Skip to main content
Student Offices logo InfoBOS Help Center
Home Study Regulations Instructions Rules and Instructions - ITC Contact Log In
PL EN

Font size

Colour theme

Language

PL EN

Privacy Policy

Updated Last update: 19.08.2026  ·  Effective: 19.08.2026

Table of contents

  1. 1. Introduction and scope
  2. 2. Definitions
  3. 3. Data Controller & contact details
  4. 4. Purposes & legal basis of processing
  5. 5. Categories of personal data
  6. 6. Retention periods
  7. 7. Your rights under GDPR
  8. 8. Recipients of personal data
  9. 9. Transfers to third countries (Schrems II)
  10. 10. Automated decisions & profiling
  11. 11. Cookies & similar technologies
  12. 12. Processing for marketing purposes
  13. 13. Security of personal data
  14. 14. Data breach notification
  15. 15. Lodging a complaint (UODO)
  16. 16. Changes to this privacy policy
  17. 17. Contact & print version
English translation note: The authoritative version of this policy is the Polish one. The English version is provided for convenience only and is currently being expanded. For legally binding text please switch to Polish (PL) or contact our Data Protection Officer.

§ 1   Introduction and scope

This Privacy Policy sets out the rules for processing of personal data by the InfoBOS UAM web platform operated by the Student Service Offices (Biura Obsługi Studentów) of Adam Mickiewicz University in Poznań, and complies with the following legislation:

  • EU LAW Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation — GDPR / RODO).
  • PL LAW Polish Act of 10 May 2018 on the protection of personal data (Journal of Laws 2023 item 1208).
  • PL LAW Polish Act of 18 July 2002 on the provision of services by electronic means (Journal of Laws 2024 item 471).
  • COOKIES Polish Telecommunications Law (Journal of Laws 2024 item 521) & ePrivacy rules, consistent with the CJEU Planet 49 judgment (C-673/17) and UODO Cookie Guidelines of September 2024.

The policy applies to every visitor, registered user, and person who contacts us through the platform.

This Privacy Policy fulfils the information obligation under Article 13 GDPR towards platform users, people using the contact form, and people receiving marketing communications related to the activities of the Student Service Offices of Adam Mickiewicz University in Poznań.

§ 2   Definitions

Administrator / Controller
Adam Mickiewicz University in Poznań, represented by the Rector, with its registered office at ul. Henryka Wieniawskiego 1, 61-712 Poznań — the entity deciding on the purposes and means of processing personal data on the InfoBOS UAM FAQ platform.
Personal Data
Any information relating to an identified or identifiable natural person; in particular name, e-mail address, student number, telephone number, IP address.
RODO / GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
UODO
The Polish data protection authority — President of the Office for the Protection of Personal Data (Prezes Urzędu Ochrony Danych Osobowych).
Cookie
A small text file stored on the user's device by the web server, used to recognise the device on subsequent visits.
Processor
An entity which processes personal data on behalf of the Controller (e.g. hosting provider, e-mail server operator) under a written data processing agreement (DPA / art. 28 GDPR).

§ 3   Data Controller & contact details

Controller details

Name
Adam Mickiewicz University in Poznań, represented by the Rector
Registered office / address for service
ul. Henryka Wieniawskiego 1, Collegium Minus, 61-712 Poznań, Poland
Identification numbers
NIP: 7770006350, REGON: 000001293 (as a public university, Adam Mickiewicz University is not entered in the KRS)
Platform contact e-mail
infobos@amu.edu.pl
Contact phone
+48 61 829 21 43 (Student Service Office) or +48 61 829 43 08 (Adam Mickiewicz University Rector's Office)

Data Protection Officer (IOD / DPO)

E-mail
iod@amu.edu.pl
Scope
All matters related to the processing of personal data and the exercise of the rights of data subjects.
Tip: You may contact the Controller or the DPO at any time by e-mail, letter or phone. E-mails that include sensitive personal data (e.g. student records) should be sent from your official student or employee e-mail address for your own safety.

§ 4   Purposes & legal basis of processing

Every single processing activity has an explicit purpose and a legal basis from article 6(1) of the GDPR. We never process data "just in case".

Purpose of processing Legal basis Categories of data Retention period Whether providing data is required and consequences of not providing it
Maintenance of administrative accounts (panel administrators, editors of FAQ content) GDPR art. 6(1)(b) performance of a contract — employment/commission
GDPR art. 6(1)(c) legal obligation (archiving, tax law — 6 years)
name, surname, job title, institutional e-mail, password (bcrypt hash), authentication logs, permissions Duration of the authorisation + 6 years after revocation for accounting/archival purposes Providing the data is necessary to perform the employment/commission contract and official duties involving FAQ system administration. Without it, we cannot create the account or provide access to the administration panel.
Handling contact form enquiries, requests and reports GDPR art. 6(1)(a) consent (if required)
GDPR art. 6(1)(f) legitimate interest — answer the enquiry
name, e-mail, telephone (if voluntarily provided), contents of the message 3 years from the end of the correspondence (statute of limitations period) Providing the data is voluntary but necessary to answer your enquiry. Without contact details, answering may be impossible or more difficult.
InfoBOS chatbot operation & knowledge base improvement GDPR art. 6(1)(f) legitimate interest — improving the quality of public services anonymous contents of unanswered questions only (answered questions are never saved); NO personal identifiers requested Max. 90 days — then automatically deleted or fully anonymised Providing the data, including the enquiry content, is voluntary. Where processing is based on legitimate interest, you may object; see § 7.
Security monitoring & incident response (access logs, rate limiting, brute-force protection) GDPR art. 6(1)(f) legitimate interest — security of IT systems and networks IP address (pseudonymised), User-Agent, login attempts timestamps, CSRF tokens 12 months — then rotated and deleted Processing technical data follows our legitimate interest in securing UAM IT systems and networks. Without it, we cannot ensure secure use of the platform.
Internal statistical analytics (clickstream, anonymous sessions) GDPR art. 6(1)(a) explicit, opt-in consent (strictly required — cookie banner button "Accept") fully anonymised session hash, pages visited, timestamp; NO IP or personal identifiers 24 months from collection — then automatically aggregated and anonymised further Consent to analytics cookies is entirely voluntary. Refusing it does not affect access to InfoBOS UAM or the quality of chatbot answers.
Newsletter / marketing communications (if ever introduced) GDPR art. 6(1)(a) Double opt-in consent
UŚUDE art. 10 Polish electronic services act
e-mail address, date/time of opt-in confirmation Until consent is withdrawn + 3 years after withdrawal for audit trail
Compliance with legal obligations (archival, tax, court orders) GDPR art. 6(1)(c) compliance with a legal obligation to which the Controller is subject any of the above, as required by applicable law Periods specified by specific laws (e.g. 6 years for accounting records)
Balancing test for legitimate interest basis (GDPR art. 6(1)(f)): For every processing operation marked "legitimate interest" we have prepared a written balancing test confirming that our interest does not override your fundamental rights and freedoms. We can provide a summary of such a test upon request. You have the right to object at any time — see § 7.

§ 5   Categories of personal data

We only process the data that is strictly necessary for each purpose. We never collect the so-called "special categories" of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data or data concerning sex life or sexual orientation) unless it is voluntarily provided by you in a message or form — in which case it is only processed for the purpose of replying to you.

  • LOW RISK Account data: name, surname, institutional e-mail, password hash (bcrypt cost=12, never stored in plaintext), permissions role.
  • LOW RISK Contact data: e-mail address, name, phone number (optional), contents of your message.
  • LOW RISK Technical data: pseudonymised IP address, browser User-Agent, operating system, screen resolution, preferred language setting.
  • ANONYMOUS Chatbot data: text of unanswered questions only — no identifier, never linked to a device.

§ 6   Retention periods

Data is kept only as long as it is needed for the purpose it was collected for. After that time it is securely deleted (shredded / overwritten) or irreversibly anonymised.

  • Editor/admin accounts: duration of authorisation + 6 years (accounting/tax law).
  • Contact form correspondence: 3 years after last reply (limitation period for civil claims).
  • Unanswered chatbot questions: max. 90 days.
  • Security logs: 12 months.
  • Anonymous analytics: 24 months.
  • Newsletter subscriptions: until consent is withdrawn + 3 years (audit trail for consent proof).

§ 7   Your rights under the GDPR

The GDPR grants you the following rights. You can exercise them free of charge. We are required to respond within 1 month (up to 2 extra months for complex requests).

  • GDPR art. 15 Right of access — you can receive a confirmation of whether we process your data and a copy of that data.
  • GDPR art. 16 Right to rectification — you can ask us to correct inaccurate or incomplete data about you.
  • GDPR art. 17 Right to erasure ("right to be forgotten") — you can ask us to delete your data when e.g. it is no longer needed, you withdraw consent, or you object to processing.
  • GDPR art. 18 Right to restriction of processing — you can ask us to "pause" processing while we verify your request or the accuracy of the data.
  • GDPR art. 20 Right to data portability — for consent-based or contract-based processing you can receive the data in a structured, machine-readable format.
  • GDPR art. 21 Right to object — you can object at any time to processing based on legitimate interest (§ 4) or for direct marketing purposes. Objection is free and requires no justification.
  • GDPR art. 7(3) Right to withdraw consent — if processing is based on your consent, you can withdraw it at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • GDPR art. 22 Right concerning automated individual decision-making — see § 10.
How to exercise your rights: Send an e-mail to infobos@amu.edu.pl or iod@amu.edu.pl. To prevent unauthorised access, we may ask you to verify your identity. For users with a University account, verification may take place by sending a message from their registered university e-mail address (staff or student). For other visitors, identity verification takes place through alternative and secure communication methods, for example the e-mail address previously used in the contact form. Identity verification is limited strictly to what is necessary to confirm that we are exercising your rights for the correct person, in accordance with Article 12(6) GDPR. This is for your safety.

Regardless of the rights listed above, you may always lodge a complaint with the President of the Personal Data Protection Office (UODO) if you believe that processing of your data violates data protection law; see § 15 for details.

§ 8   Recipients of personal data

We never sell your personal data. We only share data with the following carefully selected categories of recipients where necessary:

  • Hosting / server operator — the Adam Mickiewicz University IT Centre servers (or private Laragon virtual host for development purposes), with signed data processing agreement (DPA / GDPR art. 28).
  • SMTP / mail operator — the University's central e-mail infrastructure (self-hosted) used to send replies to contact forms, via the open-source PHPMailer library.
  • Law enforcement / courts / public authorities — only when compelled by a binding law or court order (GDPR art. 6(1)(c)). We will inform you about such disclosure, unless legally prohibited.
  • Data Protection Officer (external, if applicable) — bound by professional secrecy.

All of our processors commit in writing to provide adequate safeguards — encryption, access controls, regular audits, breach notification within 24 hours, and right-to-audit clauses.

§ 9   Transfers to third countries ("Schrems II")

All personal data processed on the InfoBOS UAM platform is stored on the servers of the Adam Mickiewicz University IT Centre and is not transferred to third countries or international organisations outside the European Economic Area (EEA). If external tools requiring such a transfer are introduced in the future, the transfer will take place only under the strict conditions set out in Chapter V GDPR, including on the basis of the European Commission's Standard Contractual Clauses.

  • EEA ONLY Platform data, hosting and mail infrastructure are located within the EEA.
  • NO PIXELS No Meta Pixel, no Google Analytics, no Hotjar, no AdSense, no Chatbot widgets hosted abroad.
  • SELF-HOSTED All JavaScript, fonts (Inter 4.0), CSS and icons (Lucide SVG) are delivered from /assets/vendor_cache/ — no third-party CDN requests at runtime.

§ 10   Automated individual decision-making & profiling (GDPR art. 22)

We do not carry out any automated decision-making that produces legal effects concerning you or similarly significantly affects you — including credit scoring, automated refusal of services, or behavioural advertising.

  • NOT PROFILING Anonymous click-stream analytics and BM25-like FAQ content ranking are not "profiling" within the meaning of GDPR art. 22. They serve purely to improve the public content, and produce no individual output.
  • NOT DECISIONS Chatbot answers are informational and not binding. Any substantive decision on the status of a student is taken by a human administrator and subject to internal appeal procedures at the University.

Consistent with the CJEU judgment in Case C-34/21 — Meta Platforms Ireland v Data Protection Commission, if we were ever to introduce genuine profiling (e.g. personalised recommendations), we would first perform a Data Protection Impact Assessment (DPIA / GDPR art. 35) and explicitly inform you about it, and you would be given a clear right to object.

§ 11   Cookies & similar technologies

Our cookie policy is fully aligned with:

  • CJEU judgment in Case C-673/17 — Planet49: consent must be an active, opt-in action; pre‑ticked boxes, inactivity, or "continue scrolling" are not valid consent.
  • UODO Guidelines on cookies and similar technologies of September 2024: strict opt-in for analytics, functional and marketing cookies; narrow "strictly necessary" exception.
Cookie name Category Expiry Purpose Consent required?
PHPSESSID Strictly necessary Session (deleted when the browser closes) Maintains session state (login, CSRF tokens, rate limiting) — core platform functionality. No (technical necessity)
faq_lang Strictly necessary 12 months Stores user's selected interface language (PL / EN). No (technical necessity)
faq_csrf_token Strictly necessary Session Cross-site request forgery protection for forms. No (security — legal obligation, GDPR art. 6(1)(c) + 32)
faq_analytics_consent Strictly necessary 6 months Records the user's choice on the cookie banner (granted / denied). No (records the consent decision itself)
faq_theme Functional 12 months Stores light/dark/high-contrast theme choice when consent is granted. Yes (falls back to browser defaults without consent)
faq_font_size Functional 12 months Stores user's preferred font size (A- / A / A+) when consent is granted. Yes
faq_anon_session_* Analytics 24 months Fully anonymised session identifiers for internal, self-hosted clickstream analytics. NEVER stores IP addresses. Yes (strict opt-in) — only when you click "Accept" on the banner.
Service Worker cache Strictly necessary (PWA) Managed by the SW (Network‑First strategy) Offline fallback for PWA users, faster reloads of already-visited FAQ pages. No (part of core platform operation; only caches already downloaded assets — no tracking)

Analytics, functional and marketing cookie consent options are always unchecked by default. We do not use pre-ticked checkboxes or consent by scrolling; consent requires a clear, active click, in accordance with the CJEU Planet49 judgment (C-673/17).

How to manage cookies

You can manage or delete cookies at any time through:

  • Your browser settings: Chrome → chrome://settings/cookies, Firefox → about:preferences#privacy, Safari → Settings → Privacy, Edge → edge://settings/siteData.
  • Our cookie banner: available at every visit until you make a choice; you can re-open it by clearing the faq_analytics_consent cookie or via this button (requires JS).

You can change your cookie settings at any time by using the “Cookie settings” control in the site footer or by reopening the consent banner. Withdrawal does not affect the lawfulness of cookie use before withdrawal.

Blocking some functional cookies is perfectly safe and will not prevent the site from working; it will simply mean that we cannot remember your theme or font choice between visits.

§ 12   Processing for marketing purposes

At present the platform does not send any marketing communications or newsletters. If we ever introduce such functionality, the following rules will apply automatically (as a safeguard):

  • Consent is always collected via Double opt-in: the user must first tick an unticked checkbox (never pre‑ticked — consistent with Planet 49 CJEU C-673/17), then confirm by clicking a link in a verification e-mail.
  • Marketing messages always contain a clear, one-click unsubscribe link (working within 24 hours at most).
  • You can object to marketing processing at any time, free of charge and without giving any reason (GDPR art. 21(2) — absolute right).
  • Marketing consent is never a precondition for using the FAQ or chatbot.

§ 13   Security of personal data (GDPR art. 32)

We apply a broad set of technical and organisational security measures, consistent with the state of the art:

  • CRYPTO TLS 1.3 encryption in transit for every HTTP(S) connection; HSTS header with long max-age.
  • CRYPTO Password hashing with bcrypt, cost factor = 12 (NIST OWASP recommended minimum), never stored in plaintext, never logged.
  • CSP Content Security Policy Level 3 with per-request nonces — blocks all inline scripts and styles not explicitly allowed; no third-party content.
  • CSRF Synchronizer token pattern for every state-changing action (forms, login, password change, content edits).
  • SESSION Hardened PHP sessions: HttpOnly + Secure flags, SameSite=Lax, short lifetime, rotation on privilege change (login / role change).
  • RATE Per-IP + per-account rate limiting and temporary account lockout for repeated failed logins (anti brute-force).
  • AUDIT Role-based access control (RBAC) with least-privilege principle; full audit log of all administrative content edits.
  • PRIV Input/output security: all HTML context is escaped via htmlescape(); all database queries use real prepared statements (PDO emulation OFF — no SQL injection); safe file uploads with MIME-type + extension allow-list.

§ 14   Personal data breach notification (GDPR arts. 33 & 34)

In the (unlikely) event of a personal data breach we follow a strict, documented procedure:

  1. Our incident response team is notified immediately (SLA: on-call within 1 hour).
  2. The breach is reported to the UODO (President of the Personal Data Protection Office) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (GDPR art. 33(1)).
  3. If the personal data breach may result in a high risk to the rights and freedoms of natural persons, we inform the affected persons directly without undue delay, including the nature of the breach, the DPO's contact details and recommendations for mitigating potential adverse effects (GDPR art. 34).
  4. All breaches are logged internally with timeline, scope, mitigation actions and lessons learned for continuous improvement.

§ 15   Lodging a complaint with the supervisory authority (UODO)

If you consider that our processing of your personal data infringes the GDPR or the Polish Act on the protection of personal data, you have the right to lodge a complaint with the Polish supervisory authority at any time:

Name
Prezes Urzędu Ochrony Danych Osobowych (President of the Office for the Protection of Personal Data)
Address
ul. Stawki 2, 00-193 Warszawa, Poland
Website
www.uodo.gov.pl
Phone
+48 22 531 03 00
E-mail
kontakt@uodo.gov.pl (encrypted contact form also available on the UODO website)
No retaliation policy: Exercising your right to lodge a complaint has no negative consequences for you — it will never affect the level of service we provide.

§ 16   Changes to this privacy policy

We may update this policy from time to time to reflect:

  • changes in the law (new GDPR implementing acts, UODO guidelines, CJEU judgments);
  • changes in the scope or purposes of processing;
  • technical improvements to the platform.

Any material changes will be prominently announced on the home page for at least 30 days before they take effect, together with a clear note in the "last update" field at the top of this document. Substantive changes affecting consent-based processing (e.g. new analytics, new cookies) will require a fresh opt-in consent from each user.

§ 17   Contact & print version

For any questions, requests or clarifications please contact our Controller or DPO at the addresses given in § 3, or use the contact form.

✉   Contact form 🔒   E-mail the DPO

Document revision v1.0 · 19.08.2026 · Checked against CJEU case law up to August 2026 and UODO Guidelines 1/2024 on transparency & September 2024 Cookie Guidelines.

InfoBOS

Student Offices of Adam Mickiewicz University in Poznań – FAQ Knowledge Base

Information

  • Implementation: Nikodem Kałek
  • Privacy policy
  • Accessibility declaration
© 2026 Help Center - FAQ Knowledge base powered by InfoBOS

This site uses cookies required for operation and optional analytics cookies. Optional cookies are activated only after consent.

Privacy policy
InfoBOS

Polityka prywatności