Last updated: 14 September 2026

1. Who we are

This website, creativityworkseurope.pl, is run by Fundacja Creativity Works Europe, a not-for-profit foundation registered in Poland.

  • Registered office: ul. Zdrojowa 24 lok. 30, 25-336 Kielce, Poland
  • National Court Register (KRS): 0000953582, kept by the District Court in Kielce, 10th Commercial Division of the National Court Register
  • Tax identification number (NIP): 6572967611
  • Statistical number (REGON): 521254272
  • Email: creativityworkseurope@gmail.com

We are the controller of personal data processed through this website, within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

2. What this policy covers

This policy explains what happens to personal data when you visit this website. It does not cover personal data we process in our projects, programmes and partnerships — participants in those activities receive separate information at the point where their data is collected.

3. What we collect

Messages you send us

If you write to us, we receive your email address, any name you give, and whatever you choose to put in the message. We use it to answer you and to keep a record of the correspondence. There is no contact form on this website — the address above opens your own email programme.

Server logs

Like virtually every website, our server automatically records each request it receives: the IP address it came from, the date and time, the address of the page requested, the browser and operating system reported by your device, and — where your browser sends it — the page you arrived from. These records exist so that the website can function, so that faults can be diagnosed and so that abuse and attacks can be detected. They are not used to build profiles of visitors and are not combined with any other information about you.

Comments

Articles on this website can accept comments. If you leave one, we receive the comment itself, the name and email address you enter in the form, and your IP address. Comments and the data attached to them are kept for as long as the article is published, unless you ask us to remove them.

4. Cookies

There is very little to report here, and we would rather say it plainly than pad it out.

Until you answer the cookie banner, this website places no cookies on your device at all.

When you accept or decline, a single cookie is saved so that we do not ask you again:

NameWhat it doesHow long it lasts
blocksy_cookies_consent_acceptedRecords whether you accepted or declined the cookie banner, so it is not shown againSet with a very long expiry date; it stays until you clear it in your browser

That is the only cookie this website sets for visitors. No further scripts are loaded when you accept — there are none waiting behind the banner.

If you sign in as an administrator of the site, WordPress additionally sets session cookies that are necessary to keep you logged in. This concerns the people who manage the website, not visitors.

You can delete cookies, and block them in advance, in your browser settings. Blocking this one cookie simply means the banner will appear again on your next visit.

5. What this website does not do

We think it is as useful to state what is absent as what is present. This website does not use:

  • analytics of any kind — there is no Google Analytics, no Tag Manager and no equivalent tool
  • advertising or remarketing pixels, including those of Meta, Google and LinkedIn
  • social media buttons or widgets that report your visit back to a social network
  • fonts, maps or video players loaded from outside servers — everything the pages need is served from this website’s own domain
  • profiling or automated decision-making that produces legal effects for you

We do not sell personal data, and we do not share it for anyone else’s marketing.

6. Why we are allowed to process this data

  • Correspondence — our legitimate interest in answering people who contact us, and in keeping a record of what was agreed (Article 6(1)(f) GDPR). Where the exchange leads towards an agreement with you, Article 6(1)(b) GDPR also applies.
  • Server logs — our legitimate interest in operating the website securely and reliably (Article 6(1)(f) GDPR).
  • Comments — your consent, given by submitting the comment (Article 6(1)(a) GDPR), together with our legitimate interest in preventing spam and abuse (Article 6(1)(f) GDPR).
  • The cookie banner cookie — it is necessary to provide the function you asked for, namely not being shown the banner again (Article 6(1)(f) GDPR and Article 173(3) of the Polish Telecommunications Law).

7. How long we keep it

  • Emails — for as long as the matter is live, and afterwards for as long as we may need the record, in particular until any relevant limitation period or grant reporting obligation has passed.
  • Server logs — they are rotated and overwritten on an ongoing basis by our hosting arrangement; they are not archived for the long term.
  • Comments — for as long as the article they belong to is published, or until you ask for removal.

8. Who else has access

We keep the circle deliberately small. Personal data from this website may be accessible to:

  • our hosting provider — the company that operates the server on which this website and its logs are stored, acting as our processor under a written agreement;
  • the provider of our email service, to the extent that correspondence with us passes through it;
  • the spam-filtering service used for comments, which checks submitted comments, including the IP address attached to them, against known spam patterns;
  • public authorities, where we are legally obliged to disclose information.

9. Transfers outside the European Economic Area

The website itself is hosted within the European Union. Two of the services named above — our email provider and the comment spam filter — are operated by companies based in the United States, so data handled by those services may be transferred outside the EEA. Such transfers take place on the basis of the European Commission’s adequacy decision for the EU–US Data Privacy Framework or, where that does not apply, on the basis of the Commission’s standard contractual clauses.

10. Children

This website is aimed at adults — partners, funders and people interested in our work. We do not knowingly collect personal data from children through it. Young people take part in our projects, but their data is collected in those projects directly and with the appropriate consents, not through this website. If you believe a child has sent us personal data through the website, please tell us and we will delete it.

11. Your rights

Under the GDPR you have the right to ask us for access to your personal data and for a copy of it, to have inaccurate data corrected, to have data erased, to have processing restricted, and to receive data you provided in a portable form. Where we rely on our legitimate interest, you have the right to object to the processing. Where we rely on your consent, you may withdraw it at any time, which does not affect the lawfulness of what was done before.

To exercise any of these rights, write to creativityworkseurope@gmail.com. We answer without undue delay and in any case within one month.

You also have the right to lodge a complaint with the supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

12. Changes to this policy

If we change how this website handles personal data, we will update this page and change the date at the top. Material changes will be signalled on the website itself.

13. Contact

Questions about this policy, or about how we handle your data, go to creativityworkseurope@gmail.com, or by post to Fundacja Creativity Works Europe, ul. Zdrojowa 24 lok. 30, 25-336 Kielce, Poland.