Document · GDPR
Privacy policy
The voctensemble.com website is an informational website and a channel for receiving donations towards the Foundation's statutory purposes. We use no marketing cookies and no analytics tools, we do not profile our visitors, and we take no automated decisions about them. Below we set out precisely what data may be processed while you use the site — including while you make a donation — and who is responsible for it.
Data controller
The controller of the personal data processed in connection with your use of the voctensemble.com website is:
ul. Św. Filipa 23/3, 31-150 Kraków
KRS 0001237252 · NIP 6762718992 · REGON 544621525
The Foundation pursues statutory purposes in the field of culture and sacred art. This site is its informational website and a channel for receiving donations.
Contact about your data
For anything to do with the processing of personal data, please write to:
or by post, to the Foundation's registered office
We have not appointed a Data Protection Officer — the scope and nature of our processing do not require one (art. 37 GDPR).
What data we process
Visitors to the site
Simply opening the site causes technical data to be processed automatically by the hosting servers and the content delivery networks (CDN):
- the device's IP address,
- HTTP headers (browser type, language and referrer, among others),
- the date and time of the request,
- the address of the resource requested.
These are standard HTTP server logs. We do not combine them with any other data and we do not use them for profiling or marketing. They serve only to keep the site running and secure (blocking abusive traffic, for instance).
Donors
When a donation is made, we process the data needed to carry out the transaction, to issue any donation certificate, and to meet the Foundation's accounting obligations. What is processed, and how, depends on the method chosen:
The Axepta BNP Paribas payment gateway (BLIK, instant transfers, Apple Pay, Google Pay, cards)
We use the Axepta BNP Paribas payment gateway, operated by BNP Paribas Bank Polska S.A. For card transactions the acquirer is PayU S.A. Payment follows a redirect model, onto the operator's own secure page:
- Once you have chosen an amount and given an e-mail address, our server passes the gateway only the amount, the currency, the e-mail address and the donation identifier, and receives in return a single-use link to a payment page.
- You are redirected to the operator's hosted payment page, where you enter your payment details directly (a BLIK code, card details, or your choice of bank for an instant transfer). When it is done you return to our site with the status of the transaction.
Full payment details (card number, BLIK code, online banking credentials) are entered on the operator's page and nowhere else — they do not pass through the Foundation's servers and we do not store them. It is the operator that tokenises them and that carries the burden of authorisation and the security obligations of the PCI DSS standard. On the Foundation's side we keep only the donor's e-mail address, the amount, the currency, the date, the transaction identifier and its status — no more than is needed for our accounting records and to issue a confirmation of the donation.
Zrzutka.pl
What data is processed is determined by Zrzutka.pl's own policy; within that service the controller of contributors' data is Zrzutka Sp. z o.o.
Bank transfer (one-off or standing order)
The data comes from the transfer instruction itself (sender, reference, amount) and reaches us only through the bank that holds our account. The same applies to recurring transfers (standing orders): setting one up, changing it and cancelling it all happen entirely within the donor's own banking — we store neither your card details nor a debit mandate for the purpose, and the instruction remains under your sole control.
Joining the patrons (the regular-support form)
If you decide to join the patrons of the cycle and fill in the form in the “Patronage” section, we process the first name, surname and e-mail address you give us. We record them for one purpose only: to be in touch with you about regular support. The form collects no payment details whatsoever — the support itself is made by transfer (a standing order) that you set up and control in your own banking. Your data is held on our servers in the European Union; the internal notice of a new submission that we send ourselves contains none of your personal data.
The concert invitation list
If you ask us for invitations to the concerts, we process your e-mail address, the language of the page you signed up on, and — if you give one — your first name. The name is optional and serves one purpose only: so that the letter can greet you by name. Without it the invitation is exactly the same. Signing up takes two steps: once the form is sent we send a single message asking you to confirm, and only following the link in it puts the address on the list; until then we send nothing further. Alongside the address we record the date and time of the confirmation and the version of the consent clause shown beside the form — that is the proof the consent was given, and nothing beyond it; we do not record your IP address. Every message we send carries a link that takes you off the list in one click.
The list exists in order to invite you to the concerts of the VoctEnsemble. Should the foundation cease to operate or be reorganised, the list may be transferred to the person or entity that carries the ensemble on. We will tell you before that happens — in a separate message, and with the chance to leave the list before any transfer. Without that notice and without that chance, no transfer will take place.
E-mail correspondence
If you write to one of our addresses, we process the data contained in that correspondence — the sender's e-mail address, the signature, the content of the message — solely in order to reply.
Audio preference (localStorage)
When you choose “Enter with voice” or “Enter in silence”, we save your choice in your browser's local storage (localStorage) under the key voct.demo.audio. The entry expires after 3 hours and holds nothing but the preference and a timestamp. It is not personal data and it never leaves your browser.
Purposes and legal bases
We process your data for the following purposes and on the following legal bases under the GDPR:
- Keeping the site running and secure (server logs) — art. 6(1)(f) GDPR, the controller's legitimate interest in the continuity and security of the site.
- Carrying out a donation — art. 6(1)(b) GDPR (necessary for the performance of the donation contract) together with (c) (legal obligations relating to a foundation's accounts and reporting). To that extent the payment is handled by the operator Axepta BNP Paribas / PayU.
- Issuing a donation certificate — art. 6(1)(c) GDPR, in performance of obligations arising from tax law.
- Contact about patronage — art. 6(1)(a) GDPR (the consent you give in the form). You may withdraw that consent at any time by writing to rodo@voctensemble.com; withdrawal does not affect the lawfulness of processing carried out before it.
- Inviting you to concerts — art. 6(1)(a) GDPR (the consent you give when signing up) and art. 10(2) of the Polish Act on providing services by electronic means. You may withdraw that consent at any time — through the link in every message we send, or by writing to rodo@voctensemble.com; withdrawal does not affect the lawfulness of processing carried out before it.
- Establishing, pursuing or defending claims — art. 6(1)(f) GDPR, the Foundation's legitimate interest (in connection with a mistaken payment or a dispute, for instance).
- Replying to correspondence — art. 6(1)(f) GDPR, our legitimate interest in communicating with people interested in the Foundation's work.
Recipients of the data
Depending on what you are doing, your data may reach the following parties (either as processors or as separate controllers):
- Providers of technical infrastructure (hosting, CDN) — trusted parties supplying the servers and the content delivery network the site needs to run and to stay protected. They act as processors on our instructions. We serve our fonts locally and pass no IP addresses to third-party font providers.
- Vercom S.A. (ul. Wierzbięcice 1B, 61-569 Poznań, Poland) — operator of the EmailLabs service, which we use for the concert invitations. It acts as a processor on our instructions and receives only the recipient's e-mail address and the content of the message being sent. It is a Polish company, and the servers handling the sending are in Poznań and Berlin — the sending does not leave the EEA.
- BNP Paribas Bank Polska S.A. (ul. Kasprzaka 2, 01-211 Warszawa) — operator of the Axepta BNP Paribas gateway. It processes transaction data (BLIK, instant transfers, Apple Pay, Google Pay) in order to authorise and settle payments. Under the agreement we have with it, it is a separate (independent) controller of the personal data processed to carry out a payment. Privacy policy: bnpparibas.pl/repozytorium/rodo.
- PayU S.A. (ul. Grunwaldzka 186, 60-166 Poznań) — the acquirer for card transactions. It handles authorisation and tokenisation and processes card data in line with the PCI DSS standard. It too is a separate (independent) controller of personal data. Privacy policy: poland.payu.com/prywatnosc.
- Zrzutka Sp. z o.o. — from the moment you follow the link to our fundraiser and give through Zrzutka. It is a separate controller; its policy: https://zrzutka.pl/privacy.
- The Foundation's accountancy office — to the extent needed to keep the books and the record of donations.
Transfers outside the EEA
The Foundation limits transfers of data outside the European Economic Area wherever it can. Our main server infrastructure is located within the European Union.
Where the technical operation of the site does involve a transfer outside the EEA (through content delivery networks, for instance), it takes place solely on the basis of Standard Contractual Clauses (SCCs) or another safeguard provided for by the GDPR.
The payment gateway's operator (BNP Paribas Bank Polska S.A.) and the card acquirer (PayU S.A.) are both established in Poland. They may nonetheless — within their own anti-fraud systems — process data outside the EEA as well, for which they answer on the terms set out in their own privacy policies.
The concert invitations are delivered by Vercom S.A. (the EmailLabs service), established in Poznań, Poland, and the servers handling the sending are in Poznań and Berlin. Neither the content of the invitations nor the recipients' addresses are therefore transferred outside the EEA.
How long we keep it
- HTTP server logs — up to 12 months as a rule, unless the law or an ongoing procedure (an abuse investigation, for instance) justifies keeping them longer.
- Donors' data (accounting records and proof of payment) — for 5 years, counted from the beginning of the year following the financial year the data concerns. This obligation follows directly from art. 74 of the Polish Accounting Act and from the provisions of the Tax Ordinance. That period applies to payments that went through; the point below covers an attempt that was interrupted.
- An interrupted or unsuccessful attempt to give — for 12 months from the attempt, after which we permanently delete the e-mail address and everything recorded about the attempt. Where a payment did not go through, no accounting document and no tax obligation arises, so the five-year period above does not apply here. We keep the shorter period for one reason only: to recognise a payment the operator confirms late, and to deal with a complaint should your card have been charged despite the failure recorded on our side.
- E-mail correspondence — until the matter is closed, and no longer than 3 years from the last exchange. That period may be extended until any claims become time-barred, where the correspondence is evidence in a case.
- Patronage submissions — until contact about patronage ends or consent is withdrawn. If a lasting relationship follows, the data moves into the retention regime for donors (accounting records, 5 years). Otherwise we delete it permanently 12 months after the matter is closed, and a submission nobody formally closed — after 24 months with no contact from either side.
- Sign-up to the invitation list — we keep the address and any first name you gave until consent is withdrawn. A sign-up left unconfirmed (no click on the link) is deleted when the link expires, that is after 7 days. Once you unsubscribe we send nothing further and keep only the proof of the consent given earlier — the address, the date of the confirmation and the version of the clause — for as long as any claims may be brought, and no longer than 3 years.
- Audio preference in localStorage — 3 hours from when it is written, or until the user clears their browser data.
Your rights
Under the GDPR you have the following rights:
- The right of access to your data and to obtain a copy of it (art. 15 GDPR).
- The right to rectification of inaccurate or incomplete data (art. 16).
- The right to erasure of your data (“the right to be forgotten”, art. 17).
- The right to restriction of processing (art. 18).
- The right to data portability, where processing is based on consent or on a contract and is carried out by automated means (art. 20).
- The right to object to processing based on the controller's legitimate interest (art. 21).
- The right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl).
To exercise any of these rights, write to rodo@voctensemble.com. We answer without undue delay, and within one month of receiving the request at the latest.
Visit statistics
To improve the site and to understand what content interests you, we use Plausible Analytics. It is a privacy-first tool:
- No cookies: the tool uses no cookie files and writes nothing into your browser's storage.
- Fully anonymous: we collect no IP addresses, no location data and no information that would allow any individual to be identified.
- Minimal: we process only raw, aggregated statistics (visit counts, the most-read pages), and we use them for nothing but improving the site.
Full details of how the tool protects privacy can be found in Plausible's official Data Policy.
Security
- The site is served only over an encrypted HTTPS (TLS 1.3) connection.
- We enforce HTTP Strict Transport Security (HSTS) with preload — a browser will not allow an unencrypted connection to our domain.
- We store no full payment card details and no BLIK codes on the Foundation's servers — you enter them directly on the operator's hosted page (Axepta BNP Paribas / PayU), which tokenises them and answers for their security under the PCI DSS standard.
- Our server is not an intermediary in the transmission of payment data — all we pass to the gateway is the amount, the currency, the e-mail address and the donation identifier, over an encrypted TLS connection alone, in order to generate the link to the payment page.
- E-mail addresses are held in mailboxes protected by multi-factor authentication.
Changes to this policy
We update the policy whenever the way we process data changes — when we add a payment method, add a form, or change our technical infrastructure. Every change carries a new version number and a date from which it applies (at the head of this document).
This policy is published in Polish, and also in English and French translation. The Polish version is the binding one; the translations are for information only, and in the event of any discrepancy between the language versions the Polish wording prevails.
Version history
- 1.5 · 15 September 2026 — The changes concern the mailing list. We have named it the concert invitation list rather than the notice list — the name changes, not the scope. You may now give a first name when signing up; it is optional and serves only so that the letter can greet you by name (§ 3 and § 7). We have also added an explicit reservation that, should the foundation cease to operate or be reorganised, the list may be transferred to the person or entity that carries the VoctEnsemble on — of which we will tell you beforehand, with the chance to leave before any transfer (§ 3). Consents given before this change remain consents given under the previous wording of the clause. We have also added to § 7 two retention periods we had not stated before: an interrupted or unsuccessful attempt to give is deleted after 12 months (the five-year accounting obligation applies only to payments that went through), and a patronage submission after 12 months from the closing of the matter, or after 24 months with no contact. Neither period lengthens how long anything is kept; both shorten it.
- 1.4 · 11 September 2026 — We changed our mail delivery provider. The concert notices are now handled by Vercom S.A. (the EmailLabs service), established in Poznań, Poland, in place of Resend, Inc. of the United States — § 5 changes accordingly in its disclosure of the processor. The transfer to the United States on the basis of Standard Contractual Clauses, described in § 6 of the previous version, has thereby ceased: the sending takes place entirely within the European Economic Area.
- 1.3 · 5 September 2026 — We launched the concert notice list: § 3 gains the scope of the data (an e-mail address and a language, a two-step sign-up, the record of consent kept without an IP address), § 4 the purpose and its basis (consent, together with art. 10 of the Polish Act on providing services by electronic means), and § 7 the retention periods (7 days for a sign-up left unconfirmed, 3 years for the record of a consent withdrawn). § 5 now discloses Resend, Inc. as the processor handling the sending, and § 6 the transfer to the United States on the basis of Standard Contractual Clauses.
Earlier versions: 3
- 1.2 · 4 September 2026 — Added § 12: the policy is also published in English and French translation, the Polish version remaining the binding one. Clarified § 4: the payment is handled by the operator — the earlier wording spoke of the Foundation acting as an intermediary in transmitting payment data, which contradicted § 11.
- 1.1 · 3 June 2026 — Clarified how an online payment proceeds: payment follows a redirect onto the operator's hosted page, and full payment details do not pass through the Foundation's servers. Added an account of recurring transfers (standing orders) as a form of regular support. Added the handling of the patronage form (submissions recorded: first name, surname, e-mail — on the basis of consent; data held on servers in the European Union).
- 1.0 · 13 May 2026 — The original version of the policy, published together with the launch of the voctensemble.com site.
You may always obtain the full history of changes by writing to rodo@voctensemble.com.