Privacy Policy

Version dated 16 July 2026

1. Personal data controller

The controller of personal data processed in connection with the use of the Website is the Chancellery of the Senate, with its registered office at 6/8 Wiejska Street, 00-902 Warsaw. The Website is operated with the involvement of the Education, Promotion and Publications Office of the Chancellery of the Senate.

The Chancellery of the Senate has appointed a Data Protection Officer. For matters concerning the processing of personal data and the exercise of rights under data protection law, the Data Protection Officer may be contacted:

  • by e-mail at [email protected],
  • by post at: Data Protection Officer, Chancellery of the Senate, 6/8 Wiejska Street, 00-902 Warsaw, Poland.

Current contact details for the Data Protection Officer are available on the official website of the Chancellery of the Senate.

2. Scope of this Policy

This Policy describes the rules governing the processing of personal data in connection with:

  • using the Website and its search function,
  • sending messages through the contact form,
  • booking a visit to the Senate or educational activities,
  • checking, updating and cancelling bookings,
  • communications concerning bookings,
  • ensuring the security and proper operation of the Website,
  • using the map and following links to external services.

Detailed information about cookies, similar technologies and consent management is available on the separate Cookie Policy page.

3. Personal data we process

3.1. Using the Website

When the Website is used, technical data may be processed automatically, including:

  • the device IP address,
  • the date and time of the connection,
  • the address of the requested page and the referring page,
  • the type of browser, device and operating system,
  • information about errors, technical events and attempted security breaches,
  • the content of queries entered into the Website search function.

This data may be recorded in server logs and used by security mechanisms protecting the Website against misuse.

3.2. Contact form

The contact form processes the sender’s first and last name, e-mail address, message subject and content, as well as any other information voluntarily provided in the message.

Please do not provide data that is not necessary for handling your enquiry, particularly special categories of personal data, such as information concerning health, beliefs, opinions or personal circumstances, unless this is necessary.

3.3. Bookings for visits and educational activities

Depending on the type of booking, the following data may be processed:

  • the first and last name of the person making the booking,
  • an e-mail address and telephone number,
  • the first and last name, e-mail address and telephone number of the group supervisor, if this is a different person,
  • the name of the school, university, institution or organiser,
  • the type of group, age range or field of study,
  • the number of participants and supervisors,
  • the selected or preferred date,
  • the subject of the activity or additional lecture,
  • organisational information and any special requirements of the group provided in the additional comments field,
  • the booking number, status and handling history,
  • the content of messages sent in connection with the booking,
  • information confirming that the visitor rules, booking terms and personal data processing information have been read.

The booking system does not require the first and last names of individual participants or minors. Such data should not be entered in the additional comments field unless expressly required and necessary.

3.4. Personal data of other individuals

If the person making a booking provides the personal data of a supervisor or another contact person, they should have a lawful basis for providing that data and should inform the person that their data will be processed in accordance with this Policy.

4. Purposes and legal bases for processing

Personal data may be processed for the following purposes:

  1. Ensuring the operation, availability and security of the Website, handling errors and preventing misuse — on the basis of Article 6(1)(c) or (e) of the GDPR, in connection with the controller’s obligations and the performance of tasks carried out in the public interest.
  2. Handling messages and enquiries — on the basis of Article 6(1)(e) of the GDPR where the matter relates to the performance of tasks carried out in the public interest, or Article 6(1)(c) or (b) of the GDPR where a response is necessary to comply with a legal obligation, enter into an arrangement or provide an agreed service.
  3. Receiving and handling bookings, confirming dates, organisational communication, reminders, and enabling users to check, update or cancel bookings — on the basis of Article 6(1)(e) of the GDPR and, where applicable, Article 6(1)(b) or (c) of the GDPR.
  4. Maintaining records, handling complaints, complying with archival obligations and demonstrating the proper performance of activities — on the basis of Article 6(1)(c) or (e) of the GDPR.
  5. Processing based on consent — Article 6(1)(a) of the GDPR — only where the user is expressly asked to provide voluntary consent for a specific additional purpose.

The specific legal basis for processing may depend on the subject of the message or the nature of the matter.

5. Voluntary provision of personal data

Providing personal data through the contact form is voluntary. However, if the data necessary to contact you is not provided, it may not be possible to respond.

Providing data marked as required in the booking form is necessary to accept and process a booking. Data marked as optional may be omitted unless it is necessary due to the group’s specific organisational requirements.

6. Recipients of personal data

Personal data may be accessed by:

  • authorised employees and associates of the Chancellery of the Senate,
  • entities providing hosting, technical maintenance, security and backup services for the Website,
  • providers of e-mail and message delivery services,
  • entities providing IT and technical support services,
  • entities providing archiving or document management services,
  • public authorities and other entities authorised to receive personal data under applicable law.

Entities processing personal data on behalf of the controller may process it only to the extent necessary to provide the services entrusted to them and in accordance with the relevant agreements.

7. Map and external services

The contact page uses a map based on OpenStreetMap. When the map is displayed, the browser may connect to the servers of the map tile provider and to an external content delivery network used for the map library files.

As a result of such a connection, the providers may receive technical data, in particular the IP address, browser type, date and time of the connection, and the address of the page visited. Information about data processing by the OpenStreetMap Foundation is available in the OSMF Privacy Policy.

The Website also contains links to external services, including Facebook, Instagram, YouTube, X and Flickr. When a link is followed, the user leaves the Website, and any subsequent processing of personal data is governed by the rules of the relevant service provider.

8. Transfers of personal data outside the European Economic Area

Some external service providers may use infrastructure located outside the European Economic Area.

Where the use of these services involves a transfer of personal data outside the EEA, the transfer should take place in accordance with Chapter V of the GDPR, in particular on the basis of an adequacy decision, standard contractual clauses or another mechanism provided for by law.

9. Retention of personal data

Personal data is retained no longer than necessary for the purpose for which it was collected:

  • contact correspondence — for the time required to review and conclude the matter, and subsequently for the period required under office, archival or accountability rules,
  • booking data — for the period required to handle the submission, organise the visit or activity, and comply with documentation and archiving requirements,
  • messages associated with a booking — for the retention period applicable to the documentation of that booking,
  • temporary draft booking data — until it expires and the technical deletion cycle has been completed,
  • technical data and security logs — for the period resulting from the security configuration, diagnostic needs and the hosting provider’s retention rules,
  • documentation demonstrating compliance with legal obligations — for the period during which the controller should be able to demonstrate that the processing was lawful.

After the applicable period has expired, personal data is deleted, anonymised or transferred to an archive where required by law.

10. Rights of data subjects

Within the limits laid down by the GDPR, data subjects may have the right to:

  • obtain information about the processing of their personal data,
  • access their personal data and receive a copy,
  • have their personal data rectified or completed,
  • have processing restricted,
  • have their personal data erased where there is no obligation or other legal basis for its continued retention,
  • object to processing based on Article 6(1)(e) of the GDPR,
  • data portability where processing is automated and based on consent or a contract,
  • withdraw consent at any time where processing is based on consent; withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn,
  • lodge a complaint with the President of the Personal Data Protection Office.

Current information about exercising data subject rights is available on the website of the Personal Data Protection Office. Requests concerning personal data may be addressed to the Data Protection Officer of the Chancellery of the Senate.

11. Automated decision-making

The Website may automatically check form correctness, date availability, participant limits and attempted misuse of forms. These mechanisms support the technical handling of submissions and the security of the Website.

Personal data is not used for profiling or for decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them. The substantive handling of bookings involves authorised employees.

12. Personal data security

The controller applies organisational and technical measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction. Access to personal data is restricted to persons and entities that require it to perform the tasks entrusted to them.

13. Cookies

The Website uses cookies and similar technologies to ensure its proper operation, remember user choices and manage consent.

Information about the types of cookies, their providers, purposes and lifetimes, as well as how to change or withdraw consent, is published on the separate Cookie Policy page.

14. Changes to this Policy

This Policy may be updated following changes to the Website, the ways in which personal data is processed, the services used or applicable law. The date of the current version is stated at the beginning of the page.