Privacy Policy

Hello and welcome.

If you are here, it means that your privacy matters to you. We understand that, so this document explains in one place how personal data, cookies and other tracking technologies are used in connection with the website https://kinomural.com/.

This Privacy Policy is informational and is based on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly known as the GDPR.

# 1: Who is the controller of your personal data?

The controller of your personal data is the organiser of Kinomural, responsible for operating the website and handling communication connected with the festival. You can contact the controller using the contact details published on the website.

# 2: Who can you contact about personal data processing?

For all matters concerning privacy and personal data, contact us by e-mail through the address provided on the website or through the contact form.

# 3: What information about you do we process?

We may process data that you provide voluntarily, especially your name, e-mail address, message content, organisation or other details included in a form, application, e-mail or cooperation request. We may also process technical data connected with website use, such as IP address, browser type, operating system, approximate location, pages visited and cookie identifiers.

# 4: Where do we obtain your personal data from?

We receive most data directly from you when you contact us, subscribe to information, apply to an open call, send a message or use website forms. Technical data may be collected automatically by the website, server logs and analytical or security tools.

# 5: Is your data safe?

We use organisational and technical measures intended to protect personal data against accidental loss, unauthorised access, disclosure, alteration or destruction. Access to data is limited to people and service providers who need it to perform their tasks.

# 6: For what purposes do we process personal data?

We process personal data to operate the website, answer messages, handle applications and cooperation requests, organise festival activities, publish programme and archive information, maintain security, keep server logs, analyse website traffic, pursue or defend claims, fulfil legal obligations and, where applicable, send information requested by you.

# 7: How long do we store personal data?

We store data only for as long as necessary for the purpose for which it was collected. Correspondence may be kept for the time needed to handle the matter and secure possible claims. Data processed on the basis of consent is kept until consent is withdrawn, unless another legal basis allows or requires further storage. Server logs are stored for technical and security purposes for a limited period.

# 8: Who receives your personal data?

Data may be shared with trusted service providers, including hosting providers, e-mail and IT service providers, website administrators, analytics providers, form and security tool providers, accounting or legal advisers and entities authorised by law. Each provider receives only the data necessary to perform its service.

# 9: Do we transfer data outside the European Economic Area?

Some external tools may involve data transfer outside the European Economic Area. When this happens, we rely on mechanisms required by law, such as adequacy decisions, standard contractual clauses or other safeguards provided under the GDPR.

# 10: Do we use profiling or automated decision-making?

We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significant consequences. Website analytics may involve basic statistical profiling of traffic and content performance.

# 11: What rights do you have?

You have the right to access your data, receive a copy of it, rectify it, erase it, restrict processing, object to processing, transfer data where applicable and withdraw consent at any time. You also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland.

# 12: What are cookies?

Cookies are small text files stored on your device when you use a website. Similar technologies may also be used to remember settings, maintain security, measure traffic and improve the website.

# 13: On what basis do we use cookies?

Essential cookies are used because they are necessary for the website to function. Analytical, marketing or optional cookies are used only where the applicable law allows it, including on the basis of your consent where required.

# 14: Can you disable cookies?

Yes. You can change cookie settings in your browser at any time. You may also delete cookies already stored on your device. Disabling some cookies may affect how the website works.

# 15: Why do we use our own cookies?

We use our own cookies to ensure correct website operation, remember basic settings, protect forms, maintain security and improve user experience.

# 16: What third-party cookies may be used?

The website may use third-party tools connected with analytics, embedded media, maps, social media, security, forms or performance optimisation. The exact set of tools may change as the website develops.

# 17: Do we track your behaviour on the website?

We may analyse aggregated information about website visits, traffic sources and interaction with content. This helps us understand how the website is used and improve it. We do not use this information to identify you unnecessarily.

# 18: Do we show targeted advertising?

If targeted advertising tools are used, they are configured in line with applicable law and consent requirements. You can manage advertising and tracking settings through your browser, cookie settings and the privacy settings of external providers.

# 19: How can you manage your privacy?

You can manage privacy by changing browser cookie settings, withdrawing consents, contacting us about your rights, limiting the data you provide in forms and using privacy settings offered by external services.

# 20: What are server logs?

Server logs are technical records created automatically by the server. They may include IP address, request date and time, browser type, requested URL and information about errors. Logs are used for administration, diagnostics, security and statistical purposes.

# 21: Is there anything else you should know?

The website may contain links to external websites. We are not responsible for the privacy practices of those websites. Before using them, please review their privacy policies.

# 22: Can this Privacy Policy change?

Yes. The Privacy Policy may be updated if the website changes, new tools are introduced or legal requirements change. The current version is always published on this page.

Appendix 1 – purposes of personal data processing

Personal data may be processed for communication, handling applications and forms, organising festival activities, publishing and archiving festival information, website administration, analytics, security, legal compliance and the establishment, pursuit or defence of claims.

Appendix 2 – external tools

The website may use external tools such as hosting services, e-mail services, analytics tools, embedded media providers, map providers, social media integrations, form tools, security tools and content management plugins. Data processing by those providers is governed by their own terms and privacy policies.