1. Data controller and contact
The controller of personal data processed in connection with the website at warsawglitch.com and the events held under the WARSAW GLITCH brand is Warsaw Glitch LLC, the organiser of WARSAW GLITCH (the “Controller”, “Administrator” or “Warsaw Glitch”). The co-organiser of selected programme elements is Fundacja Akcelerator Plus, ul. Królowej Aldony 17, 03-928 Warsaw; where it independently or jointly determines the purposes and means of processing for a given element, processing is carried out on the basis of separate arrangements, of which data subjects are informed to the necessary extent.
This Policy was prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Polish Personal Data Protection Act of 10 May 2018, the Electronic Communications Law of 12 July 2024 and other applicable provisions of Polish and EU law. It covers visitors to the website, persons contacting the Administrator, newsletter subscribers, buyers and participants, persons using Google sign-in, persons submitting films or projects, creators, industry and media representatives, partners, sponsors, speakers, jurors, volunteers and persons present during events.
In all matters concerning the processing of personal data, the exercise of GDPR rights, cookies, marketing communications or data security you can contact the Administrator at contact@warsawglitch.com, with “Privacy” or “Data Protection” in the subject line. The Administrator has not appointed a Data Protection Officer; the address above serves as the contact point for data-protection matters.
2. Categories of data we may process
Depending on how you use the website or take part in an event, the Administrator may process the following categories of data:
- identification data: first name, surname, professional pseudonym, company or institution name, role, professional profile, profile image, participant ID, submission ID or order number;
- contact data: e-mail address, phone number, correspondence or billing address, preferred contact channel;
- website-usage data: IP address, connection date and time, requested resource, device, operating system, browser, language settings, approximate location derived from the IP address, session identifiers, security logs and error messages;
- authentication data: a limited set of data provided by Google during Google sign-in, in particular first name, e-mail, profile picture and a technical account identifier, only to the extent shared by the user and necessary for authentication;
- transaction and billing data: purchased product or pass type, price, currency, discount, payment status, transaction ID, customer or order ID, data required to issue an accounting document, and refund, cancellation or complaint history;
- participation data: type of accreditation or ticket, attendance and entry confirmation, sign-ups for workshops, panels, the gala, industry events or restricted-access zones, and voluntarily provided organisational needs (e.g. accessibility or dietary requirements);
- correspondence data: the content of messages, submissions, attachments and information provided in the contact form or in direct e-mail communication;
- newsletter data: e-mail address, optionally first name, communication preferences, date and method of sign-up, source, proof of granting or withdrawing consent and technical anti-abuse information;
- film/project submission data: data of the submitter and creators, contact data, title, description, genre, running time, country of production, subtitles, posters, stills, biographies, press materials, trailers, links to materials submitted for review, declarations of rights, selection-related communication and submission status;
- professional-cooperation data: contact data of representatives of partners, sponsors, media, schools, industry entities, speakers, jury, experts, suppliers and other collaborators, and data needed to perform arrangements, contracts, settlements and accreditation;
- image and voice: photographs, video or audio recordings made during events, panels, workshops, screenings, the gala, industry meetings, networking zones and other festival activities;
- confidential-materials access data: e-mail address, represented organisation, access code, time and result of the authorisation attempt, security logs and information needed to protect confidential partner or media materials.
Please do not provide special categories of data (e.g. data on health, political views, religion, origin, sexual orientation or biometric data) unless an organisational process expressly requires it and a separate basis and information are provided.
3. Sources of data
Data is obtained primarily directly from the data subject, in particular through the website, forms, e-mail, registration, purchase, the newsletter, a film or project submission and during an event. In specific situations data may be obtained from Google sign-in, the payment operator Stripe, the FilmFreeway platform, an entity making a submission or purchase on behalf of a participant, an institutional partner, a school, an employer or another person authorised to register, submit or accredit. Where data is received from a third party, the Administrator provides the information required under Art. 14 GDPR where that obligation applies.
For professional contacts (e.g. industry, media, partners, speakers and jurors), data may also be obtained from publicly available professional sources, such as professional networks (e.g. LinkedIn) and official websites, and from business partners, only to the extent relevant to cooperation with the Festival.
4. Purposes and legal bases for processing
The Administrator processes data only where there is an appropriate legal basis:
- performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR): handling ticket, pass, package, product and service purchases, registration and accreditation, providing access to a stated digital service, running an account, responding to cooperation enquiries, handling film/project submissions, delivering the festival programme, contacting creators and handling complaints, refunds and order changes;
- legal obligation (Art. 6(1)(c) GDPR): tax, accounting, reporting, consumer-protection and security obligations, disclosure to authorised bodies and data-protection duties;
- legitimate interests of the Administrator (Art. 6(1)(f) GDPR): running and protecting the website and events, IT security, fraud and abuse prevention, establishing and defending claims, organisational continuity, protecting confidential materials, managing partner and media relations, documenting and archiving the festival, transparent information about submitted and selected works and their creators, promotion of current and future editions, and limited technical analysis needed to run the website;
- consent (Art. 6(1)(a) GDPR): the newsletter, optional cookies and similar technologies, and any case where separate consent is required for a specific use of an image or material. Consent may be withdrawn at any time without affecting the lawfulness of earlier processing.
Special-category data is processed only where an additional basis under Art. 9(2) GDPR applies. Providing data required to conclude or perform a contract is voluntary but necessary; without it, a purchase, registration, submission, accreditation, reply or other requested service may be impossible. Providing newsletter data or accepting optional cookies is voluntary.
5. Recording and use of image, voice and statements at events
WARSAW GLITCH may take photographs and make video and audio recordings during events, screenings, panels, workshops, the gala, industry meetings, networking zones, partner activations and other festival activities. Such materials may capture image, voice, statements and other information recorded in the natural course of the event, for the purpose of documenting and reporting on the event, informing about its programme and results, creating press and archival materials, communicating the Festival’s activities and promoting current and future editions of WARSAW GLITCH, without territorial limits, including over the Internet.
For a participant who buys a ticket, registers or uses accreditation, acceptance of the Ticket Terms or the participation terms, confirmed by actively ticking the relevant box during purchase or registration, or by entering the event area on the basis of a valid entitlement, constitutes a free-of-charge permission to disseminate their image, voice and statements recorded during the event, in the scope described in the Terms (see Terms § on image), pursuant to Art. 81(1) of the Polish Act on Copyright and Related Rights. The permission covers only materials connected with WARSAW GLITCH and does not transfer any rights to the image, nor consent to its use by third parties for their independent advertising, save for action on behalf of or commissioned by the Administrator for the purposes stated above.
Personal data captured in event materials is processed in principle on the basis of Art. 6(1)(f) GDPR (legitimate interest in documenting, informing about and promoting the Festival), and where a separate consent is required under the GDPR or image-dissemination rules, on the basis of that consent. Where a person is merely a detail of a whole (e.g. a gathering or a public event), their image may be disseminated within the limits of Art. 81(2)(2) of the Act on Copyright and Related Rights, without separate permission. A person who is the main, individually recognisable subject of a separately produced promotional material (e.g. a speaker, juror, performer, ambassador, special guest) may be covered by a separate agreement or consent.
6. Specific processing operations
Website, logs and security, to deliver content, maintain sessions, detect errors and protect against attacks, abuse and unauthorised access (Art. 6(1)(f), and Art. 6(1)(b) for service-necessary data). Contact form and correspondence, to handle and respond to your matter; sending a form is not consent to marketing. Google sign-in, the Administrator receives only the data shared during authorisation; Google remains an independent controller of data processed in its own service.
Purchases, Stripe payments and settlement, payments for tickets, packages, products or other services may be handled by Stripe. The Administrator does not receive or store full payment-card data; it may receive payment status, transaction ID, purchase type, amount, currency, customer ID, e-mail, billing data and data needed for refunds, complaints and accounting. Stripe processes data as a payment-service provider and, for its own security, fraud-prevention and regulatory-compliance duties, as a separate controller. Newsletter, sent after prior consent under the GDPR and Art. 398 of the Electronic Communications Law; consent may be withdrawn at any time via the unsubscribe link or by contacting the Administrator.
Film and project submissions, submissions may be received via FilmFreeway or another stated channel; FilmFreeway runs its own service and processing. After receiving submission data the Administrator is an independent controller processing it for organising WARSAW GLITCH. Submitted materials may be screened, including by third-party and AI-based tools, for compliance with copyright and the submission rules. Confidential partner/media materials, data needed to grant and authenticate access, protect trade secrets, detect unauthorised use and keep an access log.
Public information about submitted works and creative teams, in connection with a submission the Administrator may process and publish, in the website, programme, catalogues, press materials, social channels and archives, data identifying the submission and its creators (e.g. title, year and country of production, category, submission/selection/award status, the name or stated artistic pseudonym of the submitter, director, producer and crew, their creative roles, the representing entity, description, biography, press materials and stills). For the submitter the basis is Art. 6(1)(b) GDPR; for other crew members, Art. 6(1)(f) GDPR (proper attribution, programme presentation and transparent results). Only data necessary for these purposes is published; contact details, ID documents, private addresses and billing data are not published without separate consent or a legal obligation.
Security monitoring and AI services, the venue and the Organiser may use security monitoring (CCTV) at entrances and common areas of the event for the safety of people and property; such recordings are kept for a short period and accessed only for security purposes, unless needed longer in connection with an incident or claim. Where AI-based or third-party services support the event (e.g. networking, recaps, summaries or personalisation), the providers act as processors under contract and may not use the data to train their own models or for their own marketing.
7. Recipients of data
Data may be shared only as necessary with: authorised members of the Administrator’s team, collaborators, programmers, producers, jurors, selectors and volunteers bound by confidentiality; providers of IT infrastructure, hosting, cloud, databases, security, e-mail, forms, registration, newsletter, access control and technical support; Stripe (payments); Google (Google sign-in); FilmFreeway (submissions handled there); providers of accounting, legal, audit, insurance, banking, logistics, printing, production, security and courier services; institutions and partners co-delivering a programme element, only where necessary; and authorised public authorities, courts and law-enforcement bodies where required by law or necessary to establish, pursue or defend claims. The Administrator does not sell personal data and does not share it with sponsors or partners for their own marketing without a separate, explicit legal basis.
When the Organiser runs its own social-media channels and campaigns, the operators of those platforms (e.g. Meta, Instagram, YouTube, LinkedIn, X, TikTok) may process related data under their own policies as independent or joint controllers; the Organiser uses them only for the Festival's communication.
8. International data transfers
Some technology, payment, authentication or communication providers may process data outside the European Economic Area, including in the United States, or use sub-processors located outside the EEA. In such cases the Administrator applies the safeguards required by Chapter V of the GDPR, in particular a European Commission adequacy decision, the Commission’s standard contractual clauses, binding corporate rules, the EU-US Data Privacy Framework where applicable, or another mechanism permitted by the GDPR, together with supplementary measures where required. Information on the safeguards applied can be obtained from the Administrator.
9. Data retention
Data is kept no longer than necessary for the purposes for which it was collected, unless longer retention follows from the law or is necessary to establish, pursue or defend claims. As a rule: contact-form data, up to 24 months from closing the matter; newsletter data, until consent is withdrawn (limited proof of consent kept until claims are time-barred); purchase, payment, invoice, refund and complaint data, for the period required by tax and accounting law, generally at least five years, plus the time needed to defend claims; account and sign-in data, for the period of active access plus the time needed to close the account and handle claims; technical and security logs, generally up to 12 months; confidential-materials access data, up to 12 months from the end of access; film/project submission data, for the duration of the call, selection and edition, then five years for archival, reporting and claim-defence purposes (screening materials of non-selected projects are deleted or made inaccessible after selection, no later than 24 months); speaker, partner, media, juror and collaborator data, for the period of cooperation plus documentation and settlement; event photographs and recordings, for the period justified by documentation and the festival archive, subject to the right to object and to withdraw consent where applicable.
10. Your rights
Where the GDPR applies, you have the right to: access your data and obtain a copy; rectify inaccurate and complete incomplete data; erase data where Art. 17 GDPR applies; restrict processing; port data where processing is based on consent or a contract and is automated; object to processing based on legitimate interest, including direct marketing; withdraw consent at any time without affecting earlier processing; lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw); and not be subject to a decision based solely on automated processing producing legal or similarly significant effects.
To exercise these rights, write to contact@warsawglitch.com. The Administrator may ask for information reasonably needed to confirm your identity, and responds without undue delay, generally within one month (extendable under the GDPR). Some rights may be limited by law, in particular tax/accounting duties, the need to establish, pursue or defend claims, and freedom of expression and information. The Administrator does not take decisions producing legal or similarly significant effects solely by automated means; programme and organisational decisions are made by people.
11. Security, cookies and children
The Administrator applies appropriate technical and organisational measures (role-based access, authentication, encrypted connections, security monitoring, backups, incident procedures and confidentiality obligations). No method of transmission or storage is completely secure. A personal-data breach will be handled as required by law, including notifying the supervisory authority and data subjects where the breach may cause a high risk to their rights. Cookies and similar technologies are described in the Cookie Policy. The website is not intended for the independent provision of personal data by children under 16 for consent-based purposes; such consent is valid only if given or approved by a parent or guardian.
12. Changes and contact
The Administrator may update this Policy as the law, technology, the website, providers or organisational processes evolve. The current version is published on the website with its effective date; material changes will be signalled appropriately. In matters not regulated here, the GDPR, Polish law and applicable EU law apply. Detailed terms of purchase, image permission, participation and submissions are also set out in the Terms & Conditions. Contact for privacy matters: contact@warsawglitch.com.










