Skip to main content

Privacy Po­licy

Hello!

If you are reading this, it is a sure sign that you value your privacy. We completely understand, which is why we have prepared this document for you. Here you will find, in one place, all the information regarding how we process personal data and use cookies and other tracking technologies in connection with the operation of the aixmat.candela.org.pl website.

To begin with the formalities, the controller of this website is the Candela Foundation, with its registered office in Warsaw (02-822), ul. Grochowska 357/513, entered into the Polish National Court Register (KRS) under number 0000885495, holding Tax Identification Number (NIP) 1133028363 and REGON number 388293056.

This Privacy Policy has been structured in the form of questions and answers to make it as clear and easy to read as possible. Should you have any questions regarding this Privacy Policy, you may contact us at any time by sending an email to hello@candela.org.pl.

1. Who is the controller of your personal data?

The controller of your personal data is the Candela Foundation, with its registered office in Warsaw (02-822), ul. Grochowska 357/513, entered into the Polish National Court Register (KRS) under number 0000885495, holding Tax Identification Number (NIP) 1133028363 and REGON number 388293056.

2. Who can you contact regarding the processing of your personal data?

As part of implementing personal data protection measures within our organisation, we have decided not to appoint a Data Protection Officer (DPO) because, in our circumstances, such an appointment is not required by law. For any matters relating to the protection of your personal data or privacy in general, you may contact us at: hello@candela.org.pl

3. What information do we hold about you?

The categories of personal data we process are specified separately for each processing purpose in Appendix 1 to this Privacy Policy.

4. Where do we obtain your personal data?

In most cases, you provide your personal data directly to us. This happens when you:

  • contact us by email;
  • submit a request relating to the processing of your personal data.

Appendix 1 to this Privacy Policy identifies the source of the personal data for each processing purpose. In addition, certain information about you may be collected automatically through the tools we use. For example:

  • our website automatically records your IP address.

5. Is your personal data secure?

We take the security of your personal data seriously. We have assessed the risks associated with each processing activity involving your personal data and have implemented appropriate technical and organisational measures to ensure its security. We continuously monitor the condition of our technical infrastructure, provide regular staff training, review our internal procedures and introduce improvements whenever necessary. If you have any questions regarding the security of your personal data, please contact us at: hello@candela.org.pl

6. For what purposes do we process your personal data?

The purposes for which we process your personal data are set out in Appendix 1 to this Privacy Policy.

7. How long do we retain your personal data?

We retain your personal data for as long as is justified by the relevant purpose of processing. Accordingly, retention periods vary depending on the purpose for which the data are processed. Details of the applicable retention periods can be found in the table attached as Appendix 1 to this Privacy Policy.

Please note that the completion of processing for one purpose does not necessarily mean that your personal data will be deleted or destroyed entirely. This is because the same data may continue to be processed for another lawful purpose for the period applicable to that purpose.

For example, once correspondence between us has concluded, we cease processing your personal data for the purpose of handling that correspondence. However, the data contained within that correspondence may continue to be retained for archival purposes, including the establishment, exercise or defence of legal claims relating to that correspondence.

Your personal data will be permanently deleted or securely destroyed only once all applicable processing purposes have come to an end. In practice, this will usually occur after the expiry of the relevant limitation period for legal claims or administrative liability, or after the statutory period during which we are legally required to retain specific information.

8. Who are the recipients of your personal data?

Modern organisations rely on services provided by third parties, and we are no exception. Some of these services involve the processing of your personal data on our behalf. The external service providers who process your personal data include:

  • our hosting provider, which stores data on its servers.

All of the above entities process your personal data under data processing agreements concluded with us and provide an appropriate level of protection for your personal data.

Where necessary, your personal data may also be disclosed to a solicitor, barrister or other legal adviser who is bound by professional confidentiality obligations. Such disclosure may be necessary where we require legal assistance involving access to your personal data.

In addition, where Anonymous Information is concerned, providers of tools or plugins that collect such Anonymous Information may also have access to it. These providers act as independent controllers of the data they collect and may process or disclose such data in accordance with their own terms and privacy policies, over which we have no control.

9. Do we transfer your personal data to third countries or international organisations?

Yes. Certain processing activities may involve the transfer of your personal data to third countries.

We transfer personal data to third countries in connection with our use of tools and services that store personal data on servers located outside the European Economic Area, particularly in the United States.

The providers of these services ensure an appropriate level of protection for personal data by implementing the safeguards required under the GDPR, in particular by using the European Commission's Standard Contractual Clauses (SCCs) or other recognised transfer mechanisms.

The services that may involve transfers of personal data to third countries include:

  • email services.

The categories of personal data transferred include:

  • information contained in email correspondence.

10. Do we use profiling or make automated decisions based on your personal data?

No. We do not make decisions concerning you based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you.

11. What rights do you have in relation to the processing of your personal data?

Under the GDPR, you may have the following rights in relation to the processing of your personal data:

  • the right to access your personal data and obtain a copy of it;
  • the right to rectify inaccurate or incomplete personal data;
  • the right to erasure ("the right to be forgotten"), where the legal conditions are met;
  • the right to restrict the processing of your personal data;
  • the right to object to processing based on our legitimate interests, where your particular situation justifies such an objection;
  • the right to data portability, allowing you to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have those data transmitted directly to another controller;
  • the right to withdraw your consent at any time where processing is based on your consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn;
  • the right to lodge a complaint with a supervisory authority if you believe that your personal data are being processed unlawfully.

The rules governing the exercise of these rights are set out in Articles 16–21 of the GDPR. We encourage you to familiarise yourself with those provisions. Please note that these rights are not absolute and may not apply in every circumstance involving the processing of your personal data. However, you always have the right to lodge a complaint with the competent supervisory authority if you believe that we have breached applicable data protection legislation.

You may also contact us at any time to request information about what personal data we hold about you and the purposes for which we process it. Simply send an email to hello@candela.org.pl.

We have made every effort to ensure that this Privacy Policy provides comprehensive information about our processing activities. If you have any further questions concerning the processing of your personal data, please contact us at: hello@candela.org.pl

12. Do we use cookies or similar technologies, and what are they?

No. We do not collect cookies.

13. Do we monitor your activity on our website?

No. We do not monitor your activity within our website.

14. Do we display targeted advertising?

No. We do not display targeted or behavioural advertising.

15. How can you manage your privacy?

Many of the privacy controls available to you have already been described throughout this Privacy Policy, particularly in relation to cookies, behavioural advertising and consent mechanisms. For your convenience, we have summarised them below.

You can manage your privacy by using:

  • your web browser's cookie settings;
  • browser extensions supporting cookie management, such as Ghostery;
  • additional software designed to manage cookies;
  • your browser's private or incognito mode;
  • behavioural advertising preference tools, such as youronlinechoices.com.

16. What are server logs?

Using our website involves sending requests to the server on which the website is hosted. Every request made to the server is recorded in server logs.

Server logs typically include:

  • your IP address;
  • the date and time of the request;
  • information about your web browser;
  • information about your operating system.

These logs are stored on the server.

The information contained in server logs is not linked to individual users and is not used by us to identify you.

Server logs are used solely for the purpose of administering the website and are accessible only to authorised persons responsible for server administration.

17. Is there anything else you should know?

As you can see, the topics of personal data processing, cookies and privacy management are complex.

We have made every effort to ensure that this Privacy Policy provides clear and comprehensive information about the matters that are most important to you.

If anything remains unclear, if you would like further information, or if you simply wish to discuss your privacy with us, please contact us at: hello@candela.org.pl

18. Can this Privacy Policy be amended?

Yes.

We may update this Privacy Policy from time to time, particularly in response to:

  • technological changes affecting our website;
  • changes in applicable legislation; or
  • changes in our processing activities.

Where any amendment materially affects the way in which we process your personal data and we hold your electronic contact details, we will notify you of the changes by email.

This version of the Privacy Policy has been effective since 1 July 2026.


Appendix 1 – Purposes of Personal Data Processing

Purpose of processingLegal basisCategories of personal dataRetention periodSource of the data
Handling correspondenceArticle 6(1)(f) GDPR – our legitimate interest in responding to correspondence addressed to us.Email address and personal data contained in correspondence.Until the correspondence has been concluded.Incoming correspondence.
Handling requests relating to personal data processingArticle 6(1)(c) GDPR – compliance with our legal obligations under the GDPR.Personal data provided in the request, including the contents of the request.Until the request has been fully processed and closed.Request submitted by the data subject.
ArchivingArticle 6(1)(f) GDPR – our legitimate interest in retaining information for the purposes of establishing, exercising or defending legal claims and demonstrating compliance with our obligations under the GDPR.Various categories of personal data, depending on the information provided to us and the extent to which its retention is justified for archival purposes.Until the expiry of the applicable limitation period for legal claims or the expiry of any legal obligation relating to the protection of personal data.All forms and communications through which personal data are provided to us.