This website uses cookies

Read our Privacy policy and Terms of use for more information.

Privacy Policy

Available in other languages: Deutsch · Hrvatski · Latviešu · Polski

Introduction

At FUNDACJA OŚRODEK KONTROLI OBYWATELSKIEJ OKO, we are committed to protecting your personal data and upholding your rights under European and Polish data-protection laws.

This Privacy Policy explains how we collect, use and safeguard your personal data when you visit the website, engage with our services or interact with us in other ways. It applies to all processing of personal data where FUNDACJA OŚRODEK KONTROLI OBYWATELSKIEJ OKO acts as the data controller. That is, when we determine the purposes and means of processing your data.

In this policy, “we”, “us” and “our” refer to FUNDACJA OŚRODEK KONTROLI OBYWATELSKIEJ OKO, a non-profit legal entity based in Warsaw, Poland.

We process your personal data responsibly, transparently and in compliance with the General Data Protection Regulation (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data (Ustawa o ochronie danych osobowych). Our aim is to ensure you understand what data we collect, why we collect it and how you can exercise your rights.

General information

In accordance with the Polish Act of 10 May 2018 on the Protection of Personal Data and the EU General Data Protection Regulation (Regulation (EU) 2016/679), every individual has the right to the protection of their personal data. We handle your data in compliance with that legal framework and take appropriate technical and organisational measures to protect it against unauthorised access, loss or misuse.

Please note that data transmission over the internet, for example via email, may be subject to vulnerabilities. While we work with secure hosting providers to safeguard our systems, full protection cannot be guaranteed.

The website may be used without registration. We may store anonymised usage data, such as accessed pages and timestamps, for analytical purposes. Any personal data, such as your name or email address, is collected voluntarily and is not shared with third parties without a lawful basis.

Processing of personal data

Personal data is any information relating to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, regardless of the means and procedures used, including storage, disclosure, collection, deletion, modification, destruction and use of personal data.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.

The legal bases for processing are set out in Article 6(1) GDPR, including:

  • Consent: when you have given clear permission for a specific purpose;
  • Contract: when processing is necessary for a contract or steps prior to a contract;
  • Legal obligation: when required to meet a legal duty;
  • Vital interests: to protect someone’s life or safety;
  • Legitimate interest: for our justified interests unless overridden by your fundamental rights.

We process personal data for the duration required for the relevant purpose or purposes. Where longer retention is required by legal or other obligations, we restrict processing accordingly.

Transfer of personal data

As part of our processing of personal data, data may be transferred to other bodies, companies, legally independent organisational units or persons or disclosed to them. Recipients may include service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we observe the legal requirements and conclude appropriate contracts or agreements with recipients to protect your data.

Data processing in third countries

If we process data in a third country, meaning outside the European Union or European Economic Area, or if processing takes place through third-party services or the disclosure or transfer of data to other persons, bodies or companies, this will only take place in accordance with legal requirements.

Subject to express consent or transfer required by contract or law, we process data in third countries only where there is a recognised level of protection, through the European Commission’s standard contractual clauses, or where certifications or binding internal data-protection rules are in place, in accordance with Articles 44 to 49 GDPR.

Relevant legal bases

  • Consent: Article 6(1)(a) and Article 7 GDPR.
  • Contractual necessity: Article 6(1)(b) GDPR.
  • Legal obligation: Article 6(1)(c) GDPR.
  • Vital interests: Article 6(1)(d) GDPR.
  • Legitimate interests: Article 6(1)(f) GDPR.

Security measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with legal requirements. These include safeguards for the confidentiality, integrity and availability of personal data, as well as controls on access, input, disclosure and storage.

We also have procedures to support data-subject rights, data deletion and incident response. Data protection is considered from the outset in our choice of systems and processes, following privacy-by-design and privacy-by-default principles.

Website privacy policies

Privacy policy for cookies

This website is run using Beehiiv Inc., 228 Park Avenue South, Suite 2329976, New York, NY 10003, United States. Beehiiv uses cookies, which are text files stored by your browser to retain data about your visit, such as language settings, login status or viewed content. The term also covers similar technologies that serve the same purpose, including pseudonymous user identifiers.

You can find more information in Beehiiv’s Privacy Policy.

Privacy policy for contact form

If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We will not pass on this data without a lawful basis.

Newsletter – Beehiiv

We use Beehiiv to manage and send our newsletters. The platform allows us to maintain subscriber lists, design campaigns and analyse engagement metrics. Beehiiv processes personal data on our behalf under appropriate data-processing arrangements.

The legal basis for sending the newsletter is your consent under Article 6(1)(a) GDPR.

Privacy policy for newsletter data

If you would like to receive the newsletter offered on this website, we require an email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected.

We use this data exclusively for sending the requested information and do not pass it on to third parties without a lawful basis.

You can revoke your consent to the storage of your data, your email address and its use for sending the newsletter at any time, for example via the unsubscribe link in the newsletter.

Rights of data subjects

Under the General Data Protection Regulation (GDPR), any person whose personal data is processed is entitled to exercise the following rights. To do so, you may contact us at [email protected].

Right to confirmation

You have the right to request confirmation as to whether your personal data is being processed.

Right to access

You have the right to access your personal data and to obtain information about:

  • The purposes of processing;
  • The categories of personal data processed;
  • The recipients or categories of recipients to whom the data has been or will be disclosed;
  • The envisaged storage period or the criteria used to determine it;
  • The existence of the right to rectification, erasure, restriction or objection;
  • The right to lodge a complaint with a supervisory authority;
  • Where data was not collected from you, any available information about its source; and
  • Whether the data has been transferred to a third country or international organisation.

Right to rectification

You have the right to request the correction of inaccurate personal data and the completion of incomplete data.

Right to erasure (right to be forgotten)

You may request the deletion of your personal data without undue delay, in particular when:

  • The data is no longer necessary for the purposes for which it was collected;
  • You withdraw consent and no other legal ground applies;
  • You object to processing and no overriding legitimate grounds exist;
  • The data was unlawfully processed;
  • Erasure is required by a legal obligation; or
  • The data was collected in relation to services offered to a child.

Right to restriction of processing

You may request restriction of processing where:

  • The accuracy of the data is contested;
  • Processing is unlawful, but erasure is opposed;
  • The data is no longer needed for processing but is required for legal claims; or
  • An objection to processing is pending verification of overriding grounds.

Right to data portability

You have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible and legally permitted.

Right to object

You may object, on grounds relating to your particular situation, to the processing of your personal data. Processing must cease unless compelling legitimate grounds are demonstrated, or the data is required for legal claims.

Right to withdraw consent

You have the right to withdraw consent to the processing of your personal data at any time.

Right to lodge a complaint

You have the right to lodge a complaint with the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.

International data transfers

We use Beehiiv to provide and manage the newsletter. Beehiiv and some of its service providers may process personal data outside the European Economic Area, including in the United States.

Where personal data is transferred outside the EEA, appropriate safeguards are used in accordance with applicable data-protection law, including the EU–US Data Privacy Framework where applicable and the European Commission’s Standard Contractual Clauses.

General disclaimer

All content on this website and newsletter is reviewed with care, and we aim to provide accurate, up-to-date and complete information. However, we cannot guarantee the absence of errors or the accuracy and timeliness of all content. We accept no liability for damages arising from the use of the website and newsletter, unless due to wilful misconduct or gross negligence.

Content may be modified or removed at any time without notice. Use of the website and newsletter is at your own risk. We are not liable for the content or availability of third-party sites linked here; responsibility lies solely with their operators.

Changes

We may amend this Privacy Policy at any time without prior notice. The current version published on this website shall apply. If the data-protection declaration is part of an agreement with you, we will inform you of the change by email or other suitable means in the event of an update.

Questions regarding data protection

If you have any questions about data protection, please send us an email at [email protected].