Accessibility settings

Contrast
Font size
Text spacing
Font type
Animations
Search the collection PL

Privacy and Cookies Policy

This policy explains what data may be processed when using the Virtual Museum Gręboszowa website and how we comply with our information obligations regarding privacy and cookies.

1. Data Controller

The data administrator is the Municipal Centre for Culture and Reading in Gręboszów (GCKiCz) / the entity running the website. For data protection matters, contact: the contact details provided on the Contact page.

2. Scope and purposes of processing

  • service and technical safety support,
  • publication of museum content and information materials,
  • handling correspondence addressed to contact addresses GCKiCz,
  • authentication of authorized editors in the CMS panel (only people with access to the project repository),
  • anonymous statistics of visits to the public website (page popularity, traffic sources, devices — without identifying individuals).

3. Editorial Panel (CMS)

The panel at '/admin/' is used only by authorized editors to edit the content of the page. Visitors to the public service are not asked to log in to the panel.

When logging in with GitHub, the following can be processed:

  • GitHub account ID (login) and data necessary to authorize access to the repository,
  • an access token issued by GitHub after the login is approved,
  • Request specifications (IP address, browser headers, timestamp) – in infrastructure provider logs.

The CMS session token can be saved locally in the editor's browser ('localStorage' mechanism) – just so that you don't have to log in every time you visit. It is not used to profile visitors to a public website.

Alternatively, the editor can use Sign In with Token (a personal GitHub access token) - then the token is also stored locally in the editor's browser and is not published to the page repository.

Objective: To ensure secure content editing and accountability of changes (commit history in the Git repository). Basis: performance of tasks carried out in the public interest and the legitimate interest of the administrator (security and maintenance of the website).

4. Legal basis

The data are processed in accordance with the provisions of the GDPR on the basis of appropriate premises, in particular: performance of legal obligations, performance of tasks performed in the public interest and the legitimate interest of the administrator (e.g. security of the website).

Anonymous statistics of visits to the public website (Umami Cloud) are processed on the basis of the legitimate interest of the administrator (Art. 6(1)(f) GDPR) — assessing content popularity and maintaining the service, without identifying visitors and without profiling.

5. Data recipients and service providers

The service is published using the GitHub Pages infrastructure (GitHub / Microsoft). The content and history of editorial changes are stored in the Git repository on GitHub.

Logging in editors to the CMS panel uses:

  • GitHub (Microsoft) - account authentication and authorization of access to the repository (OAuth or personal token),
  • Cloudflare Workers — an OAuth intermediary (worker 'muzeum-greboszow-cms-auth') that handles login redirection between the CMS panel and GitHub; Worker does not store editorial content.

Depending on the functions of the public website used, technical data may also be processed by other external service providers embedded on the website (e.g. links to social media, YouTube or Internet Archive video embeds).

Traffic analytics (public website): we use Umami Cloud (Umami Software) — anonymous visit statistics without cookies and without user profiling. The analytics script is loaded from the website domain; events (page views, page URL, referrer, device type, approximate country) are sent to Umami Cloud infrastructure. This is not used to identify specific individuals.

6. Transfers of data outside the EEA

If data is processed by suppliers outside the European Economic Area, this is done on the basis of mechanisms permitted by the GDPR (e.g. standard contractual clauses). Details are based on the current terms and conditions of service providers.

Umami Cloud (public website analytics): statistical data is processed in the provider's cloud infrastructure. The account should be configured for the EU region when available. If processing takes place outside the EEA, Umami applies GDPR transfer mechanisms (e.g. standard contractual clauses).

7. Data retention period

The data is stored for the period necessary to achieve the purpose of processing or for the period required by law, and then deleted or anonymized.

Traffic statistics in Umami Cloud (Hobby plan) are retained for 6 months, after which they are automatically deleted by the service provider.

The CMS session token in the editor's browser remains until you sign out or delete the site data in the browser. The history of changes to content in a Git repository is stored according to GitHub policies and project archiving needs.

8. Rights of data subjects

You have the right to access the data, rectify them, delete them, limit processing, object (in cases provided for by law), as well as the right to lodge a complaint with the President of the Personal Data Protection Office.

9. Cookie policy and browser local storage

The Website may use technically necessary mechanisms for storing data in the browser (e.g. interface settings, accessibility or editorial panel settings). They are not used to profile a user visiting a public website.

On the public website, the accessibility panel stores preferences (contrast, font size, etc.) in localStorage — only in the user's browser, without cookies and without sharing this data with external providers.

The CMS panel of the editor can save, m.in: login session token, editing language preference (PL/EN), and toolbar settings — only in the browser of the authorized user.

As of the date of publication of this policy, the public website uses Umami Cloud — a cookie-free analytics tool that does not require cookie consent under ePrivacy rules. We do not use marketing tools that require a consent banner.

If in the future other analytical or marketing tools requiring consent are added, the website will be supplemented with an appropriate mechanism for managing cookie consents.

10. Policy changes

The Policy may be updated with changes in regulations or the functionality of the website. The current version is always published on this page.

Last updated: 2026-08-14