Effective 24 August 2026. This operational notice should be reviewed with counsel and supplemented with the organisation’s registered legal details before the members hub launches.
1. Who is responsible for your data
Vistula Valley is responsible for personal data processed through this website and the Vistula Valley members service. Questions and data-protection requests can be sent to info@vistulavalley.org.
2. Information we collect
We collect information you choose to provide when you apply, contact us, create or update a member profile, request an introduction, or pay for membership. This may include your name, email address, phone number, professional information, profile links, photograph, referral and application details, membership status, and payment reconciliation information.
We also process limited technical information needed to operate and secure the service, such as authentication records, request metadata, and security or audit events. Payment card details are handled by the payment provider and are not stored in the Vistula Valley members database.
3. Why we use it
We use personal data to:
- review membership applications and administer memberships;
- provide the private member directory and member-requested introductions;
- reconcile payments, renewals, and access to membership services;
- communicate about an application, account, membership, or service request;
- protect the service, investigate misuse, and meet legal obligations.
The legal basis depends on the activity and may include your consent, steps requested before or under a membership arrangement, Vistula Valley’s legitimate interest in operating a safe professional community, or a legal obligation. Directory consent can be withdrawn, although this does not affect processing that was lawful before withdrawal.
4. Who receives it
Access is limited to authorised Vistula Valley administrators and service providers that supply hosting, database, storage, email, authentication, and payment services. Providers receive only the information needed for their role and are expected to protect it. We may disclose information where required by law or needed to establish or defend legal claims. We do not sell personal data.
5. Retention and security
We keep information only as long as needed for membership administration, security, accounting, dispute handling, and legal requirements, then delete or anonymise it. Retention periods should be finalised in Vistula Valley’s internal data-retention schedule.
The members service uses access controls, private attachment storage, encrypted transport, and application-level encryption for member and payment identity data at rest. No online service can guarantee absolute security; suspected incidents should be reported to the contact above.
6. Cookies
The public site does not require advertising cookies. The members service uses essential session and security cookies to sign users in and protect their accounts. If analytics or non-essential cookies are introduced, this notice and the consent controls must be updated before they are enabled.
7. Your rights
Subject to applicable law, you may ask to access, correct, delete, restrict, or receive a copy of your personal data, object to certain processing, or withdraw consent. You may also complain to the data-protection authority that applies to you; in Poland this is the President of the Personal Data Protection Office (UODO).
To make a request, email info@vistulavalley.org. We may need to verify your identity before acting on a request.
8. Changes
We will update this page when our processing or legal details change and will show the effective date above. Material changes affecting members will also be communicated through an appropriate membership channel.


