Privacy Policy

1. General Provisions This Privacy Policy and Personal Data Protection Policy sets out the principles for the processing and protection of personal data of individuals using the website:
https://learningfreedom.tilda.ws/portfolio
This Policy has been prepared in accordance with the applicable personal data protection regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 — the General Data Protection Regulation (GDPR) and the relevant provisions of Polish law concerning personal data protection.
The data controller is Daria Lupashko, hereinafter referred to as the “Controller”.
1.1.The Controller attaches particular importance to protecting users’ privacy and the security of their personal data.
Personal data is processed in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.
1.2.This Privacy Policy applies to all information that the Controller may obtain in connection with users’ use of the website:
https://learningfreedom.tilda.ws/portfolio
1.3.Use of the website constitutes acknowledgement of this Privacy Policy.
2. Basic Terms Used in the Policy 2.1. Personal Data Any information relating to an identified or identifiable natural person.
2.2. Processing of Personal Data Any operation or set of operations performed on personal data, such as collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.3. Controller A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
2.4. User Any person using the website:
https://learningfreedom.tilda.ws/portfolio
2.5. Website The website available at:
https://learningfreedom.tilda.ws/portfolio
together with its content, graphic materials, texts and other elements.
2.6. GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data.
2.7. Data Subject A natural person to whom the processed personal data relates.
2.8. Consent A freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
2.9. Anonymisation A process of processing data as a result of which it is not possible to attribute the data to a specific person without the use of additional information.
2.10. Recipient A natural or legal person, public authority, agency or other body to whom personal data is disclosed.
3. Rights and Obligations of the Controller 3.1. The Controller has the right to:— process personal data within the scope and for the purposes specified in this Policy and in accordance with applicable law;
— use the services of entities processing personal data on its behalf if necessary for the proper functioning of the website or the provision of specific services;
— retain personal data for the period necessary to achieve the purposes of processing, in accordance with applicable law;
— process personal data without consent where another legal basis specified in Article 6 of the GDPR applies.
3.2. The Controller is obliged to:— process personal data in accordance with applicable law;
— provide appropriate technical and organisational measures to protect personal data;
— ensure that Data Subjects are able to exercise the rights granted to them under the GDPR;
— provide information regarding the processing of personal data in a transparent, clear and understandable manner;
— take appropriate measures to protect personal data against unauthorised access, loss, destruction, alteration or unlawful processing;
— update or delete personal data where required by applicable law;
— cease processing personal data when there is no longer a legal basis for further processing.
4. Rights of Data Subjects 4.1. The Data Subject has the right to:— obtain information as to whether their personal data is being processed;
— obtain access to their personal data;
— obtain information about the purposes of data processing;
— obtain information about the categories of personal data being processed;
— obtain information about the recipients or categories of recipients of personal data;
— request the rectification of inaccurate or completion of incomplete personal data;
— request the erasure of personal data in cases provided for by the GDPR;
— request restriction of the processing of personal data in cases provided for by the GDPR;
— object to the processing of personal data in cases provided for by the GDPR;
— receive their personal data in a structured, commonly used and machine-readable format where the conditions specified in the GDPR are met;
— withdraw consent to the processing of personal data at any time where processing is based on consent;
— lodge a complaint with the competent supervisory authority if the Data Subject believes that the processing of their personal data violates the provisions of the GDPR.
4.2.Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
4.3.Where personal data is processed for direct marketing purposes, the Data Subject may object to such processing at any time.
4.4.To exercise their rights, the User may contact the Controller at:
zakolucki@gmail.com
5. Principles of Personal Data Processing 5.1.Personal data is processed lawfully, fairly and transparently.
5.2.Personal data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes.
5.3.The scope of personal data collected is limited to what is necessary for the specified processing purposes.
5.4.The Controller takes appropriate measures to ensure the accuracy and up-to-date nature of personal data.
5.5.Personal data is stored for no longer than is necessary for the purposes for which it was collected, unless the law requires longer storage.
5.6.The Controller takes appropriate technical and organisational measures to ensure the security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
6. Purposes of Personal Data ProcessingPersonal data may be processed in particular for the following purposes:
— enabling contact with the User;
— responding to messages and enquiries;
— providing services or preparing an offer at the User’s request;
— conducting electronic correspondence;
— fulfilling obligations arising from applicable law;
— protecting the legitimate interests of the Controller;
— ensuring the proper functioning of the website.
Personal data may include:
— first and last name;
— email address;
— telephone number;
— other data voluntarily provided by the User through the contact form or correspondence.
Legal bases for processing data:Personal data may be processed on the basis of:
— Article 6(1)(a) GDPR — consent of the Data Subject;
— Article 6(1)(b) GDPR — processing necessary for the performance of a contract or for taking steps at the request of the Data Subject prior to entering into a contract;
— Article 6(1)(c) GDPR — processing necessary for compliance with a legal obligation to which the Controller is subject;
— Article 6(1)(f) GDPR — processing necessary for the purposes of the legitimate interests pursued by the Controller or a third party, taking into account the rights and freedoms of the Data Subject.
Types of personal data processing:— collection;
— recording;
— storage;
— organisation;
— use;
— updating;
— disclosure where lawful;
— restriction of processing;
— erasure;
— destruction;
— anonymisation.
7. Conditions for Processing Personal Data 7.1.Personal data is processed on the basis of one of the grounds specified in Article 6(1) of the GDPR.
7.2.If processing is based on the User’s consent, the consent may be withdrawn at any time.
7.3.Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
7.4.Where the processing of personal data is necessary for the performance of a contract or for taking steps prior to entering into a contract at the User’s request, the Controller may process data to the extent necessary to achieve this purpose.
7.5.The Controller may process personal data for the purposes of legitimate interests, provided that such interests do not override the fundamental rights and freedoms of the Data Subject.
7.6.Personal data may also be processed where this is necessary to comply with a legal obligation to which the Controller is subject.
7.7.The Controller does not process personal data to a greater extent than is necessary to achieve the specific purpose.
8. Principles of Collection, Storage, Transfer and Protection of Personal DataThe security of personal data processed by the Controller is ensured through the use of appropriate technical and organisational measures.
8.1.The Controller takes appropriate measures to protect personal data against access by unauthorised persons.
8.2.Personal data is not sold or disclosed to third parties for purposes other than those specified in this Policy, unless the User has given consent or the transfer of data is required or permitted by applicable law.
8.3.The User may contact the Controller to correct or update their personal data by sending a message to:
zakolucki@gmail.com
with the subject line “Personal Data Update”.
8.4.The retention period for personal data depends on the purpose of processing and applicable legal requirements.
Personal data is stored for no longer than necessary to achieve the purpose for which it was collected, unless further storage is required by law.
The User may withdraw consent to the processing of personal data at any time where processing is based on consent by sending a message to:
zakolucki@gmail.com
with the subject line “Withdrawal of Consent to Personal Data Processing”.
8.5.If the Controller uses external service providers, such as hosting providers, communication tools, analytics services, payment systems or other services necessary for the operation of the website, data may be transferred to such entities only to the extent necessary to provide the relevant services and in accordance with applicable personal data protection regulations.
If an external entity processes personal data on behalf of the Controller, the Controller ensures an appropriate legal basis for such processing, including, where necessary, entering into a data processing agreement.
8.6.If personal data is transferred to a third country or an international organisation, the Controller ensures that such transfer complies with the GDPR requirements concerning transfers of data outside the European Economic Area.
8.7.The Controller ensures the confidentiality of personal data and takes appropriate measures to protect it.
8.8.Personal data is stored in a form that permits identification of the Data Subject for no longer than is necessary for the purposes for which the data is processed.
8.9.The processing of personal data may be terminated in particular in the event of:
— achievement of the purpose for which the data was collected;
— withdrawal of consent, where consent constituted the basis for processing;
— an effective objection to processing;
— expiry of the data retention period;
— cessation of the legal basis for processing.
9. Actions Taken by the Controller with Regard to Personal Data 9.1.The Controller may perform the following operations on personal data:
— collection;
— recording;
— organisation;
— storage;
— updating;
— use;
— disclosure;
— restriction of processing;
— anonymisation;
— erasure;
— destruction.
9.2.Personal data may be processed in an automated manner, including through the use of information systems and telecommunications networks, where necessary to achieve specific processing purposes.
10. Transfer of Data Outside the European Economic Area 10.1.Where personal data is transferred outside the European Economic Area, the Controller ensures that such transfer complies with the requirements of the GDPR.
10.2.Personal data may be transferred to a third country or an international organisation only where an appropriate legal basis for such transfer exists in accordance with the GDPR.
10.3.Where the Controller uses services of providers established outside the European Economic Area, the Controller may use appropriate legal mechanisms provided for by the GDPR for such transfers.
11. Confidentiality of Personal DataThe Controller and persons authorised to process personal data are obliged to maintain the confidentiality of personal data and to protect it against unauthorised access, disclosure, loss or misuse.
Personal data will not be disclosed to third parties without an appropriate legal basis, in particular without the consent of the Data Subject where such consent is required.
12. Final Provisions 12.1.The User may obtain information regarding the processing of their personal data by contacting the Controller at:
zakolucki@gmail.com
12.2.The Controller reserves the right to update this Privacy Policy in the event of changes to applicable laws, methods of personal data processing, website functionality or other significant circumstances.
12.3.The current version of the Privacy Policy will be published on the website:
https://learningfreedom.tilda.ws/portfolio
12.4.This Privacy Policy shall remain in force from the date of its publication on the website until it is replaced by a new version.
12.5.In matters concerning personal data protection, the User may also exercise their right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority responsible for personal data protection is the President of the Personal Data Protection Office (UODO). The GDPR provides Data Subjects with the right to lodge a complaint with a supervisory authority.
Get it
Made on
Tilda