i.

Summary

A short, plain-language overview of what data this Website collects and how it is used. The detailed sections below cover each point in the form expected by data-protection authorities.

Data we collect automatically

Data we collect as you browse
  • Usage Data
  • System logs
Used for · Hosting · Content delivery · Security & maintenance

Data you give to us

Data you give us
  • Account & registration details
  • Abstract submissions
  • Contact & sponsor enquiries
Used for · Your account & registration · Abstract handling · Invoicing · Contacting you
ii.

Owner and Data Controller

Organiser / Account Holder

MEDCONGRESS GROUP SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ

Registered office:ul. Chmielna 2 / 31, 00-020 Warszawa, Poland
KRS:0001237036
REGON:544567895
NIP:5253087146
Owner contact email:info@iccsh2027.org

A Data Protection Officer has not been appointed, as the Owner is not required to designate one under Article 37 GDPR. For any matter relating to the protection of personal data — including the exercise of your rights — you may contact the Owner at info@iccsh2027.org.

iii.

Types of Data we collect

The Personal Data this Website collects depends on how you interact with it. The following is collected, by the Owner or through the processors listed in this policy:

Account

When you create an account: email address, password (stored only as a cryptographic hash, never in plain text), preferred language and email-confirmation status.

Congress registration

When you register for the Congress: title, first name, last name, email address, phone number, country, institution, specialization (e.g. Oncology, Urology, Sexual Medicine, Psycho-oncology, Gynecology), participant type, dietary requirements, any additional comments, fee category and selected add-ons. If you request a VAT invoice, also your billing details: company name, street, city, postal code, country and tax identification number (NIP / VAT).

Abstract submission

When you submit an abstract: title, body text, theme, keywords, comments, session type, presentation language and the list of authors. For each author: academic title, first name, last name, affiliation, email address, phone number and whether they are the presenting author.

Important: when you submit an abstract you provide the Personal Data of co-authors — that is, of other people (third parties). By submitting, you confirm that you are authorised to share their data with the Owner for the purposes of the Congress and that you have informed them of this processing, as required by Article 14 GDPR. The Owner processes co-authors' data on the basis of its legitimate interest in delivering the event with all listed authors (Article 6(1)(f) GDPR).

Abstract attachment: the PDF file you upload is stored on EU-based object storage (see Section vi) and is accessed only by the Owner and the scientific committee for the purpose of reviewing and, where accepted, publishing the abstract.

Contact form

When you use the contact form: your name, email address and the content of your message.

Sponsorship enquiry

When you submit a sponsorship enquiry: company / organisation name, contact person, email address, your message and, where provided, billing details for a VAT invoice.

Data collected automatically

When you visit the Website, technical Usage Data is processed automatically — for example IP address, browser and operating-system characteristics, the pages requested and the time of each request — together with system logs needed to operate and secure the Service. A single strictly-necessary session cookie is used to keep you signed in; it has no tracking purpose and requires no consent. This Website uses no analytics, advertising or tracking cookies and performs no profiling.

Unless a field is explicitly marked optional, the Data requested is necessary to provide the relevant service, and failure to provide it may make that service unavailable. Users who are unsure which Data is mandatory are welcome to contact the Owner.

iv.

Mode and place of processing the Data

Methods of processing

The Owner takes appropriate technical and organizational security measures (Article 32 GDPR) to prevent unauthorized access, disclosure, modification or destruction of the Data. Processing is carried out using computers and IT tools, following procedures strictly related to the purposes indicated. Besides the Owner, the Data may in some cases be accessible to persons involved in operating this Website (administration, the scientific committee, IT and system administration) or to external processors appointed by the Owner (such as hosting, storage and email providers). An updated list of these parties may be requested from the Owner at any time.

Place

Almost all Personal Data is processed and stored within the European Union / European Economic Area (EEA). The Owner relies on the following processors:

  • Vercel — frontend hosting and content delivery (EU region).
  • Railway — backend hosting and the PostgreSQL database (EU region).
  • Cloudflare R2 — storage of abstract attachments (EU region).
  • Zoho Mail (Zoho Corporation B.V.) — delivery of transactional email via Zoho's EU data centres.
  • Jakub Pożarycki (sole proprietorship) — development, maintenance and administration of the application (Poland).
  • Cloudflare Turnstile (Cloudflare, Inc.) — anti-bot verification on the account sign-up form; processes limited technical data (including IP address) on Cloudflare's global network.

Personal Data is stored within the EEA. Where a provider's parent company is established outside the EEA (for example a US-incorporated provider), the Data continues to be stored in EU data centres. The one service that may process limited technical data (including IP address) on a provider's global network is Cloudflare Turnstile, used for anti-bot verification on the sign-up form; that processing and any other transfer is safeguarded by Standard Contractual Clauses (Article 46 GDPR) and/or the EU–US Data Privacy Framework. Details of each provider, including a link to its own privacy policy, are set out in Section vi.

Payment data

Payments are handled by external providers — Stripe Payments Europe, Ltd. (Dublin, Ireland) and PayPro SA / Przelewy24 (Poznań, Poland). With respect to payment data, including card details, these providers act as independent data controllers, not as the Owner's processors; their own privacy policies govern that processing. The Owner never receives or stores card data — it receives only confirmation of whether a payment succeeded, together with the billing details you provide for invoicing.

Retention time

Unless specified otherwise in this document, Personal Data is processed and stored for as long as required by the purpose it was collected for, and may be retained longer where required by a legal obligation or based on the User's consent. The specific retention periods applied to each category of Data are set out in Section vi.

v.

The purposes of processing

Data concerning Users is processed to allow the Owner to provide its Service and comply with its legal obligations. The legal basis under Article 6(1) GDPR for each activity is as follows:

  • Account — creating and operating your user account — performance of a contract for the provision of electronic services (Article 6(1)(b) GDPR).
  • Congress registration — registering you for the Congress, including specialization and institution as part of providing the professional medical-registration service — performance of a contract (Article 6(1)(b) GDPR).
  • Abstract submission — receiving, reviewing and, where accepted, publishing your abstract — performance of a contract (Article 6(1)(b) GDPR).
  • Co-authors' data provided by the submitter — being able to deliver the event with the participation of the listed co-authors — legitimate interest (Article 6(1)(f) GDPR).
  • VAT invoices — issuing and retaining invoices — compliance with a legal obligation under tax law (the VAT Act and the Tax Ordinance) (Article 6(1)(c) GDPR).
  • Contact form — responding to your enquiry — legitimate interest (Article 6(1)(f) GDPR).
  • Transactional email — sending service messages such as account confirmation, registration received, abstract decisions and payment confirmation — performance of a contract (Article 6(1)(b) GDPR).

The Owner does not process Personal Data for marketing purposes and does not carry out profiling or automated decision-making.

vi.

Detailed information on the processing of Personal Data

The third-party providers this Website relies on, what each one processes, where it operates and a link to its own privacy policy. All operate within the EU / EEA, with the sole exception of Cloudflare Turnstile (anti-bot verification on the sign-up form), which may process limited technical data on Cloudflare's global network under appropriate safeguards — see "Security and anti-spam".

Hosting and infrastructure

These services host the Data and files needed for this Website to run, and provide the infrastructure on which it operates.

VercelFrontend hosting & CDN

Vercel hosts the frontend of this Website and delivers it through a content-delivery network, configured to use EU regions.

Personal Data processed: Usage Data
ProviderVercel, Inc.CountryEuropean Union (EU region) Privacy Policy
RailwayBackend & database

Railway hosts the backend application and the PostgreSQL database that stores account, registration and abstract Data, configured to use EU regions.

Personal Data processed: all Data you provide (account, registration, abstract, billing) · Usage Data
ProviderRailway CorporationCountryEuropean Union (EU region) Privacy Policy
Cloudflare R2File storage

Cloudflare R2 stores the PDF attachments uploaded with abstract submissions, configured to use EU jurisdiction.

Personal Data processed: abstract attachments (PDF)
ProviderCloudflare, Inc.CountryEuropean Union (EU jurisdiction) Privacy Policy

Security and anti-spam

To protect the account sign-up form against automated abuse (bots and spam accounts), the Website uses a privacy-preserving human-verification service.

Cloudflare TurnstileAnti-bot verification

Cloudflare Turnstile runs a human-verification check on the account sign-up form to block automated submissions. It does not use tracking cookies. Because Cloudflare operates a global network, limited technical data may be processed outside the EEA under the EU Standard Contractual Clauses (Article 46 GDPR) and Cloudflare's EU–US Data Privacy Framework certification.

Personal Data processed: IP address · technical interaction and browser signals used to tell humans from bots
ProviderCloudflare, Inc.CountryCloudflare global network (transfers safeguarded by SCC / EU–US DPF) Privacy Policy

Technical maintenance and data management

The Owner engages an external IT processor to develop, maintain and administer the application. This processor acts only on the Owner's documented instructions under a data-processing agreement (Article 28 GDPR).

Jakub PożaryckiIT maintenance & data management

Jakub Pożarycki, a sole trader operating under the business name Jakub Pożarycki, with registered office at ul. Bukszpanowa 2, Bezrzecze, Poland (NIP 8513262181, REGON 389487615), develops, maintains and administers this Website on behalf of the Owner. In the course of technical maintenance this processor may access Personal Data, acting solely on the Owner's documented instructions under a data-processing agreement (Article 28 GDPR).

Personal Data processed: all Data processed by the application, accessed only for technical maintenance
ProviderJakub Pożarycki, sole proprietorship — NIP 8513262181, REGON 389487615CountryPoland (Bezrzecze)

Contacting the User

Transactional emails — such as account confirmation, registration received, abstract decisions and payment confirmation — are sent through an email-delivery provider. There is no newsletter and no marketing email.

Zoho MailTransactional email

Delivers the Owner's transactional email through Zoho Mail's SMTP service; messages are routed through Zoho's EU data centres (smtp.zoho.eu).

Personal Data processed: email address · first name · last name
ProviderZoho Corporation B.V.CountryEuropean Union (Zoho EU data centre) Privacy Policy

Handling payments

Payments are processed by external providers acting as independent data controllers. The Owner does not receive or store card data; it only learns whether a payment succeeded.

Stripe Payments EuropePayments · Independent controller

Stripe processes card payments. With respect to payment data, Stripe acts as an independent data controller.

Personal Data processed: payment and card data provided directly to Stripe · email address
ProviderStripe Payments Europe, Ltd.CountryIreland (Dublin) Privacy Policy
Przelewy24 (PayPro SA)Payments · Independent controller

PayPro (Przelewy24) processes online payments and bank transfers. With respect to payment data, PayPro acts as an independent data controller.

Personal Data processed: payment data provided directly to PayPro
ProviderPayPro SACountryPoland (Poznań) Privacy Policy

Retention periods

Personal Data is kept only as long as necessary for the purpose it was collected for, or as required by law. The periods applied are:

Account data
until you delete the account, plus 1 year from your last activity.
Registration data
3 years after the Congress (limitation period for claims).
VAT invoices
5 years from the end of the tax year in which the invoice was issued (Article 70 of the Tax Ordinance).
Abstracts and attachments
until publication in the book of abstracts, plus 5 years of scientific archiving.
System logs
12 months.
Contact-form messages
1 year.
vii.

Further Information for Users in the European Union

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the following applies:

  • Users have given their consent for one or more specific purposes.
  • provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
  • processing is necessary for compliance with a legal obligation to which the Owner is subject;
  • processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
  • processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.

In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.

Further information about retention time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
  • Personal Data collected for the purposes of the Owner's legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.

The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority. Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

The rights of Users based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Owner.

In particular, Users have the right to do the following, to the extent permitted by law:

i.
Withdraw their consent at any time.

Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.

ii.
Object to processing of their Data.

Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.

iii.
Access their Data.

Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.

iv.
Verify and seek rectification.

Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.

v.
Restrict the processing of their Data.

Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.

vi.
Have their Personal Data deleted or otherwise removed.

Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner.

vii.
Receive their Data and have it transferred to another controller.

Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.

viii.
Lodge a complaint.

Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.

Users are also entitled to learn about the legal basis for Data transfers abroad including to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.

Details about the right to object to processing

Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.

Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users' request, the Owner will inform them about those recipients.

viii.

Further information for Users in Switzerland

This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.

Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the personal data, if any, the retention period and further information about Personal Data can be found in the section titled "Detailed information on the processing of Personal Data" within this document. the section titled "Detailed information on the processing of Personal Data" within this document.

The rights of Users according to the Swiss Federal Act on Data Protection

Users may exercise certain rights regarding their Data within the limits of law, including the following:

  • right of access to Personal Data;
  • right to object to the processing of their Personal Data (which also allows Users to demand that processing of Personal Data be restricted, Personal Data be deleted or destroyed, specific disclosures of Personal Data to third parties be prohibited);
  • right to receive their Personal Data and have it transferred to another controller (data portability);
  • right to ask for incorrect Personal Data to be corrected.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible, providing Users with the information required by law.

ix.

Additional information about Data collection and processing

Legal action

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Website or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.

Additional information about User's Personal Data

In addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.

System logs and maintenance

For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (System logs) or use other Personal Data (such as the IP Address) for this purpose.

Information not contained in this policy

More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document. contact us.

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Website and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom. Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.

x.

Definitions and legal references

Plain definitions for the legal terms used throughout this policy.

Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Website, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using this Website who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Owner of this Website.
This Website (or this Application)
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Website as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Strictly-necessary session cookie
A small technical cookie used solely to keep a signed-in User's session active. It is strictly necessary to provide the Service, has no tracking or analytics purpose and does not require consent. This Website uses no other cookies.
Work in Progress