General information.
This Privacy Policy concerns the Warsaw Glitch event and governs the protection of the personal data provided by Users of the warsawglitch.com website and of the other information obtained through the use of the website. This Privacy Policy sets out, among other things, the rules and the scope of our processing of your personal data, the rights available to you and our obligations as the data Controller.
Information clause on the processing of personal data.
- 1.On the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”), we set out below basic information on how we obtain and process personal data.
- 2.Controller
Your personal data are processed by the data Controller, that is:
GLITCH GROUP sp. z o.o., with its registered office in Warsaw (03-984), ul. Gen. Romana Abrahama 12/47, entered in the register of entrepreneurs kept by the District Court for the Capital City of Warsaw in Warsaw, Commercial Division of the National Court Register, under KRS number 0001259140, tax identification number (NIP) 1133209188.
More information on the rules for processing personal data is available in Chapter VI of the Event Terms and Conditions: https://warsawglitch.com/terms#dane-i-wizerunek
- 3.Purposes and legal bases for processing personal data
We will process your personal data on the following bases:
- 1.Article 6(1)(b) GDPR – in order to organise the event, and in particular to register Event participants (including speakers);
- 2.Article 6(1)(c) GDPR – in order to comply with legal obligations arising from, among others, tax rules, payroll and HR rules, accounting legislation (the Accounting Act) and archiving rules;
- 3.Article 6(1)(f) GDPR in conjunction with Article 399(1) of the Act of 12 July 2024, Electronic Communications Law (Journal of Laws 2024.1221, as amended), that is, where information is stored on or accessed from a terminal device (as regards data in the form of cookies) and this is necessary for the website to work or display correctly, to maintain sessions and to provide other functionalities (functional cookies);
- 4.Article 6(1)(a) GDPR in conjunction with Article 399(1) of the Act of 12 July 2024, Electronic Communications Law (Journal of Laws 2024.1221, as amended), that is, where you have consented to the storage of marketing or statistical information, or to access to information already stored on a terminal device (as regards data in the form of marketing or statistical cookies or cookies relating to individual users' preferences);
- 5.Article 6(1)(f) GDPR – in order to pursue our legitimate interest consisting in direct marketing of our products and services;
- 6.Article 6(1)(a) GDPR in conjunction with Article 398 of the Act of 12 July 2024, Electronic Communications Law (Journal of Laws 2024.1221, as amended) – where you have consented to receive information about the current activities undertaken as part of the tasks of GLITCH GROUP sp. z o.o.;
- 7.Article 6(1)(f) GDPR – in order to pursue our legitimate interest consisting in the possible establishment, exercise or defence of claims and the pursuit of our rights;
- 8.Article 6(1)(a) GDPR in conjunction with Article 81(1) of the Act of 4 February 1994 on Copyright and Related Rights – in order to process your image.
- 4.Recipients of personal data
The recipients of your personal data may be:
- 1.the competent authorities or third parties who request such information on an appropriate legal basis and in accordance with applicable law;
- 2.entities cooperating with us in performing the contract, where the categories of such recipients may include, for example, IT service providers, including entities operating the system that enables registration for the Event or for the Competition held as part of the Event, and entities handling Ticket sales, providers of postal or courier services, providers of legal advice and debt collection services, as well as our Partners, Main Partners, Strategic Partners, Content Partners, Prize Providers, members of the Assessment Committee and of the Competition Jury;
- 3.social media operators, online news portals, radio and television broadcasters;
- 5.How long we will process your personal data
Your personal data will be processed for the period necessary to achieve the processing purposes indicated in point 2:
- 1.as regards performance of the contract, until it ends, after which personal data will be processed for the period required by law for us to fulfil our legal obligations or for the period necessary to pursue, establish or defend possible claims;
- 2.as regards the pursuit of our legitimate interests, personal data will be processed until an objection you raise to the processing is upheld;
- 3.where processing is based on consent you have given, personal data are processed until that consent is withdrawn. Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
- 6.Voluntary only
Providing your personal data is voluntary, but it is necessary in order to take part in the Event.
- 7.Your rights in connection with the processing of personal data
You may exercise your rights concerning personal data arising from the GDPR against each of us.
You have the right to:
- 1.request access to your personal data, including information about their processing (Article 15 GDPR);
- 2.have your data rectified or completed if they are inaccurate or incomplete (Article 16 GDPR);
- 3.request erasure of your data (the right to be forgotten) where there is no basis for processing them or where consent to their processing has been withdrawn (Article 17 GDPR);
- 4.request restriction of processing where the data are inaccurate or unnecessary, are processed without a legal basis, or where an objection has been raised to processing based on the controller's legitimate interest (Article 18 GDPR);
- 5.receive and transfer your personal data in a structured, commonly used format, in the case of data provided to the controller and processed on the basis of consent (Article 20 GDPR);
- 6.object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(f) GDPR. In that case we will no longer process your personal data for those purposes, unless there are compelling legitimate grounds for the processing which override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of claims;
- 7.object at any time to the processing of your personal data where they are processed for direct marketing purposes, in which case we will no longer process your personal data for those purposes;
- 8.lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority in Poland is the President of the Personal Data Protection Office (PUODO), ul. S. Moniuszki 1A, Warsaw;
- 9.withdraw consent to the processing of personal data where your personal data are processed on the basis of Article 6(1)(a) GDPR.
- 8.Transfers of data to third countries or international organisations
In our core personal data processing operations your data will not be processed outside the EEA. Your data may be processed outside the EEA (in the territory of the United States) only where the Gridaly application's technical support chat, based on the Intercom tool, is used. We note that Intercom is on the Data Privacy Framework (DPF) list, https://www.dataprivacyframework.gov/list, and that the basis for processing personal data outside the EEA is the implementing decision finding an adequate level of protection of personal data ensured by the EU-US Data Privacy Framework. Under that decision, the United States and the European Union have agreed on the possibility of data from the EEA being processed by entities established in the United States.
- 9.Profiling and automated decision-making
No decisions concerning your personal data will be taken by automated means within the meaning of Article 22 GDPR.
- 10.How to obtain information about the processing of data
All correspondence on matters connected with the processing of your personal data should be sent to: contact@warsawglitch.com
Google Analytics
The Controller uses statistical analysis of website traffic through Google Analytics (Google Inc., with its registered office in the USA). The Controller does not transfer personal data to the provider of that service, only anonymised information. The service relies on the use of cookies on the user's terminal device. As regards information about user preferences collected by the Google advertising network, users may review and edit the information arising from cookies using the tool at https://www.google.com/ads/preferences/
YouTube
Our website contains a plugin for the YouTube portal, which connects you directly with our WARSAW GLITCH YouTube channel. YouTube may obtain the information that you have visited our website from your IP address. We wish to stress that YouTube does not provide us with information about the data it collects or how it is used. For further information on privacy on the YouTube portal we suggest contacting the service directly or reading the portal's privacy policy at https://policies.google.com/privacy. The operator of the YouTube portal is Google Ireland Limited.
Hotjar
The Controller uses analysis of website traffic through the Hotjar tool (Hotjar Limited). The tool works by collecting data on how visitors interact with individual elements of the website, from tracking cursor movements to analysing clicks and scrolling. More information is available at https://www.hotjar.com/legal/policies/privacy/
Stripe
The Controller uses a tracking cookie used by Stripe for basic functions such as fraud detection, payment processing and analysis of users' interactions with the website. These cookies are a standard part of online transactions and help ensure security and functionality. More information is available at https://stripe.com/en-pl/cookie-settings.
Data protection measures applied by the Controller.
The places where you log in and transfer personal data are protected at the transmission layer (SSL certificate). As a result, your personal data and the login details entered on the website are encrypted on the user's computer and can be read only on the destination server.
Changes to the Privacy Policy
In order to provide you with the highest possible level of personal data protection, adapted to changing legislation, we reserve the right to change the content of this Privacy Policy.
Categories of data we may process
Depending on how you use the website or take part in an event, the Administrator may process the following categories of data:
- identification data: first name, surname, professional pseudonym, company or institution name, role, professional profile, profile image, participant ID, submission ID or order number;
- contact data: e-mail address, phone number, correspondence or billing address, preferred contact channel;
- website-usage data: IP address, connection date and time, requested resource, device, operating system, browser, language settings, approximate location derived from the IP address, session identifiers, security logs and error messages;
- authentication data: a limited set of data provided by Google during Google sign-in, in particular first name, e-mail, profile picture and a technical account identifier, only to the extent shared by the user and necessary for authentication;
- transaction and billing data: purchased product or pass type, price, currency, discount, payment status, transaction ID, customer or order ID, data required to issue an accounting document, and refund, cancellation or complaint history;
- participation data: type of accreditation or ticket, attendance and entry confirmation, sign-ups for workshops, panels, the gala, industry events or restricted-access zones, and voluntarily provided organisational needs (e.g. accessibility or dietary requirements);
- correspondence data: the content of messages, submissions, attachments and information provided in the contact form or in direct e-mail communication;
- newsletter data: e-mail address, optionally first name, communication preferences, date and method of sign-up, source, proof of granting or withdrawing consent and technical anti-abuse information;
- film/project submission data: data of the submitter and creators, contact data, title, description, genre, running time, country of production, subtitles, posters, stills, biographies, press materials, trailers, links to materials submitted for review, declarations of rights, selection-related communication and submission status;
- professional-cooperation data: contact data of representatives of partners, sponsors, media, schools, industry entities, speakers, jury, experts, suppliers and other collaborators, and data needed to perform arrangements, contracts, settlements and accreditation;
- image and voice: photographs, video or audio recordings made during events, panels, workshops, screenings, the gala, industry meetings, networking zones and other festival activities;
- confidential-materials access data: e-mail address, represented organisation, access code, time and result of the authorisation attempt, security logs and information needed to protect confidential partner or media materials.
Please do not provide special categories of data (e.g. data on health, political views, religion, origin, sexual orientation or biometric data) unless an organisational process expressly requires it and a separate basis and information are provided.
Sources of data
Data is obtained primarily directly from the data subject, in particular through the website, forms, e-mail, registration, purchase, the newsletter, a film or project submission and during an event. In specific situations data may be obtained from Google sign-in, the payment operator Stripe, the FilmFreeway platform, an entity making a submission or purchase on behalf of a participant, an institutional partner, a school, an employer or another person authorised to register, submit or accredit. Where data is received from a third party, the Administrator provides the information required under Art. 14 GDPR where that obligation applies.
For professional contacts (e.g. industry, media, partners, speakers and jurors), data may also be obtained from publicly available professional sources, such as professional networks (e.g. LinkedIn) and official websites, and from business partners, only to the extent relevant to cooperation with the Festival.
Recording and use of image, voice and statements at events
WARSAW GLITCH may take photographs and make video and audio recordings during events, screenings, panels, workshops, the gala, industry meetings, networking zones, partner activations and other festival activities. Such materials may capture image, voice, statements and other information recorded in the natural course of the event, for the purpose of documenting and reporting on the event, informing about its programme and results, creating press and archival materials, communicating the Festival’s activities and promoting current and future editions of WARSAW GLITCH, without territorial limits, including over the Internet.
For a participant who buys a ticket, registers or uses accreditation, acceptance of the Ticket Terms or the participation terms, confirmed by actively ticking the relevant box during purchase or registration, or by entering the event area on the basis of a valid entitlement, constitutes a free-of-charge permission to disseminate their image, voice and statements recorded during the event, in the scope described in the Terms (see Terms § on image), pursuant to Art. 81(1) of the Polish Act on Copyright and Related Rights. The permission covers only materials connected with WARSAW GLITCH and does not transfer any rights to the image, nor consent to its use by third parties for their independent advertising, save for action on behalf of or commissioned by the Administrator for the purposes stated above.
Personal data captured in event materials is processed in principle on the basis of Art. 6(1)(f) GDPR (legitimate interest in documenting, informing about and promoting the Festival), and where a separate consent is required under the GDPR or image-dissemination rules, on the basis of that consent. Where a person is merely a detail of a whole (e.g. a gathering or a public event), their image may be disseminated within the limits of Art. 81(2)(2) of the Act on Copyright and Related Rights, without separate permission. A person who is the main, individually recognisable subject of a separately produced promotional material (e.g. a speaker, juror, performer, ambassador, special guest) may be covered by a separate agreement or consent.
Specific processing operations
Website, logs and security, to deliver content, maintain sessions, detect errors and protect against attacks, abuse and unauthorised access (Art. 6(1)(f), and Art. 6(1)(b) for service-necessary data). Contact form and correspondence, to handle and respond to your matter; sending a form is not consent to marketing. Google sign-in, the Administrator receives only the data shared during authorisation; Google remains an independent controller of data processed in its own service.
Purchases, Stripe payments and settlement, payments for tickets, packages, products or other services may be handled by Stripe. The Administrator does not receive or store full payment-card data; it may receive payment status, transaction ID, purchase type, amount, currency, customer ID, e-mail, billing data and data needed for refunds, complaints and accounting. Stripe processes data as a payment-service provider and, for its own security, fraud-prevention and regulatory-compliance duties, as a separate controller. Newsletter, sent after prior consent under the GDPR and Art. 398 of the Electronic Communications Law; consent may be withdrawn at any time via the unsubscribe link or by contacting the Administrator.
Film and project submissions, submissions may be received via FilmFreeway or another stated channel; FilmFreeway runs its own service and processing. After receiving submission data the Administrator is an independent controller processing it for organising WARSAW GLITCH. Submitted materials may be screened, including by third-party and AI-based tools, for compliance with copyright and the submission rules. Confidential partner/media materials, data needed to grant and authenticate access, protect trade secrets, detect unauthorised use and keep an access log.
Public information about submitted works and creative teams, in connection with a submission the Administrator may process and publish, in the website, programme, catalogues, press materials, social channels and archives, data identifying the submission and its creators (e.g. title, year and country of production, category, submission/selection/award status, the name or stated artistic pseudonym of the submitter, director, producer and crew, their creative roles, the representing entity, description, biography, press materials and stills). For the submitter the basis is Art. 6(1)(b) GDPR; for other crew members, Art. 6(1)(f) GDPR (proper attribution, programme presentation and transparent results). Only data necessary for these purposes is published; contact details, ID documents, private addresses and billing data are not published without separate consent or a legal obligation.
Security monitoring and AI services, the venue and the Organiser may use security monitoring (CCTV) at entrances and common areas of the event for the safety of people and property; such recordings are kept for a short period and accessed only for security purposes, unless needed longer in connection with an incident or claim. Where AI-based or third-party services support the event (e.g. networking, recaps, summaries or personalisation), the providers act as processors under contract and may not use the data to train their own models or for their own marketing.
Security, cookies and children
The Administrator applies appropriate technical and organisational measures (role-based access, authentication, encrypted connections, security monitoring, backups, incident procedures and confidentiality obligations). No method of transmission or storage is completely secure. A personal-data breach will be handled as required by law, including notifying the supervisory authority and data subjects where the breach may cause a high risk to their rights. Cookies and similar technologies are described in the Cookie Policy. The website is not intended for the independent provision of personal data by children under 16 for consent-based purposes; such consent is valid only if given or approved by a parent or guardian.




















