Terms of Service
Terms of Service for TheSecondStep.net
Last updated: February 13, 2024
Table of Contents
-
Subject Matter
-
Definitions
-
User Access to Service Resources / User Registration
-
Obligations of the Service Administrator
-
Obligations of the User
-
Blocking Access to the Service
-
Liability of the Parties
-
Processing of Personal Data of Service Users / Information Clause
-
Final Provisions
I. SUBJECT MATTER
These "Terms of Service for https://thesecondstep.net" define the rules for users' free use of contractual services, i.e., content and functionality offered within the online courses published at https://thesecondstep.net.
Use of the services takes place in accordance with the provisions of this document, together with the principles set out in the Terms and Conditions (https://thesecondstep.net/info/terms-of-service).
II. DEFINITIONS
Terms used in the "Terms of Service for https://thesecondstep.net" (hereinafter: "Terms") mean:
DeoLink Association (hereinafter: DeoLink) / Service Administrator – a registered association with its registered office in Wisła (43-460), ul. Malinka 65D/2, https://deolink.org, KRS number 0000160777, NIP 5481580840.
Service – the website https://thesecondstep.net
Service Resources – content and services made available within the Service, on the terms and to the extent set out in these Terms, in particular its open section and the section requiring registration (Contractual Services).
Contractual Service – any course available in the Service, the use of which is based on an agreement concluded between the User and the Service Administrator, under the terms described in these "Terms of Service for https://thesecondstep.net."
User – a natural person with a User Profile, using the Service Resources to the extent provided for in these Terms. In addition to course participants, Users also include volunteers and associates of the Service Administrator who provide support during the use of Contractual Services (answering course participants' questions).
User Profile – an encrypted space within the Service, accessible only to the person who created it (User registration), by providing a login (email address) and setting a password. The Profile stores the User's data and history of use of Contractual Services.
Regulation 2016/679 – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).
III. USER ACCESS TO SERVICE RESOURCES / USER REGISTRATION
-
Access to the portion of the Service containing information about Contractual Services and their technical and organizational aspects is not conditional on the User completing any formalities, and in particular is not conditional on registration in the Service system.
-
Access to Contractual Services is conditional on registration in the Service system, which proceeds as follows:
-
Option I: Registration via the Service
-
The visitor selects a course by clicking the "Sign up" button.
-
The visitor enters their email address, sets a password, and reviews the terms of the course use agreement (Contractual Service) available at the provided link.
-
The User Profile is created and the User gains access to the selected course (Contractual Service) as well as the ability to sign up for any other course available in the Service — without the need to register again.
-
Option II – Registration via external services
-
The Service allows account registration using external services such as Facebook. The number of such options may increase over time.
-
For certain Contractual Services and any potential needs expressed by the User (such as mailing materials in paper form), it may be necessary to provide selected additional data, e.g.:
-
First name or nickname
-
Email address
-
Notes – a free-text field at the User's discretion
-
Creating a User Profile constitutes the conclusion of an agreement between the User and the Service Administrator. The subject of the agreement is the use of Contractual Services in accordance with the rules set out in these Terms.
-
In emergency situations, the main Service Administrator may also have access to the User's profile.
-
Users' systems should have cookies and JavaScript enabled.
IV. OBLIGATIONS OF THE SERVICE ADMINISTRATOR
-
The Service Administrator provides visitors to the Service and active Users with free access to the relevant portion of the resources — for an indefinite period.
-
If a User does not log into their User Profile for a period exceeding 12 months, the Service Administrator reserves the right to deactivate the Profile (delete the User's account from the Service) — after first notifying the User of such intent.
-
The Service Administrator undertakes to use the personal data provided by the User solely for the purposes and to the extent specified in Section VIII of these Terms.
V. OBLIGATIONS OF THE USER
-
The User is obliged to use the Service in compliance with applicable law, the provisions of these Terms, and good practices.
-
The User is entitled to use the Service Resources exclusively for their own personal use — for the purpose of using the Contractual Service.
-
To use data and any other materials contained in the Service — whether or not they are subject to copyright protection — in any way other than using the Contractual Service, the User must obtain prior written consent from a person authorized to represent the Service Administrator. To obtain consent, a written request (by post or email) must be submitted to the contact address provided in the Service.
-
The User is entitled to use the Service Resources exclusively for their own personal use. This means in particular that with respect to data and any other materials contained in the Service Resources, whether or not subject to copyright protection, use of such materials for the User's commercial activities is not permitted.
-
The User is obliged to provide accurate information (personal data) during registration.
-
The User is obliged to keep their personal data up to date.
-
The User is obliged to keep their individual password confidential and to protect it from access by third parties.
-
The User is obliged to refrain from actions that may hinder or disrupt the functioning of the Service, in particular actions that may impair other users' use of the Service.
-
The User is obliged to refrain from actions that may violate the privacy of other users, in particular collecting, processing, and distributing information about other users without their explicit consent, as well as from violating the confidentiality of correspondence.
-
The User is obliged not to use the Service — directly or indirectly — to send unsolicited commercial communications / spam.
-
If the format of a Contractual Service enables or assumes the option of a Participant inviting or sharing course content with a third party — which would involve providing personal data such as the third party's name and email address — the Participant must first ensure that the third party has consented to this.
-
The User is obliged to refrain from actions that damage the reputation of the Service Administrator and entities cooperating with it.
-
The User is obliged not to impersonate other persons.
VI. BLOCKING ACCESS TO THE SERVICE
-
The Service Administrator reserves the right to block access to the Service at any time in the event of a User's violation of the terms of use, in particular in situations involving:
-
providing false personal data,
-
sharing their login and/or password with third parties,
-
violating good practices, including with respect to the content of information and texts posted in the Service, as well as in relation to the Service Administrator.
-
Blocking access to the Service is equivalent to termination of the Contractual Service agreement.
VII. LIABILITY OF THE PARTIES
-
The Service Administrator is not liable for instances of unavailability of Service Resources resulting from failures of IT systems or telecommunications networks, nor for other consequences of faulty telecommunications connections and damages caused thereby.
-
The Service Administrator's liability, regardless of its legal basis, is limited to cases of damage caused by willful misconduct and to the amount of actual loss incurred, excluding lost profits.
-
The Service Administrator makes every effort to ensure that the proposed content is of the highest quality and provides maximum benefit to the User. However, the Administrator is not liable for the manner of use or suitability of the Service Resources for the purposes intended by the User, nor for the absence of functionality not expressly included in the specific scope of a given Contractual Service. We note that the Service does not provide professional addiction therapy, psychotherapy, or crisis intervention services. In such cases, we recommend contacting appropriate institutions or organizations — contact details for selected ones can be found in the Service Resources. The Service Administrator is not liable for the methods, quality, or outcomes of services provided by those entities, as they are entirely independent of the Service Administrator.
-
The User bears full responsibility to third parties for the content of information and texts they post in the Service.
-
The User is liable for damages resulting from disclosure of their individual login and/or password to unauthorized parties.
VIII. PROCESSING OF PERSONAL DATA OF SERVICE USERS
-
Personal data of users who have duly completed the registration process in the Service are processed in accordance with personal data protection regulations and DeoLink's internal procedures.
-
Activating and maintaining a User Profile is deemed to constitute the User's ongoing (regular) contact with DeoLink (Service Administrator), which forms the basis for potential processing of special categories of data within the meaning of Article 9(2)(d) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: Regulation 2016/679).
-
The information clause on the processing of personal data is contained in Annex 1 to these Terms.
-
Information on any transfers of personal data to third countries within the meaning of Regulation 2016/679 is contained in Annex 2 to these Terms.
-
Exercising the right to deletion of data from the Service is carried out in particular through the "Edit profile – delete user account" function.
-
Exercising the right to deletion of data from the Service is equivalent to the User's deregistration from the Service. The User's profile data and all messages from individual courses are deleted; in courses in which other persons participated, the User's data are anonymized.
IX. FINAL PROVISIONS
-
In the event of a change to these Terms, Users will be notified by posting the updated Terms on the Service website.
-
Neither party may transfer rights arising from the Agreement to a third party without the written consent of the other party.
-
https://thesecondstep.net/contact
-
Disputes arising in connection with the performance of the Contractual Service shall be resolved amicably.
-
In the absence of an amicable resolution, disputes between the parties shall be submitted to the court having jurisdiction over DeoLink's registered office.
Annex 1 – Information Clause on the Processing of Personal Data
In accordance with Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: Regulation 2016/679), each Service User is informed that:
-
The controller of your personal data is DeoLink, with its registered office in Wisła (43-460), ul. Malinka 65D/2, KRS number 0000160777, NIP 5481580840 (hereinafter: Data Controller).
-
The Data Controller has appointed a Data Protection Officer, who can be contacted at:
-
Your personal data will be processed for the purpose of:
-
Enabling participation in a course (performance of the Contractual Service) pursuant to Article 6(1)(b) of Regulation 2016/679, i.e., processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, and — with respect to special categories of data — Article 9(2)(d) of Regulation 2016/679, i.e., processing carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association, or any other not-for-profit body with a political, philosophical, religious, or trade-union aim, on condition that the processing relates solely to the members or former members of the body or to persons who have regular contact with it in connection with its purposes, and that the personal data are not disclosed outside that body without the consent of the data subjects;
-
Initiating subsequent contact with the User as a person using content offered by the Data Controller, for the purpose of informing them about other services and events they may be interested in, as well as for conducting analyses aimed at improving the offer and User service, pursuant to Article 6(1)(f) of Regulation 2016/679, i.e., for the purpose of pursuing the Controller's legitimate interests.
-
If, in the course of a Contractual Service, the situation referred to in Section V.11 arises, DeoLink provides the third party with information on the processing of their personal data — in the manner provided for in Article 14 of Regulation 2016/679.
-
Personal data will not be transferred to other entities, except for entities authorized to process them under applicable law and entities providing services necessary for ongoing operations, with which the Data Controller has concluded data processing agreements in accordance with Article 28 of Regulation 2016/679.
-
Your personal data will be processed for the duration of the Contractual Service — until the User Profile is deleted or until an objection to processing is raised for data processed on the basis of Article 6(1)(f) of Regulation 2016/679. In special circumstances, data may be processed for the period required by applicable law, including until the expiry of:
-
the limitation period for any claims related to performance of the agreement,
-
the mandatory documentation period for tax authorities. The longest period applies.
-
In connection with the processing of data, you have the following rights:
-
In all cases:
-
the right of access to your personal data, pursuant to Article 15 of Regulation 2016/679;
-
the right to rectification of your personal data, pursuant to Article 16 of Regulation 2016/679;
-
the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office — if you consider that data are being processed in a manner inconsistent with applicable law;
-
the right to request restriction of processing of personal data from the controller, pursuant to Article 18 of Regulation 2016/679 — subject to the cases referred to in Article 18(2)–(3) of Regulation 2016/679;
-
the right to object to processing, pursuant to Article 21 of Regulation 2016/679, and the right not to be subject to a decision producing legal effects concerning you, based solely on automated processing, including profiling, pursuant to Article 22 of Regulation 2016/679 — with respect to data processed on the basis of the Controller's legitimate interests;
-
the right to data portability, pursuant to Article 20 of Regulation 2016/679 — with respect to data processed on the basis of Article 6(1)(b), where processing is carried out by automated means;
-
the right to request erasure of data, pursuant to Article 17 of Regulation 2016/679 — where data are no longer necessary for the purposes for which they were collected or otherwise processed, or the data subject objects pursuant to Article 21(1) to the processing and there are no overriding legitimate grounds for processing, or the data subject objects pursuant to Article 21(2) to the processing (i.e., an objection to processing for direct marketing purposes).
-
At the same time, you do not have:
-
the right to data portability, pursuant to Article 20 of Regulation 2016/679 — where the legal basis for processing is Article 6(1)(f) of Regulation 2016/679;
-
the right to object to processing, pursuant to Article 21 of Regulation 2016/679 — where the legal basis for processing is Article 6(1)(b) of Regulation 2016/679;
-
the right not to be subject to a decision producing legal effects concerning you, based solely on automated processing, including profiling, pursuant to Article 22 of Regulation 2016/679 — where the legal basis for processing is Article 6(1)(b) of Regulation 2016/679;
-
the right to withdraw consent to the processing of personal data — as in every case the legal basis for processing is a ground other than the consent of the data subject.
-
Providing personal data to the extent necessary to create a User Profile is a contractual requirement, and failure to provide such data will result in the inability to perform the Contractual Service.
-
Your personal data in the form of contact and statistical data may be transferred to third countries in connection with the use by the Controller or entities acting on its behalf of IT systems and tools provided by globally operating organizations. In every such case, the Controller guarantees the existence of necessary data protection measures in the form of standard contractual clauses approved by the European Commission, or the use of data processing in countries for which the European Commission has issued an adequacy decision. A detailed list of such potential transfers is contained in the "Data Controller's Information on Transfer of Data to Third Countries" set out below.
-
Your personal data may be subject to profiling (e.g., for the purpose of sending an email with a proposal for a subsequent course); however, we will not make any decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Annex 2 – Data Controller's Information on Transfer of Data to Third Countries
Pursuant to Article 13(1)(f) of Regulation 2016/679, the Data Controller is obliged — where applicable — to provide information on:
-
the intention to transfer personal data to a third country or international organization,
-
whether or not the Commission has determined an adequate level of protection, or, in the case of a transfer referred to in Article 46, 47, or Article 49(1) second subparagraph of the GDPR, a reference to the appropriate or suitable safeguards and information on how to obtain a copy of them or where they have been made available.
In reference to the above, DeoLink Association, with its registered office in Wisła, ul. Malinka 65D/2 (43-460), hereinafter also referred to as the "Data Controller," informs that in the course of providing services and delivering content, there is a likelihood of transfer of collected personal data (including metadata) of users, contractors, or donors to third countries within the meaning of the GDPR. The detailed list of entities to which data may be disclosed, together with the purpose of processing and information on the safeguards applied, is contained in the table below:
| Entity name – country of registration |
Purpose of processing |
Type of safeguards / how to obtain a copy or where they are made available |
| Salesforce.com, Inc. (USA) |
Technical maintenance of user databases, content and services provided by the Controller, its contractors and donors |
1) Data processing agreement provisions: https://www.salesforce.com/con... 2) Standard contractual clauses (amendment to the processing agreement): https://www.salesforce.com/con... 3) Binding corporate rules: https://www.salesforce.com/con... |
| Google LLC (USA) |
Traffic analysis (user behavior) on websites and effectiveness of marketing campaigns (Google Analytics) |
1) European Commission adequacy decisions and standard contractual clauses: https://policies.google.com/pr... 2) Description of safeguards and GDPR compliance, including use of standard contractual clauses: https://business.safety.google... 3) Data security for Google Ads: https://business.safety.google... |
| Meta (formerly: Facebook) (USA) |
Use of the login mechanism for services via a user account created on Facebook. |
1) Standard contractual clauses: https://www.facebook.com/help/... 2) Data security officer's statement on secure data transfer: https://about.fb.com/news/2021... |