PGON Website Privacy Policy
1. General information
This Privacy Policy sets out the rules for processing personal data and using cookies on the PGON website available at pgon.eu, including within the user panel.
The PGON website enables users, among other things, to access information concerning GNSS and InSAR technologies, create a user account, contact the PGON team and use services related to the processing of GNSS observations.
2. Personal Data Controller
The controller of the personal data of website users is:
Wrocław University of Environmental and Life Sciences
25 C.K. Norwida Street
50-375 Wrocław
Tax Identification Number (NIP): 896-000-53-54
REGON Statistical Number: 000001867
The PGON website is operated as part of the activities and projects carried out by the Wrocław University of Environmental and Life Sciences.
PGON team address:
PGON
55 Grunwaldzka Street
50-357 Wrocław
3. Data Protection Officer
The Controller has appointed a Data Protection Officer who may be contacted regarding all matters concerning the processing of personal data and the exercise of rights arising from data protection laws.
Contact details of the Data Protection Officer:
4. Scope of the data processed
Depending on how the website is used, we may process the following data:
User account
When registering and using an account, we may process:
- username,
- email address,
- authentication data,
- login information,
- IP address,
- account creation date and activity data,
- account and website settings.
Contact form
When a message is submitted through the contact form, we may process:
- email address,
- message content,
- data voluntarily provided in the message,
- IP address,
- date and time when the form was submitted.
Use of PGON services
In connection with the use of services involving the processing of GNSS observations, we may process:
- identifiers of GNSS receivers and stations,
- device configuration data,
- raw GNSS observations, including data transmitted using the RTCM protocol,
- RINEX files,
- coordinates and location of a station or receiver,
- measurement date and time,
- connection and transmission data,
- calculation results,
- information concerning the status and activity of a device.
Measurement or location data constitutes personal data only when it can be linked to an identified or identifiable natural person.
Data collected automatically
When the website is used, the following information may be recorded automatically:
- IP address,
- connection date and time,
- address of the visited page,
- address of the website from which the user accessed the website,
- browser type,
- type of operating system and device,
- information about errors and technical events,
- data stored in cookies.
This information may be stored in server logs and used to ensure security, diagnose errors and maintain the proper operation of the website.
5. Purposes and legal bases for data processing
Personal data may be processed for the following purposes:
Account administration and provision of services
Data is processed for the purposes of:
- registering and administering an account,
- authenticating the user,
- providing access to the user panel,
- processing GNSS observations,
- archiving measurement data,
- making calculation results available,
- operating the user’s devices and stations.
The legal basis for processing is Article 6(1)(b) of the GDPR, meaning that processing is necessary for the performance of a contract or in order to take steps at the user’s request before entering into a contract.
Handling correspondence
Data submitted through a form or by email is processed in order to respond, handle the enquiry and conduct further correspondence.
The legal basis for processing is:
- Article 6(1)(b) of the GDPR where the message concerns entering into or performing a contract,
- Article 6(1)(f) of the GDPR, meaning the Controller’s legitimate interest in handling correspondence and responding to enquiries.
Website security and administration
Technical data and logs may be processed for the purposes of:
- ensuring website security,
- preventing misuse,
- detecting unauthorised access attempts,
- diagnosing errors,
- creating backups,
- administering IT infrastructure.
The legal basis for processing is Article 6(1)(f) of the GDPR, meaning the Controller’s legitimate interest.
Establishment, exercise and defence of legal claims
Data may be processed for the establishment, exercise or defence of legal claims.
The legal basis for processing is Article 6(1)(f) of the GDPR.
Compliance with legal obligations
Data may be processed in order to comply with obligations arising from applicable laws, particularly tax, accounting and archiving regulations and provisions concerning projects financed from public funds.
The legal basis for processing is Article 6(1)(c) of the GDPR.
Cookies and external tools
Data connected with the use of optional cookies, analytics tools, marketing tools, external fonts or embedded content is processed on the basis of the user’s consent in accordance with Article 6(1)(a) of the GDPR and Article 399 of the Polish Electronic Communications Law Act.
Consent may be withdrawn at any time through the privacy settings available on the website.
6. Cookies
The website uses cookies and similar technologies. Cookies are small pieces of information stored on or read from the user’s device while the website is being used.
The following categories of cookies may be used on the website:
Necessary cookies
These cookies are required for the proper and secure operation of the website. They may be used for purposes including:
- handling user login and sessions,
- remembering privacy settings,
- securing forms,
- protecting the website against misuse,
- ensuring the proper operation of the website’s essential functions.
Necessary cookies do not require the user’s consent. Blocking them through browser settings may prevent the website, forms or user account from functioning correctly.
Analytics cookies
These cookies help determine how users interact with the website. They may provide information concerning the number of visits, traffic sources, the popularity of individual pages and how users navigate the website.
Analytics cookies are activated only after the user has given consent.
Embedded video content
Some pages may contain content provided by external video platforms such as YouTube or Vimeo.
Playing or displaying such content may result in information concerning the user’s device, IP address and visited page being transferred to the provider. The provider may also use its own cookies.
Such content is activated only after the appropriate consent has been obtained where loading it requires access to information stored on the user’s device.
Google Fonts
The website may download fonts from Google’s servers. In such cases, the user’s browser may connect to the font provider’s servers and transmit basic technical data, including the user’s IP address.
Where external fonts are covered by the consent management system, they are loaded only after the appropriate consent has been given.
Marketing cookies
Marketing cookies may be used to measure the effectiveness of promotional activities, create audience groups or personalise advertising content.
They are activated only after the user has given consent. Where no marketing tools are active on the website, cookies belonging to this category are not stored.
7. Managing consent to cookies
During the first visit to the website, the user may:
- accept all optional cookies,
- reject all optional cookies,
- select individual categories,
- leave only necessary cookies enabled.
These settings may subsequently be changed using the consent management option available on the website.
Cookies may also be deleted and blocked through browser settings. Restricting the use of necessary cookies may prevent the user from logging in, saving settings or using certain website functions.
Detailed information concerning the names, providers, purposes and retention periods of individual cookies may be presented in the consent management panel.
8. Recipients of personal data
Data may be disclosed to:
- persons authorised by the Controller,
- organisational units of the Wrocław University of Environmental and Life Sciences,
- hosting and server infrastructure providers,
- email service providers,
- entities responsible for maintaining, developing and securing the website,
- providers of form systems, backup systems and misuse prevention services,
- providers of legal, accounting or auditing services,
- providers of analytics tools, marketing tools, fonts or video content, solely to the extent resulting from the consent given,
- public authorities where the obligation to disclose data arises from applicable laws.
Entities processing data on behalf of the Controller operate under concluded agreements and may process data only in accordance with the Controller’s instructions.
9. Transfers of data outside the European Economic Area
The use of certain external services may result in personal data being transferred outside the European Economic Area.
Such transfers may take place on the basis of:
- a European Commission adequacy decision,
- standard contractual clauses approved by the European Commission,
- other mechanisms provided for under the GDPR.
This applies in particular where the user has consented to the use of services provided by suppliers whose infrastructure or affiliated entities are located outside the European Economic Area.
10. Data retention period
Data is retained for the period necessary to fulfil the purpose for which it was collected.
In particular:
- account data is retained while the account remains active and subsequently for the period necessary to settle services and protect against legal claims,
- data connected with the provision of services and the processing of GNSS observations is retained for the period during which the service is used or for the period specified in the terms applicable to a given service or project,
- correspondence is retained for the period necessary to handle the matter and subsequently for the period required to protect against legal claims or comply with archiving obligations,
- technical logs are retained for the period necessary to ensure website security and diagnostics,
- data processed on the basis of consent is retained until consent is withdrawn or the data is no longer useful,
- data connected with legal obligations is retained for the period required under the applicable laws.
Deleting an account does not always result in the immediate deletion of all data. Certain information may continue to be retained where required by law, project archiving rules or the need to protect against legal claims.
11. User rights
The user has:
- the right of access to personal data,
- the right to obtain a copy of personal data,
- the right to rectification,
- the right to request erasure,
- the right to restriction of processing,
- the right to data portability where the conditions specified in the GDPR are met,
- the right to object to processing based on a legitimate interest,
- the right to withdraw consent at any time,
- the right to lodge a complaint with the President of the Polish Personal Data Protection Office.
The withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
To exercise these rights, the user should contact the Controller or the Data Protection Officer at iod@upwr.edu.pl.
Individual rights are not absolute. The possibility of exercising them depends on the legal basis and purpose of processing and on the applicable laws.
12. Voluntary provision of data
Providing personal data is voluntary. However, failure to provide data required during registration, login or use of a form may prevent the creation of an account, the provision of a response or the use of a selected service.
13. Automated decision-making
User data is not used to make decisions producing legal effects concerning users solely through automated means.
Should the Controller implement such solutions in the future, the user will receive separate information in accordance with the requirements of the GDPR.
14. Links to external websites
The website may contain links to external websites, scientific publications and social media platforms such as YouTube, Facebook or LinkedIn.
After accessing an external website, the user’s data is processed in accordance with the rules established by the operator of that website. The Controller has no control over how data is processed by the operators of external websites.
15. Data security
The Controller applies appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration, disclosure or destruction.
Access to personal data is granted only to authorised persons and entities providing services to the Controller to the extent necessary to perform the tasks entrusted to them.
16. Amendments to the Privacy Policy
This Privacy Policy may be updated in the event of changes to applicable laws, the operation of the website, the scope of the services provided or the tools used.
The current version of the Privacy Policy is published on the pgon.eu website.
Last updated: 18 July 2026

