Privacy Policy
This is an English translation provided for convenience. The Polish version is the binding one; in the event of any discrepancy, the Polish text prevails.
This document describes what personal data we process on the Torodeo website, for what purpose, on what legal basis and for how long, as well as the rights available to data subjects.
1. Data controller
The controller of personal data is the operator of the Torodeo website.
Personal data matters are handled at [email protected].
We have not appointed a data protection officer, because none of the conditions in Article 37 GDPR applies.
2. Purposes, legal bases and scope of data
- Providing the service and security
- IP address and basic technical information recorded in server logs. Basis: Article 6(1)(f) GDPR, the legitimate interest in maintaining and protecting the infrastructure.
- Audience statistics
- IP address, anonymised before it is stored, together with data on page views, entry source and device type. Basis: Article 6(1)(f) GDPR, the legitimate interest in learning which content is read.
- Handling correspondence
- Email address and the content of the message. Basis: Article 6(1)(f) GDPR, the legitimate interest in providing a reply.
The Service does not operate user accounts and does not send a newsletter. Providing personal data is voluntary and is not required in order to use the content of the Service; in correspondence, the absence of an email address makes it impossible to reply.
3. Retention periods
The periods below are target periods. Data may be retained longer where this is necessary to investigate a security incident, to establish, pursue or defend claims, or to comply with an obligation arising from the law, and for as long as it remains in backups until those are overwritten in the normal cycle. Once that need ends, the data is deleted.
- Server logs: not less than 30 days, up to 12 months as a target.
- Statistical data: up to 25 months.
- Correspondence: up to 12 months from the closure of the matter.
4. Recipients of the data
We do not sell the data and do not share it for marketing purposes. We entrust it only to entities processing it on our instructions, under a data processing agreement: the provider of hosting infrastructure and the provider of the content protection and delivery acceleration service, through whose infrastructure traffic directed to the Service passes.
We run our statistics on our own installation, on our own infrastructure; data about visits does not reach any external analytics provider.
5. Transfers outside the European Economic Area
As a rule we process data within the European Economic Area. The content protection and delivery acceleration service relies on nodes distributed globally, so requests may be handled outside the EEA. Any such transfer takes place solely on the basis of a European Commission adequacy decision or standard contractual clauses approved by the Commission.
6. Analytics and cookies
We use our own, self-hosted visit analytics. It operates in cookieless mode: the analytics tool neither stores nor reads any information on the user's device, does not use a user identifier, heatmaps, session recording or browser fingerprinting, and does not combine data across websites. The IP address is anonymised and the session identifier is computed server-side and reset daily.
Article 399 of the Polish Electronic Communications Law of 12 July 2024 requires consent for storing information or gaining access to information in terminal equipment. Since our analytics neither stores nor gains access, that provision does not apply to it, and this is why we do not display a cookie consent banner.
Independently of analytics, the Service may store on the user's device cookies necessary for it to function: those remembering the user's choices as to how the Service is displayed (language version and colour theme) and those ensuring the security of using the Service, including protection against requests being sent on the user's behalf without authorisation. They are stored when they are needed; a user relying on default settings may receive none of them.
None of them serves to track, none contains an identifier or any other information allowing a person to be recognised, and none is read for a purpose other than the one it was created for. They are information necessary to provide the service requested by the user within the meaning of Article 399(3) of the Electronic Communications Law, and storing them does not require consent. They can be deleted and blocked in browser settings; the Service will then stop remembering the chosen settings and some of its features may not work correctly.
The language version and the colour theme can be changed at any time using the switches available on every page.
7. Links to external services
The Service may contain links to third-party websites. The transition takes place through a redirect on our server, and we store no information on the user's device in the process. Once the user has moved on, the data processing rules of the owner of the destination website apply; that owner is a separate controller of such data. Their privacy policy should be read on their own site.
8. Social media profiles
We operate profiles on social media services. As regards statistics concerning visitors to those profiles, we are a joint controller of the data together with the operator of the given service, within the meaning of Article 26 GDPR. We do not receive data identifying individual persons in the process, only aggregate summaries. Basis: Article 6(1)(f) GDPR, the legitimate interest in conducting communication and promoting the Service.
The essence of the arrangement between the joint controllers is determined by the operator of the social media service and made available in its own terms. Processing of data by the operator, including profiling for advertising purposes, takes place on terms set by that operator and is outside our control. Rights under the GDPR may be exercised both against us and against the operator of the service.
Where a user contacts us by private message or comment, we process the content of the message and the profile name in order to reply. Basis: Article 6(1)(f) GDPR.
9. Profiling
On the Service we do not carry out profiling or automated decision-making producing legal effects concerning the user or similarly significantly affecting them.
10. Rights of data subjects
- the right of access to the data and to obtain a copy of it,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing based on a legitimate interest, including to audience statistics.
These rights apply to the extent and on the conditions set out in the GDPR; some of them, including the right to data portability, depend on the legal basis of the processing.
A request need only be sent to [email protected]. We reply without undue delay and at the latest within one month.
11. Complaint to the supervisory authority
A data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
12. Changes to this policy
We update this policy when the scope of processing or the law changes. The date of the last change appears at the end of this document.