Privacy Policy

PRIVACY AND COOKIE POLICY

FOR konferencja.processwork.pl

Last updated: 28 August 2026

WERSJA POLSKA: Polityka prywatności

1. GENERAL INFORMATION

This Privacy and Cookie Policy sets out the rules governing the processing of personal data of persons using the website available at konferencja.processwork.pl, in particular persons visiting the Website, contacting the Organiser, placing orders and participating in the conference “Meta-Skills and Therapeutic Style”.

This Policy also provides information concerning the use of cookies and similar technologies, the organisation of the conference via the Zoom platform, and the provision of conference recordings to persons who have purchased a package including access to the recordings.

The Website is operated by Fundacja Instytut Psychologii Procesu.

For the purposes of this Policy, konferencja.processwork.pl is hereinafter referred to as the “Website”.


2. CONTROLLER OF PERSONAL DATA

The Controller of personal data is:

Fundacja Instytut Psychologii Procesu

ul. Jana Kochanowskiego 27/7

01-864 Warsaw

Poland

KRS: 0000807315

NIP: 1182200537

REGON: 384591443

Correspondence address:

Al. Ujazdowskie 16 lok. 58

00-557 Warsaw

Poland

Contact concerning personal data protection:

instytut@processwork.pl

For organisational matters relating to the conference, the Controller may also communicate using the following address:

konferencjaipp@gmail.com

For the purposes of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), Fundacja Instytut Psychologii Procesu is the controller of personal data within the meaning of Article 4(7) GDPR.


3. CATEGORIES OF PERSONAL DATA THAT MAY BE PROCESSED

Depending on the manner in which the Website is used, the Controller may process, in particular, the following categories of personal data:

a) identification and contact details:

  • first name and surname,
  • e-mail address,
  • information provided in connection with an order,
  • company or institution details, including the Polish tax identification number (NIP), where provided for accounting or invoicing purposes;

b) order-related data:

  • selected conference package,
  • price,
  • date of the order,
  • order number,
  • information concerning the status of the order and payment,
  • information concerning a code or entitlement to a particular type of ticket, where applicable;

c) payment-related data:

  • selected payment method,
  • transaction identifier or transaction status,
  • information provided to the Controller by a payment service provider to the extent necessary to confirm a payment, process a refund or resolve an issue relating to a transaction.

The Controller does not receive or store the full payment card details used by a participant to make a payment. Data required for processing card payments are processed by the relevant payment service provider.

d) contact and correspondence data:

  • first name and surname,
  • e-mail address,
  • subject of the message,
  • content of the message,
  • other information voluntarily provided by a person contacting the Controller;

e) data relating to participation in the online conference:

  • first name and surname or display name used in Zoom,
  • e-mail address, where used for participation or registration,
  • data concerning connection to the conference,
  • time of joining and leaving a meeting,
  • duration of participation,
  • technical information made available to the meeting organiser by Zoom,
  • other data provided by a participant when using Zoom;

f) data required for issuing a certificate of participation:

  • participant identification data,
  • information confirming participation in the conference,
  • information contained in a Zoom attendance report;

g) technical data relating to the use of the Website:

  • IP address,
  • date and time of connection,
  • requested page or resource,
  • information concerning the browser and device,
  • server logs,
  • information required to ensure the proper and secure operation of the Website;

h) data relating to cookie preferences:

  • information as to whether consent has been given or refused,
  • choice or consent identifier,
  • technical data necessary to record and demonstrate the user’s preferences.

4. PURPOSES AND LEGAL BASES OF PROCESSING

The Controller processes personal data for the purposes and on the legal bases described below.

4.1. Handling orders and entering into a contract

Personal data are processed for the purposes of accepting an order, registering a participant, accepting payment, confirming the purchase, providing organisational information and performing the contract concerning participation in the conference.

Legal basis:

Article 6(1)(b) GDPR – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

4.2. Payment processing

Data relating to an order and transaction are processed in order to enable payment, confirm receipt of payment, process any refund and resolve irregularities concerning a payment.

Legal basis:

Article 6(1)(b) GDPR – performance of a contract;

and, to the extent required for compliance with the Controller’s legal obligations:

Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject.

4.3. Accounting and tax obligations

Transaction data may be processed for the purposes of maintaining accounting and tax documentation and complying with other obligations imposed by applicable law.

Legal basis:

Article 6(1)(c) GDPR.

4.4. Organisation of the conference

Participants’ data are processed in order to send organisational information, provide the information required to join the Zoom meeting, conduct the conference and enable the participant to use the services included in the purchased package.

Legal basis:

Article 6(1)(b) GDPR.

Organisational messages relating to a purchased conference package, including information on how to join the meeting, organisational changes or access to purchased materials, do not constitute a newsletter or marketing communication. They are communications necessary for the performance of the contract.

4.5. Verification of attendance and issuing certificates of participation

The Controller may use attendance reports made available through the Zoom platform in order to verify a person’s actual participation in the conference and to issue certificates of participation.

Depending on the information made available by Zoom, an attendance report may include, in particular:

  • the participant’s name or display name,
  • e-mail address or another participant identifier,
  • time of joining the meeting,
  • time of leaving the meeting,
  • total duration of participation.

Where verification of participation or issuance of a certificate forms part of the service provided to the participant or is carried out at the participant’s request, the legal basis for processing is Article 6(1)(b) GDPR.

Where applicable, processing may also be based on Article 6(1)(f) GDPR – the legitimate interests pursued by the Controller consisting in documenting participation, ensuring the proper issuance of certificates and resolving any subsequent doubts or disputes concerning participation in the conference.

The Controller will use attendance reports only to the extent necessary for these purposes.

4.6. Providing recordings to persons who have purchased an eligible package

Where a participant has purchased a package including access to conference recordings, the participant’s e-mail address and order information are used to provide a link granting access to the recordings.

Legal basis:

Article 6(1)(b) GDPR – performance of a contract.

4.7. Contact and correspondence

Where a message concerns entering into or performing a contract, personal data are processed on the basis of Article 6(1)(b) GDPR.

In other cases, the legal basis is Article 6(1)(f) GDPR – the legitimate interests pursued by the Controller consisting in conducting correspondence, responding to enquiries and handling communications addressed to the Foundation.

Consent within the meaning of Article 6(1)(a) GDPR is not required merely in order to submit an enquiry through the contact form or by e-mail where another legal basis applies.

4.8. Complaints, refunds and other matters relating to the contract

Data may be processed for the purpose of handling complaints, processing refunds and resolving other matters relating to the performance of the contract.

Depending on the circumstances, the legal basis is:

Article 6(1)(b) GDPR – performance of the contract; and/or

Article 6(1)(c) GDPR – compliance with a legal obligation.

4.9. Establishment, exercise and defence of legal claims

The Controller may process personal data for the purpose of establishing, exercising or defending legal claims relating to the operation of the Website, an order or participation in the conference.

Legal basis:

Article 6(1)(f) GDPR – the legitimate interests pursued by the Controller consisting in protecting its rights and establishing, exercising or defending legal claims.

4.10. Website security

Technical data, including server logs, may be processed in order to ensure the security of the Website, detect errors and attempted unauthorised access, prevent abuse and ensure the proper operation of IT systems.

Legal basis:

Article 6(1)(f) GDPR – the legitimate interests pursued by the Controller consisting in ensuring the security and proper operation of the Website.

4.11. Managing cookie consent

Where a technology requires the user’s consent, personal data associated with the use of that technology are processed on the basis of:

Article 6(1)(a) GDPR – the data subject’s consent.

Information concerning whether consent has been granted, refused or withdrawn may also be retained to the extent necessary to demonstrate compliance with legal obligations relating to consent and accountability under the GDPR.

Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.


5. PROVISION OF PERSONAL DATA

Providing personal data is generally voluntary.

However, providing the data identified as mandatory when placing an order is necessary in order to enter into and perform the contract.

Without an e-mail address, the Controller may be unable to provide organisational information, information required to access the conference or, in the case of an eligible package, the link to the recordings.

Providing data required for an accounting document or certificate of participation is necessary if the participant requests such a document.


6. WOOCOMMERCE AND ORDER PROCESSING

The Website uses WordPress and WooCommerce software to operate the Website and the ordering process.

WooCommerce may process, within the Website’s infrastructure, information relating to, among other things:

  • orders,
  • customers,
  • selected conference packages,
  • payment status,
  • session data,
  • shopping cart data,
  • checkout data.

WordPress and WooCommerce operate within the Website’s technical infrastructure.

The mere use of WordPress or WooCommerce does not in itself mean that conference participants’ personal data are automatically transferred to the developers of WordPress or WooCommerce. Data may be transferred to an external provider only where a particular service, integration or additional functionality requires such communication.


7. ELECTRONIC PAYMENTS

Electronic payments relating to the purchase of conference participation may be processed through Paynow, a payment integration service offered within mBank S.A.’s services.

Depending on the currently available and selected payment method, the user may be redirected to the payment service provider’s system or relevant payment functionality may be made available as part of the checkout process.

Where card payments are available on the Website, the entity providing online payment processing services for card payments is Autopay S.A.

The above applies where card payments are active and available as a payment method on the Website.

The Controller may provide payment service providers with information necessary to associate a payment with an order, such as:

  • order number,
  • transaction amount,
  • other transaction data required to process the payment.

The Controller receives from the payment service provider information necessary to determine the status of the transaction.

The Controller does not store the participant’s full payment card details.

Payment service providers may, within the scope of their own statutory duties and payment services, act as separate controllers of personal data. In such cases, they process personal data in accordance with their own privacy information and applicable legal obligations.


8. HOSTING, SERVER AND BACKUPS

The Website is hosted using the infrastructure of:

dhosting.pl Sp. z o.o.

ul. Pamiętna 14B/2

02-972 Warsaw

Poland

The hosting provider may process data stored on the Website, in databases and in server logs to the extent necessary to provide hosting services, maintain security, provide technical support, remedy failures and create technical backups.

Backups of konferencja.processwork.pl are stored within the infrastructure of dhosting.pl.

Backups of the conference Website are not stored on Google Drive.


9. E-MAIL AND GOOGLE WORKSPACE

The Controller may use Google services, including Google Workspace, Gmail and Google Drive, for the purposes of correspondence, storing documents relating to the organisation of the conference and providing recordings to authorised participants.

In connection with the use of those services, Google may process personal data to the extent necessary to provide the relevant service.


10. ZOOM AND PARTICIPATION IN THE ONLINE CONFERENCE

The conference is conducted online using the Zoom platform.

In connection with participation in the conference, Zoom may process, in particular:

  • the participant’s name or display name,
  • e-mail address, where used for participation in the meeting,
  • technical data concerning the participant’s device and connection,
  • IP address,
  • information concerning the time of joining and leaving the meeting,
  • duration of participation,
  • data generated through the participant’s use of Zoom functions.

The scope of the data processed depends on the participant’s use of Zoom and the configuration of the particular meeting.

To the extent that Zoom processes data on the Controller’s instructions for the purpose of providing the conference service, it may act as a processor.

In certain circumstances Zoom may also process personal data for its own purposes and on its own legal bases, in accordance with its applicable privacy information.


11. ZOOM ATTENDANCE REPORT

The Controller intends to use Zoom’s functionality allowing an attendance report to be generated.

The report will be used primarily for the purposes of:

  • confirming a person’s participation in the conference,
  • determining the duration of participation where necessary,
  • issuing a certificate of participation,
  • resolving any doubts concerning attendance.

The Controller will use the report only to the extent necessary for the purposes described above.

The full detailed report will not be retained for longer than is necessary to complete the verification of attendance and the process of issuing certificates.

After those activities have been completed, the Controller may retain only the minimum information necessary to document the fact of participation or the issuance of a certificate, where this is justified by the need to handle subsequent enquiries, complaints or legal claims.


12. RECORDING OF THE CONFERENCE

Selected parts of the conference will be recorded for the purpose of preparing materials to be made available to persons who have purchased a package including access to recordings.

The recordings are intended primarily to cover presentations by speakers, moderators and other persons conducting the conference.

The Controller seeks to minimise the recording and subsequent disclosure of the images, voices, names and other personal data of ordinary conference participants.

Where a participant speaks during the conference or activates their camera, their voice or image may technically be captured in the source recording.

Before recordings are made available to participants who have purchased an eligible package, the Controller should review the recordings and, where necessary, remove or limit personal data relating to ordinary participants.

The Controller does not intend to use a participant’s image or voice for promotional or advertising purposes solely on the basis of that person’s participation in the conference.

Where the image, voice or statement of a particular participant is to be used in a manner going beyond the ordinary organisation of the conference and performance of the contract, the Controller will ensure that an appropriate legal basis exists, including obtaining separate consent where required.

Where applicable, the dissemination of a participant’s likeness will also be carried out in accordance with the requirements of applicable Polish law concerning the protection and dissemination of a person’s image.


13. RECORDINGS FOR PREMIUM PACKAGE PARTICIPANTS

Recordings intended for participants who have purchased the Premium Package are stored using Google Drive within the Google services used by the Foundation.

A link to the recordings will be sent by e-mail to persons who have purchased the Premium Package.

The link may be a common link provided to a group of persons entitled to access the recordings. Access does not have to be associated with an individual participant’s Google account.

A person who receives the link is required to use it in accordance with the applicable Terms and Conditions and must not make it available to unauthorised persons.

When a participant opens the recordings, Google may process technical information relating to the use of the service, including the IP address and information concerning the browser, device and connection.

The recordings will be made available for a period of one year from the date on which they are made available to participants, in accordance with the Conference Terms and Conditions.

After that period, the access link may be deactivated.

Any further storage of source materials by the Controller may take place only where there is a justified purpose for continued storage and an appropriate legal basis.


14. CONTACT FORM AND CORRESPONDENCE

The Website enables users to contact the Controller through a contact form and by e-mail.

Data provided through the form may include, in particular:

  • first name and surname,
  • e-mail address,
  • subject,
  • content of the message.

The data are processed within the systems used to operate the Website and handle correspondence.

The rules set out in this Policy do not depend on whether a technical copy of a message is stored directly in the WordPress database or only within the e-mail system.

The Controller asks users not to provide special categories of personal data through the ordinary contact form, including in particular information concerning:

  • health,
  • racial or ethnic origin,
  • political opinions,
  • religious or philosophical beliefs,
  • sex life or sexual orientation,

or other particularly sensitive information, unless providing such information is genuinely necessary in order to deal with a specific matter.


15. RECIPIENTS OF PERSONAL DATA

Personal data may be disclosed to entities supporting the Controller in organising the conference and operating the Website, in particular:

  • dhosting.pl Sp. z o.o. – hosting provider;
  • providers of IT services and entities responsible for the technical maintenance of the Website;
  • providers of e-mail and Google Workspace services;
  • Google – in connection with the use of Google Drive;
  • Zoom – in connection with the organisation of the online conference;
  • CookieYes – in connection with cookie consent management;
  • mBank S.A. – in connection with the Paynow payment service;
  • Autopay S.A. – in connection with card payments, where that payment method is active;
  • providers of accounting, legal or advisory services, where access to personal data is necessary for the provision of those services;
  • public authorities or other authorised entities, where disclosure is required by applicable law.

Not all of the above entities act in the same legal capacity.

Some entities may process personal data on behalf of the Controller as processors, while other entities – in particular certain payment service providers – may act as separate controllers in respect of processing carried out under their own legal obligations or in connection with the services they provide.

The Controller does not sell participants’ or Website users’ personal data to third parties.


16. TRANSFERS OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

The use of services such as Google, Zoom or CookieYes may involve the processing of personal data outside the European Economic Area (“EEA”) or access to personal data from countries outside the EEA.

Where personal data are transferred outside the EEA, such transfers will take place in accordance with Chapter V GDPR and, depending on the relevant provider and circumstances, may be based in particular on:

  • a European Commission adequacy decision;
  • an applicable framework recognised by the European Commission as providing an adequate level of protection, where the relevant recipient is covered by such a framework;
  • Standard Contractual Clauses approved by the European Commission;
  • other safeguards or transfer mechanisms permitted under the GDPR.

The place and scope of processing may depend on the particular service used and its current configuration.


17. DATA RETENTION

Personal data are not retained for longer than is necessary for the purposes for which they were collected, taking into account the Controller’s legal obligations and the need to establish, exercise or defend legal claims.

In particular:

a) data relating to an order and performance of a contract – are retained for the period necessary to perform the contract and thereafter to the extent necessary to comply with legal obligations and until the expiry of the applicable limitation periods for claims;

b) accounting and tax documentation – is retained for the period required under applicable law;

c) payment-related data held by the Controller – are retained for the period necessary to handle the order, payment, refunds, accounting obligations and any claims; payment service providers apply their own retention periods;

d) correspondence – is retained for the period necessary to deal with the relevant matter and, where justified, thereafter for the period necessary to protect against claims or demonstrate the course of correspondence;

e) detailed Zoom attendance reports – are retained for the period necessary to verify attendance and issue certificates; afterwards, the scope of retained information should be limited to the data necessary to document the relevant actions;

f) recordings made available to Premium Package participants – access is provided for one year from the date the recordings are made available, in accordance with the Conference Terms and Conditions;

g) technical logs – are retained for a period resulting from justified technical and security requirements and the configuration of the hosting services;

h) information concerning cookie consent – is retained for the period necessary to record the user’s preferences and demonstrate proper consent management.

When the purpose and legal basis for further processing cease to exist, the data will be deleted or anonymised, unless further retention is required or permitted by law.


18. COOKIES AND SIMILAR TECHNOLOGIES

The Website uses cookies and similar technologies.

Cookies are small pieces of information stored on a user’s terminal device or information to which the Website obtains access on that device.

The Website primarily uses technologies necessary for:

  • proper operation of the Website,
  • maintaining a user session,
  • operation of the WooCommerce shopping cart and ordering process,
  • security,
  • remembering the user’s cookie preferences.

The Website uses CookieYes to manage users’ preferences concerning cookies and, where applicable, to record whether consent has been granted or refused.


19. STRICTLY NECESSARY COOKIES

Cookies and similar technologies may be used without the user’s additional consent to the extent that storing information or accessing information already stored on the user’s terminal device is necessary:

  • for the transmission of an electronic communication; or
  • to provide a telecommunications service or an electronically supplied service expressly requested by the user.

This follows from the exception provided for in Article 399(3) of the Polish Act of 12 July 2024 – Electronic Communications Law (Prawo komunikacji elektronicznej).

Such technologies may include, in particular, technical mechanisms required for:

  • operation of WooCommerce,
  • operation of the shopping cart,
  • maintaining a session,
  • completion of an order,
  • ensuring security,
  • remembering the user’s cookie choices.

Blocking strictly necessary technologies through browser settings may result in some functions of the Website, in particular the shopping cart or ordering process, not operating correctly.


20. OPTIONAL COOKIES

Cookies and similar technologies that are not necessary to provide a service expressly requested by the user may be used only after the user has received the information required by applicable law and has given the required consent.

In particular, the user may:

  • consent to optional technologies,
  • refuse consent,
  • select individual categories where such options are available,
  • subsequently change their preferences,
  • withdraw consent.

Under Article 399 of the Polish Electronic Communications Law, storing information or accessing information stored on the user’s terminal device is, as a general rule, subject to prior information and consent unless a statutory exemption applies.

Where information obtained through cookies constitutes personal data, processing is also subject to the GDPR.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.


21. META PIXEL AND EXTERNAL ANALYTICS TOOLS

As at the date of the last update of this Policy, the Controller does not use Meta Pixel on the Website.

The Controller also does not use external analytics tools such as Google Analytics 4 or Microsoft Clarity.

Accordingly, the Controller does not currently use analytics or advertising cookies originating from those tools.

This does not exclude technical or attribution-related mechanisms associated with WooCommerce where such mechanisms are currently used by the Website. Where such technologies require consent under applicable law, they should be identified in CookieYes and activated only after the appropriate consent has been obtained.

If the Controller decides in the future to implement analytics, advertising or marketing technologies requiring consent, such technologies will be configured so that, to the extent required by law, they are activated only after obtaining the user’s consent, and this Policy will be updated accordingly.


22. CURRENT LIST OF COOKIES

The exact names of cookies, their providers and their storage periods may change as a result of updates to WordPress, WooCommerce, CookieYes and other technical components of the Website.

For this reason, the current list of cookies detected and classified by the consent management system should be available through the CookieYes cookie settings accessible on the Website.

The information displayed in the CookieYes settings supplements this Policy with regard to the current technical list of cookies used by the Website.


23. CHANGING COOKIE SETTINGS

The user may change their preferences concerning optional cookies at any time through the CookieYes consent management tool available on the Website.

Cookies may also be deleted or restricted through the settings of the user’s web browser.

However, blocking all cookies may adversely affect the correct operation of the Website, shopping cart and ordering process.


24. EXTERNAL WEBSITES

The Website may contain links to websites and online services operated by other entities.

The mere presence of an ordinary hyperlink to an external website does not mean that content from that website is automatically loaded when the user visits the Website.

As at the date of the last update of this Policy, the Website does not embed YouTube videos or similar external content that is automatically loaded when a user visits the Website.

When a user follows a link to an external service, further processing of personal data is governed by the privacy rules and policies of the operator of that external service.


25. PROFILING AND AUTOMATED DECISION-MAKING

The Controller does not make decisions concerning participants that are based solely on automated processing, including profiling, and that produce legal effects concerning them or similarly significantly affect them within the meaning of Article 22 GDPR.

As at the date of the last update of this Policy, the Controller does not use Meta Pixel or external analytics tools to profile users for advertising purposes.

This does not prevent independent payment service providers from using their own automated security, fraud prevention or risk assessment mechanisms in accordance with the rules applicable to those providers.


26. RIGHTS OF DATA SUBJECTS

Subject to the conditions and limitations laid down in the GDPR, a data subject may have the following rights:

  • the right of access to personal data, including the right to obtain a copy of the data – Article 15 GDPR;
  • the right to rectification of inaccurate or incomplete personal data – Article 16 GDPR;
  • the right to erasure of personal data – Article 17 GDPR;
  • the right to restriction of processing – Article 18 GDPR;
  • the right to data portability – Article 20 GDPR;
  • the right to object, on grounds relating to the data subject’s particular situation, to processing based on Article 6(1)(f) GDPR – Article 21 GDPR;
  • the right to withdraw consent at any time where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

The exercise of certain rights may be subject to restrictions under the GDPR or other applicable law, for example where continued processing is required for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

Requests concerning the exercise of data protection rights may be submitted to:

instytut@processwork.pl


27. RIGHT TO LODGE A COMPLAINT

A person who considers that the processing of their personal data infringes the GDPR has the right to lodge a complaint with a supervisory authority.

The supervisory authority competent in Poland is:

President of the Personal Data Protection Office

(Prezes Urzędu Ochrony Danych Osobowych – PUODO)

A complaint may be lodged in accordance with the procedures provided by the Polish Personal Data Protection Office.

The right to lodge a complaint is without prejudice to any other administrative or judicial remedy available under the GDPR.


28. DATA SECURITY

The Controller implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure of or access to personal data.

Access to personal data is limited to authorised persons and entities for whom such access is necessary to perform their duties or provide the relevant services.

The Controller also uses IT and infrastructure service providers whose services include appropriate security measures.


29. CHANGES TO THIS PRIVACY POLICY

This Policy may be updated, in particular, in the event of:

  • changes in applicable law,
  • changes in the operation of the Website,
  • implementation of new services or tools,
  • changes in the organisation of the conference,
  • changes of service providers,
  • implementation of new analytics or marketing technologies,
  • changes in the cookies and similar technologies used by the Website.

The current version of this Policy will be published on the Website together with the date of its latest update.


30. CONTACT

For questions concerning this Policy, privacy, the processing of personal data or the exercise of data protection rights, please contact the Controller:

Fundacja Instytut Psychologii Procesu

ul. Jana Kochanowskiego 27/7

01-864 Warsaw

Poland

Correspondence address:

Al. Ujazdowskie 16 lok. 58

00-557 Warsaw

Poland

E-mail:

instytut@processwork.pl