Privacy policy

Personal data processing notice


I. Data controller

Data Controller

The Candela Foundation. Grochowska 357/513, 03-822 Warsaw, Poland Warsaw is the Controller of your personal data processed as part of the newsletter.

You can contact the Controller:

  • via mail: The Candela Foundation. Grochowska 357/513, 03-822 Warsaw, Poland 
  • by email: hello@candela.org.pl

II. Data Protection Officer (DPO)

The Controller has appointed a Data Protection Officer (DPO) who may be contacted via e-mail at: iod@candela.org.pl

You may contact the DPO in all matters regarding your personal data processing by the Candela Foundation and executing your rights related to personal data processing.

However, the DPO’s duties shall not include other matters, such as providing information on the newsletter.

III. Purposes of and legal basis for processing

The Controller shall process the data of newsletter subscribers to send the newsletters issued by Candela Foundatio by electronic means. 

The Controller shall process the following data:

  1. name and surname;
  2. email address;
  3. affiliation.
  4. information on sending newsletters.

The basis for personal data processing is provided by Article 6(1)(a) of the GDPR (personal data processing consent).

You may withdraw the consents for personal data processing at any time, for example, by sending an e-mail to the following address: newsletter@candela.org.pl or iod@candela.org.pl

Please also be reminded that withdrawal of your consent shall not affect the lawfulness of processing based on your consent before its withdrawal 

IV. Data retention period

Your data shall be processed for the period necessary to achieve the purpose specified above or until the time you withdraw your processing consent. After the intended purpose is achieved, your personal data shall be deleted. 

V. Data recipients

Access to your personal data shall also be granted to authorized employees and associates of the Candela Foundation who must process your data in connection with the executed task. 

Entities that the Controller commissioned to perform certain activities entailing the necessity to process personal data may also be data recipients; these include GetResponse Sp. z o.o. . In order to ensure appropriate protection of personal data we signed data processing agreements with such recipients. 

VI. Data transfers outside of the European Economic Area (EEA)

Your personal data shall not be transferred to third countries.The newsletter is implemented using the forms and drives provided by Google. Your data shall be processed by Google, our Google Workspace for Non-profit service provider (with whom we have signed a personal data processing agreement) at their data processing centers.

VII. Rights connected with data processing

We guarantee you the ability to exercise all your rights according to the principles specified by the GDPR, i.e. the right to:

  • access the data and receive a copy;
  • rectify (correct) your personal data;
  • restrict personal data processing;
  • erase personal data (subject to Article 17(3) of the GDPR);
  • lodge a complaint with the President of the Personal Data Protection Office if you believe that the personal data processing violates the personal data protection laws. 

VIII. Obligation to provide data and consequences of failure to provide data

Providing personal data to be able to use the newsletter is voluntary. Failure to provide the data shall prevent you from receiving the newsletter.