Data Controller
The controller of personal data processed in connection with the operation of the Beveria Platform is:
ANM Collective sp. z o.o.
Włodzimierz 5A
98-105 Wodzierady
KRS: 0001219850
NIP: 8311649267
REGON: 54382029200000
Contact regarding personal data:
e-mail: kontakt@anmcollective.pl
phone: +48 572 069 851.
In the remainder of the document, ANM Collective sp. z o.o. is referred to as "ANM", "Controller", or "we".
Roles of ANM and the Organizer
The scope of responsibility for data depends on the purpose for which the data is processed.
ANM as the Controller
ANM is the controller of data processed in particular for the purpose of:
- creating and maintaining a Beveria Account;
- authenticating and securing the Platform;
- billing ANM plans and services;
- handling contact, inquiries, and complaints;
- maintaining the public event board;
- maintaining statistics and developing the Platform;
- Beveria marketing – if there is an appropriate basis;
- establishing, pursuing, and defending claims.
Organizer as an independent controller
The event Organizer is, as a rule, a separate controller of data processed for the purpose of:
- receiving and evaluating applications;
- selling and settling participation in the Event;
- handling participants, accompanying persons, and children;
- providing services, transport, catering, and workshops;
- conducting communication regarding the Event;
- organizing security and entry to the Event;
- marketing their own subsequent events.
The Organizer should provide the Participant with their own information clause, indicating their identity, purposes, legal bases, and data retention periods.
ANM as a processor
When ANM stores or processes Participant data solely on the documented instructions of the Organizer, it acts as a processor. Detailed rules for such processing are set out in the processing agreement concluded with the Organizer.
Scope of processed data
Depending on how the Platform is used, we may process:
Account Data
- first and last name;
- e-mail address;
- phone number, if provided;
- user ID;
- login data and authentication information;
- history of accepting regulations and consents;
- language settings and preferences.
Organizer Data
- company or organization name;
- NIP (tax ID), address, and billing data;
- contact persons' data;
- information about the plan and payments;
- team data and assigned roles;
- activity history in the panel.
Participant Data
- identification and contact data;
- application and participation status;
- ticket type and payment status;
- accompanying persons and children data;
- selected meals, workshops, transport, and gadgets;
- information stored in the Event Pass;
- entry, exit, and service provision status;
- messages related to the Event.
Data regarding special needs
The Organizer may allow providing information about allergies, diet, health condition, or special needs. Some of this information may constitute a special category of personal data.
ANM does not independently determine the purpose of collecting such information for a specific Event. The Organizer decides on their scope, need, and legal basis.
Technical data
- IP address;
- device and browser type;
- operating system;
- date and time of activity;
- session identifiers and cookies;
- security logs and error information;
- visited subpages and used functions.
Purposes and legal bases
Data may be processed for the following purposes:
Account creation and maintenance
The basis is the necessity to conclude and perform an agreement for the provision of electronic services – Art. 6 sec. 1 lit. b GDPR.
Provision of paid services
Data is processed to fulfill orders, subscriptions, billing, and payment handling based on Art. 6 sec. 1 lit. b GDPR.
Accounting and tax obligations
The basis is a legal obligation resting on the Controller – Art. 6 sec. 1 lit. c GDPR.
Platform Security
The basis is the legitimate interest of the Controller consisting in the protection of Accounts, data, systems, and abuse prevention – Art. 6 sec. 1 lit. f GDPR.
Contact and complaint handling
The basis is the performance of a contract, taking steps prior to entering into it, or a legitimate interest consisting in handling communication – Art. 6 sec. 1 lit. b or f GDPR.
Event board
Organizer data and public information about the Event are processed to publish the Announcement and provide the selected service – Art. 6 sec. 1 lit. b GDPR, and to a certain extent also on the basis of a legitimate interest in developing the Platform – Art. 6 sec. 1 lit. f GDPR.
Analytics and development
Data may be processed on the basis of a legitimate interest consisting in analyzing the operation, improving the quality, and developing the Platform – Art. 6 sec. 1 lit. f GDPR. If a given technology requires consent for cookies, the basis is consent.
Beveria Marketing
Depending on the channel and nature of communication, the basis may be consent or the legitimate interest of the Controller. Consent can be withdrawn at any time.
Claims
Data may be processed to establish, assert, or defend claims based on Art. 6 sec. 1 lit. f GDPR.
Data related to an event
When a User applies for a specific Event, their data may be made available to the Organizer of that Event.
The Organizer determines among others:
- what data is needed in the form;
- whether the application is subject to acceptance;
- what are the payment and participation rules;
- what data about diet, transport, or special needs is needed;
- how long they store data after the Event ends;
- whether and on what basis they contact regarding subsequent events.
Acceptance of the Beveria Regulations is not equivalent to consent for the Organizer's marketing.
Communication necessary to handle a specific application, payment, ticket, Event Pass, program change, or Event security may be conducted independently of marketing consent.
Accompanying persons and children
The data of an accompanying person or a child should be added only by a person authorized to provide it.
A User adding such data should inform the appropriate person about the rules for processing data, and in the case of a child, act as a parent, legal guardian, or person with appropriate authorization.
The Platform should limit the scope of children's data to information actually needed for participation, security, and service provision.
The Organizer is responsible for determining whether in a specific case additional consent of a parent or guardian is necessary.
Data and AI functions
AI functions may process data and content provided in the User's command and information from Platform modules to which a given function has been connected.
The purpose of such processing may be:
- creating a description or message;
- preparing a summary;
- analyzing operational data;
- detecting shortcomings or potential risks;
- suggesting answers or actions;
- comparing organizational variants.
The User should not enter special category data, passwords, full payment data, or information that is not needed to perform the task into free text AI commands.
Data may be transferred to AI model providers acting as processors or sub-processors, in accordance with concluded agreements and applied security measures.
Beveria does not use exclusively automated decisions producing legal effects concerning the User, unless a separate function is explicitly described along with appropriate information and safeguards.
Data recipients
Data may be transferred to:
- the Organizer of the Event to which the Participant applies;
- the authorized personnel of the Organizer – to the extent of the assigned role;
- hosting and cloud infrastructure providers;
- database and authentication providers;
- payment operators;
- e-mail and communication providers;
- analytics and security tools providers;
- AI model and infrastructure providers;
- accountants, lawyers, and other professional advisors;
- public authorities, if the obligation to provide them results from the law.
Technology providers used by the Platform may include in particular Supabase, Vercel, Stripe, Brevo, OpenAI, or DeepSeek – depending on the current configuration and the function used by the User.
Providers receive data solely to the extent needed to perform the entrusted services.
Data transfers outside the EEA
Some technology providers may process data outside the European Economic Area.
In such cases, mechanisms required by the GDPR are applied, in particular:
- a decision by the European Commission confirming an adequate level of protection;
- standard contractual clauses;
- additional technical and organizational safeguards;
- other legally permissible grounds for transfer.
Information about the applied transfer mechanism can be obtained by contacting the Controller.
Retention period
We store data no longer than is necessary to achieve the purpose for which it was collected.
In particular:
- Account data – for the duration of its activity, and then for the period needed for billing, claims handling, and legal obligations;
- contracts and payment data – for the period required by tax and accounting regulations;
- contact and complaint data – for the time of handling the matter and the limitation period for possible claims;
- marketing data – until consent is withdrawn, an objection is raised, or the purpose ceases;
- security logs – for a period justified by Platform protection and incident analysis;
- data processed for the Organizer – in accordance with their instructions, data processing agreement, and configured retention.
After the appropriate period, the data is deleted, anonymized, or kept only to the extent required by law.
Rights of data subjects
The data subject has the right – depending on the basis and circumstances – to:
- access data and obtain a copy;
- rectify data;
- erase data;
- restrict processing;
- data portability;
- object;
- withdraw consent at any time;
- obtain information about automated decision-making, where applicable;
- lodge a complaint with a supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Requests regarding Account data or Beveria operation should be directed to ANM.
Requests regarding data processed by a specific Organizer in connection with participation in an Event should primarily be directed to that Organizer. ANM may support the Organizer in fulfilling the request as the Platform provider.
Objection and withdrawal of consent
If data is processed on the basis of a legitimate interest, a person may object on grounds relating to their particular situation.
In the case of direct marketing, an objection can be raised at any time, without the need for justification.
Marketing consent can be withdrawn by:
- Account settings – if a given option is available;
- an unsubscribe link in the message;
- contact at kontakt@anmcollective.pl.
Withdrawing marketing consent does not result in loss of access to the Account, purchased ticket, or information necessary for Event handling.
Complaint to the supervisory authority
A person who believes that their data is processed unlawfully may lodge a complaint with the President of the Personal Data Protection Office.
Authority details:
Prezes Urzędu Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A
00-014 Warszawa
website: uodo.gov.pl
Voluntary provision of data
Providing data is voluntary, but some data is necessary to:
- create an Account;
- submit an application for participation;
- conclude and perform an agreement;
- settle payments;
- make the Event Pass available;
- provide selected services.
Failure to provide data marked as required may prevent the use of a given function.
Additional data, such as some preferences, marketing data, or information not required to conduct the Event, should be marked as optional.
Data security
We apply technical and organizational measures appropriate to the nature of the data and the risk, in particular:
- access control and user roles;
- Account authentication;
- transmission encryption;
- monitoring errors and security events;
- limiting the scope of data visible to personnel;
- backups and recovery mechanisms – depending on the service;
- agreements with data processing providers;
- incident response procedures.
No IT system ensures a complete absence of risk. The User should protect their password, device, and access links.
Changes to the Privacy Policy
The Policy may be changed due to a change in Platform functions, providers, technologies, processing methods, or legal provisions.
The current version is published on the Beveria website and marked with the date of entry into force.
We may inform Account holders of significant changes in the Platform or by e-mail.
Contact
In matters relating to privacy, data subject rights, and data processing by ANM, you can contact:
ANM Collective sp. z o.o.
Włodzimierz 5A
98-105 Wodzierady
e-mail: kontakt@anmcollective.pl
phone: +48 572 069 851
Once a separate Beveria help address is launched, you can replace the address kontakt@anmcollective.pl with a support address or leave both contact channels.
Potrzebujesz pomocy?
W sprawach dotyczących platformy, dokumentów prawnych lub danych osobowych skontaktuj się z ANM Collective.
