Skip to content

Privacy policy

God bless you, and welcome!

If you have found your way here, it is a sure sign that you value your privacy. We understand that perfectly, which is why we are placing in your hands a document that gathers in one place the rules on processing personal data and on the use of cookies and other tracking technologies in connection with the operation of the dlcenter.org website.

A formal note to begin with – the administrator of the website is Fundacja Dominikańska, which runs the Dominican Liturgical Center, Stolarska 6/30, 31-043 Kraków, Poland, VAT ID: 6762419775, company register (KRS): 0000354036.

This privacy policy has been written in the form of questions and answers. We chose this form out of concern for the clarity and readability of the information presented to you. Should you have any doubts about this privacy policy, you can contact us at any time by writing to daneosobowe@liturgia.dominikanie.pl.

1. Who is the administrator of your personal data?

The administrator of your personal data is Fundacja Dominikańska, which runs the Dominican Liturgical Center, Stolarska 6/30, 31-043 Kraków, Poland, VAT ID: 6762419775, company register (KRS): 0000354036.

2. Whom can you contact about the processing of your personal data?

In implementing data protection within our organisation, we decided not to appoint a data protection officer, as this is not mandatory in our situation. For matters relating to the protection of personal data and to privacy in the broad sense, you can contact us by e-mail at daneosobowe@liturgia.dominikanie.pl.

3. What information about you do we hold?

Depending on the purpose, we may process the following information about you:

  • first name and surname
  • e-mail address
  • telephone number
  • postal or delivery address
  • data contained in e-mail correspondence
  • the content of a recorded telephone conversation
  • information visible on social media profiles
  • details of orders placed
  • data required to issue an invoice, including company details and VAT ID
  • bank account number
  • data of an event participant, including age or date of birth
  • data of a legal guardian, where the event participant is a minor
  • information about special needs reported when registering for an event, e.g. dietary requirements, allergies, information about health or about being a member of the clergy or of a religious order
  • IP address
  • approximate location
  • statistics relating to the newsletters you receive

Some of the above information constitutes special categories of data within the meaning of Article 9 GDPR – this concerns information about health (including dietary requirements and allergies, which may result from a health condition) and information about being a member of the clergy or of a religious order, which reveals your religious beliefs. Providing this information is always voluntary, and we process it solely on the basis of your explicit consent and solely for the purpose of organising the event properly. We describe the details in the answer to question 22.

Above we have listed specific pieces of information. In Annex 1 to this privacy policy you will find categories of personal data assigned to the individual purposes of processing.

Moreover, we use tools that collect a range of information about you connected with your use of our website. In particular, this concerns the following information:

  • information about your device, operating system and web browser
  • user identifier (user-ID)
  • IP address subject to truncation and anonymisation
  • the date of your visit to the website
  • the subpages viewed
  • time spent on the website
  • movements between individual subpages
  • mouse clicks or screen taps
  • clicks on individual links
  • the source from which you came to the website
  • the age bracket you fall into
  • your gender
  • your approximate location limited to the town or city
  • your interests determined on the basis of your online activity

In the remainder of this privacy policy we refer to this information as “Anonymous Information“.

In our assessment, Anonymous Information does not in itself constitute personal data, because it does not allow us to identify you and we do not combine it with the ordinary personal data we collect about you. Nevertheless, bearing in mind the strict case law of the Court of Justice of the European Union and the divided opinions among lawyers, out of caution, and in case Anonymous Information were to be treated as personal data, we have also included in this privacy policy detailed explanations regarding the processing of that information.

We are not able to give you access to Anonymous Information about you, because we cannot assign any of the Anonymous Information to any specific user. From within the tools that collect Anonymous Information we have access only to a set of statistics and information not assigned to specific individuals. What is more, we have no access at all to the information collected by some of the tools, since all we are interested in is that the function provided by a given tool works correctly, not the information it collects. For example, a particular plugin may collect some information, but it is not made available to us in any way, and we are not interested in that information at all, because all we care about is that a given function of the plugin (e.g. submitting the newsletter form) simply works.

Processing Anonymous Information makes it possible to provide you with the functionality available on the website. In addition, Anonymous Information is used for analytical and statistical purposes as well as for marketing purposes, such as setting up and targeting advertising. To the extent that this involves the use of cookies and similar technologies, it takes place solely after you have given your consent.

Because Anonymous Information is collected by the external tools we use, Anonymous Information is also processed by the providers of those tools under the rules set out in their terms of service and privacy policies.

Anonymous Information is also used by the providers of the individual tools to provide and improve their services, to manage them, to develop new services, to measure the effectiveness of advertising, to protect against fraud and abuse, and to personalise the content and advertising displayed in their services, websites and applications.

The tools we use that involve the collection of Anonymous Information are listed in Annex 2 to this privacy policy.

4. Where did we get your personal data from?

In most cases you give it to us yourself. This happens when you:

  • register a user account
  • place an order in the shop
  • register for an event, or register another person for it, for example as a legal guardian
  • submit a complaint or withdraw from a contract
  • subscribe to the newsletter
  • add a comment or a product review
  • fill in a survey after an event
  • contact us by e-mail or through the contact form
  • call us on the telephone
  • follow our social media profiles or interact with the content we publish on social media

In Annex 1 to this privacy policy we have assigned the source of the data to each purpose of processing.

In addition, some information about you may be collected automatically by the tools we use:

  • the website mechanism collects your IP address
  • the mail delivery system records information about the delivery of a message and, if we use such a feature, also about it being opened and about clicks on the links it contains
  • the telephone exchange saves a recording of the conversation if you call us – we describe the details in the answer to question 21
  • the external tools listed in Annex 2 to this privacy policy collect Anonymous Information connected with the actions you take on the website

5. Is your data safe?

We take care of the security of your personal data. We have analysed the risks involved in the individual processes of processing your data, and then implemented appropriate measures for the security and protection of personal data. We continuously monitor the state of our technical infrastructure, train our staff, review the procedures we apply and introduce the improvements that are needed. Should you have any questions about your personal data, we are at your disposal at daneosobowe@liturgia.dominikanie.pl

6. For what purposes do we process your personal data?

The purposes of processing your personal data are listed in Annex 1 to this privacy policy.

7. How long will we store your personal data?

The storage periods have been indicated separately for each purpose of processing. You will find that information in Annex 1 to this privacy policy. Most data is deleted once the limitation period for claims has expired, whereby the limitation period may differ under the applicable law (for example, it may be 3 years for businesses and 6 years for consumers).

8. Who are the recipients of your personal data?

We would venture to say that present-day activity cannot manage without services provided by third parties. We use such services too. Some of them involve the processing of your personal data. The external service providers who take part in processing your personal data are:

  • the hosting provider, which stores data on its server
  • providers of cloud software in which data is processed
  • the provider of the e-mail delivery service (SMTP) through which we send the newsletter and transactional messages – Mailtrap (mailtrap.io)
  • the provider of the chat system, if you yourself start a conversation with us on the chat
  • the provider of telecommunications services within which recordings of telephone conversations are saved
  • the payment operators handling payments in the shop
  • the accounting office, which processes your data visible on invoices
  • the entity providing technical support services, which gains access to data if the technical work carried out concerns areas in which personal data is held

All the entities listed above process your data on the basis of data processing agreements concluded with us and guarantee an appropriate level of personal data protection.

If the need arises, your data may be disclosed to a legal adviser or attorney bound by professional secrecy. The need may arise from having to obtain legal assistance that requires access to your personal data.

Your personal data may also be transferred to the tax authorities to the extent necessary to fulfil tax, settlement and accounting obligations. This concerns in particular all declarations, reports, statements and other accounting documents containing your personal data.

Your data is made available to courier companies to the extent necessary to deliver an order. Those companies become independent administrators of your personal data. The same applies to payment operators, which are independent administrators of the data within the scope of the transaction carried out.

If the event you are registering for takes place at premises run by another entity (e.g. a retreat house or a monastery providing accommodation and meals), we pass on to that entity the data necessary to provide you with accommodation and meals – including information about dietary requirements, if you have reported any.

Moreover, as regards Anonymous Information, it is accessible to the providers of the tools or plugins that collect Anonymous Information. The providers of those tools are independent administrators of the data collected within them and may share that data under the rules they themselves set out in their own terms of service and privacy policies, over which we have no influence.

9. Do we transfer your data to third countries or international organisations?

Yes, some operations involving the processing of your personal data may entail transferring it to third countries.

We transfer your personal data to third countries in connection with the use of tools that store personal data on servers located in third countries, in particular in the USA. The providers of those tools guarantee an appropriate level of personal data protection through the compliance mechanisms provided for by the GDPR. This concerns in particular the European Commission implementing decision of 10 July 2023 finding an adequate level of data protection under the Data Privacy Framework, and, in the remaining cases, standard contractual clauses.

The tools that involve transferring data to third countries are in particular: cloud software and electronic mail, the analytical and advertising tools listed in Annex 2, the chat system if you yourself start a conversation, and the service that secures the website and speeds up its delivery.

The following information in particular is transferred to third countries: data contained in e-mail correspondence, IP address and Anonymous Information.

At this point we also remind you that we use external tools which may collect Anonymous Information. We have mentioned this several times already in this policy, including in the answer to the previous question. The providers of those tools often use servers located all over the world, in particular in the United States of America (USA), to store the information they collect.

10. Do we use profiling? Do we take automated decisions on the basis of your personal data?

We do not take decisions in relation to you that are based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you.

We do use tools that may take certain actions depending on the information gathered through tracking mechanisms, but we believe that these actions do not significantly affect you, because they do not differentiate your situation as a customer, do not affect the terms of any contract you may conclude with us, and so on.

Using certain tools, we may for example direct personalised advertising to you based on your earlier actions on the website, or suggest products that may interest you. This is what is known as behavioural advertising. This happens only if you consent to marketing cookies. We encourage you to deepen your knowledge of behavioural advertising, in particular as regards privacy matters. You will find detailed information, together with the ability to manage behavioural advertising settings, here.

We stress that within the tools we use we have access only to Anonymous Information. That information is stored on the servers of the providers of the individual tools, and those servers may most often be located anywhere in the world.

11. What rights do you have in connection with the processing of your personal data?

The GDPR grants you the following potential rights connected with the processing of your personal data:

  • the right to access your data and to receive a copy of it,
  • the right to rectify (correct) your data,
  • the right to erasure of data (if in your opinion there is no basis for us to process your data, you may demand that we delete it),
  • the right to restrict the processing of data (you may demand that we restrict processing solely to storing the data or to carrying out actions agreed with you, if in your opinion we hold incorrect data or process it without a basis),
  • the right to object to the processing of data (you have the right to object to processing based on a legitimate interest; you should indicate the particular situation which in your opinion justifies our ceasing the processing objected to; we will stop processing your data for those purposes unless we demonstrate that our grounds for processing the data override your rights, or that we need your data to establish, pursue or defend claims),
  • the right to data portability (you have the right to receive from us, in a structured, commonly used, machine-readable format, the personal data you provided to us on the basis of a contract or your consent; you may instruct us to send that data directly to another entity),
  • the right to withdraw consent to the processing of personal data, if you previously gave such consent,
  • the right to lodge a complaint with a supervisory authority (if you find that we process data unlawfully, you may lodge a complaint on the matter with the President of the Personal Data Protection Office or another competent supervisory authority).

The rules concerning the exercise of the rights indicated above are described in detail in Articles 16 to 21 GDPR. We encourage you to read those provisions. For our part, we consider it necessary to explain to you that the rights indicated above are not absolute and will not be available to you in relation to all activities involving the processing of your personal data.

We stress that one of the rights indicated above is always available to you – if you consider that in processing your personal data we have infringed the personal data protection rules, you have the option of lodging a complaint with the supervisory authority (the President of the Personal Data Protection Office).

You can also always come to us with a request to be given information about what data we hold about you and for what purposes we process it. All you need to do is send a message to daneosobowe@liturgia.dominikanie.pl. We have, however, made every effort to present the information of interest to you exhaustively in this privacy policy. You can also use the e-mail address given above if you have any questions relating to the processing of your personal data.

12. Do we use cookies, and what actually are they?

Our website, like almost all other websites, uses cookies and similar technologies, such as the browser’s local storage. Everything we write below about cookies applies to those similar technologies as well.

Cookies are small pieces of text information stored on your end device (e.g. a computer, tablet or smartphone) which can be read by our IT system (first-party cookies) or by the IT systems of third parties (third-party cookies). Specific information may be saved and stored in cookies, which IT systems can then access for specific purposes.

Some of the cookies we use are deleted when the browser session ends, that is, once it is closed (so-called session cookies). Other cookies remain on your end device and allow us to recognise your browser on your next visit to the website (persistent cookies).

If you would like to learn more about cookies as such, you can read, for example, this material: https://en.wikipedia.org/wiki/HTTP_cookie.

13. On what basis do we use cookies?

We use cookies on the basis of your consent, except where cookies are necessary for the proper provision of an electronic service to you.

Cookies that are not necessary for the proper provision of an electronic service remain blocked until you consent to the use of cookies. This is not merely a declaration: the scripts of analytical and marketing tools are not started until you give your consent, and until then Google’s tools operate in a restricted mode (Consent Mode). During your first visit to the website we show you a message asking for your consent.

Consent is voluntary, and refusing is just as easy as giving it – in the message you have, side by side, a button to accept and a button that lets you use only the necessary files. You can also consent separately to analytical and to marketing cookies.

Please remember that disabling or restricting the handling of cookies may make it impossible to use some of the functions available on our website and may cause difficulties in using the website, as well as many other websites that use cookies. For example, if you do not consent to third-party cookies, the buttons, widgets and social functions implemented on the website may be unavailable to you. This does not apply to the chat with our team – that is always available, regardless of your decision, because it starts only when you yourself click the conversation button.

14. Can you disable cookies or withdraw your consent?

Yes, and in two ways.

First, you can change or withdraw your consent at any time without leaving our website. In the footer of the website there is a “Cookie settings” link, which reopens the consent message. Withdrawing consent is just as easy as giving it, and it results not only in our ceasing to use the cookies for which there is no consent, but also in the deletion of those files that have already been saved on your device.

Second, you can manage cookie settings within your web browser. You can block all or selected cookies. You can also block cookies from specific websites. At any time you can also delete cookies saved earlier as well as other website and plugin data.

Web browsers also offer the option of using incognito mode. You can use it if you do not want information about the websites visited and files downloaded to be saved in your browsing and download history. Cookies created in incognito mode are deleted the moment all windows of that mode are closed.

There are also browser plugins that make it possible to control cookies, such as Ghostery (https://www.ghostery.com). Additional software, in particular antivirus packages and the like, may also provide the option of controlling cookies.

In addition, tools are available on the internet that allow control over certain types of cookies, in particular collective management of behavioural advertising settings (e.g. www.youronlinechoices.com, optout.networkadvertising.org).

Please remember that disabling or restricting the handling of cookies may make it impossible to use some of the functions available in our website and may cause difficulties in using it, as well as many other websites that use cookies.

15. For what purposes do we use first-party cookies?

First-party cookies are used to ensure the proper functioning of individual website mechanisms, such as the correct submission of the forms visible on the website, handling the shopping basket and orders in the shop, maintaining your session after you log in to your user account, and remembering the language version you have chosen.

Information about the consent you have given to cookies is also stored in a first-party cookie. We save it in a file named dol_cc for a period of 12 months. It contains only the version number of the consent request, information about which categories of files you consented to, and the date and time of your choice – there is nothing in it that would allow you to be identified. We save the same information as a backup in the browser’s local storage and, if you are logged in, also in your user profile, so that we do not ask you the same question on every device.

16. Which third-party cookies are used?

Third-party cookies connected with the tools listed in Annex 2 to this privacy policy operate within our website. For each tool we have indicated the consent category it belongs to, so that you know exactly what your decision in the cookie message sets in motion. Individual tools may use more than one cookie, but we have refrained from listing them in detail, not wishing to overwhelm you with an excess of information and taking the view that it will be more readable for you to work with a list of tools together with a statement of the purposes for which those tools are used than to list every cookie technically operating within each tool.

We have also refrained from stating the scope of information collected in cookies in relation to each tool used, bearing in mind that every tool collects information connected with your characteristics and with the behaviour you display on our website. In this respect we are dealing with Anonymous Information, which we mentioned earlier in this privacy policy.

Aware of the requirements created by the Court of Justice of the European Union, we have nonetheless refrained from stating the lifespan of the cookies used by the individual tools. In order to state the lifespan of every cookie reliably we would have to overwhelm you with an excess of information which would in no way fulfil the principle of transparency and readability of the information addressed to you. Moreover, the lifespan of cookies may be subject to changes on the part of tool providers that are active enough that we are not able to exercise reliable control over it. In refraining from stating the lifespan of cookies, we remind you that you have two real ways of controlling how long information is stored in cookies: withdrawing consent through the “Cookie settings” link in the footer of the website, which deletes the files already saved, and managing cookies directly from within your web browser.

At this point we want to stress once again that within cookies we have no access to information that would allow us to identify you. In this respect we are dealing with Anonymous Information, which we have mentioned in this privacy policy.

What is more, while in the case of statistical and marketing tools we can view various kinds of reports generated on the basis of Anonymous Information, in relation to the remaining tools we do not obtain any access whatsoever to the information collected in cookies, being interested solely in whether the functions of a given tool, for which the tool was installed, work correctly within our website.

17. Do we track the behaviour you display within our website?

Yes, provided you consent to it. We use tools that involve collecting information about your activity on our website. Those tools are listed in Annex 2 to this privacy policy. Until you give your consent, those tools are not started.

18. Do we direct targeted advertising to you?

Yes, if you consent to marketing cookies.

We use the Google Ads and Meta (Facebook and Instagram) advertising systems, within which we measure the effectiveness of our advertising and may direct advertising to people who have visited our website – this is what is known as remarketing. That advertising concerns solely our own activity: the events we organise and the products available in our shop. We do not sell or share your data with other entities so that they can direct their advertising to you.

If you do not consent to marketing cookies, the advertising tools are not started and targeted advertising is not directed to you. You can withdraw your consent at any time through the “Cookie settings” link in the footer of the website. You can also manage advertising settings directly with the providers of those systems – you will find the links in Annex 2.

19. How can you manage your privacy?

The answer to this question can be found in many places in this privacy policy, in connection with the description of individual tools, behavioural advertising, cookie consent and so on. Nevertheless, for your convenience we have gathered this information once more in one place. Below you will find a list of ways to manage your privacy.

  • the “Cookie settings” link in the footer of our website – changing or withdrawing consent together with the deletion of files already saved
  • cookie settings within your web browser
  • browser plugins supporting cookie management, e.g. Ghostery
  • additional software for managing cookies
  • incognito mode in your web browser
  • behavioural advertising settings, e.g. youronlinechoices.com
  • settings on the side of the providers of external tools (links to the settings have been gathered in Annex 2 to this privacy policy)
  • unsubscribing from the newsletter using the link visible in every message we send
  • contacting us at daneosobowe@liturgia.dominikanie.pl on any matter concerning your data

20. What are server logs?

Using the website involves sending requests to the server on which the website is stored. Every request addressed to the server is saved in the server logs. The logs include, among other things, your IP address, the date and time of the server, and information about the web browser and operating system you use. The logs are saved and stored on the server.

The data saved in the server logs is not associated with specific individuals using the website and is not used by us to identify you. The server logs are solely auxiliary material serving the administration of the website, and their content is not disclosed to anyone other than the persons authorised to administer the server.

21. Do we record telephone conversations?

Yes. Telephone conversations with our office are recorded. Before the conversation begins you will hear a message informing you that it is being recorded – this gives you the chance to decide whether you wish to continue the call or would rather contact us in another way, for example by writing to us by e-mail.

We use the recordings for two purposes: taking care of the quality of our service, and retaining the ability to reconstruct the content of arrangements made during the conversation, for example regarding registration for an event or an order placed. The basis for the processing is Article 6(1)(f) GDPR, that is, our legitimate interest consisting in ensuring proper service and in establishing, pursuing or defending claims.

We store the recordings for 30 days, after which they are deleted. The exception is a situation in which a recording constitutes evidence in a specific matter – we then store it until that matter has been finally concluded.

Access to the recordings is available only to persons authorised by us and to the provider of telecommunications services, which gives us the technical ability to record and acts on the basis of a data processing agreement.

You have the right to object to the recording of conversations, indicating your particular situation. You can also come to us at any time with a question as to whether we hold a recording of your conversation, and ask for access to it.

22. How do we process data in connection with registration for events?

Registration for the events we organise – workshops, retreats, meetings – involves processing data that calls for a separate explanation.

Ordinary data. To register for an event you give us your identification and contact data as well as the details of your registration. We process it on the basis of Article 6(1)(b) GDPR, that is, in order to conclude and perform the contract for participation in the event.

Special categories of data. The registration form contains fields in which you may provide information about dietary requirements, allergies or your state of health, and also about being a member of the clergy or of a religious order. Information about health, as well as information about being a member of the clergy or of a religious order, which reveals your religious beliefs, constitute special categories of data within the meaning of Article 9 GDPR. Providing it is entirely voluntary – you can take part in the event without it as well, although we may then be unable to accommodate your needs, for example to provide a suitable meal. We process it solely on the basis of your explicit consent (Article 9(2)(a) GDPR), solely for the purpose of organising the event properly, and solely for as long as is needed to hold and settle it. You can withdraw your consent at any time by writing to daneosobowe@liturgia.dominikanie.pl. If the event takes place at premises run by another entity, we pass on information about dietary requirements to that entity to the extent necessary to provide you with meals.

Data of minors. Minors may take part in some of our events. In such a case the registration is submitted by a legal guardian, or the registration requires the guardian’s written consent, which we accept on a form prepared by us. We then process the participant’s data as well as the legal guardian’s contact data – the latter is necessary for us to be able to contact the guardian on matters concerning the participant’s involvement in the event, including in emergencies. If, in connection with the participation of a minor, we collect any consents, including consent to the processing of special categories of data, they are given by the legal guardian.

Surveys after an event. After an event has ended we may ask you to fill in an evaluation survey. Taking part in the survey is voluntary, and we use its results to improve future events.

23. Is there anything else you should know?

As you can see, the subject of processing personal data, using cookies and managing privacy in general is fairly complicated. We have made every effort to ensure that this document gives you the fullest possible knowledge on matters that are important to you. If anything is unclear to you, if you want to know more, or if you simply want to talk about your privacy, write to us at daneosobowe@liturgia.dominikanie.pl.

24. Can this privacy policy be subject to changes?

Yes, we may modify this privacy policy, in particular because of technological changes on the part of our website and changes in the law. If you are a registered user of the website, you will receive a message about every change to the privacy policy.

This content of the Privacy Policy is effective from 1 August 2026.

Annex 1 – purposes of processing personal data

Purpose of processing Legal basis for processing Categories of data processed Data storage period Source of the data
Handling a user account Article 6(1)(b) GDPR – conclusion and performance of a contract for the provision of an electronic service in the form of a user account Identification data. Contact data. Until the limitation period for claims connected with the contract for the provision of an electronic service has expired (in view of the separate archiving purpose listed below). User account registration form.
Handling an order Article 6(1)(b) GDPR – conclusion and performance of a contract concluded as a result of placing an order. Identification data. Contact data. Order details. Until the limitation period for claims connected with the contract concluded as a result of placing an order has expired (in view of the separate archiving purpose listed below). Order form.
Handling registration for an event Article 6(1)(b) GDPR – conclusion and performance of a contract for participation in an event. Identification data. Contact data. Registration details. Age or date of birth of the participant. Until the limitation period for claims connected with participation in the event has expired (in view of the separate archiving purpose listed below). Event registration form.
Registration of a minor for an event Article 6(1)(b) GDPR – conclusion and performance of a contract for participation in an event, where the registration is submitted or approved by a legal guardian. Article 6(1)(f) GDPR as regards the guardian’s contact data – legitimate interest consisting in the ability to contact the guardian on matters concerning the participant’s involvement, including in emergencies. Identification and contact data of the participant. Identification and contact data of the legal guardian. Age or date of birth of the participant. Until the limitation period for claims connected with participation in the event has expired. Event registration form. Written consent of the legal guardian.
Accommodating the special needs of an event participant Article 9(2)(a) GDPR – explicit consent of the data subject, and in the case of a minor – of their legal guardian. Data concerning health (dietary requirements, allergies, information about the state of health). Data revealing religious beliefs (information about being a member of the clergy or of a religious order). Until the event has been held and settled, and if consent is withdrawn earlier – until its withdrawal. Voluntary fields in the event registration form. Written consent of the legal guardian.
Handling complaints Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in handling the complaints procedure. Identification data. Contact data. Complaint details. Until the limitation period for claims connected with the complaint has expired. Complaint.
Handling withdrawal from a contract Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in handling the procedure for withdrawal from a contract. Identification data. Contact data. Until the expiry of the period for which the law requires accounting documentation to be stored (the statement of withdrawal from the contract is included in it). Statement of withdrawal from the contract.
Handling payments Article 6(1)(b) GDPR – performance of a contract concluded as a result of placing an order or registering for an event. Identification data. Contact data. Transaction details. Bank account number. Until the expiry of the period for which the law requires accounting documentation to be stored. Order form. Event registration form. Information from the payment operator.
Accounting Article 6(1)(c) in conjunction with the relevant tax law provisions – fulfilment of tax obligations. Identification data. Contact data. Invoice details. Until the expiry of the period for which the law requires accounting documentation to be stored. Order form, event registration form or withdrawal form.
Archive Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in securing data for the purposes of establishing, defending or pursuing claims and for the purposes of demonstrating compliance with the obligations arising from the GDPR. Data of varying scope, depending on what data has reached us and what scope of data is justified from an archiving point of view. Until the limitation period for claims or for our liability connected with the protection of personal data has expired. All forms used to transfer data.
Handling the newsletter Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in sending messages after prior consent to receive the newsletter has been obtained. Identification data. Contact data. Statistical information connected with the messages sent. Until the limitation period for claims connected with sending the newsletter or for our liability connected with the protection of personal data has expired. Newsletter subscription form.
Recording telephone conversations Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in taking care of the quality of service and in retaining the ability to reconstruct the content of arrangements made during the conversation, including for the purposes of establishing, pursuing or defending claims. Telephone number. Content of the recording of the conversation. Date and time of the call. 30 days from the recording. If the recording constitutes evidence in a specific matter – until that matter has been finally concluded. Telephone call to our office.
Handling surveys after an event Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in gathering and analysing participants’ opinions in order to improve future events. Identification data, if provided. Content of the answers to the survey questions. Until it ceases to be useful for evaluating and planning events. Survey form.
Handling comments / reviews Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in publishing a comment / review after it has previously been submitted by the user. Identification data. Contact data. Details of the comment / review. Until the comment / review is deleted. Form for adding a comment / review.
Handling correspondence Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in exchanging correspondence with the user and possibly archiving it. Identification data. Contact data. Details of the correspondence. Impossible to determine unequivocally. Some correspondence may be deleted on an ongoing basis, and some archived if we consider that there is a need to store it, in particular in order to ensure the ability to reconstruct its course in the future. Contact form. Chat on the website. Incoming message.
Handling social media Article 6(1)(f) GDPR – legitimate interest pursued by the administrator consisting in running profiles on social media. Data publicly visible on the user’s profile in the social media service. Details of interaction with the user within the social media profiles. Until the user deletes the data from the social media service. Social media profiles. Content published by the user on social media.
Analytics and statistics Article 6(1)(a) GDPR – your consent given in the cookie message. Anonymous Information (details discussed within the definition of Anonymous Information contained in the privacy policy) Until consent is withdrawn, and at the latest until consent expires 12 months after it was given. Tracking code embedded in the website, started after consent has been given.
Own marketing Article 6(1)(a) GDPR – your consent given in the cookie message. Anonymous Information (details discussed within the definition of Anonymous Information contained in the privacy policy) Until consent is withdrawn, and at the latest until consent expires 12 months after it was given. Tracking code embedded in the website, started after consent has been given.
Creating advertising audiences Article 6(1)(a) GDPR – your consent given in the cookie message. E-mail address. Personal data deleted by the advertising system immediately after the matching process within the creation of an audience has been completed. The audience created does not contain information having the character of personal data. User account registration form. Order form. Newsletter subscription form.

Annex 2 – list of external tools

For each tool we have indicated the consent category it belongs to. Tools marked as necessary operate at all times, because without them the website cannot function properly. Analytical and marketing tools are started solely after the relevant consent has been given in the cookie message. A separate category is a tool started at your request – the chat. It does not wait for consent to cookies, but neither does it start by itself: until you click the conversation button, it is not loaded at all and saves nothing on your device.

Tool Provider Purpose of use Provider’s explanations Provider’s settings
Cloudflare Cloudflare, Inc. Necessary. Protecting the website against attacks and abuse and speeding up its delivery. See See
reCaptcha Google LLC Necessary. Assessing whether the user visiting the website is a real person or a bot, in order to protect forms against abuse. See See
Stripe Stripe, Inc. Necessary. Handling payments in the shop and preventing payment fraud. See See
Montonio Montonio Finance OÜ Necessary. Handling online payments and bank transfers in the shop. See See
Tpay Krajowy Integrator Płatności S.A. Necessary. Handling online payments in the shop as a fallback solution. See See
YouTube Google LLC Necessary in order to play a video. Embedding video material from the YouTube service. We embed videos in restricted processing mode (youtube-nocookie.com), thanks to which YouTube does not save any cookies on your device until you start playing the video. See See
Google Analytics Google LLC Analytical. Analysis and statistics concerning the behaviour of people visiting the website. See See
Google Ads Google LLC Marketing. Measuring the effectiveness of our advertising and directing advertising to people who have visited our website (remarketing). See See
Meta Pixel Meta Platforms, Inc. Marketing. Measuring the effectiveness of advertising and targeting advertising in the Facebook and Instagram services. See See
LiveChat LiveChat, Inc. Started at your request. A chat enabling direct contact with our team. The chat is always available, regardless of your decision about cookies, but it is not loaded in advance: on the website you see our own conversation button, and only clicking it starts the LiveChat tool. Until that moment LiveChat receives no information about you and saves nothing on your device. We do not approach you on the chat ourselves – you start the conversation. See See