Last Updated: 22 July 2026
This Privacy Policy describes how Wamahe Kileso (the "Controller") collects, uses, stores, and protects personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR"), as supplemented by the Polish Act of 10 May 2018 on the Protection of Personal Data (Dz.U. 2018 poz. 1000, as amended) and other applicable Polish legislation.
The Data Controller is Wamahe Kileso, with its registered address at Jerzego Plesnarowi cza 5/2, Rzeszow, Poland. You can contact us regarding any data protection matter by email at [email protected] or by telephone at +48 608 582 477.
As Controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that processing is carried out lawfully, fairly, and transparently in accordance with GDPR Article 5.
We collect personal data in the following circumstances and categories:
When you use our contact form: your full name, email address, telephone number, and the content of your message. This data is submitted voluntarily by you.
When you browse our website: technical data including your IP address, browser type, device type, operating system, pages visited, time of visit, and referring URL. This data is collected automatically through server logs and, where consent has been given, through cookies.
When you communicate with us by email or telephone: the content of the communication and any personal data contained within it.
We do not collect special categories of personal data as defined in GDPR Article 9 (such as data relating to health, racial or ethnic origin, or financial account details). The educational content of this program is general and non-personalized; we do not process individual financial data as part of the educational service.
We process personal data on the following legal grounds under GDPR Article 6:
Legitimate interest (Article 6(1)(f)): For responding to enquiries sent through our contact form and for maintaining the security and basic functionality of our website. We have conducted a legitimate interest assessment and determined that our interest in communicating with prospective participants does not override the rights and freedoms of the data subjects concerned.
Consent (Article 6(1)(a)): For analytics and marketing cookies, which are only placed after you have given explicit, freely given, specific, informed, and unambiguous consent through our cookie consent mechanism. You may withdraw consent at any time without detriment.
Legal obligation (Article 6(1)(c)): Where processing is required to comply with applicable Polish or EU law.
Personal data collected through the contact form is used exclusively to respond to your enquiry and to communicate with you about the program offerings you have asked about. We do not use contact form data for automated marketing purposes without separate consent.
Technical browsing data is used for website security, to diagnose technical problems, and, where consent is given, to understand how visitors navigate the site so that we can improve its structure and content.
We do not use personal data for automated decision-making or profiling as defined in GDPR Article 22.
We do not sell, rent, or trade personal data to third parties. Data may be shared with the following categories of recipients only where necessary:
Hosting and technical service providers: Companies that host our website and manage server infrastructure. These providers act as data processors under written agreements that comply with GDPR Article 28 requirements.
Analytics providers: Only where you have consented to analytics cookies. Any analytics processing is governed by the terms of the relevant provider and is conducted on the basis of your consent.
Legal and regulatory authorities: Where we are required by applicable Polish or EU law to disclose data to competent authorities, including the President of the Personal Data Protection Office (UODO).
Where we use third-party service providers who process data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place as required by GDPR Chapter V. These safeguards may include Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other approved transfer mechanisms.
We will inform you of any such transfers where they are relevant to the data you have provided, upon request.
Contact form data is retained for a period of up to 24 months from the date of last contact, after which it is securely deleted unless we have a continuing legal obligation to retain it or you have agreed to a longer retention period.
Technical browsing data in server logs is retained for a maximum of 12 months for security purposes. Cookie data is retained for the duration specified in our Cookie Policy.
We review our retention periods periodically and delete data that is no longer necessary for the purpose for which it was collected.
As a data subject, you have the following rights under the GDPR, which you may exercise at any time by contacting us at [email protected]:
Right of access (Article 15): You may request a copy of the personal data we hold about you.
Right to rectification (Article 16): You may request correction of inaccurate or incomplete personal data.
Right to erasure (Article 17): You may request deletion of your personal data where there is no legitimate reason for us to continue processing it.
Right to restriction of processing (Article 18): You may request that we restrict the processing of your data in certain circumstances.
Right to data portability (Article 20): Where processing is based on consent or contract and carried out by automated means, you may request transfer of your data in a structured, commonly used format.
Right to object (Article 21): You may object to processing based on legitimate interest at any time. We will cease processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent (Article 7(3)): Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
We will respond to all requests within one calendar month. Where a request is complex or numerous, we may extend this period by a further two months and will notify you accordingly.
If you believe that our processing of your personal data is in violation of applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland. Information on how to lodge a complaint is available at the UODO website (uodo.gov.pl).
We ask that you contact us first before lodging a complaint with a supervisory authority, as we are often able to resolve concerns directly and more quickly.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as required by GDPR Article 32. These measures include encrypted data transmission (HTTPS), access controls on systems that process personal data, and regular review of our security practices.
No method of electronic transmission or storage is entirely secure. However, we take the protection of your data seriously and maintain measures appropriate to the nature and volume of the data we process.
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. The "Last Updated" date at the top of this document indicates when the most recent version was published. Where changes are significant, we will take reasonable steps to bring them to your attention. Continued use of the website following publication of an updated policy constitutes your acknowledgment of the changes.