Polish Early Buddhism Society
Privacy Policy
of the Polish Early Buddhism Society
We care about the privacy of people who visit our website, contact us, subscribe to our newsletter, support the Society’s activities, or submit a membership application.
Below, we explain what personal data we process, for what purposes, and under what rules.
1. Personal Data Controller
The controller of personal data is:
Polish Early Buddhism Society
Registered office: ul. marsz. Józefa Piłsudskiego 74, unit 320, Wrocław
KRS: 0001257998
NIP: 8971977144
REGON: 545462419
For matters related to personal data protection, please contact us at:
pebs.rada@gmail.com
2. What Personal Data Do We Process?
Depending on how you use the website and contact the Society, we may process, in particular:
your first name and surname,
your date of birth – in the case of a membership application,
your email address,
your telephone number, if provided,
information relating to membership in the Society,
information provided in forms or correspondence,
data relating to membership fees, donations, and other payments,
data relating to registrations for events,
technical data relating to the use of the website, including information collected through cookies and similar technologies.
The scope of the data processed depends on the purpose for which it has been provided to us. We endeavour to collect only the data necessary to fulfil a given purpose.
3. Membership Applications and Membership
If you submit an electronic membership application through our website, we process the data you provide for the purposes of:
receiving and considering the membership application,
contacting you regarding the application,
enabling the Management Board to make a decision concerning membership,
and, once you have been admitted to the Society, maintaining the register of members and administering the rights and obligations associated with membership.
An electronic membership application is one of the forms of submitting an application provided for in the Statute of the Polish Early Buddhism Society.
Depending on the specific situation, the legal basis for processing personal data is taking steps at the request of the individual prior to establishing the membership relationship and the performance of that relationship (Article 6(1)(b) of the GDPR), compliance with legal obligations incumbent upon the Society (Article 6(1)(c) of the GDPR), or the Society’s legitimate interest in properly conducting its activities and maintaining its documentation (Article 6(1)(f) of the GDPR).
Providing the data marked as required in the form is necessary for the membership application to be considered. Providing any remaining data is voluntary.
4. Contacting the Society
If you contact us through the contact form, by email, or in any other manner, we process the data you provide in order to conduct correspondence and respond to you.
The legal basis for processing is our legitimate interest in conducting communications and handling enquiries addressed to us (Article 6(1)(f) of the GDPR).
If the contact concerns entering into or performing a contract, Article 6(1)(b) of the GDPR may also constitute the legal basis for processing.
5. Newsletter
If you subscribe to the newsletter, we will process the email address you provide and, where applicable, any other data provided during subscription in order to send information about the activities of the Polish Early Buddhism Society, events, meetings, lectures, initiatives, and other news relating to our activities.
We use the MailerLite platform for the technical operation of the newsletter.
We send the newsletter to people who have consented to receiving such messages. Providing data and giving consent are voluntary.
You may unsubscribe from the newsletter at any time by using the unsubscribe link included in every message or by contacting us.
The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
6. Membership Fees and Donations
If you make a payment through our website, in particular if you pay a membership fee or make a donation, we may process the data necessary to:
identify the payment,
correctly allocate the payment,
maintain financial and accounting records,
fulfil obligations arising from applicable law.
Online payments are processed by Stripe. In connection with the processing of a payment, the necessary data may be transferred to Stripe and processed in accordance with the rules applicable to that payment service provider.
The Polish Early Buddhism Society does not store full payment card details. The data necessary to authorise a payment is processed by the payment service provider.
Depending on the type of payment and the circumstances, the legal basis for the Society’s processing of personal data is the performance of obligations relating to membership or a donation (Article 6(1)(b) of the GDPR), compliance with a legal obligation, in particular one relating to the maintenance of financial and accounting records (Article 6(1)(c) of the GDPR), or the Society’s legitimate interest (Article 6(1)(f) of the GDPR).
7. Events, Meetings, and Other Registrations
If you register through our website for an event, meeting, workshop, conference, or another initiative organised or co-organised by the Society, we may process the data necessary to handle the registration and organise the event.
The scope of the data processed and the legal basis for processing may depend on the nature of the particular event.
If data is collected for another purpose or its scope goes beyond the standard handling of a registration, we may provide additional information about the processing of personal data alongside the relevant form.
8. Data Recipients and Data Processors
As a rule, personal data is not disclosed to third parties unless this is necessary for the provision of specific services or expressly required by law.
Personal data may be entrusted for processing to entities acting on the Controller’s behalf, solely to the extent necessary for them to provide their services. These may include, in particular:
Squarespace – the provider of services for maintaining and operating the website and the forms available on it;
MailerLite – the provider of newsletter distribution and mailing-list management services;
Google – the provider of services used to operate registration forms;
providers of email, IT, and hosting services;
entities providing accounting, legal, and other services supporting the Society’s activities.
Stripe and the bank maintaining the Society’s bank account are not entities processing data on behalf of the Society, but separate data controllers with regard to the payment and banking services they provide.
Personal data may also be disclosed to authorised public authorities where such an obligation arises from applicable law.
9. Transfers of Personal Data Outside the European Economic Area
As a result of the Society’s use of technology service providers, some personal data may be processed outside the European Economic Area.
In such cases, personal data is transferred using the mechanisms provided for under the GDPR that are appropriate to the particular provider and manner of processing.
10. How Long Do We Retain Personal Data?
We retain personal data for the period necessary to fulfil the purpose for which it was collected and subsequently for the period required by law or necessary to safeguard against potential claims.
In particular:
data relating to applicants for membership – for the period necessary to consider the application and, where justified, for the period necessary to document how it was considered;
members’ data – for the duration of membership and, after it ends, for the period required by law or necessary to retain the documentation required of the Society;
data relating to the newsletter – until consent is withdrawn, the person unsubscribes from the newsletter, or the purpose of processing ceases to exist;
data contained in correspondence – for the period necessary to handle and archive the matter concerned;
data relating to payments – for the period required by regulations governing financial, accounting, and tax documentation;
data relating to events – for the period necessary to organise and settle the event and subsequently for the period justified by legal obligations or the possibility of pursuing claims.
11. Your Rights
In the circumstances provided for under the GDPR, you have the right to:
access your personal data,
receive a copy of your data,
rectify inaccurate or outdated data,
request the erasure of your data,
request the restriction of processing,
data portability,
object to processing based on a legitimate interest,
withdraw your consent at any time where your data is processed on the basis of consent.
The exercise of certain rights may be restricted in the circumstances provided for under applicable law, for example where the Society is under a legal obligation to continue retaining certain data.
For matters concerning personal data, you may contact us at: pebs.rada@gmail.com
If you believe that your personal data is being processed unlawfully, you also have the right to lodge a complaint with the President of the Personal Data Protection Office.
12. Cookies
Our website uses cookies and similar technologies.
Essential cookies may be used to ensure the proper, secure, and technical functioning of the website.
In the case of cookies that are not essential for the functioning of the website, in particular analytical or marketing cookies, the user may grant or refuse consent through the cookie management mechanism available on the website.
We use the functionality available within the Squarespace platform to manage consent relating to cookies.
Users may change their cookie preferences. Information about their choice may be stored in order to remember their settings.
Users may also manage cookies through their web browser settings.
13. Voluntary Provision of Personal Data
As a rule, providing personal data is voluntary.
In certain cases, however, providing specific data is necessary in order to use a particular service or function, for example to submit a membership application, make a payment, receive a response to a message, or register for an event.
Mandatory fields in forms are marked accordingly.
14. Data Security
We apply appropriate organisational and technical measures designed to protect personal data against unauthorised access, loss, alteration, destruction, or unauthorised disclosure.
Access to personal data should be limited to individuals who require it in connection with the performance of their duties.
15. Changes to the Privacy Policy
The Privacy Policy may be updated, in particular where there are changes to the operation of the website, the services used, the Society’s activities, or applicable law.
The current version of the Privacy Policy is published on the Society’s website.
Date of last update: 25 August 2026