This document defines the rules for processing personal data and using cookies within the website of the LEGACY AND INNOVATION Foundation.
1. Data Controller
The controller of your personal data is:
LEGACY AND INNOVATION Foundation
registered office: ul. Szeroka 26, 27-500 Opatów
board office (correspondence address): ul. Mariana Zdziechowskiego 10/78, 02-659 Warszawa
entered into the Register of Associations, Other Social and Professional Organizations, Foundations and Public Healthcare Facilities of the National Court Register under KRS number: 0001188002, NIP: 8631711631, REGON: 542421331 (hereinafter: the “Foundation” or “Controller”).
You can contact us by writing to the email address: foundation@aimindllc.com or by sending traditional mail to the board office address.
2. Purposes, Legal Bases, and Retention Periods of Data Processing
Personal data is processed for purposes related to the functioning of the website and communication with users:
| Purpose of processing | Legal basis | Retention period |
|---|---|---|
| Handling inquiries sent via contact forms or email | Legitimate interest of the Controller (Art. 6 sec. 1 lit. f GDPR) – communicating with users and providing answers | Until the correspondence is finished, and then for the limitation period of potential claims |
| Cooperation activities (internships, volunteering, partnership) | Taking steps at the request of the data subject prior to entering into a contract/agreement (Art. 6 sec. 1 lit. b GDPR) or voluntary consent expressed by submitting the form (Art. 6 sec. 1 lit. a GDPR) | For the duration of recruitment / arrangements, and in case of establishing cooperation – for its duration and the period resulting from legal provisions |
| Handling donations and fulfilling accounting/tax obligations | Fulfilling a legal obligation incumbent on the Controller (Art. 6 sec. 1 lit. c GDPR) in connection with tax regulations | For a period of 5 years from the end of the calendar year in which the donation was made |
| Defense against claims or pursuing them | Legitimate interest of the Controller (Art. 6 sec. 1 lit. f GDPR) consisting in protecting the rights of the Foundation | Until the limitation period for claims expires in accordance with the Polish Civil Code |
3. Recipients of Personal Data
Your personal data may be entrusted to third parties providing services to the Foundation, including:
- Hosting and email service providers,
- Entities handling contact form systems on the website (e.g., Web3Forms as a processor),
- Legal advisers, accountants, and patent attorneys (to the extent necessary to perform their tasks).
All these entities process data on the basis of personal data processing entrustment agreements and are obliged to ensure full data security.
4. Rights of the Data Subject
In connection with the processing of personal data, you have the following rights:
- Right to access the content of your data and receive a copy thereof,
- Right to rectify (correct) your data,
- Right to erase data (“right to be forgotten”) – unless there are circumstances excluding this right (e.g., legal obligation to store accounting documents),
- Right to restrict processing,
- Right to object to data processing based on the Controller’s legitimate interest,
- Right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, Poland).
To exercise your rights, please contact us at: foundation@aimindllc.com.
5. Cookies and Technical Data
Our website uses cookies. These are small text files saved on your terminal device.
- Necessary cookies: Used for the proper operation of the website (e.g., navigation, language switching PL/EN). They do not require user consent.
- Analytical/statistical cookies: Help us understand how users use the site (e.g., visitor counter). This data is anonymized.
- Cookie management: You can change your cookie settings in your web browser at any time (completely block them or delete existing ones).
6. Data Security and Transfers Outside the EEA
The Foundation makes every effort to protect personal data against unauthorized access, loss, or destruction. Data is transmitted using an encrypted SSL/TLS protocol.
In connection with the use of third-party IT tools and contact forms (e.g., Web3Forms), data may be transferred to and processed by these entities in a manner consistent with the protection mechanisms provided by the GDPR (e.g., Standard Contractual Clauses approved by the European Commission). Data is not transferred to third countries that do not ensure an adequate level of data protection, nor is it subject to automated decision-making (including profiling).