- 1. Personal data controller
- 2. Purposes and legal bases of processing
- 3. Scope of data and sources
- 4. Data recipients and processors
- 5. Transfers of data outside the EEA
- 6. Data retention period
- 7. Rights of data subjects
- 8. Right to lodge a complaint
- 9. Cookies and tracking technologies
- 10. Data security
- 11. Voluntary nature of providing data
- 12. Changes to the Privacy policy
1. Personal data controller
1.1. The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) is:
| Data controller | Dariusz Włodarczyk – Kancelaria |
|---|---|
| NIP (tax ID) | 1250476187 |
| REGON | 011698970 |
| Address | ul. Fabryczna 18, 02-892 Warszawa |
| Contact for personal data matters | office@cosc.org.pl |
1.2. The Controller has not appointed a formal Data Protection Officer — for all matters concerning the processing of personal data you may contact the Controller directly at the e-mail address indicated.
2. Purposes and legal bases of processing
2.1. The personal data of visitors to the website and of persons contacting the Controller (by phone, WhatsApp or e-mail) are processed for the following purposes:
| Purpose of processing | Legal basis |
|---|---|
| Replying to an enquiry and taking steps prior to concluding a contract at the request of the data subject | Article 6(1)(b) GDPR |
| Performance of the contract for the provision of services (handling the Client's case, representation in proceedings) | Article 6(1)(b) GDPR |
| Fulfilment of legal obligations incumbent on the Controller (e.g. tax and accounting rules) | Article 6(1)(c) GDPR |
| Establishing, pursuing or defending against claims, archiving correspondence | Article 6(1)(f) GDPR (legitimate interest of the Controller) |
| Maintaining and securing the operation of the website (technical logs of the hosting server) | Article 6(1)(f) GDPR (legitimate interest of the Controller) |
2.2. The contact form available on the website does not automatically send data to the Controller's server or store them on the site — it serves solely to conveniently compose the message that the person contacting us sends themselves via the WhatsApp messenger or e-mail. Data are therefore transmitted to the Controller solely at the initiative of the person making contact, by phone, WhatsApp or e-mail.
3. Scope of data and sources
3.1. In connection with contact and the provision of services, the Controller may process in particular: first name and surname, contact details (telephone number, e-mail address), the content of correspondence, and — in the course of handling the case — data contained in documents necessary to conduct the residence or legalisation case (e.g. data from the travel document, employment data).
3.2. The personal data come directly from the data subject and are provided voluntarily in order to obtain information or to commission a service.
3.3. To the extent that documents provided by the Client contain special categories of data within the meaning of Article 9 GDPR, the Controller processes them only to the extent necessary to conduct the case and on the basis of Article 9(2)(f) GDPR (establishment, exercise or defence of legal claims) or with the data subject's consent.
4. Data recipients and processors
4.1. Personal data may be disclosed to the following categories of recipients:
- the website hosting provider — GitHub Pages (GitHub, Inc. / GitHub B.V.) — as regards technical server logs (IP address, time of visit),
- the WhatsApp service provider (WhatsApp Ireland Limited / Meta Platforms Ireland Limited) — as regards the content of correspondence conducted through that messenger, in accordance with that provider's separate privacy policy,
- the e-mail hosting provider — dHosting — as regards the operation of the office@cosc.org.pl mailbox,
- public administration authorities to which the Controller submits applications and letters on behalf of the Client on the basis of the power of attorney granted,
- entities providing accounting and legal services to the Controller, to the extent necessary to perform those services,
- public authorities entitled to obtain data on the basis of legal provisions.
4.2. The Controller does not sell personal data or make them available to third parties for marketing purposes.
5. Transfers of data outside the EEA
5.1. Website hosting (GitHub Pages) and the WhatsApp messenger may involve transferring data to countries outside the European Economic Area, including the United States. These providers declare that they apply appropriate safeguards, including standard contractual clauses approved by the European Commission, in accordance with Article 46 GDPR. Detailed information is available in those providers' privacy policies.
6. Data retention period
6.1. The data of persons who only contacted the Controller without concluding a contract are stored for the period necessary to reply and then for the limitation period of any potential claims.
6.2. The data of Clients with whom a contract has been concluded are stored for the duration of the case and for the period required by law (including tax and accounting rules) and the limitation period for claims arising from the contract, in accordance with the provisions of the Civil Code on the limitation of claims.
6.3. Technical logs of the hosting server are stored for the period resulting from the hosting provider's policy.
7. Rights of data subjects
7.1. The data subject has the following rights under the GDPR:
- the right of access to data (Article 15 GDPR),
- the right to rectification of data (Article 16 GDPR),
- the right to erasure of data (Article 17 GDPR),
- the right to restriction of processing (Article 18 GDPR),
- the right to data portability (Article 20 GDPR),
- the right to object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR),
- the right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal.
7.2. To exercise the above rights, please contact the Controller at office@cosc.org.pl.
8. Right to lodge a complaint
8.1. The data subject has the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa) — if they consider that the processing of their data infringes the GDPR.
9. Cookies and tracking technologies
9.1. As at the date of publication of this Policy, the website does not use analytical or marketing cookies or other tracking technologies (no Google Analytics, advertising pixels or similar tools).
9.2. If in the future the Controller introduces cookies on the website requiring the user's consent in accordance with Article 173 of the Act of 16 July 2004 – Telecommunications Law, this Policy will be updated accordingly and users will be informed of the possibility of giving and withdrawing consent.
10. Data security
10.1. The Controller applies technical and organisational measures ensuring the security of the personal data processed, appropriate to the risk involved in the processing, in accordance with Article 32 GDPR.
11. Voluntary nature of providing data
11.1. Providing personal data is voluntary, but necessary in order to reply to an enquiry or to conclude and perform a contract for the provision of services.
12. Changes to the Privacy policy
12.1. The Controller reserves the right to amend this Privacy policy, in particular in the event of a change in the applicable law or a change in the way data are processed. The current version of the Policy is always available on the website.
Note: this document is a template prepared on the basis of the GDPR and applicable Polish law. It does not constitute legal advice for visitors to the website. The rules for providing services are set out in a separate document: Terms of service.