Skip to main content Scroll Top

Privacy Policy

The Privacy Policy set out below sets out the rules governing the storage of and access to data on the Devices of Users accessing the Website for the purposes of the Controller providing services electronically, as well as the rules governing the collection and processing of Users’ personal data, which they have provided personally and voluntarily via the tools available on the Website.

The Privacy Policy set out below forms an integral part of Terms and Conditions of the Website, which sets out the rules, rights and obligations of Users of the Website.

§1 Definitions

  • Website – the „coti-conference.com” website, accessible at https://coti-conference.com
  • External websites – websites operated by partners, service providers or service users who collaborate with the Controller
  • Website / Data Controller – The Website Controller and Data Controller (hereinafter referred to as the „Controller”) is the company ‘Anna Inglot Coti Conference Time’, trading at the following address: 31-623 Kraków, os. Piastów 4/53, with tax identification number (NIP): 5511536448, providing services electronically via the Website
  • User – a natural person to whom the Controller provides services electronically via the Website.
  • Device – an electronic device, together with its software, through which the User accesses the Website
  • Cookies – text data collected in the form of files stored on the User’s Device
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • Personal data – means information relating to an identified or identifiable natural person („data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person
  • Processing – means any operation or set of operations which is carried out on personal data or sets of personal data, whether by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adapting or modifying, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, erasing or destroying;
  • Restriction of processing – means marking stored personal data in order to restrict its future processing
  • Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, their economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
  • Consent – the consent of the data subject means a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify their agreement to the processing of their personal data
  • Personal data breach – means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed
  • Pseudonymisation – means the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and is subject to technical and organisational measures that prevent it from being attributed to an identified or identifiable natural person
  • Anonymisation – Data anonymisation is an irreversible data processing operation that destroys or overwrites „personal data”, thereby preventing the identification of, or the linking of, a given record to a specific user or natural person.

§2 Data Protection Officer

Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.

For matters relating to data processing, including the processing of personal data, please contact the Data Controller directly.

§3 Types of Cookies

  • First-party cookies – files placed on and read from the User’s Device by the Website’s IT system
  • Third-party cookies – files placed on and read from the User’s Device by the IT systems of third-party websites. Scripts from third-party websites, which may place cookies on the User’s device, have been deliberately incorporated into the Website via scripts and services made available and installed on the Website
  • Session cookies – files placed on and read from the User’s Device by the Website during a single session on that Device. Once the session ends, the files are deleted from the User’s Device.
  • Persistent cookies – files placed on and read from the User’s Device by the Website until they are manually deleted. These files are not automatically deleted at the end of the Device’s session unless the User’s Device is configured to delete cookies at the end of the Device’s session.

§4 Data storage security

  • Mechanisms for storing and reading cookies – The mechanisms for storing, retrieval and exchange of data between cookies stored on the User’s Device and the Website are carried out via the built-in mechanisms of web browsers and do not allow for the retrieval of other data from the User’s Device or data from other websites which the User has visited, including personal data or confidential information. It is also practically impossible for viruses, Trojan horses or other worms to be transferred to the User’s Device.
  • First-party cookies – the cookies used by the Controller are safe for Users’ devices and do not contain any scripts, content or information that could compromise the security of personal data or the security of the device the User is using.
  • Third-party cookies – The Controller takes all possible measures to verify and select the website’s partners with a view to ensuring Users’ security. The Administrator selects well-known, large partners who enjoy global public trust for collaboration. However, the Administrator does not have full control over the content of cookies originating from third-party partners. To the extent permitted by law, the Administrator accepts no liability for the security of cookies, their content or their licence-compliant use by scripts installed on the website that originate from external websites. A list of partners is provided later in this Privacy Policy.
  • Cookie Management
  • Risks on the part of the User – The Administrator takes all possible technical measures to ensure the security of data stored in cookies. However, it should be noted that ensuring the security of this data depends on both parties, including the User’s actions. The Controller accepts no liability for the interception of this data, impersonation of the User’s session or the deletion of such data, resulting from the User’s deliberate or inadvertent actions, viruses, Trojan horses and other spyware with which the User’s Device may be or may have been infected. To protect themselves against these threats, Users should comply with guidelines for using the internet.
  • Storage of personal data – The Controller ensures that it makes every effort to ensure that the personal data processed, which has been provided voluntarily by Users, is secure, and that access to it is restricted and carried out in accordance with its intended use and the purposes of processing. The Controller also ensures that it makes every effort to protect the data it holds against loss by implementing appropriate physical and organisational security measures.
  • Password storage – The Administrator declares that passwords are stored in encrypted form, using the latest standards and guidelines in this regard. It is virtually impossible to decrypt the account passwords entered on the Website.

§5 Purposes for which cookies are used

  • Improving and facilitating access to the Website
  • Personalisation of the Website for Users
  • Enabling login to the website
  • Marketing, Remarketing on third-party websites
  • Advertising services
  • Affiliate services
  • Keeping statistics (users, number of visits, types of devices, internet connection, etc.)
  • Provision of multimedia services
  • Provision of community services

§6 Purposes of personal data processing

Personal data provided voluntarily by Users is processed for one of the following purposes:

  • Provision of electronic services:
    • Services relating to the registration and maintenance of a User’s account on the Website and the associated features
    • Newsletter services (including the sending of advertising content with the recipient’s consent)
    • Services enabling users to share information about content posted on the Website on social media platforms or other websites.
  • Communication between the Administrator and Users on matters relating to the Website and data protection
  • To safeguard the Controller’s legitimate interests

User data collected anonymously and automatically is processed for one of the following purposes:

  • Keeping records
  • Remarketing
  • Serving adverts tailored to users’ preferences
  • Affiliate programme management
  • To safeguard the Controller’s legitimate interests

§7 Cookies from third-party websites

The Website Administrator uses JavaScript scripts and web components from partners, who may place their own cookies on the User’s Device. Please note that you can use your browser settings to decide for yourself which cookies are permitted for use by individual websites. Below is a list of partners or their services implemented on the Website that may place cookies:

Services provided by third parties are beyond the Controller’s control. These third parties may, at any time, amend their terms and conditions, privacy policies, the purposes for which they process data, and the ways in which they use cookies.

§8 Types of data collected

The Website collects data about Users. Some of this data is collected automatically and anonymously, whilst some of it consists of personal data provided voluntarily by Users when signing up for specific services offered by the Website.

Anonymous data collected automatically:

  • IP address
  • Browser type
  • Screen resolution
  • Approximate location
  • Subpages of the website that can be opened
  • Time spent on the relevant subpage of the website
  • Type of operating system
  • Address of the previous subpage
  • Address of the referring website
  • Browser language
  • Internet connection speed
  • Internet service provider

Data collected during registration:

  • First name / surname / nickname
  • Login
  • Email address
  • IP address (collected automatically)

Data collected when subscribing to the newsletter service

  • First name / surname / nickname
  • Email address
  • IP address (collected automatically)

Some data (excluding personally identifiable information) may be stored in cookies. Some data (excluding personally identifiable information) may be passed on to a statistics service provider.

§9 Access to personal data by third parties

As a general rule, the Controller is the sole recipient of the personal data provided by Users. Data collected in connection with the services provided is not passed on to or sold to third parties.

Access to data (usually under a Data Processing Agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary for the operation of the website, namely:

  • Hosting companies providing hosting or related services to the Controller
  • Companies through which the newsletter service is provided
  • IT service and support companies that carry out maintenance or are responsible for maintaining IT infrastructure
  • Companies acting as intermediaries in online payments for goods or services offered via the Website (in the event of a purchase transaction being made on the Website)

Entrusting the processing of personal data – Newsletter

In order to provide the Newsletter service, the Administrator uses the services of a third party – the website Freshmail, . The data entered in the newsletter subscription form is transmitted, stored and processed on this service provider’s external platform.

Please note that the partner in question may amend the privacy policy in question without the Controller’s consent.

 

Entrusting the processing of personal data – Hosting, VPS or Dedicated Server services

In order to operate the website, the Administrator uses the services of an external hosting provider, VPS or Dedicated Servers – ultimahost.pl Szeliga sp. j.. All data collected and processed on the website is stored and processed within the service provider’s infrastructure located in Poland. Access to the data may occur as a result of maintenance work carried out by the service provider’s staff. Access to this data is governed by the contract between the Administrator and the Service Provider.

 

Entrusting the processing of personal data – Website maintenance services

The Administrator uses the services of an external service provider – Instytut Studiów Programistycznych S.A. – to operate the website. Staff at the aforementioned organisation have access to data entered by users during registration and when editing their user accounts, and/or data relating to the Newsletter service. Access to this data is governed by an agreement between the Administrator and the Service Provider.

 

Data processing in the case of online payments

In the case of online payments, all payment details are provided directly by the User to the payment processor – Dotpay Sp z o.o. Selected data necessary to process the transaction is then forwarded by that entity to the Controller. The transfer of data is governed by an agreement between the Controller and the Service Provider.

 

§10 Methods of processing personal data

Personal data provided voluntarily by Users:

  • Personal data will not be transferred outside the European Union, unless it has been published as a result of an individual action by the User (e.g. posting a comment or entry), in which case the data will be accessible to anyone visiting the website.
  • Personal data will not be used for automated decision-making (profiling).
  • Personal data will not be sold to third parties.

Anonymous data (excluding personal data) collected automatically:

  • Anonymised data (without personal data) will be transferred outside the European Union.
  • Anonymised data (without personal data) will not be used for automated decision-making (profiling).
  • Anonymised data (without personal data) will not be sold to third parties.

§11 Legal basis for the processing of personal data

The website collects and processes Users’ data on the following grounds:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
    • 6(1)(a)
      the data subject has given consent to the processing of their personal data for one or more specific purposes
    • 6(1)(b)
      processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the data subject’s request prior to entering into a contract
    • 6(1)(f)
      processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
  • The Act of 10 May 2018 on the protection of personal data (Journal of Laws 2018, item 1000)
  • The Act of 16 July 2004 – Telecommunications Law (Journal of Laws 2004, No. 171, item 1800)
  • The Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994 No. 24, item 83)

§12 Retention period for personal data

Personal data provided voluntarily by Users:

As a general rule, the personal data in question is stored solely for the duration of the provision of the Service by the Controller via the Website. It is deleted or anonymised within 30 days of the service ceasing (e.g. deletion of a registered user account, unsubscribing from the newsletter, etc.)

An exception to this is a situation where there is a legitimate legal basis for the Controller to continue processing this data. In such a situation, the Controller will retain the specified data, from the time the User requests its erasure, for no longer than 3 years in the event of a breach or suspected breach of the website’s terms and conditions by the User

Anonymous data (excluding personal data) collected automatically:

Anonymous statistical data, which does not constitute personal data, is stored by the Controller for the purpose of compiling website statistics for an indefinite period

§13 Users’ rights in relation to the processing of personal data

The website collects and processes Users’ data on the following grounds:

  • The right of access to personal data
    Users have the right to access their personal data, which is granted upon request submitted to the Controller
  • The right to rectify personal data
    Users have the right to request that the Controller immediately rectify any personal data that is incorrect and/or complete any personal data that is incomplete, upon submission of a request to the Controller
  • The right to have personal data erased
    Users have the right to request that the Controller immediately erase their personal data, upon submission of a request to the Controller. In the case of user accounts, the erasure of data involves the anonymisation of data that enables the User to be identified. The Controller reserves the right to withhold compliance with a request for data deletion in order to protect the Controller’s legitimate interests (e.g. where the User has breached the Terms and Conditions or where the data was obtained as a result of correspondence).
    In the case of the Newsletter service, Users can delete their personal data themselves by using the link included in every email sent.
  • The right to restrict the processing of personal data
    Users have the right to restrict the processing of their personal data in the cases set out in Article 18 of the GDPR, including where they contest the accuracy of their personal data; this right is exercised by submitting a request to the Controller
  • The right to data portability
    Users have the right to obtain from the Controller their personal data in a structured, commonly used, machine-readable format, upon request submitted to the Controller
  • The right to object to the processing of personal data
    Users have the right to object to the processing of their personal data in the cases set out in Article 21 of the GDPR, which may be exercised by submitting a request to the Controller
  • The right to lodge a complaint
    Users have the right to lodge a complaint with the supervisory authority responsible for the protection of personal data.

§14 Contact details for the Data Controller

You can contact the Data Controller in one of the following ways

  • Postal address – Anna Inglot Coti Conference Time, 31-623 Kraków, os. Piastów 4/53
  • Email address – office@coti-conference.com
  • Telephone number – +48 504004517
  • Contact form – available at: https://coti-conference.com/kontakt/

§15 Website Requirements

  • Restricting the storage of and access to cookies on the User’s device may cause certain features of the Website to malfunction.
  • The Administrator accepts no liability for any malfunctioning of the Website’s features should the User restrict, in any way, the ability to store and read cookies.

§16 External links

On the Website – in articles, posts, entries or User comments – there may be links to external websites with which the Website Owner does not collaborate. These links, and the pages or files they point to, may be harmful to your device or pose a security risk to your data. The Administrator accepts no liability for content located outside the Website.

§17 Changes to the Privacy Policy

  • The Administrator reserves the right to amend this Privacy Policy at its discretion without the need to notify Users regarding the use and processing of anonymous data or the use of cookies.
  • The Administrator reserves the right to amend this Privacy Policy at its discretion in relation to the processing of Personal Data, and will notify Users who hold user accounts or are subscribed to the newsletter service by email within 7 days of any such amendments. Continued use of the services constitutes acknowledgement and acceptance of the changes made to the Privacy Policy. Should a User not agree with the changes made, they are obliged to delete their account from the Website or unsubscribe from the newsletter service.
  • Any changes made to the Privacy Policy will be published on this page of the Website.
  • The amendments come into force upon their publication.

 

 

Privacy Preferences
When you visit our website, it may store information from specific services via your browser, usually in the form of cookies. You can change your privacy preferences here. Please note that blocking certain types of cookies may affect your experience on our website and the services we offer.