Privacy policy

1. General information
⦁ This policy applies to the website, which operates at the url: aidsuganda.org
⦁ The Operator is the Administrator of your personal data in relation to the data provided voluntarily in the Service.
⦁ The service uses personal data for the following purposes:
⦁ Running a commentary system
⦁ Enquiry handling by form
⦁ Presentation of an offer or information
⦁ The service performs the functions of obtaining information about users and their behaviour in the following way:
⦁ Through the data voluntarily entered in the forms, which are entered into the Operator’s systems.
⦁ By storing cookies (so-called “cookies”) on your terminal equipment.

2. Selected data protection methods used by the Operator
⦁ The places for logging in and entering personal data are protected in the transmission layer (SSL certificate). This ensures that the personal and login data entered on the website are encrypted on the user’s computer and can only be read on the target server.
⦁ User passwords are stored in a hashed form. The hash function works unidirectionally – it is not possible to reverse it, which is currently the modern standard for storing user passwords.
⦁ The Operator periodically changes its administrative passwords.
⦁ In order to protect the data, the Operator regularly makes backup copies.
⦁ An important element of data protection is the regular updating of any software used by the Operator to process personal data, which in particular means regular updates of programming components.

3. hosting
⦁ The service is hosted (technically maintained) on the operator’s server: hexcore.pl
⦁ Hosting company:
⦁ applies data loss protection measures (e.g. disk arrays, regular security copies),
⦁ apply appropriate measures to protect processing sites in the event of fire (e.g. special fire-fighting systems),
⦁ applies adequate measures to protect processing systems in the event of a sudden power failure (e.g. dual power lines, generators, UPS backup systems),
⦁ apply measures to physically protect access to data processing sites (e.g. access control, monitoring),
⦁ applies measures to ensure appropriate environmental conditions for servers as part of a data processing system (e.g. environmental conditions control, specialised air-conditioning systems),
⦁ applies organisational arrangements to ensure the highest possible degree of protection and confidentiality (training, internal regulations, password policies, etc.),
⦁ has appointed a Data Protection Officer.
⦁ The hosting company keeps logs at the server level to ensure technical reliability. Logs may be saved:
⦁ resources defined by the URL identifier (addresses of requested resources – pages, files),
⦁ time for the inquiry to arrive,
⦁ time to send the answer,
⦁ client station name – identification implemented by the HTTP protocol,
⦁ information on errors that occurred during the execution of HTTP transactions,
⦁ the URL of the page previously visited by the user (referer link) – in the case where the access to the Service was made via a link,
⦁ information about your browser,
⦁ IP address information,
⦁ Diagnostic information related to the process of self-ordering services through recorders on the website,
⦁ information related to the handling of electronic mail addressed to and sent by the Operator.

4. your rights and additional information on the use of your data
⦁ In some situations, the Administrator has the right to transfer your personal data to other recipients if it is necessary to perform the contract concluded with you or to fulfil the Administrator’s obligations. This applies to such groups of recipients:
⦁ hosting company on a trust basis
⦁ authorised employees and associates who use the data in order to achieve the purpose of the website
⦁ Your personal data is processed by the Administrator no longer than it is necessary to perform the related activities specified in separate regulations (e.g. on accounting). With regard to marketing data, the data will not be processed for more than 3 years.
⦁ You have the right to demand from the Administrator:
⦁ access to your personal information,
⦁ their corrigenda,
⦁ deletions,
⦁ processing restrictions,
⦁ and data transfer.
⦁ You have the right to object to the processing of personal data indicated in point 3.3 c) to the processing of personal data in order to exercise the legitimate interests pursued by the Administrator, including profiling, but the right of objection will not be exercised if there are important legitimate grounds for processing, interests, rights and freedoms overriding your interests, in particular to establish, pursue or defend your claims.
⦁ Providing personal data is voluntary, but necessary to operate the Service.
⦁ You may be subject to automated decision making activities, including profiling, in order to provide services under the contract and to conduct direct marketing by the Administrator.
⦁ Personal data is not transferred from third countries within the meaning of data protection regulations. This means that we do not send them outside the European Union.

5. information in the forms
⦁ The service collects information voluntarily provided by the user, including personal data, if any.
⦁ The service can save information about the connection parameters (time stamp, IP address).
⦁ The service, in some cases, may save information to facilitate linking the data in the form to the e-mail address of the user filling in the form. In this case, the user’s e-mail address appears inside the url of the page containing the form.
⦁ The data provided in the form are processed for the purpose resulting from the function of a particular form, e.g. to handle a service request or business contact, register services, etc. Each time the context and description of the form clearly indicate what it is used for.

6. Administrators’ logs
⦁ Information about user behavior on the site may be subject to login. This data is used to administer the service.

7. Important marketing techniques
⦁ The operator uses statistical analysis of website traffic through Google Analytics. The operator does not pass on personal data to the operator of this service, but only anonymised information. The service is based on the use of cookies on your terminal equipment.
⦁ The Operator uses remarketing techniques that allow for matching advertising messages with the user’s behaviour on the website, which may give the illusion that the user’s personal data is used to track the user, but in practice there is no transfer of any personal data from the Operator to the advertising operators. The technological condition for such actions is that cookies are enabled.
⦁ The operator uses a solution that investigates user behaviour by creating heat maps and recording behaviour on the website. This information is anonymised before it is sent to the service provider so that he does not know which individual it concerns. In particular, passwords and other personal data are not recorded.

8. information about cookies
⦁ The website uses cookies.
⦁ Cookie files (so-called “cookies”) are IT data, in particular text files, which are stored in the final device of the Service User and are designed to use the Website’s websites. Cookies usually contain the name of the website from which they come, the time they are stored on the terminal equipment and a unique number.
⦁ Subject placing cookies on the end device of the Service User and obtaining access to them is the Operator of the Service.
⦁ The cookies are used for the following purposes:
⦁ maintaining the Service user session (after logging in), thanks to which the user does not have to re-enter his login and password on each subpage of the Service;
⦁ the achievement of the objectives set out above under “Relevant marketing techniques”;
⦁ The Service uses two basic types of cookies: “session” cookies (session cookies) and “permanent” (persistent cookies). Session” cookies are temporary files, which are stored in the user’s terminal device until logging out, leaving the website or turning off the software (web browser). “Persistent” cookies are stored in the User’s terminal equipment for the time specified in the parameters of cookies or until they are deleted by the User.
⦁ Software for web browsing (web browser) usually by default allows to store cookies in the user’s terminal device. Service users can change their settings in this area. Internet browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject is contained in the help or documentation of the Internet browser.
⦁ Restrictions on the use of cookies may affect some features available on the Website.
⦁ Cookies placed in the final device of the Website User may also be used by entities cooperating with the operator of the Website, in particular companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. based in the USA).

9. Cookie management – how to give and withdraw consent in practice?
⦁ If you do not want to receive cookies, you can change your browser settings. We reserve the right to disable the use of cookies necessary for authentication processes, security, maintenance of user preferences may make it difficult, and in extreme cases may prevent the use of websites