Fungazza

Legal

Privacy Policy

Privacy Policy of Fundacja Fungazza

Version: 1.0 — DRAFT, pending KRS registration Effective date: [PUBLICATION_DATE] Last updated: [PUBLICATION_DATE]

§1 Introduction

This policy describes how Fundacja Fungazza ("the Foundation", "we", "us") processes your personal data when you use our website, subscribe to our newsletter, contact us, use the service configurator, make purchases in our shop, or download educational materials (freebies).

We try to write plainly while keeping the precision required by GDPR. For information about cookies specifically, see the separate Cookie Policy.

§2 Data controller

The controller of your personal data is:

Fundacja Fungazza Tęczowa 65, 53-601 Wrocław, Poland KRS (court register no.): XXXXXXXXXX (to be filled in after registration) NIP (tax no.): XXXXXXXXXX REGON (statistical no.): XXXXXXXXX

GDPR contact:

Data Protection Officer (DPO): The Foundation has not appointed a DPO because our activities do not meet the criteria of GDPR art. 37(1) (no large-scale processing, no special categories of data). For data protection matters please contact the controller directly.

Controller's representative: Michał Wysocki, President of the Board.

Nature of activities: The Foundation does not conduct commercial activity. Sales of materials and provision of services are carried out as paid public benefit activity (art. 8 of the Polish Act of 24 April 2003 on Public Benefit and Volunteer Work).

§3 Definitions

Terms used in this policy in line with GDPR:

  • Personal data — information identifying a natural person (name, email, IP address, etc.).
  • Processing — any operation on data: collecting, storing, sharing, deleting, etc.
  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • Controller — entity deciding on the purposes and means of processing (i.e. us, the Foundation).
  • Processor — external provider entrusted with processing (e.g. ConvertKit for the newsletter).
  • Consent — a freely given, informed, and unambiguous indication of will to allow processing.
  • Recipient — entity to whom we share data (e.g. courier service for shop orders).
  • Profiling — automated analysis of data to evaluate personal aspects (we do not use it).

§4 Purposes, legal bases, and retention periods

4.1 Newsletter and freebies

When you subscribe to the newsletter (directly or by requesting a freebie), we collect:

  • Your email address
  • Language preference (PL/EN)
  • An entry tag for the freebies section (freebies-access)

Purpose: Sending the newsletter (info on new content, events, educational materials) and delivering the requested freebies as a welcome incentive.

Legal basis: GDPR art. 6(1)(a) (your freely given consent confirmed via double opt-in) and art. 10(1) of the Polish Act of 18 July 2002 on Electronic Services (consent to marketing communication).

Retention: Until you withdraw consent (unsubscribe link in every email) plus up to 30 days technical buffer in our newsletter provider's system.

Recipient: ConvertKit (newsletter platform provider, USA — see §6 International transfers).

4.2 Contact form

When you write to us via the contact form, we collect:

  • Name
  • Email address
  • Phone number (if provided)
  • Subject of inquiry
  • Message content

Purpose: Responding to your inquiry and conducting correspondence.

Legal basis: GDPR art. 6(1)(b) (steps taken at your request prior to entering a contract, if your inquiry concerns our services) or art. 6(1)(f) (legitimate interest of the controller in answering general questions).

Retention: 1 year from last correspondence. After this period messages are deleted from our email archive.

Recipient: Google (Gmail/Google Workspace, USA — see §6).

4.3 Service configurator

When you use the service configurator to obtain a quote, we collect:

  • Name
  • Email
  • Phone (optional)
  • Configuration parameters: service type, number of tracks/hours, genre, deadline, additional notes

Purpose: Preparing a quote and continuing the conversation regarding potential service delivery within paid public benefit activity.

Legal basis: GDPR art. 6(1)(b) (steps taken at your request prior to a contract).

Retention: 1 year from last correspondence.

Recipient: Google (Gmail, USA).

4.4 Shop

When you place an order in our shop, we collect:

  • First name and last name
  • Email address
  • Phone number
  • Shipping address and billing address
  • Tax number (if ordering as a company)
  • Order notes (optional)
  • List of purchased products, amount, order status

Purpose: Performing the contract for sale of Foundation materials within paid public benefit activity, shipping, complaint handling, accounting and tax obligations.

Legal basis:

  • GDPR art. 6(1)(b) (contract performance)
  • GDPR art. 6(1)(c) (legal obligation — Polish tax and accounting regulations)

Retention: 6 years from the end of the year in which the transaction occurred. This results from the longest applicable obligation: 5 years for accounting documents (Polish Tax Ordinance art. 86) and 6 years for potential claims (Polish Civil Code art. 118). After this period the order is anonymized — we delete personal data (name, email, phone, addresses, notes), keeping only statistical data (amount, date, status, product list).

Recipients:

  • Google (Gmail — order confirmations, USA)
  • In the future: Vercel (hosting, USA) and Neon (database) — after infrastructure migration

4.5 Site security

To ensure security and proper operation of the site we process:

  • Anonymized IP address (last octet zeroed) in the order spam protection mechanism. Basis: GDPR art. 6(1)(f) (legitimate interest — security). Retention: 15 minutes in server memory.
  • Administrator sessions (admin email, JWT in a secure cookie) — solely for site managers. Basis: GDPR art. 6(1)(f) (legitimate interest — administration). Retention: 30 days or until logout.
  • Server logs (HTTP request metadata — URL, status, response time; without full IP address) — for debugging and monitoring. Basis: GDPR art. 6(1)(f). Retention: per Vercel default (~24 hours).

Summary table

WhatBasisRetention
Newsletter + freebiesconsent (art. 6.1.a + Polish Electronic Services Act art. 10)until unsubscribe + 30 days
Contact formcontract or legitimate interest (6.1.b/f)1 year
Configuratorcontract (6.1.b)1 year
Shop — ordercontract + legal obligation (6.1.b + 6.1.c)6 years → anonymization
Order rate limitinglegitimate interest (6.1.f)15 minutes
Admin sessionslegitimate interest (6.1.f)30 days
Server logslegitimate interest (6.1.f)~24h

§5 Recipients and processors

To pursue the purposes above we work with the following providers:

  • ConvertKit — newsletter platform. Processes subscriber emails. ConvertKit Privacy Policy
  • Google (Gmail / Google Workspace) — sending and archiving emails related to forms and orders. Google Privacy Policy
  • Cloudinary — image hosting (product photos, banners, freebie thumbnails). Does not process customer personal data, only images uploaded by the administrator. Cloudinary Privacy Policy
  • Sentry — application error and performance monitoring plus Session Replay (5% session sampling in production). We have sendDefaultPii: false set, so Sentry does not receive IP addresses, cookies, or request headers. Replay records DOM interactions with input field contents masked by default. Basis: GDPR art. 6(1)(f) (legitimate interest — service stability). Sentry Privacy Policy
  • Google Maps — embedded map showing the studio location. After cookie banner acceptance, Google may process the user's IP address and device identifiers. Google Privacy Policy
  • Vercel (after migration) — application hosting. Processes standard HTTP request metadata. Vercel Privacy Policy
  • Neon Postgres (after migration) — database. Stores order and site settings data. Neon Privacy Policy

We have signed (or will sign before deployment) a Data Processing Agreement (DPA) with each provider in line with GDPR art. 28.

§6 International transfers (Schrems II)

Some of our providers (ConvertKit, Google, Cloudinary, Sentry, Vercel, Neon) are based in the United States. This means your data may be processed outside the European Economic Area.

Transfer basis: GDPR art. 46(2)(c) — Standard Contractual Clauses (SCC) approved by the European Commission via implementing decision 2021/914.

Additional safeguard: Commission implementing decision 2023/1795 of 10 July 2023 (EU-US Data Privacy Framework, DPF) — our US providers are DPF-certified, providing an adequate level of protection.

We are considering selecting an EU region for Neon Postgres at infrastructure migration to limit transfers outside the EEA for order data.

§7 Your rights

Under GDPR you have the following rights:

  • Right of access (art. 15) — find out what personal data we process about you.
  • Right to rectification (art. 16) — correct inaccurate data.
  • Right to erasure ("right to be forgotten", art. 17) — request deletion when no further basis exists.
  • Right to restriction (art. 18) — request temporary halt of processing.
  • Right to data portability (art. 20) — receive your data in a structured format.
  • Right to object (art. 21) — to processing based on legitimate interest.
  • Right to withdraw consent (art. 7(3)) — at any time, without affecting the lawfulness of prior processing. For the newsletter just click "Unsubscribe" in any email.

§8 How to exercise your rights

To exercise any of the above rights, contact us:

We respond to requests within 30 days. In particularly complex cases the deadline may be extended to 60 days — we will inform you with reasoning within the first 30 days.

We may request additional information for identity verification (e.g. confirmation from the email used to subscribe).

§9 Complaint to the Polish DPA

You have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO):

ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl

§10 Automated decisions and profiling

We do not engage in automated decision-making or profiling within the meaning of GDPR art. 22. Your data is not used for automatic evaluation or classification.

§11 Data security

We apply appropriate technical and organisational measures to protect your data:

  • Connection encryption (HTTPS site-wide)
  • Password hashing for administrators (bcrypt)
  • Access control — administrator panel data accessible only after authentication
  • Data Processing Agreements with all providers (DPA art. 28 GDPR)
  • Data minimisation — we collect only what is necessary for each purpose

On your side it is important to maintain device security and not share logins or passwords with third parties.

§12 Cookies, embeds, and external links

Our site uses cookies and embeds content from external services (e.g. Google Maps, YouTube and Spotify players). Details on cookie types, purposes, and management are in a separate document: Cookie Policy.

Links in site content may lead to external websites. Once you navigate to such a site, that site's privacy policy applies — we are not responsible for how third parties process data.

§13 Changes to the policy

We reserve the right to update this policy, e.g. due to legal changes, infrastructure changes, or changes in the services we provide.

We will notify you of material changes:

  • Newsletter subscribers — by email at least 14 days before changes take effect
  • All users — by notice on the policy page

Earlier versions of the policy are available on request (contact: fundacja@fungazza.com).


In the event of any discrepancy between the Polish and English versions, the Polish version prevails.