Personal Data Privacy Policy
Applicable to the online service: https://takpelnosprawni.org
Effective from: September 16, 2024
§1. Definitions
- Personal Data Privacy Policy – this Policy, which defines the purposes and scope of data processing, the entities to whom the data will be transferred, as well as the rights of persons whose data are concerned, in connection with the use of the Website’s services.
- Personal Data Controller, Operator – the entity deciding on the purposes and means of data processing. The Personal Data Controller of the Users of the Website is: Fundacja TAKpełnosprawni
a. address of registered office: Taczaka 24 lok 103, 61-819 Poznań, Poland
b. correspondence address: Taczaka 24 lok 103, 61-819 Poznań, Poland - Data Subject – a natural person who, when using the Website, provides personal data in order to sign up for the newsletter or to make contact via the contact form.
- Website – the website available at https://takpelnosprawni.org by means of which the User can browse the content of blog posts, sign up for the newsletter, or contact the Personal Data Controller.
- User – a person who voluntarily uses the services and content available on the Website, i.e. browses the pages of the Website, registers an account, subscribes to the free newsletter, or contacts the owner of the Website via the contact form.
- Newsletter – one of the services provided electronically on the Website, consisting of sending marketing information via email to the email address provided by the User, with the User’s prior consent.
- Contact Form – one of the services provided electronically in the Shop by the Seller, allowing the Buyer to send an inquiry to the Seller via a dedicated form on the Shop’s page.
- Personal Data – all information that, without excessive time and cost, can lead to the identification of a natural person, including identifying information, address, and contact data.
- Data Processing – performing operations on personal data, such as collecting data, modifying data, archiving data, or deleting data.
§2 General Provisions:
- This Privacy Policy applies to the Website operating at the URL: https://takpelnosprawni.org/
- The operator of the Website and the Personal Data Controller is: Fundacja TAKpełnosprawni.
- The Operator is the Controller of your personal data with regard to data voluntarily provided on the Website.
- In view of the protection of the privacy of individuals whose data may be processed by the Personal Data Controller in connection with the use of services provided on the Website, this Privacy Policy has been implemented.
- The data subject will learn the most important information regarding the principles of processing their personal data and the rights they are entitled to in connection with such processing.
- Personal data are processed in accordance with applicable laws, including: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the Act of 10 May 2018 on Personal Data Protection, and the Act of 18 July 2002 on the provision of electronic services.
- The Data Controller applies appropriate technical and organizational measures to protect the processed data against threats and categories of data covered by protection, in particular securing data against access by unauthorized persons, taking by unauthorized persons, processing in violation of the law, and alteration, loss, damage, or destruction.
- The Data Controller has developed and implemented internal data security policies that must be followed by all employees and collaborators.
- Access to personal data is restricted only to authorized persons who are required to keep the data and the methods of securing them confidential.
- This Privacy Policy applies to all persons using and services provided on the Website, in particular:
a. persons browsing the content of the Website,
b. persons ordering the free subscription service (Newsletter),
c. persons contacting the Data Controller via the contact form, by telephone or by email.
§3 Purposes and scope of data processing:
- Personal data are collected directly from data subjects, in particular through:
a. filling out the contact form when submitting an inquiry via the form on the Website,
b. filling out the newsletter subscription form,
c. providing data by telephone,
d. providing data by sending an email,
e. storing cookies on end devices, in accordance with the Cookie Policy. - The Personal Data Controller processes personal data for the following purposes:
a. responding to an inquiry via the contact form available on the Website – processing is based on Art. 6(1)(b) GDPR – it is necessary to take action at the request of the data subject before concluding a contract. Data provided in the form are processed for the purpose indicated by the specific form, e.g. handling a service request, commercial contact, service registration, etc. The context and description of the form always clearly inform about its purpose.
b. sending the Newsletter and related commercial and marketing information electronically – processing is based on Art. 6(1)(a) GDPR – when the data subject has given their voluntary consent. The Website sends the Newsletter only to individuals who have confirmed their subscription and have expressed a desire to receive commercial and marketing information.
c. marketing of the Shop’s own products and services – processing is based on Art. 6(1)(f) GDPR – processing is necessary for purposes arising from the legitimate interests pursued by the Data Controller. - The scope of processed personal data is limited to the minimum necessary for the provision of services:
a. in the case of submitting an inquiry via the Contact Form: identification data, phone number, email address, and any other data voluntarily provided by the person in the message,
b. in the case of subscribing to the Newsletter: first name and email address. - Providing data is necessary to receive a response from the Website. Failure to provide the required data makes it impossible to process the request and make contact.
- In the case of ordering the Newsletter, providing data is voluntary but necessary for its delivery.
- In some cases, the Website may record information that facilitates linking form data with the email address of the user filling out the form. In such cases, the user's email address may appear in the URL of the page containing the form.
- The Website may record information about connection parameters (timestamp, IP address).
§4 Selected data protection methods used by the Personal Data Controller:
- Login areas and personal data entry points are protected at the transmission layer (SSL certificate). This ensures that personal data and login credentials entered on the site are encrypted on the user's computer and can be read only on the target server.
- Personal data stored in the database are encrypted in such a way that only the Personal Data Controller, holding the key, can read them. This protects the data in case the database is stolen from the server.
- To protect the data, the Personal Data Controller regularly performs security backups.
- An essential element of data protection is the regular updating of all software used by the Personal Data Controller to process personal data, particularly through regular updates of programming components.
§5 Data retention period:
- Personal data are processed for the period necessary to achieve the purpose for which they were collected, namely:
a. for the period required by other legal regulations, such as tax settlements or issuing an invoice at the request of the data subject – data are stored for 5 years, counting from the end of the calendar year in which the tax payment deadline occurred,
b. until the consent is withdrawn, if data processing is based on the consent of the data subject.
§6 Data recipients:
- Data may be entrusted to other entities in order to perform specific services commissioned by the Data Controller, in particular to entities providing on its behalf:
a. website hosting, maintenance, and IT systems where data are processed,
b. automation – newsletter (email, first name),
c. marketing services on behalf of the Data Controller.
§7 Rights of data subjects:
- The data subject has the right to:
a. access their data and correct them – to do so, please contact the Personal Data Controller,
b. withdraw consent to the processing of personal data at any time, if the processing was based on such consent – in the case of the Newsletter. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal,
c. erase the data (right to be forgotten), unless other legal provisions require the Data Controller to retain the data for a specified period, e.g. under tax regulations,
d. data portability, if the data are processed based on a contract or consent and by automated means,
e. object to the processing of data for direct marketing purposes carried out by the Data Controller under legitimate interest, and to restrict processing,
f. not be subject to automated decision-making, including profiling, if such decisions would produce legal effects or similarly significantly affect the data subject,
g. control the processing of data and obtain information on whether and who is the Data Controller, as well as information about the purpose, scope, and method of data processing, the content and source of the data, and how the data are shared, including recipients or categories of recipients. - The data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office if they believe that the processing of their data is not compliant with the applicable legal regulations.
- To exercise the right to control the data, access the content of the data, rectify them, or exercise other rights, you may contact the Personal Data Controller via the contact form on the Website.
§8 Final provisions:
- The Data Controller reserves the right to amend this Privacy Policy if required by the applied technical solutions or changes in the legal provisions regarding the privacy of Website users.
- If the current Privacy Policy is amended, the above provision will be appropriately modified. The current version of the Privacy Policy will always be posted on the Website, so it is recommended to review the currently applicable document each time you use the Website.