This Privacy Policy sets out the rules governing the processing of personal data (including data collected through the website) by the International Institute for Particle Astrophysics of the Polish Academy of Sciences, with its registered office in Warsaw at ul. Bartycka 18, 00-716 Warsaw, Poland, Tax Identification Number (NIP): 5214157173 (hereinafter: the “Institute” or the “Data Controller”).
The Data Controller has appointed Mr Michał Zajdowicz as Data Protection Officer, who may be contacted by email at: iodo@astrocent.edu.pl.
The Data Controller may be contacted by email at: office@astrocent.edu.pl or in writing at the postal address indicated above.
In connection with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”), we hereby provide information on the rules governing the processing of your personal data by the Institute.
We make every effort to ensure all possible physical, technical and organisational measures to protect personal data against accidental or intentional destruction, accidental loss, alteration, unauthorised disclosure, use or access, in accordance with all applicable laws.
I. Definitions
Cookies – means IT data, in particular small text files, saved and stored on devices through which the User accesses the Service websites.
Controller Cookies – means Cookies placed by the Data Controller in connection with the provision of electronic services by the Data Controller through the Service.
Third-Party Cookies – means Cookies placed by the Data Controller’s partners through the Service website.
Service – means the Institute’s website available at: www.astrocent.edu.pl.
Device – means an electronic device through which the User accesses the Service.
User – means an entity for whom, in accordance with this Policy and applicable law, services may be provided electronically or with whom an agreement for the provision of electronic services may be concluded.
II. Personal Data
- When using the Service, the Institute may process Users’ personal data, such as:
- First and last name;
- Email address.
2. Personal data are processed by employees and associates of the Data Controller on the basis of authorisations granted to them. Every person authorised to process personal
data has been informed of the rules governing personal data protection and has undertaken to keep the information made available to them confidential.
3. Personal data may be entrusted to an external entity that supports the Data Controller in achieving the purposes of processing, including marketing services, email services, hosting, IT, administrative services, legal services, advisory services, etc.
4. The Data Controller uses only the services of professional entities that guarantee services of the highest standard and ensure the security of the information entrusted to them.
5. The website may redirect Users to another website managed by another data controller. The Data Controller is not responsible for the processing of personal data through other websites. On each new visit, the User should review the applicable Privacy Policy.
III. Purpose of Personal Data Processing and Legal Basis
- Personal data processed through the Service are processed for the purposes of:
- responding to messages from Service Users;
- sending content concerning the Institute’s activities in the form of a newsletter.
2. The legal basis for the processing of personal data by the Data Controller is Article 6(1)(a) GDPR, i.e. consent obtained for the processing of personal data;
IV. Rules and Duration of Personal Data Processing
- The User’s personal data will be processed until consent is withdrawn or, in connection with the Institute’s activities, for the period specified by law or until the purpose of processing has been fulfilled.
- To the extent provided for by law, the User has the right to: access their data and obtain a copy thereof; rectify their personal data; erase their personal data; restrict the processing of their personal data; and data portability.
- Where processing is based on consent pursuant to Article 6(1)(a) GDPR, the User has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
- The User has the right to lodge a complaint concerning unlawful processing of personal data with the President of the Personal Data Protection Office.
V. Transfer of Personal Data Outside the EU
- The Data Controller may use tools provided by entities established outside the European Economic Area (hereinafter: the “EEA”) or entities that may store data outside the EEA. Personal data will not be transferred to international organisations. The Data Controller will apply all legally available safeguards to protect such transfers. Transfers of data outside the EEA may take place on the basis of the derogations provided for in Article 49 GDPR, provided that the conditions set out in that Article are met. Information on the safeguards applied and the scope of data transferred outside the EEA may be obtained by contacting the Data Controller or the DPO.
VI. Profiling
Users’ personal data will not be processed by automated means, including profiling. This means that no decisions producing legal effects concerning a person or similarly
significantly affecting that person will be based solely on automated processing of personal data or involve such automated decision-making as referred to in Article 22(1) and (4) GDPR.
VII. Activities on Social Media Platforms
1. The Data Controller owns accounts on the following social media platforms:
- Facebook;
- Instagram;
- X;
- LinkedIn;
- Bluesky;
2. The Data Controller operates and manages accounts on social media platforms for the purpose of promoting its products, services and activities. In connection with these activities, it processes the personal data of social media users who follow the Data Controller’s profiles, including those who participate in competitions and events or communicate with the Data Controller and other users through accounts managed by the Data Controller.
3. If a User wishes to stop the processing of personal data made available through social media platforms, they should stop following the Data Controller’s profiles using the options provided by the relevant platform, e.g. by clicking the “Like” button on Facebook.
4. All rights to marks (including logos), copyrights, database rights and all other intellectual property rights relating to the content of the website and social media profiles belong to the Data Controller.
5. It is prohibited to copy, modify, use in any form or reproduce, in whole or in part, the content of the website for commercial purposes without the prior written consent of the Data Controller and the author of the text.
6. The content presented on the website and social media profiles is intended to promote the Data Controller’s activities. Use of the materials for other purposes is prohibited.
7. Materials made available on the Data Controller’s social media profiles are owned by the Data Controller or have been made available with the consent of their authors.
8. User who uses the Data Controller’s social media profiles represents that the Content they post:
a. will not be inappropriate. Content is considered inappropriate if it:
- constitutes plagiarism, is defamatory, offensive, abusive, false, misleading, derogatory, discriminatory, threatening or harassing, or expresses racial or sexual prejudice;
- contains mocking, discourteous or offensive elements, insults, indecent suggestions or profanity;
- contains quotations from statements made by other users that are taken out of context in order to create a false or negative impression;
- is indecent, obscene or pornographic; or
- violates another person’s right to confidentiality or privacy;
b. will not prejudice any ongoing legal proceedings of which the User is aware;
c. will not contain allegations of indecency or personal criticism directed at the Data Controller’s employees;
d. is not reasonably likely to: (i) cause another person fear, uncertainty or distress, (ii) incite conduct contrary to accepted social norms; or (iii) incite aggression or hatred on racial or religious grounds;
e. will not infringe any copyright, trademark, patent or other intellectual property right of the Data Controller or any third party;
f. will not be technically harmful (including, in particular, computer viruses, logic bombs, Trojan horses, computer worms, harmful components, corrupted data or other malicious software, harmful data or harmful activities);
g. will not constitute an offer, advertisement or promotion of any product or service and will not contain requests for donations or financial support;
h. will not constitute spam or unsolicited bulk advertising sent by email;
i. will not be intended to impersonate another person or otherwise falsely represent the User’s identity, affiliation or status;
j. will not depict or encourage conduct that could be considered a criminal offence, give rise to civil liability or otherwise be unlawful.
9. The User may post links on the Data Controller’s profile to other websites and webpages provided that:
- the content of, or links to, such websites or webpages do not violate any provisions of this Privacy Policy;
- the terms and conditions governing the use of such websites or webpages permit links to them to be posted;
- the links are clearly and visibly identified as links;
- the content of the websites or webpages is clearly related to the Content next to which the link is posted; and
- the link does not cause any files to be downloaded automatically.
10. The Data Controller reserves the right to immediately remove any content that does not comply with the above rules, in particular comments that are:
- defamatory, false or misleading;
- offensive, insulting or threatening;
- obscene or sexual in nature;
- abusive, racist, sexist, homophobic or discriminatory against any religion or other group of persons.
Such content will be deleted immediately.
- Without the Data Controller’s express consent, the User is not entitled to repost any Content, materials or applications that have previously been removed.
VIII. Types of Cookies Used
The Cookies used by the Data Controller are safe for the User’s Device. In particular, they cannot be used to introduce viruses, other unwanted software or malicious software into Users’ Devices. These files make it possible to identify the software used by the User and to tailor the Service individually to each User. Cookies usually contain the name of the domain from which they originate, the period for which they are stored on the Device, and an assigned value.
The Data Controller uses two types of cookies:
- Session Cookies: these are stored on the User’s Device and remain there until the end of the relevant browser session. The stored information is then permanently deleted from the Device’s memory. The session cookie mechanism does not allow any personal data or confidential information to be retrieved from the User’s Device.
- Persistent Cookies: these are stored on the User’s Device and remain there until they are deleted. Ending a browser session or switching off the Device does not remove them from the User’s Device. The persistent cookie mechanism does not allow any personal data or confidential information to be retrieved from the User’s Device.
The following types of cookies are used within the Service:
- “necessary” cookies, enabling the use of services available within the Service, e.g. authentication cookies used for services requiring authentication within the Service;
- cookies used to ensure security, e.g. to detect misuse of authentication within the Service;
- “performance” cookies, enabling the collection of information on how the Service websites are used;
- “functional” cookies, enabling the Service to “remember” settings selected by the User and personalise the User interface, e.g. the selected language or the region from which the User originates, font size, website appearance, etc.;
In many cases, software used to browse websites (a web browser) allows cookies to be stored on the User’s end device by default. Service Users may change their cookie settings at any time. In particular, these settings may be changed so as to block automatic handling of cookies in the web browser settings or to notify the User each time cookies are placed on the Service User’s device. Detailed information on the options and methods for managing cookies is available in the software settings (web browser).
IX. Purposes for Which Cookies Are Used
The Data Controller uses First-Party Cookies for the following purposes:
- configuring the Service, adapting the content of the Service websites to the User’s preferences and optimising use of the Service websites;
- recognising the Service User’s Device and its location and displaying the website appropriately, tailored to the User’s individual needs;
- remembering settings selected by the User and personalising the User interface, e.g. the selected language or the region from which the User originates;
- remembering the history of pages visited within the Service for the purpose of recommending content; font size, website appearance, etc.;
- correctly configuring selected Service functions, in particular enabling verification of the authenticity of the browser session;
- optimising and improving the performance of services provided by the Data Controller;
- carrying out processes necessary for the full functionality of the websites, adapting the content of the Service websites to the User’s preferences and optimising use of the Service websites. In particular, these files make it possible to recognise the basic parameters of the User’s Device and display the website appropriately, tailored to the User’s individual needs;
- correct operation of the affiliate programme, in particular enabling verification of the sources from which Users are referred to the Service websites;
- remembering the User’s location and correctly configuring selected Service functions, in particular enabling information provided to the User to be adapted with regard to their location;
- analysis, research and audience measurement by creating anonymous statistics that help to understand how Service Users use the Service websites, thereby enabling improvements to their structure and content;
- ensuring the security and reliability of the Service.
X. Options for Determining the Conditions for Storing or Accessing Information via Cookies:
The User may independently change their Cookie settings at any time, specifying the conditions for storing Cookies and for Cookies to access the User’s Device. The User may make the changes referred to in the preceding sentence using the web browser settings or service configuration. In particular, these settings may be changed so as to block automatic handling of cookies in the web browser settings or to notify the User each time Cookies are placed on the User’s device. Detailed information on the options and methods for managing cookies is available in the software settings (web browser).
Cookies placed on the Service User’s end device may also be used by partners cooperating with the operator.
The User may delete Cookies at any time using the functions available in the web browser they use.
Restricting the use of Cookies may affect some functionalities available on the Service website.
See how to disable cookies:
XI. Final Provisions
- The Data Controller reserves the right to update the content of the Privacy Policy.
- The Data Controller reserves the right to withdraw or modify content presented on the Website without prior notice. The Data Controller shall not be liable if, for any reason beyond its control, the Website is unavailable at any time or for any period.
- The Data Controller reserves the right to occasionally restrict access to certain parts of the Website in connection with maintenance work or Website updates.
- In matters not regulated by the Privacy Policy but relating to its subject matter, and where any part of the Privacy Policy is inconsistent with applicable law, the relevant provisions of Polish law shall apply in place of the challenged provision of the Policy, in particular:
- the Act of 23 April 1964 – Civil Code;
- the Act of 2 March 2000 on the protection of certain consumer rights and liability for damage caused by a dangerous product;
- the Act of 27 July 2002 on specific conditions of consumer sales and amendments to the Civil Code;
- the Act of 18 July 2002 on Providing Services by Electronic Means (hereinafter: the “Act on Electronic Services”);
- the Act of 10 May 2018 on the Protection of Personal Data;
- the GDPR.