Privacy
Privacy policy
Version: 2026-08-27 · effective 27 August 2026
1. Who is responsible for your data?
The controller of personal data processed to operate Didaxi is:
Matimenti Marcin Kobuszewski, a sole proprietorship operated by Marcin Kobuszewski, using the Didaxi trading name, registered in the Central Register and Information on Economic Activity (CEIDG), business address: 07-411 Ławy, Ławy 91A, correspondence address: 07-411 Ławy, Ławy 91A, NIP: 7582274330, REGON: 526832383 (the “Operator”, “Didaxi”, “we”, “us”).
Contact:
- privacy and data-rights requests: privacy@didaxi.net;
- general support: support@didaxi.net;
- postal correspondence: 07-411 Ławy, Ławy 91A;
- data protection officer: none appointed; privacy questions and data-rights requests go to privacy@didaxi.net.
The Service is available at https://didaxi.net.
2. Scope and roles
This Policy applies to visitors, registered readers, creators, buyers, seller representatives, and people who contact us.
The Operator controls account administration, platform operation, security, platform billing, support, and its own legal compliance. A creator decides what creator content to upload and publish. If creator content contains another person's personal data, that creator may be a separate controller and must have a lawful basis and provide any required information. The Operator may host such data to provide the Service. Didaxi is offered to individuals. It is not offered to schools or institutions, so no arrangement is made for an institution to place other people's data in a workspace; that would require a separate agreement before any such use.
If your personal data appears in creator content, contact the creator where identified or contact us at privacy@didaxi.net. We will assess the request, preserve applicable rights, and route it to the responsible party where appropriate.
Do not upload special-category data, medical data, government identifiers, financial credentials, confidential student records, or other third-party personal data unless the intended use is expressly supported by Didaxi and you have documented authority to process it.
3. Data we process
Depending on how you use Didaxi, we process:
- Account and identity data: email address, password hash, first and last name, language, email-confirmation status, account role, administrator flag, and account timestamps.
- Authentication and security data: session-token hashes, confirmation and password-reset records, encrypted administrator MFA secret, MFA challenge records, session/device timestamps, IP address, user agent, request/security events, audit logs, rate-limit events, and incident information.
- Policy evidence: policy key, exact version and status, language, document path, acceptance source and time, IP address, and user agent.
- Workspace and creator data: workspace name and slug, public profile/about text, creator status, plan and quota settings, memberships, taxonomies, drafts, documents, bundles, courses, publications, access settings, sharing tokens, and related metadata.
- Uploaded and generated content: files, images, PDFs, text assets, filenames, MIME type, size, checksums, titles, descriptions, OCR inputs/results, prompts, selected context, AI responses, and content metadata. Content may contain personal data if a user puts it there.
- Usage and operational data: actions in the Service, feature usage, AI/OCR consumption, timestamps, statuses, errors, technical logs, and support diagnostics.
- Communications: support requests, complaints, notices, email address, message content, delivery status, and email-queue metadata.
- Billing and transaction data: buyer type, name, invoice email, address, country, currency, plan, billing interval, amount, VAT breakdown/status, purchase status, seller/buyer identifiers, Stripe customer/session/payment/subscription/account identifiers, refund status, and timestamps. Didaxi does not intentionally store full payment-card numbers or CVC codes; those are entered into Stripe.
- Public and social actions: public creator/publication content, follows, bookmarks, access grants, and publication purchase entitlements.
- Seller data: declared trader/non-trader status, public legal/trading name, address, email, telephone, country, applicable registration/tax identifiers, confirmation time, the seller snapshot accepted for an order, Stripe connected-account identifier, onboarding/status information returned by Stripe, payout/sales aggregates, and transaction data. Stripe may independently collect identity, bank, tax, and verification documents that are not stored in Didaxi's application database.
We do not currently use external advertising trackers or analytics SDKs identified in the application code.
4. Where data comes from
We obtain data:
- directly from you when you register, configure a profile, create or upload content, buy or sell, use AI/OCR, or contact us;
- automatically from your browser/device and our infrastructure when you use the Service;
- from Stripe regarding checkout, subscriptions, payments, refunds, disputes, seller onboarding, and payouts;
- from OpenAI and Mathpix as responses and technical usage information when you request those optional features;
- from creators when they publish content or administer access and sales;
- from public registers or competent authorities where verification or legal compliance requires it.
5. Why we use data and our legal bases
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Create, authenticate, and administer an account; provide reader and creator features | Account, session, workspace, content, settings | Contract or steps requested before contract, Article 6(1)(b) |
| Host, render, share, publish, and provide purchased access to content | Content, profile, access and entitlement data | Contract, Article 6(1)(b); legitimate interests in operating user-directed publishing, Article 6(1)(f) |
| Provide optional AI drafting and OCR at the user's request | Prompts, selected context/content, files/images, outputs, usage | Contract, Article 6(1)(b); the user chooses each submission |
| Process Premium billing, publication checkout, seller onboarding and payouts | Contact, billing, transaction, Stripe identifiers | Contract, Article 6(1)(b); legal obligations, Article 6(1)(c); fraud/payment security interests, Article 6(1)(f) |
| Maintain accounting, tax, consumer, and transaction evidence | Billing, purchase, seller and communication records | Legal obligation, Article 6(1)(c) |
| Send confirmation, security, service, purchase and billing messages | Email, name, event and message data | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c); legitimate interests in reliable service communication, Article 6(1)(f) |
| Send optional marketing communications | Email and communication preferences | Consent, Article 6(1)(a), together with applicable electronic-communications rules |
| Secure the Service, prevent abuse/fraud, diagnose failures, and enforce terms | IP, user agent, logs, sessions, audit events, content and transaction signals | Legitimate interests in security and legal claims, Article 6(1)(f); legal obligation where applicable, Article 6(1)(c) |
| Record policy acceptance and transaction/withdrawal evidence | Versioned evidence, IP, user agent, timestamps | Legal obligation, Article 6(1)(c); legitimate interests in demonstrating the contract and compliance, Article 6(1)(f) |
| Support users, handle complaints, rights requests, notices, and disputes | Account, communications, content, transaction and verification data | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c); legal claims, Article 6(1)(f) |
| Moderate illegal or prohibited content and protect users/third parties | Content, account, reports, audit evidence |
Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Withdrawal does not affect processing required for the contract, law, security, or legal claims.
6. AI drafting and OCR
AI and OCR are optional and run only after a user requests them.
- OpenAI: Didaxi sends the instruction, current/selected educational content, and any selected OCR context to the OpenAI API and receives generated text. Didaxi stores prompts, context, responses, model/usage data, status, and bounded error information for 12 months, or until the workspace is deleted, whichever comes first. OpenAI states that API inputs and outputs are not used to train its models by default.
- Mathpix: Didaxi sends the selected source image, filename, and MIME type to the Mathpix API and requests text/LaTeX/HTML extraction with
improve_mathpix: false. Didaxi stores the result and usage/status records for 12 months, or until the workspace is deleted, whichever comes first. Mathpix is established in the United States, and the transfer relies on the standard contractual clauses in its data-processing agreement.
Do not submit third-party personal data or confidential material to either feature unless you have authority and understand the provider transfer. AI/OCR output may be inaccurate; users must review it before use or publication. Didaxi does not use AI output to make decisions producing legal or similarly significant effects about individuals.
7. Payments and creator sales
Stripe receives information required for payment, fraud prevention, regulatory checks, subscriptions, connected-account onboarding, and payouts. Stripe may act as Didaxi's processor for some activities and as an independent or joint controller for its own regulated, fraud-prevention, and compliance purposes. Consult Stripe's privacy information presented during checkout/onboarding.
For creator-publication purchases, Didaxi currently makes the buyer's name, email address, purchase amount, VAT breakdown, status, and timestamp visible to the creator's workspace. This disclosure must be limited to data necessary for contract performance, accounting, complaints, and lawful seller obligations. The Creator is the seller of record for their own publications: the payment is taken on their own payment account and they decide refunds, so they receive this data as a controller in their own right and are responsible for it accordingly.
8. Who receives data
Data may be disclosed, only as needed, to:
- personnel and contractors authorized by the Operator under confidentiality and access controls;
- SEOHOST, in Poland, for application hosting, the database and backups;
- Cloudflare Ireland Ltd for object storage of uploaded files and related delivery and security services. The storage bucket currently carries no jurisdictional restriction, so files may be held outside the European Economic Area under Cloudflare's data-processing agreement;
- the Operator's own mail relay and SEOHOST, in Poland, for transactional email;
- Stripe entities, financial institutions, payment networks, verification providers, and connected sellers for payments, fraud prevention, regulatory checks, and payouts — Stripe Payments Europe, Limited, Dublin, Ireland;
- OpenAI for user-requested AI drafting — OpenAI Ireland Ltd; no data residency is configured, so processing may take place in the United States;
- Mathpix for user-requested OCR — Mathpix, Inc., United States;
- YouTube (Google) or Vimeo when a viewer chooses to load an embedded external video; those providers receive network/browser information and may process data under their own notices;
- creators/sellers where required to provide access, sales records, complaints, or refunds;
- professional advisers, auditors, insurers, and potential business successors subject to appropriate safeguards;
- courts, regulators, tax, law-enforcement, and other authorities where disclosure is legally required or necessary to protect rights.
An up-to-date list of processors and subprocessors is published at https://didaxi.net/processors.
9. International transfers
Some providers or their subprocessors process data outside the European Economic Area, including in the United States. Each such transfer relies on European Commission Standard Contractual Clauses in the relevant provider's data-processing agreement, unless another lawful safeguard is stated for it.
Where the data sits: hosting, the database, email delivery and backups are provided by SEOHOST in Poland, with no transfer outside the European Economic Area; object storage is provided by Cloudflare Ireland Ltd; payments are handled by Stripe Payments Europe, Limited in Ireland; AI drafting uses OpenAI Ireland Ltd and OCR uses Mathpix, Inc. in the United States, both of which may involve processing outside the European Economic Area under the standard contractual clauses in their data-processing agreements. Write to privacy@didaxi.net for a copy of the safeguards.
10. Retention
We keep data only for as long as the purpose, the law, security or legal claims require:
| Record | Intended period/criterion |
|---|---|
| Unconfirmed account and confirmation records | Confirmation codes 15 minutes; unconfirmed accounts deleted after 7 days |
| Active account, workspace, private content and settings | While the account is active, then removal within 30 days subject to exceptions below |
| Object-storage files after deletion | Best-effort immediate deletion, incident follow-up if deletion fails, and removal within 30 days |
| Backups | 30 days; isolated from ordinary use and removed through rotation |
| Financial, purchase, invoice, VAT and payout evidence | The statutory tax and accounting period |
| Policy/withdrawal/contract evidence | The applicable limitation period; kept after account deletion as evidence of agreement |
| Security, authentication, audit and incident logs | 12 months |
| Support, complaint and rights-request correspondence | 24 months |
| Email queue content and delivery metadata | Message bodies 90 days; delivery metadata 12 months |
| AI prompts, context, responses and errors | 12 months, or until the workspace is deleted, whichever comes first |
| OCR results and local OCR usage records | 12 months, or until the workspace is deleted, whichever comes first |
| Public content after account closure | Removed with the account, except material with completed purchases, which stays available until the guaranteed access term expires |
| Data required for existing or anticipated claims | The applicable limitation period, extended for data relevant to a live dispute |
Provider-side copies follow the verified provider contracts and deletion mechanisms. Erasure may be restricted where data is necessary for legal obligations, freedom of expression/information, or establishing, exercising, or defending legal claims.
11. Your rights
Subject to applicable conditions, you may request:
- access to and a copy of your personal data;
- correction of inaccurate or incomplete data;
- erasure;
- restriction of processing;
- portability of data you provided where processing is automated and based on consent or contract;
- objection to processing based on legitimate interests, and an unconditional objection to direct marketing;
- withdrawal of consent;
- information about relevant international-transfer safeguards;
- not to be subject to a solely automated decision with legal or similarly significant effects, where applicable.
Send requests to privacy@didaxi.net. We may need proportionate information to verify identity and protect other people. You may complain to the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl) or another competent supervisory authority. Contacting us first is optional.
12. Is providing data mandatory?
Account, authentication, and core service data are contractually required; without them we cannot create or operate an account. Billing/payment data is required to purchase or sell. Data required by tax, consumer, payment, or anti-fraud rules may be legally required. AI and OCR submissions and optional marketing consent are voluntary; declining them does not prevent use of unrelated core features.
13. Cookies and device storage
Didaxi uses a strictly necessary authentication session cookie to keep signed-in users authenticated and secure the Service. It is HTTP-only and subject to the configured session expiry of up to 30 days. Necessary storage does not require optional marketing consent but must still be disclosed.
No optional analytics or advertising storage was identified in the reviewed code. If it is added, Didaxi will update this Policy and obtain any consent required before storing or accessing information on a user's device.
Creator content may contain YouTube or Vimeo embeds. Nothing is requested from those providers until you choose to play a video: until then the page shows a placeholder and makes no connection to them. When you do play one, the provider receives your IP address and browser information and may access storage on your device. YouTube embeds use youtube-nocookie.com.
14. Security
We use measures appropriate to risk, including password hashing, hashed session tokens, mandatory TOTP MFA for platform administrators, access controls, TLS through service providers, signed payment webhooks, scoped storage credentials, audit records, rate limits, backups encrypted at rest and restorable only by the Operator, and incident procedures owned by the Operator, with security reports to security@didaxi.net and supervisory-authority notification within 72 hours where required. No system is completely secure. Report suspected compromise to security@didaxi.net.
15. Children
Reading published material requires no account and has no minimum age. An account may be created from 16, and buying or selling requires 18. Both minimums are confirmed by the person at the point they apply, and the confirmation is recorded with the same evidence as the policy acceptances. Didaxi does not verify age by document and does not knowingly process the data of a child below the account minimum; if you believe it holds such data, write to privacy@didaxi.net and it will be removed.
16. Changes to this Policy
We will publish the version and effective date. Material changes will be communicated in a durable or prominent form appropriate to their impact. Where a new purpose requires consent, we will request it before processing. A privacy notice is information about processing; users are asked to acknowledge reading it, not to waive data-protection rights.
17. Contact
- Questions and rights requests: privacy@didaxi.net
- Security reports: security@didaxi.net
- General support: support@didaxi.net
- Postal address: 07-411 Ławy, Ławy 91A