Archiwaliapl

Legal and privacy

Privacy Policy and information on personal data processing for Archiwalia.com (GDPR)

Information on personal data processing in the Archiwalia.com service.

Version 2026-10-01 · effective from 1 October 2026

§ 1. Personal data controller

1. The controller of personal data of Users of the online service archiwalia.com, hereinafter referred to as the “Service” or “Archiwalia”, is the business Olgierd Witkowski, with its registered office in Józefosław at ul. Sekwojowa 4, Tax Identification Number (NIP): 5211325026, hereinafter referred to as the “Controller”. 2. For matters concerning personal data protection, the Controller can be contacted at: kontakt@archiwalia.com 3. The Controller has not appointed a data protection officer unless such appointment is required by applicable law. 4. This Policy describes how personal data connected with use of the Service is processed, including: a. data of Users who have Accounts; b. technical data connected with use of the Service; c. data provided to the Controller in connection with contact, complaints, and reports; d. data that may appear in Materials and Memorabilia stored by Users in the Service.

§ 2. Basic principles of data processing

1. The Controller processes personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the “GDPR”. 2. Data is processed only to the extent necessary for specified purposes and for no longer than required by those purposes, the Controller's legal obligations, or the establishment, exercise, or defence of legal claims. 3. The Controller applies appropriate technical and organisational measures intended to protect data against: a. unauthorised access; b. unauthorised disclosure; c. alteration; d. accidental loss; e. destruction or damage.

§ 3. User data processed by Archiwalia

1. In connection with maintaining an Account, the Controller may process: a. first and last name; b. email address; c. Account authentication and security data; d. information about membership in Family Spaces; e. the User's roles and permissions in individual Family Spaces; f. information about Memorabilia and Materials created by the User; g. information connected with invitations to Family Spaces; h. information about acceptance of the Terms, including the accepted version, language, and acceptance date. 2. The Controller may also process technical data connected with use of the Service, including: a. IP address; b. date and time of connection to the Service; c. information about requests sent to the server; d. error information; e. User session data; f. other technical information necessary to provide and secure the Service. 3. If a person contacts the Controller, submits a complaint or content report, or sends other correspondence, the Controller may process: a. the contact person's identifying data; b. email address; c. the content of the correspondence; d. information necessary to investigate the matter; e. the history of the correspondence. 4. The Service does not require Users to provide personal data that is not necessary to supply the offered service. 5. The Controller receives the email address of a person invited to a Family Space from the User who sends the invitation. The invitation email identifies the source of the data and contains a link to this Policy.

§ 4. Purposes and legal bases of processing

1. Users' personal data is processed to create and maintain Accounts, enable use of Family Spaces, store Materials, and supply the other functions of the Service. The legal basis is Article 6(1)(b) GDPR – processing is necessary to perform the electronic services contract or to take steps at the data subject's request before entering into a contract. 2. Data may be processed to comply with legal obligations to which the Controller is subject. The legal basis is Article 6(1)(c) GDPR. This applies in particular to obligations arising from legislation concerning electronic services, personal data protection, handling reports, and other obligations imposed by law. 3. Data may be processed to secure the Service, prevent abuse, detect attempted unauthorised access, and maintain technical logs. The legal basis is Article 6(1)(f) GDPR – the Controller's legitimate interest in protecting the Service, its Users, and stored data. 4. Data may be processed for the establishment, exercise, or defence of legal claims. The legal basis is Article 6(1)(f) GDPR – the Controller's legitimate interest in protecting its rights. 5. Data in correspondence sent to the Controller may be processed to respond, handle a report, or resolve the reported issue. Depending on the nature of the matter, the legal basis may be: a. Article 6(1)(b) GDPR – if the correspondence concerns performance of the contract; b. Article 6(1)(c) GDPR – if handling the matter follows from a legal obligation; c. Article 6(1)(f) GDPR – in other cases, as the Controller's legitimate interest in communicating with people who contact the Service and documenting that communication. 6. The Controller does not use User data for direct marketing unless such a function is introduced in the future in accordance with applicable law and this Policy is updated accordingly.

§ 5. Data contained in family Memorabilia and Materials

1. The Service enables Users to store family Memorabilia and related Materials. 2. Materials may contain information about people other than the User who uploaded them, including: a. first and last names; b. family relationships; c. dates and places connected with family events; d. the image of people appearing in photographs or documents; e. the contents of letters, diaries, and other documents; f. other information arising from the historical or family nature of the Memorabilia. 3. The Controller does not determine which people, information, or data a User places in particular Material. 4. The Controller does not review Materials in advance to identify people appearing in them or classify their data. 5. The User decides: a. which Memorabilia to place in the Service; b. which Materials to attach to it; c. which information to enter in descriptions; d. which Family Space to assign the Memorabilia to. 6. If a User uses the Service in the course of a purely personal or household activity, the exclusion under Article 2(2)(c) GDPR may apply to that processing. 7. If, in a particular case, processing carried out by a User does not fall within a purely personal or household activity, the User is responsible for ensuring an appropriate legal basis for processing the data placed in the Service. 8. The mere appearance of a person in a historical document, photograph, or other Material does not mean that the Controller uses information about that person for its own marketing, profiling, or analysis. 9. Materials are not made publicly available by the Service. They are accessible only to Users with the relevant permissions. 10. If the Controller receives a request or report from a person whose data appears in Material, it will assess the matter taking into account the nature of the Material, the legal bases for processing, the User's rights, the reporting person's rights, and applicable law.

§ 6. Special categories of data and historical information

1. Because of the nature of family archives, Materials uploaded by Users may in some cases contain information regarded by the GDPR as special categories of personal data or other private information. 2. The Controller does not require such data to be uploaded and does not automatically analyse Materials to detect it. 3. Users should exercise particular caution when uploading information about living people, especially information that is particularly private or protected. 4. Historical Materials may contain information about deceased people. As a rule, the GDPR applies to personal data of living natural persons, although other laws may protect personal rights, confidentiality, or other rights relating to such Materials.

§ 7. Access to data within a Family Space

1. Data and Materials placed in a Family Space may be accessible to other Users who have permission to access that Family Space. 2. The User acknowledges that inviting another person to a Family Space will give that person access to the data and Materials in that Family Space in accordance with the scope of their permissions. 3. Users with access to a Family Space may use the Service from different countries around the world. 4. The Controller does not make Materials publicly available or provide unauthorised persons with access to Family Spaces. 5. Other Users' access to Materials results from the operation of the Family Space and permissions granted in accordance with the rules of the Service.

§ 8. Data recipients

1. Personal data may be entrusted or disclosed to entities that supply services necessary for the operation of the Service to the Controller. 2. Categories of such entities may include: a. server infrastructure and hosting providers; b. email service providers; c. IT service providers, such as software developers; d. network infrastructure providers; e. technical and IT support providers; f. legal, accounting, or advisory service providers, if access to data is necessary to perform their services. 3. Entities that process data on behalf of the Controller may process it only within the scope of their contracts and in accordance with applicable law. 4. Data may be disclosed to competent public authorities if disclosure is required by law or a legally binding request from a competent authority.

§ 9. Transfers outside the European Economic Area

1. On the effective date of this Policy, the Controller uses core infrastructure supplied by service providers that process data within the European Economic Area. 2. The Controller does not currently intend to transfer User data to infrastructure providers located in third countries outside the European Economic Area. 3. This does not mean that a User must be located in the EEA. The Service is available to Users staying or residing in other countries. 4. If the Controller begins using services in the future that require data transfers to a third country, transfers will take place only in accordance with Chapter V GDPR, in particular on the basis of a European Commission adequacy decision or other appropriate safeguards required by the GDPR. 5. This Policy will be updated if material changes are made to the location of data processing.

§ 10. Data retention

1. Data necessary to maintain an Account is stored while the Account is active. 2. After an Account is deleted, data may be retained for the period necessary to: a. comply with the Controller's legal obligations; b. establish, exercise, or defend legal claims; c. investigate security events; d. complete technical processes for deleting data from backups. 3. Data contained in security logs is stored for a period justified by the need to secure the Service and investigate incidents. 4. Data connected with complaints, infringement reports, and other correspondence may be stored for the time needed to conclude the matter and then until the limitation period for potential claims expires. 5. Materials in an active Family Space may be stored for as long as necessary to supply the service to Users who have permission to access them. 6. Data in backups may remain there for a limited time after deletion from the active system. Backups are not used for ordinary access to data and are deleted or overwritten in accordance with the backup cycle.

§ 11. Data subject rights

1. Where provided for by the GDPR, the data subject has: a. the right of access to data; b. the right to obtain a copy of the data; c. the right to rectify inaccurate data; d. the right to request erasure; e. the right to restriction of processing; f. the right to data portability, where the conditions specified in the GDPR are met; g. the right to object to processing based on Article 6(1)(f) GDPR. 2. Individual rights are not absolute. Whether they can be exercised depends on the legal basis, purpose of processing, and other circumstances set out in the GDPR. 3. A request to exercise rights can be sent to: kontakt@archiwalia.com 4. The Controller may request information necessary to verify the identity of the person making a request if there are reasonable doubts about their identity. 5. Requests concerning data appearing only in Material uploaded by another User may require the specific Material to be identified and the roles of the Controller and User in the particular case to be assessed.

§ 12. Right to lodge a complaint

1. A person who believes that the processing of their personal data infringes the GDPR has the right to lodge a complaint with the competent supervisory authority. 2. The supervisory authority in Poland is: President of the Personal Data Protection Office Personal Data Protection Office ul. Stanisława Moniuszki 1A 00-014 Warsaw Poland 3. The right to lodge a complaint does not restrict the ability to contact the Controller first in order to clarify the matter.

§ 13. Required or voluntary provision of data

1. Providing the data necessary to create an Account is voluntary but required to enter into and perform the contract for the Service. 2. Failure to provide data required during registration may prevent an Account from being created or particular functions from being used. 3. Providing additional information relating to Memorabilia is generally voluntary. 4. The User decides which Materials to upload to the Service, subject to the technical requirements and rules specified in the Terms.

§ 14. Profiling and automated decision-making

1. The Controller does not use personal data to make decisions about Users based solely on automated processing that produce legal effects concerning them or similarly significantly affect them. 2. The Controller does not profile Users for advertising purposes. 3. The Controller does not automatically analyse the contents of family Materials to create profiles of people whose data may appear in them.

§ 15. Data security

1. The Controller applies organisational and technical measures appropriate to the nature of the Service and the risks connected with processing. 2. Access to User Accounts requires authentication. 3. Access to Family Spaces is restricted in accordance with the Service's permission system. 4. The Controller takes measures intended to protect the Service against unauthorised access, data loss, attacks, and other security incidents. 5. To limit the effects of failures, the Controller may create data backups. 6. Backups are technical in nature and are not intended for ordinary viewing or use of data. 7. The backup system does not replace an independent copy of particularly valuable Materials retained by the User outside the Service.

§ 16. Data deletion and backups

1. Deleting data from the active part of the Service does not mean it is immediately physically deleted from every existing backup. 2. Data in backups may remain there until it is scheduled to be overwritten or deleted in accordance with the backup cycle. 3. Data remaining only in a backup is not restored to the active system unless this is necessary to recover the system after a failure or is required by law. 4. If the system is restored from a backup, the Controller takes appropriate steps to repeat data deletion requests completed before the restoration if that data reappears in the active system.

§ 17. Cookies and server logs

1. The Service uses cookies necessary for its proper and secure operation. 2. Cookies are used in particular to: a. maintain the User's session after sign-in; b. ensure the authentication mechanism operates correctly; c. protect forms and operations performed in the Service; d. protect User Accounts and the Service. 3. The Service currently does not use cookies for behavioural advertising, marketing profiling, tracking Users across independent websites, or external marketing analytics. 4. The cookies used by the Service are necessary to supply services requested by the User. Their use therefore does not require the User's separate consent. 5. Users can manage cookies through their web browser settings. Blocking or deleting cookies necessary for the Service may cause some functions to operate incorrectly and, in particular, may prevent sign-in or maintenance of a session. 6. When the Service is used, the server may automatically record technical connection information, including the IP address, date and time of the request, requested resource, server response code, and error information. 7. Server logs are used to ensure the proper operation of the Service, diagnose errors, provide security, detect attempted unauthorised access, and investigate incidents. 8. Information in logs may constitute personal data. It is processed in accordance with this Privacy Policy. 9. If the Service begins using cookies or similar technologies in the future that are not necessary to supply the requested service, this Policy will be updated accordingly and, where required by law, those technologies will be activated only after the User has given consent.

NamePurposeStorage period
archive_sessionidMaintains the User's secure signed-in session.Up to 14 days
archive_csrftokenProtects forms and requests against CSRF attacks.Up to 1 year

§ 18. Changes to the Privacy Policy

1. The Privacy Policy and information on personal data processing for Archiwalia.com may be amended, in particular if: a. applicable law changes; b. the manner in which the Service operates changes; c. new functions are introduced; d. the entities or infrastructure used to process data change; e. the manner or location of data storage changes. 2. The current version of the Policy will be available in the Service. 3. If a change has a material impact on the processing of User data, the Controller will inform Users in an appropriate manner. 4. Version 2026-10-01 of this Privacy Policy takes effect on 1 October 2026.