- GENERAL PROVISIONS
1.1 The Administrator of the personal data collected through the european-games.org website is Igrzyska Europejskie 2023 sp. z o.o.; registered office and place of business address and address for delivery: 20 Życzkowskiego St. , 31-864 Kraków, Poland, entered in the Register of Entrepreneurs under KRS: 0000947256, NIP: 6762610220, REGON: 521030271, e-mail address of the Data Protection Inspector: firstname.lastname@example.org, which is also a service provider, hereinafter referred to as the Administrator.
1.2 Personal data collected by the Administrator through the website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as RODO, and the Law on Personal Data Protection of May 10, 2018.
- TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
2.1 PURPOSE OF PROCESSING AND LEGAL BASIS. The Administrator processes personal data through the european-games.org website for:
a. User’s use of the contact form. The personal data is processed on the basis of Article 6(1)(f) RODO as a legitimate interest of the Administrator.
b. subscription by the user to the Newsletter for the purpose of sending commercial information by electronic means. Personal data is processed upon separate consent, pursuant to Article 6(1)(a) RODO.
2.2 TYPE OF PERSONAL DATA PROCESSED. The Administrator processes the following categories of user’s personal data:
a. first and last name,
b. name of the editorial office,
c. e-mail address,
d. telephone number,
2.3 ARCHIVING PERIOD OF PERSONAL DATA. Users’ personal data are kept by the Administrator:
a. in the case where the basis of data processing is the performance of a contract, for as long as it is necessary to perform the contract, and thereafter for a period corresponding to the period of limitation of claims. Unless a specific provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business – three years.
b. where the basis for data processing is consent, for as long as consent is not revoked, and after revocation of consent for a period of time corresponding to the statute of limitations for claims that the Administrator may raise and that may be raised against him. Unless a specific provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business – three years.
2.4 When using the website, additional information may be collected, in particular: the IP address assigned to the user’s computer or the ISP’s external IP address, domain name, browser type, access time, operating system type.
2.5 Navigation data may also be collected from users, including information about the links and references they choose to click on or other actions they take on the website. The legal basis for such activities is the Administrator’s legitimate interest (Article 6(1)(f) RODO) in facilitating the use of electronically provided services and improving the functionality of such services.
2.6 The provision of personal data by the user is voluntary.
2.7 Personal data will also be processed in an automated manner in the form of profiling, if the user consents to it on the basis of Article 6(1)(a) RODO. The consequence of profiling will be the assignment of a profile to a person in order to make decisions concerning him or her or to analyse or predict his or her preferences, behaviours and attitudes.
2.8 The Administrator shall exercise special care to protect the interests of data subjects, and in particular shall ensure that the data it collects are:
a. processed in accordance with the law,
b. collected for designated legitimate purposes and not subjected to further processing incompatible with those purposes,
c. substantively correct and adequate in relation to the purposes for which they are processed, and kept in a form that makes it possible to identify the persons to whom they relate for no longer than is necessary to achieve the purpose of the processing.
- SHARING OF PERSONAL DATA
3.1 Users’ personal data are transferred to the service providers used by the Administrator to operate the website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either are subject to the Administrator’s instructions as to the purposes and means of processing such data (processors) or determine the purposes and means of processing themselves (controllers).
3.2 Your personal data is stored exclusively in the European Economic Area (EEA).
- RIGHT TO CONTROL AND ACESS TP THE CONTENT OF OWN DATA
4.1 The data subject has the right to access the content of his/her personal data and the right to rectification, erasure, restriction of processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.
Legal grounds for the user’s request:
a. Access to data – Article 15 RODO
b. Correction of data – Article 16 RODO.
c. Deletion of data (so-called right to be forgotten) – Article 17 RODO.
d. Restriction of processing – Article 18 RODO.
e. Transfer of data – Article 20 RODO.
f. Objection – Article 21 RODO.
g. Withdrawal of consent – Article 7(3) RODO.
4.2 In order to exercise the rights referred to in Section 4.1, you can send a relevant email to: email@example.com.
4.3 In a situation where the user has asserted an entitlement under the above-mentioned rights, the Administrator shall either comply with the request or refuse to comply with it immediately, but no later than within one month after receiving it. However, if – due to the complex nature of the request or the number of requests – the Administrator is unable to fulfil the request within one month, it will fulfil it within another two months informing the user in advance – within one month of receiving the request – of the intended extension of the deadline and the reasons for it.
4.4 If it is determined that the processing of personal data violates the provisions of the RODO, the data subject has the right to file a complaint with the President of the Office for Personal Data Protection.
5.1 The Administrator’s website uses “cookies” files.
5.2 The installation of “cookies” is necessary for the proper provision of services on the website. The “cookies” files contain information necessary for the proper functioning of the website, and they also provide the opportunity to develop general statistics of website visits.
5.3 The website uses types of “cookies”: session cookies and permanent cookies
a. “Session” “cookies” are temporary files that are stored on the user’s terminal device until the user logs out (leaves the site).
b. “Permanent” “cookies” are stored on the user’s end device for the time specified in the parameters of the “cookies” or until they are deleted by the user.
5.4 The Administrator uses its own cookies to better understand how the user interacts with the content of the site. The files collect information about the user’s use of the website, the type of website from which the user was redirected, and the number of visits and the time of the user’s visit to the website.
5.5 This information does not record specific personal information about the user, but is used to compile statistics on the use of the website.
5.6 You have the right to decide on the access of “cookies” to your computer by selecting them in advance in your browser window. Detailed information about the possibility and methods of handling “cookies” is available in the settings of your software (web browser).
- FINAL PROVISIONS
6.1 The Administrator shall apply technical and organizational measures to ensure the protection of the processed personal data appropriate to the risks and categories of protected data, and in particular shall protect the data from being disclosed to unauthorized persons, from being taken by an unauthorized person, from being processed in violation of applicable regulations, and from being altered, lost, damaged or destroyed.
6.2 The Administrator shall provide appropriate technical means to prevent acquisition and modification by unauthorized persons, of personal data sent electronically.