PRIVACY POLICY

of the VIAMOO.pl Website

Version 1.0 of 01.09.2026 (This is a helper translation; the binding version is the Polish one.)

§1 General provisions

  • This Privacy Policy supplements the information set out in the Terms of Service for the electronic provision of services of the Viamoo.pl website, available at: https://viamoo.pl/regulamin , and presents the rules for processing and protecting the personal data of persons using the services provided via the website https://viamoo.pl/ . This Privacy Policy has been drawn up on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).
  • We inform you that, in accordance with the Terms of Service of the Viamoo.pl website, with respect to personal data processed within a specific Event (in particular data contained in photos, video materials, guest book entries, the seating plan, the Event schedule and other content posted by the Event Organiser or Guests), the Operator of the Viamoo.pl website acts as a processor of personal data acting on behalf of the Event Organiser, who is the controller of that personal data. In such a case, the Operator of the Viamoo.pl website processes personal data solely on the Event Organiser's instructions, to the extent and for the purpose necessary to provide the Services specified in the Terms of Service, in particular for the purpose of storing, organising, making available, displaying, securing and deleting data within the Website's functionalities.
  • Notwithstanding section 2, the Operator of the Viamoo.pl website acts as a controller of personal data with respect to data processed in connection with the operation of the Website, the electronic provision of services, the conclusion and performance of Agreements, payment handling, ensuring the security of ICT systems, keeping technical statistics, handling user requests, pursuing or defending against claims, fulfilling the legal obligations incumbent on the controller, and preventing abuse and unauthorised use of the Website.

§2 Definitions and useful information

  • Website - the website and web application available at https://viamoo.pl/ and on individual subdomains name.viamoo.pl, through which the Services are provided;
  • Service - any services provided electronically within the Website, in accordance with the Terms of Service of the Viamoo.pl website available at: https://viamoo.pl/regulamin ;
  • Policy - this Privacy Policy;
  • Terms of Service - the Terms of Service for the electronic provision of services of the Viamoo.pl website, available at: https://viamoo.pl/regulamin;
  • User and/or Service Recipient - any person using the Services available on the Website, regardless of their type or manner of use. In this Policy we may use the term „User” or „Service Recipient”, as well as address the data subject directly. Where we refer to personal data processed on behalf of the Event Organiser, we will use the term „Guest” or „Event Guest”;
  • Viamoo - the Operator of the website, being the Service Provider, i.e. Mateusz Pawłowski, who can be contacted by electronic correspondence sent to: contact@viamoo.pl Where this Policy uses the terms „us” or „we”, this should be understood as referring to Viamoo;
  • Event Organiser - a natural person, legal person or organisational unit without legal personality that has concluded an Agreement on the terms set out in the Terms of Service and uses the Services as an Event organiser;
  • Guest - a person who, by means of an individual link or QR code shared by the Event Organiser and, if set, the Event Password, gains access to the Event's features without having to conclude an Agreement with Viamoo and without registering an account, in accordance with the Terms of Service;
  • Event - an occasion organised by the Event Organiser using the Website's functionalities, in accordance with the Terms of Service;
  • GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
  • Whenever this Policy uses terms such as: personal data, processing, Controller, processor, data processing entrustment agreement, consent or profiling, they should be understood respectively as:
    • personal data - information about an identified or identifiable natural person („data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, in accordance with Article 4(1) GDPR;
    • processing - an operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, in accordance with Article 4(2) GDPR;
    • Controller - a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, in accordance with Article 4(7) GDPR;
    • Processor - a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, as defined in Article 4(8) GDPR;
    • Data processing entrustment agreement - an agreement concluded between the Controller and the Processor, on the basis of which the Processor processes personal data on behalf of and on the instructions of the Controller;
    • profiling - any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements, as defined in Article 4(4) GDPR;
    • consent - any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them, as defined in Article 4(11) GDPR.
  • Whenever this Policy uses terms identical to those defined in the GDPR, they have the same meaning as those terms.

§3 Controller of the Service Recipient's personal data

  • The controller of personal data processed in connection with the operation of the Website, the performance of the Agreement, the use of the Admin Panel, ensuring the security of the Website and the fulfilment of legal obligations is Viamoo.
  • In the rest of this Policy we use the terms „Controller” or „Viamoo”. However, for the sake of a clear and transparent message, we also use direct forms (e.g. „we”, „our”, „we may”). In each such case it should be assumed that these formulations refer to the Controller (e.g. the phrase „we may process personal data” means that the Controller has the right to process personal data).
  • The Controller can be contacted via the communication channels indicated below:
  • With respect to personal data processed in connection with the organisation of a specific Event, in particular Guests' data posted in the gallery, guest book, seating plan, Event schedule and other functionalities made available by the Event Organiser, the controller of the personal data is the Event Organiser.
  • Viamoo processes the personal data referred to in section 4 solely as a processor, on the terms set out in the Terms of Service and in accordance with the instructions of the Event Organiser as the controller of the personal data.
  • Notwithstanding sections 4 and 5, Viamoo may act as a controller of Guests' personal data to the extent that the processing of that data is necessary to provide services electronically, ensure the security of the Website, operate the ICT infrastructure, fulfil the legal obligations incumbent on Viamoo, pursue or defend against claims, and achieve other purposes described in detail in this Policy.
  • The detailed rules for the entrustment of personal data processing by the Event Organiser to Viamoo are set out in the Terms of Service.

§4 Rules for processing the Service Recipient's personal data

  • When you visit our Website and/or use the Services available on the Website, your personal data is usually processed. The GDPR imposes on us, as the Controller of your personal data, particular obligations related to such processing. Below we present the rules according to which we will process your personal data while you use the Website or the Services:
    • the principle of lawfulness, fairness and transparency - we undertake to process your personal data lawfully, fairly and in a transparent manner for you, in accordance with the obligation set out in Article 5(1)(a) GDPR;
    • the principle of purpose limitation - we undertake to process your personal data for specified, explicit and legitimate purposes and not to process your personal data in a manner incompatible with those purposes, in accordance with the obligation set out in Article 5(1)(b) GDPR;
    • the principle of data minimisation - we undertake to process your personal data to an extent that is adequate, relevant and limited to the purposes of processing we have determined, in accordance with the obligation set out in Article 5(1)(c) GDPR;
    • the principle of accuracy - we undertake to process your personal data while ensuring its accuracy and being up to date, and where we consider the personal data not to be up to date, we undertake to erase it or take all available steps to have it rectified, in accordance with the obligation set out in Article 5(1)(d) GDPR;
    • the principle of storage limitation - we undertake to process your personal data for a period no longer than necessary for the purposes for which the personal data was collected, in accordance with the obligation set out in Article 5(1)(e) GDPR;
    • the principle of integrity and confidentiality - we undertake to process your personal data ensuring its appropriate security, protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, in accordance with the obligation set out in Article 5(1)(f) GDPR.

§5 Purposes, legal bases, scope and period of processing the Service Recipient's personal data

  • The scope of personal data we process depends on the type of your activity while using the Website and the Services available on it. Below we present the purposes, legal bases, scope and period of processing your personal data depending on the actions you take.
  • Your personal data is processed for one of the purposes defined below:
    • management, operation and adaptation of the Website;
    • establishing and conducting correspondence with Viamoo;
    • visiting Viamoo's social media profiles;
    • setting up and using the Admin Panel and configuring the Event;
    • making online payments;
    • the Guest's use of the Event's functionalities.
  • Scope, legal basis and period of processing of personal data:
    • Management, operation and adaptation of the Website:

      during visits to the Website, a connection is established with your web browser and/or information such as the IP number and type of your device and data concerning the web browser you use are recorded. The information obtained during this activity is stored temporarily and serves the proper display and operation of the Website or the Services available on the Website.

      The legal basis for processing your personal data for this purpose is the legitimate interest of the Controller, consisting in ensuring the proper functioning of the Website and the security of the Services provided - Article 6(1)(f) GDPR.

      The data is processed for the period necessary to achieve the indicated purpose, and with respect to data recorded in system logs for the period resulting from the security and data retention rules applied by the Controller.

    • in the event of establishing and conducting correspondence with Viamoo:

      on the Website we have made available contact details and links to our social media profiles, through which you can contact Viamoo. Below we indicate the scope of processing your personal data in the event of contact via:

      - e-mail:

      • name;
      • e-mail address;
      • IP number;
      • and other data that may constitute the content of the correspondence.

      - other means of communication:

      • if you use other forms of contact with Viamoo (e.g. via messengers on social media), your personal data is not required; however, you may decide to provide it yourself or it may be transferred automatically (e.g. name or nickname). Viamoo encourages the use of official contact channels only, because the use of messengers whose operation Viamoo does not influence does not guarantee full control and security of your personal data.

      The legal bases for processing your personal data for this purpose are:

      • performance of a contract or steps taken prior to concluding a contract at the request of the data subject - Article 6(1)(b) GDPR;
      • the legitimate interest of the Controller consisting in handling the correspondence conducted, as well as processing personal data for the purposes of establishing, pursuing or defending against potential claims - Article 6(1)(f) GDPR.

      Your personal data will be processed for the period resulting from the limitation of civil-law claims, counted from the day the correspondence ends or from the day the relationship with the Controller ceases. The limitation period for civil-law claims is regulated in detail by generally applicable law and depends on the type of communication conducted (the maximum limitation period provided for by law in this case is 6 years).

    • In the event of visiting our social media:

      on the Website we have placed links to our social media profiles; if you use the placed link, then your personal data will also be processed by the operator of the given service. We inform you that, as part of managing our social media profiles, we may process your personal data to the extent that you decide to provide it to us through your activity on a given profile, e.g. name and/or nickname, contact details, image and/or avatar, etc. The personal data you provide as part of your activity on our profile on a given social medium will be processed for the purpose of conducting any correspondence with you, as well as in connection with analysing your reactions to our activity, e.g. likes of posts, comments, shares, etc. Please remember that the operator of a given social medium is a separate controller of your personal data, so we have no influence over the purposes and means of processing your personal data by a given operator (e.g. Meta Platforms Inc. in the case of Facebook and Instagram). Below we present information on the processing of your personal data by the operators of selected social media services:

      Facebook (Meta Platforms Inc.): https://www.facebook.com/privacy/explanation

      Instagram (Meta Platforms Inc.): https://www.facebook.com/help/instagram/155833707900388

      TikTok (TikTok Technology Limited): https://www.tiktok.com/legal/page/eea/privacy-policy/pl

    • In the event of using the Admin Panel and configuring the Event:

      Viamoo makes available to you the possibility of setting up and using the Admin Panel and configuring the Event. Below we indicate the scope of processing your personal data for this purpose:

      • name;
      • e-mail address;
      • data resulting from settlements and payments;
      • entity data (if applicable);
      • Event name and type;
      • Event subdomain name;
      • Event date;
      • and other data necessary to provide the Services in accordance with the Terms of Service.

      The legal bases for processing your personal data for this purpose are:

      • performance of a contract or steps taken prior to concluding a contract at the request of the data subject - Article 6(1)(b) GDPR;
      • the legitimate interest of the Controller, consisting in ensuring the proper functioning of the Services, ensuring the security of the User's data and the continuity of the Services, documenting the course of the Service provided to you, and processing personal data for the purposes of establishing, pursuing or defending against potential claims - Article 6(1)(f) GDPR;
      • fulfilment of a legal obligation incumbent on the Controller, including obligations set out in accounting regulations and tax regulations, in particular where the personal data forms part of the accounting documentation - Article 6(1)(c) GDPR

      Your personal data will be processed for the term of the Agreement, then for the period resulting from the limitation of civil-law claims, counted from the day the relationship with the Controller ceases. The limitation period for civil-law claims is regulated in detail by generally applicable law and depends on the type of relationship between you and the Controller (the maximum limitation period provided for by law in this case is 6 years).

      Personal data processed in connection with the fulfilment of legal obligations incumbent on the Controller will be stored for the periods resulting from the relevant legal provisions (e.g. accounting documentation for 5 years, counted from the next accounting period).

    • In the event of making an online payment:

      as part of the Services available on the Website, you may make a payment via one of the payment methods indicated in the Terms of Service. Below we indicate the scope of processing your personal data in connection with purchases made and the associated payments:

      • name;
      • e-mail address;
      • telephone number;
      • invoicing data;
      • other data necessary for the proper conduct of the payment.

      The legal basis for processing your personal data for this purpose is:

      • performance of a contract or steps taken prior to concluding a contract at the request of the data subject - Article 6(1)(b) GDPR;
      • a legal obligation incumbent on the Controller in connection with the need to retain accounting evidence - Article 6(1)(c) GDPR;
      • the legitimate interest of the Controller, consisting in ensuring the proper functioning of the Service, ensuring the security of the User's data, documenting the course of the Service provided, and processing personal data for the purposes of establishing, pursuing or defending against potential claims - Article 6(1)(f) GDPR.

      Your personal data will be processed for the period resulting from the Service provided, then for the limitation period of civil-law claims, counted from the day the relationship with the Controller ceases. Personal data whose processing arises from a legal obligation incumbent on the controller will be processed for the period resulting from the relevant generally applicable law (e.g. accounting evidence is stored for 5 years, counted from the next accounting period).

      Making a payment with Stripe

      We inform you that if you choose a payment made via Stripe, your personal data will be transferred to the payment operator Stripe Technology Company Limited. This operator acts as a separate controller of personal data and processes the data for the purpose of carrying out the payment transaction, handling payments, examining complaints and fulfilling obligations arising from the law.

      Detailed information on the rules for processing personal data by Stripe is available at: https://stripe.com/en-pl/legal/privacy-center .

    • The Guest's use of the Website's functionalities:

      In the event of a Guest using the Event's functionalities, personal data such as the Guest's name or nickname, the image captured in photos and video materials, entries posted in the guest book, data contained in the seating plan, the Event schedule and other Content posted by the Event Organiser or Guests is processed by the Event Organiser as the controller of the personal data. Viamoo processes this data solely as a processor acting on the instructions of the Event Organiser, to the extent and for the purpose necessary to provide the Service.

      Personal data related to the Event is processed for the duration of the Event and for the further period indicated in the Terms of Service. In accordance with the Terms of Service, data related to the Event is, as a rule, deleted by Viamoo within 30 days of the end of the Service's activity period, unless applicable law requires further retention.

      Notwithstanding the above, Viamoo may process certain personal data related to the use of the Website as a separate controller, where this is necessary to ensure the security of ICT systems, keep technical statistics, handle requests, establish, pursue or defend against claims, fulfil obligations arising from the law, or prevent abuse and unauthorised use of the Website, as set out in detail in this Policy.

§6 Cookies

The Website uses cookies (so-called „cookies”), i.e. files that are saved on the device (computer, smartphone, tablet) on which the web browser through which you visit the Website is installed. By default, the Controller uses only those cookies without which the Website cannot function properly. Otherwise, the use of other types of cookies depends on your decision, made through the choice in the cookie preferences management form; you can change this choice at any time. The cookie preferences management form is located on the Website, regardless of the tab you have selected. Consent to the use of a given type of cookies is granted on the basis of Article 399 of the Act of 12 July 2024 - Electronic Communications Law (Journal of Laws 2024, item 1221, as amended). We inform you that the following types of cookies may be used on the Website:

  • necessary

    necessary cookies contribute to the usability of the site by enabling basic functions such as site navigation and access to secure areas of the website. The website cannot function properly without these cookies. Such cookies are used on the basis of the legitimate interest of the Controller, in accordance with Article 6(1)(f) GDPR.

  • functional

    functionality cookies enable the site to remember information that changes the appearance or functioning of the site, e.g. the preferred language or the region where the user is located. Functionality cookies are used only after obtaining your consent, in accordance with the provisions of the Act of 12 July 2024 - Electronic Communications Law (Journal of Laws 2024, item 1221, as amended). If the information obtained via these files constitutes personal data, the basis for its processing is also your consent within the meaning of Article 6(1)(a) GDPR.

  • Statistical and analytical

    statistical cookies help website owners understand how different users behave on the site by collecting and reporting anonymous information. Statistics cookies are used only after obtaining your consent, in accordance with the provisions of the Act of 12 July 2024 - Electronic Communications Law (Journal of Laws 2024, item 1221, as amended). If the information obtained via these files constitutes personal data, the basis for its processing is also your consent within the meaning of Article 6(1)(a) GDPR.

  • marketing

    marketing cookies are used to track users across websites. The aim is to display advertisements that are relevant and engaging for individual users and thus more valuable for third-party publishers and advertisers. Marketing cookies are used only after obtaining your consent, in accordance with the provisions of the Act of 12 July 2024 - Electronic Communications Law (Journal of Laws 2024, item 1221, as amended). If the information obtained via these files constitutes personal data, the basis for its processing is also your consent within the meaning of Article 6(1)(a) GDPR.

We inform you that, apart from the cookie preferences management form, you can also block cookies from your web browser, in accordance with Article 399 of the Act of 12 July 2024 - Electronic Communications Law (Journal of Laws 2024, item 1221, as amended). Below we present information on the possibility of blocking cookies from the most popular web browsers:

Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=pl

Safari: https://support.apple.com/pl-pl/HT201265

Opera: https://help.opera.com/pl/latest/web-preferences/

Firefox: https://support.mozilla.org/pl/kb/usuwanie-ciasteczek-i-danych-stron-firefox

Microsoft Edge: https://support.microsoft.com/pl-pl/microsoft-edge/usuwanie-plików-cookie-w-przeglądarce-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09

We inform you that cookies may also be used by providers of external analytical and marketing tools used by the Controller, in particular Google Analytics 4, Google Ads, Google Tag Manager and Meta Pixel. Detailed information on the analytical and marketing tools used is described in §7 of this Policy.

§7 Analytical and marketing tools

In order to analyse how the Website is used, improve its functionality, measure the effectiveness of marketing activities and conduct advertising activities, the Controller may use tools provided by third parties. These tools may use cookies, similar tracking technologies and process information about the user's activity on the Website. Analytical and marketing tools are activated only after obtaining the User's consent via the cookie preferences management form, except for those technologies that are necessary for the proper functioning of the Website.

Google Analytics 4

The Controller uses the Google Analytics 4 tool provided by Google Ireland Limited and Google LLC in order to analyse traffic on the Website, study how Users use the Website and optimise its functioning. Google Analytics 4 may process in particular:

  • IP address (in anonymised form);
  • user and device identifiers;
  • information about the web browser and device;
  • data on activity on the Website, including subpages visited, visit duration and entry source;
  • information about events and conversions.

The basis for processing personal data in connection with the use of Google Analytics 4 is the User's consent, in accordance with Article 6(1)(a) GDPR.

Google Tag Manager

The Controller also uses the Google Tag Manager tool, which is used to manage the scripts and tags used on the Website. Google Tag Manager does not itself serve to collect Users' personal data, but enables the management of other analytical and marketing tools used on the Website.

Google Ads

The Controller uses the Google Ads advertising tools, provided by Google Ireland Limited and Google LLC, enabling the display of advertisements tailored to Users' interests and the conduct of marketing activities. In connection with the use of Google Ads, the following may be processed in particular:

  • cookie identifiers and advertising identifiers;
  • information concerning the User's activity on the Website;
  • data on pages and subpages visited;
  • IP address to the extent provided by the service provider.

The basis for processing personal data is the User's consent, in accordance with Article 6(1)(a) GDPR. Detailed information on the personalisation of Google ads is available at: https://adssettings.google.com .

Meta Pixel

The Controller also uses the Meta Pixel tool provided by Meta Platforms Ireland Limited. This tool enables the analysis of the effectiveness of advertising activities conducted on Facebook and Instagram, the conduct of remarketing activities and the targeting of advertisements to audiences with specific characteristics. Data may be transferred to Meta Platforms Ireland Limited and entities of the Meta group. In connection with the use of Meta Pixel, the following may be processed in particular:

  • cookie identifiers;
  • IP address;
  • information about the device and browser;
  • information about the User's activity on the Website, including subpages visited and actions taken.

The basis for processing personal data is the User's consent, in accordance with Article 6(1)(a) GDPR. Detailed information on the rules for processing data by Meta is available at: https://www.facebook.com/privacy/policy/ .

§8 Hosting and cloud tools

In order to maintain the transparency of the processes in which your personal data is processed, below we indicate to which entities we transfer your personal data in connection with the provision of the services. The entities indicated below may act both as processors of personal data on behalf of Viamoo and as further processors of personal data entrusted to Viamoo by Event Organisers, while you use the Website or the Services available on it:

Cloudflare, Inc.

Role: file storage - guests' photos and videos and guest book photos, handling domains, traffic and file caching.

Scope of data: image in photos/videos + the associated displayed guest name, as well as IP addresses, request metadata.

Railway (Railway Corp.)

Role: application hosting (backend) and PostgreSQL database

Scope of data: all textual data - guest names, administrators' name and e-mail, guest book entry content, photo metadata, logs

Resend (Resend, Inc.)

Role: sending transactional e-mails, panel login links, order confirmations

Scope of data: recipient's e-mail address and name, event name

Vercel (Vercel, Inc.)

Role: hosting the marketing site and the order form.

Scope of data: form data (name, e-mail) passing through the server, IP/logs

§9 Necessity of providing personal data

Providing personal data is, as a rule, voluntary; however, in many cases it is necessary to use certain Services offered by Viamoo. In particular, providing data may be necessary in order to set up and use the Admin Panel, make an electronic payment, conduct correspondence, examine a complaint or use other functionalities available within the Services. Failure to provide the required data may result in the inability to provide a given Service or to take actions related to your request.

If the processing of personal data takes place on the basis of your consent (e.g. in order to receive commercial information, use cookies or marketing communication), providing the data is voluntary, and the lack or non-granting of consent does not entail any negative consequences. In such a case, however, we will not be able to carry out activities requiring such consent.

In cases where the processing of personal data is necessary to perform a contract, take steps prior to concluding a contract or fulfil a legal obligation incumbent on the Controller, providing the data is necessary. Failure to provide the required data may prevent the conclusion or performance of the contract, the making of a payment, the running of the client panel or the fulfilment of obligations arising from the law.

If the processing of personal data takes place on the basis of the legitimate interest of the Controller, providing the data may be necessary to ensure the proper functioning and security of the Services, prevent abuse, handle requests and pursue or defend against claims. In such a case, failure to provide the data may prevent the use of certain functionalities of the Services or the performance of certain activities.

§10 Recipients and categories of recipients of personal data

Your personal data may be transferred to:

  • entities that perform activities necessary for the Controller to provide the Services; in such a case, the transfer of your personal data takes place on the basis of a concluded data processing entrustment agreement, with the application of appropriate technical and organisational measures. The entities to which the Controller may transfer your personal data in connection with the performance of the Services include, among others:
    • entities that provide hosting and cloud services to the Controller (e.g. server, e-mail, etc.);
    • entities that provide the software used by the Controller (e.g. providers of software for handling e-mail, providers of online sales software, providers of software for distributing commercial information, etc.);
    • entities providing IT support services (e.g. entities that support the Controller in managing and maintaining ICT systems);
    • entities that provide advertising, analytical and/or sales services to the controller (e.g. marketing agencies, providers of solutions for online advertising and/or sales, etc.);
    • a law firm and other entities that support the Controller in legal, tax, etc. matters.
  • entities or parties authorised to do so on the basis of generally applicable law (e.g. they may be transferred to public authorities in connection with a legal obligation requiring the Controller to transfer your personal data);
  • payment service providers and operators of payment systems, which, as a rule, act as separate controllers of your personal data;

§11 Transfer of personal data outside the European Economic Area (EEA)

As a rule, we do not intend to transfer your personal data outside the European Economic Area (EEA), comprising the Member States of the European Union, Norway, Liechtenstein and Iceland, unless this is necessary for the proper and lawful provision of the Services. At the same time, we inform you that, in connection with the Controller's use of selected analytical, marketing, cloud or IT tools, your personal data may be transferred outside the EEA. In such a case, we ensure an appropriate level of protection of personal data and apply the measures required by the GDPR, in particular European Commission decisions confirming an adequate level of protection, standard contractual clauses or other legally permissible safeguard mechanisms.

In the case of entities established in countries for which the European Commission has confirmed an adequate level of protection of personal data, the transfer of personal data takes place on the basis of a European Commission decision confirming an adequate level of protection. In other cases, the appropriate safeguards required by the GDPR apply, in particular standard contractual clauses or agreements on the entrustment of personal data processing, depending on the nature of the relationship with a given data recipient and the requirements arising from the law. In the case of transferring your personal data to the United States of America (USA), the „EU-US Data Privacy Framework” program will also apply, under which the transfer of personal data from the EEA to organisations that have joined the „EU-US Data Privacy Framework” program is possible without the need to obtain additional permits or apply legal instruments such as standard contractual clauses.

Additional information:

The transfer of personal data outside the European Economic Area (EEA) means that this data may not be subject to safeguards as strong as those guaranteed within the European Union. In the event of an unregulated transfer of data outside the EEA, the enforcement of rights and the pursuit of claims by data subjects may be more difficult. Therefore, the application of the instruments required by the GDPR is necessary so that, if providers established outside the EEA are used, your personal data continues to be protected under EU law. Viamoo declares that all Services are provided on the basis of the safeguards required by law regarding the transfer of your personal data outside the European Economic Area, but such a transfer will take place only where it is necessary for the operation and/or provision of certain Services.

§12 Automated decision-making, including Profiling

When you visit our Website, your personal data may be processed in an automated manner; however, by default no decision is made that has a significant effect on you, i.e. this type of automated processing does not produce legal effects concerning you and does not affect your situation.

If you consent to the use of advertising cookies, the Controller will in selected cases apply profiling. This means that, thanks to the automatic processing of data, the Controller evaluates selected factors concerning natural persons in order to analyse their behaviour or create a prediction of preferences for the future. Profiling consists in directing behavioural advertising to users (i.e. tailored to their individual interests). The use of personal data collected via this technology for marketing purposes - in particular in the scope of promoting the goods and services of third parties - requires your consent, which may be withdrawn at any time. This type of profiling does not constitute the sole basis for making decisions that produce legal effects concerning you or similarly significantly affect your situation.

§13 Source of your personal data

The personal data we process in connection with your activity on the Website comes directly from you. In the case of using certain Services, personal data may be obtained from the Event Organiser, other Website users or entities participating in the execution of payments, if this is necessary to provide the Services or fulfil obligations arising from the law.

§14 Your rights

When your personal data is processed, the Controller is obliged to ensure that you can exercise your rights, because they are guaranteed by the GDPR. Below we indicate what rights you have in connection with the processing of your personal data:

  • the right to withdraw the consent given, on the basis of Article 7 GDPR,
  • the right of access and to obtain a copy of the data, in accordance with Article 15 GDPR,
  • the right to rectification of data, in accordance with Article 16 GDPR,
  • the right to request the erasure of personal data, in accordance with Article 17 GDPR,
  • the right to restrict the processing of data, in accordance with Article 18 GDPR,
  • the right to data portability, in accordance with Article 20 GDPR,
  • the right to object to the processing of data, in accordance with Article 21 GDPR,
  • the right not to be subject to decisions based on automated processing, including profiling, in accordance with Article 22 GDPR,
  • the right to lodge a complaint against the Controller's actions.

You can send your request concerning the exercise of your rights to us at any time, by sending an e-mail to: contact@viamoo.pl or by traditional correspondence sent to the Controller's address marked „RODO”.

You may exercise the right to complain by directing an appropriate application to the President of the Personal Data Protection Office; all necessary information in this respect is available at: www.uodo.gov.pl

We inform you that in the case of personal data processed by the Event Organiser as the controller, the exercise of GDPR rights may require directing the request to the Event Organiser directly.

§15 Security

  • We make every effort to ensure the security of your personal data during processing and the protection required by generally applicable law. To this end, below we present basic information on the security measures we apply:
    • we strictly control our methods of processing all data and information, including physical security measures, to protect data against unauthorised access;
    • we cooperate only with entities that guarantee compliance with personal data protection regulations, in particular the GDPR;
    • we constantly raise the level of security of our IT systems so that their safeguards are up to date against all cyber threats and so that the use of our Services takes place in a safe and comfortable manner for you;
    • we grant access to personal data only to those employees, contractors and representatives who have the necessary knowledge and qualifications to guarantee, during the processing of personal data, its security and protection against unauthorised disclosure or modification;
    • our employees, associates and contractors continually raise their level of knowledge in the field of protecting the processed personal data;
    • we constantly monitor the risk associated with processing your personal data and, where we consider that a given process may involve a potential breach of the protection of this data, we take the necessary measures to eliminate such risk;
    • all processes related to the processing of your personal data are carried out in accordance with the principle of transparency - we guarantee you full control over all operations in which we process your personal data;
    • when designing our Services, we always apply the principles of: „data protection by design” (privacy by design) and „data protection by default” (privacy by default).
  • Please remember that using services available on the Internet may involve certain risks, regardless of whether you use services provided by Viamoo or services of other entities; we recommend that you:
    • install antivirus software on the device you use (computer, smartphone, tablet); it is also recommended that the antivirus program be kept constantly updated, immediately after updates become available for installation;
    • enable the system firewall on the device you use;
    • use only original software;
    • regularly update software;
    • exercise caution when clicking links and opening attachments from unknown senders (e.g. a sender who may be impersonating Viamoo);
    • refrain from providing specially protected data (e.g. PESEL number, ID document details, payment card details, etc.).
  • Any additional information on possible risks when using services provided electronically (not only within the Website) is available at: https://www.gov.pl/web/baza-wiedzy/cyberbezpieczenstwo.

§16 Contact details

If you have questions or concerns about the way we process your personal data, please use the contact details presented below:

  • e-mail address: contact@viamoo.pl
  • address for traditional correspondence: in preparation

§17 Final provisions

This Privacy Policy may be subject to change. All changes to the Privacy Policy will be published on the Website, and in the case of significant changes concerning the methods or purposes of processing your personal data, information about the change to the Policy will be directed to you directly.

Document version 1.0 | The last update of this document took place on 01.09.2026.