Privacy Policy
Version: 2026-05 · Last updated: 2026-05-31
This is an English translation provided for convenience. The Polish version of this document is the legally binding one.
-
The data controller is Fundacja Organic Flow, with its registered office in Warsaw, at ul. Sienna 86/17, NIP: 5273194187 (hereinafter referred to as: the “Company”).
-
Provision of any personal data is voluntary, however it is necessary to achieve the purpose or take actions related to their provision.
-
The Controller processes the following Customer data:
- surname and given names,
- e-mail address,
- telephone number,
- residential address and postal code,
- age,
- activity in relation to individual projects,
- activity in relation to the use of individual services,
- necessary health data related to the provision of the service,
- personal data or information which we are obliged to collect under applicable legal acts, recommendations, or guidelines,
- the amount and date of payment, data provided by your bank or payment operator, and the method by which payment was made.
Where the participant in a service is a child, the data of both the child and the child’s parents is processed. The Controller also processes the e-mail address, telephone number, and first name of the newsletter recipient. For employees, the scope of processed data results from personnel-related legislation.
-
Pursuant to Article 6 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) — GDPR, the basis for the Controller’s processing of personal data is the consent of Users, a legal obligation, and the performance of a contract.
-
Purposes of data processing:
- sale of Services and products that are the subject of the offer (Art. 6(1)(b) GDPR),
- proper performance of contracts concluded with Fundacja Organic Flow (Art. 6(1)(b) GDPR),
- delivery of informational and promotional mailings to which the user has consented (Art. 6(1)(a) GDPR),
- organization of trips, workshops, conferences, meetings, sporting and educational events (Art. 6(1)(b) GDPR),
- organization of sports classes (Art. 6(1)(b) GDPR),
- activity related to sport and a healthy lifestyle,
- ongoing informational, educational, and promotional communication with recipients,
- ensuring the health and safety of clients and employees, in particular by collecting data on, among other things, training frequency, weight, exercises performed, and other aspects of training and the training process, analyzing this data, and creating reports in order to provide services of the highest quality,
- analysis, improvement of the services provided, automation of business processes, and the creation of statistics and reports using tools based on artificial intelligence (Art. 6(1)(a) GDPR).
-
All members of the Company’s team have access to personal data. Access for individual categories of persons is separated by restricting technical permissions to access the shared drive or folder. On a similar basis, documents are also physically secured in cabinets locked with a key. A list of external entities that have access to personal data can be found here.
The privacy policy of each of these entities is available on their respective websites listed in the link above.
The above-mentioned entities guarantee compliance with the Regulation, or compliance with standards analogous to the Regulation, with respect to the protection of personal data, and the Controller’s use of their technologies in the processing of personal data is lawful. Data processing agreements have been concluded with these entities, usually in the form of updates to their terms and conditions.
The Controller will not sell or transfer Customers’ personal data to entities other than those indicated in the link.
The User acknowledges that his or her personal data may be transferred to authorized state authorities in connection with proceedings conducted by them, at their request and upon fulfillment of the conditions confirming the necessity of obtaining this data from us.
-
The User has the following rights:
- Right to withdraw consent – however, withdrawal of consent may make it impossible to continue using services which, in accordance with the law, the Controller may provide only with consent. Moreover, withdrawal of consent does not render the processing of personal data unlawful prior to its withdrawal.
- Right to object to the use of data – if the Controller processes data on the basis of a legitimate interest, the User may object to its use. If the objection proves justified and the Controller has no other legal basis for processing the data, the Controller will delete the data that is the subject of the objection.
- Right to erasure of data (“right to be forgotten”) – at the User’s request, the Controller will delete data in the event of withdrawal of consent, a justified objection to the use of data for marketing or statistical purposes, unlawful processing, or where the data is no longer necessary for the purposes for which it was collected or processed. The Controller reserves the right to retain certain personal data to the extent necessary for backup purposes or for the purpose of establishing, pursuing, or defending claims and relations with state authorities.
- Right to restriction of processing – in the event of contesting the accuracy of the data and the lawfulness or necessity of its processing, and in the event of an objection being raised.
- Right of access to data – the Controller undertakes to confirm whether personal data processing is taking place. In such a case, the User has the option of obtaining a copy of the data and access to it, as well as obtaining the information contained in this Policy and other requested information.
- Right to rectification of data – at the request of the User or Customer, the Controller undertakes to rectify data (for inaccurate data) and to complete it (for incomplete data).
- Right to data portability – at the request of the User or Customer, the Controller will send the personal data, in the form of a PDF file or another agreed format, to the person requesting it or directly to another Controller indicated by that person.
- In addition, the User has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
The Controller ensures the exercise of these rights by means of an e-mail sent to: kontakt@organicflow.pl, clearly stating in the subject line which right the User wishes to exercise. The Controller will fulfil the request within 30 days of receiving the message.
-
Data retention
- The data retention period will not be shorter than that resulting from applicable legal provisions (special statutes), i.e. among others: the Accounting Act, the Tax Ordinance Act, the Act on Pensions and Disability Pensions from the Social Insurance Fund, or the Act on the Social Insurance System.
- Newsletter recipients’ data will be stored until a request for its deletion is made.
- Customers’ data will be stored until the expiry of the limitation period for claims arising from them.
The Company undertakes to destroy any temporarily created documents containing personal data (e.g. a list of participants of a specific event or class) and to take care of the circulation of data and its minimization in accordance with the procedures set out in the Register of Processing Activities.
The Controller applies technical and organizational measures ensuring protection of the processed personal data appropriate to the risks and categories of data covered by protection, and in particular protects the data against disclosure to unauthorized persons, seizure by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage, or destruction.
The Personal Data Controller hereby informs that it has not appointed a Data Protection Officer (DPO) and independently performs the duties related to the processing of personal data.
-
Analytical and marketing tools
With the User’s consent (Art. 6(1)(a) GDPR), the website uses analytical and marketing tools operating on the basis of cookies and similar technologies:
- Meta Pixel – provider Meta Platforms Ireland Ltd. (Ireland) – measuring the effectiveness of advertising and activities on Facebook and Instagram,
- Google Analytics, Google Tag Manager, and Google Ads – provider Google Ireland Ltd. (Ireland) – website traffic statistics and conversion measurement.
These tools are activated only after the User gives consent via the cookie consent banner. Until consent is given, they remain disabled by default (Google Consent Mode mechanism). Consent may be given, refused, or changed at any time via the “Cookie Settings” link in the website footer; withdrawal of consent results in the deactivation of these tools and the deletion of the associated cookies.
Use of the above-mentioned tools may involve the transfer of data (including identifiers stored in cookies and the IP address) to their providers, including entities within the Meta and Google groups, which may process data also outside the European Economic Area (including in the USA) — on the basis of standard contractual clauses approved by the European Commission or other mechanisms provided for in Chapter V of the GDPR.
A detailed list of the cookies used and their retention period can be found in the Cookie Policy.