Research and educational use only. Vea is not a certified medical device and is not intended for diagnosis or treatment. Read the full statement

Legal

Privacy policy

This explains what personal data this website collects, why, on what legal basis, and what you can require of us. It is written to be read rather than to be survived.

Last updated: 10 August 2026

1. Who is responsible for your data

The controller of your personal data is VIRTUAL SIMULATIONS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office at ul. Stefana Batorego 18/108, 02-591 Warszawa, Poland, entered in the National Court Register under KRS 0001030848, NIP 9492260555, REGON 525034751.

For anything in this policy, including any request about your data, write to support@virtual-simulations.pro. A person reads that address; you do not need to use a particular form of words.

2. Please do not send us patient data

We do not ask for, and do not want, identifiable patient information. Do not attach imaging studies or clinical records to a contact form or a first email. When a case genuinely needs to be looked at together, we agree a route that satisfies your institution's rules first — and very often the right answer is that the data never leaves your network at all.

3. What we collect, and why

When you send an enquiry

The contact form collects your name, email address and message, and optionally your institution, role and country. We use it to answer you and to keep a record of the conversation. The legal basis is our legitimate interest in responding to people who write to us (Article 6(1)(f) GDPR), or the steps taken at your request before entering into a contract (Article 6(1)(b) GDPR) where the enquiry concerns a possible order.

When you book training

Booking collects your name, email address, billing address, country, and optionally your institution, VAT or tax number and any scheduling note you write. We need these to perform the contract with you (Article 6(1)(b) GDPR), to determine the correct tax treatment, and to keep accounting records as required by Polish law (Article 6(1)(c) GDPR).

These details are collected by us, on this website, and passed to our payment service provider so that the payment page is prefilled and the tax is calculated against the right country. That provider acts as merchant of record for the sale and issues the corresponding tax documentation. Your card details are never sent to this website and we never see them — they are entered on the provider's own secure payment page.

When you simply read the site

Our hosting provider records standard server logs — IP address, time, the page requested, the browser's user-agent string — as every web server does. These are used to keep the site running and to investigate abuse or faults, on the basis of our legitimate interest in the security and stability of the service (Article 6(1)(f) GDPR).

We do not run analytics, advertising or tracking scripts of any kind. There is no tracking pixel, no advertising network, no cross-site profiling, and nothing on this site is loaded from a third-party content network — the fonts, images and scripts all come from this domain.

4. Who else sees your data

We do not sell personal data and we do not share it for anybody else's marketing. It is disclosed only to the categories of recipient needed to run the service:

  • Our hosting provider, which stores the website and its email.
  • Our payment service provider, which processes payments and acts as merchant of record for training sales.
  • Our accountants, for the records that tax law requires us to keep.
  • Public authorities, where we are legally obliged to provide information.

Some of these providers may process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision of the European Commission or by standard contractual clauses. If you want to know the specific arrangements that apply to your data, ask us and we will tell you.

5. How long we keep it

DataKept for
Enquiries and the correspondence that followsUp to 24 months from the last message, unless it becomes part of a contract
Order and billing recordsAs long as accounting and tax law requires — currently five years from the end of the accounting year
Training scheduling notesUntil the program has been delivered, then with the order record
Server logsShort-term, as set by our hosting provider, typically no more than 12 months

6. Your rights

Under the GDPR you may ask us to:

  • confirm what data we hold about you and give you a copy of it;
  • correct anything inaccurate or incomplete;
  • erase it, where we have no continuing legal reason to keep it;
  • restrict how we use it while a dispute about it is resolved;
  • provide it in a portable, machine-readable form, where processing is based on consent or a contract and is automated;
  • stop processing based on legitimate interests, by objecting to it.

We answer within one month. If you think we have handled your data badly, please tell us first — but you are entitled to complain directly to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, or to the authority in your own country of residence.

7. Automated decisions

We do not make decisions about you by automated means, and we do not profile you. Anti-fraud checks carried out by our payment service provider on a transaction are that provider's own processing; if a payment is declined on those grounds, tell us and we will arrange another way to pay.

8. Cookies

This site sets one strictly necessary cookie, and no others. The detail is on the cookie policy page.

9. Changes

If this policy changes materially we will update the date at the top and, where the change affects an active customer, tell them directly. Older versions are available on request.