User manualChapter 11
11. Rules, data security and GDPR
This chapter explains in plain language who is responsible for your data, where the legal documents are, how cookie consent works, how to use your GDPR rights, how your account and files are protected, what others can see about you and how to unsubscribe from emails. The legal documents on the website are always what counts. This chapter only summarises them.
11.1. Who is responsible for your data
What it is for: so you know who to contact about your data, a purchase or an invoice.
Who can see it: everyone.
Where to find it: the footer of every page → Privacy policy, Data protection and DPA.
Cohorta and the academy
| Who | Role for the data | What it covers |
|---|---|---|
| YES FOR sp. z o.o., the operator of the Cohorta platform | Controller of your account data on the platform | Account, login, security, system emails, payments for the Cohorta subscription |
| The academy (the company or person running it) | Controller of the data it enters and collects in its academy | Learners, customers, community members, enrolments, progress, certificates |
| YES FOR sp. z o.o. for the academy's data | Processor, acting on the academy's instructions under the data processing agreement (DPA) | Storing and handling the data the academy keeps on the platform |
The Terms of Service add that the academy may be a joint controller of the data of people it invited.
In practice: for your Cohorta account, contact Cohorta. For data in a specific academy (for example what the academy does with your progress or email), contact that academy first.
Who sells the course
- The seller of a course, ebook or membership is the academy, not Cohorta. Cohorta provides the platform and the technical side of payments through Stripe.
- Refunds and invoices for courses are handled by the academy, under the terms in its own rules. Details are in chapter 3 and chapter 12.
- The Cohorta subscription (what the academy pays for the platform) is sold by YES FOR sp. z o.o.
11.2. Legal documents on the website
What it is for: the Terms of Service, the privacy policy, the GDPR notice and the template data processing agreement in one place.
Who can see it: everyone, also without logging in.
Where to find it: the footer at the bottom of every app screen, the login pages and cohorta.pl: Help, Terms of service, Privacy policy, Data protection, DPA. The English site (cohorta.co) has the same documents in English, with a note that the Polish version is legally binding.
How to open the documents
- Scroll to the very bottom of any screen.
- In the footer, click the document name.
- The document opens in the same tab. The version date is at the bottom of each document.
Direct addresses: cohorta.co/terms, cohorta.co/privacy, cohorta.co/gdpr, cohorta.co/dpa (Polish versions: cohorta.pl/regulamin, cohorta.pl/polityka-prywatnosci, cohorta.pl/rodo, cohorta.pl/dpa).
What the Terms of Service say
- Service provider: YES FOR sp. z o.o., based in Kęty, Poland.
- Creating an account requires accepting the terms, being 18 or older and giving true contact details.
- The academy admin is responsible for the people they invite and for how their academy is set up.
- Payments are handled by Stripe, VAT invoices are issued through the Fakturownia integration. Consumers have 14 days to withdraw, except for digital content delivered in full after their explicit consent.
- Subscriptions renew automatically until cancelled. Cancellation takes effect at the end of the current period, with no refund for the unused part.
- Content stays the property of its authors. Unlawful content and content that infringes others' rights is not allowed.
- The academy and Cohorta may hide, ban and remove content that breaks the terms. You have the right to appeal a moderation decision.
- Complaints: through the contact form, handled within 14 working days.
What the privacy policy and GDPR notice say
- What data is collected: account data (email, first name, last name, avatar), payment metadata without card numbers, content you create on the platform, technical data (IP address, browser, time of visit), cookies.
- How long it is kept: account data while you use the service and up to 3 years after the account is deleted, accounting records 5 years, technical logs 90 days, marketing data until you withdraw consent or object.
- Who it is shared with: the list of processors (hosting, payments, email, invoicing, analytics) is in the privacy policy and in the annex to the DPA. Some are based in the USA; transfers rely on standard contractual clauses and the Data Privacy Framework.
- Cohorta has not appointed a Data Protection Officer. For data matters, use the contact form or write to YES FOR sp. z o.o., ul. Świętokrzyska 61, 32-650 Kęty, Poland.
- The platform does not make automated decisions about you with legal effects. Automations and gamification are for communication only.
- You have the right to complain to the President of the Polish Personal Data Protection Office (UODO).
Data processing agreement (DPA) for academies
Who it applies to: the academy owner and admins.
- The DPA is a template data processing agreement under Article 28 GDPR. It is binding through accepting the Terms of Service when you run an academy.
- A version for separate signature is available on request through the contact form.
- It covers, among other things, security measures, the list of sub-processors, notifying the academy of a breach within 48 hours of discovering it, deleting or returning data when the service ends, and the right to audit.
- If you use the AI features for outlines and lessons, only the text you enter goes to the model (topic, target group, goal, lesson titles, guidelines). Learners' data is not sent.
11.3. Cookies and consent
What it is for: you decide whether academy pages may use Google analytics cookies.
Who can see it: everyone, on the first visit to any Cohorta page in a given browser.
Where to find it: the cookie banner at the bottom of the screen, with the Essential only and Accept all buttons.
How the banner works
- On your first visit a banner appears at the bottom of the screen with the text "We use essential cookies to run the platform. With your consent we will also enable analytics cookies (Google Analytics) that help us improve the service."
- The Privacy policy link in the banner opens the full description.
- Choose one option:
- Essential only: only the cookies needed for login and for remembering your preferences (theme, language) are used.
- Accept all: Google analytics cookies are turned on as well.
- The banner disappears and the page follows your choice straight away.
How to change your choice
- Clear the cookies for cohorta.co (or cohorta.pl) in your browser settings.
- Open the site again.
- The banner appears again and you can choose once more.
There is no separate button in the app for changing consent. Clearing cookies logs you out of Cohorta, so log in again afterwards.
What happens automatically
- Your choice is remembered for 6 months. After that the banner asks again.
- Google Analytics and Google Tag Manager load only on product sales pages and on the page after a purchase, and only when the academy has entered its Google ID and you chose Accept all. With Essential only, Google scripts do not load at all.
- If you arrive through a referral link (an address with ref= in it), the browser remembers the referral code for 30 days. This way the person who referred you gets their commission if you buy.
- Cohorta also counts visits to its pages in aggregate, without cookies and without an identifier that could track you across sites.
11.4. Your rights: access, export and deletion of data
What it is for: you use your GDPR rights: access, correction, deletion, restriction, portability, objection and withdrawing consent.
Who can see it: everyone.
Where to find it: you exercise these rights by contacting Cohorta or the academy. Account settings have no button for downloading all your data or deleting your account.
How to ask for a copy of your data or its deletion
- Work out who the request is for (section 11.1). Data in a specific academy: the academy first. Your Cohorta account: Cohorta.
- Write to support@cohorta.pl from the address your account uses. You can also use the form at cohorta.co/contact.
- Say what you want: a copy of your data, a correction, account deletion or an objection to marketing.
- Cohorta replies within one month of receiving the request.
What you can do yourself
- Correct your name, photo, bio and links in My profile (section 1.15).
- Hide your profile from other members and turn off your public profile (section 11.7).
- Turn off event reminders (section 11.8).
- Download your certificates and purchased files (chapter 9).
- Change your password (section 1.5).
You cannot change your account email yourself: write to support@cohorta.pl from both addresses, the old and the new one.
What the academy can export
Who it applies to: the academy owner and admins.
- The member list as a CSV file: Administration → Members → Export CSV (section 8.9).
- The certificate list as a CSV file: Administration → Certificates → Export CSV.
- If a learner asks the academy for their data, the academy can use these exports. For anything it cannot handle itself, Cohorta helps (as stated in the DPA).
What happens after your account is deleted
- You lose access to all purchased courses, including paid ones, and to issued certificates. This cannot be undone.
- Some data is kept for as long as the law requires, for example accounting records for 5 years, and account data for up to 3 years for evidence purposes.
- Being removed from one academy (its admin does this, chapter 7) does not delete your Cohorta account or your access to other academies. You cannot leave an academy yourself: ask its admin.
11.5. Account security
What it is for: you protect your account from being taken over.
Who can see it: everyone with an account.
Where to find it: the login screen (password and changing it through Forgot your password?, section 1.5), the account menu in the top right corner (signing out).
Password
- Your password must be at least 8 characters. That is the technical minimum. A longer password made of a few unrelated words is safer.
- Do not reuse a password from another service.
- If you log in with Continue with Google, you do not need a Cohorta password. You can set one through Forgot your password?.
Attempt limits
| Action | Limit | What you will see |
|---|---|---|
| Logging in to the same email address | 5 attempts in 15 minutes | "Too many login attempts. Please try again shortly" |
| Logging in from the same internet address | 10 attempts in 15 minutes | the same message |
| Creating an account from the same internet address | 5 attempts per hour | "Too many sign-up attempts. Please try again in an hour" |
| Resending the activation link | 3 times per email address in 15 minutes | "Too many attempts. Wait a few minutes and try again." |
The limit protects against password guessing. It is not a penalty. When the time is up you can try again. A password reset through Forgot your password? works even while login is blocked.
Signing out
- Click your photo or initials in the top right corner.
- Choose Sign out.
- Always sign out on someone else's or a shared computer. Signing out applies to the browser where you click it.
What happens automatically
- Your connection to Cohorta is encrypted.
- Each academy's data is kept separate from other academies' data.
- Cohorta records logins, password changes and password reset requests in a security log. Technical logs are kept for 90 days.
- If there is a personal data breach, Cohorta notifies the Polish data protection authority within 72 hours.
Something not working?
- Message "Too many login attempts. Please try again shortly" → wait a quarter of an hour, or set a new password through Forgot your password?.
- Message "Could not log in. Check your email and password." → check that Caps Lock is off and that you are using the address you signed up with.
- Message "Confirm your email address. The link is in the message from Cohorta." → click the link in the activation email.
- Message "The password must be at least 8 characters" → make the password longer.
- You suspect someone knows your password → change it straight away through Forgot your password? and write to support@cohorta.pl.
11.6. Files and access to them
What it is for: you understand how Cohorta protects courses, ebooks, resources and learners' work from outsiders.
Who can see it: everyone who downloads or views files in an academy.
Where to find it: lessons in Learning, Resources, My library, assignments, certificates.
How downloading works
Files in an academy are not stored at a fixed, public address. Each time you click Download or play a video, Cohorta checks that you are allowed to, and only then creates a short-lived link for you.
| File type | How long the link works |
|---|---|
| A resource from Resources | 5 minutes |
| A purchased ebook or digital file | 10 minutes |
| A file submitted for an assignment (for the learner and the grader) | 10 minutes |
| A video uploaded to a lesson | 1 hour |
What this means for you:
- If you copy a file link and send it to someone, it stops working after that time. The other person needs their own access.
- If a download did not start and the tab was open for a long time, click Download again. A new link is created.
- The academy can set a download limit for a file. Once it is used up, downloading is blocked.
- The email link for downloading a file bought without an account works for 90 days after the purchase.
PDF watermark
- The academy can turn on a watermark for PDF files in a product.
- Then each page of the downloaded file has small grey text at the bottom starting with "Licencjonowane dla:" (Licensed to), followed by the buyer's name, email address and the date. The text is always in Polish.
- The watermark shows who bought the file. Do not pass such files on.
Certificates
- You download your PDF certificate from your account. Each certificate has a number and a public verification page (chapter 9).
- The verification page does not show your email address, results or progress.
Something not working?
- Message "The download limit (n) has been reached" → you have used up the limit set by the academy. Contact the academy.
- Message "The link has expired (90 days after purchase). Contact the trainer to extend access." → the email link after buying without an account has expired. Contact the academy.
- Message "Access denied" → you do not have the product the file belongs to, or your access has expired.
- Message "Another download of this file is in progress. Refresh the page and try again" → wait a moment, refresh the page and click Download again.
11.7. What other members can see
What it is for: you know what information about you is visible to others in the academy and outside it.
Who can see it: every academy member.
Where to find it: sidebar → Account → My profile, the Visibility in the academy and Public visibility sections.
What other academy members see
- Next to your posts and comments and in the member directory: your display name, photo, headline, job title, location, bio, links and skills, if you fill them in.
- Your role in the academy, the date you joined, your last activity, points and badges (if gamification is on).
- Your email address is not shown next to posts, in the member directory or on your public profile.
- Only the two of you can see the content of a private conversation. The trainer, moderators and admins cannot see it.
What academy staff see
- Trainers and admins see your course enrolments and progress. This helps them when someone gets stuck.
- Admins see your email address, last activity and your product access on the member list.
- Moderators see reported content but not who reported it. Your report is confidential.
How to hide your profile
- In the sidebar, open Account → My profile.
- In the Visibility in the academy section, turn off Profile visible to other members. Your profile disappears from the member directory. Academy admins can always see you.
- In the Public visibility section, the Show my profile publicly switch decides whether your profile is available at cohorta.pl/profil/… to anyone with the link and to Google. It is off by default.
- When your public profile is on, the Show me in the people directory switch decides whether you appear in the public people directory.
- Click Save changes.
Important: your display name goes on certificates and into the member directory. Your public profile shows the details from the profile form, without your job title.
11.8. Emails and unsubscribing
What it is for: you know which emails you get, who sends them and how to turn them off.
Who can see it: everyone.
Where to find it: the link in the email footer, sidebar → Account → Settings → Notifications.
Which emails you get
| Type | From | Can you turn it off |
|---|---|---|
| Activation link, password reset, purchase confirmation, login link after buying without an account | Cohorta | No, they are needed for your account to work |
| Academy invitation, certificate, notice about a ban | Cohorta on behalf of the academy | No |
| Reminders 24 hours and 1 hour before an event | Cohorta on behalf of the academy | Yes, in notification settings |
| The academy's email campaigns | The academy | Yes, with the Unsubscribe link in the footer |
| The academy's automation emails | The academy | Contact the academy |
| News and tips about the Cohorta product (only for people running academies) | Cohorta | Yes, with the link in the footer |
| Invoice for a course | The seller (the academy), for example through Fakturownia | No |
We do not send emails about new posts, comments or private messages. You see them under the bell in the app.
How to turn off event reminders
- In the sidebar, open Account → Settings.
- In the Preferences section, click Notifications.
- In the Events block, turn off Reminder 24h before the event or Reminder 1h before the event.
- The setting applies to the academy you are in.
How to unsubscribe from Cohorta emails
- Open a Cohorta email with news or tips.
- In the footer, click "Zrezygnuj z subskrypcji" (Unsubscribe). These emails are sent in Polish.
- A page opens with the heading "Unsubscribe from these messages?" and your address. Opening the page on its own changes nothing.
- Click Unsubscribe me. You will see "Done, you will not hear from us again". The page follows your language setting.
- From then on you will not get product news or onboarding tips. Purchase confirmations, invoices and password resets will still arrive.
Emails from the academy
- Campaigns and automation emails are sent by the academy. It decides who receives them.
- You can unsubscribe from campaigns yourself: click Unsubscribe in the email footer. A page saying "Unsubscribe from these messages?" opens with your address and the academy's name. Click Unsubscribe me and you will see "Done, you will not hear from us again". The unsubscribe applies to that academy only. If your email app, for example Gmail, shows an unsubscribe button next to the sender, that button unsubscribes you straight away too.
- Messages about courses you have access to, such as purchase confirmations and event reminders, will still arrive.
- If you do not want automation emails, reply to such an email or contact the academy. Replies go to the address the academy has set.
Something not working?
- After clicking the unsubscribe link I see "Nie rozpoznaliśmy tego linku" (We did not recognise this link) → your email app may have cut the link short. Write to the address shown on that page and we will unsubscribe you by hand.
- I still get emails after unsubscribing → check who they are from. Purchase and password emails always arrive, and emails from the academy are turned off by the academy.
- I do not get any emails at all → see chapter 12.