FortepianArt – International Music Hub
Privacy policy
Last updated: 29 September 2026
This policy explains what personal data FortepianArt collects through this website, the student & teacher portal and our email addresses, why we use it, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
The data controller is FortepianArt – International Music Hub, run by Maryna Rak (Founder & Director), ul. Pastewna 25, 02-972 Warszawa, Poland — Trinity College London Registered Exam Centre No. 76372.
For any privacy question or request, write to info@fortepianart.com or call +48 575 403 537.
2. What data we collect
- Enquiries — when you use the “Book a lesson” form, your own email app sends us an email with your name, email, phone number, chosen programme and message. We also receive any email you send to our @fortepianart.com addresses.
- Portal accounts (created by the school for its students and teachers) — name, email, phone, age group, instrument(s), level, parent or guardian details for students under 18, notes, role (student, teacher, admin), assigned teachers, preferred language and the date of your last sign-in.
- Learning records — lessons (date, time, place), lesson notes, homework and feedback, Trinity exam entries (instrument, grade, exam date, status, result) and files shared with you (for example sheet music).
- Sign-in and security data — your password (stored only as a secure hash), a sign-in cookie, one-time sign-in links, a log of important actions (for example sign-ins, approvals and changes to accounts), and technical data such as IP address that our hosting provider processes to deliver the site and protect it from abuse.
- Google sign-in (optional) — if you choose “Continue with Google”, Google tells us your name and verified email address. We do not receive your Google password or anything else from your account.
We do not use analytics, advertising or tracking cookies, and we do not sell or share your data for marketing.
3. Why we use it and on what legal basis
- To answer enquiries and set up portal accounts — steps taken at your request before or under an agreement (Art. 6(1)(b) GDPR).
- To organise lessons, homework, performances and Trinity exam preparation and registration — performance of our agreement with you (Art. 6(1)(b)).
- To keep accounts secure and prevent misuse — our legitimate interest in protecting the service and its users (Art. 6(1)(f)).
- To meet accounting and legal obligations where they apply (Art. 6(1)(c)).
4. Children
Many of our students are children. For students under 16, the portal account is set up at the request of a parent or legal guardian, and we keep the guardian’s contact details. Parents may contact us at any time to see, correct or delete their child’s data.
5. Who we share data with
Only with service providers we need to run the school and this website, under data processing terms:
- Cloudflare, Inc. — hosting of the website and portal, database, file storage, email forwarding and protection against attacks.
- Google — only if you choose Google sign-in; the school’s mailbox also uses Gmail.
- Resend — delivery of portal emails such as sign-in links.
- Trinity College London — the details needed to register a candidate for a Trinity exam (only for students entered for an exam).
Some of these providers may process data outside the European Economic Area. Where this happens, transfers are protected by the European Commission’s adequacy decisions (for example for the United Kingdom and the EU–US Data Privacy Framework) or by Standard Contractual Clauses.
6. How long we keep data
- Sign-in sessions end after 60 days without use; one-time sign-in links expire after 7 days (email links after 20 minutes).
- The security activity log is deleted automatically after 24 months.
- Accounts and learning records are kept while you study or teach with us. After an account is deactivated we review it at least once a year and delete it when it is no longer needed, or earlier at your request. Exam results may be kept longer where needed to confirm a qualification.
- Emails are kept only as long as needed to answer them and to keep our records.
7. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw consent at any time (this does not affect processing before withdrawal). To use any of these rights, write to info@fortepianart.com. We will reply within one month.
You can also lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
8. Cookies and local storage
We only use what is strictly necessary for the site to work:
fa_session— keeps you signed in to the portal (up to 60 days).fa_oauth— protects the Google sign-in step (10 minutes).- Your browser’s local storage remembers your chosen language and light/dark mode on this device.
Fonts are served from our own website, so no data is sent to font providers.
9. How we protect your data
All traffic is encrypted (HTTPS). Passwords are never stored in readable form — only a salted, slow hash (PBKDF2) — and one-time links are stored only as fingerprints. Repeated wrong passwords lock the account for 15 minutes. Only people the school has added can use the portal, each person only sees the records they are allowed to see, and requests are rate-limited to prevent abuse.
10. Changes
We may update this policy when our services change. The date at the top shows the latest version.