VoctEnsemble ← back

Document · GDPR

Privacy policy

Version 1.5 · in force since 15 September 2026

The voctensemble.com website is an informational website and a channel for receiving donations towards the Foundation's statutory purposes. We use no marketing cookies and no analytics tools, we do not profile our visitors, and we take no automated decisions about them. Below we set out precisely what data may be processed while you use the site — including while you make a donation — and who is responsible for it.

Data controller

The controller of the personal data processed in connection with your use of the voctensemble.com website is:

Fundacja VoctFoundation
ul. Św. Filipa 23/3, 31-150 Kraków
KRS 0001237252 · NIP 6762718992 · REGON 544621525

The Foundation pursues statutory purposes in the field of culture and sacred art. This site is its informational website and a channel for receiving donations.

Contact about your data

For anything to do with the processing of personal data, please write to:

rodo@voctensemble.com
or by post, to the Foundation's registered office

We have not appointed a Data Protection Officer — the scope and nature of our processing do not require one (art. 37 GDPR).

What data we process

Visitors to the site

Simply opening the site causes technical data to be processed automatically by the hosting servers and the content delivery networks (CDN):

These are standard HTTP server logs. We do not combine them with any other data and we do not use them for profiling or marketing. They serve only to keep the site running and secure (blocking abusive traffic, for instance).

Donors

When a donation is made, we process the data needed to carry out the transaction, to issue any donation certificate, and to meet the Foundation's accounting obligations. What is processed, and how, depends on the method chosen:

The Axepta BNP Paribas payment gateway (BLIK, instant transfers, Apple Pay, Google Pay, cards)

We use the Axepta BNP Paribas payment gateway, operated by BNP Paribas Bank Polska S.A. For card transactions the acquirer is PayU S.A. Payment follows a redirect model, onto the operator's own secure page:

Full payment details (card number, BLIK code, online banking credentials) are entered on the operator's page and nowhere else — they do not pass through the Foundation's servers and we do not store them. It is the operator that tokenises them and that carries the burden of authorisation and the security obligations of the PCI DSS standard. On the Foundation's side we keep only the donor's e-mail address, the amount, the currency, the date, the transaction identifier and its status — no more than is needed for our accounting records and to issue a confirmation of the donation.

Zrzutka.pl

What data is processed is determined by Zrzutka.pl's own policy; within that service the controller of contributors' data is Zrzutka Sp. z o.o.

Bank transfer (one-off or standing order)

The data comes from the transfer instruction itself (sender, reference, amount) and reaches us only through the bank that holds our account. The same applies to recurring transfers (standing orders): setting one up, changing it and cancelling it all happen entirely within the donor's own banking — we store neither your card details nor a debit mandate for the purpose, and the instruction remains under your sole control.

Joining the patrons (the regular-support form)

If you decide to join the patrons of the cycle and fill in the form in the “Patronage” section, we process the first name, surname and e-mail address you give us. We record them for one purpose only: to be in touch with you about regular support. The form collects no payment details whatsoever — the support itself is made by transfer (a standing order) that you set up and control in your own banking. Your data is held on our servers in the European Union; the internal notice of a new submission that we send ourselves contains none of your personal data.

The concert invitation list

If you ask us for invitations to the concerts, we process your e-mail address, the language of the page you signed up on, and — if you give one — your first name. The name is optional and serves one purpose only: so that the letter can greet you by name. Without it the invitation is exactly the same. Signing up takes two steps: once the form is sent we send a single message asking you to confirm, and only following the link in it puts the address on the list; until then we send nothing further. Alongside the address we record the date and time of the confirmation and the version of the consent clause shown beside the form — that is the proof the consent was given, and nothing beyond it; we do not record your IP address. Every message we send carries a link that takes you off the list in one click.

The list exists in order to invite you to the concerts of the VoctEnsemble. Should the foundation cease to operate or be reorganised, the list may be transferred to the person or entity that carries the ensemble on. We will tell you before that happens — in a separate message, and with the chance to leave the list before any transfer. Without that notice and without that chance, no transfer will take place.

E-mail correspondence

If you write to one of our addresses, we process the data contained in that correspondence — the sender's e-mail address, the signature, the content of the message — solely in order to reply.

Audio preference (localStorage)

When you choose “Enter with voice” or “Enter in silence”, we save your choice in your browser's local storage (localStorage) under the key voct.demo.audio. The entry expires after 3 hours and holds nothing but the preference and a timestamp. It is not personal data and it never leaves your browser.

Purposes and legal bases

We process your data for the following purposes and on the following legal bases under the GDPR:

Recipients of the data

Depending on what you are doing, your data may reach the following parties (either as processors or as separate controllers):

IT infrastructure providersEmailLabsBNP ParibasPayUZrzutka.plAccountancy office

Transfers outside the EEA

The Foundation limits transfers of data outside the European Economic Area wherever it can. Our main server infrastructure is located within the European Union.

Where the technical operation of the site does involve a transfer outside the EEA (through content delivery networks, for instance), it takes place solely on the basis of Standard Contractual Clauses (SCCs) or another safeguard provided for by the GDPR.

The payment gateway's operator (BNP Paribas Bank Polska S.A.) and the card acquirer (PayU S.A.) are both established in Poland. They may nonetheless — within their own anti-fraud systems — process data outside the EEA as well, for which they answer on the terms set out in their own privacy policies.

The concert invitations are delivered by Vercom S.A. (the EmailLabs service), established in Poznań, Poland, and the servers handling the sending are in Poznań and Berlin. Neither the content of the invitations nor the recipients' addresses are therefore transferred outside the EEA.

How long we keep it

Your rights

Under the GDPR you have the following rights:

To exercise any of these rights, write to rodo@voctensemble.com. We answer without undue delay, and within one month of receiving the request at the latest.

Visit statistics

To improve the site and to understand what content interests you, we use Plausible Analytics. It is a privacy-first tool:

Full details of how the tool protects privacy can be found in Plausible's official Data Policy.

Cookies, localStorage and third-party scripts

Our own cookies

We use no cookies of our own — neither analytical nor marketing. The site carries no Google Analytics, no Meta Pixel and no comparable profiling tool.

The browser's localStorage and sessionStorage

We use the browser's localStorage and sessionStorage solely to remember a few technical interface preferences. None of the entries below identifies a user, none contains personal data, and none serves any tracking purpose. They are “strictly necessary” to functions of the site that you have chosen — which, under recital 30 of Directive 2002/58/EC and the case law, means they require no prior consent.

The payment gateway's technical scripts and cookies

When you press “Support us” you are redirected to the operator's hosted payment page. It is on that page — already outside voctensemble.com — that the technical JavaScript libraries supplied by BNP Paribas / PayU load, and they may set cookies or use other browser storage mechanisms in order to:

These mechanisms are strictly necessary to carrying out a payment safely and require no separate consent. The controller of the data processed by those scripts is BNP Paribas Bank Polska S.A. and — for card payments — PayU S.A., on the terms set out in their privacy policies (the links are in “Recipients of the data”). They never appear on our site: they run only on the operator's page, after the redirect, once you begin the payment.

Security

Changes to this policy

We update the policy whenever the way we process data changes — when we add a payment method, add a form, or change our technical infrastructure. Every change carries a new version number and a date from which it applies (at the head of this document).

This policy is published in Polish, and also in English and French translation. The Polish version is the binding one; the translations are for information only, and in the event of any discrepancy between the language versions the Polish wording prevails.

Version history
  • 1.5 · 15 September 2026 — The changes concern the mailing list. We have named it the concert invitation list rather than the notice list — the name changes, not the scope. You may now give a first name when signing up; it is optional and serves only so that the letter can greet you by name (§ 3 and § 7). We have also added an explicit reservation that, should the foundation cease to operate or be reorganised, the list may be transferred to the person or entity that carries the VoctEnsemble on — of which we will tell you beforehand, with the chance to leave before any transfer (§ 3). Consents given before this change remain consents given under the previous wording of the clause. We have also added to § 7 two retention periods we had not stated before: an interrupted or unsuccessful attempt to give is deleted after 12 months (the five-year accounting obligation applies only to payments that went through), and a patronage submission after 12 months from the closing of the matter, or after 24 months with no contact. Neither period lengthens how long anything is kept; both shorten it.
  • 1.4 · 11 September 2026 — We changed our mail delivery provider. The concert notices are now handled by Vercom S.A. (the EmailLabs service), established in Poznań, Poland, in place of Resend, Inc. of the United States — § 5 changes accordingly in its disclosure of the processor. The transfer to the United States on the basis of Standard Contractual Clauses, described in § 6 of the previous version, has thereby ceased: the sending takes place entirely within the European Economic Area.
  • 1.3 · 5 September 2026 — We launched the concert notice list: § 3 gains the scope of the data (an e-mail address and a language, a two-step sign-up, the record of consent kept without an IP address), § 4 the purpose and its basis (consent, together with art. 10 of the Polish Act on providing services by electronic means), and § 7 the retention periods (7 days for a sign-up left unconfirmed, 3 years for the record of a consent withdrawn). § 5 now discloses Resend, Inc. as the processor handling the sending, and § 6 the transfer to the United States on the basis of Standard Contractual Clauses.
Earlier versions: 3
  • 1.2 · 4 September 2026 — Added § 12: the policy is also published in English and French translation, the Polish version remaining the binding one. Clarified § 4: the payment is handled by the operator — the earlier wording spoke of the Foundation acting as an intermediary in transmitting payment data, which contradicted § 11.
  • 1.1 · 3 June 2026 — Clarified how an online payment proceeds: payment follows a redirect onto the operator's hosted page, and full payment details do not pass through the Foundation's servers. Added an account of recurring transfers (standing orders) as a form of regular support. Added the handling of the patronage form (submissions recorded: first name, surname, e-mail — on the basis of consent; data held on servers in the European Union).
  • 1.0 · 13 May 2026 — The original version of the policy, published together with the launch of the voctensemble.com site.

You may always obtain the full history of changes by writing to rodo@voctensemble.com.