Privacy Policy
Table of contents
- 1. Introduction and scope
- 2. Definitions
- 3. Data Controller & contact details
- 4. Purposes & legal basis of processing
- 5. Categories of personal data
- 6. Retention periods
- 7. Your rights under GDPR
- 8. Recipients of personal data
- 9. Transfers to third countries (Schrems II)
- 10. Automated decisions & profiling
- 11. Cookies & similar technologies
- 12. Processing for marketing purposes
- 13. Security of personal data
- 14. Data breach notification
- 15. Lodging a complaint (UODO)
- 16. Changes to this privacy policy
- 17. Contact & print version
§ 1 Introduction and scope
This Privacy Policy sets out the rules for processing of personal data by the InfoBOS UAM web platform operated by the Student Service Offices (Biura Obsługi Studentów) of Adam Mickiewicz University in Poznań, and complies with the following legislation:
- EU LAW Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation — GDPR / RODO).
- PL LAW Polish Act of 10 May 2018 on the protection of personal data (Journal of Laws 2023 item 1208).
- PL LAW Polish Act of 18 July 2002 on the provision of services by electronic means (Journal of Laws 2024 item 471).
- COOKIES Polish Telecommunications Law (Journal of Laws 2024 item 521) & ePrivacy rules, consistent with the CJEU Planet 49 judgment (C-673/17) and UODO Cookie Guidelines of September 2024.
The policy applies to every visitor, registered user, and person who contacts us through the platform.
This Privacy Policy fulfils the information obligation under Article 13 GDPR towards platform users, people using the contact form, and people receiving marketing communications related to the activities of the Student Service Offices of Adam Mickiewicz University in Poznań.
§ 2 Definitions
- Administrator / Controller
- Adam Mickiewicz University in Poznań, represented by the Rector, with its registered office at ul. Henryka Wieniawskiego 1, 61-712 Poznań — the entity deciding on the purposes and means of processing personal data on the InfoBOS UAM FAQ platform.
- Personal Data
- Any information relating to an identified or identifiable natural person; in particular name, e-mail address, student number, telephone number, IP address.
- RODO / GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- UODO
- The Polish data protection authority — President of the Office for the Protection of Personal Data (Prezes Urzędu Ochrony Danych Osobowych).
- Cookie
- A small text file stored on the user's device by the web server, used to recognise the device on subsequent visits.
- Processor
- An entity which processes personal data on behalf of the Controller (e.g. hosting provider, e-mail server operator) under a written data processing agreement (DPA / art. 28 GDPR).
§ 3 Data Controller & contact details
Controller details
- Name
- Adam Mickiewicz University in Poznań, represented by the Rector
- Registered office / address for service
- ul. Henryka Wieniawskiego 1, Collegium Minus, 61-712 Poznań, Poland
- Identification numbers
- NIP: 7770006350, REGON: 000001293 (as a public university, Adam Mickiewicz University is not entered in the KRS)
- Platform contact e-mail
- infobos@amu.edu.pl
- Contact phone
- +48 61 829 21 43 (Student Service Office) or +48 61 829 43 08 (Adam Mickiewicz University Rector's Office)
Data Protection Officer (IOD / DPO)
- iod@amu.edu.pl
- Scope
- All matters related to the processing of personal data and the exercise of the rights of data subjects.
§ 4 Purposes & legal basis of processing
Every single processing activity has an explicit purpose and a legal basis from article 6(1) of the GDPR. We never process data "just in case".
| Purpose of processing | Legal basis | Categories of data | Retention period | Whether providing data is required and consequences of not providing it |
|---|---|---|---|---|
| Maintenance of administrative accounts (panel administrators, editors of FAQ content) |
GDPR art. 6(1)(b) performance of a contract — employment/commission GDPR art. 6(1)(c) legal obligation (archiving, tax law — 6 years) |
name, surname, job title, institutional e-mail, password (bcrypt hash), authentication logs, permissions | Duration of the authorisation + 6 years after revocation for accounting/archival purposes | Providing the data is necessary to perform the employment/commission contract and official duties involving FAQ system administration. Without it, we cannot create the account or provide access to the administration panel. |
| Handling contact form enquiries, requests and reports |
GDPR art. 6(1)(a) consent (if required) GDPR art. 6(1)(f) legitimate interest — answer the enquiry |
name, e-mail, telephone (if voluntarily provided), contents of the message | 3 years from the end of the correspondence (statute of limitations period) | Providing the data is voluntary but necessary to answer your enquiry. Without contact details, answering may be impossible or more difficult. |
| InfoBOS chatbot operation & knowledge base improvement | GDPR art. 6(1)(f) legitimate interest — improving the quality of public services | anonymous contents of unanswered questions only (answered questions are never saved); NO personal identifiers requested | Max. 90 days — then automatically deleted or fully anonymised | Providing the data, including the enquiry content, is voluntary. Where processing is based on legitimate interest, you may object; see § 7. |
| Security monitoring & incident response (access logs, rate limiting, brute-force protection) | GDPR art. 6(1)(f) legitimate interest — security of IT systems and networks | IP address (pseudonymised), User-Agent, login attempts timestamps, CSRF tokens | 12 months — then rotated and deleted | Processing technical data follows our legitimate interest in securing UAM IT systems and networks. Without it, we cannot ensure secure use of the platform. |
| Internal statistical analytics (clickstream, anonymous sessions) | GDPR art. 6(1)(a) explicit, opt-in consent (strictly required — cookie banner button "Accept") | fully anonymised session hash, pages visited, timestamp; NO IP or personal identifiers | 24 months from collection — then automatically aggregated and anonymised further | Consent to analytics cookies is entirely voluntary. Refusing it does not affect access to InfoBOS UAM or the quality of chatbot answers. |
| Newsletter / marketing communications (if ever introduced) |
GDPR art. 6(1)(a) Double opt-in consent UŚUDE art. 10 Polish electronic services act |
e-mail address, date/time of opt-in confirmation | Until consent is withdrawn + 3 years after withdrawal for audit trail | |
| Compliance with legal obligations (archival, tax, court orders) | GDPR art. 6(1)(c) compliance with a legal obligation to which the Controller is subject | any of the above, as required by applicable law | Periods specified by specific laws (e.g. 6 years for accounting records) |
§ 5 Categories of personal data
We only process the data that is strictly necessary for each purpose. We never collect the so-called "special categories" of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data or data concerning sex life or sexual orientation) unless it is voluntarily provided by you in a message or form — in which case it is only processed for the purpose of replying to you.
- LOW RISK Account data: name, surname, institutional e-mail, password hash (bcrypt cost=12, never stored in plaintext), permissions role.
- LOW RISK Contact data: e-mail address, name, phone number (optional), contents of your message.
- LOW RISK Technical data: pseudonymised IP address, browser User-Agent, operating system, screen resolution, preferred language setting.
- ANONYMOUS Chatbot data: text of unanswered questions only — no identifier, never linked to a device.
§ 6 Retention periods
Data is kept only as long as it is needed for the purpose it was collected for. After that time it is securely deleted (shredded / overwritten) or irreversibly anonymised.
- Editor/admin accounts: duration of authorisation + 6 years (accounting/tax law).
- Contact form correspondence: 3 years after last reply (limitation period for civil claims).
- Unanswered chatbot questions: max. 90 days.
- Security logs: 12 months.
- Anonymous analytics: 24 months.
- Newsletter subscriptions: until consent is withdrawn + 3 years (audit trail for consent proof).
§ 7 Your rights under the GDPR
The GDPR grants you the following rights. You can exercise them free of charge. We are required to respond within 1 month (up to 2 extra months for complex requests).
- GDPR art. 15 Right of access — you can receive a confirmation of whether we process your data and a copy of that data.
- GDPR art. 16 Right to rectification — you can ask us to correct inaccurate or incomplete data about you.
- GDPR art. 17 Right to erasure ("right to be forgotten") — you can ask us to delete your data when e.g. it is no longer needed, you withdraw consent, or you object to processing.
- GDPR art. 18 Right to restriction of processing — you can ask us to "pause" processing while we verify your request or the accuracy of the data.
- GDPR art. 20 Right to data portability — for consent-based or contract-based processing you can receive the data in a structured, machine-readable format.
- GDPR art. 21 Right to object — you can object at any time to processing based on legitimate interest (§ 4) or for direct marketing purposes. Objection is free and requires no justification.
- GDPR art. 7(3) Right to withdraw consent — if processing is based on your consent, you can withdraw it at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- GDPR art. 22 Right concerning automated individual decision-making — see § 10.
Regardless of the rights listed above, you may always lodge a complaint with the President of the Personal Data Protection Office (UODO) if you believe that processing of your data violates data protection law; see § 15 for details.
§ 8 Recipients of personal data
We never sell your personal data. We only share data with the following carefully selected categories of recipients where necessary:
- Hosting / server operator — the Adam Mickiewicz University IT Centre servers (or private Laragon virtual host for development purposes), with signed data processing agreement (DPA / GDPR art. 28).
- SMTP / mail operator — the University's central e-mail infrastructure (self-hosted) used to send replies to contact forms, via the open-source PHPMailer library.
- Law enforcement / courts / public authorities — only when compelled by a binding law or court order (GDPR art. 6(1)(c)). We will inform you about such disclosure, unless legally prohibited.
- Data Protection Officer (external, if applicable) — bound by professional secrecy.
All of our processors commit in writing to provide adequate safeguards — encryption, access controls, regular audits, breach notification within 24 hours, and right-to-audit clauses.
§ 9 Transfers to third countries ("Schrems II")
All personal data processed on the InfoBOS UAM platform is stored on the servers of the Adam Mickiewicz University IT Centre and is not transferred to third countries or international organisations outside the European Economic Area (EEA). If external tools requiring such a transfer are introduced in the future, the transfer will take place only under the strict conditions set out in Chapter V GDPR, including on the basis of the European Commission's Standard Contractual Clauses.
- EEA ONLY Platform data, hosting and mail infrastructure are located within the EEA.
- NO PIXELS No Meta Pixel, no Google Analytics, no Hotjar, no AdSense, no Chatbot widgets hosted abroad.
- SELF-HOSTED All JavaScript, fonts (Inter 4.0), CSS and icons (Lucide SVG) are delivered from
/assets/vendor_cache/— no third-party CDN requests at runtime.
§ 10 Automated individual decision-making & profiling (GDPR art. 22)
We do not carry out any automated decision-making that produces legal effects concerning you or similarly significantly affects you — including credit scoring, automated refusal of services, or behavioural advertising.
- NOT PROFILING Anonymous click-stream analytics and BM25-like FAQ content ranking are not "profiling" within the meaning of GDPR art. 22. They serve purely to improve the public content, and produce no individual output.
- NOT DECISIONS Chatbot answers are informational and not binding. Any substantive decision on the status of a student is taken by a human administrator and subject to internal appeal procedures at the University.
Consistent with the CJEU judgment in Case C-34/21 — Meta Platforms Ireland v Data Protection Commission, if we were ever to introduce genuine profiling (e.g. personalised recommendations), we would first perform a Data Protection Impact Assessment (DPIA / GDPR art. 35) and explicitly inform you about it, and you would be given a clear right to object.
§ 11 Cookies & similar technologies
Our cookie policy is fully aligned with:
- CJEU judgment in Case C-673/17 — Planet49: consent must be an active, opt-in action; pre‑ticked boxes, inactivity, or "continue scrolling" are not valid consent.
- UODO Guidelines on cookies and similar technologies of September 2024: strict opt-in for analytics, functional and marketing cookies; narrow "strictly necessary" exception.
| Cookie name | Category | Expiry | Purpose | Consent required? |
|---|---|---|---|---|
PHPSESSID |
Strictly necessary | Session (deleted when the browser closes) | Maintains session state (login, CSRF tokens, rate limiting) — core platform functionality. | No (technical necessity) |
faq_lang |
Strictly necessary | 12 months | Stores user's selected interface language (PL / EN). | No (technical necessity) |
faq_csrf_token |
Strictly necessary | Session | Cross-site request forgery protection for forms. | No (security — legal obligation, GDPR art. 6(1)(c) + 32) |
faq_analytics_consent |
Strictly necessary | 6 months | Records the user's choice on the cookie banner (granted / denied). | No (records the consent decision itself) |
faq_theme |
Functional | 12 months | Stores light/dark/high-contrast theme choice when consent is granted. | Yes (falls back to browser defaults without consent) |
faq_font_size |
Functional | 12 months | Stores user's preferred font size (A- / A / A+) when consent is granted. | Yes |
faq_anon_session_* |
Analytics | 24 months | Fully anonymised session identifiers for internal, self-hosted clickstream analytics. NEVER stores IP addresses. | Yes (strict opt-in) — only when you click "Accept" on the banner. |
Service Worker cache |
Strictly necessary (PWA) | Managed by the SW (Network‑First strategy) | Offline fallback for PWA users, faster reloads of already-visited FAQ pages. | No (part of core platform operation; only caches already downloaded assets — no tracking) |
Analytics, functional and marketing cookie consent options are always unchecked by default. We do not use pre-ticked checkboxes or consent by scrolling; consent requires a clear, active click, in accordance with the CJEU Planet49 judgment (C-673/17).
How to manage cookies
You can manage or delete cookies at any time through:
- Your browser settings: Chrome →
chrome://settings/cookies, Firefox →about:preferences#privacy, Safari → Settings → Privacy, Edge →edge://settings/siteData. - Our cookie banner: available at every visit until you make a choice; you can re-open it by clearing the
faq_analytics_consentcookie or via this button (requires JS).
You can change your cookie settings at any time by using the “Cookie settings” control in the site footer or by reopening the consent banner. Withdrawal does not affect the lawfulness of cookie use before withdrawal.
Blocking some functional cookies is perfectly safe and will not prevent the site from working; it will simply mean that we cannot remember your theme or font choice between visits.
§ 12 Processing for marketing purposes
At present the platform does not send any marketing communications or newsletters. If we ever introduce such functionality, the following rules will apply automatically (as a safeguard):
- Consent is always collected via Double opt-in: the user must first tick an unticked checkbox (never pre‑ticked — consistent with Planet 49 CJEU C-673/17), then confirm by clicking a link in a verification e-mail.
- Marketing messages always contain a clear, one-click unsubscribe link (working within 24 hours at most).
- You can object to marketing processing at any time, free of charge and without giving any reason (GDPR art. 21(2) — absolute right).
- Marketing consent is never a precondition for using the FAQ or chatbot.
§ 13 Security of personal data (GDPR art. 32)
We apply a broad set of technical and organisational security measures, consistent with the state of the art:
- CRYPTO TLS 1.3 encryption in transit for every HTTP(S) connection; HSTS header with long max-age.
- CRYPTO Password hashing with
bcrypt, cost factor = 12 (NIST OWASP recommended minimum), never stored in plaintext, never logged. - CSP Content Security Policy Level 3 with per-request nonces — blocks all inline scripts and styles not explicitly allowed; no third-party content.
- CSRF Synchronizer token pattern for every state-changing action (forms, login, password change, content edits).
- SESSION Hardened PHP sessions: HttpOnly + Secure flags, SameSite=Lax, short lifetime, rotation on privilege change (login / role change).
- RATE Per-IP + per-account rate limiting and temporary account lockout for repeated failed logins (anti brute-force).
- AUDIT Role-based access control (RBAC) with least-privilege principle; full audit log of all administrative content edits.
- PRIV Input/output security: all HTML context is escaped via
htmlescape(); all database queries use real prepared statements (PDO emulation OFF — no SQL injection); safe file uploads with MIME-type + extension allow-list.
§ 14 Personal data breach notification (GDPR arts. 33 & 34)
In the (unlikely) event of a personal data breach we follow a strict, documented procedure:
- Our incident response team is notified immediately (SLA: on-call within 1 hour).
- The breach is reported to the UODO (President of the Personal Data Protection Office) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (GDPR art. 33(1)).
- If the personal data breach may result in a high risk to the rights and freedoms of natural persons, we inform the affected persons directly without undue delay, including the nature of the breach, the DPO's contact details and recommendations for mitigating potential adverse effects (GDPR art. 34).
- All breaches are logged internally with timeline, scope, mitigation actions and lessons learned for continuous improvement.
§ 15 Lodging a complaint with the supervisory authority (UODO)
If you consider that our processing of your personal data infringes the GDPR or the Polish Act on the protection of personal data, you have the right to lodge a complaint with the Polish supervisory authority at any time:
- Name
- Prezes Urzędu Ochrony Danych Osobowych (President of the Office for the Protection of Personal Data)
- Address
- ul. Stawki 2, 00-193 Warszawa, Poland
- Website
- www.uodo.gov.pl
- Phone
- +48 22 531 03 00
- kontakt@uodo.gov.pl (encrypted contact form also available on the UODO website)
§ 16 Changes to this privacy policy
We may update this policy from time to time to reflect:
- changes in the law (new GDPR implementing acts, UODO guidelines, CJEU judgments);
- changes in the scope or purposes of processing;
- technical improvements to the platform.
Any material changes will be prominently announced on the home page for at least 30 days before they take effect, together with a clear note in the "last update" field at the top of this document. Substantive changes affecting consent-based processing (e.g. new analytics, new cookies) will require a fresh opt-in consent from each user.
§ 17 Contact & print version
For any questions, requests or clarifications please contact our Controller or DPO at the addresses given in § 3, or use the contact form.
Document revision v1.0 · 19.08.2026 · Checked against CJEU case law up to August 2026 and UODO Guidelines 1/2024 on transparency & September 2024 Cookie Guidelines.