This privacy policy describes how we process information about you, including personal data and cookies.

General information This policy applies to the Website, operating under the url: www.mosir.zgierz.pl The Operator of the Website and the Administrator of personal data is: Miejski Ośrodek Sportu i Rekreacji w Zgierz Wschodnia 2, 95-100, Zgierz E-mail contact address: operatora:biuro@mosir.zgierz.pl .The Operator is the Administrator of your personal data with regard to the data provided voluntarily on the Website. The Website uses your personal data for the following purposes: Running the newsletter Handling of enquiries via the form Handling of orders of goods – preparation, packaging, dispatch Fulfilment of ordered services Handling of relevant accounting documents Collection of receivables Presentation of an offer or information Performance by the Administrator of personal data of legally incumbent obligations in accordance with Article 6 (1) (c) RODO to the extent that this is provided for by special regulations (e.g. bookkeeping). The Service performs the functions of obtaining information about users and their behaviour in the following ways: Through the voluntary data entered in the forms, which are entered into the Operator’s systems. Through the storage of cookies (so-called “cookies”) in the end devices.

2. Selected data protection methods used by the Operator The sites for logging in and entering personal data are protected in the transmission layer (SSL certificate). This ensures that personal and login data entered on the website is encrypted on the user’s computer and can only be read on the target server. The personal data stored in the database are encrypted in such a way that only those holding the Operator key can read them. This protects the data in case the database is stolen from the server. User passwords are stored in hashed form. The hashing function works in a one-way fashion – it is not possible to reverse it, which is the current modern standard for storing user passwords. The Service uses two-factor authentication, which is an additional form of protection for logging into the Service. The Operator periodically changes its administrative passwords. In order to minimise the risk of unauthorised access to data, the Operator uses complex passwords containing upper and lower case letters, digits and special characters, no shorter than 8 characters.

Hosting The website is hosted (technically maintained) on the provider’s server: Euron

4. Your rights and additional information on how your data is used In order to comply with the obligations under data protection legislation and to ensure real data protection, the Operator has appointed a Data Protection Officer. The Data Protection Officer is: Witold Szczecińśki address: Wschodnia 2, 95-100, Zgierz contact elektroniczny:biuro@mosir.zgierz.pl .In certain situations the Administrator has the right to transfer your personal data to other recipients, if it is necessary to perform the agreement concluded with you or to fulfil the obligations incumbent on the Administrator. This applies to such groups of recipients: persons authorised by us, employees and co-employees who need to have access to your personal data in order to perform their duties, a hosting company, companies handling mailings, companies handling SMS messages, companies with which the Administrator cooperates on its own marketing, couriers, insurers, law firms and debt collectors, banks, payment operators, public authorities. Your personal data processed by the Administrator for no longer than it is necessary to perform the related activities defined by separate regulations (e.g. on accounting). With regard to marketing data, data will not be processed for longer than 3 years. You have the right to request from the Administrator: access to personal data concerning you, rectification, erasure, restriction of processing, and data portability. You have the right to object within the scope of the processing indicated in 3.3 c) to the processing of your personal data for the purpose of carrying out the legitimate interests pursued by the Administrator, including profiling, whereby the right to object will not be exercised if there are valid legitimate grounds for processing overriding your interests, rights and freedoms, in particular the establishment, assertion or defence of claims. You may complain about the Administrator’s actions to the President of the Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw. Providing personal data is voluntary, but necessary to operate the Service. Automated decision-making, including profiling for the purpose of providing services under a concluded agreement and for the purpose of direct marketing by the Administrator, may be undertaken in relation to you. Personal data is not transferred from third countries within the meaning of data protection legislation. This means that we do not send them outside the European Union.

5. Information in forms The Service collects information provided voluntarily by the user, including personal data if provided. The Service may record information about your connection parameters (timestamp, IP address). The service, in some cases, may record information to facilitate the linking of the data in the form with the e-mail address of the user completing the form. In this case, the user’s e-mail address appears inside the url of the page containing the form. The data provided in the form is processed for the purpose resulting from the function of the specific form, e.g. to carry out the process of service request or commercial contact, registration of services, etc. In each case, the context and description of the form clearly indicate what it is used for.

6. Administrator logs Information on user behaviour on the website may be subject to logging. This data is used for the administration of the website.

7. Relevant marketing techniques The operator uses statistical analysis of website traffic, via Google Analytics (Google Inc., based in the USA). The operator does not transmit personal data to the operator of this service, only anonymised information. The service is based on the use of cookies on the user’s terminal device. With regard to the information about the user’s preferences collected by the Google advertising network, the user can view and edit the information resulting from the cookies using the tool: https://www.google.com/ads/preferences/ The Operator uses remarketing techniques to match advertising messages with the user’s behaviour on the website, which may give the illusion that the user’s personal data is being used to track the user, but in practice no personal data is transferred from the Operator to the advertising operators. A technological prerequisite for such activities is that cookies are enabled. The Operator uses the Facebook pixel. This technology means that Facebook (Facebook Inc., USA) knows that a person registered with it is using the Website. The Operator does not transfer any additional personal data to Facebook. The service is based on the use of cookies on the user’s terminal device. The Operator uses a solution to study user behaviour by creating heat maps and recording behaviour on the website. This information is anonymised before it is sent to the service operator so that it does not know which individual it relates to. In particular, typed passwords and other personal data are not recorded. The Operator uses a solution that automates the operation of the Service in relation to users, e.g. it may send an e-mail to the user after visiting a specific subpage, provided that the user has agreed to receive commercial correspondence from the Operator. The Operator may apply profiling within the meaning of the data protection regulations

8 Information on cookies The Website uses cookies. Cookies (so-called “cookies”) are IT data, in particular text files, which are stored in the Service User’s terminal equipment and are intended for use on the Website. Cookies usually contain the name of the website from which they originate, the time of storing them on the terminal equipment and a unique number. The Service operator is the entity placing and accessing cookies on the Service User’s terminal equipment. Cookies are used for the following purposes: maintaining a session of the Website user (after logging in), thanks to which a user does not have to re-enter his/her login and password on each sub-page of the Website; realisation of the purposes specified above under “Important marketing techniques”; There are two basic types of cookies used within the Website: “session” cookies and “permanent” cookies (persistent cookies). “Session” cookies are temporary files that are stored on the User’s terminal equipment until the User logs out, leaves the website or switches off the software (web browser). “Permanent” cookies are stored on the User’s terminal device for the time specified in the parameters of the cookies or until they are deleted by the User. Web browsing software (web browser) usually allows the storage of cookies on the User’s terminal equipment by default. Users of the Website may change their settings in this respect. The Internet browser makes it possible to delete cookies. It is also possible to automatically block cookies Detailed information on this subject is contained in the help or documentation of the Internet browser. Restrictions on the use of cookies may affect some of the functionalities available on the Website. Cookies placed in the Service User’s terminal equipment may also be used by entities cooperating with the Service Operator, in particular companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. based in the USA).

cookie management – how to give and withdraw consent in practice? If you do not wish to receive cookies, you can change your browser settings. We would like to point out that disabling cookies that are essential for authentication processes, security, maintaining user preferences may make it more difficult, and in extreme cases may make it impossible, to use the websites In order to manage your cookie settings, select the web browser you are using from the list below and follow the instructions: Edge Internet Explorer Chrome Safari Firefox Opera Mobile devices: Android Safari (iOS) Windows Phone.