POLIVERSUM Foundation · AI Assurance & Operational Validationinfo@poliversum.org.pl

Privacy Policy

This document describes the rules under which the POLIVERSUM Group processes personal data: the data of visitors to the website poliversum.org.pl (the “Service”), the data of persons who contact us or subscribe to our communications, and the data contained in materials entrusted to us by institutions, solution providers and partners in connection with the validation of artificial intelligence systems, analytical work and knowledge building.

This policy serves both as information for data subjects (Articles 13 and 14 GDPR) and as an accountability framework (Article 5(2) GDPR) – it indicates who acts in which role, on what legal basis and within what limits.

1. Data controller and structure of responsibility

The controller of personal data processed in connection with the operation of the Service and communications is the POLIVERSUM Group – a team of cooperating experts operating under the POLIVERSUM brand and at poliversum.org.pl, which does not have legal personality.

The controller’s obligations are performed jointly by the persons forming the Group, listed on the page About us, Trust Center and contact. These persons have determined by arrangement between them their respective responsibilities for compliance with the obligations under the GDPR, including the exercise of data subjects’ rights (joint controllership – Article 26 GDPR). The essence of this arrangement is made available to the data subject on request.

Irrespective of the internal allocation of obligations, every person may exercise their rights in respect of and against each of the joint controllers and may direct all matters concerning personal data to a single address: info@poliversum.org.pl. This address constitutes the contact point within the meaning of the third sentence of Article 26(1) GDPR.

2. Guiding principles

All the processes described below are subject to four principles that we treat as binding irrespective of the legal basis of a particular operation:

  • Voluntariness. We do not obtain data covertly, we do not buy databases, and we do not use scraping or tracking techniques. Every dataset at our disposal comes from a voluntary transfer – by the data subject or by an entity that has entrusted material to us for a specified purpose.
  • Purpose limitation and role binding. A Group expert processes only the data, and only to the extent, necessary to perform the role entrusted to them in a given process – validation, audit, advisory or research. The role sets the limit of access, not the other way round.
  • Minimisation and reduction of identifiability. Data that need not remain identifiable are pseudonymised and ultimately anonymised – as early as the purpose of processing allows (section 6).
  • Accountability. We maintain a record of processing activities and categories of processing activities, document legal bases and impact assessments where required, and are able to demonstrate the compliance of every operation.

3. Categories of data and sources

  • Correspondence (addresses in the poliversum.org.pl domain): name and surname, e-mail address, institution and position, message content and attachments.
  • Requests for a briefing, qualification session and EU Market Entry Call: contact details, name of the institution or company, description of the system or undertaking to which the enquiry relates, preferred date.
  • POLIVERSUM communications and newsletter: e-mail address and – if provided – name, surname and institution, together with information on delivery of and interaction with the message (section 8).
  • Materials entrusted for expert work: technical documentation, compliance documentation, test and evaluation datasets, system logs, process descriptions and other materials provided to us by the commissioning entity – to the extent that they contain personal data (section 5).
  • Substantive cooperation (experts, partners, participants in workshops, consultations and pilots): identification and contact data necessary to conclude and perform the agreement, billing data, and data contained in working documents and co-authored materials.
  • Technical data of the Service: IP address, date and time of the request, subpage address, browser and system identifier – in server logs and in security mechanisms.

4. Purposes and legal bases

  • Responding to enquiries and conducting correspondence – legitimate interest consisting in communicating with persons who contact us on their own initiative (Article 6(1)(f) GDPR).
  • Arranging and conducting a briefing, qualification session or EU Market Entry Call – taking steps at the request of the data subject prior to entering into a contract, and performance of a contract (Article 6(1)(b) GDPR); with regard to persons acting on behalf of an institution – the legitimate interest of both parties (Article 6(1)(f) GDPR).
  • Performance of expert, validation and analytical work – performance of the contract with the commissioning entity and, with regard to data contained in the entrusted materials, processing on behalf of and on the documented instructions of that entity (Article 28 GDPR) or in our own role as controller where this follows from the agreed allocation of roles (section 5).
  • Own research, studies, publications and methodology development – legitimate interest consisting in conducting research and expert activities and disseminating knowledge (Article 6(1)(f) GDPR), subject to the safeguards of Article 89(1) GDPR; further processing for research and statistical purposes is not considered incompatible with the initial purposes (Article 5(1)(b) GDPR). Details – section 6.
  • Communications and newsletter – consent (Article 6(1)(a) GDPR), which may be withdrawn at any time with effect for the future.
  • Billing and documentation – legal obligations, in particular tax and accounting obligations (Article 6(1)(c) GDPR).
  • Security of the Service and infrastructure, prevention of abuse, and the establishment, exercise and defence of legal claims – legitimate interest (Article 6(1)(f) GDPR).

5. Data entrusted to us by institutions and providers – allocation of roles

A significant part of the materials we work with does not come from data subjects but from the entities commissioning the work: public administration, regulated institutions, AI system providers and research consortia. This situation requires a precise allocation of roles, because it determines who is accountable to whom.

5.1. Basic principle

With regard to personal data contained in materials entrusted to us by the commissioning entity, that entity remains the controller, and the POLIVERSUM Group acts as a processor within the meaning of Article 28 GDPR – it processes the data only on the documented instructions of the entrusting party, for the purpose specified by it and for the period determined by it. These rules are set out in each case in a data processing agreement concluded before work begins.

Any departure from this principle – i.e. the Group assuming the role of a separate controller or joint controller – requires an express written arrangement and is recorded in the project documentation. The role is never implied.

5.2. Voluntary entrustment and representations of the entrusting party

Entrusting any materials to us is entirely voluntary and takes place on the initiative of the entrusting party. We do not require the transfer of personal data as a condition for starting a conversation or cooperation; on the contrary, we recommend transferring materials stripped of identifying data where the purpose of the work does not preclude this.

By transferring to us material containing personal data, the entrusting party represents – and remains responsible for this towards data subjects and the supervisory authority – that:

  1. it has a valid legal basis for processing the data and a basis for disclosing or entrusting them to the POLIVERSUM Group;
  2. it has fulfilled its information obligations towards data subjects, including informing them of the categories of recipients;
  3. the scope of data transferred is adequate and limited to what is necessary for the purpose of the work, and does not include data not required for that purpose – in particular, it does not include special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), unless previously agreed in writing together with an indication of the legal basis;
  4. the processing instructions it gives us are lawful.

The POLIVERSUM Group is not able – and is under no legal obligation – to verify independently whether the entrusting party has obtained the required legal bases and fulfilled its information obligations towards data subjects. The risk and consequences of the absence of such bases are borne by the entrusting party. However, if in our opinion an instruction of the entrusting party infringes the GDPR or other data protection provisions, we inform it without delay and suspend the execution of the instruction until the matter is clarified – in accordance with the processor’s obligation under the second subparagraph of Article 28(3) GDPR. We treat this obligation as part of the service, not as a courtesy.

5.3. Limits of responsibility

The POLIVERSUM Group is responsible for data processing with regard to its own activities and the obligations that the GDPR imposes directly on processors (Article 82(2) GDPR), and, as controller, for the processes described in section 4 as carried out in its own role. We do not, however – and cannot – accept responsibility for:

  • the lawfulness of the collection of the data by the entrusting party and its fulfilment of information obligations;
  • the scope and content of material transferred to us on the initiative of the entrusting party, including the transfer of data going beyond the purpose of the work;
  • the consequences of instructions of the entrusting party executed after we have raised the objections referred to in section 5.2;
  • the further use by the entrusting party of the results of our work, including decisions taken on their basis.

We also stress that the above allocation describes the actual distribution of roles and does not constitute an exclusion of liability towards data subjects. The liability of the controller and the processor towards a person who has suffered damage arises from Article 82 GDPR and cannot be excluded by contract; an entity that has paid full compensation retains a right of recourse against the other parties involved in the processing for the part corresponding to their responsibility (Article 82(5) GDPR). Contractual provisions between us and the entrusting party govern only this mutual allocation of the burden.

6. Building and disseminating knowledge – own research, studies, machine processing

POLIVERSUM’s activity consists in validating AI systems and compliance systems and then transforming the experience from this work into methodological knowledge: risk patterns, defect catalogues, assessment criteria, publications and recommendations. This layer is part of our mission and needs to be described explicitly, because it involves further processing.

6.1. Principle of exiting the personal data regime

For research, methodological, statistical and publication purposes – including training, testing and evaluating models and analytical tools – we aim to use anonymised data, i.e. data that cannot be attributed to an identified or identifiable person, taking into account all the means reasonably likely to be used. Data meeting this condition do not constitute personal data and are not subject to the GDPR (Recital 26 GDPR); the restrictions described in the other sections of this policy do not apply to their further use.

We treat anonymisation as an operational objective of every research process, not as a declaration. We assess the effectiveness of anonymisation before a dataset is used, taking into account the risks of singling out, linkability and inference, and we document the result of that assessment. If anonymisation cannot be achieved for a given dataset, the dataset remains under the personal data regime and is subject to the safeguards in section 6.2.

6.2. Safeguards for research processing (Article 89(1) GDPR)

Where processing for research, methodological or statistical purposes involves personal data, we apply technical and organisational safeguards meeting the requirements of Article 89(1) GDPR, in particular:

  • Pseudonymisation (Article 4(5) GDPR) as the default state of a working dataset – information allowing the data to be attributed to a specific person is stored separately and subject to separate access control.
  • Separation of the analytical layer from the identification layer – the team conducting the analysis has no access to pseudonymisation keys unless the purpose of the analysis requires it.
  • Aggregation and publication thresholds – results are presented at a level at which information about an individual person, case or institution cannot be reconstructed; in publications we apply minimum cell-size thresholds and statistical disclosure control.
  • Minimisation and limited retention of research datasets – the working dataset contains only variables relevant to the research question posed and is deleted or permanently anonymised once the work is completed.

6.3. Federated approach – analysis without moving data

Wherever technically feasible, we use a federated architecture: the data remain in the environment of the entity that holds them, and only the results of computations are exchanged – model parameters, aggregate statistics, quality metrics – not the source records. In that case the POLIVERSUM Group does not download a copy of the dataset and does not create a central data repository.

This solution significantly reduces, though does not eliminate, the risks associated with processing: it removes the risk of the dataset leaking in transit and at the recipient, and the risk of secondary use of copies, but it leaves the risk of inference from the computation results themselves. We therefore supplement the federated layer with controls over what leaves the source environment: aggregation thresholds, query limits, review of results before release and, where justified, statistical perturbation mechanisms. We do not present federation as a guarantee of anonymity – we present it as a risk-reduction measure whose effectiveness is assessed separately in each project.

6.4. Machine and automated processing

We carry out analytical, validation and research work using automated tools, including machine learning and text analysis methods. This applies both to entrusted materials (within the limits of the entrusting party’s instructions – section 5) and to datasets used for our own research (within the limits of sections 6.1–6.3).

Three restrictions apply, which no instruction or consent can lift:

  1. We do not take decisions concerning individuals based solely on automated processing, including profiling, which would produce legal effects concerning them or similarly significantly affect them (Article 22(1) GDPR). The outputs of automated tools are material for expert assessment, not a substitute for it; every validation conclusion is approved by a human who is accountable for it.
  2. We do not transfer personal data from entrusted materials to external generative model services or other tools that process data outside an environment we control, unless the entrusting party expressly so decides in writing, specifying the provider and the basis for the transfer.
  3. We do not use entrusted materials to train models made available outside the projectin which those materials were created, unless the data have first been anonymised as described in section 6.1 or the entrusting party has given separate, express consent.

6.5. Data subjects’ rights in the research context

With regard to processing for research and statistical purposes, the data subject has the right to object on grounds relating to their particular situation (Article 21(6) GDPR). We consider objections individually and uphold them unless the processing is necessary for the performance of a task carried out in the public interest.

We also inform you candidly of the limitations: to the extent that processing serves research or statistical purposes covered by the safeguards of Article 89(1) GDPR, the right to erasure may not apply where erasure would render impossible or seriously impair the achievement of the research objectives (Article 17(3)(d) GDPR). We apply this restriction only to the actual extent to which it arises and do not extend it to other processes. With regard to anonymised data, the exercise of GDPR rights is technically impossible, because we are unable to link such data to a specific person – we do not collect or retain additional information solely in order to enable such identification (Article 11 GDPR).

7. Publications and expert materials

We publish the results of our work in the form of reports, analyses and methodological studies. These materials are based on anonymised or aggregated findings. The name of an institution, a description of a specific deployment or other information enabling the identification of an entity or person is disclosed only with the prior, express consent of that entity, given separately for each publication. By default, the identity of the subjects of our findings is not disclosed.

We process the data of persons appearing publicly in connection with our activities – authors, speakers, panellists – to the extent necessary to attribute authorship and document the event, on the basis of legitimate interest or consent, as the circumstances require.

8. Newsletter and communications – Mailchimp

To maintain the recipient list and send the POLIVERSUM newsletter and communications, we use the Mailchimpplatform, provided by The Rocket Science Group LLC d/b/a Mailchimp – an Intuit Inc. group company based in the United States. Mailchimp acts as a processor under a data processing agreement incorporating standard contractual clauses.

  • Subscription takes place solely on the basis of voluntary consent. The e-mail address and any additional data (name, surname, institution) are stored on Mailchimp servers.
  • Mailing statistics. Mailchimp records the delivery of a message, its opening and clicks on the links it contains, together with basic technical data (IP address, device type and e-mail client). We use this information solely to assess the usefulness of our communications and to maintain list hygiene. We do not build recipient profiles on this basis, we do not combine it with data from other sources, and we do not use it in the research described in section 6.
  • Unsubscribing is possible at any time – via the “unsubscribe” link in the footer of each message or by writing to info@poliversum.org.pl. The address is then removed from the list of active recipients; Mailchimp may keep it in an unsubscribe register solely to avoid sending further mailings to it.
  • Transfer to a third country. The data are processed in the United States. The transfer is based on the provider’s certification under the EU–U.S. Data Privacy Framework, covered by a European Commission adequacy decision (Article 45 GDPR), and additionally on the European Commission’s standard contractual clauses incorporated into the data processing agreement (Article 46(2)(c) GDPR).

9. Recipients of data and transfers outside the EEA

We do not sell personal data or share it for marketing purposes. Data may be entrusted only to providers necessary for operating the Service and communications, on the basis of data processing agreements:

  • Hosting of the Service and e-mail in the poliversum.org.pl domain – Bluehost (Newfold Digital Inc., United States); transfer outside the EEA based on the European Commission’s standard contractual clauses (Article 46(2)(c) GDPR).
  • Newsletter – Mailchimp, under the terms set out in section 8.
  • Security of the Service – web application firewall and scanner provided by Defiant Inc. (Wordfence, United States), analysing IP addresses and request parameters in order to block abuse.
  • Backups – performed within the hosting infrastructure indicated above.

Materials entrusted for expert work are not transferred to sub-processors without the prior consent of the entrusting party (Article 28(2) GDPR). Data may also be disclosed to entities authorised under the law, including supervisory authorities and courts.

10. Retention periods

  • Correspondence and requests – for the time needed to handle the matter, and then until the expiry of the limitation period for any claims.
  • Entrusted materials – for the period specified by the entrusting party, no longer than until the work is completed; after completion, the materials are, as instructed, returned or deleted together with working copies (Article 28(3)(g) GDPR). We retain only the documentation necessary to demonstrate due performance of the engagement.
  • Research datasets – for the time needed to achieve the research purpose; then deleted or permanently anonymised. Anonymised derivative datasets may be retained indefinitely, as they do not constitute personal data.
  • Newsletter – until consent is withdrawn; thereafter only in the unsubscribe register (section 8).
  • Cooperation and billing – for the duration of the agreement, then for the period required by tax and accounting regulations and until the expiry of the limitation period for claims.
  • Server logs and security system data – in accordance with the configuration of the hosting and security software providers, no longer than necessary for security purposes and the investigation of incidents.

11. Rights of data subjects

Every person has the right of access to their data, to rectification, erasure, restriction of processing and data portability (to the extent that processing is based on consent or contract and carried out by automated means), the right to object to processing based on legitimate interest, and the right to withdraw consent at any time with effect for the future.

Please send requests to info@poliversum.org.pl. We respond without undue delay and in any event within one month of receipt of the request; this period may be extended by a further two months for complex requests, in which case we will inform you and give our reasons.

If a request concerns data contained in materials entrusted to us by another entity, we forward it without delay to the controller, which is that entity, and assist it in responding (Article 28(3)(e) GDPR); we are not entitled to decide such requests ourselves, and we inform the requesting person accordingly.

Every person has the right to lodge a complaint with the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl).

12. Cookies and analytics tools

The Service uses only cookies necessary for its proper and secure operation, including cookies of security mechanisms and login sessions of content editors. We do not use analytics tools, advertising pixels or marketing cookies, and we do not profile visitors. If in the future we introduce tools requiring consent, we will update this policy and implement a consent mechanism before enabling them.

The newsletter sign-up form may be handled by Mailchimp; in that case the provider may set its own technical cookie protecting the form against abuse.

13. Security

We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), in particular: encryption in transit (HTTPS), separation of the public part of the Service from the administration panel, a web application firewall, role-based access control on a need-to-know basis, separation of project working environments and regular backups. The persons forming the Group and those cooperating with it are bound by confidentiality.

In the event of a personal data breach, we act in accordance with Articles 33 and 34 GDPR – as controller, we notify the breach to the supervisory authority and, where necessary, inform the data subjects; as processor, we notify the breach to the controller without undue delay after becoming aware of it.

14. Voluntary provision of data and no automated decisions concerning individuals

Providing data is voluntary. Without contact details, however, we are unable to respond to an enquiry, arrange a meeting or send communications. We do not take decisions concerning data subjects based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect them (Article 22 GDPR); this principle also applies to the work described in section 6.

15. Changes to the policy

This policy is updated as the Service develops, new tools and processes are introduced and the legal framework changes. The current version is always available at this address; we notify recipients of our communications of material changes. Date of last update: 1 September 2026.