Last modified: 27 June 2026
Privacy Policy of Fundacja Nie Musi Boleć
I. General provisions
The personal data controller is Fundacja Nie Musi Boleć (It Doesn’t Have to Hurt Foundation), KRS: 0001117935, NIP: 9662195289, REGON: 529228080, registered office at ul. Zbigniewa Religi 4 lok. 04, 15-797 Białystok, Poland.
Controller contact details: email fundacja@niemusibolec.com, phone +48 790 277 795, website Foundation.niemusibolec.com.
Foundation representatives: Anna Maria Łotowska Ręczmień – President of the Foundation, country of birth: Poland, and Maciej Ręczmień – Vice President of the Foundation, country of birth: Poland.
This Policy sets out the rules for processing personal data of website users, donors, shop customers, event participants, volunteers, beneficiaries and people contacting the Foundation.
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the Polish Personal Data Protection Act and other applicable laws.
II. Purposes and legal bases of processing
Personal data is processed for the following purposes:
a) handling correspondence and responding to inquiries;
b) pursuing the Foundation’s statutory purposes;
c) handling donations and contact with donors;
d) handling shop orders, payments, complaints, refunds and access to digital products or events;
e) concluding and performing contracts and cooperation arrangements;
f) fulfilling tax, accounting and reporting obligations;
g) organizing events, projects, collections and Foundation initiatives;
h) operating the newsletter, if the user has consented to receive it;
i) ensuring proper website operation, website security and protection against abuse;
j) establishing, pursuing or defending claims.
The legal bases for processing are:
a) Article 6(1)(a) GDPR – consent of the data subject;
b) Article 6(1)(b) GDPR – performance of a contract or steps taken before entering into a contract;
c) Article 6(1)(c) GDPR – compliance with a legal obligation imposed on the Controller;
d) Article 6(1)(f) GDPR – the Controller’s legitimate interest, in particular communication, website security, development of statutory activities and securing claims.
III. Categories of data processed
The Foundation may process the following categories of data:
a) identification data, such as first and last name or entity name;
b) contact data, such as email address and phone number;
c) address and billing data;
d) data concerning donations, payments, orders, complaints and refunds;
e) data voluntarily provided in forms, messages or documents;
f) data resulting from correspondence and contact history;
g) data concerning participation in events, projects, training, workshops or Foundation initiatives;
h) technical data, such as IP address, cookie identifiers, device and browser information and website activity.
IV. Data recipients
Data may be transferred to entities cooperating with the Foundation, such as:
a) IT, hosting, email and technical administration service providers;
b) payment operators, banks and transaction service providers;
c) accounting office, legal and tax advisers;
d) providers of mailing services, forms, CRM systems, analytics and advertising tools;
e) entities supporting the organization of events, projects, collections and statutory activities of the Foundation;
f) other entities acting for the Foundation under data processing agreements or other appropriate legal bases.
Data may be transferred to public authorities only to the extent required by law.
The Foundation does not sell personal data and does not disclose it to other entities for marketing purposes unrelated to the Foundation’s activities.
V. Transfers of data outside the EEA
Data may be transferred outside the European Economic Area only where this is necessary to use tools supporting the Foundation’s activities and where the provider applies GDPR-compliant mechanisms, in particular standard contractual clauses, an adequacy decision or certifications such as the EU-U.S. Data Privacy Framework.
VI. Data retention period
Data is stored only for the time necessary to achieve the purpose of processing.
The retention period depends on the data category and may result from legal provisions. For example, accounting and tax documentation is stored for the period required by applicable regulations, generally for 5 years from the end of the tax year.
Data processed on the basis of consent is stored until consent is withdrawn, unless further storage is needed to demonstrate the correctness of the Foundation’s actions or to secure claims.
Data processed for correspondence purposes is stored for the time needed to handle the matter and then for the limitation period of possible claims.
VII. Rights of data subjects
Every person has the right to:
a) access their data;
b) rectify their data;
c) erase their data, also known as the right to be forgotten;
d) restrict processing;
e) data portability;
f) object to processing;
g) withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
h) lodge a complaint with the President of the Personal Data Protection Office in Poland.
To exercise these rights, contact the Foundation at fundacja@niemusibolec.com or by post at the Foundation’s registered office address.
VIII. Use of data for promotional activities of the Foundation
The user may consent to the use of their personal data for promotional and informational purposes of the Foundation, including targeting or displaying Foundation communications in advertising systems operated by Meta (Facebook, Instagram), Google and other platforms used by the Foundation.
Data will be used only as part of campaigns run by the Foundation to promote its statutory, educational, informational and fundraising activities and activities supporting the Foundation’s beneficiaries.
The Foundation does not sell, disclose or transfer personal data to external entities for marketing purposes unrelated to the Foundation’s activities.
Consent is voluntary and may be withdrawn at any time, without affecting the lawfulness of processing before withdrawal. If consent is withdrawn, data will no longer be used for consent-based advertising purposes.
IX. Cookies
The Foundation website uses cookies necessary for its proper operation, security, session handling, remembering settings, shop and cart operation, form handling and consent management.
With the user’s consent, the website may also use cookies and similar technologies for analytics, content personalization and promotional activities of the Foundation.
The user may change cookie settings at any time in their browser or in the consent mechanism available on the website, if such a mechanism is displayed.
X. Security measures
The Foundation applies organizational and technical measures ensuring compliance with GDPR, including server security, encrypted connections, access control, limiting the scope of processed data and cooperation with providers that declare the use of appropriate safeguards.
XI. Contact regarding personal data
In all matters related to personal data processing, you can contact the Controller by email at fundacja@niemusibolec.com or by post at the Foundation’s registered office address: ul. Zbigniewa Religi 4 lok. 04, 15-797 Białystok, Poland.
XII. Policy changes
This Policy may be updated as the website and Foundation activities develop, technical tools, payment operators, service providers or legal rules change. The latest version of the document is always published on this page.

