Obowiązuje od 28.08.2026 / In force from 28.08.2026
Polityka prywatności

§ 1. Administrator

1.1. Administratorem danych osobowych jest Magnitudo Group sp. z o.o. z siedzibą we Wrocławiu, ul. Wyspa Słodowa 7 lok. 220, 50-266 Wrocław, KRS 0001067988, NIP 8971929665, REGON 526938578 (dalej: Administrator).

1.2. We wszystkich sprawach dotyczących danych osobowych można kontaktować się pod adresem office@darkdancestudio.com, oznaczając wiadomość dopiskiem „Ochrona danych".

1.3. Odwołania do RODO oznaczają rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 z dnia 27 kwietnia 2016 r. w sprawie ochrony osób fizycznych w związku z przetwarzaniem danych osobowych i w sprawie swobodnego przepływu takich danych.


§ 2. Dane przetwarzane w związku z zakupem biletu

2.1. W związku ze sprzedażą wstępu na wydarzenie Administrator przetwarza następujące kategorie danych:

Dane

Źródło

Cel

Podstawa prawna

Imię i nazwisko

podane przez osobę

wystawienie i ponowne wystawienie biletu, identyfikacja przy wejściu

art. 6 ust. 1 lit. b RODO — wykonanie umowy

Adres poczty elektronicznej

podany przez osobę

dostarczenie biletu, potwierdzenia płatności i faktury, kontakt w sprawie wydarzenia

art. 6 ust. 1 lit. b RODO

Numer telefonu

podany przez osobę

pilny kontakt w sprawie wydarzenia

art. 6 ust. 1 lit. b RODO

Wiek

podany przez osobę

weryfikacja wymogów wiekowych i planowanie harmonogramu

art. 6 ust. 1 lit. f RODO — prawnie uzasadniony interes

Adres rozliczeniowy

podany przez osobę

ustalenie właściwego podatku i wystawienie prawidłowej faktury

art. 6 ust. 1 lit. c RODO — obowiązek prawny

Numer VAT, w przypadku zakupu przez przedsiębiorcę

podany przez osobę

wystawienie faktury na przedsiębiorcę; weryfikacja w systemie VIES wraz z datowanym zapisem

art. 6 ust. 1 lit. c RODO

Kwota, waluta i identyfikator płatności

otrzymane od dostawcy usług płatniczych

księgowanie i powiązanie płatności z biletami

art. 6 ust. 1 lit. c RODO

2.2. Administrator nie otrzymuje, nie przetwarza ani nie przechowuje danych kart płatniczych. Dane karty przekazywane są bezpośrednio dostawcy usług płatniczych. Jeżeli numer karty zostanie omyłkowo wpisany w pole tekstowe, system to wykrywa i nie zapisuje wartości.


§ 3. Dane przetwarzane w związku z uczestnictwem

3.1. W związku z wstępem na teren wydarzenia Administrator przetwarza:

Dane

Cel

Podstawa prawna

Kod QR biletu

wpuszczenie i zapobieżenie wielokrotnemu użyciu tego samego kodu

art. 6 ust. 1 lit. b RODO

Godzina wejścia i sposób jego udzielenia

wiedza o liczbie osób obecnych, ze względu na pojemność i bezpieczeństwo

art. 6 ust. 1 lit. f RODO


§ 4. Dane uczestników poniżej 18. roku życia

4.1. Uczestnik poniżej 18. roku życia składa przy wejściu pisemne oświadczenie o zgodzie rodzica lub opiekuna prawnego. Oświadczenie zawiera imię i nazwisko rodzica lub opiekuna, numer telefonu oraz podpis.

Dane

Źródło

Cel

Podstawa prawna

Imię, nazwisko i podpis rodzica lub opiekuna

oświadczenie złożone przez uczestnika

potwierdzenie dopuszczalności udziału oraz ważności zakupu zgodnie z art. 17 Kodeksu cywilnego

art. 6 ust. 1 lit. c RODO

Numer telefonu rodzica lub opiekuna

to samo oświadczenie

kontakt w razie zdarzenia z udziałem osoby małoletniej w czasie wydarzenia

art. 6 ust. 1 lit. f RODO

4.2. Powyższe stanowią dane osoby trzeciej. Uczestnik składający oświadczenie obowiązany jest poinformować rodzica lub opiekuna o obowiązywaniu niniejszej Polityki.


§ 5. Fotografowanie i nagrywanie

5.1. Wydarzenie jest fotografowane i nagrywane. Materiały z zajęć, sali i miejsca wydarzenia publikowane są w kanałach Administratora na podstawie jego prawnie uzasadnionego interesu polegającego na dokumentowaniu i promocji wydarzenia (art. 6 ust. 1 lit. f RODO).

5.2. Zgodnie z art. 81 ust. 2 pkt 2 ustawy z dnia 4 lutego 1994 r. o prawie autorskim i prawach pokrewnych odrębne zezwolenie nie jest wymagane dla rozpowszechniania wizerunku osoby stanowiącej jedynie szczegół całości takiej jak zgromadzenie lub impreza publiczna.

5.3. Jeżeli Administrator zamierza uczynić rozpoznawalnego uczestnika przedmiotem materiału reklamowego, uzyskuje uprzednio zgodę tej osoby (art. 6 ust. 1 lit. a RODO). Zgoda może zostać cofnięta w każdym czasie, a wobec wykorzystania materiału z wizerunkiem osoby można w każdym czasie wnieść sprzeciw.


§ 6. Pliki cookies

6.1. Strona wykorzystuje pliki cookies własne i podmiotów trzecich. Stosowane narzędzia to Google Analytics, Google Ads, Meta Pixel, Google reCAPTCHA i Google Tag Manager.

6.2. Cookies niezbędne są konieczne do działania strony i zapisywane w każdym przypadku, na podstawie prawnie uzasadnionego interesu Administratora (art. 6 ust. 1 lit. f RODO).

6.3. Cookies analityczne i reklamowe zapisywane są wyłącznie za zgodą osoby (art. 6 ust. 1 lit. a RODO), wyrażoną za pomocą banera wyświetlanego przy pierwszej wizycie. Zgodę można w ten sam sposób zmienić lub cofnąć. Odmowa nie wpływa na możliwość zakupu biletu.

6.4. Pełna lista narzędzi, ich dostawców oraz odesłania do właściwych polityk znajdują się w Polityce cookies.


§ 7. Komunikacja marketingowa

7.1. Informacje handlowe dotyczące przyszłych edycji wydarzenia wysyłane są wyłącznie osobom, które wyraziły na to zgodę. Zakup biletu nie stanowi takiej zgody. Każda wiadomość zawiera możliwość cofnięcia zgody.


§ 8. Odbiorcy danych8.1. Dane osobowe udostępniane są wyłącznie podmiotom, których udział jest niezbędny do organizacji wydarzenia:

a) Stripe Payments Europe, Ltd. — obsługa płatności, wystawianie potwierdzeń płatności i faktur, obliczanie podatku;

b) dostawca hostingu — przechowywanie bazy biletowej na swoich serwerach, zlokalizowanych na Ukrainie;

c) doradcy księgowi i prawni — fakturowanie, rozliczenia podatkowe i doradztwo;

d) organy władzy publicznej — gdy wymagają tego przepisy prawa.

8.2. Osoby z obsługi Administratora obecne przy wejściu mają dostęp do imienia, nazwiska i rodzaju biletu uczestnika, co jest niezbędne do weryfikacji wstępu. Instruktorzy, obsługa obiektu i pozostali uczestnicy nie otrzymują danych osobowych.

8.3. Przekazywanie poza Europejski Obszar Gospodarczy. Ukraina nie należy do państw, w odniesieniu do których Komisja Europejska wydała decyzję stwierdzającą odpowiedni stopień ochrony. Przechowywanie bazy na serwerach zlokalizowanych na Ukrainie stanowi zatem przekazanie do państwa trzeciego. Przekazanie to odbywa się na podstawie standardowych klauzul umownych zatwierdzonych przez Komisję Europejską, zawartych z dostawcą hostingu.

8.4. Jeżeli którykolwiek z pozostałych podmiotów wskazanych w pkt 8.1 przetwarza dane poza Europejskim Obszarem Gospodarczym, czyni to na podstawie decyzji stwierdzającej odpowiedni stopień ochrony albo standardowych klauzul umownych, o których mowa powyżej.


§ 9. Okresy przechowywania

9.1. Dane przechowywane są przez następujące okresy:

a) faktury i dokumentacja księgowa — przez okres wymagany polskimi przepisami podatkowymi, liczony od końca roku, w którym powstał obowiązek podatkowy;

b) dane biletowe i dane o obecności — do końca roku następującego po roku, w którym odbyło się wydarzenie, po czym są usuwane, chyba że są potrzebne w związku z roszczeniem;

c) fotografie i nagrania — nie dłużej niż 5 lat, chyba że wcześniej zostanie wniesiony sprzeciw albo materiał stanowi część opublikowanego archiwum;

d) zapisy weryfikacji VIES — przez taki sam okres jak związana z nimi dokumentacja podatkowa;

e) oświadczenia o zgodzie rodzica dla uczestników poniżej 18. roku życia — do końca roku następującego po roku, w którym odbyło się wydarzenie.

9.2. Każdy z powyższych okresów ulega przedłużeniu na czas trwania roszczenia lub biegu terminu przedawnienia.


§ 10. Prawa osób, których dane dotyczą

10.1. Osobie, której dane dotyczą, przysługuje prawo dostępu do danych i otrzymania ich kopii, prawo do ich sprostowania, usunięcia lub ograniczenia przetwarzania oraz prawo do przenoszenia danych. Przysługuje jej także prawo wniesienia sprzeciwu wobec przetwarzania opartego na prawnie uzasadnionym interesie oraz prawo cofnięcia udzielonej zgody. Cofnięcie zgody nie wpływa na zgodność z prawem przetwarzania dokonanego przed jej cofnięciem.

10.2. Podanie danych wskazanych w pkt 2.1 jest warunkiem zakupu. Bez tych danych Administrator nie może wystawić biletu ani faktury, a podanie części z nich wymagane jest przepisami podatkowymi.

10.3. Wniosek o usunięcie danych niezbędnych do wpuszczenia, złożony przed odbyciem się wydarzenia, uniemożliwi weryfikację biletu przy wejściu.

10.4. Osobie, której dane dotyczą, przysługuje prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.


§ 11. Zautomatyzowane podejmowanie decyzji

11.1. Administrator nie prowadzi profilowania i nie podejmuje wobec osób, których dane dotyczą, decyzji w sposób zautomatyzowany.

11.2. W zakresie płatności dostawca usług płatniczych stosuje wobec transakcji zautomatyzowane kontrole przeciwdziałające oszustwom i może odmówić realizacji płatności. Przetwarzanie to prowadzi dostawca usług płatniczych na własnych zasadach. Jeżeli płatność została odrzucona, a osoba uznaje to za błąd, może skontaktować się z Administratorem.


§ 12. Zakup na rzecz innej osoby12.1. Osoba nabywająca bilet na rzecz innej osoby obowiązana jest posiadać jej upoważnienie do przekazania danych Administratorowi oraz poinformować ją o obowiązywaniu niniejszej Polityki. Administrator traktuje nabywcę jako punkt kontaktowy.


§ 13. Zmiany Polityki13.1. Administrator może zmienić niniejszą Politykę. Do danego zakupu stosuje się wersję obowiązującą w chwili jego dokonania.

Magnitudo Group sp. z o.o. · ul. Wyspa Słodowa 7 lok. 220, 50-266 Wrocław · KRS 0001067988 · NIP 8971929665

Privacy Policy
1. Controller
1.1. The controller of personal data is Magnitudo Group sp. z o.o., with its registered office at ul. Wyspa Słodowa 7 lok. 220, 50-266 Wrocław, Poland, KRS 0001067988, NIP PL8971929665, REGON 526938578 (hereinafter: the Controller).
1.2. In all matters concerning personal data, contact may be made at office@darkdancestudio.com, marking the message "Data protection".
1.3. References in this Policy to the GDPR mean Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

2. Data processed in connection with the purchase of a ticket
2.1. In connection with the sale of admission to the event, the Controller processes the following categories of data:

Data

Source

Purpose

Legal basis

Name and surname

provided by the data subject

issue and reissue of the ticket, identification at the entrance

art. 6(1)(b) GDPR — performance of a contract

Email address

provided by the data subject

delivery of the ticket, confirmation of payment and invoice, communication concerning the event

art. 6(1)(b) GDPR

Telephone number

provided by the data subject

urgent communication concerning the event

art. 6(1)(b) GDPR

Age

provided by the data subject

verification of age requirements and planning of the programme

art. 6(1)(f) GDPR — legitimate interest

Billing address

provided by the data subject

determination of the applicable tax and issue of a valid invoice

art. 6(1)(c) GDPR — legal obligation

VAT identification number, in the case of purchases by businesses

provided by the data subject

issue of an invoice to the business; verification in the VIES system with retention of a dated record

art. 6(1)(c) GDPR

Amount, currency and payment identifier

received from the payment provider

accounting and reconciliation of payments with tickets

art. 6(1)(c) GDPR

2.2. The Controller does not receive, process or store payment card data. Card details are transmitted directly to the payment provider. Where a card number is entered into a text field in error, the system detects it and does not record the value.

3. Data processed in connection with participation
3.1. In connection with admission to the venue, the Controller processes:

Data

Purpose

Legal basis

The QR code of the ticket

admission and prevention of the use of a single code more than once

art. 6(1)(b) GDPR

Time of admission and the manner in which it was granted

knowledge of the number of persons present, for reasons of capacity and safety

art. 6(1)(f) GDPR


4. Data of participants under 18 years of age
4.1. A participant under 18 years of age submits, at the entrance, a written statement of consent of a parent or legal guardian. The statement contains the name of the parent or guardian, a telephone number and a signature.

Data

Source

Purpose

Legal basis

Name and signature of the parent or guardian

the statement submitted by the participant

confirmation that participation is permitted and that the purchase is valid pursuant to art. 17 of the Civil Code

art. 6(1)(c) GDPR

Telephone number of the parent or guardian

the same statement

contact in the event of an incident involving the minor during the event

art. 6(1)(f) GDPR

4.2. The above constitutes data of a third party. A participant who submits the statement is obliged to inform the parent or guardian that this Policy applies.

5. Photography and filming
5.1. The event is photographed and filmed. Recordings of the classes, the hall and the venue are published in the Controller's channels on the basis of its legitimate interest in documenting and promoting the event (art. 6(1)(f) GDPR).
5.2. Pursuant to art. 81(2)(2) of the Act of 4 February 1994 on Copyright and Related Rights, separate permission is not required for the dissemination of the image of a person constituting only a detail of a whole such as a public event.
5.3. Where the Controller intends to make an identifiable participant the subject of advertising material, the consent of that person is obtained beforehand (art. 6(1)(a) GDPR). Consent may be withdrawn at any time, and objection may be raised at any time to the use of material featuring the data subject.

6. Cookies
6.1. The website uses cookies, both its own and those of third parties. The tools employed are Google Analytics, Google Ads, the Meta Pixel, Google reCAPTCHA and Google Tag Manager.
6.2. Necessary cookies are required for the operation of the website and are set in every case, on the basis of the Controller's legitimate interest (art. 6(1)(f) GDPR).
6.3. Analytics and advertising cookies are set solely with the consent of the data subject (art. 6(1)(a) GDPR), given by means of the banner displayed on the first visit. Consent may be modified or withdrawn by the same means. Refusal does not affect the ability to purchase a ticket.
6.4. A full list of the tools, their providers and links to their respective policies is set out in the Cookies Policy.

7. Marketing communications
7.1. Commercial communications concerning future editions of the event are sent solely to persons who have consented to receive them. The purchase of a ticket does not constitute such consent. Each communication contains a means of withdrawing consent.

8. Recipients of data
8.1. Personal data are disclosed exclusively to entities whose involvement is necessary for the organisation of the event:
a) Stripe Payments Europe, Ltd. — processing of payments, issue of confirmations of payment and invoices, calculation of tax;
b) the hosting provider — storage of the ticketing database on its servers, located in Ukraine;
c) accounting and legal advisers — invoicing, tax filings and advice;
d) public authorities — where required by law.
8.2. Members of the Controller's staff present at the entrance have access to the name and ticket type of a participant, this being necessary for the verification of admission. Instructors, venue staff and other participants do not receive personal data.
8.3. Transfers outside the European Economic Area. Ukraine is not among the countries in respect of which the European Commission has adopted an adequacy decision. Accordingly, the storage of the database on servers located in Ukraine constitutes a transfer to a third country. That transfer is effected on the basis of standard contractual clauses approved by the European Commission and concluded with the hosting provider.
8.4. Where any other entity referred to in clause 8.1 processes data outside the European Economic Area, it does so on the basis of an adequacy decision or of the standard contractual clauses referred to above.

9. Retention periods
9.1. Data are retained for the following periods:
a) invoices and accounting records — for the period required by Polish tax law, calculated from the end of the year in which the tax became due;
b) ticket and attendance records — until the end of the year following that in which the event took place, after which they are erased, unless required in connection with a claim;
c) photographs and recordings — for no longer than 5 years, unless objection is raised earlier or the material forms part of published archive material;
d) records of VIES verification — for the same period as the related tax records;
e) statements of parental consent for participants under 18 years of age — until the end of the year following that in which the event took place.
9.2. Each of the above periods is extended for as long as a claim remains open or a limitation period is running.

10. Rights of data subjects
10.1. The data subject has the right to obtain a copy of their data, to have them rectified, erased or their processing restricted, and to data portability. The data subject has the right to object to processing carried out on the basis of legitimate interest and to withdraw any consent given. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
10.2. Provision of the data set out in clause 2.1 is a condition of purchase. Without those data the Controller is unable to issue a ticket or an invoice, and provision of certain of those data is required by tax law.
10.3. Where a request for erasure of the data necessary for admission is made before the event has taken place, verification of the ticket at the entrance will no longer be possible.
10.4. The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

11. Automated decision-making
11.1. The Controller does not carry out profiling and does not take decisions concerning data subjects by automated means.
11.2. In relation to payments, the payment provider applies automated fraud checks to transactions and may decline a payment. Such processing is carried out by the payment provider in accordance with its own rules. Where a payment is declined and the data subject considers this to be erroneous, contact may be made with the Controller.

12. Purchases made on behalf of another person
12.1. A person purchasing a ticket on behalf of another shall have that person's authorisation to provide their data to the Controller and shall inform them that this Policy applies. The Controller treats the purchaser as the point of contact.

13. Amendments
13.1. The Controller may amend this Policy. The version applicable to a given purchase is the version in force at the time that purchase was made.
Magnitudo Group sp. z o.o. · ul. Wyspa Słodowa 7 lok. 220, 50-266 Wrocław · KRS 0001067988 · NIP PL8971929665