Table of Contents
In accordance with the requirements of Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the GDPR), we hereby provide information regarding the processing of personal data at the University of Zielona Góra (hereinafter: the University). The University operates in accordance with the GDPR and protects the rights of EU citizens, whilst striving to ensure the protection of individuals whose data is processed in connection with the data controller’s activities or the provision of services to them within the EU.
The data controller, as defined by the GDPR, is the entity that determines the purposes and means of processing personal data. The data controller is the University of Zielona Góra, with its registered office at 9 Licealna Street, Zielona Góra. You may contact a representative of the data controller in writing at the address of its registered office. The Controller has appointed a Data Protection Officer, whom you may contact regarding matters of personal data protection by email atIOD@adm.uz.zgora.pl or by post (writing to the Controller’s registered office address).
The Data Controller processes personal data in both electronic and paper form and implements appropriate procedures (e.g. when making backup copies) to ensure confidentiality, integrity and availability. The University of Zielona Góra, hereinafter referred to as the University, employs the necessary measures and tools to protect personal data against unauthorised use, access, disclosure and alteration.
The data controller guarantees to data subjects whose data it processes the rights set out in the GDPR. Depending on the basis for data processing, these may include the rights to:
Most of these rights are not absolute. Below you will find detailed explanations of the rights to which you are entitled and information on how to exercise them. If a request is made to exercise a specific right, the Controller will respond within one month; however, if necessary, we reserve the right to extend this period by a further two months. If the response time is extended, the Controller will notify you of this within one month of receiving the request. You may exercise your rights by contacting us via the contact details provided above. If you have any questions regarding the processing of personal data or wish to exercise your rights under the GDPR, please contact a representative of the Controller using the contact details provided at the beginning of this document, stating your full name and residential address or other contact address. In the event of any doubt regarding the identity of the person contacting the Data Controller, you may be required to provide additional information or to present proof of identity.
In justified cases, it is advisable to contact the persons who collect personal data on behalf of the Data Controller (e.g. via forms). In connection with the specific activities of the University’s units, the Data Controller endeavours (wherever possible) to provide, in the relevant information notices, the addresses or telephone numbers of the appropriate contact persons for data subjects wishing to exercise their rights.
Every data subject also has the statutory right to lodge a complaint with the supervisory authority responsible for the protection of personal data in the Member State of their habitual residence, place of work or the place where the alleged infringement occurred. In Poland, this authority is the President of the Personal Data Protection Office (PUODO), with its registered office at ul. Stawki 2, 00-193 Warsaw.
The personal data provided to the University during the admissions process is necessary for the performance of a task carried out in the public interest (which is to be understood as establishing and making available the conditions, procedures and information regarding the start dates of the admissions process at a public university). This data is also required to conduct and complete the admissions process. The applicable provisions are: Article 6(1)(e) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) in conjunction with Article 70 of the Act on Higher Education and Science.
A successful outcome of the admissions process means that the personal data provided earlier will continue to be necessary for the University of Zielona Góra for the purposes of:
Such processing will be necessary to fulfil the legal obligations incumbent on the controller (pursuant to the Act of 20 July 2018 on Higher Education and Science and the Regulation of the Minister of Science and Higher Education of 27 September 2018 on studies).
Refusal to provide personal data will result in you being unable to enrol and commence your studies. The applicable provisions are: Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) in conjunction with Article 49(2), Article 258, Article 342(4), Article 344, Article 345, Article 347 and Article 352 of the Act on Higher Education and Science, and Section 6 of the Regulation of the Ministry of Science and Higher Education of 27 September 2018 on studies.
Personal data provided to the University may be used to prepare and conclude a contract involving the data subject, the subject matter of which will be the mutual rights and obligations of the University and the student (in accordance with Article 6(1)(b)). In such a case (e.g. where a student is participating in an international exchange programme), the student’s data will be processed until the end of the limitation period for claims relating to the performance of that contract and, for example, the use of services available at the University of Zielona Góra.
The recipients of the student’s data will be public institutions (authorities or bodies) authorised to obtain the data under applicable legislation, as well as persons acting on behalf of those institutions. During your studies (i.e. once you have enrolled), recipients will also include bodies assessing study programmes, auditors and institutions supervising the implementation of projects (if you take part in them), as well as organisations representing students or PhD students. Any organisation involved in organising work placements or internships will receive the necessary information about the student. The data of a student participating in international exchange programmes will also be provided to the host university abroad. Recipients of the data may include entities cooperating with the data controller that provide IT, legal, insurance and financial services on its behalf.
Student and graduate data is not disclosed to third parties who simply cite the need for profiling or employment agency services as justification. The data controller does not consider scans and declarations sent to it by ordinary email to be reliable if they are not signed using the trust tools provided for under European and Polish national law. A student may request the University to issue a certificate and confirm official facts known to the University. They may also do so electronically (e.g. using the ePUAP platform, a Trusted Profile, a qualified electronic signature and similar tools) and may specify the address of the recipient of such a certificate; the University, after verifying the student’s identity, may then provide information about the student to the specified recipient.
The personal data of foreign nationals studying at the University of Zielona Góra on fee-paying courses may be made available to scholarship providers as well as to authorised authorities and representative bodies of their country of origin.
If a student’s data is to be transferred to entities in third countries (outside the EU) or to international organisations, this will take place provided that there is an appropriate legal instrument confirming an adequate level of protection, such as a decision by the European Commission. The student also has the right to receive a copy of their personal data being transferred to a third country.
An applicant taking part in the admissions process loses the right to request the erasure of their data because, from the start of the admissions process, the aforementioned legal obligations and interests of the Data Controller will apply, which will require the Data Controller to process the applicant’s personal data – for example, for archiving or accounting purposes.
Applicants taking part in the admissions process should also be aware that:
The data controller is authorised under the law to process the personal data of natural persons who enter into a contract with it (for the purpose of preparing such a contract for conclusion and performance) in accordance with Article 6(1)(b) of the GDPR. Processing may also relate to a contract in which personal data is merely included (e.g. personal data of a business representative, details of the contact person specified in the contract, details of persons with whom the terms of the contract are agreed, etc.). Such data is received from other parties to contracts concluded with the data controller – usually from the employers of the data subject concerned. This means that the University of Zielona Góra also receives data on individuals who are not parties to the contract but whose data is required to draw up the contract, for example, with the entity employing that person or with the entity that the person represents. This will generally consist of basic data revealing the first name, surname, position or job responsibilities, scope of authority (e.g. power of attorney) and contact details (email address, telephone number and postal address of the place of work). This is necessary to maintain contact in connection with the contract and may reveal the role of the individual concerned in the performance of the contract.
The data controller endeavours to minimise the scope of data it collects, but where precise identification is required (and only where a natural person is a Party), not only basic data but also data identifying the individual, such as date of birth or PESEL number, may be processed (e.g. where necessary to pursue claims arising from signed obligations or contracts).
The basis for processing such personal data may therefore, as appropriate in a given situation, be the necessity to:
Where personal data is processed on a basis other than consent, there is no right to withdraw consent or to request the erasure of data (‘the right to be forgotten’), but the right to restrict processing, as well as most of the rights listed in the introduction, may apply. Before exercising these rights, it may be necessary to verify the identity of the person making such a request.
As a public university, the Controller is subject to various obligations relating to documentation, archiving, reporting and even the public disclosure of certain information. The University’s activities are monitored and are subject to audits and inspections by authorised institutions, which often involves providing such institutions with information (including personal data).
Personal data is processed by persons authorised in writing by the Data Controller (primarily staff) and only to the extent necessary as specified in the University’s internal regulations. Personal data may only be disclosed, in justified cases, to the Data Controller’s partners and subcontractors (law firms, advisers and auditors serving the University, as well as debt collection and IT companies) and their employees. This may occur when they provide services to the University that require access to the data.
Personal data is processed for the minimum period necessary to perform and settle the Contract. The data is then archived. Where a natural person is a Party to the contract, the period for which their data is processed is determined by tax legislation, the statute of limitations for claims and, in some cases, a contractual obligation of confidentiality (where the Parties are bound by such an agreement).
The data controller for data relating to the civil law contract being concluded is the University of Zielona Góra, with its registered office in Zielona Góra, ul. Licealna 9, 65-417 Zielona Góra; the data controller’s representative can be contacted via the contact form on the website: https://www.uz.zgora.pl/index.php?kontakt. The Controller has appointed a Data Protection Officer, who can be contacted at: iod@adm.uz.zgora.pl. If you have any questions regarding the processing of personal data, you may contact a representative of the Controller via the form on the website, providing your full name and residential address or other contact details; in the case of representatives, please specify the entity on whose behalf you are acting or have acted, in order to correctly identify the data subject and respond to your enquiry. In the event of any doubt regarding the identity of the person contacting the Controller, it may be necessary to provide additional information or to present proof of identity.
In connection with the conclusion of civil law contracts, in the vast majority of cases the Controller processes the following categories of data: identification data (first name, surname, where applicable the name of the company or entity that the natural person represents, role/position held, email address or telephone number). As regards persons representing a Party, also processes the PESEL number or identity document details or address details enabling the identification of the natural person as authorised to represent the Party. If a natural person is a Party to the Agreement, the settlement account number, tax identification number (NIP) or business registration number (REGON), and the address of the registered office or place of residence are also processed. Personal data will be processed for the purposes of concluding and performing the Agreement, making financial settlements, archiving documentation relating to the conclusion and performance of the Agreement, and handling any claims. Such data will not be subject to automated decision-making, including profiling.
The individual’s data will be processed on the basis of:
The Controller processes personal data that has been provided to it:
The Parties’ personal data may be transferred to or made available to entities authorised under the law, entities providing advisory and audit services, law firms, other entities in connection with the provision by such entities of support for the Controller’s day-to-day operations, software suppliers and maintenance providers, and companies providing postal or courier services. In each case, the scope of information disclosed to these entities will be proportionate and necessary to achieve the intended purposes. Personal data may also be transferred outside the European Economic Area in connection with the provision of IT services by these entities, as well as to third parties on the basis of a data processing agreement concluded with them, based on the so-called Standard Contractual Clauses. When using the services of the aforementioned third parties to whom we may disclose data, the Controller obliges these entities to maintain the security and confidentiality of the data and not to disclose it to unauthorised parties; these entities will comply with the relevant security standards to meet the requirements of the GDPR.
The data will be processed for the period necessary to perform the Contract and for the limitation period of claims arising from legal provisions applicable to the Controller, as this is necessary to fulfil the purposes arising from the Controller’s legitimate interests.
Data will be processed to demonstrate compliance with information obligations and to fulfil the obligation to retain records arising from applicable accounting regulations and the Tax Ordinance. As a general rule, this will be a period of 5 years, counted from the end of the calendar year in which the tax payment deadline expired.
Rights of data subjects – A data subject has the following rights in relation to their personal data, which apply depending on the circumstances: the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing. Most of these rights are not absolute. Below you will find detailed explanations of the rights to which you are entitled and information on how to exercise them. If a request is made to exercise a specific right, the Controller will respond within one month; however, if necessary, we have the right to extend this period by a further two months. If the response time is extended, the Controller will notify you of this within one month of receiving the request. You may exercise your rights by contacting us via the contact form provided above.
A data subject may ask the Controller whether their personal data is being processed. If so, that person has the right to request access to such personal data and information such as the purpose of processing, the categories of personal data being processed, the recipients or categories of recipients, the envisaged retention period for such data, if it is possible to specify it (or the criteria on the basis of which the data retention period is determined), the right to request the rectification or erasure of personal data or the restriction of its processing; the right to lodge a complaint with the relevant supervisory authorities; if the Controller has not received the data from the data subject, the data subject may request any available information regarding the source of the data. The data subject may also ask whether the Controller uses their data to make any automated decisions that may have legal effects or other significant consequences for that person.
The data subject may ask the Controller to rectify the data if it is inaccurate. Taking into account the purpose of the processing, they may also request that incomplete data be completed.
The data subject may object to the processing of their personal data on the basis of the Controller’s legitimate interests; the Controller shall take the objection into account and cease processing, unless:
The data subject may request the restriction of the processing of personal data in the following circumstances:
If a data subject’s request results in the restriction of the processing of their personal data, the Controller shall retain such data and process it only with the data subject’s consent; for the purpose of establishing, exercising or defending legal claims; for the purpose of protecting the rights of another natural or legal person; or in the substantial public interest of the European Union or a Member State.
The data subject whose personal data is processed by the Controller has the right to lodge a complaint with the supervisory authority responsible for the protection of personal data in the Member State of their habitual residence, their place of work or the place where the alleged infringement occurred. In Poland, this is the President of the Office for Personal Data Protection (PUODO).
The University of Zielona Góra (UZ), as the Data Controller, is also the organiser or co-organiser of conventions, academic conferences (including those for students), trade fairs, industry and sector-specific meetings, and similar events. The data controller organises various types of events promoting science, as well as events on social media and in traditional media (radio, television, press). Participants in such events are asked to provide identifying details and contact information. This privacy policy also aims to inform participants of such events about when and how their personal data is processed and what it is used for in practice.
When someone decides to take part in an event organised by the University of Zielona Góra, the participant’s personal data is collected. Typically, the scope of data includes, in particular, first name and surname, postal address, email address, telephone number and other contact details, affiliation or organisational membership, and possibly other details – such as specific dietary requirements or the need for other support from the organiser, accommodation details, information on payment methods and credit card details for hotel bookings, and so on – necessary for the preparation of the event. If an event participant does not enter into a contract with the Data Controller, the basis for data processing will be the participant’s consent (in accordance with Article 6(1)(a) of the GDPR).
If the relevant terms and conditions, registration rules or the very nature of the event (e.g. ticketed job fairs) do not allow it to be assumed that the provision of data is tantamount to consent to its processing, the Data Controller will request separate, additional consent for the processing of personal data for specific purposes.
The personal data of participants in individual events may also be shared with other co-organisers of the event in question, as academic institutions typically collaborate closely with one another in such activities.
Participants’ data may be used to register attendance, provide materials, and ensure ancillary services and services facilitating communication between participants (such data may be shared with providers of services such as email, instant messaging, etc.).
Participants’ likenesses and voices may be recorded in photographic and video materials and may be used on the organisers’ websites and in press reports. If an event participant does not wish to disclose their identity and does not consent to the use of such data, they should – before providing any personal information – confirm with the organiser’s representatives that they have the right to opt out of such data processing.
Participants’ data may also be made available to sponsors and may be used to present offers; however, as a general rule (unless the organiser states otherwise), this will be for the purposes of other data controllers. UZ stores and uses personal data:
Failure to provide the personal data necessary for the above purposes may result in the Data Controller being unable to carry out the activities described above, and it will not be possible to achieve objectives such as contacting a participant via a unique email address.
Personal data will be processed by UZ for the period necessary to fulfil the purposes set out above, after which it will be anonymised and destroyed or archived. The event organiser may approach participants with a proposal to retain their data necessary for future notifications, e.g. regarding subsequent editions of the event or similar events.
The data controller (UZ) does not disclose personal data to third parties for any purpose other than those set out here, and in particular to enable them to send unsolicited marketing materials. However, we may use and share non-identifiable data – pseudonymised, altered or aggregated information – for research, reporting or statistical purposes.
UZ does not disclose personal data to entities not involved in organising the event. If the event in which you are participating or intend to participate is located outside the European Union and it is necessary to provide data, the Data Controller will do everything in its power to ensure that this is done on the basis of appropriate legal instruments guaranteeing that the participant’s personal data will be protected to a standard no less stringent than that within the EU. The data controller reserves the right to state that participants may decide for themselves whether to provide their data to entities which are not obliged to comply with European law when processing data.
Access to personal data is restricted solely to those persons for whom such access is necessary in the course of their duties or to carry out a specific task.
As a general rule, the Data Controller accepts that data subjects may only provide their own data to it. Providing the Data Controller with another person’s personal data is permissible only if the person providing such data does so with the consent of the data subject . When providing another person’s data, reasonable measures should therefore be taken – for example, to inform the individuals whose data is being recorded of the principles set out in this policy.
IT systems and event websites may contain links to third-party websites. These other websites are not subject to this privacy policy or the Data Controller’s procedures. You should exercise extreme caution when using them and familiarise yourself with the terms and conditions and privacy policies available on those sites. The Data Controller does not generally endorse, approve or certify any services, nor does it recommend services or products offered on third-party websites – even if it refers to them in the course of its activities.
The University of Zielona Góra does not store customers’ credit or debit card details – to process payments relating to the University’s events, we use the services of an external provider, which ensures secure online payments and provides the appropriate tool to handle such transactions (an online portal).
At the University of Zielona Góra, particular attention is paid to establishing and maintaining good relations with entrepreneurs, industry and the business sector. The University actively establishes contacts with entrepreneurs, approaching them with proposals for research collaboration, to organise meetings and conferences, and to present opportunities for utilising the infrastructure available at the University. To this end, data is used which is obtained from publicly available sources, such as company websites and the public registers CEIDG and KRS. Some of the data comes from entrepreneurs when they enter into cooperation with the University – even if no agreement is concluded in this regard.
The scope of data in such cases includes, in particular, the company name (including the first name and surname in the case of sole traders), correspondence address, email address, telephone number and other data used for segmentation (such as the main PKD code and province). Such processing is necessary to fulfil the purposes arising from our legitimate interests and is in accordance with the grounds set out in Article 6 (1)(f) of the GDPR. The specific purposes of data processing in this case are:
The Data Controller is assisted in managing these communications by other entities that guarantee an appropriate level of data security. This cooperation essentially involves the handling, storage and management of email communications. Data is provided to them with due care and confidentiality, and only to the extent necessary for the technical handling of the communications.
Contact details are not disclosed to anyone for any purpose other than those set out above. We do not consent to the disclosure of data to any entities that might send unsolicited commercial communications. We endeavour to process data that does not reveal anyone’s identity (pseudonymised, altered, aggregated or otherwise processed) and only for research, reporting or statistical purposes.
The Data Controller operates in accordance with the GDPR, European law and Polish national law. Should the data subject receive an unsolicited message and not wish such processing to take place, they may restrict the Data Controller’s processing of their data by sending an email to:iod@adm.uz.zgora.pl . The Data Controller advises that verification of the data may be required before the request can be processed.
The University of Zielona Góra organises and co-organises numerous competitions, academic contests, rankings and similar events related to the University’s activities. The rules governing these events are usually set out in the relevant regulations. However, it is not possible to run them without processing data, even to a minimal extent.
The competition organiser will usually intend to publish the results and information about the winners – including online – using images of the winners or participants. Participants’ data will be made available to those involved in the competition procedures – including authorised staff of the University. This data may also be made available to staff of companies and institutions cooperating in the organisation of the competition – including on their websites. If such entities are also co-organisers of the competition, participants may usually receive separate information from them regarding data processing. Institutions and entities authorised to supervise the University’s activities may also become recipients of the data. Where justified, legally permissible and technically feasible, the Data Controller will endeavour to anonymise the data in such cases.
Entry into the competition, which involves providing one’s personal data, is, as a general rule, tantamount to confirming consent to the processing of personal data in connection with the competition (Article 6(1)(a) of the GDPR).
Competition documentation may subsequently be subject to archiving obligations based on general regulations applicable in higher education. This may lead to the disclosure of competition documentation to authorised persons and institutions, including information about the individuals selected as competition winners. Such processing will be necessary for the purposes arising from the legitimate interests pursued by the Data Controller (Article 6(1)(c) of the GDPR).
As part of the competition procedures, personal data will be processed from the time of collection until the end of the month following the month in which the competition results were announced.
If the details of the winners (those selected by the competition jury) are made public, they will be processed in this way indefinitely. They may remain publicly available until they are replaced by details of new winners, and may also be archived. The data controller reserves the right to archive competition entries, together with information about their authors, for the purpose of subsequent display, exhibition or publication in accordance with the copyright licences acquired. In the event of the publication of information or reports relating to the competition (in the press or on social media), personal data, together with the participant’s image, will be publicly available for as long as such reports are made available to their audience (depending on the medium).
In addition to the other rights listed in the introduction, as the basis for data processing is consent, the participant also has the associated right to withdraw their consent. To withdraw consent, please contact the Competition Organiser. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal, but may prevent the completion of competition procedures involving the participant who withdraws their consent. The provision of personal data is voluntary but necessary to enable participation in the competition procedures, and failure to give consent prevents participation in the competition (which is also voluntary by its very nature).
The University of Zielona Góra, as the Data Controller, processes personal data relating to minors – for example, in connection with enrolment for preparatory courses and activities designed to promote learning, which are carried out with the participation of children and young people. The data of such individuals is processed in order to organise and carry out recruitment or enrolment for classes, to enable eligible persons to take part in the classes, and to provide them with the associated benefits or services.
The University requires first names, surnames and contact details in order to be able to contact course participants – for example, regarding organisational matters – and to retain the ability to contact parents or guardians and, for instance, to inform them of their child’s situation where this is necessary to protect the child’s health or safety. Consent to the processing of personal data on behalf of minors may only be given by the participant’s parents or legal guardians.
In such cases, the recipients of personal data may include: organisations cooperating with the Data Controller – including sponsors, organisations funding projects carried out by the University, schools, local education authorities and educational institutions, accredited laboratories, and government bodies, etc. Participants’ data, as well as the data of their guardians and parents, may be made available to entities providing services to the University – such as IT or audit services.
Data relating to minors will be processed for a period dependent on the consent of their parents or guardians. The Data Controller will also delete such data immediately once the reason justifying its processing ceases to exist – for example, when a university preparatory course ends. If data retention is required by archiving regulations, such personal data will be retained for the period specified in those regulations.
Where necessary, the data controller will ask the parents or guardians of a minor to give separate, additional consent to the processing of their own data and that of their children.
Providing personal data for the purpose of receiving the University of Zielona Góra’s newsletters is voluntary; without such data, it would not be possible to deliver subsequent issues of the newsletters. The data is processed solely for the purpose of delivering the requested information to the email address provided. Providing your details as a newsletter subscriber is equivalent to giving your consent (in accordance with Article 6(1)(a) of the GDPR).
Subscription to the newsletter is voluntary and free of charge. You may remove your details from the database and unsubscribe at any time using the link provided in the newsletter.
The websites and IT systems managed by the Data Controller may contain links to third-party websites which are not subject to our privacy policy and procedures. This applies, amongst other things, to access to various resources and knowledge bases made available by the University of Zielona Góra or through it, on the basis of relevant licence agreements.
We cannot be held responsible for the privacy policies applicable to these websites, and this privacy policy applies only to the University of Zielona Góra’s websites.
The data controller does not advertise or endorse services or products offered by third parties. Nor does the data controller approve or certify the services provided by such third parties. It is recommended that, before using such services, you check them carefully and familiarise yourself with the relevant privacy policies and terms and conditions governing the provision of such services.
The University of Zielona Góra attaches great importance to respecting the privacy of users visiting its website (the term ‘website’ refers to the various web pages available under the .uz.zgora.pl domain). The website , operated by the University of Zielona Góra, collects information about users and their behaviour in the manner described below:
The University of Zielona Góra uses cookies. These files (known as ‘cookies’) constitute IT data, in particular text files, which are stored on the Website User’s end device and are intended for use when browsing websites. They usually contain the name of the website from which they originate, the duration for which they are stored on the end device, and a unique number.
The entity that places cookies on the Website User’s device and accesses them is the University of Zielona Góra. They are used for the following purposes:
The Website uses two main types of cookies: ‘session’ cookies and ‘persistent’ cookies. ‘Session’ cookies are temporary files that are stored on the User’s device until they log out, leave the website or close the software (web browser). ‘Persistent’ cookies are stored on the User’s device for the period specified in the cookie settings or until they are deleted by the User.
Web browsing software (a web browser) allows cookies to be stored on the User’s device. Users of the Website may change their settings in this regard. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject can be found in the web browser’s help section or documentation. Such information is available, for example, here:
Restrictions on the use of cookies may affect certain features available on the University of Zielona Góra’s website, for example, by limiting the ability to save settings or passwords. Disabling cookies that are essential for authentication, security and the retention of user preferences may hinder, and in extreme cases may prevent, the use of the websites.
Cookies placed on the Website User’s device may also be used by advertisers and partners cooperating with the Data Controller.
Cookies may be used by advertising networks, in particular the Google network, to display adverts tailored to the way in which the user uses the Website. To this end, they may store information about the user’s navigation path or the time spent on a given page.
Cookies help the University of Zielona Góra to compile statistics for the UZ.edu.pl portal.
We use cookies (such as: utma, utmb, utmc and utmz_) as well as geolocation data; that is, we check the location (e.g. continent or country) from which requests to our Website are received.
Our Website uses Google Tag Manager to manage the analytics codes embedded on the site. These are used to analyse user traffic on the site with a view to optimising it. Hotjar codes enable us to analyse anonymised user behaviour on the site. This allows us to optimise the site’s usability. The Facebook Pixel code we use is designed to measure the effectiveness of adverts based on an analysis of users’ actions on the Website.
Information about certain user behaviours on our Website is recorded at the server level. This data is used to administer the Website and to ensure the secure and most efficient provision of services.
The resources viewed are identified by their URLs. In addition, the following may be recorded:
the user accessed the Website via a relevant link,
The above data is not linked to specific individuals browsing the pages and is used solely for server administration purposes.
Data is disclosed to third parties solely within the limits permitted by law and for purposes specified by the University of Zielona Góra.
Before disclosing data that enables the identification of a natural person, the Data Controller obtains the consent of the data subject. When accessing the Data Controller’s website, you should familiarise yourself with the information regarding the data collected in connection with the use of the website and, if necessary, adjust your browser settings accordingly to meet your expectations.
The Data Controller may be obliged to provide information collected via its website to authorised bodies on the basis of lawful requests, to the extent specified in the request.
The Privacy Policy may be supplemented or updated in accordance with the Data Controller’s current needs in order to provide users with up-to-date and accurate information regarding their personal data and information about them.
The current version of the Privacy Policy is made available on an ongoing basis on the Data Controller’s relevant website.
