
PRIVACY POLICY
WWW.DOBROSIENIESIE.PL
1. About US
- The owner of www.dobrosieniesie.pl and the administrator of personal data collected through the Website is the DOBRO SIĘ NIESIE FOUNDATION with its registered office at: ul. Hugona Kołłątaja 84, 61-421 Poznań, Poland, email address: maciej@dobrosieniesie.pl. (Administrator)
- The Service Provider operates the Website and is responsible for the proper provision of the Website's Electronic Services.
2. GENERAL PROVISIONS
- This Website Privacy Policy is a measure implemented by the Administrator, the purpose of which is to define the actions taken by the Administrator regarding the protection of personal data made available to the Administrator by data subjects. Furthermore, it aims to inform data subjects about the procedure for handling personal data in force at the company run by the Administrator, including in particular the purposes and legal bases for processing, as well as the categories of recipients to whom personal data processed by the Administrator is further transferred. It also fulfills the Administrator's obligation to inform data subjects arising from Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119 of 4.5.2016, p. 1, hereinafter referred to as „GDPR”) in other respects.
- The service provider exercises special care to protect the interests of data subjects, and in particular ensures that the data collected by it are processed lawfully; collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; factually correct and adequate in relation to the purposes for which they are processed, and stored in a form which permits the identification of data subjects for no longer than is necessary to achieve the purpose of processing.
- This Website Privacy Policy is for informational purposes only, meaning it does not create any obligations for the Website Users.
- Any words, phrases, and acronyms appearing on this page and starting with a capital letter (e.g., Service Provider, Internet Service, Electronic Service) shall be understood in accordance with their definition contained in the Internet Service Regulations, available on the Internet Service pages.
- The User's personal data is processed in accordance with the GDPR, the Act of May 10, 2018 on the Protection of Personal Data (hereinafter referred to as the Personal Data Protection Act), and the Act on the Provision of Electronic Services of July 18, 2002 (Journal of Laws of 2002, No. 144, item 1204, as amended).
3. PURPOSE AND SCOPE OF DATA COLLECTION
- Each time, the purpose, scope, and recipients of the data processed by the Service Provider result from the actions taken by the Service Recipient on the Website. For example, if the Service Recipient intends to use the Account, their personal data will be processed for the purpose of concluding and performing the contract for the use of the Account.
- The Administrator processes personal data concerning the Service User or their representatives for the following purposes:
- entering into and performing an agreement for the use of the Electronic Service,
- fulfilling obligations arising from legal provisions, including tax and accounting regulations,
- conducting court, arbitration, administrative, administrative court, enforcement, and mediation proceedings,
- documenting contractual relationships for evidentiary purposes for the period of the statute of limitations for claims related to them,
- conducting direct marketing of services or goods offered by the Administrator, including via email newsletters,
- handling of complaints and claims arising from warranty rights
- The Service Provider may process the following personal data of Service Recipients using the Online Service:
- Service recipient's full name,
- email address,
- Name of Cooperating Organization,
- Name of Collaborating Organization Branch,
- Providing personal data, as mentioned in the above point, is not mandatory, but it is necessary for the conclusion and performance of the contract for the provision of the Electronic Service on the Website. The scope of data required for the conclusion of the contract is each time indicated beforehand on the Website page, during the use of the Website, and in its Regulations.
- Personal data concerning the User may be transferred to public administration bodies or to other third parties or entities to the extent and in cases where the law obliges the Administrator to disclose them. Furthermore, personal data concerning the User may also be transferred to entities performing accounting, bookkeeping, and legal services for the Administrator based on a separate agreement.
- The Administrator declares that they have implemented appropriate technical and organizational measures to ensure an adequate level of security corresponding to the risk associated with the processing of personal data entrusted to them, as referred to in Article 32 of the GDPR. The Administrator regularly reviews and updates the technical and organizational measures they use to ensure an adequate level of protection for the entrusted personal data.
- The Administrator declares that in order to ensure the security of personal data processing, they have introduced a Personal Data Protection Policy. The Personal Data Protection Policy is a measure implemented by the Administrator in accordance with Article 24(1) and (2) of the GDPR, the purpose of which is to introduce a procedure for handling personal data in the company run by the Administrator, based on which its processing by the Administrator will comply with the GDPR.
- Processing of personal data within the scope of the purposes indicated above in point 3(2) includes, in particular, their collection, modification, storage, review, updating, analysis, and archiving.
- The service provider also processes anonymized data related to the use of the Internet Service (e.g., number of Service Recipients) to generate service usage statistics. This data is aggregate and anonymous, i.e., it does not contain characteristics identifying persons using the Service.
- Personal data relating to the User shall be stored by the Administrator for the following period:
- in the case of personal data, for which the legal basis for processing by the Controller is the fact that it is necessary for the proper performance of the contract – until the expiry of claims arising from this contract,
- in the case of personal data processed by the Controller based on a legitimate interest – until this legal basis for processing ceases to apply, in particular until the statute of limitations for the Controller's claims and the User's claims arising from their legal relationship expires, the legal existence of the Controller ceases, or a legally binding or final determination, adjudication, satisfaction, or defense of a claim or other right of the Controller or User in court, arbitration, administrative, administrative court, enforcement, or mediation proceedings takes place,
- in the case of personal data, for which the basis for their processing is that it is necessary to fulfill the legal obligations incumbent upon the Administrator – until this basis for processing ceases to exist.
4. COOKIES AND USAGE DATA
- The service provider does not process data contained in cookies when using the website.
5. LEGAL BASIS FOR DATA PROCESSING
- The provision of personal data by the Service Recipient is voluntary. However, failure to provide personal data indicated on the Website and in the Website's Regulations, which is necessary for the conclusion and execution of the electronic service agreement, will result in the inability to conclude said agreement.
- The legal basis for processing personal data for the purpose specified above in point 3(2)(a) is that it is necessary for the performance of a contract. The legal basis for processing personal data for the purpose specified above in point j3(2)(b) is that it is necessary for the fulfillment of legal obligations incumbent upon the Administrator. The legal basis for processing personal data for the other purposes indicated above in the point is the legitimate interest pursued by the Administrator.
6. DATA SUBJECT RIGHTS RELATED TO PERSONAL DATA PROTECTION
A. Right to information
- Administrator, when obtaining personal data, is obliged to provide the person from whom the data originates with all of the following information:
- its identity and contact details and, where applicable, the identity and contact details of its representative,
- when applicable – Data Protection Officer contact details,
- purposes of personal data processing, and the legal basis for processing,
- information about recipients of personal data or about categories of recipients, if they exist,
- when it applies – information about the intention to transfer Personal Data to a third country or an international organization,
- the period for which the personal data will be stored, and where that is not possible, the criteria used to determine that period,
- information on whether the provision of personal data is a statutory or contractual requirement or a condition for concluding a contract, whether the data subject is obliged to provide it, and what the possible consequences of not providing the data are.
- If the Administrator intends to further process personal data for a purpose other than that for which the personal data were collected, they are obliged to inform the data subject of this other purpose and provide them with all other relevant information before such further processing.
B. Right to withdraw consent for personal data processing
- The data subject has the right to withdraw their consent to the processing of personal data at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
C. Right of access to personal data
- The data subject has the right to obtain from the Controller confirmation as to whether personal data concerning him or her are being processed, and where that is the case, the right to access them and the following information:
- processing fees;
- categories of personal data concerned;
- information about recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- the planned period for which the personal data will be stored, or, where that is not possible, the criteria used to determine that period;
- information on the right to request from the Administrator the rectification, erasure, or restriction of the processing of personal data, and to object to such processing;
- information on the right to lodge a complaint with a supervisory authority;
- If personal data have not been collected from the data subject – any available information relating to their source;
- information about automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR, and – at least in those cases – meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
- The controller is obliged to provide the data subject with a copy of personal data. The controller may charge a reasonable fee based on administrative costs for any further copies requested by the data subject. If the data subject requests a copy electronically, and unless otherwise indicated, the information is provided by commonly used electronic means.
D. Right to request correction and erasure of personal data
- The data subject has the right to request from the Controller the immediate rectification of personal data concerning him or her that is inaccurate. Taking into account the purposes of processing, the data subject has the right to request the supplementation of incomplete personal data, including by means of a supplementary statement.
- The data subject is entitled to request the Controller to immediately erase personal data concerning them, and the Controller is obliged to erase personal data without undue delay if one of the following circumstances occurs:
- personal data are no longer necessary for the purposes for which they were collected or otherwise processed,
- the data subject has withdrawn consent on which the processing is based pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal ground for the processing,
- the data subject objects to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) GDPR,
- personal data was processed unlawfully,
- personal data must be erased in order to comply with a legal obligation to which the Controller is subject under Union law or the law of a Member State.,
- personal data has been collected in connection with the offering of information society services referred to in Article 8(1) of the GDPR.
- The data subject's rights indicated in point 2 above shall not apply to the extent that the processing is necessary for exercising the right to freedom of expression and information, for the establishment, exercise or defense of legal claims, to comply with a legal obligation requiring processing under Union or Member State law to which the Controller is subject, or to perform a task carried out in the public interest or in the exercise of official authority vested in the Controller, for reasons of public interest in the area of public health, in accordance with Article 9(2)(h) and (i) of the GDPR and Article 9(3) of the GDPR, for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes in accordance with Article 89(1) of the GDPR, provided that such right is likely to render impossible or seriously impair the achievement of the objectives of that processing.
- The administrator is obliged to inform the data subject about the rectification or erasure of personal data, unless it proves impossible or requires disproportionately significant effort.
Right to restriction of processing of personal data
- The data subject has the right to request that the controller restrict the processing of their personal data in the following cases:
- The data subject disputes the accuracy of the personal data – for a period allowing the Controller to verify their accuracy,
- processing is unlawful, and the Data Subject objects to the erasure of personal data, requesting instead restriction of their use,
- The administrator no longer needs personal data for processing purposes, but it is needed by the data subject for the establishment, exercise, or defense of claims.,
- The data subject objected to the processing under Article 21(1) of the GDPR, pending verification of whether the controller's legitimate grounds override the data subject's grounds for objection.
- The administrator is obliged to provide the data subject with information about the restriction of personal data processing, unless it proves impossible or would require disproportionately significant effort.
F. Right to data portability
- The data subject has the right to receive in a structured, commonly used, machine-readable format personal data concerning him/herself which he/she has provided to the controller, and has the right to transmit such personal data to another controller without hindrance from the controller, where the processing is carried out by automated means and a) based on consent of the data subject or b) is necessary for the performance of a contract.
- In exercising the right specified above, the data subject has the right to request that personal data be transferred by the Controller directly to another controller, provided that it is technically possible. This right does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller. This right may not adversely affect the rights and freedoms of others either.
G. Right to object and rights related to automated decision-making in individual cases
- The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
- If personal data are processed by the Controller for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for such marketing, including profiling, to the extent that the processing relates to such direct marketing.
- If the data subject objects to the processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
- If personal data are processed for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the GDPR, the data subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
- The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her, unless that decision: (a) is necessary for the entering into or the performance of a contract between the data subject and a data controller; (b) is authorised by Union or Member State law to which the data controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or (c) is based on the data subject’s explicit consent.
7. FINAL PROVISIONS
- The Online Service may contain links to other websites. The Service Provider encourages you to review the privacy policy established on those sites after visiting them. This privacy policy applies only to the Online Service.
- The administrator properly provides the following technical measures to prevent unauthorized persons from acquiring and modifying personal data transmitted electronically:
- Securing a dataset against unauthorized access;
- In all matters relating to personal data processing, including in particular matters related to the provisions of this privacy policy, the Service User should contact the Administrator using the following contact details:
THE GOODNESS SPREADS FOUNDATION ul. Hugona Kołłątaja 84, 61-421 Poznań, Poland, e-mail address: maciej@dobrosieniesie.pl
