Privacy Policy

Last updated: February 13, 2024

The Administrator of TheSecondStep.net takes the protection of personal data very seriously. We assure you that we make every effort to protect the personal data of Service Users. Therefore:

  • Our online forms are always encrypted, and our network is protected and monitored.
  • We never sell or transfer collected personal data to third-party institutions or individuals for commercial use.
  • The content of posts / conversations conducted through our Service cannot be disclosed to third parties without the explicit consent of their authors.
  • We have appointed a professional Data Protection Officer to ensure that our safeguards guarantee data protection at an appropriately high level.

Introduction

We understand that only clear information about how your personal data is handled will allow you to trust us and freely make use of what our Service offers. This document will help you understand the principles we follow, whether you use our services as an end user (visiting our pages, taking online courses, sending messages, or in any other way), or are actively involved as an E-Coach, volunteer, associate, or financial supporter.

We assure you that we want to protect and treat the personal data of our users appropriately. We publish this Privacy Policy to present our approach to this topic.

Data Controller

The controller of your personal data is DeoLink Association (hereinafter: DeoLink), with its registered office in Wisła. When we use the terms "we," "us," or "our," we refer to DeoLink and entities acting on its behalf.

If you have any questions about our privacy policy, please contact our specially appointed Data Protection Officer by email or by post:

Emilian KujawskiEmail: iod@deolink.orgPostal address:Data Protection OfficerDeoLinkMalinka 65D/2,43-460 Wisła, Poland

Table of Contents

  • What is personal data?
  • How do we collect your personal data?
  • What if you are 16 or under?
  • What information may we collect?
  • How and why do we use your data?
  • Who do we share your data with?
  • Links to third-party websites
  • How do we protect your data?
  • How long will we retain your data?
  • How does international transfer of personal data work?
  • What rights do you have regarding your personal data?
  • How to file a complaint or raise a concern
  • What are cookies?
  • What cookies do we use and for what purposes?
  • How can I control the use of cookies?
  • Can this Privacy Policy change?

What is personal data?

Generally speaking, personal data is any information that allows you to be identified as a unique natural person. More information about the categories of data we collect can be found in the section "What information may we collect?"

How do we collect your personal data?

We may collect and store your data…

1. …when you visit our website.You can browse our website without telling us who you are or disclosing information about yourself, such as your email address. Our servers may collect anonymous information (metadata) about your visit, such as the IP address and domain you used to access our site, the type of browser, the page you entered and exited from, any subpage within our site viewed from that IP address, and the country you are in. We use this data to monitor how our site is performing (e.g., number of visits, average time spent, pages viewed, etc.), as well as for operational purposes such as continuously improving our site.

2. …when you share your personal data with us directly.We may collect and store your data when you interact with us through this or other pages of the Service. This may happen when you…

  • …use the contact form on our website;
  • …register to receive one of our newsletters / emails;
  • …register for one of our online courses;
  • …send us a response, inquiry, or complaint;
  • …support our work financially;
  • …correspond with a member of our team.

3. …when you indirectly provide us with information about yourself.If you visit our social media profiles, e.g., on Facebook, WhatsApp, Instagram, or use YouTube, we may also read your personal data. The scope of such data depends on the privacy settings you have specified on each of those platforms. Changing current settings on external services requires you to refer to their respective privacy policies.

We may also obtain information about your visit to our website or subpage — for example, which subpages you viewed as you navigated — based on cookies. For more information on this, please go to the Cookies section of this Privacy Policy.

What if you are 16 or under?

If you are 16 or under, before providing us with any personal data — in particular if you wish to create a User Profile and use online courses — you must obtain the consent of your parent or legal guardian.

What information may we collect?

We collect only the information necessary to provide you with our services at an appropriate standard. The minimum data required to create a User Profile is: a first name (or nickname) and an email address. As certain services develop (e.g., group courses), we may ask for additional data such as: year of birth or age range, gender, reasons for your interest in a given topic or course, as well as any other personal information you voluntarily choose to share with us in a registration form or during the course.

Selected parts of the Service also allow you to have direct conversations (written or spoken) with our volunteers. The content of those conversations is outside our direct control and we are not responsible for their improper use. We recommend not sharing any personal data in those conversations. Any breach of this principle is entirely at the risk of the person disclosing their data and will never be grounds for any claims against the Data Controller.

Data protection law recognizes certain types of personal data as more sensitive. These are defined as 'special category' data and include information revealing racial or ethnic origin, religious and philosophical beliefs, political opinions and views, trade union membership, genetic or biometric data, health information, and data relating to sex life or sexual orientation.

Only on the basis of your explicit and voluntary consent may we collect special category personal data — that is, only if you yourself choose to tell us about your reflections and/or experiences. We guarantee that not providing special category data will in no case restrict your ability to use the Service.

How and why do we use your data?

Your personal data may be used for the following purposes:

Responding to requests: If you contact us with a question, we may use your personal data to respond to it.

Access to online courses: Your data is used to enable you to participate in online courses (first name and email address), and — if the course is group-based (always clearly indicated at registration) — data necessary for assignment to the appropriate group (first name, gender, age, region) or course supervisor.

Accessing and customizing our website: We may use your personal data to help you access our website and tailor content to your personal development needs.

Processing applications for involvement: We may process your personal data if you send us a résumé or CV in connection with a potential engagement with our work, in order to assess your qualifications and respond to you.

Transactional purposes: We will use your personal data to fulfill obligations arising from any agreements for goods or services you order from us or that we have agreed upon together (for example, participation in a training or conference).

Quality of service analysis: We may use your personal data to improve current and future ways of delivering our services. We may use the services of third-party providers for this purpose.

Fundraising or direct marketing: You will receive marketing communications from us only if you have given your consent. If you withdraw your consent and then re-subscribe to such communications, your most recent decision will be binding.

Processing donations: We operate on a non-profit basis. If you wish to support us, we will process your personal data to record one-time or recurring donations.

Administration: We may use your personal data to record and process your complaint, record a request not to receive further marketing communications, record the history of cooperation with volunteers, and for other necessary internal archiving purposes.

Protecting your vital interests: We may process your personal data when we have reason to believe there is a risk of serious harm to you or someone else.

Market research and surveys: We may invite you to participate in surveys or market research for the purposes of improving our website, fundraising, and strategic development of our services. Participation is always voluntary and we will not identify individual persons, except where we have obtained consent to do so.

Legal, regulatory, and tax compliance: We may use your personal data to fulfill obligations under applicable law.

Who do we share your data with?

We will use your data only for the purposes for which it was collected. We will never sell or transfer personal data to third parties or institutions. If you receive a marketing message suggesting we have given our consent or shared data, please contact us urgently.

We will transfer your personal data only for the following purposes:

External providers: It may be necessary to transfer your data to service providers or databases that help us provide our services, projects, or fundraising. Such providers will act solely on instructions received from us, are subject to verification before signing any cooperation agreement, and the contractual obligations include strict data protection conditions.

We currently have agreements in place with the following service providers:

  • Studio DR Sp. z o.o.
  • Salesforce.com, Inc.

Conference and meeting organization: To deliver offered services/events, required data may be transferred to contracted service providers such as venues/hotels or insurance companies.

Legal requirement: We will comply with requests to disclose data where required by law. For example, we may disclose your personal data to an authority for tax investigation purposes or to law enforcement agencies for the prevention or detection of crime. We may also share your data with emergency services if we have reason to believe there is a risk of serious harm to you or another person.

How do we use AI?

The online courses available in our Service use a tool that supports trainers' work, based on artificial intelligence solutions. This tool is used solely to analyze the content of communications within courses (in particular messages) in order to prepare suggestions and directions for further work for the trainer. Processing takes place using anonymized data and does not result in automated decision-making regarding users. The data is not used to train any AI models. The detailed principles governing the use of AI tools in The Second Step initiative, run by DeoLink Association, are described in a separate AI Policy, available at: https://deolink.org/ai-policy/

Links to third-party websites

Our website may contain links to other websites operated by third parties, such as other organizations, content providers, sponsors, or advertising organizations/companies. When you click a link or button directing you to an external site, you leave our website and are taken to sites outside our control. Our Privacy Policy therefore no longer applies there. You must read the Privacy Policy of the third-party website to find out how your personal data will be used there.

How do we protect your data?

To ensure the security of your personal data, we use appropriate technical and organizational measures. We restrict access to information to those who need to know it, and we ensure that our people are aware that this information must be used solely in accordance with this Privacy Policy and other procedures established to ensure the lawfulness of data processing.

We regularly review and update the permissions of those who may have access to the information we store, to ensure that data is processed only by trained staff, volunteers, or contractors.

Our online forms are always encrypted, and our network is protected and monitored.

Confidentiality and security are very important to us. The content of conversations conducted through the Service cannot be disclosed to third parties without the explicit consent of their authors, except where conversations are explicitly marked as public. Our employees and associates have been informed of this and have agreed to it. We also require you to maintain confidentiality. By using our Service, you agree not to publish or share the content of conversations held with our volunteers or other users without their explicit consent.

If you use your credit or debit card to send a donation, we securely pass your card details to our payment processing partners. We do not store this data on our site.

Nevertheless, you should be aware that there are risks associated with transmitting information over public networks (open hotspots) or using publicly accessible computers, and we cannot guarantee 100% security of data (including personal data) disclosed or transmitted via public networks or unencrypted connections.

How long will we retain your data?

Your personal data will be processed no longer than is necessary for the purposes for which it was collected, or until you explicitly withdraw your consent to its processing. If you cannot quickly locate the appropriate option to stop the processing of your personal data in one of our services, you can always write to iod@deolink.org and request deletion of your data from that specific service.

If you request that we stop processing your personal data for marketing purposes, in some cases we will need to add your data to a suppression file so that your request can be enforced.

With regard to personal data related to financial transactions, your data will be processed for as long as required by tax and accounting law (this may be up to six years from the date of the transaction).

How does international transfer of personal data work?

We make every effort to ensure that the personal data we collect is not transferred or processed outside the European Economic Area (EEA) — that is, to the greatest extent possible, it is processed within the scope of the GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

However, due to the global nature and interconnectedness of certain internet services, in specific cases we may use a provider located outside the EEA. You will be informed of such a situation each time before data processing begins. When selecting providers outside the EEA, we always verify the guarantees of appropriate safeguards provided during the processing of your personal data by the provider — for example, whether the provider is based in a country recognized as safe by an appropriate European Commission adequacy decision, or whether they apply the standard contractual clauses established by the Commission.

Full document link: https://deolink.org/transfer-of-data-to-third-countries/

What rights do you have regarding your personal data?

At any time you may exercise the right to access your personal data being processed by us (information about its scope and purposes of processing) and to correct any inaccuracies. You also have the right to ask us to delete your personal data or to restrict its processing. Our services — such as online courses and email subscriptions — allow you to easily exercise these rights directly. If a given service does not offer this functionality automatically, write to the Data Protection Officer (iod@deolink.org) and they will guide you through the process. Please also include any additional information related to previous communications with us that may help us locate your data.

Under data protection law, your request will be fulfilled no later than 1 month from receipt of your written request.

How to file a complaint or raise a concern

If you would like more information or have questions about this Privacy Policy, wish to file a formal complaint about our approach to data protection, or wish to raise a privacy concern, contact DeoLink at: iod@deolink.org or by post:

Data Protection OfficerDeoLinkMalinka 65D/243-460 Wisła, Poland

When you wish to file a complaint regarding our improper handling of your personal data, follow the complaints procedure. If you are not satisfied with the response received, raise your concern with the relevant supervisory authority:

Data Protection OfficerDeoLinkul. Malinka 65D/243-460 Wisła, Poland

and

President of the Personal Data Protection Officeul. Stawki 200-193 Warsawhttps://uodo.gov.pl/

What are cookies?

Cookies are small text files that are downloaded and stored on your device when you visit websites. Cookies are a widely used tool among website owners, used to provide you with a good browsing experience while giving owners information that can help them improve their sites.

When you visit our site, we may send a cookie to your computer and observe your visit. It works like an identification card, allowing our site to recognize you and retain information that may be relevant to your interaction with our site. A cookie allows us to observe your visit, helping us better understand how you use our site and allowing us to tailor it to better meet your needs.

What cookies do we use and for what purposes?

We have divided the cookies we use into two categories — functionality cookies and performance cookies. Each of these categories is described below, including details of specific cookies, although we may use additional or alternative cookies within each group.

Note that third parties (including, for example, advertising networks and providers of external services such as internet traffic analytics) may also use cookies that are outside our control. These cookies may be from the functionality or advertising cookie categories.

Functionality cookiesThese improve your experience of using the site by recognizing when you return, for example by remembering access preferences, system behavior preferences, etc.

Performance cookiesThese allow us to monitor and improve the performance of our site. For example, they enable visitor counting, identify traffic sources, and indicate the most popular parts of the site.

  1. Google Analytics.
  2. Matomo (Piwik).
  3. Facebook Pixel

How can I control the use of cookies?

Until you change the settings, most web browsers automatically accept cookies. If you want to restrict, block, or delete cookies set on websites, you can usually do so in your browser settings. These can typically be found in the "options" or "preferences" menu of your browser.

Note, however, that if you set your browser to block all cookies, you may not be able to access all parts of our Service. If you do not change your settings, our site will send cookies.

Can this Privacy Policy change?

We reserve the right to make changes or additions to this Privacy Policy. Any such changes will be published at www.thesecondstep.net under the "Privacy Policy" tab, and we therefore recommend visiting our website regularly and monitoring current terms of use. Changes do not affect our core principle: we do not share the personal data of our users with third parties or institutions.

Thank you for reading our Privacy Policy.Have a great day!

The TheSecondStep.net Team