiktor@mext.pl
post: Mext.pl sp. z o.o., ul. Polna 9c, 96-314 Baranów
telephone: 606286050.
The personal data of persons using the Service is processed by the Controller:
1. on the basis of consent (Art. 6(1)(a) GDPR) for the purpose of:
sending the newsletter and commercial and marketing information by means of electronic communication – with respect to data provided optionally (Art. 10 of the Act on Providing Services by Electronic Means and Art. 172 of the Telecommunications Law);
storing data in functional, analytics or marketing cookies, should any be implemented in the future.
2. as necessary for the conclusion and/or performance of a contract or to take steps at the User's request (Art. 6(1)(b) GDPR) for the purpose of:
storing data in strictly necessary cookies and ensuring the proper functioning of the Service;
providing services by electronic means, including making available content collected in the Service (including video materials), creating and managing an Account, and providing the newsletter service;
delivering digital content and performing the purchased subscription or order;
handling payments via a payment operator;
contact in matters related to the performance of the service;
handling complaints or withdrawal from a distance contract.
3. as necessary to comply with a legal obligation of the Controller (Art. 6(1)(c) GDPR) for the purpose of:
issuing and storing invoices and fulfilling obligations arising from tax and accounting regulations, including for archival purposes;
ensuring accountability and demonstrating compliance with obligations imposed by law, including the GDPR;
handling complaints or withdrawal from a distance contract.
4. on the basis of the Controller's legitimate interest (Art. 6(1)(f) GDPR) for the purpose of:
ensuring the security and management of the Service, including keeping event logs (including IP address and device information) in order to detect and prevent abuse and unauthorised access;
carrying out statistical analyses of how the Service is used in order to improve its functionality and performance;
contacting Users, in particular to obtain feedback about the service;
establishing, pursuing or defending against claims;
storing data for archival and evidentiary purposes.
1. The User has the following rights with respect to their personal data:
right of access – the right to request information about the personal data processed, including the purposes and legal bases of processing;
right to rectification – the right to request the correction of inaccurate data and completion of incomplete data;
right to obtain a copy of the data – the right to obtain a copy of the personal data processed;
right to erasure – the right to request the erasure of data whose processing is no longer necessary;
right to restriction of processing – in the cases set out in Art. 18 GDPR;
right to data portability – with respect to data processed by automated means on the basis of a contract or consent;
right to object to processing based on the Controller's legitimate interest, including an unconditional right to object to direct marketing, and, in other respects, a right to object on grounds relating to the User's particular situation;
right to withdraw consent – at any time, without affecting the lawfulness of processing carried out before its withdrawal;
right to lodge a complaint with the supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.
2. The User's rights are not absolute and do not apply to all processing activities. To exercise their rights, the User may contact the Controller at: contact@leksykon.app or by post at: ul. Polna 9c, 96-314 Baranów, indicating the scope of their request.
In connection with the use of the Service, the Controller processes in particular:
Account data: e-mail address, password (stored only in encrypted/hashed form), first and last name (if provided), marketing-consent status, account creation date and last login date;
billing data (billing profile): first and last name or company name, NIP (Tax ID), address (street, postal code, city, country) – to the extent necessary to issue an invoice;
payment and subscription data: information about the purchased plan, payment history and invoices; payment card data is processed solely by the payment operator (Stripe) – it is not stored in the Service;
usage data: history of viewed exercises and viewing time;
technical data and event logs: IP address, device and browser information, security events (logins, login attempts, password resets), data from strictly necessary cookies.
1. The Controller's activity is supported by external entities (processors), to which the Controller entrusts personal data solely to the extent necessary to provide services to the Controller.
2. The main recipients of the data are:
Render Services, Inc. – infrastructure provider (hosting of the application, database and supporting services);
Cloudflare, Inc. – provider of content delivery network (CDN), security and proxy services, as well as file storage (Cloudflare R2) and hosting and streaming of video materials (Cloudflare Stream);
Stripe (Stripe, Inc. / Stripe Payments Europe, Ltd.) – payment and subscription operator; payment is made on the operator's page (hosted checkout);
Resend (Resend, Inc.) – provider of the e-mail delivery system (transactional messages and the newsletter);
InFakt sp. z o.o., ul. Szlak 49, 31-153 Kraków, KRS: 0000325203 – provider of the invoicing system; the Controller transfers billing data (first and last name / company name, NIP, address) in order to issue an invoice;
entities providing accounting and advisory services;
public authorities entitled under the law. In particular, to verify the NIP (Tax ID), the Controller uses the public REGON register maintained by Statistics Poland (the GUS BIR service).
3. The Controller reserves the right to disclose personal data where this results from a legal obligation imposed on the Controller, including the obligation to provide information to the competent administrative authorities or law-enforcement authorities.
1. The level of personal data protection outside the EEA differs from that within the European Union. The Controller cooperates with entities located both within and outside the EEA.
2. Some of the Controller's service providers (in particular Cloudflare, Stripe and Resend) are entities established in, or processing data in, the United States, which may involve the transfer of personal data outside the EEA. In such cases, the transfer takes place on the basis of appropriate safeguards provided for in Art. 46 GDPR, primarily the Standard Contractual Clauses (SCC) approved by the European Commission and, in respect of certified providers, on the basis of the EU–U.S. Data Privacy Framework. A copy of the safeguards applied may be obtained by contacting the Controller.
3. More information on the rules for transferring data outside the EEA is available on the European Commission's website.
1. Personal data is stored for the time necessary to achieve the purpose for which it was collected, including:
Account data – for the duration of the Account, and after its deletion for the period necessary to establish, pursue or defend against claims;
data processed on the basis of consent (e.g. the newsletter) – until consent is withdrawn or the purpose of processing is achieved;
billing data and invoices – for the period required by tax and accounting law;
data processed on the basis of the Controller's legitimate interest (including security logs) – until an effective objection is raised under Art. 21 GDPR or the purpose of processing ceases;
data processed in connection with handling enquiries – for the period necessary to handle the request.
2. The User's personal data will additionally be processed for the purpose of establishing, pursuing or defending against claims for the applicable limitation period.
Providing personal data is voluntary. However, failure to provide personal data may result in the inability to create an Account, use a given functionality of the Service, access certain content, or the impossibility of performing a service or completing an order.
The User's personal data is not subject to automated decision-making, including profiling as referred to in Art. 22 GDPR, that produces legal effects concerning the User or similarly significantly affects them. The Controller may carry out statistical analyses of the use of the Service that do not produce such effects.
1. The Service uses only strictly necessary (technical) cookies, required for the proper operation of the Service, in particular to maintain the logged-in User's session and ensure security. These are first-party cookies, marked as HttpOnly.
2. As at the date of publication of this Policy, the Service does not use analytics, marketing or advertising cookies, nor any third-party tracking tools. Accordingly, the use of strictly necessary cookies does not require the User's consent.
3. The security and CDN provider layer (Cloudflare) may set its own technical cookies for security and correct traffic routing.
4. Fonts used in the Service are self-hosted; loading them does not involve requests to external font providers.
5. The User can manage cookies from their browser settings (deletion, blocking, incognito mode). Disabling strictly necessary cookies may prevent proper use of the Service (e.g. logging in).
6. If analytics or marketing tools are implemented in the future, the Controller will update this Policy and – where necessary – implement a consent mechanism (a cookie banner).
The Controller uses the following tools and functionalities within the Service:
1. Account in the Service – the Controller enables the creation of an Account to obtain access to purchased content and services. The Account is a set of information, including personal data, about the User and the history of their activity.
2. Payments – payment and subscription handling is provided by the payment operator Stripe. Payment is made on the operator's page; the Controller does not store payment card data.
3. Invoices – the issuing and handling of invoices is provided by InFakt; for this purpose the Controller transfers the User's billing data.
4. Video materials – video materials are hosted and streamed via the Cloudflare Stream service. Access to the materials is secured (signed, time-limited playback URLs).
5. E-mail messages – the Controller sends e-mail messages (including a welcome message with a password-setup link, password-reset messages, and subscription and payment messages) via the Resend service.
6. Newsletter – the Controller may process subscribers' data (first name, e-mail address) in order to send the newsletter on the basis of consent. A subscriber may withdraw consent at any time.
7. Analytics and marketing tools – the Service does not use analytics tools (e.g. Google Analytics) or marketing/tracking tools (e.g. Meta Pixel, Google Ads).
1. Using the Service involves sending requests to the server. In order to ensure security, the Controller keeps event logs, including, among others, the IP address, browser/device information, and events such as logins, failed login attempts and password resets. Unlike standard server logs, some of these events are linked to the User's Account and used solely for security, audit, and establishing, pursuing or defending against claims (Art. 6(1)(f) GDPR).
2. The Controller continuously analyses whether personal data is processed securely and takes measures to ensure that cooperating entities guarantee the application of appropriate security measures.
1. The Privacy Policy is regularly reviewed and amended where necessary.
2. The Controller encourages Users to check the content of this document regularly.
3. The most recent version of the Privacy Policy is published in the Service at leksykon.app/page/privacy.
Date of publication: 1 July 2026