Privacy Policy

This Privacy Policy outlines the principles governing the processing and protection of personal data of individuals using the website and the registration system for the scientific conference (hereinafter referred to as the “Event” or “Conference”) available at the internet address https://nephrology-conference.fumed.pl.

§ 1. DATA CONTROLLER

The controller of your personal data is Fundacja dla Uniwersytetu Medycznego w Łodzi (Foundation for the Medical University of Lodz), a non-governmental organization with its registered office at: ul. gen. J. Hallera 1B (room 227), 90-647 Łódź, Poland, entered into the National Court Register (KRS) – Register of Associations, Other Social and Professional Organizations, Foundations and Public Healthcare Institutions, operating the website at: https://nephrology-conference.fumed.pl (hereinafter referred to as the “Controller”).

Controller Contact Details:
E-mail address: fumed@fumed.pl
Mailing address: Fundacja dla Uniwersytetu Medycznego w Łodzi, ul. gen. J. Hallera 1B (pok. 227), 90-647 Łódź, Poland

§ 2. PURPOSES AND LEGAL BASES OF DATA PROCESSING

Your personal data is processed for the following purposes, based on the specified legal grounds of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 24 April 2016):

  1. Registration and organization of the Conference participation: Conducting the participant registration process, verifying applications, preparing conference materials and badges, as well as organizational support and contacting the participant regarding the preparation and execution of the Event.
    Legal basis: Art. 6(1)(b) GDPR (necessity for the performance of a contract to participate in the Conference or to take steps at the request of the data subject prior to entering into a contract).
  2. Payment handling and billing processes: Verification and accounting of conference and registration fees, as well as issuing accounting documents (invoices).
    Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject, particularly in the field of tax and accounting law).
  3. Provision of electronic services: Enabling the use of the website’s functionalities, including the registration form, user profile (if applicable), and other digital tools provided on the page.
    Legal basis: Art. 6(1)(b) GDPR (necessity for the performance of a contract for the provision of services by electronic means).
  4. Marketing and website traffic analysis: Monitoring user activity on the website, optimizing website performance, and carrying out promotional and informational activities related to the Event.
    Legal basis: Art. 6(1)(a) GDPR (consent to the installation and use of optional cookies) and Art. 6(1)(f) GDPR (legitimate interest of the Controller consisting in conducting statistical analysis of website traffic).
  5. Establishment, exercise, or defense of legal claims: Safeguarding the legal interests of both the Controller and the participants.
    Legal basis: Art. 6(1)(f) GDPR (legitimate interest consisting in the establishment, exercise, or defense against potential legal claims).

§ 3. SCOPE OF PROCESSED DATA

Depending on your interaction with the website and the nature of your participation in the Conference, we process, in particular, the following data:

  • Participant registration data: first and last name, academic title/degree, represented institution / university / company, billing details (including Tax Identification Number/NIP, entity name, registered office address), e-mail address, phone number, mailing address.
  • Billing and payment data: bank account number, payment status, amount, date of credit.
  • Technical and operational data: IP address, approximate geolocation, browser type, operating system, time of visit, and behavior on the website (subpages visited, clicks).

§ 4. DATA RECIPIENTS

Participant data may be shared with the European Renal Association (ERA), scientific organiser of the course, for purposes related to the management of the educational activity and the fulfilment of legal and accreditation obligations.

Your personal data may be shared and transferred exclusively to trusted partners supporting the organization of the Conference on the basis of data processing agreements:

  • IT technology and infrastructure providers: entities providing server hosting services, IT system maintenance, registration system providers, and operators of tools used for sending e-mails and organizational notifications.
  • Financial and accounting services: accounting office and auditors responsible for processing payments and issuing invoices.
  • Electronic payment operators: banks or payment institutions handling and securing online transactions for tickets/registration.
  • Authorized bodies based on legal regulations: state authorities, tax offices, or courts, solely within the limits and on the basis of applicable laws.

The website uses the following third-party tools and plugins:

  • Google Analytics (Google LLC): statistics and website traffic analysis (based on voluntary cookie consent).
  • Meta Pixel / Facebook Pixel (Meta Platforms, Inc.): measuring ad effectiveness and conducting remarketing campaigns (based on voluntary cookie consent).
  • Google Maps (Google LLC): an interactive map to help locate the venue of the Conference.

§ 5. DATA TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)

Some of the analytical and marketing tools we use (including services by Google LLC and Meta Platforms, Inc.) are provided by entities based in the United States. Personal data transfers outside the EEA take place in compliance with the highest security standards, based on:

  • Standard Contractual Clauses (SCC) approved by the European Commission (Art. 46(2)(c) GDPR),
  • Adequacy decisions issued by the European Commission (including the “EU-U.S. Data Privacy Framework”), ensuring a level of protection for personal data equivalent to that in the European Union.

§ 6. DATA RETENTION PERIOD

Your personal data will be processed only for the time necessary to achieve the purposes for which it was collected:

  • Registration data and Conference participation: for the period necessary to conduct the Conference, settle accounts, summarize the Event, and distribute participation certificates, and thereafter until the expiry of the limitation period for claims arising from participation in the Event (typically 3 years).
  • Billing, tax, and accounting data: for a period of 5 years, counting from the end of the calendar year in which the tax payment deadline related to the conference fee expired.
  • System logs and analytical data (cookies): for the duration of their validity or until they are removed by the user from the browser, up to a maximum of 26 months.

§ 7. RIGHTS OF THE DATA SUBJECT

In connection with the processing of your personal data by the Controller, you have the following rights:

  • Right of access to your data and to receive a copy of it (Art. 15 GDPR).
  • Right to rectification (correction) of your data if it is inaccurate or incomplete (Art. 16 GDPR).
  • Right to erasure (“right to be forgotten”) in cases provided for by law (Art. 17 GDPR).
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability provided to the Controller in a machine-readable format (Art. 20 GDPR).
  • Right to object to the processing of data based on a legitimate interest (Art. 21 GDPR).
  • Right to withdraw consent at any time (to the extent that processing was based on consent), without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint with a supervisory authority – the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl), if you believe that the processing of your data violates the GDPR.

All requests and inquiries regarding the exercise of your rights should be directed to: fumed@fumed.pl. A response will be provided without undue delay, no later than within 30 days.

§ 8. DATA SECURITY

The Controller applies advanced technical and organizational security measures to prevent unauthorized access, modification, loss, damage, or destruction of participants’ personal data. To secure the transmission of data sent via the registration system, the website uses SSL/TLS protocol encryption (confirmed by the padlock icon in the browser address bar). Information systems and databases are protected against unauthorized access through strict access control procedures and network firewalls.

§ 9. CHANGES TO THE PRIVACY POLICY

The Controller reserves the right to make changes to this Privacy Policy, in particular in the event of changes to data protection laws, technological advancements, or modifications to the functionalities of the website. Information about significant changes to the Privacy Policy will be posted on the Event website or sent to registered participants via e-mail.

Ikona
Event date
16-17 October 2026
Ikona
Event venue
Hotel Ambasador Premium, Łódź