Online Personal Trainer Course: €99 · offer for 10 new learners!

View the offer →
PFA
PFA Academy
Menu

PFA Academy

Online Personal Trainer Course

€99 · Offer for 10 new learners!

View the course offer

Privacy and cookies

PFA Academy Privacy Policy.

Information about the data we process when you use the website, learner account, online courses, forms, payments and certificates, as well as cookies, analytics and Google Ads and Meta/Facebook campaigns.

1. Data controller

The controller of personal data processed through PFA Academy is Bartłomiej Romanowski, operating under the PFA Academy / Pro Fitness Academy brand.

For privacy and personal data enquiries, contact biuro@pfa.edu.pl or +48 790-314-021.

The same email address is used to handle requests relating to personal data, marketing consent, forms, learner accounts, payments, certificates and complaints.

2. What data may we process?

Learner account data: first name, surname, email address, user identifier in the authentication system, sign-in method and information needed to manage the account.

Course data: the course purchased, access status, learning progress, completed module quizzes, final exam result, course completion date and certificate status.

Certificate data: full name, course name, certificate number, issue or completion date, certificate language and verification status.

Payment data: order status, Stripe session identifier, amount, currency, payment status and basic information needed to assign course access to the account.

Form data: full name, email address, phone number, subject, message, selected city, experience level, the course the enquiry concerns and contact consents.

Technical data: IP address, browser type, device information, referring page, security logs, event times and information needed to operate the website and prevent misuse.

3. Why we process data

Creating and managing learner accounts, sign-in and dashboard access.

Providing the online course, recording progress and managing quizzes, the final exam and certificates.

Handling purchases, payments, access activation, complaints, refunds and technical issues.

Handling contact forms, registrations of interest in in-person courses and interest lists for planned courses.

Providing public certificate verification using a document number or QR code.

Keeping the platform secure, detecting misuse, diagnosing errors and improving website performance.

Carrying out analytics and marketing activities, including Google Ads and Meta/Facebook, only in accordance with the consents given and cookie settings selected.

4. External tools and service providers

Clerk may handle sign-in, registration and user accounts.

Supabase may store course data, form submissions, access statuses, quiz results, exams, certificates and technical application data.

Stripe processes online payments and may process the data needed to complete transactions.

Vercel may provide hosting, deployment and the technical operation of the website.

Google may be used for analytics, conversion measurement, Google Ads, Google Tag Manager or similar functions once an appropriate consent mechanism has been implemented.

Meta Platforms may be used for Meta Pixel, event and conversion measurement through the Conversions API, and campaigns on Facebook and Instagram, only after the relevant marketing consent has been given.

Data may be entrusted to providers only to the extent needed to operate the platform, deliver services, maintain security, process payments or carry out analytics or marketing in accordance with the user’s consent.

5. Forms and consent to contact

Submitting a contact form, registering interest in an in-person course or joining an interest list requires the information needed to handle the enquiry.

Consent to contact about a specific enquiry is used to handle that enquiry and does not automatically mean consent to a newsletter or general marketing.

Marketing consent, where included in a form, should be voluntary and separate from the consent needed to handle the enquiry.

Users can request deletion of their submission or ask us to stop contacting them by writing to biuro@pfa.edu.pl.

6. Public certificate verification

The certificate verification page allows the authenticity of a document to be checked using its certificate number or QR code.

Public verification may display only the information needed to confirm the document, such as the holder’s full name, course name, completion date, certificate number and document status.

Public verification should not display the learner’s email address, detailed exam result, private account information or learning history.

7. Cookies and similar technologies

The website may use cookies and similar technologies to support website operation, sign-in, security, saved preferences and essential platform features.

Essential cookies are needed for the website to work and should not be disabled through the consent banner, as the platform may not function correctly without them.

Analytics cookies may be used to measure visits, traffic sources and user behaviour on the website.

Marketing cookies may be used for conversion measurement, remarketing and advertising campaigns, including Google Ads and Meta/Facebook.

Analytics and marketing cookies should only be activated after the user has given the relevant consent, where consent is required by law or the tool provider’s rules.

The website provides a cookie consent management tool that allows users to accept all optional cookies, reject them or adjust analytics and marketing consent separately.

8. Google Ads, Meta/Facebook, analytics and user consent

If PFA Academy enables Google Ads, Google Analytics, Google Tag Manager or conversion measurement, the website should communicate the user’s consent choices to Google’s tools.

After marketing consent has been given, Meta Pixel may record page views and events during the purchase journey. The server may send a confirmed purchase event through the Meta Conversions API, including the amount, currency, transaction identifier and data used for matching and deduplication.

Data sent to Meta for matching may include a hashed email address and a hashed stable account identifier, as well as _fbp and _fbc identifiers, the IP address and browser information, where collected after marketing consent.

Users should be able to accept, reject or adjust consent for optional cookies, including analytics and marketing cookies.

Declining marketing or analytics cookies may limit advertising measurement and analytics, but should not prevent access to essential website features.

9. How long we keep data

Account and course data may be stored for as long as the account is active, the course remains accessible or certificate records need to be maintained.

Certificate data may be kept for longer to allow documents to be verified using their certificate number.

Form submissions are stored for the period needed to handle the enquiry, coordinate course arrangements or carry out activities to which the user has consented.

Order and payment data may be stored for the period required to handle sales, complaints, accounting and legal obligations.

Technical data and logs may be kept for as long as needed for security, diagnostics and the prevention of misuse.

10. Your rights

Users may request access to their data, correction or deletion of their data, restriction of processing or data portability, or object to certain processing activities.

Users may withdraw consent where processing is based on consent.

Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

For personal data enquiries, users can contact PFA Academy at biuro@pfa.edu.pl.

Users have the right to lodge a complaint with the competent supervisory authority if they believe their data is being processed in breach of applicable rules.