DataProcessing.
Information common to all clauses
These information clauses describe how MEDCONGRESS GROUP sp. z o.o. processes your personal data for each form on this website, in line with Articles 13 and 14 GDPR. Short notices appear next to each form; the full clauses are below.
Data controller
The controller of your personal data is MEDCONGRESS GROUP sp. z o.o., entered in the Register of Entrepreneurs of the National Court Register under number KRS 0001237036, NIP 5253087146, REGON 544567895 (the "Controller" or "Organizer").
- KRS
- 0001237036
- NIP
- 5253087146
- REGON
- 544567895
- Registered office
- ul. Chmielna 2/31, 00-020 Warsaw, Poland
Contact details for data protection matters
- General & GDPR matters
- info@iccsh2027.org
- Registration
- registration@iccsh2027.org
- Abstracts
- abstracts@iccsh2027.org
- Sponsorship
- sponsors@iccsh2027.org
- Postal address
- ul. Chmielna 2/31, 00-020 Warsaw, Poland
Data Protection Officer (DPO)
The Controller has not appointed a Data Protection Officer. Appointing a DPO is not mandatory under Article 37 GDPR (the Controller is not a public authority, and its core activities do not consist of large-scale monitoring of data subjects or large-scale processing of special categories of data). For all data-protection matters, please contact info@iccsh2027.org.
General legal framework
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
Categories of recipients (processors)
The Controller uses the following IT service providers acting as processors under data processing agreements concluded in accordance with Article 28 GDPR. Most process data within the European Economic Area (EEA); Resend (transactional e-mail) is established in the United States, Cloudflare Turnstile (anti-bot verification on the sign-up form) may process limited technical data on Cloudflare's global network, and Zoho documents that its support personnel may access mailbox data from outside the EEA — see "Transfers" for the safeguards that apply to each.
- Vercel Inc. — Frontend hosting (website) · EEA (EU region)
- Railway Corp. — Backend hosting and PostgreSQL database · EEA (EU region)
- Zoho Corporation B.V. — Human-staffed mailbox correspondence (info@, registration@, abstracts@, sponsors@, admin@) · EEA (EU data centre); support access may originate outside the EEA, including India
- Resend (Plus Five Five, Inc.) — Transactional / system e-mail (HTTP API) · United States — EU–US Data Privacy Framework certified, Standard Contractual Clauses (Art. 46 GDPR)
- Cloudflare, Inc. — File storage — abstract attachments (Cloudflare R2) · EU region 【DECYZJA: EU Jurisdictional Restriction on the bucket unconfirmed — a region setting alone is a performance hint, not a residency guarantee】
- Cloudflare, Inc. — Anti-bot verification on the account sign-up form (Cloudflare Turnstile) · processes IP address and technical signals on Cloudflare's global network · transfers safeguarded by SCC (Art. 46 GDPR) / EU–US Data Privacy Framework
- Jakub Pożarycki, sole trader operating under the business name "Jakub Pożarycki", with registered office at ul. Bukszpanowa 2, Bezrzecze, Poland, NIP 8513262181, REGON 389487615 — Technical support / application maintenance · EEA (Poland/EU)
Recipients may also include providers of accounting, legal and advisory services, and authorized public bodies — solely on the basis of applicable law. With respect to payments, the independent, separate controllers of payment data are Stripe Payments Europe, Ltd. (Dublin, Ireland) and PayPro SA (Przelewy24) — see the Payments section.
Transfers outside the EEA
The Controller uses infrastructure and IT service providers, some of which are established or have personnel outside the EEA. Depending on how a given service is configured, Data may be transferred to a third country or may be subject to remote access from outside the EEA — most notably Resend (United States, transactional e-mail) and Zoho's documented support access, which may originate from India. Transfers are carried out on the basis of the appropriate mechanism under Chapter V GDPR — in particular an adequacy decision, the EU–US Data Privacy Framework, or Standard Contractual Clauses together with a transfer impact assessment and supplementary measures where required. The Controller will inform data subjects of any further transfer not already described here.
Automated decision-making and profiling
Your personal data are not subject to solely automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
Account registration and operation
Article 13 GDPR
Categories of data
E-mail address, hashed password (passwordHash — stored solely as a salted, one-way hash; never in plain text or in reversibly encrypted form), preferred interface language, e-mail confirmation status.
Purposes of processing
- creating and operating a user account on iccsh2027.org,
- authentication (login) and securing access to the account,
- confirming the e-mail address (account-confirmation message),
- enabling features requiring an account (congress registration, abstract submission).
Legal basis
Article 6(1)(b) GDPR — processing necessary for the performance of a contract for the provision of an electronic service (account operation), or to take steps at your request prior to entering into a contract.
Recipients
Vercel (frontend hosting), Railway (backend hosting + PostgreSQL), Resend (e-mail confirmation, United States), Cloudflare, Inc. (anti-bot verification on the sign-up form — Turnstile), and the application-maintenance developer. See "Common information".
Retention period
Until the account is deleted by the user or the Controller, and thereafter for 1 year from deletion (to handle complaints and demonstrate correct execution of the deletion request). An account left inactive for 【DECYZJA: account inactivity period before a deletion notice is sent】 receives an advance notice and, absent renewed activity, is deleted automatically 【DECYZJA: notice period between the deletion notice and anonymisation】 later — never while a registration, abstract or claim linked to the account is still open.
Voluntariness
Providing an e-mail address and setting a password is voluntary but necessary to create and operate an account — without this data, creating an account is not possible.
Your rights
Access, rectification, erasure, restriction of processing, data portability, and complaint to the President of PUODO (ul. Stawki 2, 00-193 Warsaw). Objection under Article 21 GDPR does not apply — this processing rests solely on Article 6(1)(b) GDPR, not on a legitimate-interest basis.
Transfers outside the EEA: see "Transfers outside the EEA" in Common information. Automated decision-making/profiling: none.
Congress registration
Article 13 GDPR
Categories of data
Title/salutation, first name, last name, e-mail, phone, country, institution/affiliation, specialization, participant type, additional comments, fee category, add-ons, whether an invoice is required, and — where requested — invoicing details (company name, street, city, postal code, country, Tax ID). Dietary requirements are optional and processed only under the separate consent described below.
Purposes of processing
- performance of the ICCSH 2027 participation contract (registration, badge, access control),
- organization of catering and accompanying events (dietary requirements, where you have given the separate consent described below),
- settlement of the registration fee and add-ons,
- issuing a VAT invoice and fulfilling accounting and tax obligations,
- organizational communication with the participant.
Legal basis
- Article 6(1)(b) GDPR — performance of the participation contract (title, name, e-mail, phone, country, participant type, fee category, add-ons, comments);
- specialization and institution/affiliation — Article 6(1)(b) GDPR: data necessary for a professional service directed at healthcare professionals (correct assignment to the scientific programme, fee-category eligibility, session organization);
- Article 6(1)(c) GDPR — legal obligation regarding issuance and retention of invoices and tax documentation (VAT Act, Accounting Act, Tax Ordinance) — for invoicing data;
- Article 6(1)(f) GDPR — the Controller's legitimate interest in establishing, pursuing or defending claims — for data retention after the congress;
- dietary requirements (optional) — Article 9(2)(a) GDPR: your separate, explicit, revocable consent, given solely to arrange catering — this field is not required to register and is not covered by the bases above.
Recipients
Vercel, Railway (hosting + PostgreSQL), Resend (transactional e-mail, United States), the maintenance developer, the accounting-services provider, and — for payments — Stripe Payments Europe, Ltd. and PayPro SA (Przelewy24) as separate controllers (see Payments). See "Common information".
Retention period
- Participation data (registration, add-ons, contact, specialization, institution, comments)
- 3 years from the end of the congress — establishment/defence of claims (Art. 6(1)(f) GDPR), limitation periods.
- Dietary requirements (Art. 9(2)(a) consent)
- 【DECYZJA: dietary-data deletion deadline after the congress】 — kept separately from, and for a shorter period than, the rest of the participation record, restricted to catering use.
- Invoicing data and accounting documents
- 5 years from the end of the calendar year in which the tax obligation arose — legal obligation (Art. 6(1)(c) GDPR), tax and accounting law.
Voluntariness
Providing data marked as required is voluntary but necessary to conclude and perform the participation contract; invoicing data is necessary if you request an invoice, and the Tax ID (NIP) is a requirement of tax law. Data not marked as required (e.g. additional comments) is entirely voluntary.
Your rights
Access, rectification, erasure, restriction, data portability, objection (for data processed under Art. 6(1)(f) GDPR, on grounds relating to your particular situation), and complaint to the President of PUODO.
Transfers outside the EEA: see "Transfers outside the EEA" in Common information. Automated decision-making/profiling: none.
Abstract submission (submitting person)
Article 13 GDPR
Categories of data
Identification and contact data of the submitting person (academic title, first name, last name, affiliation, e-mail, phone), plus the submission itself in IMRaD structure: abstract title, abstract body (up to 300 words), the Introduction (up to 800 words), Material and Methods, Results and Discussion sections (up to 1000 words each) and, optionally, Limitations (up to 400 words) and References (up to 8000 characters), theme, keywords (up to 3), comments, session type, presentation language, presenting-author indicator, and attachments (up to 5 files per abstract in PDF, PNG, JPEG, or TIFF format, up to 5 MB per file, with an optional caption).
Purposes of processing
- receipt and substantive evaluation (review) of the abstract by the scientific committee,
- contact with the submitting person about the status of the submission,
- publication of the accepted abstract in the book of abstracts and congress materials,
- scientific archiving.
Legal basis
Article 6(1)(b) GDPR — processing necessary to carry out submission, evaluation and publication (a contractual relationship between the submitter and the Organizer). For scientific archiving and publication of the author's name alongside the abstract, Article 6(1)(f) GDPR also applies (legitimate interest — integrity and permanence of conference output).
Recipients
Scientific-committee reviewers (acting under the Controller's authorization and bound by confidentiality), Cloudflare, Inc. (attachment storage via Cloudflare R2), Vercel and Railway (hosting + database), Resend (transactional e-mail, United States), the maintenance developer. After publication — congress participants and, where the book is public, the general public.
Retention period
Published abstracts remain publicly available indefinitely in the book of abstracts, in line with the purpose of publication. The underlying source files and attachments are kept only for 1 month (30 days) after the end of the Congress — a shorter, limited archive window distinct from the perpetual publication itself. Where the abstract is not accepted, the submitter's and co-authors' contact data is kept only for 1 month (30 days) after the end of the Congress.
Voluntariness
Providing the data is voluntary but necessary to submit, evaluate and publish the abstract — without it the submission cannot be processed.
Your rights
Access, rectification, erasure, restriction, data portability, objection (to processing under Art. 6(1)(f) GDPR), and complaint to the President of PUODO. Some rights (e.g. erasure) may be limited for already-published abstracts, owing to the integrity of the scientific output.
Transfers outside the EEA: see "Transfers outside the EEA" in Common information. Automated decision-making/profiling: none — the abstract is evaluated by reviewers (humans).
Contact form
Article 13 GDPR
Categories of data
First and/or last name, e-mail address, and the content of the message (and any other data you voluntarily include).
Purpose of processing
Responding to the enquiry submitted via the contact form and conducting correspondence on the matter (including the contact-inquiry-autoreply message).
Legal basis
Article 6(1)(f) GDPR — the Controller's legitimate interest in handling and responding to enquiries addressed to it.
Recipients
Vercel, Railway (hosting + database), Resend (transactional e-mail, United States), the maintenance developer. See "Common information".
Retention period
1 year from the last contact on the matter, and in the event of claims — until they become time-barred.
Voluntariness
Providing the data is voluntary but necessary to respond — without an e-mail address we cannot reply.
Your rights
Access, rectification, erasure, restriction, objection (Art. 21 GDPR — on grounds relating to your particular situation, to processing under Art. 6(1)(f) GDPR), and complaint to the President of PUODO. Data portability does not apply — this processing rests solely on legitimate interest, not on consent or a contract.
Transfers outside the EEA: see "Transfers outside the EEA" in Common information. Automated decision-making/profiling: none.
Sponsorship inquiry form
Article 13 GDPR
Categories of data
First and last name of the contact person, e-mail address, telephone number, name of the represented company/organization, position/role, and the content of the enquiry.
Purpose of processing
Conducting business discussions on sponsorship/exhibition cooperation, preparing and presenting an offer, and taking steps towards concluding a contract (including the sponsorship-received message).
Legal basis
- Article 6(1)(b) GDPR — taking steps at the request of the data subject prior to entering into a contract (pre-contractual steps);
- Article 6(1)(f) GDPR — the Controller's legitimate interest in conducting business discussions, marketing its own congress services to business partners, and the possible establishment, pursuit or defence of claims.
Recipients
Vercel, Railway (hosting + database), Resend (transactional e-mail, United States), the maintenance developer. See "Common information".
Retention period
For the duration of the discussions, and after their conclusion for 3 years (general limitation period for claims arising from business activity). If a contract is concluded — for its performance and the period arising from tax and accounting obligations.
Voluntariness
Providing the data is voluntary but necessary to undertake discussions and present an offer.
Your rights
Access, rectification, erasure, restriction, data portability (for data processed under Art. 6(1)(b) GDPR), objection (Art. 21 GDPR — to processing under Art. 6(1)(f) GDPR), and complaint to the President of PUODO.
Transfers outside the EEA: see "Transfers outside the EEA" in Common information. Automated decision-making/profiling: none.
Photography and recording at the Congress
Article 13 GDPR â attendees, exhibitors and guests present at the Congress venue.
Data processed
Image and voice fixed in photographs and audio/video recordings made at the Congress venue, together with the date, place and name of the session concerned.
Purposes
- documenting the course of the Congress and reporting to partners and public bodies;
- promoting the Congress and its future editions in the Organizer’s own channels;
- establishing, pursuing or defending claims.
Legal basis
Article 6(1)(f) GDPR — the Organizer’s legitimate interest in documenting and promoting a scientific event. General coverage of the room, the audience and the exhibition area is made on this basis; no separate consent is taken for it. For close-up and portrait shots see “Separate consent” below.
On-site notice
A notice about image capture is displayed at the entrances to the venue and to each session room, and is repeated in the registration materials. Photographers and camera operators working for the Organizer are identifiable by press accreditation.
No-photography zones
Photography and recording are prohibited in signposted no-photography zones — at minimum the wellbeing/rest area, the first-aid point and any space identified by contributors to patient sessions. Exhibitors and sponsors may photograph only within their own stand, never in session rooms, and are separate controllers of anything they record.
Separate consent
Using a shot in which you are recognisable as the main subject of the frame (portrait, close-up, image-led promotional material) requires your separate, voluntary consent, taken on the same image-consent form used for speakers and abstract submitters. That consent is never a condition of participation and may be withdrawn at any time with effect for the future by writing to info@iccsh2027.org.
Recipients
The photography and video contractor engaged by the Organizer, Vercel and Railway (hosting), Cloudflare R2 (file storage), the maintenance developer. Published material is visible to anyone who visits the Organizer’s channels. See “Common information”.
Retention period
for as long as the Organizer carries on congress activity, for archival and documentation purposes, with a review of the continued need every 5 years; shots in which a person is recognisable as the main subject of the frame are kept no longer than until that person withdraws their consent, and general shots no longer than until an objection is upheld. Material published in the Organizer’s channels remains available until the publication is withdrawn.
Your rights
Access, rectification, erasure, restriction and — because the basis is Article 6(1)(f) GDPR — the right to object under Article 21 GDPR, which you may exercise on site by telling Congress staff or the photographer. Where a shot rests on your separate consent, you may withdraw that consent at any time. You also have the right to complain to the President of PUODO.
Transfers outside the EEA: see “Transfers outside the EEA” in Common information. Automated decision-making/profiling: none. Facial recognition and biometric identification: not used.
Payments (three-party processing)
Processing model
Online payments (registration fee, add-ons) are handled by external payment operators. The Controller does not store your payment card data — payment data are entered by you directly in the operator's environment, which is responsible for their security under the PCI DSS standard.
What the Controller receives
The Controller receives from the operator only the transaction status (e.g. paid/unpaid/refunded) and the transaction identifier, needed to confirm payment and link it to your submission (payment-confirmed message). To that extent the Controller processes data under Article 6(1)(b) GDPR (performance of the participation contract) and Article 6(1)(c) GDPR (settlement and tax obligations).
Payment operators as separate controllers
With respect to payment data, the separate, independent data controllers are:
- Stripe Payments Europe, Ltd.
- Dublin, Ireland — Privacy policy
- PayPro SA (Przelewy24)
- ul. Pastelowa 8, Poznań, KRS 0000347935 — GDPR information obligation
Each operator processes your payment data in its own name and on its own responsibility, as an independent data controller — detailed information (purposes, bases, rights, any transfers) is set out in their own privacy policies above.
Retention period (on the Controller's side)
Data on the status and identifier of the transaction are retained with settlement and invoicing documentation for 5 years from the end of the calendar year in which the tax obligation arose (Art. 6(1)(c) GDPR).
Your rights vis-à-vis the Controller
Access, rectification, erasure (subject to tax and accounting obligations), restriction, data portability, and complaint to the President of PUODO. Rights concerning payment data processed by the operators are exercised directly vis-à-vis the relevant operator.
Transfers outside the EEA (on the Controller's side): see "Transfers outside the EEA" in Common information. Automated decision-making/profiling on the Controller's side: none.
Complaints and legal sources
Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority if you consider that the processing of your personal data infringes the GDPR.
President of the Personal Data Protection Office (PUODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Sources and legal basis
- Regulation (EU) 2016/679 (GDPR), in particular Articles 6, 13, 14, 21 and 22, and Chapter V;
- Guidelines of the Article 29 Working Party / European Data Protection Board on transparency under Regulation 2016/679 (WP260 rev.01);
- Decisions and guidelines of the President of the Personal Data Protection Office (uodo.gov.pl);
- the Act of 11 March 2004 on VAT, the Act of 29 September 1994 on Accounting, and the Act of 29 August 1997 — Tax Ordinance (retention periods for settlement documents).
dp.handoff.privacy.title1 dp.handoff.privacy.title2
dp.handoff.privacy.body
II.dp.handoff.terms.eyebrowdp.handoff.terms.title1 dp.handoff.terms.title2
dp.handoff.terms.body
III.dp.handoff.cancellationPolicy.eyebrowdp.handoff.cancellationPolicy.title1 dp.handoff.cancellationPolicy.title2
dp.handoff.cancellationPolicy.body