wellcultureinstitute.com
Privacy policy
This Privacy Policy defines the principles of processing personal data obtained via the website wellcultureinstitute.com, hereinafter referred to as the “Website.”
The owner of the Website and at the same time the Data Controller is WELLCULTURE INSTITUTE BY EWA STELMASIAK, 05-410 Józefów, ul. Jachowicza 3a, NIP: 5212990122, hereinafter referred to as the “Controller.”
Personal data collected by the Controller via the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as “GDPR.”
The Controller exercises particular diligence to respect the privacy of Clients visiting the Website.
§1 Types of data processed, purposes and legal basis
The Controller collects information about natural persons performing a legal action not directly related to their business, natural persons conducting business or professional activities in their own name, and natural persons representing legal entities or organizational units without legal personality, which are granted legal capacity by law, conducting business or professional activities in their own name, hereinafter collectively referred to as “Clients.”
The Controller processes Clients’ personal data within the scope of using the contact form service on the Website, to the extent necessary to perform a contract or take steps prior to entering into a contract – legal basis: Article 6(1)(b) GDPR.
In the case of using the contact form service, the Client provides the following data:
email address
first name
phone number
When using the Website, additional information may be collected, in particular: the IP address assigned to the Client’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type. Navigational data may also be collected from Clients, including information on links and references they choose to click or other actions taken on the Website, for purposes related to service provision, as well as technical, administrative, analytical, and statistical purposes. The legal basis for such processing is also Article 6(1)(f) GDPR, i.e. necessity for the purposes of the legitimate interests pursued by the Controller, such as ensuring IT security, managing the Website, and improving its functionality and the services provided.
§2 Data recipients
Clients’ personal data is transferred to service providers used by the Controller in operating the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either follow the Controller’s instructions regarding the purposes and methods of data processing (processors) or determine the purposes and methods of processing themselves (controllers).
1.1. Processors. The Controller uses service providers who process personal data solely on the Controller’s instructions. These include, among others, providers of hosting services, accounting services, marketing systems, traffic analysis systems, and marketing campaign effectiveness analysis systems.
1.2. Controllers. The Controller uses service providers who do not act solely on instructions and independently determine the purposes and methods of processing Clients’ personal data. They provide electronic payment and banking services.Location. Service providers are based mainly in Poland and in other countries of the European Economic Area (EEA).
Upon request, the Controller makes personal data available to authorized state authorities, in particular to organizational units of the Prosecutor’s Office, Police, President of the Personal Data Protection Office, President of the Office of Competition and Consumer Protection, or President of the Office of Electronic Communications.
§3 Data retention period
Clients’ personal data is stored as follows:
1.1. Where the basis for processing is consent, personal data is processed by the Controller until the consent is withdrawn, and after withdrawal, for a period corresponding to the limitation period of claims that may be raised by the Controller or against the Controller. Unless otherwise provided by specific regulations, the limitation period is six years, and for periodic benefits and business-related claims – three years.
1.2. Where the basis for processing is performance of a contract, personal data is processed by the Controller as long as necessary for contract performance, and thereafter for a period corresponding to the limitation period of claims. Unless otherwise provided by specific regulations, the limitation period is six years, and for periodic benefits and business-related claims – three years.
§4 Cookies mechanism, IP address
The Website uses small files called cookies. They are saved by the Controller on the end device of the person visiting the Website, provided the web browser allows it. A cookie file usually contains the domain name it originates from, its “expiry time,” and an individual randomly generated identifier. Information collected through such files helps tailor the Controller’s products to the individual preferences and actual needs of persons visiting the Website.
The Controller uses two types of cookies:
2.1. Session cookies: once the browser session ends or the computer is switched off, the stored information is deleted from the device memory. The session cookie mechanism does not allow collecting any personal data or confidential information from Clients’ computers.
2.2. Persistent cookies: stored in the Client’s device memory and remain there until deleted or expired. The persistent cookie mechanism does not allow collecting any personal data or confidential information from Clients’ computers.The Controller uses own cookies for:
3.1. analysis, research, and audience auditing, particularly to create anonymous statistics that help understand how Clients use the Website, enabling improvements in its structure and content.The Controller uses third-party cookies for:
4.1. displaying on the Website informational pages showing the location of the Controller’s office via maps.google.com (external cookie administrator: Google Inc., based in the USA).The cookies mechanism is safe for Clients’ computers visiting the Website. In particular, it is not possible for viruses, unwanted software, or malicious software to reach Clients’ computers this way. Nevertheless, Clients can limit or disable cookies in their browsers. If this option is used, using the Website remains possible, except for functions that by their nature require cookies.
The Controller may collect Clients’ IP addresses. An IP address is a number assigned to the visitor’s computer by the Internet service provider. In most cases, it is assigned dynamically (changes with every Internet connection) and therefore is generally treated as non-personal identifying information. The Controller uses IP addresses to diagnose technical server problems, create statistical analyses (e.g. identifying regions with the most visits), administer and improve the Website, as well as for security purposes and to identify undesirable automated browsing programs that overload the server.
§5 Rights of data subjects
Data subjects have the right to:
Withdraw consent at any time:
Clients may withdraw any consent previously given.
Withdrawal is effective from the moment of withdrawal.
Withdrawal does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.
Withdrawal entails no negative consequences for the Client but may prevent further use of services or features that the Controller can lawfully provide only with consent.
Object to processing:
Clients have the right at any time to object – for reasons related to their particular situation – to the processing of their personal data based on Article 6(1)(e) or (f) GDPR, including profiling on this basis. The Controller may no longer process such personal data unless it demonstrates compelling legitimate grounds for processing overriding the interests, rights, and freedoms of the Client, or for establishing, pursuing, or defending claims.
Opting out of receiving marketing communications by email regarding products or services will mean an objection to processing of personal data, including profiling, for these purposes.
Erasure of data (“right to be forgotten”):
Clients may request the erasure of all or some personal data if:
the data is no longer necessary for the purposes collected;
consent has been withdrawn where processing was based on consent;
an objection has been lodged and there are no overriding legitimate grounds for processing;
the data is processed unlawfully;
erasure is required to comply with a legal obligation under EU or Member State law;
the data was collected in connection with the provision of information society services.
Despite a request for erasure, the Controller may retain certain personal data where processing is necessary for establishing, pursuing, or defending claims, or for compliance with a legal obligation under EU or Member State law. This particularly applies to data including first name, last name, email address (for handling complaints and claims related to the Controller’s services), or additionally home/mailing address, order number (for handling complaints and claims related to sales contracts or service provision).
Restriction of processing:
Clients may request restriction of processing their personal data. Pending such a request, use of functionalities requiring the data will be suspended. The Controller will not send any communications, including marketing communications.
Restriction may be requested where:
the accuracy of personal data is contested (restriction applies during verification, no longer than 7 days);
processing is unlawful but the Client requests restriction instead of erasure;
the data is no longer needed but is required for claims;
an objection is lodged pending verification whether the Controller’s legitimate grounds override those of the Client.
Access to data and copies:
Clients have the right to obtain confirmation from the Controller whether their personal data is being processed. If so, they have the right to:
access their personal data;
receive information on purposes, categories of data, recipients or categories of recipients, planned storage periods or criteria for determining them, rights under GDPR, the right to lodge a complaint with a supervisory authority, source of data if not collected directly, automated decision-making (including profiling), its principles, significance, and consequences, as well as safeguards related to transfers outside the EU;
receive a copy of their personal data (without adversely affecting the rights and freedoms of others).
Rectification of data:
Clients have the right to request immediate rectification of inaccurate personal data. Considering the purposes of processing, Clients may request completion of incomplete data, including by providing an additional statement, by email as per §6 of this Privacy Policy.
Data portability:
Clients may receive their personal data provided to the Controller and transfer it to another data controller, or request direct transfer if technically feasible. In this case, the Controller provides the data in CSV format (machine-readable, commonly used).
Lodge a complaint:
Clients have the right to lodge a complaint with the President of the Personal Data Protection Office regarding any violation of their personal data protection rights under GDPR.
The Controller fulfills or denies requests without undue delay, no later than one month after receipt. Due to complexity or number of requests, this period may be extended by another two months, with prior notice within one month.
Clients may submit complaints, inquiries, and requests regarding personal data processing and their rights to the Controller.
§6 Changes to the Privacy Policy
The Privacy Policy may change, and the Controller is not obliged to notify about such changes.
Questions regarding this Privacy Policy should be sent to:ewastelmasiak@wellcultureinstitute.com
Date of last modification: 24 September 2025